[El-errata] ELSA-2026-500248 Important: Unbreakable Enterprise kernel security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Sat Sep 5 05:22:29 UTC 2026


Oracle Linux Security Advisory ELSA-2026-500248

http://linux.oracle.com/errata/ELSA-2026-500248.html

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-core-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-devel-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-doc-6.12.0-206.104.3.3.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-tools-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-206.104.3.3.el10uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-206.104.3.3.el10uek.x86_64.rpm

aarch64:
kernel-uek-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-devel-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-doc-6.12.0-206.104.3.3.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-tools-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-206.104.3.3.el10uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-206.104.3.3.el10uek.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-206.104.3.3.el10uek.src.rpm

Related CVEs:

CVE-2025-10263
CVE-2025-21807
CVE-2025-23131
CVE-2025-38525
CVE-2025-39729
CVE-2025-39936
CVE-2025-68299
CVE-2025-68768
CVE-2026-23247
CVE-2026-31419
CVE-2026-31732
CVE-2026-43010
CVE-2026-43116
CVE-2026-43197
CVE-2026-43216
CVE-2026-43303
CVE-2026-45850
CVE-2026-45897
CVE-2026-45901
CVE-2026-45907
CVE-2026-45944
CVE-2026-46054
CVE-2026-46093
CVE-2026-46252
CVE-2026-52908
CVE-2026-52909
CVE-2026-52910
CVE-2026-52917
CVE-2026-52923
CVE-2026-52924
CVE-2026-52927
CVE-2026-52929
CVE-2026-52930
CVE-2026-52934
CVE-2026-52942
CVE-2026-52946
CVE-2026-52947
CVE-2026-52948
CVE-2026-52975
CVE-2026-52995
CVE-2026-53005
CVE-2026-53078
CVE-2026-53090
CVE-2026-53101
CVE-2026-53131
CVE-2026-53132
CVE-2026-53134
CVE-2026-53135
CVE-2026-53136
CVE-2026-53137
CVE-2026-53138
CVE-2026-53142
CVE-2026-53143
CVE-2026-53144
CVE-2026-53146
CVE-2026-53147
CVE-2026-53148
CVE-2026-53149
CVE-2026-53150
CVE-2026-53151
CVE-2026-53154
CVE-2026-53156
CVE-2026-53167
CVE-2026-53168
CVE-2026-53175
CVE-2026-53176
CVE-2026-53177
CVE-2026-53180
CVE-2026-53181
CVE-2026-53182
CVE-2026-53183
CVE-2026-53184
CVE-2026-53185
CVE-2026-53186
CVE-2026-53189
CVE-2026-53190
CVE-2026-53191
CVE-2026-53192
CVE-2026-53193
CVE-2026-53194
CVE-2026-53195
CVE-2026-53196
CVE-2026-53199
CVE-2026-53207
CVE-2026-53208
CVE-2026-53209
CVE-2026-53210
CVE-2026-53212
CVE-2026-53213
CVE-2026-53214
CVE-2026-53215
CVE-2026-53216
CVE-2026-53217
CVE-2026-53218
CVE-2026-53219
CVE-2026-53220
CVE-2026-53221
CVE-2026-53223
CVE-2026-53225
CVE-2026-53226
CVE-2026-53227
CVE-2026-53228
CVE-2026-53229
CVE-2026-53230
CVE-2026-53232
CVE-2026-53233
CVE-2026-53235
CVE-2026-53236
CVE-2026-53237
CVE-2026-53238
CVE-2026-53239
CVE-2026-53241
CVE-2026-53245
CVE-2026-53249
CVE-2026-53251
CVE-2026-53252
CVE-2026-53253
CVE-2026-53254
CVE-2026-53255
CVE-2026-53256
CVE-2026-53260
CVE-2026-53261
CVE-2026-53262
CVE-2026-53263
CVE-2026-53264
CVE-2026-53266
CVE-2026-53267
CVE-2026-53268
CVE-2026-53269
CVE-2026-53270
CVE-2026-53272
CVE-2026-53273
CVE-2026-53275
CVE-2026-53325
CVE-2026-53328
CVE-2026-53329
CVE-2026-53337
CVE-2026-53341
CVE-2026-53345
CVE-2026-53347
CVE-2026-53349
CVE-2026-53350
CVE-2026-53352
CVE-2026-53353
CVE-2026-53354
CVE-2026-53356
CVE-2026-53358
CVE-2026-53360
CVE-2026-53361
CVE-2026-53364
CVE-2026-53365
CVE-2026-53381
CVE-2026-53384
CVE-2026-53385
CVE-2026-53388
CVE-2026-53391
CVE-2026-53392
CVE-2026-53393
CVE-2026-53394
CVE-2026-53397
CVE-2026-53398
CVE-2026-53399
CVE-2026-53400
CVE-2026-53402
CVE-2026-53403
CVE-2026-63794
CVE-2026-63795
CVE-2026-63796
CVE-2026-63800
CVE-2026-63801
CVE-2026-63802
CVE-2026-63803
CVE-2026-63804
CVE-2026-63806
CVE-2026-63807
CVE-2026-63808
CVE-2026-63809
CVE-2026-63810
CVE-2026-63821
CVE-2026-63822
CVE-2026-63823
CVE-2026-63824
CVE-2026-63826
CVE-2026-63829
CVE-2026-63830
CVE-2026-63831
CVE-2026-63834
CVE-2026-63835
CVE-2026-63836
CVE-2026-63867
CVE-2026-63868
CVE-2026-63869
CVE-2026-63870
CVE-2026-63871
CVE-2026-63875
CVE-2026-63881
CVE-2026-63882
CVE-2026-63884
CVE-2026-63891
CVE-2026-63892
CVE-2026-63893
CVE-2026-63897
CVE-2026-63898
CVE-2026-63899
CVE-2026-63900
CVE-2026-63901
CVE-2026-63902
CVE-2026-63903
CVE-2026-63904
CVE-2026-63908
CVE-2026-63912
CVE-2026-63913
CVE-2026-63914
CVE-2026-63916
CVE-2026-63917
CVE-2026-63918
CVE-2026-63919
CVE-2026-63920
CVE-2026-63921
CVE-2026-63922
CVE-2026-63924
CVE-2026-63925
CVE-2026-63926
CVE-2026-63927
CVE-2026-63928
CVE-2026-63929
CVE-2026-63937
CVE-2026-63938
CVE-2026-63939
CVE-2026-63940
CVE-2026-63942
CVE-2026-63944
CVE-2026-63945
CVE-2026-63946
CVE-2026-63947
CVE-2026-63948
CVE-2026-63949
CVE-2026-63952
CVE-2026-63956
CVE-2026-63957
CVE-2026-63958
CVE-2026-63961
CVE-2026-63962
CVE-2026-63963
CVE-2026-63968
CVE-2026-63969
CVE-2026-63970
CVE-2026-63971
CVE-2026-63973
CVE-2026-63974
CVE-2026-63975
CVE-2026-63976
CVE-2026-63978
CVE-2026-63980
CVE-2026-63981
CVE-2026-63982
CVE-2026-63983
CVE-2026-63984
CVE-2026-63985
CVE-2026-63987
CVE-2026-63990
CVE-2026-63992
CVE-2026-63993
CVE-2026-63994
CVE-2026-63995
CVE-2026-63996
CVE-2026-63997
CVE-2026-64000
CVE-2026-64002
CVE-2026-64003
CVE-2026-64007
CVE-2026-64009
CVE-2026-64012
CVE-2026-64014
CVE-2026-64090
CVE-2026-64091
CVE-2026-64093
CVE-2026-64094
CVE-2026-64095
CVE-2026-64122
CVE-2026-64123
CVE-2026-64131
CVE-2026-64187
CVE-2026-64189
CVE-2026-64191
CVE-2026-64192
CVE-2026-64205
CVE-2026-64206
CVE-2026-64227
CVE-2026-64235
CVE-2026-64237
CVE-2026-64239
CVE-2026-64241
CVE-2026-64244
CVE-2026-64245
CVE-2026-64247
CVE-2026-64251
CVE-2026-64253
CVE-2026-64256
CVE-2026-64257
CVE-2026-64265
CVE-2026-64266
CVE-2026-64270
CVE-2026-64271
CVE-2026-64272
CVE-2026-64275
CVE-2026-64276
CVE-2026-64279
CVE-2026-64284
CVE-2026-64286
CVE-2026-64287
CVE-2026-64289
CVE-2026-64294
CVE-2026-64296
CVE-2026-64298
CVE-2026-64299
CVE-2026-64304
CVE-2026-64305
CVE-2026-64306
CVE-2026-64307
CVE-2026-64308
CVE-2026-64309
CVE-2026-64310
CVE-2026-64312
CVE-2026-64313
CVE-2026-64317
CVE-2026-64319
CVE-2026-64320
CVE-2026-64321
CVE-2026-64322
CVE-2026-64323
CVE-2026-64324
CVE-2026-64326
CVE-2026-64330
CVE-2026-64332
CVE-2026-64333
CVE-2026-64334
CVE-2026-64335
CVE-2026-64336
CVE-2026-64338
CVE-2026-64340
CVE-2026-64341
CVE-2026-64342
CVE-2026-64343
CVE-2026-64344
CVE-2026-64348
CVE-2026-64351
CVE-2026-64352
CVE-2026-64354
CVE-2026-64355
CVE-2026-64357
CVE-2026-64362
CVE-2026-64363
CVE-2026-64364
CVE-2026-64365
CVE-2026-64368
CVE-2026-64370
CVE-2026-64371
CVE-2026-64372
CVE-2026-64373
CVE-2026-64374
CVE-2026-64375
CVE-2026-64376
CVE-2026-64378
CVE-2026-64379
CVE-2026-64380
CVE-2026-64381
CVE-2026-64382
CVE-2026-64383
CVE-2026-64384
CVE-2026-64385
CVE-2026-64386
CVE-2026-64387
CVE-2026-64401
CVE-2026-64403
CVE-2026-64404
CVE-2026-64405
CVE-2026-64406
CVE-2026-64408
CVE-2026-64411
CVE-2026-64412
CVE-2026-64413
CVE-2026-64414
CVE-2026-64415
CVE-2026-64416
CVE-2026-64418
CVE-2026-64420
CVE-2026-64422
CVE-2026-64423
CVE-2026-64424
CVE-2026-64425
CVE-2026-64427
CVE-2026-64433
CVE-2026-64434
CVE-2026-64435
CVE-2026-64436
CVE-2026-64438
CVE-2026-64448
CVE-2026-64450
CVE-2026-64452
CVE-2026-64455
CVE-2026-64456
CVE-2026-64457
CVE-2026-64458
CVE-2026-64461
CVE-2026-64465
CVE-2026-64470
CVE-2026-64471
CVE-2026-64472
CVE-2026-64473
CVE-2026-64474
CVE-2026-64475
CVE-2026-64476
CVE-2026-64477
CVE-2026-64478
CVE-2026-64479
CVE-2026-64480
CVE-2026-64481
CVE-2026-64484
CVE-2026-64486
CVE-2026-64487
CVE-2026-64489
CVE-2026-64490
CVE-2026-64496
CVE-2026-64503
CVE-2026-64504
CVE-2026-64508
CVE-2026-64510
CVE-2026-64511
CVE-2026-64512
CVE-2026-64514
CVE-2026-64523
CVE-2026-64524
CVE-2026-64527
CVE-2026-64528
CVE-2026-64529
CVE-2026-64530
CVE-2026-64531
CVE-2026-64534
CVE-2026-64535
CVE-2026-64538
CVE-2026-64539
CVE-2026-64540
CVE-2026-64542
CVE-2026-64543
CVE-2026-64544
CVE-2026-64545
CVE-2026-64546
CVE-2026-64547
CVE-2026-64548
CVE-2026-64549
CVE-2026-64551
CVE-2026-64552
CVE-2026-64553
CVE-2026-64554
CVE-2026-64555
CVE-2026-64556
CVE-2026-64557
CVE-2026-64560
CVE-2026-64561
CVE-2026-64562
CVE-2026-64563
CVE-2026-64564
CVE-2026-64567
CVE-2026-64568
CVE-2026-64569
CVE-2026-64570
CVE-2026-64571
CVE-2026-64572
CVE-2026-64574
CVE-2026-64575
CVE-2026-64576
CVE-2026-64577
CVE-2026-64579
CVE-2026-64580
CVE-2026-64582
CVE-2026-64586
CVE-2026-64589
CVE-2026-64593
CVE-2026-64597
CVE-2026-64598
CVE-2026-64599
CVE-2026-64600
CVE-2026-64603
CVE-2026-64604
CVE-2026-68085
CVE-2026-68091
CVE-2026-68092
CVE-2026-68093
CVE-2026-68096
CVE-2026-68102
CVE-2026-68106
CVE-2026-68107
CVE-2026-68108
CVE-2026-68110
CVE-2026-68111
CVE-2026-68112
CVE-2026-68113
CVE-2026-68115
CVE-2026-68116
CVE-2026-68117
CVE-2026-68118
CVE-2026-68119
CVE-2026-68121
CVE-2026-68123
CVE-2026-68125
CVE-2026-68126
CVE-2026-68128
CVE-2026-68129
CVE-2026-68131
CVE-2026-68133
CVE-2026-68136
CVE-2026-68138
CVE-2026-68139
CVE-2026-68142
CVE-2026-68143
CVE-2026-68145
CVE-2026-68146
CVE-2026-68148
CVE-2026-68149
CVE-2026-68153
CVE-2026-68154
CVE-2026-68155
CVE-2026-68156
CVE-2026-68157
CVE-2026-68158
CVE-2026-68160
CVE-2026-68161
CVE-2026-68162
CVE-2026-68164
CVE-2026-68165
CVE-2026-68166
CVE-2026-68169
CVE-2026-68180
CVE-2026-68181
CVE-2026-68184
CVE-2026-68186
CVE-2026-68187
CVE-2026-68188
CVE-2026-68189
CVE-2026-68192
CVE-2026-68193
CVE-2026-68194
CVE-2026-68197
CVE-2026-68198
CVE-2026-68199
CVE-2026-68200
CVE-2026-68201
CVE-2026-68202
CVE-2026-68205
CVE-2026-68206
CVE-2026-68212
CVE-2026-68213
CVE-2026-68214
CVE-2026-68216
CVE-2026-68217
CVE-2026-68218
CVE-2026-68226
CVE-2026-68227
CVE-2026-68234
CVE-2026-68235
CVE-2026-68236
CVE-2026-68243
CVE-2026-68244
CVE-2026-68245
CVE-2026-68246
CVE-2026-68247
CVE-2026-68248
CVE-2026-68249
CVE-2026-68250
CVE-2026-68251
CVE-2026-68252
CVE-2026-68253
CVE-2026-68254
CVE-2026-68255
CVE-2026-68256
CVE-2026-68257
CVE-2026-68259
CVE-2026-68264
CVE-2026-68266
CVE-2026-68267
CVE-2026-68269
CVE-2026-68271
CVE-2026-68272
CVE-2026-68273
CVE-2026-68276
CVE-2026-68277
CVE-2026-68278
CVE-2026-68279
CVE-2026-68284
CVE-2026-68293
CVE-2026-68294
CVE-2026-68296
CVE-2026-68297
CVE-2026-68299
CVE-2026-68300
CVE-2026-68301
CVE-2026-68304
CVE-2026-68307
CVE-2026-68309
CVE-2026-68310
CVE-2026-68311
CVE-2026-68313
CVE-2026-68315
CVE-2026-68317
CVE-2026-68318
CVE-2026-68319
CVE-2026-68320
CVE-2026-68325
CVE-2026-68326
CVE-2026-68328
CVE-2026-68329
CVE-2026-68336
CVE-2026-68338
CVE-2026-68339
CVE-2026-68343
CVE-2026-68344
CVE-2026-68346
CVE-2026-68348
CVE-2026-68349
CVE-2026-68350
CVE-2026-68351
CVE-2026-68352
CVE-2026-68353
CVE-2026-68355
CVE-2026-68362
CVE-2026-68363
CVE-2026-68365
CVE-2026-68372
CVE-2026-68373
CVE-2026-68374
CVE-2026-68376
CVE-2026-68377
CVE-2026-68378
CVE-2026-68386
CVE-2026-68388
CVE-2026-68391
CVE-2026-68392
CVE-2026-68394
CVE-2026-68398
CVE-2026-68402
CVE-2026-68403
CVE-2026-68405
CVE-2026-68406
CVE-2026-68407
CVE-2026-68408
CVE-2026-68410
CVE-2026-68411
CVE-2026-68413
CVE-2026-68414
CVE-2026-68416
CVE-2026-68419
CVE-2026-68422
CVE-2026-68425
CVE-2026-68427
CVE-2026-68428
CVE-2026-68429
CVE-2026-68430
CVE-2026-68432
CVE-2026-68433
CVE-2026-68434
CVE-2026-68439
CVE-2026-68442
CVE-2026-68444
CVE-2026-68445
CVE-2026-68446
CVE-2026-68450
CVE-2026-68456
CVE-2026-68461
CVE-2026-68469
CVE-2026-68475
CVE-2026-68476
CVE-2026-68477
CVE-2026-68479
CVE-2026-68480
CVE-2026-72004
CVE-2026-72005
CVE-2026-72010
CVE-2026-72012
CVE-2026-72014
CVE-2026-72015
CVE-2026-72017
CVE-2026-72019
CVE-2026-72020
CVE-2026-72021
CVE-2026-72024
CVE-2026-72027
CVE-2026-72029
CVE-2026-72030
CVE-2026-72032
CVE-2026-72034
CVE-2026-72035
CVE-2026-72036
CVE-2026-72037
CVE-2026-72039
CVE-2026-72040
CVE-2026-72045
CVE-2026-72046
CVE-2026-72049
CVE-2026-72051
CVE-2026-72052
CVE-2026-72053
CVE-2026-72054
CVE-2026-72055
CVE-2026-72056
CVE-2026-72057
CVE-2026-72059
CVE-2026-72061
CVE-2026-72063
CVE-2026-72065
CVE-2026-72066
CVE-2026-72067
CVE-2026-72068
CVE-2026-72070
CVE-2026-72083
CVE-2026-72084
CVE-2026-72085
CVE-2026-72086
CVE-2026-72087
CVE-2026-72088
CVE-2026-72096
CVE-2026-72099
CVE-2026-72100
CVE-2026-72101
CVE-2026-72102
CVE-2026-72103
CVE-2026-72105
CVE-2026-72106
CVE-2026-72107
CVE-2026-72108
CVE-2026-72110
CVE-2026-72111
CVE-2026-72113
CVE-2026-72114
CVE-2026-72115
CVE-2026-72116
CVE-2026-72117
CVE-2026-72118
CVE-2026-72119
CVE-2026-72120
CVE-2026-72121
CVE-2026-72122
CVE-2026-72123
CVE-2026-72124
CVE-2026-72125
CVE-2026-72126
CVE-2026-72127
CVE-2026-72129
CVE-2026-72130
CVE-2026-72132
CVE-2026-72135
CVE-2026-72136
CVE-2026-72138
CVE-2026-72144
CVE-2026-72151
CVE-2026-72152
CVE-2026-72155
CVE-2026-72157
CVE-2026-72159
CVE-2026-72160
CVE-2026-72161
CVE-2026-72163
CVE-2026-72164
CVE-2026-72165
CVE-2026-72166
CVE-2026-72170
CVE-2026-72172
CVE-2026-72174
CVE-2026-72175
CVE-2026-72176
CVE-2026-72177
CVE-2026-72178
CVE-2026-72182
CVE-2026-72183
CVE-2026-72212
CVE-2026-72213
CVE-2026-72217
CVE-2026-72218
CVE-2026-72219
CVE-2026-72221
CVE-2026-72222
CVE-2026-72223
CVE-2026-72224
CVE-2026-72225
CVE-2026-72226
CVE-2026-72227
CVE-2026-72228
CVE-2026-72229
CVE-2026-72230
CVE-2026-72231
CVE-2026-72232
CVE-2026-72233
CVE-2026-72234
CVE-2026-72235
CVE-2026-72237
CVE-2026-72240
CVE-2026-72241
CVE-2026-72242
CVE-2026-72243
CVE-2026-72245
CVE-2026-72247
CVE-2026-72250
CVE-2026-72251
CVE-2026-72252
CVE-2026-72253
CVE-2026-72254
CVE-2026-72255
CVE-2026-72256
CVE-2026-72261
CVE-2026-72262
CVE-2026-72265
CVE-2026-72266
CVE-2026-72272
CVE-2026-72273
CVE-2026-72280
CVE-2026-72282
CVE-2026-72284
CVE-2026-72286
CVE-2026-72289
CVE-2026-72297
CVE-2026-72298
CVE-2026-72299
CVE-2026-72300
CVE-2026-72301
CVE-2026-72302
CVE-2026-72304
CVE-2026-72305
CVE-2026-72306
CVE-2026-72307
CVE-2026-72308
CVE-2026-72310
CVE-2026-72314
CVE-2026-72316
CVE-2026-72317
CVE-2026-72318
CVE-2026-72319
CVE-2026-72320
CVE-2026-72322
CVE-2026-72323
CVE-2026-72324
CVE-2026-72325
CVE-2026-72326
CVE-2026-72330
CVE-2026-72333
CVE-2026-72335
CVE-2026-72336
CVE-2026-72338
CVE-2026-72339
CVE-2026-72342
CVE-2026-72343
CVE-2026-72347
CVE-2026-72348
CVE-2026-72349
CVE-2026-72350
CVE-2026-72351
CVE-2026-72356
CVE-2026-72360
CVE-2026-72361
CVE-2026-72362
CVE-2026-72364
CVE-2026-72371
CVE-2026-72372
CVE-2026-72373
CVE-2026-72374
CVE-2026-72376
CVE-2026-72378
CVE-2026-72379
CVE-2026-72389
CVE-2026-72390
CVE-2026-72392
CVE-2026-72395
CVE-2026-72396
CVE-2026-72400
CVE-2026-72405
CVE-2026-72406
CVE-2026-72409
CVE-2026-72416
CVE-2026-72418
CVE-2026-72419
CVE-2026-72420
CVE-2026-72421
CVE-2026-72425
CVE-2026-72427
CVE-2026-72428
CVE-2026-72430
CVE-2026-72433
CVE-2026-72434
CVE-2026-72435
CVE-2026-72436
CVE-2026-72437
CVE-2026-72441
CVE-2026-72443
CVE-2026-72444
CVE-2026-72447
CVE-2026-72449
CVE-2026-72450
CVE-2026-72451
CVE-2026-72452
CVE-2026-72464
CVE-2026-72465
CVE-2026-72466
CVE-2026-72467
CVE-2026-72468
CVE-2026-72469
CVE-2026-72472
CVE-2026-72473
CVE-2026-72476
CVE-2026-72481
CVE-2026-72487
CVE-2026-72491
CVE-2026-72502
CVE-2026-74255
CVE-2026-74256
CVE-2026-74259
CVE-2026-74263
CVE-2026-74265
CVE-2026-74267
CVE-2026-74270
CVE-2026-74271
CVE-2026-74278
CVE-2026-74279
CVE-2026-74281
CVE-2026-74282
CVE-2026-74283
CVE-2026-74284
CVE-2026-74287
CVE-2026-74288
CVE-2026-74290
CVE-2026-74296
CVE-2026-74297
CVE-2026-74300
CVE-2026-74302
CVE-2026-74305
CVE-2026-74306
CVE-2026-74307
CVE-2026-74308
CVE-2026-74310
CVE-2026-74312
CVE-2026-74313
CVE-2026-74316
CVE-2026-74318
CVE-2026-74320
CVE-2026-74321
CVE-2026-74327
CVE-2026-74329
CVE-2026-74330
CVE-2026-74331
CVE-2026-74332
CVE-2026-74339
CVE-2026-74340
CVE-2026-74341
CVE-2026-74346
CVE-2026-74348
CVE-2026-74349
CVE-2026-74351
CVE-2026-74352
CVE-2026-74353
CVE-2026-74356
CVE-2026-74359
CVE-2026-74362
CVE-2026-74363
CVE-2026-74365
CVE-2026-74376
CVE-2026-74377
CVE-2026-74378
CVE-2026-74379
CVE-2026-74380
CVE-2026-74381
CVE-2026-74382
CVE-2026-74384
CVE-2026-74386
CVE-2026-74387
CVE-2026-74390
CVE-2026-74391
CVE-2026-74393
CVE-2026-74394
CVE-2026-74395
CVE-2026-74397
CVE-2026-74398
CVE-2026-74399
CVE-2026-74401
CVE-2026-74404
CVE-2026-74406
CVE-2026-74408
CVE-2026-74410
CVE-2026-74411
CVE-2026-74416
CVE-2026-74417
CVE-2026-74424
CVE-2026-74425
CVE-2026-74426
CVE-2026-74427
CVE-2026-74432
CVE-2026-74435
CVE-2026-74436
CVE-2026-74439
CVE-2026-74440
CVE-2026-74441
CVE-2026-74442
CVE-2026-74443
CVE-2026-74444
CVE-2026-74445
CVE-2026-74446
CVE-2026-74447
CVE-2026-74448
CVE-2026-74453
CVE-2026-74454
CVE-2026-74455
CVE-2026-74456
CVE-2026-74457
CVE-2026-74458
CVE-2026-74460
CVE-2026-74464
CVE-2026-74465
CVE-2026-74469
CVE-2026-74470
CVE-2026-74471
CVE-2026-74472
CVE-2026-74473
CVE-2026-74475
CVE-2026-74476
CVE-2026-74479
CVE-2026-74480
CVE-2026-74481
CVE-2026-74482
CVE-2026-74484
CVE-2026-74485
CVE-2026-74486
CVE-2026-74487
CVE-2026-74488
CVE-2026-74490
CVE-2026-74492
CVE-2026-74495
CVE-2026-74497
CVE-2026-74498
CVE-2026-74499
CVE-2026-74500
CVE-2026-74501
CVE-2026-74502
CVE-2026-74503
CVE-2026-74504
CVE-2026-74505
CVE-2026-74507
CVE-2026-74508
CVE-2026-74509
CVE-2026-74510
CVE-2026-74512
CVE-2026-74516
CVE-2026-74517
CVE-2026-74518
CVE-2026-74519
CVE-2026-74523
CVE-2026-74531
CVE-2026-74532
CVE-2026-74535
CVE-2026-74536
CVE-2026-74540
CVE-2026-74541
CVE-2026-74543
CVE-2026-74546
CVE-2026-74547
CVE-2026-74548
CVE-2026-74549
CVE-2026-74550
CVE-2026-74552
CVE-2026-74553
CVE-2026-74555
CVE-2026-74556
CVE-2026-74557
CVE-2026-74564
CVE-2026-74565
CVE-2026-74566
CVE-2026-74567
CVE-2026-74569
CVE-2026-74572
CVE-2026-74574
CVE-2026-74575
CVE-2026-74577
CVE-2026-74579
CVE-2026-74580
CVE-2026-74581
CVE-2026-74582
CVE-2026-74583
CVE-2026-74584
CVE-2026-74585
CVE-2026-74586
CVE-2026-74587
CVE-2026-74588
CVE-2026-74589
CVE-2026-74590
CVE-2026-74592
CVE-2026-74594
CVE-2026-74595
CVE-2026-74597
CVE-2026-74598
CVE-2026-74603
CVE-2026-74604
CVE-2026-74606
CVE-2026-74607
CVE-2026-74608
CVE-2026-74609
CVE-2026-74610
CVE-2026-74612
CVE-2026-74613
CVE-2026-74614
CVE-2026-74615
CVE-2026-74616
CVE-2026-74618
CVE-2026-74619
CVE-2026-74620
CVE-2026-74621
CVE-2026-74622
CVE-2026-74623
CVE-2026-74624
CVE-2026-74625
CVE-2026-74630
CVE-2026-74632
CVE-2026-74634
CVE-2026-74635
CVE-2026-74636
CVE-2026-74641
CVE-2026-74642
CVE-2026-74644
CVE-2026-74654
CVE-2026-74656
CVE-2026-74657
CVE-2026-74658
CVE-2026-74660
CVE-2026-74661
CVE-2026-74663
CVE-2026-74664
CVE-2026-74665
CVE-2026-74666
CVE-2026-74667
CVE-2026-74668
CVE-2026-74669
CVE-2026-74670
CVE-2026-74671
CVE-2026-74673
CVE-2026-74675
CVE-2026-74676
CVE-2026-74677
CVE-2026-74678
CVE-2026-74680
CVE-2026-74682
CVE-2026-74683
CVE-2026-74684
CVE-2026-74688
CVE-2026-74689
CVE-2026-74691
CVE-2026-74696
CVE-2026-74700
CVE-2026-74701
CVE-2026-74704
CVE-2026-74705
CVE-2026-74710
CVE-2026-74712
CVE-2026-74714
CVE-2026-74717
CVE-2026-74718
CVE-2026-74720
CVE-2026-74722
CVE-2026-74724
CVE-2026-74725
CVE-2026-74726
CVE-2026-74730
CVE-2026-74732
CVE-2026-80590




Description of changes:

[6.12.0-206.104.3.3]
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge)  [Orabug: 39974840]  {CVE-2026-80590}

[6.12.0-206.104.3.2]
- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi)  [Orabug: 39931938]  {CVE-2026-74517}
- tcp: challenge ACK for non-exact RST in SYN-RECEIVED (Yuxiang Yang)  [Orabug: 39931929]  {CVE-2026-68118}
- tcp: reorganize tcp_sock_write_txrx group for variables later (Chia-Yu Chang)  [Orabug: 39931929]
- tcp: fast path functions later (Ilpo Järvinen)  [Orabug: 39931929]
- tcp: Pass flags to __tcp_send_ack (Ilpo Järvinen)  [Orabug: 39931929]
- mm/damon/ops-common: putback folios on invalid migrate nid (liyouhong)  [Orabug: 39931902]  {CVE-2026-74644}
- KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (Paolo Bonzini)  [Orabug: 39931893]  {CVE-2026-74607}
- binfmt_misc: restore write access when removing an entry (Christian Brauner)  [Orabug: 39931874]  {CVE-2026-74487}
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner)  [Orabug: 39931874] {CVE-2026-74486}
- fs: don't block write during exec on pre-content watched files (Amir Goldstein)  [Orabug: 39931874]
- fsnotify: opt-in for permission events at file open time (Amir Goldstein)  [Orabug: 39931874]
- fsnotify, lsm: Decouple fsnotify from lsm (Song Liu)  [Orabug: 39931874]
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye)  [Orabug: 39931868]  {CVE-2026-74479}
- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)  [Orabug: 39931868]
- userfaultfd: prevent registration of special VMAs (Mike Rapoport (Microsoft))  [Orabug: 39931866]  {CVE-2026-68166}
- mm/khugepaged: guard is_zero_pfn() calls with pte_present() (Lance Yang)  [Orabug: 39931866]
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo)  [Orabug: 39931864]  {CVE-2026-68138}
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)  [Orabug: 39924423]
- Revert "octeontx2-vf: clear stale mailbox IRQ state before request_irq()" (Saeed Mirzamohammadi)  [Orabug: 39924423]
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)  [Orabug: 39924423]
- Revert "octeontx2-pf: clear stale mailbox IRQ state before request_irq()" (Saeed Mirzamohammadi)  [Orabug: 39924423]
- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms (Gao Xiang)
- m68k: Define NR_CPUS to 1 (Uwe Kleine-König)
- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (Pierre-Eric Pelloux-Prayer)
- drm/amdgpu: remove unused function parameter (Yunxiang Li)
- drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (Nathan Lucas)

[6.12.0-206.100.3.1]
- LTS version: v6.12.104 (Saeed Mirzamohammadi)
- bpf: tcp: fix double sock release on batch realloc (Xiang Mei (Microsoft))
- thunderbolt: Fix bandwidth group reservation indexing (Xu Rao) {CVE-2026-80736}
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas) {CVE-2026-74585}
- sctp: clear new_transport when removing a peer (Qing Ming) {CVE-2026-74586}
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) {CVE-2026-74587}
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee) {CVE-2026-74588}
- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) {CVE-2026-74589}
- fsverity: Fix silent truncation in bpf_get_fsverity_digest() (Eric Biggers)
- fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions (Eric Biggers) {CVE-2026-74590}
- ima: Instantiate file_truncate and path_truncate hooks (Mimi Zohar) {CVE-2026-74592}
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) {CVE-2026-74594}
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) {CVE-2026-74595}
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou) {CVE-2026-74597}
- ipv6: fix Route Information option length validation (Yuejie Shi) {CVE-2026-74598}
- ptp: ocp: Fix board ID over-read (Ahmad Byagowi) {CVE-2026-74603}
- Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (Rafael J. Wysocki) {CVE-2026-74604}
- eventfs: Fix use-after-free in eventfs_remove_rec() (Shuangpeng Bai) {CVE-2026-74606}
- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (Sean Christopherson) {CVE-2026-80726}
- smb: client: Fix use-after-free in cifs_try_adding_channels() (Shuangpeng Bai) {CVE-2026-74608}
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang) {CVE-2026-74609}
- tls: don't leave a full plaintext sk_msg ring unpushed (chanyoung) {CVE-2026-74610}
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) {CVE-2026-74580}
- veth: fix skb length accounting after XDP frag adjustment (Sun Jian) {CVE-2026-74612}
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) {CVE-2026-74613}
- vsock/virtio: read virtqueues under worker locks (Weiming Shi) {CVE-2026-74614}
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) {CVE-2026-74615}
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) {CVE-2026-74616}
- Revert "drm/amdgpu: fix aperture mapping leak" (Asad Kamal) {CVE-2026-80728}
- binfmt_misc: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74618}
- ovl: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74619}
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) {CVE-2026-74620}
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) {CVE-2026-74621}
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) {CVE-2026-74622}
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) {CVE-2026-74623}
- netfilter: nf_conntrack: defer invalid log until after unlock (Zihan Xi) {CVE-2026-74624}
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) {CVE-2026-74625}
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) {CVE-2026-74630}
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li) {CVE-2026-74631}
- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes (ARM))
- ring-buffer: Prevent subbuf order change when resizing is disabled (Vincent Donnefort) {CVE-2026-74634}
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) {CVE-2026-74635}
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) {CVE-2026-74636}
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) {CVE-2026-74641}
- ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (Takashi Iwai) {CVE-2026-74642}
- ring-buffer: Fix crash passing ERR_PTR to kthread_stop() (Hui Su) {CVE-2026-80730}
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)
- misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (Junrui Luo) {CVE-2026-74646}
- misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta) {CVE-2026-74647}
- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) {CVE-2026-74648}
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) {CVE-2026-74649}
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) {CVE-2026-74650}
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) {CVE-2026-74651}
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) {CVE-2026-74654}
- serial: qcom-geni: fix TX DMA buffer flush (Jan Sebastian Götte) {CVE-2026-74655}
- nvmem: layouts: Add fixed-layout driver (Mathieu Dubois-Briand)
- mei: pull kvfree out of spinlock (Alexander Usyskin)
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) {CVE-2026-74656}
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) {CVE-2026-74657}
- selftests/bpf: Adapt sockmap update error handling (Michal Luczaj)
- selftests/bpf: Ensure UDP sockets are bound (Michal Luczaj)
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- kunit/fortify: Add back "volatile" for sizeof() constants (Kees Cook)
- kunit/fortify: Replace "volatile" with OPTIMIZER_HIDE_VAR() (Kees Cook)
- futex: Prevent robust futex exit race some more (Keno Fischer) {CVE-2026-74658}
- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Ashish Kalra)
- crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length (Michael Roth)
- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Ashish Kalra)
- crypto: ccp - Add new SEV/SNP platform shutdown API (Ashish Kalra)
- dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk (Harshal Dev)
- block: Reorder the request allocation code in blk_mq_submit_bio() (Bart Van Assche)
- KVM: s390: pci: Fix aisb calculation (Matthew Rosato)
- KVM: s390: pci: Fix resource leak on IRQ registration failure (Farhan Ali)
- KVM: s390: pci: Fix missing error codes and memory unaccounting (Farhan Ali)
- KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (Farhan Ali) {CVE-2026-74514}
- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee) {CVE-2026-74659}
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) {CVE-2026-74660}
- mac802154: fix netdev use-after-free in beacon worker (Zihan Xi) {CVE-2026-74661}
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang) {CVE-2026-80731}
- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)
- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) {CVE-2026-74663}
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) {CVE-2026-74664}
- net: fix skb length accounting after generic XDP frag adjustment (Sun Jian) {CVE-2026-74665}
- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) {CVE-2026-74666}
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) {CVE-2026-74667}
- packet: use consistent hard_header_len in TX_RING send path (Qihang Tang) {CVE-2026-74668}
- packet: use consistent hard_header_len in non-ring send paths (Qihang Tang) {CVE-2026-74582}
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) {CVE-2026-74669}
- ipvs: properly update the overload flag on dest edit (Julian Anastasov)
- ipvs: add totalconns for dest (Julian Anastasov)
- ipvs: stop estimator after disabled calc phase (Zhiling Zou) {CVE-2026-74670}
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) {CVE-2026-74671}
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) {CVE-2026-74673}
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) {CVE-2026-74675}
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) {CVE-2026-74676}
- net: usb: ipheth: fix carrier_work UAF on disconnect (Doruk Tan Ozturk) {CVE-2026-74677}
- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (Yi Cong) {CVE-2026-74678}
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) {CVE-2026-74679}
- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)
- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) {CVE-2026-74680}
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) {CVE-2026-74682}
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) {CVE-2026-74683}
- swapfile: call cond_resched() before locking si->lock (Guillaume Morin)
- mtd: spinand: repeat reading in regular mode if continuous reading fails (Mikhail Kshevetskiy)
- mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (Mikhail Kshevetskiy)
- mtd: spinand: fix direct mapping creation sizes (Mikhail Kshevetskiy)
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)
- net: fec: do not release NULL pages when RX buffer allocation fails (Mehmet Fide)
- hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (Guenter Roeck)
- hwmon: (ltc4282) Clamp negative current limits (Guenter Roeck) {CVE-2026-74685}
- hwmon: (ltc4282) Avoid overflow in maximum power calculation (Guenter Roeck)
- hwmon: (ads7828) Fix external VREF regulator handling (Qingshuang Fu)
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)
- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)
- sctp: clear control chunk transport if it is being removed (Xin Long) {CVE-2026-74688}
- net/atm: fix slab-out-of-bounds read in vcc_setsockopt() (Eric Dumazet) {CVE-2026-74689}
- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu) {CVE-2026-80732}
- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan) {CVE-2026-74691}
- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond) {CVE-2026-74692}
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) {CVE-2026-80733}
- net: prestera: validate firmware header length (Pengpeng Hou) {CVE-2026-74693}
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin) {CVE-2026-74694}
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) {CVE-2026-74696}
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)
- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)
- bnxt_en: Refresh VNIC default ring on queue restart if needed (Shravya KN)
- bnxt_en: Determine and store default RX ring in vnic structure (Shravya KN)
- bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() (Shravya KN)
- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)
- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (Guenter Roeck)
- hwmon: (nzxt-smart2) Check return value of init_device() in probe (Qingshuang Fu)
- net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (Jamal Hadi Salim) {CVE-2026-74700}
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Høiland-Jørgensen) {CVE-2026-74704}
- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo) {CVE-2026-74705}
- xsk: require at least 16 bytes of TX metadata (Stanislav Fomichev) {CVE-2026-74710}
- tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() (Nathan Gao)
- vdpa/mlx5: Fix buffer length in create_direct_keys() (Christian Borntraeger) {CVE-2026-74712}
- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)
- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (Jose Fernandez (Anthropic))
- bpf: tcp: Avoid socket skips and repeats during iteration (Jordan Rife)
- bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items (Jordan Rife)
- bpf: tcp: Get rid of st_bucket_done (Jordan Rife)
- bpf: tcp: Make sure iter->batch always contains a full bucket snapshot (Jordan Rife)
- bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch (Jordan Rife)
- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) {CVE-2026-74717}
- devlink: fix net namespace reference leak in reload (Or Har-Toov) {CVE-2026-74718}
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) {CVE-2026-74583}
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi) {CVE-2026-74719}
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) {CVE-2026-74720}
- btrfs: fix memory leak in btrfs_do_encoded_write() (Dmitry Antipov) {CVE-2026-74722}
- watchdog: bd96801_wdt: Fix timeout for enabled WDG (Matti Vaittinen)
- ipvs: return the csum validation for forward hook (Julian Anastasov)
- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (Julian Anastasov) {CVE-2026-74724}
- netfilter: ipset: switch ext_size to atomic64_t (Jozsef Kadlecsik)
- pds_core: cancel pending PCI reset work on AER recovery (Nikhil P. Rao)
- pds_core: keep the health thread stopped during reset (Nikhil P. Rao)
- net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (Shay Drory) {CVE-2026-80739}
- enic: fix tx_hang_reset use-after-free on device removal (Satish Kharat) {CVE-2026-74725}
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))
- Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" (Fan Ye)
- net: hns3: fix speed configuration residue after driver reload (Jijie Shao)
- drm/bridge: ps8640: propagate AUX transfer register errors (Pengpeng Hou)
- ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt (Rosen Penev)
- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)
- arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer (Daniel Drake)
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) {CVE-2026-74730}
- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger) {CVE-2026-80708}
- drm/amd/display: Check for tg ops in dce110_set_avmute (Ray Wu) {CVE-2026-74732}
- drm/amd/display: Add AV mute wait frames to dce110_set_avmute (Ray Wu)
- selftests/bpf: Fail unbound UDP on sockmap update (Michal Luczaj)
- mount: honour SB_NOUSER in the new mount API (Al Viro)
- LTS version: v6.12.103 (Saeed Mirzamohammadi)
- drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (Thomas Zimmermann)
- drm/fb-helper: Fix a locking bug in an error path (Bart Van Assche)
- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path (Andrei Kuchynski)
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp)
- can: use skb hash instead of private variable in headroom (Oliver Hartkopp)
- rxrpc: Fix irq-disabled in local_bh_enable() (David Howells) {CVE-2025-38525}
- rxrpc: Manage RTT per-call rather than per-peer (David Howells)
- rxrpc: Fix the calculation and use of RTO (David Howells)
- rxrpc: Adjust the rxrpc_rtt_rx tracepoint (David Howells)
- rxrpc: Generate rtt_min (David Howells)
- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Zongyao Bai) {CVE-2026-68264}
- drm/xe: Stub out new pagefault layer (Matthew Brost)
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) {CVE-2026-68253}
- drm/i915/hdcp: Skip inactive MST connectors when building stream list (Suraj Kandpal)
- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)
- drm/i915/hdcp: Move to using intel_display in intel_hdcp (Suraj Kandpal)
- drm/xe: Hold a dma-buf reference for imported BOs (Nitin Gote) {CVE-2026-68266}
- drm/xe: Rename ___xe_bo_create_locked() (Thomas Hellström)
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) {CVE-2026-68254}
- drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (Ville Syrjälä)
- drm/xe: Wait on external BO kernel fences in exec IOCTL (Matthew Brost) {CVE-2026-74440}
- drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] (Thomas Hellström)
- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)
- drm/fb-helper: Allocate and release fb_info in single place (Thomas Zimmermann)
- drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (Asad Kamal) {CVE-2026-68276}
- drm/amdgpu: give each kernel job a unique id (Pierre-Eric Pelloux-Prayer)
- drm/sched: Store the drm client_id in drm_sched_fence (Pierre-Eric Pelloux-Prayer)
- drm/amdgpu: Fix context pstate override handling (Tvrtko Ursulin) {CVE-2026-68273}
- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions (Timur Kristóf)
- mm/kmemleak: fix checksum computation for per-cpu objects (Breno Leitao)
- kmemleak: iommu/iova: fix transient kmemleak false positive (Catalin Marinas)
- mptcp: pm: userspace: fix use-after-free in get_local_id (Geliang Tang) {CVE-2026-68169}
- mptcp: pm: use addr entry for get_local_id (Geliang Tang)
- mptcp: add mptcp_userspace_pm_lookup_addr helper (Geliang Tang)
- mptcp: pm: avoid code duplication to lookup endp (Geliang Tang)
- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (Kai Vehmanen)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) {CVE-2026-68198}
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) {CVE-2026-64586}
- media: uapi: rkisp: Correct name version enum (Niklas Söderlund)
- media: chips-media: wave5: Support CBP profile (Jackson Lee)
- media: imx219: Fix maximum frame length in lines (Sakari Ailus)
- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)
- usb: typec: ucsi: Fix race condition and ordering in port unregistration (Andrei Kuchynski) {CVE-2026-74441}
- usb: typec: ucsi: split connector lock classes (Sergey Senozhatsky)
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) {CVE-2026-68367}
- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao) {CVE-2026-74468}
- lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() (Harry Yoo (Oracle))
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes (Kiryl Shutsemau (Meta))
- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() (Kiryl Shutsemau (Meta))
- drm/xe/rtp: Ensure locking/ref counting for OA whitelists (Ashutosh Dixit)
- drm/xe/oa: (De-)whitelist OA registers on OA stream open/release (Ashutosh Dixit)
- drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt (Ashutosh Dixit)
- drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs (Ashutosh Dixit)
- drm/xe/rtp: Save OA nonpriv registers to register save/restore lists (Ashutosh Dixit)
- drm/xe/rtp: Generalize whitelist_apply_to_hwe (Ashutosh Dixit)
- drm/xe/rtp: Keep track of non-OA nonpriv slots (Ashutosh Dixit)
- drm/xe/rtp: Maintain OA whitelists separately (Ashutosh Dixit)
- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (Ashutosh Dixit) {CVE-2026-68267}
- drm/xe: Apply whitelist to engine save-restore (Lucas De Marchi)
- drm/xe: Introduce xe_gt_dbg_printer() (Michal Wajdeczko)
- drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (Ashutosh Dixit)
- Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (Pauli Virtanen)
- of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails (Wandun Chen) {CVE-2026-74352}
- ata: ahci: Make ahci_ignore_port() handle empty mask_port_map (Niklas Cassel)
- ata: libahci_platform: Do not set mask_port_map when not needed (Damien Le Moal)
- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An) {CVE-2026-64427}
- spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (Jun Guo)
- drm/vmwgfx: validate external BO copy bounds for both stride paths (Zack Rusin) {CVE-2026-80700}
- drm/vmwgfx: use check_add_overflow for shader size+offset bound (Zack Rusin)
- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (Zack Rusin) {CVE-2026-74442}
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) {CVE-2026-74443}
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) {CVE-2026-74444}
- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (Zack Rusin)
- drm/vmwgfx: reject DX_BIND_QUERY without a DX context (Zack Rusin) {CVE-2026-74445}
- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (Zack Rusin) {CVE-2026-80702}
- drm/amdkfd: hold event_mutex while checkpointing CRIU events (William Palacek) {CVE-2026-74446}
- drm/amdkfd: Handle invalid event type in CRIU event restore (David Francis)
- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (William Palacek) {CVE-2026-74447}
- drm/amdkfd: fix QID bit leak in pqm_create_queue() (Vladimir Marioukhine) {CVE-2026-74448}
- drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (Gang Ba) {CVE-2026-80703}
- drm/amd/display: use proper context for logging (Jiri Slaby (SUSE))
- drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (Ray Wu)
- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)
- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)
- drm/mediatek: ovl_adaptor: balance component registrations (Myeonghun Pak)
- drm/panthor: validate firmware interface structure sizes (Osama Abdelkader) {CVE-2026-74451}
- drm/panthor: reject firmware sections with oversized data (Osama Abdelkader) {CVE-2026-74452}
- drm/vc4: Zero the tile state data array before each BIN job (Maíra Canal) {CVE-2026-74453}
- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (Jose Maria Casanova Crespo) {CVE-2026-74454}
- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (Alexander Kaplan)
- can: ctucanfd: mark error-active controller status valid (Avi Weiss)
- can: ctucanfd: handle bus error interrupts (Avi Weiss)
- can: ctucanfd: unmap BAR0 using base address (Avi Weiss)
- can: ctucanfd: use self-test mode for PRESUME_ACK (Avi Weiss)
- can: ctucanfd: add missing MODULE_DEVICE_TABLE() (Pengpeng Hou)
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) {CVE-2026-74455}
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) {CVE-2026-74456}
- can: peak_usb: add bounds check for USB channel index (James Gao) {CVE-2026-74457}
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) {CVE-2026-80706}
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) {CVE-2026-74458}
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)
- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (Tetsuo Handa)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) {CVE-2026-80707}
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)
- can: ems_usb: validate CPC message lengths (Pengpeng Hou) {CVE-2026-74460}
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) {CVE-2026-74461}
- i2c: imx: Fix slave registration race and error handling (Liem) {CVE-2026-80678}
- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller) {CVE-2026-74463}
- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)
- ice: wait for reset completion in ice_resume() (Aaron Ma)
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) {CVE-2026-74464}
- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) {CVE-2026-74465}
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)
- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler) {CVE-2026-68451}
- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler) {CVE-2026-68452}
- s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs (Harald Freudenberger) {CVE-2026-80709}
- s390/dasd: Fix undersized format-check buffer (Stefan Haberland) {CVE-2026-80710}
- s390/dasd: Fix potential NULL pointer dereference (Jan Höppner) {CVE-2026-80679}
- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally) {CVE-2026-74467}
- s390/pci: Fix s390_pci_mmio_write syscall error return without MIO (Niklas Schnelle)
- power: supply: max17040: handle missing status supplier (Jianing Li) {CVE-2026-80711}
- power: supply: bq25890: fix the -10 C NTC lookup entry (Xu Rao)
- cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized (Zhongqiu Han)
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (bui duc phuc)
- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak) {CVE-2026-80680}
- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (Vincent Jardin)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) {CVE-2026-74469}
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) {CVE-2026-74470}
- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)
- selftests/mm: fix potential wild pointer access of getline due to missing init (Chris Gellermann)
- spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (Vijaya Krishna Nivarthi)
- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))
- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() (Ming Lei) {CVE-2026-74472}
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74473}
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74475}
- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) {CVE-2026-80681}
- veth: convert frag_list skbs before running XDP (Matt Fleming) {CVE-2026-74476}
- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito) {CVE-2026-74478}
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) {CVE-2026-74581}
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) {CVE-2026-74480}
- mm: memcg: initialize *locked in memcg1_oom_prepare() stub (Breno Leitao)
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) {CVE-2026-74481}
- binfmt_misc: don't let an 'F' entry pin its own instance (Christian Brauner) {CVE-2026-74484}
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) {CVE-2026-74485}
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li) {CVE-2026-74488}
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) {CVE-2026-74490}
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) {CVE-2026-74492}
- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo) {CVE-2026-74493}
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) {CVE-2026-80714}
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) {CVE-2026-74495}
- e1000: fix memory leak in e1000_probe() (Dawei Feng)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) {CVE-2026-74497}
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) {CVE-2026-74498}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) {CVE-2026-74499}
- ALSA: usb-audio: fix stack info leak in RME Digiface status (Baul Lee) {CVE-2026-74500}
- ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (Baul Lee) {CVE-2026-74501}
- ata: libata-sata: fix ata_scsi_lpm_supported() iteration (Niklas Cassel)
- ata: libata-eh: Increase STANDBY IMMEDIATE timeout (Matt Vollrath)
- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)
- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)
- ALSA: ump: fix double free of out_cvts on rawmidi error (Baul Lee) {CVE-2026-74502}
- ALSA: seq: Fix division by zero in initialize_timer() (Norbert Szetei) {CVE-2026-74504}
- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) {CVE-2026-80716}
- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)
- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) {CVE-2026-74505}
- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)
- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) {CVE-2026-74507}
- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) {CVE-2026-74508}
- Bluetooth: hci_sync: Fix advertising data UAFs (Chengfeng Ye) {CVE-2026-74509}
- Bluetooth: mgmt: fix UAF in pair command cancellation (Zihan Xi) {CVE-2026-74510}
- Bluetooth: mgmt: fix pending command UAF in EIR updates (Zihan Xi) {CVE-2026-74511}
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (Greg Kroah-Hartman)
- Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (Greg Kroah-Hartman)
- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) {CVE-2026-74512}
- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)
- sctp: validate Adaptation Indication parameter length (Charles Vosburgh) {CVE-2026-80717}
- KVM: s390: pci: Validate AIBV and AISB before pinning guest pages (Farhan Ali)
- KVM: s390: pci: Fix NULL dereference on AIBV allocation failure (Farhan Ali) {CVE-2026-80684}
- KVM: s390: pci: Reject adapter interrupt forwarding if already enabled (Farhan Ali) {CVE-2026-74515}
- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (Sean Christopherson) {CVE-2026-74516}
- tracing/probes: Reject $arg0 in meta argument expansion (Raushan Patel)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) {CVE-2026-74518}
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan) {CVE-2026-80718}
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes (Kiryl Shutsemau (Meta))
- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE (Kefeng Wang) {CVE-2026-80686}
- fortify: Disable -Wstringop-overread in tests (Nathan Chancellor)
- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)
- erofs: cap LZMA stream pool size (Michael Bommarito)
- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) {CVE-2026-74519}
- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO (Benjamin Boortz)
- rhashtable: clear stale iter->p on table restart (Cen Zhang (Microsoft))
- ksmbd: fix use-after-free in __close_file_table_ids() (Namjae Jeon) {CVE-2026-74522}
- ksmbd: return success for deferred final close (Namjae Jeon)
- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) {CVE-2026-74523}
- net: libwx: fix FDIR ATR queue mismatch for software VLAN packets (Jiawen Wu)
- net: dsa: mt7530: error out on failed reads in MT7531 PHY polling (Daniel Golle)
- net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend (Daniel Golle)
- riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove (Karl Mehltretter) {CVE-2026-74524}
- accel/qaic: use sizeof(*trans_hdr) for transaction length check (Muhammad Bilal)
- tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions (Masami Hiramatsu (Google))
- tracing/mmiotrace: Remove reference to unused per CPU data pointer (Steven Rostedt)
- tracing: Remove TRACE_EVENT_FL_FILTERED logic (Zheng Yejian)
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))
- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)
- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)
- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao) {CVE-2026-74525}
- scsi: target: Clear cmd_cnt when initial counter enrollment fails (Leon Romanovsky)
- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)
- scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE (TanZheng) {CVE-2026-80691}
- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)
- Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync (Pauli Virtanen)
- Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (Pauli Virtanen) {CVE-2026-74531}
- Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (Pauli Virtanen)
- Bluetooth: btintel: Validate length before parsing diagnostics TLV (Zijun Hu) {CVE-2026-74532}
- Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (Pauli Virtanen) {CVE-2026-74535}
- Bluetooth: ISO: fix leaking sk after socket release (Pauli Virtanen) {CVE-2026-74536}
- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (Pauli Virtanen)
- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (Pauli Virtanen)
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) {CVE-2026-74540}
- Bluetooth: ISO: clear iso_data always when detaching conn from hcon (Pauli Virtanen) {CVE-2026-74541}
- idpf: Fix mailbox IRQ name leak on request failure (Yuho Choi)
- idpf: adjust TxQ ring count minimum (Joshua Hay)
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)
- net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller (Chenguang Zhao) {CVE-2026-80694}
- net: ethernet: mtk_eth_soc: add consts for irq index (Frank Wunderlich)
- net: ethernet: mtk_eth_soc: support named IRQs (Frank Wunderlich)
- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li) {CVE-2026-80722}
- net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() (Eric Dumazet) {CVE-2026-74543}
- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)
- rtase: fix double free of multi-frag skb on DMA map failure (Yun Lu) {CVE-2026-74545}
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) {CVE-2026-74546}
- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) {CVE-2026-74547}
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)
- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) {CVE-2026-74548}
- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) {CVE-2026-74549}
- net: do not send ICMP/NDISC Redirects when peer allocation fails (Eric Dumazet) {CVE-2026-74550}
- hwmon: (nzxt-smart2) DMA-align output buffer (Guenter Roeck) {CVE-2026-74551}
- hwmon: (lm90) Only report alarms if driver is ready (Guenter Roeck) {CVE-2026-74552}
- hwmon: (sht3x) Fix unaligned accesses (Guenter Roeck) {CVE-2026-80695}
- hwmon: (ltc4282) Fix reading the minimum alarm voltage (Guenter Roeck) {CVE-2026-80696}
- hwmon: (ina2xx) Fix various overflow issues (Guenter Roeck)
- hwmon: (ina2xx) Shift INA234 shunt and current registers (Jonas Rebmann)
- hwmon: (ina2xx) Add support for INA234 (Ian Ray)
- hwmon: (ina2xx) Make it easier to add more devices (Ian Ray)
- hwmon: (ina226) Add support for SY24655 (Wenliang Yan)
- hwmon: (ina2xx) Add support for INA260 (Guenter Roeck)
- hwmon: (ina2xx) Add support for has_alerts configuration flag (Guenter Roeck)
- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (Guenter Roeck) {CVE-2026-74553}
- spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (Srikanth Boyapally)
- spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (Jun Guo)
- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)
- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (Xingui Yang) {CVE-2026-74555}
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An) {CVE-2026-74556}
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An) {CVE-2026-74557}
- pinctrl-amd: Don't clear S4 wake bits at probe (Mario Limonciello)
- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))
- ipvs: do not mangle ICMP replies for non-first fragments (Julian Anastasov)
- ipvs: fix places with wrong packet offsets (Julian Anastasov)
- ipvs: fix the checksum validations (Julian Anastasov)
- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) {CVE-2026-74564}
- netfilter: nf_tables: make nft_object rhltable per table (Pablo Neira Ayuso) {CVE-2026-74565}
- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) {CVE-2026-74566}
- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) {CVE-2026-74567}
- KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type (Fabrice Derepas)
- Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation (Sebastian Andrzej Siewior)
- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) {CVE-2026-74569}
- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)
- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)
- btrfs: zoned: fix deadlock between metadata writeback and transaction commit (Johannes Thumshirn) {CVE-2026-74572}
- btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag (Qu Wenruo)
- of: reserved_mem: prevent OOB when too many dynamic regions are defined (Sang-Heon Jeon) {CVE-2026-80723}
- of: reserved_mem: Add code to dynamically allocate reserved_mem array (Oreoluwa Babatunde)
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() (Radhey Shyam Pandey)
- ahci: Introduce ahci_ignore_port() helper (Damien Le Moal)
- ata: libahci_platform: support non-consecutive port numbers (Josua Mayer)
- ata: sata_mv: accept 1 or 2 resources in platform probe (Rosen Penev)
- gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (Abdun Nihaal)
- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (Yuho Choi) {CVE-2026-74574}
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)
- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (Konrad Dybcio)
- pinctrl: qcom: Unconditionally mark gpio as wakeup enable (Sneh Mankad)
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) {CVE-2026-74575}
- netconsole: avoid OOB reads, msg is not nul-terminated (Jakub Kicinski) {CVE-2026-43197}
- bpf: Reset register bounds before narrowing retval range in check_mem_access() (Tristan Madani) {CVE-2026-72111}
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)
- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) {CVE-2026-74577}
- netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Lorenzo Bianconi)
- um: Preserve errno within signal handler (Tiwei Bie)
- kunit: tool: skip stty when stdin is not a tty (Shuvam Pandey)
- kunit: tool: Terminate kernel under test on SIGINT (David Gow)
- um: Set parent death signal for userspace process (Benjamin Berg)
- um: Set parent-death signal for write_sigio thread/process (Tiwei Bie)
- um: Set parent-death signal for ubd io thread/process (Tiwei Bie)
- um: Use os_set_pdeathsig helper in winch thread/process (Tiwei Bie)
- um: Set parent death signal for winch thread/process (Benjamin Berg)
- um: Add os_set_pdeathsig helper function (Tiwei Bie)
- LTS version: v6.12.102 (Saeed Mirzamohammadi)
- LTS version: v6.12.101 (Saeed Mirzamohammadi)
- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (Nikunj A Dadhania) {CVE-2026-68093}
- afs: Fix uninit var in afs_alloc_anon_key() (David Howells)
- Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() (Pavitra Jha) {CVE-2026-53364}
- Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections (Luiz Augusto von Dentz)
- Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source (Luiz Augusto von Dentz)
- Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK (Luiz Augusto von Dentz)
- afs: handle CB.InitCallBackState3 requests without a server record (Nan Li) {CVE-2026-74425}
- afs: Fix delayed allocation of a cell's anonymous key (David Howells) {CVE-2025-68299}
- dpll: fix clock quality level reporting (Ivan Vecera)
- afs: Set vllist to NULL if addr parsing fails (Edward Adam Davis)
- net: ethernet: Remove accidental duplication in Kconfig file (Lukas Bulwahn)
- wifi: nl80211: fix nl80211_start_radar_detection return value (Nicolas Escande)
- rxrpc: Fix locking issues with the peer record hash (David Howells)
- rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link (David Howells)
- gpu: Fix uninitialized buddy for built-in drivers (Koen Koning)
- net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query (Gal Pressman)
- usb: musb: omap2430: Do not put borrowed of_node in probe (Guangshuo Li) {CVE-2026-68371}
- usb: musb: omap2430: clean up probe error handling (Johan Hovold)
- USB: gadget: fsl-udc: fix dev_printk() device (Johan Hovold)
- USB: gadget: Use str_enable_disable-like helpers (Krzysztof Kozlowski)
- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)
- net: macb: drop in-flight Tx SKBs on close (Théo Lebrun) {CVE-2026-72017}
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) {CVE-2026-72015}
- ata: libata-core: Reject an invalid concurrent positioning ranges count (Bryam Vargas) {CVE-2026-72030}
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) {CVE-2026-72023}
- net/mlx5: HWS, fix matcher leak on resize target setup failure (Dawei Feng) {CVE-2026-72032}
- ipmi: fix refcount leak in i_ipmi_request() (Wentao Liang) {CVE-2026-72040}
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) {CVE-2026-72045}
- gpio: mt7621: avoid corruption of shared interrupt trigger state (Sergio Paracuellos) {CVE-2026-72062}
- gve: fix header buffer corruption with header-split and HW-GRO (Ankit Garg) {CVE-2026-72046}
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72051}
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) {CVE-2026-72065}
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner) {CVE-2026-72069}
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) {CVE-2026-72070}
- dm: avoid leaking the caller's thread keyring via the table device file (Ingo Blechschmidt) {CVE-2026-72103}
- cred: add scoped_with_kernel_creds() (Christian Brauner)
- cred: add kernel_cred() helper (Christian Brauner)
- cleanup: fix scoped_class() (Christian Brauner)
- cleanup: add a scoped version of CLASS() (Christian Brauner)
- dm-integrity: fix leaking uninitialized kernel memory (Mikulas Patocka) {CVE-2026-72101}
- block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Connor Williamson)
- block: add helper add_disk_final() (Ming Lei)
- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)
- nvmet-auth: reject short AUTH_RECEIVE buffers (Michael Bommarito) {CVE-2026-72130}
- nvmet: Introduce nvmet_req_transfer_len() (Damien Le Moal)
- tcp: Decrement tcp_md5_needed static branch (Dmitry Safonov)
- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Michael Bommarito) {CVE-2026-72139}
- xfrm: nat_keepalive: avoid double free on send error (Qianyu Luo) {CVE-2026-72137}
- xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] (Sebastian Andrzej Siewior)
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)
- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)
- dmaengine: dw-edma-pcie: Reject devices without driver data (Koichiro Den) {CVE-2026-72147}
- dmaengine: dw-edma: Fix confusing cleanup.h syntax (Krzysztof Kozlowski)
- dma: dw-edma: Fix build warning in dw_edma_pcie_probe() (Abinash Singh)
- mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization (Muchun Song)
- mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c (David Hildenbrand (Arm))
- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs) {CVE-2026-72168}
- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages (Muchun Song)
- landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path (Bryam Vargas) {CVE-2026-72183}
- landlock: Prepare to use credential instead of domain for fowner (Mickaël Salaün)
- mm/sparse-vmemmap: fix vmemmap accounting underflow (Muchun Song)
- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch (Deepanshu Kartikey) {CVE-2026-72213}
- remoteproc: xlnx: Check remote core state (Tanmay Shah)
- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow (Chuck Lever)
- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists (Chuck Lever)
- sunrpc: allocate a separate bvec array for socket sends (Jeff Layton)
- NFSD: pass nfsd_file to nfsd_iter_read() (Mike Snitzer)
- gpu/buddy: bail out of try_harder when alignment cannot be honoured (Arunpravin Paneer Selvam) {CVE-2026-72244}
- gpu: Move DRM buddy allocator one level up (part two) (Joel Fernandes)
- netfilter: nft_fib: reject fib expression on the netdev egress hook (Theodor Arsenij Larionov-Trichkine) {CVE-2026-72254}
- netfilter: nf_tables: remove register tracking infrastructure (Florian Westphal)
- netfilter: nf_tables: Remove unused nft_reduce_is_readonly() (Yue Haibing)
- netfilter: bitwise: rename some boolean operation functions (Jeremy Sowden)
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) {CVE-2026-72253}
- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)
- ASoC: mediatek: mt8183: Check runtime resume during probe (Cássio Gabriel)
- ASoC: mediatek: mt8183-afe-pcm: use local dev pointer in driver callbacks (Chen-Yu Tsai)
- ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses (Chen-Yu Tsai)
- ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (Chen-Yu Tsai)
- ASoC: mediatek: mt8192: Check runtime resume during probe (Cássio Gabriel) {CVE-2026-72260}
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)
- arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers (Abel Vesa)
- arm64: dts: qcom: correct RBR opp entry (Dmitry Baryshkov)
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- VDUSE: avoid leaking information to userspace (Jason Wang) {CVE-2026-72305}
- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Pérez)
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Pérez)
- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) {CVE-2026-72299}
- rxrpc: Fix socket notification race (David Howells)
- rxrpc: Fix notification vs call-release vs recvmsg (David Howells)
- rxrpc: Use irq-disabling spinlocks between app and I/O thread (David Howells)
- rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack (David Howells)
- rxrpc: Fix CPU time starvation in I/O thread (David Howells)
- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)
- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)
- xfs: don't replace the wrong part of the cow fork (Darrick J. Wong)
- xfs: factor out xfs_attr3_leaf_init (Long Li)
- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) {CVE-2026-74436}
- rxrpc: Pull out certain app callback funcs into an ops table (David Howells)
- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)
- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)
- i2c: i801: fix hardware state machine corruption in error path (Mingyu Wang) {CVE-2026-64205}
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) {CVE-2026-68096}
- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)
- audit: widen ino fields to u64 (Jeff Layton)
- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)
- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives) {CVE-2026-64280}
- iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Nicolin Chen)
- iommufd: Break the loop on failure in iommufd_fault_fops_read() (Nicolin Chen) {CVE-2026-64290}
- iommufd: Reject invalid read count in iommufd_fault_fops_read() (Nicolin Chen)
- mm/damon/core: disallow overlapping input ranges for damon_set_regions() (SJ Park) {CVE-2026-68164}
- mm/damon/core: validate ranges in damon_set_regions() (SJ Park) {CVE-2026-68165}
- rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98 (Miguel Ojeda)
- gve: fix Rx queue stall on alloc failure (Eddie Phillips) {CVE-2026-68129}
- net: pcs: xpcs: fix SGMII state reading (Coia Prant)
- io_uring/rw: fix missing ERESTARTSYS conversion in read paths (Yitang Yang)
- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources (Harry Wentland)
- ksmbd: validate ACE size against SID sub-authorities (Namjae Jeon) {CVE-2026-68097}
- ksmbd: bound DACL dedup walk to copied ACEs (Namjae Jeon) {CVE-2026-68098}
- bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (Jiayuan Chen) {CVE-2026-53078}
- drm/amdgpu: fix aperture mapping leak (Asad Kamal)
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) {CVE-2026-68104}
- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) {CVE-2026-68106}
- drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (Luca Coelho) {CVE-2026-68429}
- drm/amdgpu/vcn4: avoid rereading IB param length (Boyuan Zhang) {CVE-2026-68107}
- drm/amdgpu/vce: fix integer overflow in image size (Boyuan Zhang) {CVE-2026-68108}
- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68110}
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68111}
- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68112}
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) {CVE-2026-68430}
- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68113}
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68246}
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68115}
- drm/amd/pm: make pp_features read-only when scpm is enabled (Yang Wang)
- drm/amd/pm: fix amdgpu_pm_info power display units (Yang Wang)
- vxlan: mdb: Fix source list corruption on a failed replace (James Raphael Tiovalen) {CVE-2026-68116}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) {CVE-2026-68117}
- tcp: initialize standalone TCP-AO response padding (Yizhou Zhao) {CVE-2026-68119}
- rtase: Workaround for TX hang caused by hardware packet parsing (Justin Lai) {CVE-2026-68120}
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) {CVE-2026-68121}
- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) {CVE-2026-68123}
- mctp: serial: handle zero-length frames to prevent rx buffer overflow (Doruk Tan Ozturk) {CVE-2026-68124}
- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) {CVE-2026-68125}
- mac802154: hold an interface reference across the scan worker (Ibrahim Hashimov) {CVE-2026-68126}
- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito) {CVE-2026-68127}
- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)
- ice: reject out-of-range ptype in ice_parser_profile_init (Aleksandr Loktionov) {CVE-2026-68128}
- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery) {CVE-2026-68130}
- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) {CVE-2026-68131}
- ice: fix PTP Call Trace during PTP release (Paul Greenwalt) {CVE-2026-68133}
- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu) {CVE-2026-68135}
- net: gro: fix double aggregation of flush-marked skbs (Shiming Cheng) {CVE-2026-68136}
- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee) {CVE-2026-68137}
- net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) {CVE-2026-68139}
- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas) {CVE-2026-68140}
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan) {CVE-2026-68141}
- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68142}
- net: slip: serialize receive against buffer reallocation (Sungmin Kang) {CVE-2026-68143}
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68432}
- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) {CVE-2026-68144}
- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)
- iomap: fix out-of-bounds bitmap_set() with zero-length range (Zhang Yi) {CVE-2026-68145}
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) {CVE-2026-68146}
- fscrypt: Add missing superblock check in find_or_insert_direct_key() (Eric Biggers) {CVE-2026-68148}
- fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (Amir Goldstein) {CVE-2026-68149}
- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner) {CVE-2026-68151}
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (Chancel Liu)
- amt: fix use-after-free in AMT delayed works (Shihuang Liu) {CVE-2026-68152}
- libceph: remove debugfs files before client teardown (Douya Le) {CVE-2026-68153}
- libceph: reject zero bucket types in crush_decode (Douya Le) {CVE-2026-68154}
- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) {CVE-2026-68155}
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) {CVE-2026-68156}
- libceph: guard missing CRUSH type name lookup (Zhao Zhang) {CVE-2026-68157}
- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) {CVE-2026-68158}
- libceph: bound get_version reply decode to front len (Douya Le) {CVE-2026-68433}
- ceph: fix refcount leak in ceph_readdir() (WenTao Liang)
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) {CVE-2026-68160}
- sctp: close UDP tunnel sockets during netns teardown (Zhiling Zou) {CVE-2026-68161}
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) {CVE-2026-68162}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) {CVE-2026-64564}
- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)
- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" (Will Deacon)
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))
- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))
- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog) {CVE-2026-68175}
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev (Steven Rostedt) {CVE-2026-68176}
- misc: nsm: pin the module while the device is open (Xu Rao) {CVE-2026-68178}
- misc: nsm: only unlock nsm_dev on post-lock error paths (Runyu Xiao) {CVE-2026-68179}
- intel_th: fix MSC output device reference leak (Guangshuo Li) {CVE-2026-68180}
- mei: bus: access mei_device under device_lock on cleanup (Alexander Usyskin) {CVE-2026-68181}
- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)
- uio_hv_generic: Bind to FCopy device by default (Ben Hutchings)
- comedi: comedi_parport: deal with premature interrupt (Ian Abbott) {CVE-2026-68182}
- x86/boot/compressed: Disable jump tables (Nathan Chancellor)
- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng) {CVE-2026-68183}
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) {CVE-2026-68184}
- LoongArch: Retrieve CPU package ID from PPTT when available (Rong Bao)
- LoongArch: Move jump_label_init() before parse_early_param() (Kanglong Wang) {CVE-2026-68185}
- LoongArch: Fix oops during single-step debugging (Haoran Jiang)
- objtool/rust: add one more noreturn Rust function for Rust 1.99.0 (Miguel Ojeda)
- rust: allow clippy::unwrap_or_default globally (Alexandre Courbot)
- platform/loongarch: laptop: Explicitly reset bl_powered state when suspend (Zixing Liu)
- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) {CVE-2026-68186}
- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) {CVE-2026-68187}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) {CVE-2026-68188}
- Bluetooth: hci_sync: Protect UUID list traversal (Chengfeng Ye) {CVE-2026-68189}
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) {CVE-2026-68190}
- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) {CVE-2026-68192}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68193}
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68194}
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68195}
- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang) {CVE-2026-68196}
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) {CVE-2026-68197}
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) {CVE-2026-68199}
- ALSA: timer: don't re-enter an instance callback that is still running (Norbert Szetei) {CVE-2026-68200}
- ALSA: timer: drain a slave's callback before its master detaches it (Norbert Szetei) {CVE-2026-68201}
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) {CVE-2026-68202}
- media: vpif_capture: fix OF node reference imbalance (Johan Hovold)
- media: vivid: fix cleanup bugs in vivid_init() (Guangshuo Li) {CVE-2026-68203}
- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil) {CVE-2026-68204}
- media: vivid: add vivid_update_reduced_fps() (Hans Verkuil)
- media: vimc: fix reference leak on failed device registration (Guangshuo Li)
- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)
- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)
- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (Sakari Ailus)
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) {CVE-2026-68205}
- media: v4l2-ctrls: validate HEVC active reference counts (Pengpeng Hou) {CVE-2026-68206}
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)
- media: ti: vpe: unwind v4l2 device registration on probe error (Myeonghun Pak) {CVE-2026-68207}
- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)
- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68209}
- media: stm32: dcmi: unregister notifier on probe failure (Myeonghun Pak) {CVE-2026-68210}
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) {CVE-2026-68212}
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68213}
- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) {CVE-2026-68214}
- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak) {CVE-2026-68215}
- media: qcom: camss: Fix RDI streaming for CSID GEN2 (Bryan O'Donoghue)
- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68216}
- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) {CVE-2026-68217}
- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) {CVE-2026-68218}
- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (Guoniu Zhou)
- media: nxp: imx8-isi: Fix potential out-of-bounds issues (Guoniu Zhou) {CVE-2026-68219}
- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (Xiaolei Wang)
- media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (Xiaolei Wang)
- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (Xiaolei Wang) {CVE-2026-68220}
- media: nuvoton: npcm-video: fix memory leaks in probe and remove (David Carlier) {CVE-2026-68221}
- media: nuvoton: npcm-video: fix error handling in npcm_video_init() (David Carlier)
- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68222}
- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon) {CVE-2026-68223}
- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)
- media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (Marco Nenciarini)
- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (Martin Hecht) {CVE-2026-68225}
- media: cx23885: add ioremap return check and cleanup (Wang Jun) {CVE-2026-68226}
- media: cx231xx: fix devres lifetime (Johan Hovold) {CVE-2026-68227}
- media: chips-media: wave5: Move src_buf Removal to finish_encode (Brandon Brnich) {CVE-2026-68228}
- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou) {CVE-2026-68229}
- media: cedrus: Fix missing cleanup in error path (Samuel Holland)
- media: cedrus: clean up media device on probe failure (Myeonghun Pak)
- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)
- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68231}
- drm/vc4: Prevent shader BO mappings from becoming writable (Linmao Li) {CVE-2026-68445}
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) {CVE-2026-68446}
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) {CVE-2026-68234}
- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (Mario Limonciello)
- drm/amd/display: dce100: skip non-DP stream encoders for DP MST (Andriy Korud) {CVE-2026-68235}
- drm/amd/display: set new_stream to NULL after release (WenTao Liang) {CVE-2026-68236}
- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)
- drm/panthor: return error on truncated firmware (Osama Abdelkader)
- drm/gfx10: Program DB_RING_CONTROL (Alex Deucher)
- drm/amd/pm: fix smu14 power limit range calculation (Yang Wang)
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) {CVE-2026-68243}
- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) {CVE-2026-68244}
- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (Shahyan Soltani) {CVE-2026-68245}
- drm/i915/bios: range check LFP Data Block panel_type2 (Jani Nikula) {CVE-2026-68247}
- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) {CVE-2026-68248}
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68249}
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68250}
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68251}
- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68252}
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) {CVE-2026-68255}
- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (WenTao Liang) {CVE-2026-68256}
- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (Thomas Zimmermann)
- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Yongqiang Sun) {CVE-2026-68257}
- drm/amdkfd: Check bounds in allocate_event_notification_slot (David Francis) {CVE-2026-68259}
- drm/amdkfd: Use kvcalloc to allocate arrays (David Francis)
- drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (Icenowy Zheng) {CVE-2026-68260}
- drm/imagination: fix error checking of pvr_vm_context_lookup() (Luigi Santivetti) {CVE-2026-68261}
- drm/imagination: Fix user array stride in pvr_set_uobj_array() (Shuvam Pandey) {CVE-2026-68262}
- drm/imagination: Fix double call to drm_sched_entity_fini() (Brajesh Gupta) {CVE-2026-68263}
- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (Matthew Brost)
- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondračka)
- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)
- drm/i915/gem: Add missing nospec on parallel submit slot (Joonas Lahtinen) {CVE-2026-68269}
- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)
- drm/nouveau: fix reversed error cleanup order in ucopy functions (Junrui Luo) {CVE-2026-68271}
- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (Mario Limonciello) {CVE-2026-68272}
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristóf)
- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (Timur Kristóf)
- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (Timur Kristóf)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) {CVE-2026-68277}
- drm/imagination: Fit paired fragment job in the correct CCCB (Alessio Belle) {CVE-2026-68437}
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) {CVE-2026-68278}
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) {CVE-2026-68279}
- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (Vitor Soares) {CVE-2026-68280}
- drm/imagination: Count paired job fence as dependency in prepare_job() (Alessio Belle) {CVE-2026-68281}
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)
- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (Biju Das)
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) {CVE-2026-68284}
- ice: fix LAG recipe to profile association (Marcin Szycik)
- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV (Vincent Chen)
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (Gal Pressman) {CVE-2026-68293}
- net/mlx5: Refactor EEPROM query error handling to return status separately (Gal Pressman)
- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) {CVE-2026-68294}
- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)
- ppp: annotate data races in ppp_generic (Eric Dumazet)
- ppp: enable TX scatter-gather (Qingfang Deng)
- ppp: convert to percpu netstats (Qingfang Deng)
- ppp: use IFF_NO_QUEUE in virtual interfaces (Qingfang Deng)
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)
- net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (Yun Zhou) {CVE-2026-68296}
- net: stmmac: enable the MAC on link up for all supported speeds (vadik likholetov)
- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)
- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (José Expósito)
- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))
- iomap: correct the range of a partial dirty clear (Zhang Yi)
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) {CVE-2026-68299}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo) {CVE-2026-68300}
- net: dpaa: fix mode setting (Michael Walle)
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) {CVE-2026-68301}
- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)
- amt: make the head writable before rewriting the L2 header (Michael Bommarito)
- amt: re-read skb header pointers after every pull (Michael Bommarito) {CVE-2026-68302}
- ovl: fix trusted xattr escape prefix matching (Yichong Chen)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) {CVE-2026-68304}
- wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (Lorenzo Bianconi) {CVE-2026-68306}
- wifi: mt76: mt7925: fix crash in reset link replay (Sean Wang) {CVE-2026-68307}
- wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (Lorenzo Bianconi) {CVE-2026-68308}
- wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68439}
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68309}
- wifi: mt76: mt7915: guard HE capability lookups (Ruoyu Wang) {CVE-2026-68310}
- wifi: mt76: mt7925: guard link STA in decap offload (Guangshuo Li) {CVE-2026-68311}
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) {CVE-2026-68313}
- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))
- gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (Xiang Mei (Microsoft))
- selftests: openvswitch: add config file (Matthieu Baerts (NGI0))
- selftests: af_unix: add USER_NS config (Matthieu Baerts (NGI0))
- tls: device: push pending open record on splice EOF (Rishikesh Jethwani)
- net: mctp i3c: clean up notifier and buses if driver register fails (Myeonghun Pak) {CVE-2026-68314}
- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))
- pds_core: check for workqueue allocation failure (Nikhil P. Rao)
- pds_core: fix auxiliary device add/del races (Nikhil P. Rao) {CVE-2026-68317}
- pds_core: order completion reads after the ownership check (Nikhil P. Rao)
- pds_core: yield the CPU while waiting for the adminq to drain (Nikhil P. Rao)
- pds_core: fix use-after-free on workqueue during remove (Nikhil P. Rao) {CVE-2026-68318}
- pds_core: fix deadlock between reset thread and remove (Nikhil P. Rao) {CVE-2026-68319}
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan) {CVE-2026-68320}
- net: txgbe: fix FDIR filter leak on remove (Chenguang Zhao) {CVE-2026-68321}
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)
- pds_core: reject component parameter in legacy firmware update (Nikhil P. Rao)
- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing) {CVE-2026-68324}
- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) {CVE-2026-68325}
- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (ギカク))
- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang) {CVE-2026-68327}
- nfp: Check resource mutex allocation (Ruoyu Wang) {CVE-2026-68328}
- wifi: mac80211: tear down new links on vif update error path (Xiang Mei) {CVE-2026-64574}
- iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (Guanghui Feng) {CVE-2026-68329}
- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68331}
- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68333}
- gtp: parse extension headers before reading inner protocol (Zhixing Chen)
- bonding: fix devconf_all NULL dereference when IPv6 is disabled (Zhaolong Zhang) {CVE-2026-68336}
- net/packet: avoid fanout hook re-registration after unregister (David Lee) {CVE-2026-68338}
- netlink: specs: rt-link: convert bridge port flag attributes to u8 (Danielle Ratson)
- Bluetooth: btusb: validate Realtek vendor event length (Pengpeng Hou) {CVE-2026-68339}
- regulator: mt6358: use regmap helper to read fixed LDO calibration (Daniel Golle)
- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou) {CVE-2026-68340}
- smb: client: validate DFS referral PathConsumed (Yichong Chen) {CVE-2026-68343}
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM (Eugene Shalygin)
- hwmon: (asus-ec-sensors) fix EC read intervals (Eugene Shalygin)
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (Eugene Shalygin)
- drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (Mostafa Saleh)
- wifi: iwlwifi: mvm: fix read in wake packet notification handler (Shahar Tzarfati)
- wifi: iwlwifi: mvm: validate SAR GEO response payload size (Pagadala Yesu Anjaneyulu)
- ASoC: cs35l56: Use complete_all() to signal init_completion (Richard Fitzgerald)
- ASoC: cs35l56: Fix potential probe() deadlock (Richard Fitzgerald)
- ASoC: cs35l56: Don't use devres to unregister component (Richard Fitzgerald)
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)
- ALSA: hda: cs35l41: validate and free ACPI mute object (Guangshuo Li) {CVE-2026-68346}
- ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (Denis Arefev)
- ASoC: tas2781: bound firmware description string parsing (Pengpeng Hou) {CVE-2026-68348}
- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) {CVE-2026-68450}
- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (Leo Martins) {CVE-2026-68442}
- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 (You-Kai Zheng)
- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) {CVE-2026-68349}
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) {CVE-2026-68350}
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) {CVE-2026-68351}
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) {CVE-2026-68352}
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) {CVE-2026-68353}
- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) {CVE-2026-68354}
- wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)
- wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) {CVE-2026-68355}
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih) {CVE-2026-68357}
- hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68358}
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68359}
- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68443}
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68360}
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis) {CVE-2026-68361}
- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (Gaole Zhang) {CVE-2026-68362}
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) {CVE-2026-68363}
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)
- RISC-V: KVM: Serialize virtual interrupt pending state updates (Xie Bo)
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)
- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)
- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)
- USB: serial: io_edgeport: cap received transmit credits (Sunho Park) {CVE-2026-68365}
- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal) {CVE-2026-68366}
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu) {CVE-2026-64583}
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) {CVE-2026-68368}
- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)
- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)
- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew) {CVE-2026-68369}
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu) {CVE-2026-64584}
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang) {CVE-2026-68370}
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)
- usb: core: port: Deattach Type-C connector on component unbind (Chia-Lin Kao (AceLan))
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) {CVE-2026-68373}
- usb: core: sysfs: add lock to bos_descriptors_read() (Griffin Kroah-Hartman) {CVE-2026-68374}
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) {CVE-2026-64569}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) {CVE-2026-68376}
- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) {CVE-2026-68377}
- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)
- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))
- ksmbd: pin conn during async oplock break notification (Qihang) {CVE-2026-68381}
- smb: move some duplicate definitions to common/cifsglob.h (ZhangGuoDong)
- drm/xe/wopcm: fix WOPCM size for LNL+ (Daniele Ceraolo Spurio)
- can: j1939: fix lockless local-destination check (Shuhao Fu)
- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() (Mark Harris)
- s390/checksum: Fix csum_partial() without vector facility (Vasily Gorbik) {CVE-2026-68385}
- bpf, sockmap: Reject unhashed UDP sockets on sockmap update (Michal Luczaj) {CVE-2026-68386}
- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)
- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)
- powerpc/85xx: Add fsl,ifc to common device ids (Rosen Penev)
- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)
- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) {CVE-2026-68388}
- Bluetooth: hci_qca: Clear memdump state on invalid dump size (Ruoyu Wang) {CVE-2026-68389}
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (Pauli Virtanen) {CVE-2026-68391}
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (Pauli Virtanen) {CVE-2026-68392}
- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (Cen Zhang) {CVE-2026-68394}
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei) {CVE-2026-64573}
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)
- accel/ivpu: Fix wrong register read in LNL failure diagnostics (Karol Wachowski)
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev) {CVE-2026-68449}
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)
- ata: sata_dwc_460ex: use platform_get_irq() (Rosen Penev)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev) {CVE-2026-68395}
- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas) {CVE-2026-68397}
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) {CVE-2026-64572}
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) {CVE-2026-68398}
- cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq (Rafael J. Wysocki)
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)
- ASoC: cs42l43: Correct report for forced microphone jack (Charles Keepax)
- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (Vijendar Mukunda)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)
- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (ギカク))
- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) {CVE-2026-68403}
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) {CVE-2026-68405}
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)
- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li) {CVE-2026-68406}
- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)
- wifi: nl80211: validate nested MBSSID IE blobs (Zhao Li)
- wifi: cfg80211: derive S1G beacon TSF from S1G fields (Zhao Li)
- wifi: nl80211: free RNR data on MBSSID mismatch (Zhao Li) {CVE-2026-68407}
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) {CVE-2026-64571}
- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) {CVE-2026-68410}
- wifi: mac80211: fix fils_discovery double free on alloc failure (Xiang Mei) {CVE-2026-64570}
- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (Xiang Mei) {CVE-2026-64568}
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) {CVE-2026-68411}
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) {CVE-2026-68413}
- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) {CVE-2026-68414}
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))
- xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (Xiang Mei (Microsoft))
- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)
- selftests/alsa: Fix memory leak in find_controls error path (Malaya Kumar Rout)
- mtd: fix double free and WARN_ON in add_mtd_device() error paths (Xue Lei) {CVE-2026-68416}
- RDMA/siw: publish QP after initialization (Ruoyu Wang) {CVE-2026-68417}
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)
- RDMA/erdma: initialize ret for empty receive WR lists (Ruoyu Wang)
- RDMA/irdma: Prevent rereg_mr for non-mem regions (Jacob Moroni) {CVE-2026-68419}
- RDMA/umem: Add pinned revocable dmabuf import interface (Jacob Moroni)
- RDMA/cma: Fix hardware address comparison length in netevent callback (Or Gerlitz)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) {CVE-2026-68444}
- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) {CVE-2026-68422}
- btrfs: reject free space cache with more entries than pages (Xiang Mei) {CVE-2026-64567}
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)
- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)
- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) {CVE-2026-68425}
- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (Sumit Gupta)
- soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE (Harshal Dev)
- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae) {CVE-2026-64565}
- xprtrdma: Clear receive-side ownership pointers on release (Chuck Lever)
- crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (Mikko Perttunen)
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (Mikko Perttunen) {CVE-2026-68427}
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea) {CVE-2026-72146}
- can: isotp: serialize TX state transitions under so->rx_lock (Oliver Hartkopp) {CVE-2026-72124}
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) {CVE-2026-72125}
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) {CVE-2026-72115}
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) {CVE-2026-72117}
- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) {CVE-2026-72116}
- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) {CVE-2026-72113}
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) {CVE-2026-72114}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) {CVE-2026-72119}
- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) {CVE-2026-72118}
- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) {CVE-2026-72121}
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) {CVE-2026-68428}
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) {CVE-2026-64562}
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)
- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (Heiko Carstens)
- seqlock: Allow KASAN to fail optimizing (Peter Zijlstra)
- seqlock: Cure some more scoped_seqlock() optimization fails (Peter Zijlstra)
- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (Kiryl Shutsemau) {CVE-2026-72175}
- drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (Ryosuke Yasuoka)
- netfilter: nf_tables: revert commit_mutex usage in reset path (Brian Witte) {CVE-2026-45901}
- netfilter: nft_quota: use atomic64_xchg for reset (Brian Witte)
- netfilter: nft_counter: serialize reset with spinlock (Brian Witte) {CVE-2026-45897}
- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs (Daniel Borkmann)
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) {CVE-2026-53090}
- net: airoha: Move airoha_eth driver in a dedicated folder (Lorenzo Bianconi)
- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (Guixiong Wei)

[6.12.0-206.100.3]
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li) {CVE-2026-74459}
- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (Norbert Szetei) {CVE-2026-74503}
- sched/deadline: Use revised wakeup rule only for running dl_server (Gabriele Monaco)
- scsi: ufs: core: Cancel RTC work in active-active suspend (Guangshuo Li)
- net: airoha: Fix register index for Tx-fwd counter configuration (Wayen Yan)
- netfilter: nf_conntrack_expect: restore helper propagation via expectation (Pablo Neira Ayuso)
- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047408]
- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047408]
- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047408]
- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047408]
- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047408]
- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047408]
- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047408]
- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047408]
- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047408]
- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047408]
- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047408]
- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047408]
- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047408]
- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047408]
- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add fields and constants for time slice extension (Prakash Sangappa) [Orabug: 39047408]
- Revert "Sched: Scheduler time slice extension" (Prakash Sangappa) [Orabug: 39047408]
- Revert "Sched: Add scheduler stat for cpu time slice extension" (Prakash Sangappa) [Orabug: 39047408]
- Revert "Scheduler extension change under Oracle Extensions and modify enum value" (Prakash Sangappa) [Orabug: 39047408]
- net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover (Matt Fleming) [Orabug: 39203117,39870622] {CVE-2026-64122}
- net/mlx5e: Fix deadlocks between devlink and netdev instance locks (Cosmin Ratiu) [Orabug: 39203117,39870450] {CVE-2026-45907}
- net/mlx5: HWS, ignore flow level for multi-dest table (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: Prevent flow steering mode changes in switchdev mode (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Fix pattern destruction in mlx5hws_pat_get_pattern error path (Lama Kayal) [Orabug: 39203117]
- net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (Lama Kayal) [Orabug: 39203117]
- net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (Lama Kayal) [Orabug: 39203117]
- selftests: drv-net: hds: restore hds settings (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Restore missing scheduling node cleanup on vport enable failure (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Fix QoS reference leak in vport enable error path (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Destroy vport QoS element when no configuration remains (Carolina Jubran) [Orabug: 39203117]
- net/mlx5e: Preserve tc-bw during parent changes (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Remove default QoS group and attach vports directly to root TSAR (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: HWS, Fix table creation UID (Alex Vesker) [Orabug: 39203117]
- net/mlx5: HWS, don't rehash on every kind of insertion failure (Yevgeny Kliteynik) [Orabug: 39203117]
- selftests: drv-net: wait for carrier (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: Fix wild pointer access in nsim_queue_free(). (Kuniyuki Iwashima) [Orabug: 39203117]
- vfio/pci: Do vf_token checks for VFIO_DEVICE_BIND_IOMMUFD (Jason Gunthorpe) [Orabug: 39203117]
- net/mlx5e: Expose TIS via devlink tx reporter diagnose (Feng Liu) [Orabug: 39203117]
- net/mlx5e: Fix potential deadlock by deferring RX timeout recovery (Shahar Shitrit) [Orabug: 39203117]
- selftests: drv-net: Make command requirements explicit (Gal Pressman) [Orabug: 39203117]
- net/mlx5: Fix build -Wframe-larger-than warnings (Zhu Yanjun) [Orabug: 39203117]
- mlx5: access ->pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netdevsim: access ->pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netmem, mlx4: access ->pp_ref_count through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netmem: use netmem_desc instead of page to access ->pp in __netmem_get_pp() (Byungchul Park) [Orabug: 39203117]
- netmem: introduce struct netmem_desc mirroring struct page (Byungchul Park) [Orabug: 39203117]
- netdevsim: add fw_update_flash_chunk_time_ms debugfs knobs (Jiri Pirko) [Orabug: 39203117]
- devlink: Fix excessive stack usage in rate TC bandwidth parsing (Carolina Jubran) [Orabug: 39203117]
- RDMA/mlx5: Refactor optional counters steering code (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Add DMAH object support (Yishai Hadas) [Orabug: 39203117]
- RDMA/core: Introduce a DMAH object and its alloc/free APIs (Yishai Hadas) [Orabug: 39203117]
- IB/core: Add UVERBS_METHOD_REG_MR on the MR object (Yishai Hadas) [Orabug: 39203117]
- net/mlx5: Add support for device steering tag (Yishai Hadas) [Orabug: 39203117]
- net/mlx5: Expose IFC bits for TPH (Yishai Hadas) [Orabug: 39203117]
- PCI/TPH: Expose pcie_tph_get_st_table_size() (Yishai Hadas) [Orabug: 39203117]
- net/mlx5e: Remove duplicate mkey from SHAMPO header (Lama Kayal) [Orabug: 39203117]
- net/mlx5e: SHAMPO, Remove mlx5e_shampo_get_log_hd_entry_size() (Lama Kayal) [Orabug: 39203117]
- net/mlx5e: SHAMPO, Cleanup reservation size formula (Lama Kayal) [Orabug: 39203117]
- selftests: drv-net: Test XDP_PASS/DROP support (Mohsin Bashir) [Orabug: 39203117]
- net: netdevsim: hook in XDP handling (Jakub Kicinski) [Orabug: 39203117]
- RDMA/mlx5: Fix incorrect MKEY masking (Leon Romanovsky) [Orabug: 39203117]
- RDMA/mlx5: Fix returned type from _mlx5r_umr_zap_mkey() (Leon Romanovsky) [Orabug: 39203117]
- net/mlx5: Expose cable_length field in PFCC register (Oren Sidi) [Orabug: 39203117]
- net/mlx5: Add IFC bits to support RSS for IPSec offload (Jianbo Liu) [Orabug: 39203117]
- net/mlx5e: fix kdoc warning on eswitch.h (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Enable IPSec hardware offload in legacy mode (Lama Kayal) [Orabug: 39203117]
- net/mlx5: Fix an IS_ERR() vs NULL bug in esw_qos_move_node() (Dan Carpenter) [Orabug: 39203117]
- netdevsim: remove redundant branch (Dennis Chen) [Orabug: 39203117]
- selftests: net: prevent Python from buffering the output (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: define input-xfrm enum in the spec (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5e: TX, Fix dma unmapping for devmem tx (Dragos Tatulea) [Orabug: 39203117]
- RDMA/mlx5: remove redundant check on err on return expression (Colin Ian King) [Orabug: 39203117]
- net/mlx5e: Add device PCIe congestion ethtool stats (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5e: Create/destroy PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]
- selftests: net: add netpoll basic functionality test (Breno Leitao) [Orabug: 39203117]
- selftests: drv-net: add helper/wrapper for bpftrace (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: implement peer queue flow control (Breno Leitao) [Orabug: 39203117]
- RDMA/uverbs: Add a common way to create CQ with umem (Michael Margolin) [Orabug: 39203117]
- net/mlx5: Expose disciplined_fr_counter through HCA capabilities in mlx5_ifc (Carolina Jubran) [Orabug: 39203117]
- RDMA/mlx5: Optimize DMABUF mkey page size (Edward Srouji) [Orabug: 39203117]
- RDMA/mlx5: Align mkc page size capability check to PRM (Michael Guralnik) [Orabug: 39203117]
- net/mlx5: Expose HCA capability bits for mkey max page size (Michael Guralnik) [Orabug: 39203117]
- net: netdevsim: Support setting dev->perm_addr on port creation (Toke Høiland-Jørgensen) [Orabug: 39203117]
- selftests: drv-net: Add bpftool util (Mohsin Bashir) [Orabug: 39203117]
- net/mlx5e: RX, Remove unnecessary RQT redirects (Tariq Toukan) [Orabug: 39203117]
- net/mlx5: Warn when write combining is not supported (Maor Gottlieb) [Orabug: 39203117]
- net/mlx5e: Replace recursive VLAN push handling with an iterative loop (Gal Pressman) [Orabug: 39203117]
- net/mlx5e: CT: extract a memcmp from a spinlock section (Cosmin Ratiu) [Orabug: 39203117]
- net/mlx5e: Remove unused VLAN insertion logic in TX path (Carolina Jubran) [Orabug: 39203117]
- eth: mlx5: migrate to the *_rxfh_context ops (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Fix spelling mistake "disabliing" -> "disabling" (Colin Ian King) [Orabug: 39203117]
- net/mlx5: Add HWS as secondary steering mode (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Shrink empty matchers (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: HWS, Refactor rule skip logic (Vlad Dogaru) [Orabug: 39203117]
- net/mlx5: HWS, remove incorrect comment (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: HWS, remove unused create_dest_array parameter (Vlad Dogaru) [Orabug: 39203117]
- netmem: use _Generic to cover const casting for page_to_netmem() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename __page_pool_alloc_pages_slow() to __page_pool_alloc_netmems_slow() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename page_pool_return_page() to page_pool_return_netmem() (Byungchul Park) [Orabug: 39203117]
- mlxbf_gige: emit messages during open and probe failures (David Thompson) [Orabug: 39203117]
- selftests: drv-net: Add test for devlink-rate traffic class bandwidth distribution (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Manage TC arbiter nodes and implement full support for tc-bw (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add traffic class scheduling support for vport QoS (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add support for setting tc-bw on nodes (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add no-op implementation for setting tc-bw on rate objects (Carolina Jubran) [Orabug: 39203117]
- selftest: netdevsim: Add devlink rate tc-bw test (Carolina Jubran) [Orabug: 39203117]
- devlink: Extend devlink rate API with traffic classes bandwidth management (Carolina Jubran) [Orabug: 39203117]
- netlink: introduce type-checking attribute iteration for nlmsg (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: fs, fix RDMA TRANSPORT init cleanup flow (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (Parav Pandit) [Orabug: 39203117]
- time/timecounter: Fix the lie that struct cyclecounter is const (Greg Kroah-Hartman) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (Parav Pandit) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]
- RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]
- net/mlx5e: Fix error handling in RQ memory model registration (Wangfushuai) [Orabug: 39203117]
- selftests: forwarding: lib: Split setup_wait() (Petr Machata) [Orabug: 39203117]
- RDMA/ipoib: Use parent rdma device net namespace (Mark Bloch) [Orabug: 39203117]
- RDMA/mlx5: Allocate IB device with net namespace supplied from core dev (Mark Bloch) [Orabug: 39203117]
- RDMA/core: Extend RDMA device registration to be net namespace aware (Mark Bloch) [Orabug: 39203117]
- netlink: specs: ethtool: replace underscores with dashes in names (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Add IFC bits for PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5: Small refactor for general object capabilities (Dragos Tatulea) [Orabug: 39203117]
- RDMA/mlx5: Add multiple priorities support to RDMA TRANSPORT userspace tables (Patrisious Haddad) [Orabug: 39203117]
- net/mlx5: fs, add multiple prios to RDMA TRANSPORT steering domain (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Support driver APIs pre_destroy_cq and post_destroy_cq (Mark Zhang) [Orabug: 39203117]
- RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() (Mark Zhang) [Orabug: 39203117]
- mmc: sdhci-of-dwcmshc: Drop the use of sdhci_pltfm_free() (Binbin Zhou) [Orabug: 39203117]
- selftests: drv-net: import things in lib one by one (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: fix UaF when counting Tx stats (Jakub Kicinski) [Orabug: 39203117]
- eth: mlx5: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: account dropped packet length in stats on queue free (Breno Leitao) [Orabug: 39203117]
- net: add dev_dstats_rx_dropped_add() helper (Breno Leitao) [Orabug: 39203117]
- netdevsim: collect statistics at RX side (Breno Leitao) [Orabug: 39203117]
- netdevsim: migrate to dstats stats collection (Breno Leitao) [Orabug: 39203117]
- net/mlx4_en: Remove the redundant NULL check for the 'my_ets' object (Andrey Vatoropin) [Orabug: 39203117]
- netdevsim: remove udp_ports_sleep (Stanislav Fomichev) [Orabug: 39203117]
- net/mlx4e: Don't redefine IB_MTU_XXX enum (Mark Zhang) [Orabug: 39203117]
- pinctrl: Constify static 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- pinctrl: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- pinctrl: amd: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- net/mlx5e: Add TX support for netmems (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5e: Support ethtool tcp-data-split settings (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Implement queue mgmt ops and single channel swap (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Add support for UNREADABLE netmem page pools (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Convert over to netmem (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Separate pool for headers (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Improve hw gro capability checking (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Remove redundant params (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Reorganize mlx5_rq_shampo_alloc (Saeed Mahameed) [Orabug: 39203117]
- page_pool: Add page_pool_dev_alloc_netmems helper (Dragos Tatulea) [Orabug: 39203117]
- net: Add skb_can_coalesce for netmem (Dragos Tatulea) [Orabug: 39203117]
- net: Allow const args for of page_to_netmem() (Dragos Tatulea) [Orabug: 39203117]
- selftests: forwarding: Add a test for verifying VXLAN MC underlay (Petr Machata) [Orabug: 39203117]
- netmem: fix netmem comments (Mina Almasry) [Orabug: 39203117]
- selftests: net: add netconsole test for cmdline configuration (Breno Leitao) [Orabug: 39203117]
- net: ethtool: add dedicated callbacks for getting and setting rxfh fields (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: require drivers to opt into the per-RSS ctx RXFH (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: remove the duplicated handling from rxfh and rxnfc (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: copy the rxfh flow handling (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: Don't check if RSS context exists in case of context 0 (Gal Pressman) [Orabug: 39203117]
- net/mlx5: Expose serial numbers in devlink info (Jiri Pirko) [Orabug: 39203117]
- selftests: netconsole: Add support for basic netconsole target format (Breno Leitao) [Orabug: 39203117]
- selftests: netconsole: Do not exit from inside the validation function (Breno Leitao) [Orabug: 39203117]
- page_pool: fix ugly page_pool formatting (Mina Almasry) [Orabug: 39203117]
- net/mlx5e: Convert mlx5 netdevs to instance locking (Cosmin Ratiu) [Orabug: 39203117]
- net: Add support for providing the PTP hardware source in tsinfo (Kory Maincent) [Orabug: 39203117]
- selftests: drv-net: Fix "envirnoments" to "environments" (Sumanth Gavini) [Orabug: 39203117]
- net: enable driver support for netmem TX (Mina Almasry) [Orabug: 39203117]
- net: add get_netmem/put_netmem support (Mina Almasry) [Orabug: 39203117]
- netmem: add niov->type attribute to distinguish different net_iov types (Mina Almasry) [Orabug: 39203117]
- selftests: drv-net: ping: make sure the ping test restores checksum offload (Jakub Kicinski) [Orabug: 39203117]
- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (Gal Pressman) [Orabug: 39203117]
- pinctrl: mediatek: airoha: use new GPIO line value setter callbacks (Bartosz Golaszewski) [Orabug: 39203117]
- selftests: net-drv: remove the nic_performance and nic_link_layer tests (Jakub Kicinski) [Orabug: 39203117]
- devlink: define enum for attr types of dynamic attributes (Jiri Pirko) [Orabug: 39203117]
- selftests: net: exit cleanly on SIGTERM / timeout (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv: net: add version indicator (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv: net: avoid skipping tests (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv: net: fix test failure on ipv6 sys (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv-net: rss_input_xfrm: Check test prerequisites before running (Gal Pressman) [Orabug: 39203117]
- selftests: net: add a virtio_net deadlock selftest (Bui Quang Minh) [Orabug: 39203117]
- selftests: net: move xdp_helper to net/lib (Bui Quang Minh) [Orabug: 39203117]
- selftests: drv-net: Test that NAPI ID is non-zero (Joe Damato) [Orabug: 39203117]
- pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines (Christian Marangi) [Orabug: 39203117]
- netlink: specs: rename rtnetlink specs in accordance with family name (Jakub Kicinski) [Orabug: 39203117]
- pinctrl: amd: Add an LPS0 check() callback (Mario Limonciello) [Orabug: 39203117]
- selftests: drv-net: test random value for hds-thresh (Taehee Yoo) [Orabug: 39203117]
- selftests: net: use Path helpers in ping (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: replace the rpath helper with Path objects (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: use defer in the ping test (Jakub Kicinski) [Orabug: 39203117]
- net: skbuff: Remove unused skb_add_data() (Yue Haibing) [Orabug: 39203117]
- selftests: drv-net: fix merge conflicts resolution (Matthieu Baerts) [Orabug: 39203117]
- selftests: drv-net: add xdp cases for ping.py (Taehee Yoo) [Orabug: 39203117]
- selftests: drv-net: use env.rpath in the HDS test (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: report output format as TAP 13 in Python tests (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add tests for napi IRQ affinity notifiers (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net-hw: Add a test for symmetric RSS hash (Gal Pressman) [Orabug: 39203117]
- selftests: drv-net: Make rand_port() get a port more reliably (Gal Pressman) [Orabug: 39203117]
- selftests: drv-net: test XDP, HDS auto and the ioctl path (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: fix ioctl confusing drivers about desired HDS user config (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: Add FIB rule DSCP mask attribute (Ido Schimmel) [Orabug: 39203117]
- selftests: net: Add python context manager for netns entering (Xiao Liang) [Orabug: 39203117]
- selftests: drv-net: rename queues check_xdp to check_xsk (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: improve the use of ksft helpers in XSK queue test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add a way to wait for a local process (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: probe for AF_XDP sockets more explicitly (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add missing new line in xdp_helper (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: use cfg.rpath() in netlink xsk attr test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add a warning for bkg + shell + terminate (Jakub Kicinski) [Orabug: 39203117]
- net: ngbe: Add support for 1PPS and TOD (Jiawen Wu) [Orabug: 39203117]
- net: wangxun: Add periodic checks for overflow and errors (Jiawen Wu) [Orabug: 39203117]
- net: wangxun: Add support for PTP clock (Jiawen Wu) [Orabug: 39203117]
- selftests: drv-net: add a simple TSO test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: store addresses in dict indexed by ipver (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: get detailed interface info (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: resolve remote interface name (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: Add FIB rule port mask attributes (Ido Schimmel) [Orabug: 39203117]
- net: move stale comment about ntuple validation (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: Test queue xsk attribute (Joe Damato) [Orabug: 39203117]
- io_uring/zcrx: add selftest (David Wei) [Orabug: 39203117]
- selftests/net: Add selftest for IPv4 RTM_GETMULTICAST support (Yuyang Huang) [Orabug: 39203117]
- selftests: drv-net: add helper for path resolution (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: factor out a DrvEnv base class (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: prevent flow steering to RSS contexts which don't exist (Jakub Kicinski) [Orabug: 39203117]
- netconsole: selftest: test for sysdata CPU (Breno Leitao) [Orabug: 39203117]
- netconsole: selftest: Add test for fragmented messages (Breno Leitao) [Orabug: 39203117]
- net: provide pending ring configuration in net_device (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: store netdev in a temp variable in ethnl_default_set_doit() (Jakub Kicinski) [Orabug: 39203117]
- net: move HDS config from ethtool state (Jakub Kicinski) [Orabug: 39203117]
- selftest: net-drv: hds: add test for HDS feature (Taehee Yoo) [Orabug: 39203117]
- netdevsim: add HDS feature (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for hds-thresh ethtool command (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for tcp-data-split ethtool command (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for rx-copybreak ethtool command (Taehee Yoo) [Orabug: 39203117]
- net: ethtool: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]
- net: devmem: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]
- net: ethtool: add support for configuring hds-thresh (Taehee Yoo) [Orabug: 39203117]
- netconsole: selftest: verify userdata entry limit (Breno Leitao) [Orabug: 39203117]
- netconsole: selftest: Split the helpers from the selftest (Breno Leitao) [Orabug: 39203117]
- tools: ynl: move python code to separate sub-directory (Jan Stancek) [Orabug: 39203117]
- netdevsim: add debugfs-triggered queue reset (Jakub Kicinski) [Orabug: 39203117]
- netdev: define NETDEV_INTERNAL (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: test drivers sleeping in ndo_get_stats64 (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: assume stats refresh is 0 if no ethtool -c support (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: test empty queue and NAPI responses in netlink (Jakub Kicinski) [Orabug: 39203117]
- page_pool: add page_pool_dev_alloc_netmem() (Alexander Lobakin) [Orabug: 39203117]
- net: Document netmem driver support (Mina Almasry) [Orabug: 39203117]
- netlink: specs: Add FIB rule flow label attributes (Ido Schimmel) [Orabug: 39203117]
- selftests: net-drv: stats: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]
- selftests: net-drv: queues: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: support setting recv_size in YNL (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: Add support for tsconfig command to get/set hwtstamp config (Kory Maincent) [Orabug: 39203117]
- net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology (Kory Maincent) [Orabug: 39203117]
- net: Add the possibility to support a selected hwtstamp in netdevice (Kory Maincent) [Orabug: 39203117]
- net: Make net_hwtstamp_validate accessible (Kory Maincent) [Orabug: 39203117]
- net: Make dev_get_hwtstamp_phylib accessible (Kory Maincent) [Orabug: 39203117]
- page_pool: allow mixing PPs within one bulk (Alexander Lobakin) [Orabug: 39203117]
- vrf: Make pcpu_dstats update functions available to other modules. (Guillaume Nault) [Orabug: 39203117]
- page_pool: make page_pool_put_page_bulk() handle array of netmems (Alexander Lobakin) [Orabug: 39203117]
- netmem: add a couple of page helper wrappers (Alexander Lobakin) [Orabug: 39203117]
- xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model() (Alexander Lobakin) [Orabug: 39203117]
- xdp, xsk: constify read-only arguments of some static inline helpers (Alexander Lobakin) [Orabug: 39203117]
- ethtool: regenerate uapi header from the spec (Stanislav Fomichev) [Orabug: 39203117]
- ethtool: remove the comments that are not gonna be generated (Stanislav Fomichev) [Orabug: 39203117]
- ethtool: separate definitions that are gonna be generated (Stanislav Fomichev) [Orabug: 39203117]
- ynl: add missing pieces to ethtool spec to better match uapi header (Stanislav Fomichev) [Orabug: 39203117]
- selftests: fix nested double quotes in f-string (David Wei) [Orabug: 39203117]
- selftests: nic_performance: Add selftest for performance of NIC driver (Mohan Prasad J) [Orabug: 39203117]
- selftests: nic_link_layer: Add selftest case for speed and duplex states (Mohan Prasad J) [Orabug: 39203117]
- selftests: nic_link_layer: Add link layer selftest for NIC driver (Mohan Prasad J) [Orabug: 39203117]
- pinctrl: airoha: Use unsigned long for bit search (Kees Cook) [Orabug: 39203117]
- net: netconsole: selftests: Check if netdevsim is available (Breno Leitao) [Orabug: 39203117]
- docs: networking: Describe irq suspension (Joe Damato) [Orabug: 39203117]
- selftests: ncdevmem: Add automated test (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Move ncdevmem under drivers/net/hw (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Use YNL to enable TCP header split (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Properly reset flow steering (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Remove default arguments (Stanislav Fomichev) [Orabug: 39203117]
- netlink: specs: Add a spec for FIB rule management (Donald Hunter) [Orabug: 39203117]
- netlink: specs: Add a spec for neighbor tables in rtnetlink (Donald Hunter) [Orabug: 39203117]
- net: netconsole: selftests: Add userdata validation (Breno Leitao) [Orabug: 39203117]
- net: netconsole: selftests: Change the IP subnet (Breno Leitao) [Orabug: 39203117]
- pinctrl: airoha: Add support for EN7581 SoC (Lorenzo Bianconi) [Orabug: 39203117]
- Documentation: networking: Add missing PHY_GET command in the message list (Kory Maincent) [Orabug: 39203117]
- netlink: specs: Add missing phy-ntf command to ethtool spec (Kory Maincent) [Orabug: 39203117]
- selftests: net: lib: Introduce deferred commands (Petr Machata) [Orabug: 39203117]
- ethtool: rss: prevent rss ctx deletion when in use (Daniel Zahka) [Orabug: 39203117]
- selftests: net: move EXTRA_CLEAN of libynl.a into ynl.mk (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: rebuild YNL if dependencies changed (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add missing trailing backslash (Jakub Kicinski) [Orabug: 39203117]
- pinctrl: amd: Fix two small typos (Marc Ferland) [Orabug: 39203117]
- pinctrl: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 39203117]
- pinctrl: qcom: add the tlmm driver for QCS615 platform (Lijuan Gao) [Orabug: 39203117]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558732] {CVE-2026-74684}
- uek-rpm: enable Nexthop SONiC drivers for ONOS (Vijay Kumar) [Orabug: 39597630]
- platform: nexthop-sonic: add SONiC platform drivers (Vijay Kumar) [Orabug: 39597630]
- uek-rpm/modules.yaml.S.onos: Package PDDF platform drivers (Darren Kenny) [Orabug: 39597630]
- uek-rpm/config-x86_64-onos: Enable PDDF platform driver configs (Vijay Kumar) [Orabug: 39597630]
- platform: Port SONiC PDDF drivers (Test Com) [Orabug: 39597630]
- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668598]
- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668598]
- eeprom: optoe: set clientdata before publishing sysfs files (Vijay Kumar) [Orabug: 39721366]
- eeprom: optoe: remove eeprom bin file on sysfs_create_group failure (Vijay Kumar) [Orabug: 39721366]
- eeprom: optoe: fix heap OOB write from stale writebuf sizing (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: raven-fan-driver: read fan ID pins at correct offsets (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: check parse result in scd_set_debug (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: restrict /proc/scd to root-only read (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: fan-cpld: don't hold cpld->lock across work cancel on remove (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: minke-fan-cpld: fix uninitialised cpld deref in probe error path (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: tmp468: fix out-of-bounds read of names[] in probe (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd-mdio: fix mdiobus_free(NULL) and mii_bus leak on error (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: enforce register offset bound instead of advisory ASSERT (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: overflow-safe range check in scd_lpc_mmap_resource (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: rook-fan-cpld: only unregister LEDs that were registered (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: minke-fan-cpld: unregister slot_count LEDs, not fan_count (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: fix SPI controller devdata UAF and invalid kfree (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: don't panic on over-long xcvr attribute name (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: remove partial xcvr sysfs attrs before freeing on error (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: init master->list before the master-add error path (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: use strscpy for LED name to guarantee NUL termination (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: bound fan_count against speed_*_steps[] arrays (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: bound derived MMIO offsets in master/port add paths (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: fix user-controlled format string in gpio/reset add (Vijay Kumar) [Orabug: 39721366]
- src: handle ioremap error in raven-fan-driver (Arista-Hpandya) [Orabug: 39721366]
- Replace sprintf with sysfs_emit in sysfs show callbacks (Arista-Hpandya) [Orabug: 39721366]
- scd: add sysfs knob to control watchdog panic (Mohan Yelugoti) [Orabug: 39721366]
- scd: update scd driver to EOS latest (Mohan Yelugoti) [Orabug: 39721366]
- platform: remove old tricolor LED handling (Justin Oliver) [Orabug: 39721366]
- scd: add bus_speed attribute to i2c buses (Samuel Angebault) [Orabug: 39721366]
- Modify arista-drivers for arm64 compilation. (Vivek Kumar Verma) [Orabug: 39721366]
- minke-fan-cpld: seperate slot and fan initialization in cpld_init (Arista-Hpandya) [Orabug: 39721366]
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784619,39853774] {CVE-2026-68480}
- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812332]
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830589,39832725,39832878,39844799] {CVE-2026-64561}
- net/rds: remove cached rds_sock->rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832353]
- Revert "rds: cong: Make rds_cong_wait an array to reduce lock contention" (Sharath Srinivasan) [Orabug: 39832353]

[6.12.0-206.100.2]
- afs: Fix lack of locking around modifications of net->cells_dyn_ino (David Howells) {CVE-2026-72372}
- afs: Fix dynamic lookup to fail on cell lookup failure (David Howells)
- afs: Simplify cell record handling (David Howells)
- afs: Fix afs_server ref accounting (David Howells)
- afs: Use the per-peer app data provided by rxrpc (David Howells)
- rxrpc: Allow the app to store private data on peer structs (David Howells)
- afs: Drop the net parameter from afs_unuse_cell() (David Howells)
- afs: Make afs_lookup_cell() take a trace note (David Howells)
- afs: Improve server refcount/active count tracing (David Howells)
- Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately (Luiz Augusto von Dentz)
- Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections (Yang Li)
- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)
- drm/amd/pm: fix smu13 power limit range calculation (Yang Wang)
- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL (Guan Wentao) {CVE-2026-68099}
- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl (Haofeng Li) {CVE-2026-68100}
- vsock/virtio: collapse receive queue under memory pressure (Stefano Garzarella)
- proc: Fix broken error paths for namespace links (Jann Horn)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868564] {CVE-2026-68434}
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristóf)
- Revert "drm/amd/display: Add missing kdoc for ALLM parameters" (Sasha Levin)
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860411] {CVE-2026-68344}
- net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() (Lorenzo Bianconi)
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)
- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (Peddolla Harshavardhan Reddy) [Orabug: 39860409] {CVE-2026-68408}
- wifi: cfg80211: define and use wiphy guard (Johannes Berg)
- wifi: cfg80211: pass net_device to .set_monitor_channel (Felix Fietkau)
- firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (Seth Forshee)
- Revert "arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc" (Sasha Levin)
- net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() (Wayen Yan)
- LTS version: v6.12.100 (Sherry Yang)
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807437] {CVE-2026-64560}
- LTS version: v6.12.99 (Sherry Yang)
- mm: refactor mm_access() to not return NULL (Lorenzo Stoakes)
- LTS version: v6.12.98 (Sherry Yang)
- ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation (Yun Zhou)
- LTS version: v6.12.97 (Sherry Yang)
- selftests/bpf: Add simple strscpy() implementation (Ihor Solodrai)
- tools/testing: add linux/args.h header and fix radix, VMA tests (Lorenzo Stoakes)
- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (Ivan Vecera) [Orabug: 39860212] {CVE-2026-68378}
- Bluetooth: L2CAP: fix tx ident leak for commands without a response (Stig Hornang) {CVE-2026-72333}
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)
- crypto: ccp - Fix leaking the same page twice (Guenter Roeck)
- ice: drop udp_tunnel_get_rx_info() call from ndo_open() (Mohammad Heib)
- i40e: drop udp_tunnel_get_rx_info() call from i40e_open() (Mohammad Heib)
- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Borislav Petkov) [Orabug: 39838809] {CVE-2025-39936}
- Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle (Luiz Augusto von Dentz)
- Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state (Luiz Augusto von Dentz)
- udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() (Paolo Abeni)
- crypto: ccp - Fix SNP panic notifier unregistration (Ashish Kalra)
- crypto: ccp - Fix dereferencing uninitialized error pointer (Ashish Kalra) [Orabug: 39838818] {CVE-2025-39729}
- crypto: ccp - Fix __sev_snp_shutdown_locked (Ashish Kalra)
- afs: Fix afs_dynroot_readdir() to not use the RCU read lock (David Howells)
- afs: Fix afs_atcell_get_link() to check if ws_cell is unset first (David Howells)
- net: airoha: Fix channel configuration for ETS Qdisc (Lorenzo Bianconi)
- rtnetlink: Make per-netns RTNL dereference helpers to macro. (Kuniyuki Iwashima)
- ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd (Gil Portnoy)
- seqlock: fix scoped_seqlock_read kernel-doc (Randy Dunlap)
- dibs: loopback: validate offset and size in move_data() (Dust Li) {CVE-2026-72018}
- perf/x86/amd/brs: Fix kernel address leakage (Sandipan Das) {CVE-2026-72237}
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski) [Orabug: 39760895] {CVE-2026-64192}
- KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() (Marc Zyngier)
- KVM: arm64: Ensure level is always initialized when relaxing perms (Oliver Upton)
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier) {CVE-2026-72282}
- mm/damon/core: always put unsuccessfully committed target pids (Seongjae Park) {CVE-2026-72178}
- selftests/fs/statmount: build with tools include dir (Amir Goldstein)
- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)
- fscrypt: Fix key setup in edge case with multiple data unit sizes (Eric Biggers)
- slab: recognize @GFP parameter as optional in kernel-doc (Randy Dunlap)
- default_gfp(): avoid using the "newfangled" __VA_OPT__ trick (Linus Torvalds)
- add default_gfp() helper macro and use it in the new *alloc_obj() helpers (Linus Torvalds)
- slab: Introduce kmalloc_flex() and family (Kees Cook)
- slab: Introduce kmalloc_obj() and family (Kees Cook)
- btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo)
- btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo)
- exfat: preserve benign secondary entries during rename and move (Rochan Avlur)
- exfat: fix incorrect directory checksum after rename to shorter name (Chi Zhiling)
- exfat: move exfat_chain_set() out of __exfat_resolve_path() (Yuezhang Mo)
- exfat: add exfat_get_dentry_set_by_ei() helper (Yuezhang Mo)
- exfat: rename argument name for exfat_move_file and exfat_rename_file (Yuezhang Mo)
- exfat: remove unnecessary read entry in __exfat_rename() (Yuezhang Mo)
- crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta)
- crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) (Tycho Andersen) [Orabug: 39785896] {CVE-2026-64307}
- crypto: ccp - Fix a case where SNP_SHUTDOWN is missed (Tom Lendacky)
- crypto: ccp - Move SEV/SNP Platform initialization to KVM (Ashish Kalra)
- crypto: ccp - Register SNP panic notifier only if SNP is enabled (Ashish Kalra)
- crypto: ccp - Reset TMR size at SNP Shutdown (Ashish Kalra)
- crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (Ashish Kalra)
- btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC (Qu Wenruo)
- btrfs: remove the COW fixup mechanism (Qu Wenruo)
- btrfs: remove folio parameter from ordered io related functions (Qu Wenruo)
- btrfs: replace for_each_set_bit() with for_each_set_bitmap() (Qu Wenruo)
- btrfs: concentrate the error handling of submit_one_sector() (Qu Wenruo)
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron)
- crypto: atmel-sha204a - fail on hwrng registration error in probe path (Thorsten Blum)
- usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker) {CVE-2026-64594}
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum)
- crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-König)
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira) {CVE-2026-68456}
- USB: iowarrior: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786002] {CVE-2026-64341}
- usb: iowarrior: remove inherent race with minor number (Oliver Neukum)
- bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786045] {CVE-2026-64352}
- bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko)
- bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() (Luis Gerhorst)
- bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi)
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani) {CVE-2026-64361}
- hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko)
- HID: pidff: Use correct effect type in effect update (Oleg Makarenko)
- HID: pidff: Rework pidff_upload_effect (Tomasz Pakuła)
- HID: pidff: Add missing spaces (Tomasz Pakuła)
- HID: pidff: Fix missing blank lines after declarations (Tomasz Pakuła)
- HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786073] {CVE-2026-64363}
- treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner)
- proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786094] {CVE-2026-64371}
- seqlock: Change do_task_stat() to use scoped_seqlock_read() (Oleg Nesterov)
- seqlock: Introduce scoped_seqlock_read() (Peter Zijlstra)
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786077] {CVE-2026-64364}
- HID: add haptics page defines (Angela Czubak)
- perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box() (Zide Chen)
- proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786111] {CVE-2026-64375}
- proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig)
- ksmbd: track the connection owning a byte-range lock (Namjae Jeon) {CVE-2026-64390}
- ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang)
- ksmbd: use opener credentials for FSCTL mutations (Namjae Jeon) {CVE-2026-68457}
- ksmbd: fix path resolution in ksmbd_vfs_kern_path_create (Davide Ornaghi) {CVE-2026-68083}
- vfs: make LAST_XXX private to fs/namei.c (Jori Koolstra)
- ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name (Al Viro)
- smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786199] {CVE-2026-64401}
- smb: client: Improve unlocking of a mutex in cifs_get_swn_reg() (Markus Elfring)
- mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (Jose Fernandez) [Orabug: 39786239] {CVE-2026-64416}
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39802881] {CVE-2026-64557}
- Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (Pauli Virtanen)
- Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() (Siwei Zhang) [Orabug: 39786211] {CVE-2026-64405}
- Bluetooth: separate CIS_LINK and BIS_LINK link types (Pauli Virtanen)
- Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (Runyu Xiao) [Orabug: 39760900] {CVE-2026-64206}
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz)
- netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786231] {CVE-2026-64413}
- netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng)
- media: nxp: imx8-isi: Fix use-after-free on remove (Xiaolei Wang) {CVE-2026-64421}
- media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (Frank Li)
- io_uring/rw: preserve partial result for iopoll (Michael Wigham)
- io_uring/rw: ensure reissue path is correctly handled for IOPOLL (Jens Axboe)
- gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao) {CVE-2026-64428}
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver) [Orabug: 39838967] {CVE-2026-64434}
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (Giovanni Cabiddu) [Orabug: 39786297] {CVE-2026-64438}
- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu) {CVE-2026-64441}
- staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov)
- staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird)
- PCI: Skip Resizable BAR restore on read error (Marco Nenciarini)
- PCI: Move Resizable BAR code to rebar.c (Ilpo Järvinen)
- PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Järvinen)
- PCI: Free saved list without holding pci_bus_sem (Ilpo Järvinen)
- PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Järvinen)
- PCI: Use pbus_select_window() during BAR resize (Ilpo Järvinen)
- PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786365] {CVE-2026-64461}
- PCI: mediatek: Use generic MACRO for TPVPERL delay (Christian Marangi)
- PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi)
- PCI: mediatek: Switch to msi_create_parent_irq_domain() (Nam Cao)
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby)
- PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya) {CVE-2026-64462}
- vfio/mlx5: Fix racy bitfields and tighten struct layout (Alex Williamson) [Orabug: 39786400] {CVE-2026-64472}
- ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 (Geoffrey D. Bennett)
- ALSA: scarlett2: Allow selecting config_set by firmware version (Geoffrey D. Bennett)
- ALSA: hda/cs35l41: Fix firmware load work teardown (Cássio Gabriel) [Orabug: 39786423] {CVE-2026-64481}
- ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong) {CVE-2026-64488}
- iio: pressure: mpl115: fix runtime PM leak on read error (Biren Pandya) {CVE-2026-64493}
- iio: pressure: Remove redundant pm_runtime_mark_last_busy() calls (Sakari Ailus)
- iio: adc: ad7380: select REGMAP (Samuel Moelius)
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu)
- ACPI: NFIT: core: Fix possible deadlock and missing notifications (Rafael J. Wysocki)
- ACPI: NFIT: core: Use devm_acpi_install_notify_handler() (Rafael J. Wysocki)
- ACPI: bus: Introduce devm_acpi_install_notify_handler() (Rafael J. Wysocki)
- ACPI: driver: Check ACPI_COMPANION() against NULL during probe (Rafael J. Wysocki) [Orabug: 39785136] {CVE-2026-64227}
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786501] {CVE-2026-64510}
- rust: block: fix GenDisk cleanup paths (Haoze Xie) {CVE-2026-64509}
- mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method (Sergey Shtylyov)
- mmc: block: fix RPMB device unregister ordering (Ao Sun)
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou) {CVE-2026-68466}
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou)
- mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou)
- mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao) {CVE-2026-80659}
- mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou) {CVE-2026-68467}
- mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou)
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims) {CVE-2026-68469}
- wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou)
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo) {CVE-2026-68474}
- reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong) {CVE-2026-68475}
- ipvs: reload ip header after head reallocation (Florian Westphal) {CVE-2026-68476}
- ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov) {CVE-2026-68477}
- memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie) {CVE-2026-68478}
- macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen)
- llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang)
- Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya) {CVE-2026-68479}
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789563,39816011,39819142] {CVE-2026-64531}
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha)
- wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng) {CVE-2026-72004}
- wifi: mwifiex: fix roaming to different channel in host_mlme mode (Rafael Beims)
- wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao) {CVE-2026-72005}
- powerpc/pseries: fix memory leak on krealloc failure in papr_init (Thorsten Blum)
- selftests/landlock: Fix screwed up pointers in the scoped_signal_test (Thomas Huth)
- selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available (Thomas Huth)
- pmdomain: imx: Fix i.MX8MP VC8000E power up sequence (Peng Fan) {CVE-2026-72007}
- pmdomain: imx: Fix i.MX8MP power notifier (Peng Fan)
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi) {CVE-2026-72010}
- s390/mm: Fix type mismatch in get_align_mask(). (Gerald Schaefer)
- tracing/osnoise: Call synchronize_rcu() when unregistering (Crystal Wood) {CVE-2026-72012}
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu) {CVE-2026-72013}
- drbd: reject data replies with an out-of-range payload size (Michael Bommarito) {CVE-2026-72014}
- ata: libata-core: Skip HPA resize for locked drives (Terrence Adams)
- arm64: smp: Fix hot-unplug tearing by forcing unregistration (Jinjie Ruan)
- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko) {CVE-2026-72019}
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao) {CVE-2026-72020}
- ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao) {CVE-2026-72021}
- llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai) {CVE-2026-72022}
- selftests: net: make busywait timeout clock portable (Nirmoy Das)
- mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen) {CVE-2026-72024}
- s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer) {CVE-2026-72025}
- irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure (Haoxiang Li) {CVE-2026-72026}
- mm/compaction: handle free_pages_prepare() properly in compaction_free() (Zi Yan) {CVE-2026-72027}
- riscv: probes: save original sp in rethook trampoline (Martin Kaiser) {CVE-2026-72028}
- hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An) {CVE-2026-80593}
- net: wwan: iosm: bound device offsets in the MUX downlink decoder (Maoyi Xie) {CVE-2026-72029}
- ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang)
- orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas) {CVE-2026-72033}
- tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu)
- hwmon: (max1619) add missing 'select REGMAP' to Kconfig (Joshua Crofts)
- fhandle: reject detached mounts in capable_wrt_mount() (David Lee) {CVE-2026-72034}
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) {CVE-2026-72035}
- net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) {CVE-2026-72036}
- net: lan743x: Initialize eth_syslock spinlock before use (Andrea Righi) {CVE-2026-72037}
- fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li)
- hwmon: (occ) unregister sysfs devices outside occ lock (Runyu Xiao) {CVE-2026-80660}
- net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li) {CVE-2026-72038}
- hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou)
- hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou)
- rtc: mpfs: fix counter upload completion condition (Conor Dooley)
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal) {CVE-2026-72039}
- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca) {CVE-2026-72041}
- LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() (Hongchen Zhang) {CVE-2026-72043}
- batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann) {CVE-2026-72229}
- rust: block: allow(deprecated) for fetch_update for Rust >= 1.99.0 (Miguel Ojeda)
- batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann) {CVE-2026-72232}
- batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann) {CVE-2026-72235}
- s390: Revert support for DCACHE_WORD_ACCESS (Heiko Carstens) {CVE-2026-64369}
- net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants (Jamal Hadi Salim)
- platform/x86/amd/pmc: Avoid logging "(null)" for DMI values (Daniel Gibson)
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi) {CVE-2026-72047}
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi) {CVE-2026-72048}
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito)
- ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito) {CVE-2026-72049}
- octeontx2-af: Free BPID bitmap on setup failure (Haoxiang Li) {CVE-2026-72050}
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72052}
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72053}
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72054}
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72055}
- net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng) {CVE-2026-72056}
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi) {CVE-2026-72057}
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li) {CVE-2026-72058}
- net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (Haoxiang Li) {CVE-2026-72059}
- net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72061}
- gpios: palmas: add .get_direction() op (Andreas Kemnade)
- gpio-f7188x: Add support for NCT6126D version B (Paul Louvel)
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao) {CVE-2026-72063}
- cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan) {CVE-2026-72066}
- cpu: hotplug: Preserve per instance callback errors (Bradley Morgan) {CVE-2026-72067}
- selftests/ftrace: Drop invalid top-level local in test_ownership (Cao Ruichuang)
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng) {CVE-2026-72068}
- tracing/user_events: Fix use-after-free in user_event_mm_dup() (Michael Bommarito) {CVE-2026-72071}
- net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (Doruk Tan Ozturk) {CVE-2026-72072}
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov) {CVE-2026-72074}
- Input: ims-pcu - fix race condition in reset_device sysfs callback (Dmitry Torokhov) {CVE-2026-72075}
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov) {CVE-2026-80594}
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov) {CVE-2026-72076}
- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov) {CVE-2026-72077}
- Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov)
- Input: ims-pcu - add response length checks (Dmitry Torokhov) {CVE-2026-80595}
- Input: ims-pcu - validate control endpoint type (Dmitry Torokhov) {CVE-2026-72078}
- Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov)
- Input: ims-pcu - only expose sysfs attributes on control interface (Dmitry Torokhov) {CVE-2026-80596}
- Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov) {CVE-2026-72079}
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li) {CVE-2026-72081}
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang) {CVE-2026-72082}
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas) {CVE-2026-72083}
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas) {CVE-2026-72084}
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito) {CVE-2026-72085}
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito) {CVE-2026-72086}
- scsi: sg: Report request-table problems when any status is set (Xu Rao)
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal) {CVE-2026-72087}
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li) {CVE-2026-72088}
- accel/ivpu: Reject firmware log with size smaller than header (Jhonraushan) {CVE-2026-72089}
- dm-verity: make error counter atomic (Mikulas Patocka) {CVE-2026-72096}
- dm-verity: increase sprintf buffer size (Mikulas Patocka)
- dm-verity: fix a possible NULL pointer dereference (Mikulas Patocka) {CVE-2026-72097}
- dm-verity: avoid double increment of &use_bh_wq_enabled (Mikulas Patocka)
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka) {CVE-2026-72099}
- dm-integrity: fix a bug if the bio is out of limits (Mikulas Patocka) {CVE-2026-72100}
- dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka) {CVE-2026-72102}
- dm-stats: fix merge accounting (Mikulas Patocka)
- dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka)
- dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski) {CVE-2026-72105}
- dm-ioctl: fix a possible overflow in list_version_get_info (Mikulas Patocka) {CVE-2026-72106}
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka)
- dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius) {CVE-2026-72107}
- dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai) {CVE-2026-72108}
- dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang)
- net: sparx5: unregister blocking notifier on init failure (Haoxiang Li) {CVE-2026-72109}
- block: fix race in blk_time_get_ns() returning 0 (Mike Waychison)
- bpf: Add missing access_ok call to copy_user_syms (Jiri Olsa)
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn) {CVE-2026-72110}
- can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp) {CVE-2026-72120}
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp) {CVE-2026-72122}
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones) {CVE-2026-72123}
- can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp) {CVE-2026-72126}
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu) {CVE-2026-64585}
- netdev-genl: report NAPI thread PID in the caller's pid namespace (Maoyi Xie) {CVE-2026-72127}
- nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas) {CVE-2026-72129}
- NFS: Charge unstable writes by request size, not folio size (Benjamin Coddington) {CVE-2026-72132}
- sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794430] {CVE-2026-64551}
- spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi) {CVE-2026-72133}
- time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan)
- tpm: Make the TPM character devices non-seekable (Jaewon Yang) {CVE-2026-72135}
- tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum)
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72136}
- xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan)
- xen/gntdev: fix error handling in ioctl (Xu Wang) {CVE-2026-72138}
- ice: fix ice_init_link() error return preventing probe (Paul Greenwalt)
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang) {CVE-2026-72140}
- i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar)
- hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)
- pkey: Move keytype check from pkey api to handler (Holger Dengler)
- platform/x86/amd/pmc: Don't log during intermediate wakeups (Daniel Gibson)
- platform/x86/amd/pmc: Add delay_suspend module parameter (Daniel Gibson)
- platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (Daniel Gibson)
- platform/x86/amd/pmc: Check for intermediate wakeup in function (Daniel Gibson)
- platform/x86: dell-laptop: fix missing cleanups in init error path (Haoxiang Li) {CVE-2026-72144}
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li) {CVE-2026-72148}
- dmaengine: tegra: Fix burst size calculation (Kartik) {CVE-2026-72149}
- tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (Michael Bommarito) {CVE-2026-72151}
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen) {CVE-2026-72152}
- irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi) {CVE-2026-72153}
- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs) {CVE-2026-80597}
- mtd: rawnand: Pause continuous reads at block boundaries (Miquel Raynal)
- mtd: spi-nor: spansion: use die erase for multi-die devices only (Takahiro Kuwano)
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal) {CVE-2026-72155}
- s390/pkey: Check length in pkey_pckmo handler implementation (Holger Dengler) {CVE-2026-64558}
- s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (Holger Dengler) {CVE-2026-64559}
- fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (Sebastian Alba Vives) {CVE-2026-72156}
- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie) {CVE-2026-72157}
- bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (Manivannan Sadhasivam)
- fpga: dfl: add bounds check in dfh_get_param_size() (Sebastian Alba Vives) {CVE-2026-72158}
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito) {CVE-2026-72159}
- ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito)
- ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito) {CVE-2026-72160}
- ocfs2: add journal NULL check in ocfs2_checkpoint_inode() (Joseph Qi) {CVE-2026-72161}
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges) {CVE-2026-72163}
- ocfs2: avoid moving extents to occupied clusters (Kyle Zeng) {CVE-2026-72164}
- mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov) {CVE-2026-72165}
- net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev) {CVE-2026-72166}
- mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet) {CVE-2026-72167}
- ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani)
- scsi: sas: Skip opt_sectors when DMA reports no real optimization hint (Ionut Nechita)
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao) {CVE-2026-72170}
- mtd: slram: remove failed entries from the device list (Ruoyu Wang) {CVE-2026-72171}
- kcov: use WRITE_ONCE() for selftest mode stores (Karl Mehltretter)
- mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE (Muchun Song) {CVE-2026-72172}
- proc: only bump parent nlink when registering directories (Krzysztof Wilczyński)
- fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() (Kiryl Shutsemau)
- fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() (Kiryl Shutsemau) {CVE-2026-72174}
- mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error (Seongjae Park) {CVE-2026-72176}
- mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() (Seongjae Park) {CVE-2026-72177}
- riscv: cacheinfo: Fix node reference leak in populate_cache_leaves (Xu Wang) {CVE-2026-72179}
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin) {CVE-2026-72181}
- selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path (Bryam Vargas)
- power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang) {CVE-2026-72182}
- ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani) {CVE-2026-80598}
- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito) {CVE-2026-72191}
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito) {CVE-2026-72192}
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used (Michael Bommarito) {CVE-2026-72193}
- fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito) {CVE-2026-64532}
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito) {CVE-2026-72194}
- fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov) {CVE-2026-64533}
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov) {CVE-2026-72195}
- fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass (Michael Bommarito) {CVE-2026-72196}
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov) {CVE-2026-72197}
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng)
- mm/damon/core: make charge_addr_from aware of end-address exclusivity (Seongjae Park)
- mm/memory_hotplug: fix incorrect altmap passing in error path (Muchun Song) {CVE-2026-72212}
- power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (Ma Ke) {CVE-2026-72214}
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki) {CVE-2026-72215}
- MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold)
- MIPS: ip22-gio: fix kfree() of static object (Johan Hovold)
- MIPS: ip22-gio: fix gio device memory leak (Johan Hovold)
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir) {CVE-2026-72216}
- SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing (Chuck Lever) {CVE-2026-72217}
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever) {CVE-2026-72218}
- lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever) {CVE-2026-72219}
- sunrpc: wait for in-flight TLS handshake callback when cancel loses race (Chuck Lever) {CVE-2026-72221}
- sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (Chris Mason) {CVE-2026-72222}
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal) {CVE-2026-72223}
- nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal) {CVE-2026-72224}
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo) {CVE-2026-72225}
- Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen)
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen)
- HID: playstation: validate num_touch_reports in DualShock 4 reports (Benoît Sevens)
- mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski)
- cifs: invalidate cfid on unlink/rename/rmdir (Shyam Prasad N)
- batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann) {CVE-2026-72226}
- batman-adv: mcast: avoid OOB read of num_dests header (Sven Eckelmann) {CVE-2026-72227}
- batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann) {CVE-2026-72228}
- batman-adv: frag: free unfragmentable packet (Sven Eckelmann) {CVE-2026-72230}
- batman-adv: fix VLAN priority offset (Sven Eckelmann)
- batman-adv: tt: avoid request storms during pending request (Sven Eckelmann) {CVE-2026-72231}
- batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann)
- batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann) {CVE-2026-80599}
- batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann) {CVE-2026-72233}
- batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann) {CVE-2026-80600}
- batman-adv: access unicast_ttvn skb->data only after skb realloc (Sven Eckelmann) {CVE-2026-72234}
- batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann) {CVE-2026-80601}
- s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() (Sumanth Korikkar) {CVE-2026-72236}
- cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() (Rafael J. Wysocki)
- perf/x86/amd/lbr: Fix kernel address leakage (Sandipan Das) {CVE-2026-80602}
- x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum)
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum) {CVE-2026-72238}
- tools/power/x86/intel-speed-select: Harden daemon pidfile open (Unknownbbqrx) {CVE-2026-80663}
- mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li) {CVE-2026-72240}
- leds: uleds: Fix potential buffer overread (Armin Wolf) {CVE-2026-72241}
- selinux: fix incorrect execmem checks on overlayfs (Ondrej Mosnacek)
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani) {CVE-2026-72242}
- selinux: check connect-related permissions on TCP Fast Open (Stephen Smalley) {CVE-2026-72243}
- soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun)
- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli)
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li) {CVE-2026-72245}
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794441] {CVE-2026-64554}
- netfilter: xt_nat: reject unsupported target families (Wyatt Feng) {CVE-2026-80664}
- netfilter: ecache: fix inverted time_after() check (Yizhou Zhao)
- netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao) {CVE-2026-72247}
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei) {CVE-2026-72250}
- netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal) {CVE-2026-72251}
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) {CVE-2026-72252}
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie) {CVE-2026-72255}
- netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng) {CVE-2026-72256}
- netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier)
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal) {CVE-2026-80603}
- ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (Srinivas Kandagatla) {CVE-2026-72257}
- ASoC: mediatek: mt8183: Release reserved memory on cleanup (Cássio Gabriel) {CVE-2026-72258}
- ASoC: mediatek: mt8192: Release reserved memory on cleanup (Cássio Gabriel) {CVE-2026-72259}
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (Peter Ujfalusi) {CVE-2026-72261}
- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (Peter Ujfalusi) {CVE-2026-72262}
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal) {CVE-2026-72264}
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal) {CVE-2026-72265}
- fbdev: vesafb: fix memory leak in vesafb_probe() (Abdun Nihaal) {CVE-2026-72266}
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal) {CVE-2026-72267}
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal) {CVE-2026-72268}
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal) {CVE-2026-72269}
- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal) {CVE-2026-72270}
- fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal) {CVE-2026-72271}
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal) {CVE-2026-72272}
- fbdev: efifb: fix memory leak in efifb_probe() (Abdun Nihaal) {CVE-2026-72273}
- fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing)
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal) {CVE-2026-72274}
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal) {CVE-2026-72275}
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal) {CVE-2026-72276}
- KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (Weiming Shi) [Orabug: 39794445] {CVE-2026-64555}
- KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 (Oliver Upton) {CVE-2026-72280}
- KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (Sean Christopherson) {CVE-2026-72284}
- KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (Atish Patra) {CVE-2026-72286}
- KVM: s390: pci: Fix handling of AIF enable without AISB (Matthew Rosato) {CVE-2026-68454}
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim) {CVE-2026-72289}
- KVM: s390: pci: Fix GISC refcount leak on AIF enable failure (Haoxiang Li) {CVE-2026-72290}
- LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr() (Maqiang)
- LoongArch: KVM: Fix FPU register width with user access API (Bibo Mao)
- LoongArch: KVM: Check the return values for put_user() (Maqiang)
- LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() (Bibo Mao) {CVE-2026-72294}
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo (David Jander)
- arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags (Krzysztof Kozlowski)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference (David Jander)
- arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc (Judith Mendez)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times (David Jander)
- arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen)
- arm64: fpsimd: Fix type mismatch in sve_{save,load}_state() (Mark Rutland)
- net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang) {CVE-2026-72296}
- net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang) {CVE-2026-72297}
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito) {CVE-2026-72298}
- ASoC: SOF: topology: validate vendor array size before parsing (Cássio Gabriel) {CVE-2026-72300}
- ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (Peter Ujfalusi) {CVE-2026-72301}
- ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (Peter Ujfalusi) {CVE-2026-72302}
- ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (Peter Ujfalusi) {CVE-2026-72304}
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci) {CVE-2026-72306}
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang) {CVE-2026-72307}
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Xu Wang) {CVE-2026-72308}
- smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li) {CVE-2026-72310}
include (Anas Khan)
- net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing)
- selftests/net: fix EVP_MD_CTX leak in tcp_mmap (Wang Yan)
- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi) {CVE-2026-72314}
- dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui) {CVE-2026-72316}
- SUNRPC: pin upper rpc_clnt across the TLS connect_worker (Chuck Lever) {CVE-2026-72317}
- SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED (Chuck Lever)
- cifs: validate DFS referral string offsets (Guangshuo Li) {CVE-2026-72318}
- s390/zcrypt: Remove the empty file (Rongguang Wei)
- ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov) {CVE-2026-72319}
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao)
- ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao)
- ipvs: pass parsed transport offset to state handlers (Yizhou Zhao)
- netfilter: nft_lookup: fix catchall element handling with inverted lookups (Tamaki Yanagawa) {CVE-2026-72320}
- ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet) {CVE-2026-72322}
- ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima)
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (Eric Dumazet) {CVE-2026-72323}
- gpio: mvebu: free generic chips on unbind (Rosen Penev) {CVE-2026-72324}
- perf/x86/amd/core: Avoid enabling BRS from the SVM reload path (Sandipan Das) {CVE-2026-72325}
- octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh)
- net/sched: cake: reject overhead values that underflow length (Samuel Moelius) {CVE-2026-72326}
- drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (Maíra Canal) {CVE-2026-72327}
- net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon)
- net: usb: lan78xx: move functions to avoid forward definitions (Oleksij Rempel)
- net/tls: Consume empty data records in tls_sw_read_sock() (Chuck Lever) {CVE-2026-72330}
- ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang)
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794420] {CVE-2026-64549}
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen)
- Bluetooth: MGMT: Fix adv monitor add failure cleanup (Cen Zhang) {CVE-2026-72335}
- Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (Cen Zhang) {CVE-2026-72336}
- amt: fix size calculation in amt_get_size() (Eric Dumazet)
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei) {CVE-2026-64541}
- net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload (Jamal Hadi Salim) {CVE-2026-72338}
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei) {CVE-2026-64550}
- qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida) {CVE-2026-72339}
- net: microchip: vcap: fix races on the shared Super VCAP block (Jens Emil Schulz Østergaard) {CVE-2026-72340}
- net/mlx5e: Fix HV VHCA stats agent registration race (Feng Liu) {CVE-2026-72342}
- net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (Feng Liu) {CVE-2026-72343}
- net/mlx5: LAG, MPESW, Fix missing complete() on devcom error (Shay Drory) {CVE-2026-80667}
- netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng) {CVE-2026-72347}
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen) {CVE-2026-72348}
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu) {CVE-2026-72349}
- netfilter: xt_u32: reject invalid shift counts (Wyatt Feng) {CVE-2026-72350}
- gue: validate REMCSUM private option length (Qihang) {CVE-2026-72351}
- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794411] {CVE-2026-64547}
- selftests/hid: Cover hid_bpf_get_data() size overflow (Yiyang Chen)
- selftests/hid: Load only requested struct_ops maps (Yiyang Chen)
- HID: bpf: Fix hid_bpf_get_data() range check (Yiyang Chen) {CVE-2026-72352}
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual)
- HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones) {CVE-2026-80604}
- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin) {CVE-2026-80605}
- ata: libata-scsi: limit simulated SCSI command copy to response length (Karuna Ramkumar)
- ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak)
- cifs: Fix missing credit release on failure in cifs_issue_read() (David Howells) {CVE-2026-72356}
- netfs: Drop the error arg from netfs_read_subreq_terminated() (David Howells)
- drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (Michal Wajdeczko) {CVE-2026-72360}
- drm/xe/hw_engine: Fix double-free of managed BO in error path (Shuicheng Lin) {CVE-2026-72361}
- drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (Francois Dugast) {CVE-2026-72362}
- netfs: Fix writeback error handling (David Howells) {CVE-2026-72364}
- ovl: fix comment about locking order (Amir Goldstein)
- minix: avoid overflow in bitmap block count calculation (Michael Bommarito) {CVE-2026-72369}
- afs: Fix unchecked-length string display in debug statement (David Howells)
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells) {CVE-2026-72371}
- afs: Fix vllist leak (David Howells)
- afs: Fix missing NULL pointer check in afs_break_some_callbacks() (David Howells) {CVE-2026-72373}
- afs: Fix callback service message parsers to pass through -EAGAIN (David Howells) {CVE-2026-72374}
- afs: Fix misplaced inc of net->cells_outstanding (David Howells) {CVE-2026-72376}
- afs: Change dynroot to create contents on demand (David Howells)
- afs: Remove the "autocell" mount option (David Howells)
- afs: Fix afs_atcell_get_link() to handle RCU pathwalk (David Howells)
- afs: Make /afs/@cell and /afs/. at cell symlinks (David Howells)
- afs: Add rootcell checks (David Howells)
mountpoints (David Howells)
- afs: Remove erroneous seq |= 1 in volume lookup loop (Li Rongqing)
- afs: use kvfree() to free memory allocated by kvcalloc() (Zilin Guan)
- afs: Fix double netfs initialisation in afs_root_iget() (David Howells)
- afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter) {CVE-2026-72378}
- fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid (Christian Brauner) {CVE-2026-72379}
- net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius)
- pinctrl: meson: restore non-sleeping GPIO access (Viacheslav Bocharov)
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)
- ksmbd: fix use-after-free of fp->owner.name in durable handle owner check (Gil Portnoy) {CVE-2026-72381}
- ksmbd: reject undersized DACLs before parsing ACEs (Haofeng Li) {CVE-2026-72382}
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim)
- cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov)
- virtio_net: disable cb when NAPI is busy-polled (Longjun Tang)
- irqchip/ts4800: Fix missing chained handler cleanup on remove (Qingshuang Fu) {CVE-2026-72384}
- irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi)
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser)
- tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu)
- drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (Boris Brezillon)
- drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (Boris Brezillon) {CVE-2026-72386}
- drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (Boris Brezillon)
- drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (Boris Brezillon) {CVE-2026-72387}
- bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel) {CVE-2026-72389}
- net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF (Jamal Hadi Salim) {CVE-2026-72390}
- net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev)
- net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (Petr Wozniak) {CVE-2026-72391}
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794386] {CVE-2026-64540}
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang) {CVE-2026-72392}
- hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (Guenter Roeck) {CVE-2026-72394}
- hwmon: (pmbus) Fix passing events to regulator core (Guenter Roeck) {CVE-2026-72395}
- hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen) {CVE-2026-72396}
- ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 (Luca Weiss)
- ASoC: codecs: lpass-va-macro: add SM6115 compatible (Srinivas Kandagatla)
- MIPS: DEC: Ensure RTC platform device deregistration upon failure (Maciej W. Rozycki)
- sctp: fix SCTP_RESET_STREAMS stream list length limit (Yousef Alhouseen)
- net: enetc: check the number of BDs needed for xdp_frame (Wei Fang) {CVE-2026-72399}
- qede: fix out-of-bounds check for cqe->len_list[] (Matvey Kovalev) {CVE-2026-80609}
- seg6: validate SRH length before reading fixed fields (Nuoqi Gui) {CVE-2026-72400}
- gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou)
- gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou)
- spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou)
- tracing: probes: fix typo in a log message (Martin Kaiser)
- net: hns3: differentiate autoneg default values between copper and fiber (Shuaisong Yang)
- net: hns3: fix permanent link down deadlock after reset (Shuaisong Yang)
- net: hns3: refactor MAC autoneg and speed configuration (Shuaisong Yang)
- net: hns3: unify copper port ksettings configuration path (Shuaisong Yang)
- net: hns3: clear hns alarm: comparison of integer expressions of different signedness (Peiyang Wang)
- net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle layer conversion (Jijie Shao)
- net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle layer conversion (Jijie Shao)
- net: hns3: use string choices helper (Jian Shen)
- net: hisilicon: hns3: use ethtool string helpers (Rosen Penev)
- dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback (Rob Herring)
- net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync (Eric Dumazet) {CVE-2026-72405}
- udp_tunnel: remove rtnl_lock dependency (Stanislav Fomichev)
- ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (Shengjiu Wang)
- net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove (Shitalkumar Gandhi)
- net: sungem: fix probe error cleanup (Ruoyu Wang) {CVE-2026-72406}
- net: mvneta: re-enable percpu interrupt on resume (Yun Zhou) {CVE-2026-72409}
- net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() (David Yang)
- rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li)
- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson)
- smb/client: preserve errors from smb2_set_sparse() (Huiwen He)
- ACPI: processor_idle: Mark LPI enter functions as __cpuidle (Li Rongqing) {CVE-2026-80611}
- thermal: testing: zone: Flush work items during cleanup (Rafael J. Wysocki)
- ipv6: fix missing notification for ignore_routes_with_linkdown (Fernando Fernandez Mancera)
- ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL. (Kuniyuki Iwashima)
- ipv6: Add __in6_dev_get_rtnl_net(). (Kuniyuki Iwashima)
- rtnetlink: Define rtnl_net_trylock(). (Kuniyuki Iwashima)
- rtnetlink: Add assertion helpers for per-netns RTNL. (Kuniyuki Iwashima)
- rtnetlink: Add per-netns RTNL. (Kuniyuki Iwashima)
- ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera)
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787016] {CVE-2026-64530}
- veth: fix NAPI leak in XDP enable error path (Eric Dumazet) {CVE-2026-80613}
- net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona) {CVE-2026-72414}
- net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794404] {CVE-2026-64545}
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczyński)
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczyński)
- NTB: epf: Fix doorbell bitmask and IRQ vector handling (Koichiro Den)
- NTB: epf: Report 0-based doorbell vector via ntb_db_event() (Koichiro Den)
- NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den)
- gpio: davinci: fix IRQ domain leak on devm_kzalloc failure (Qingshuang Fu)
- netfilter: nft_compat: ebtables emulation must reject non-bridge targets (Florian Westphal) {CVE-2026-72416}
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot (Runyu Xiao)
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera) {CVE-2026-72418}
- netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() (Mathias Krause) {CVE-2026-72419}
- bpf: Disable xfrm_decode_session hook attachment (Bradley Morgan) {CVE-2026-80669}
- md/raid5: avoid R5_Overlap races while breaking stripe batches (Chen Cheng) {CVE-2026-72420}
- md/raid5: use stripe state snapshot in break_stripe_batch_list() (Chen Cheng)
- ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima) {CVE-2026-72421}
- eth: bnxt: improve the timing of stats (Jakub Kicinski)
- eth: bnxt: rename ring_err_stats -> ring_drv_stats (Jakub Kicinski)
- eth: bnxt: gather and report HW-GRO stats (Jakub Kicinski)
- net: bnxt: use ethtool string helpers (Rosen Penev)
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794378] {CVE-2026-64538}
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy) {CVE-2026-72422}
- rtc: msc313: fix NULL deref in shared IRQ handler at probe (Stepan Ionichev) {CVE-2026-72424}
- i40e: Fix i40e_debug() to use struct i40e_hw argument (Mohamed Khalfella)
- ice: dpll: fix memory leak in ice_dpll_init_info error paths (Zhaojinming)
- ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info (Zhaojinming)
- ice: call netif_keep_dst() once when entering switchdev mode (Marcin Szycik)
- ice: fix AQ error code comparison in ice_set_pauseparam() (Lukasz Czapnik)
- ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (Dawid Osuchowski) {CVE-2026-72425}
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794407] {CVE-2026-64546}
- power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() (Bartosz Golaszewski)
- bpf: Fix effective prog array index with BPF_F_PREORDER (Amery Hung) {CVE-2026-72427}
- bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar)
- bpftool: Fix vmlinux BTF leak in cgroup commands (Chenyichong)
- bpf: Fix stack slot index in nospec checks (Nuoqi Gui) {CVE-2026-72428}
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton)
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski)
- dpaa2-switch: do not accept VLAN uppers while bridged (Ioana Ciornei)
- ipv6: ndisc: fix NULL deref in accept_untracked_na() (Weiming Shi) [Orabug: 39794394] {CVE-2026-64542}
- net/sched: act_ct: fix nf_connlabels leak on two error paths (Michael Bommarito) {CVE-2026-72430}
- net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths (Wayen Yan)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi) [Orabug: 39794396] {CVE-2026-64543}
- net: marvell: prestera: initialize err in prestera_port_sfp_bind (Ruoyu Wang)
- selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan)
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil)
- selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil)
- selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap (Sayali Patil)
- selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap (Sayali Patil)
- selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh (Sayali Patil)
- irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi)
- mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (Sebastian Andrzej Siewior)
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal) {CVE-2026-72433}
- netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal)
- netfilter: ipset: make sure gc is properly stopped (Jozsef Kadlecsik) {CVE-2026-72434}
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik) {CVE-2026-72435}
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types (Jozsef Kadlecsik) {CVE-2026-72436}
- netfilter: ipset: annotate "pos" for concurrent readers/writers (Jozsef Kadlecsik)
- netfilter: ipset: Fix data race between add and dump in all hash types (Jozsef Kadlecsik)
- md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry (Abd-Alrhman Masalkhi) {CVE-2026-72437}
- mac802154: Prevent overwrite return code in mac802154_perform_association() (Robertus Diawan Chris)
- ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh) {CVE-2026-72441}
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov)
- ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (Xu Rao)
- ACPI: resource: Amend kernel-doc style (Andy Shevchenko)
- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri)
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao)
- ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (Cen Zhang) {CVE-2026-72443}
- flow_dissector: check device type before reading ETH_ADDRS (Yun Zhou) {CVE-2026-72444}
- devlink: Fix parent ref leak in devl_rate_node_create() (Cosmin Ratiu)
- dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei)
- virtio-net: fix len check in receive_big() (Xiang Mei) [Orabug: 39794434] {CVE-2026-64552}
- spi: rpc-if: Use correct device for hardware reinitialization on resume (Quang Nguyen)
- PCI: iproc: Restore .map_irq() for the platform bus driver (Mark Tomlinson)
- sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long) {CVE-2026-72447}
- net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794437] {CVE-2026-64553}
- drm/amdgpu: initialize irq.lock spinlock earlier (Thadeu Lima de Souza Cascardo)
- drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (Mario Limonciello) {CVE-2026-72449}
- drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (Yunxiang Li) {CVE-2026-80618}
- ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (Sen Wang)
- xfrm: validate selector family and prefixlen during match (Eric Dumazet) {CVE-2026-72450}
- xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] (Eric Dumazet)
- xfrm: Fix xfrm state cache insertion race (Herbert Xu) {CVE-2026-72451}
- spi: dw: fix wrong BAUDR setting after resume (Jisheng Zhang)
- drm/i915: clear CRTC color blob pointers after dropping refs (Guangshuo Li) {CVE-2026-72452}
- gpio: mlxbf3: fail probe if gpiochip registration fails (Pengpeng Hou)
- sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou)
- apparmor: fix label can not be immediately before a declaration (John Johansen)
- i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter)
- i3c: master: Make hot-join workqueue freezable to block hot-join during suspend (Adrian Hunter)
- i3c: master: add WQ_PERCPU to alloc_workqueue users (Marco Crivellari)
- workqueue: Add new WQ_PERCPU flag (Marco Crivellari)
- apparmor: put secmark label after secid lookup (Zygmunt Krynicki)
- apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki)
- apparmor: remove or add symlinks to rawdata according to export_binary (Georgia Garcia)
- apparmor: fix potential UAF in aa_replace_profiles (Maxime Bélair) {CVE-2026-80619}
- apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee)
- apparmor: fix rawdata_f_data implicit flex array (John Johansen)
- apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki) {CVE-2026-72459}
- apparmor: check label build before no_new_privs test (Ruoyu Wang) {CVE-2026-72460}
- security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() (Andrew Morton)
- Revert "PCI/MSI: Unmap MSI-X region on error" (Yuanhe Shu) {CVE-2026-80620}
- PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam)
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee)
- tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo)
- tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo)
- tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo)
- xprtrdma: Return sendctx slot after Send preparation failure (Chuck Lever)
- xprtrdma: Repost Receive buffers for malformed replies (Chuck Lever) {CVE-2026-72464}
- xprtrdma: Sanitize the reply credit grant after parsing (Chuck Lever) {CVE-2026-72465}
- xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason) {CVE-2026-72466}
- xprtrdma: Resize reply buffers before reposting receives (Chuck Lever)
- xprtrdma: Document and assert reply-handler invariants (Chuck Lever)
- xprtrdma: Check frwr_wp_create() during connect (Chuck Lever) {CVE-2026-72467}
- xprtrdma: Initialize re_id before removal registration (Chris Mason) {CVE-2026-72468}
- xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (Chris Mason) {CVE-2026-72469}
- PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar)
- fs/ntfs3: resize log->one_page_buf when adopting on-disk page size (Jamie Nguyen) {CVE-2026-72470}
- PCI: meson: Add missing remove callback (Shuvam Pandey)
- PCI: meson: Propagate devm_add_action_or_reset() failure (Shuvam Pandey)
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing)
- nfs: use nfsi->rwsem to protect traversal of the file lock list (Yangerkun) {CVE-2026-72472}
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer)
- nfs: keep PG_UPTODATE clear after read errors in page groups (Clark Wang)
- NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo)
- xprtrdma: Decouple req recycling from RPC completion (Chuck Lever) {CVE-2026-72473}
- xprtrdma: Use sendctx DMA state for Send signaling (Chuck Lever)
- xprtrdma: Post receive buffers after RPC completion (Chuck Lever)
- xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot (Chuck Lever)
- xprtrdma: Avoid 250 ms delay on backlog wakeup (Chuck Lever)
- pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg)
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney)
- dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (Nuno Sa) {CVE-2026-72474}
- dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (Nuno Sa) {CVE-2026-72475}
- dmaengine: Fix possible use after free (Nuno Sa) {CVE-2026-72476}
- dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng)
- perf: Fix off-by-one stack buffer overflow in kallsyms__parse() (Rui Qi)
- dmaengine: imx-sdma: Refine spba bus searching in probe (Shengjiu Wang)
- thunderbolt: debugfs: Fix margining error counter buffer leak (Xu Rao)
- drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam)
- fs/ntfs3: fix mount failure on 64K page-size kernels (Jamie Nguyen)
- fs/ntfs3: add bounds check to run_get_highest_vcn() (Konstantin Komarov) {CVE-2026-72478}
- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev)
- clk: at91: keep securam node alive while mapping it (Yuho Choi)
- iio: tcs3472: power down chip on probe failure (Aldo Conte)
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda) {CVE-2026-72479}
- iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (Guilherme Ivo Bozi) {CVE-2026-72480}
- iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts) {CVE-2026-72481}
- iio: light: si1133: prevent race condition on timeout (Joshua Crofts)
- iio: light: si1133: reset counter to prevent race condition (Joshua Crofts)
- PCI: qcom: Disable ASPM L0s for SA8775P (Shawn Guo)
- char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim) {CVE-2026-80622}
- usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae) {CVE-2026-72483}
- staging: most: video: avoid double free on video register failure (Guangshuo Li) {CVE-2026-72484}
- mailbox: mtk-adsp: fix UAF during device teardown (Sergey Senozhatsky) {CVE-2026-72486}
- coresight: Fix source not disabled on idr_alloc_u32 failure (Jie Gan)
- clk: at91: sam9x7: Fix gmac_gclk clock definition (Mihai Sain)
- phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko)
- PCI: qcom: Set max OPP before DBI access during resume (Qiang Yu)
- bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (Sumit Kumar)
- rust: alloc: fix assert in Vec::reserve doc test (Hsiu Che Yu)
- PCI: loongson: Do not ignore downstream devices on external bridges (Rongrong)
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki)
- x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki)
- PCI: Check ROM header and data structure addr before accessing (Guixin Liu) {CVE-2026-72487}
- PCI: Introduce named defines for PCI ROM (Guixin Liu)
- PCI/ASPM: Don't reconfigure ASPM entering low-power state (Carlos Bilbao)
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan)
- coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng)
- staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu) {CVE-2026-72489}
- gpiolib: acpi: Only trigger ActiveBoth interrupts on boot (Mario Limonciello)
- eventpoll: Fix epoll_wait() report false negative (Nam Cao)
- eventpoll: rename epi->next and txlist for clarity (Christian Brauner)
- eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers (Christian Brauner)
- eventpoll: extract ep_deliver_event() from ep_send_events() (Christian Brauner)
- eventpoll: split ep_insert() into alloc + register stages (Christian Brauner)
- eventpoll: rename attach_epitem() to ep_attach_file() (Christian Brauner)
- eventpoll: expand top-of-file overview / locking doc (Christian Brauner)
- net/9p: fix race condition on rdma->state in trans_rdma.c (Yizhou Zhao) {CVE-2026-72491}
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh)
- mfd: cs42l43: Sanity check firmware size (Charles Keepax) {CVE-2026-80624}
- mfd: rsmu: Fix page register setup (Matthew Bystrin)
- ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li) {CVE-2026-72492}
- ionic: Fix check in ionic_get_link_ext_stats (Brett Creeley)
- net: ethernet: oa_tc6: Remove FCS size in RX frame (Selvamani Rajagopal)
- net: airoha: Fix always-true condition in PPE1 queue reservation loop (Wayen Yan)
- net: airoha: Add sched ETS offload support (Lorenzo Bianconi)
- net: airoha: Introduce ndo_select_queue callback (Lorenzo Bianconi)
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet)
- tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet) {CVE-2026-74255}
- KEYS: Use acquire when reading state in keyring search (Gui-Dong Han)
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan)
- powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan)
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan) {CVE-2026-80626}
- MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan) {CVE-2026-80627}
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim) {CVE-2026-74256}
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794416] {CVE-2026-64548}
- udf: fix nls leak on udf_fill_super() failure (Al Viro)
- bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket (Leon Hwang)
- selftests/bpf: Initialize operation name before use (Leo Yan)
- selftests/bpf: Fix typo in verify_umulti_link_info (Jiri Olsa)
- smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He)
- cifs: remove all cifs files before kill super (Zhangjian) {CVE-2026-74259}
- ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (Takashi Iwai)
- netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal)
- kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao) {CVE-2026-74262}
- net: bcmgenet: Use weighted round-robin TX DMA arbitration (Ovidiu Panait)
- landlock: Fix unmarked concurrent access to socket family (Matthieu Buffet)
- dpll: balance create/delete notifications in __dpll_pin_(un)register (Grzegorz Nitka)
- dpll: guard sync-pair removal on full pin unregister (Grzegorz Nitka)
- dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() (Grzegorz Nitka)
- dpll: send delete notification before unregister in on-pin rollback (Grzegorz Nitka)
- dpll: fix stale iteration in dpll_pin_on_pin_unregister() (Grzegorz Nitka)
- dpll: Enhance and consolidate reference counting logic (Ivan Vecera)
- dpll: Support dynamic pin index allocation (Ivan Vecera)
- dpll: Add notifier chain for dpll events (Petr Oros)
- dpll: Allow associating dpll pin with a firmware node (Ivan Vecera)
- dpll: add reference sync get/set (Arkadiusz Kubalewski)
- dpll: add reference-sync netlink attribute (Arkadiusz Kubalewski)
- net: wwan: t7xx: check skb_clone in control TX (Ruoyu Wang) {CVE-2026-74263}
- net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() (Guan Wentao)
- octeontx2-af: npc: Fix size of entry2cntr_map (Ratheesh Kannoth) {CVE-2026-80629}
- net/mlx5: Check max_macs devlink param value against max capability (Dragos Tatulea)
- bpf: Run generic devmap egress prog on private skb (Sun Jian)
- net: ethernet: mtk_wed: fix loading WO firmware for MT7986 (Zhi-Jun You)
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg)
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg) {CVE-2026-74265}
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) {CVE-2026-74267}
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) {CVE-2026-80630}
- handshake: Require admin permission for DONE command (Chuck Lever) {CVE-2026-74270}
- power: supply: core: fix supplied_from allocations (Lucas Tsai) {CVE-2026-74271}
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li)
- spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Pöschel) {CVE-2026-74276}
- ALSA: seq: Fix kernel heap address leak in bounce_error_event() (Ji'An Zhou) {CVE-2026-74278}
- crypto: rng - Free default RNG on module exit (Herbert Xu)
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu) {CVE-2026-74279}
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu) {CVE-2026-74280}
- cxl/test: Add check after kzalloc() memory in alloc_mock_res() (Dave Jiang)
- cxl/test: Unregister cxl_acpi in cxl_test_init() error path (Dave Jiang)
- tipc: reject inverted service ranges from peer bindings (Michael Bommarito) {CVE-2026-74281}
- tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito) {CVE-2026-74282}
- tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito) {CVE-2026-74283}
- net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira) {CVE-2026-74284}
- net: pfcp: allocate per-cpu tstats for PFCP netdevs (Samuel Moelius) {CVE-2026-74286}
- sctp: validate embedded address parameter length (Xin Long) {CVE-2026-74287}
- bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei) {CVE-2026-64537}
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima) {CVE-2026-74288}
- net/sched: cls_flow: Dont expose folded kernel pointers (Jamal Hadi Salim) {CVE-2026-74290}
- net: dsa: qca8k: fix led devicename when using external mdio bus (George Moussalem)
- ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An) {CVE-2026-74292}
- ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An) {CVE-2026-74293}
- ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An) {CVE-2026-74295}
- RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one (Leon Romanovsky) {CVE-2026-74296}
- RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla) {CVE-2026-74297}
- RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad)
- RDMA/mlx5: Remove DCT restrack tracking (Patrisious Haddad)
- fs: efs: remove unneeded debug prints (Maxwell Doose)
- Bluetooth: vhci: validate devcoredump state before side effects (Samuel Moelius)
- Bluetooth: hci: validate codec capability element length (Samuel Moelius) {CVE-2026-74300}
- Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (Zhao Dongdong) {CVE-2026-74301}
- Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (Jordan Walters) {CVE-2026-74302}
- Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (Weiming Shi) [Orabug: 39794382] {CVE-2026-64539}
- Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (Zijun Hu) {CVE-2026-74303}
- s390/process: Fix kernel thread function pointer type (Heiko Carstens)
- ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (Richard Fitzgerald)
- bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann) {CVE-2026-74305}
- vfio/qat: fix f_pos race in qat_vf_resume_write() (Giovanni Cabiddu) {CVE-2026-74306}
- of: cpu: add check in __of_find_n_match_cpu_property() (Sergey Shtylyov)
- cxl/test: Zero out LSA backing memory to avoid leaking to user (Dave Jiang)
- cxl/test: Fix integer overflow in mock LSA bounds checks (Dave Jiang)
- selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song)
- ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT (Yun Zhou) {CVE-2026-74307}
- ext4: fix kernel BUG in ext4_write_inline_data_end (Aditya Prakash Srivastava) {CVE-2026-74308}
- bonding: 3ad: fix mux port state on oper down (Louis Scalbert)
- ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (Richard Fitzgerald)
- ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (Richard Fitzgerald)
- vdpa/octeon_ep: Fix PF->VF mailbox data address calculation (Srujana Challa)
- tools/virtio: check mmap return value in vringh_test (Longlong Yan)
- vhost/net: complete zerocopy ubufs only once (Qing Ming) {CVE-2026-74310}
- vduse: Requeue failed read to send_list head (Zhang Tianci)
- virtio_console: read size from config space during device init (Filip Hejsek)
- vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang) {CVE-2026-74312}
- vduse: hold vduse_lock across IDR lookup in open path (Qihang) {CVE-2026-74313}
- ASoC: codecs: aw88261: fix incorrect masks for boost regs (Val Packett)
- spi: meson-spifc: fix runtime PM leak on remove (Ruoyu Wang)
- NFSD: Handle layout stid in nfsd4_drop_revoked_stid() (Chuck Lever) {CVE-2026-74316}
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe)
- btrfs: fix deadlock cloning inline extent when using flushoncommit (Filipe Manana) {CVE-2026-74318}
- btrfs: zoned: don't account data relocation space-info in statfs free space (Johannes Thumshirn)
- hwmon: (it87) Clamp negative values to zero in set_fan() (Nikita Zhandarovich)
- fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight) {CVE-2026-74320}
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana) {CVE-2026-74321}
- wifi: mt76: mt7996: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7925: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7921: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7915: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: fix argument to ieee80211_is_first_frag() (Bjoern A. Zeeb)
- wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (Sean Wang)
- wifi: mt76: mt7925: keep TX BA state in the primary WCID (Sean Wang)
- wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (Javier Tia)
- wifi: mt76: mt7925: clean up DMA on probe failure (Myeonghun Pak)
- sched/fair: Fix cpu_util runnable_avg arithmetic (Hongyan Xia)
- hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang)
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu) {CVE-2026-74327}
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- scsi: target: Remove tcm_loop target reset handling (Mike Christie)
- scsi: target: Fix hexadecimal CHAP_I handling (David Disseldorp)
- watchdog: unregister PM notifier on watchdog unregister (Yuho Choi) {CVE-2026-74329}
- configfs: fix lockless traversals of ->s_children (Al Viro) {CVE-2026-74330}
- firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov) {CVE-2026-74331}
- ASoC: amd: acp-sdw-sof: Bound DAI link iteration (Aaron Ma) {CVE-2026-74332}
- spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu)
- IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe)
- IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe)
- thermal: testing: reject missing command arguments (Samuel Moelius)
- cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang)
- ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi)
- ALSA: seq: Clear variable event pointer on read (Kyle Zeng) {CVE-2026-74339}
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi)
- riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool (Hui Wang)
- ALSA: seq: Fix partial userptr event expansion (Hyeongjun An)
- wifi: wcn36xx: fix OOB read from short trigger BA firmware response (Tristan Madani) {CVE-2026-80635}
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani) {CVE-2026-74340}
- wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (Tristan Madani) {CVE-2026-74341}
- bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang)
- bpf: Check tail zero of bpf_prog_info (Leon Hwang)
- RDMA/siw: Fix endpoint/socket association handling (Bernard Metzler) {CVE-2026-74345}
- arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well (Alexander Stein)
- arm64: dts: imx95: Correct PCIe outbound address space configuration (Richard Zhu)
- RDMA/irdma: Initialize iwmr->access during MR registration (Jacob Moroni)
- RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni) {CVE-2026-74346}
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe)
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso)
- netfilter: conntrack: revert ct extension genid infrastructure (Pablo Neira Ayuso) {CVE-2026-80636}
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera)
- netfilter: synproxy: fix unaligned memory access in timestamp adjustment (Fernando Fernandez Mancera) {CVE-2026-80637}
- netfilter: synproxy: adjust duplicate timestamp options (Fernando Fernandez Mancera)
- netfilter: synproxy: drop packets if timestamp adjustment fails (Fernando Fernandez Mancera)
- netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags (Pablo Neira Ayuso)
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera)
- ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi)
- ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen) {CVE-2026-74348}
- ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen) {CVE-2026-74349}
- ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov)
- ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen) {CVE-2026-74351}
- drm/amdkfd: always resume_all after suspend_all (Alex Deucher) {CVE-2026-74353}
- xfrm: fix NAT-related field inheritance in SA migration (Antony Antony)
- perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains (Sandipan Das)
- perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems (Zide Chen)
- perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das)
- vhost: fix vhost_get_avail_idx for a non empty ring (Michael S. Tsirkin) {CVE-2026-74356}
- bpftool: Use libbpf error code for flow dissector query (Woojin Ji)
- drm/amdgpu: set sub_block_index for mca ras sub-blocks (Yunxiang Li)
- configfs_lookup(): don't leave ->s_dentry dangling on failure (Al Viro) {CVE-2026-74359}
- lib/test_meminit: use && for bools (Alexander Potapenko)
- tick/sched: Fix TOCTOU in nohz idle time fetch (Frederic Weisbecker)
- driver core: Use system_percpu_wq instead of system_wq (Nathan Chancellor)
- sched: restore timer_slack_ns when resetting RT policy on fork (Guanyou Chen)
- ext2: fix ignored return value of generic_write_sync() (Danila Chernetsov) {CVE-2026-74362}
- mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon)
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey) {CVE-2026-74363}
- scsi: ufs: Fix wrong value printed in unexpected UPIU response case (Chanwoo Lee)
- scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter)
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" (Martin Wilck)
- nvdimm/btt: Handle preemption in BTT lane acquisition (Alison Schofield) {CVE-2026-74365}
- ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi)
- ata: libata: Fix ata_exec_internal() (Bart Van Assche)
- HID: wiimote: Fix table layout and whitespace errors (Jonathan Neuschäfer)
- ARM: imx3: Fix CCM node reference leak (Yuho Choi)
- NFSD: Fix delegation reference leak in nfsd4_revoke_states (Chuck Lever)
- ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble (John Madieu)
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi)
- md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng) {CVE-2026-74376}
- rpmsg: use generic driver_override infrastructure (Danilo Krummrich)
- Drivers: hv: vmbus: use generic driver_override infrastructure (Danilo Krummrich) {CVE-2026-80676}
- cdx: use generic driver_override infrastructure (Danilo Krummrich)
- amba: use generic driver_override infrastructure (Danilo Krummrich)
- media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han)
- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han)
- media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han)
- RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (Tristan Madani) {CVE-2026-74377}
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (Tristan Madani) {CVE-2026-74378}
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin)
- drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang)
- drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang)
- sched/deadline: Reject debugfs dl_server writes for offline CPUs (Andrea Righi)
- sched/deadline: Always stop dl-server before changing parameters (Juri Lelli)
- crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (Herbert Xu)
- crypto: tegra - Fix dma_free_coherent size error (Herbert Xu)
- crypto: hisilicon/qm - disable error report before flr (Weili Qian)
- ocfs2: kill osb->system_file_mutex lock (Tetsuo Handa)
- ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang) {CVE-2026-80644}
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter) {CVE-2026-80645}
- dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso) {CVE-2026-74379}
- libbpf: Fix UAF in strset__add_str() (Carlos Llamas)
- bpftool: Fix typo in struct_ops map FD generation for light skeleton (Siddharth Nayyar)
- libbpf: Harden parse_vma_segs() path parsing (Michael Bommarito)
- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi)
- drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen)
- gpu: host1x: Fix iommu_map_sgtable() return value check (Mikko Perttunen) {CVE-2026-74380}
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu)
- gpu: host1x: Allow entries in BO caches to be freed (Mikko Perttunen) {CVE-2026-74381}
- drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (Ion Agorria)
- drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (Svyatoslav Ryhel)
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen) {CVE-2026-74382}
- ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet) {CVE-2026-80646}
- workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao)
- nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff) {CVE-2026-74384}
- nvmet-tcp: fix page fragment cache leak in error path (Geliang Tang) {CVE-2026-74386}
- pinctrl: cs42l43: Fix polarity on debounce (Charles Keepax)
- pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table (Joey Lu)
- ALSA: seq: midi: Serialize output teardown with event_input (Zhang Cen) {CVE-2026-74387}
- mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal)
- driver core: Guard deferred probe timeout extension with delayed_work_pending() (Danilo Krummrich)
- driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (Danilo Krummrich)
- mips: n64: add __iomem for writel call (Rosen Penev)
- mips: ralink: mt7621: add missing __iomem (Rosen Penev)
- MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki)
- MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki)
- PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu)
- RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup (Tao Cui)
- RDMA/hns: Fix log flood after cmd_mbox failure (Wenglianfa) {CVE-2026-74389}
- RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa) {CVE-2026-80647}
- IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li)
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Zhu Yanjun) [Orabug: 39839300] {CVE-2026-64582}
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni) {CVE-2026-74390}
- bus: sunxi-rsb: Always check register address validity (Samuel Holland)
- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (Shiraz Saleem)
- pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez)
- cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng)
- cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang)
- Revert "treewide: Fix probing of devices in DT overlays" (Saravana Kannan)
- driver core: Use mod_delayed_work to prevent lost deferred probe work (Zhang Yuwei)
- device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev)
- tracing: Bound synthetic-field strings with seq_buf (Pengpeng Hou) {CVE-2026-74391}
- arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node (Harshal Dev)
- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven) {CVE-2026-80649}
- media: rockchip: rga: fix too small buffer size (Sven Püschel)
- net/sched: sch_drr: annotate data-races around cl->deficit (Eric Dumazet)
- regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions (Chen-Yu Tsai)
- bitops: use common function parameter names (Randy Dunlap)
- sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman)
- firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla)
- staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() (Jose A. Perez de Azpillaga)
- media: atomisp: gc2235: fix UAF and memory leak (Yuho Choi) {CVE-2026-80650}
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan)
- selftests/mm: Fix resv_sz when parsing arm64 signal frame (Kevin Brodsky)
- selftests/bpf: Reject unsupported -k option in vmtest.sh (Roman Kvasnytskyi)
- drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (Liviu Dudau) {CVE-2026-74393}
- RDMA/hns: Initialize seqfile before creating file (Junxian Huang)
- RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh) {CVE-2026-74394}
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande) {CVE-2026-74395}
- RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov)
- IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier (Prathamesh Deshpande) {CVE-2026-74397}
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li) {CVE-2026-74398}
- net/sched: sch_htb: annotate data-races (I) (Eric Dumazet)
- net/sched: sch_htb: do not change sch->flags in htb_dump() (Eric Dumazet)
- spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (Maqiang)
- crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson) {CVE-2026-80652}
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet)
- clk: scpi: Unregister child clock providers on remove (Stepan Ionichev)
- thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki)
- evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou) {CVE-2026-74399}
- drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He)
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He)
- arm64: dts: qcom: sm8450: Fix ICE reg size (Kuldeep Singh)
- arm64: dts: qcom: kodiak: Fix ICE reg size (Kuldeep Singh)
- clk: scmi: Fix clock rate rounding (Cristian Marussi)
- rust: alloc: fix Vec::extend_with SAFETY comment (Hsiu Che Yu)
- arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host (Chen-Yu Tsai)
- iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson)
- media: qcom: camss: vfe: fix PIX subdev naming on VFE lite (Wenmeng Liu)
- nilfs2: fix backing_dev_info reference leak (Shuangpeng Bai)
- dlm: fix add msg handle in send_queue ordered (Alexander Aring) {CVE-2026-74401}
- ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD (Krzysztof Kozlowski)
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794400] {CVE-2026-64544}
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum)
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch) {CVE-2026-74402}
- crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (Tycho Andersen) {CVE-2026-74404}
- vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). (Kuniyuki Iwashima) {CVE-2026-74406}
- arm64: dts: imx8x-colibri: Correct SODIMM PAD settings (Peng Fan)
- arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc (Weixin Guo)
- drm/gpuvm: take refcount on DRM device (Alice Ryhl)
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu)
- crypto: qat - fix heartbeat error injection (Damian Muszynski)
- memory: tegra: Wire up system sleep PM ops (Ashish Mhetre)
- media: v4l2-common: Add YUV24 format info (Nas Chung)
- media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland)
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu)
- watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (Balakrishnan Sambath)
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie)
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi)
- wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani) {CVE-2026-74408}
- soc: xilinx: Shutdown and free rx mailbox channel (Prasanna Kumar T S M) {CVE-2026-80654}
- kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng)
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani) {CVE-2026-74410}
- wifi: rtw89: Correct data type for scan index to avoid infinite loop (Shin-Yi Lin) {CVE-2026-74411}
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (Danilo Krummrich) {CVE-2026-80677}
- drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (Srinivasan Shanmugam)
- dt-bindings: pinctrl: nvidia,tegra234: Add missing required block (Krzysztof Kozlowski)
- arm64: tegra: Fix Tegra234 MGBE PTP clock (Jonathan Hunter)
- wifi: cfg80211: fix grammar in MLO group key error message (Louis Kotze)
- arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning (Krzysztof Kozlowski)
- arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning (Krzysztof Kozlowski)
- arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S (Diederik de Haas)
- Documentation: proc: fix section numbering in table of contents (Baolin Liu)
- selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern (Gregory Bell)
- selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable (Gregory Bell)
- drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (Yang Wang)
- libbpf: Report error when a negative kprobe offset is specified (Aaron Tomlin)
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi) {CVE-2026-74416}
- drm/radeon: fix integer overflow in radeon_align_pitch() (Werner Kasselman) {CVE-2026-74417}
- drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (Werner Kasselman)
- drm/gpuvm: Do not prepare NULL objects (Jonathan Cavitt)
- drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen)
- drm/rockchip: Test for imported buffers with drm_gem_is_imported() (Thomas Zimmermann)
- clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() (Chen Ni)
- fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges) {CVE-2026-74424}
- afs: Fix further netns teardown to cancel the preallocation charger (David Howells)
- afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev) {CVE-2026-74426}
- afs: Fix netns teardown to cancel the preallocation charger (David Howells) {CVE-2026-74427}
- rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) (David Howells) {CVE-2026-74432}
- rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc (Jeffrey E Altman) {CVE-2026-74435}
- serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser)
- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)
- serial: msm: Disable DMA for kernel console UART (Stephan Gerhold)
- dt-bindings: power: imx93: Add MIPI PHY power domain (Guoniu Zhou)
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai)
- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)
- media: uvcvideo: Relax the constrains for interpolating the hw clock (Ricardo Ribalda)
- media: uvcvideo: Do not add clock samples with small sof delta (Ricardo Ribalda)
- media: uvcvideo: Fix dev_sof filtering in hw timestamp (Ricardo Ribalda)
- media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda)
- media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda)
- media: uvcvideo: Use hw timestaming if the clock buffer is full (Ricardo Ribalda)
- time/jiffies: Change register_refined_jiffies() to void __init (Su Hui)
- time/jiffies: Register jiffies clocksource before usage (Thomas Gleixner) [Orabug: 39859302] {CVE-2026-68092}
- crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers)
- crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: crypto4xx - Remove ahash-related code (Herbert Xu)
- af_unix: Drop all SCM attributes for SOCKMAP. (Kuniyuki Iwashima) [Orabug: 39621760] {CVE-2026-53005}
- af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg(). (Kuniyuki Iwashima)
- af_unix/scm: fix whitespace errors (Alexander Mikhalitsyn)
- af_unix: Set drop reason in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Set drop reason in manage_oob(). (Kuniyuki Iwashima)
- af_unix: Set drop reason in unix_release_sock(). (Kuniyuki Iwashima)
- net: dropreason: Gather SOCKET_ drop reasons. (Kuniyuki Iwashima)
- x86/mm: Fix check/use ordering in switch_mm_irqs_off() (Stephen Dolan)
- iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (Vasant Hegde)
- iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (Vasant Hegde)
- crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers) {CVE-2026-74438}
- vsock/virtio: bind uarg before filling zerocopy skb (Jingguo Tan) [Orabug: 39754453] {CVE-2026-63970}
- vsock/virtio: fix zerocopy completion for multi-skb sends (Stefano Garzarella) [Orabug: 39727131] {CVE-2026-53365}
- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg) [Orabug: 39789576] {CVE-2026-64535}
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789572] {CVE-2026-64534}
- timekeeping: Register default clocksource before taking tk_core.lock (Mikhail Gavrilov)
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (Michael Bommarito) {CVE-2026-74439}
- iommu/vt-d: Cleanup intel_context_flush_present() (Lu Baolu)
- KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (Hyunwoo Kim) [Orabug: 39785845] {CVE-2026-64286}
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (Hyunwoo Kim) [Orabug: 39785848] {CVE-2026-64287}
- crypto: algif_skcipher - force synchronous processing (Muhammet Kaan Kilinç)
- sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li)
- bpf: Prefer dirty packs for eBPF allocations (Pawan Gupta)
- bpf: Prefer packs that won't trigger an IBPB flush on allocation (Pawan Gupta)
- bpf: Skip redundant IBPB in pack allocator (Pawan Gupta)
- bpf: Restrict JIT predictor flush to cBPF (Pawan Gupta)
- bpf: Support for hardening against JIT spraying (Pawan Gupta) [Orabug: 39786495] {CVE-2026-64508}
- tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). (Kuniyuki Iwashima) [Orabug: 39637728] {CVE-2026-53260}
- iommu/vt-d: Clear Present bit before tearing down context entry (Lu Baolu) [Orabug: 39451910] {CVE-2026-45944}
- smb/server: do not require delete access for non-replacing links (Chenxiaosong)
- LTS version: v6.12.96 (Sherry Yang)
- xfs: don't zap bmbt forks if they are MAXLEVELS tall (Darrick J. Wong)
- xfs: fully check the parent handle when it points to the rootdir (Darrick J. Wong)
- xfs: clamp timestamp nanoseconds correctly (Darrick J. Wong)
- xfs: set xfarray killable sort correctly (Darrick J. Wong)
- xfs: don't wrap around quota ids in dqiterate (Darrick J. Wong) [Orabug: 39785773] {CVE-2026-64256}
- xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760869] {CVE-2026-64187}
- xfs: fix null pointer dereference in tracepoint (Andrey Albershteyn)
- smb: client: reject overlapping data areas in SMB2 responses (Shoichiro Miyamoto) [Orabug: 39838902] {CVE-2026-64257}
- usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks (Neill Kapron) {CVE-2026-64327}
- fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Ji'An Zhou) [Orabug: 39785783] {CVE-2026-64265}
- fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785785] {CVE-2026-64266}
- fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz)
- RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito) {CVE-2026-64268}
- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan) {CVE-2026-64269}
- Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov)
- Input: maplemouse - set driver data before registering input device (Dmitry Torokhov)
- Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov)
- Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov)
- Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs)
- Input: mms114 - reject an oversized device packet size (Bryam Vargas) [Orabug: 39785797] {CVE-2026-64270}
- Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785801] {CVE-2026-64271}
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov) [Orabug: 39785806] {CVE-2026-64272}
- Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas) {CVE-2026-64273}
- Input: goodix - clamp the device-reported contact count (Bryam Vargas) {CVE-2026-64274}
- Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785818] {CVE-2026-64275}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785822] {CVE-2026-64276}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas) {CVE-2026-64277}
- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li)
- i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodríguez)
- i2c: mpc: Fix timeout calculations (Andy Shevchenko)
- i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785830] {CVE-2026-64279}
- i2c: core: fix adapter debugfs creation (Johan Hovold)
- i2c: core: fix adapter probe deferral loop (Johan Hovold)
- i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold) [Orabug: 39843575] {CVE-2026-64589}
- i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold)
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov) {CVE-2026-64590}
- udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov)
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843614] {CVE-2026-64604}
- KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits (Sean Christopherson) [Orabug: 39785842] {CVE-2026-64284}
- KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs (Sean Christopherson)
- iommufd: Set upper bounds on cache invalidation entry_num and entry_len (Nicolin Chen) [Orabug: 39785851] {CVE-2026-64289}
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)
- selftests/mm: pagemap_ioctl: use the correct page size for transact_test() (Zenghui Yu)
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato) [Orabug: 39785858] {CVE-2026-64294}
- selftests: mm: fix and speedup "droppable" test (David Hildenbrand)
- mm: fix mmap errno value when MAP_DROPPABLE is not supported (Anthony Yznaga)
- riscv: mm: Unconditionally sfence.vma for spurious fault (Vivian Wang) {CVE-2026-64592}
- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den)
- exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785862] {CVE-2026-64296}
- module: decompress: check return value of module_extend_max_pages() (Andrii Kuchmenko) {CVE-2026-64297}
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785867] {CVE-2026-64298}
- audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina)
- tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785871] {CVE-2026-64299}
- i2c: core: fix hang on adapter registration failure (Johan Hovold)
- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang) {CVE-2026-64301}
- watchdog: apple: Add "apple,t8103-wdt" compatible (Janne Grunau)
- EDAC/i10nm: Don't fail probing if ADXL is missing (Vasiliy Khoruzhick)
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song) {CVE-2026-64303}
- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song)
- arm64: fpsimd: Fix type mismatch in sme_{save,load}_state() (Mark Rutland)
- crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation (Paul Louvel)
- crypto: talitos/hash - remove useless wrapper (Paul Louvel)
- crypto: talitos/hash - rename first_desc/last_desc to first_request/last_request (Paul Louvel)
- crypto: talitos/hash - drop workqueue mechanism for SEC1 (Paul Louvel)
- crypto: talitos/hash - use descriptor chaining for SEC1 instead of workqueue (Paul Louvel)
- crypto: talitos/hash - prepare SEC1 descriptor chaining, remove additional descriptor (Paul Louvel)
- crypto: talitos - move code in current_desc_hdr() into a standalone function (Paul Louvel)
- crypto: talitos - move dma mapping code in talitos_submit() into a standalone dma_map_request() function (Paul Louvel)
- crypto: talitos - move dma unmapping code in flush_channel() into a standalone dma_unmap_request() function (Paul Louvel)
- crypto: talitos - add chaining of arbitrary number of descriptor for the SEC1 (Paul Louvel)
- crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel)
- crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785884] {CVE-2026-64304}
- crypto: qat - protect service table iterations with service_lock (Ahsan Atta) [Orabug: 39785888] {CVE-2026-64305}
- crypto: qat - notify fatal error before AER reset preparation (Ahsan Atta)
- crypto: qat - keep VFs enabled during reset (Ahsan Atta)
- crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers)
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers)
- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785892] {CVE-2026-64306}
- crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (Tycho Andersen) [Orabug: 39785898] {CVE-2026-64308}
- crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (Tycho Andersen) [Orabug: 39785900] {CVE-2026-64309}
- crypto: ccp - Do not initialize SNP for SEV ioctls (Tycho Andersen) [Orabug: 39785902] {CVE-2026-64310}
- crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (Xu Wang)
- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785905] {CVE-2026-64312}
- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785909] {CVE-2026-64313}
- crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum) {CVE-2026-64315}
- crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers)
- isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785922] {CVE-2026-64317}
- partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas) {CVE-2026-64318}
- btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843585] {CVE-2026-64593}
- nvmet-auth: validate reply message payload bounds against transfer length (Tianchu Chen) [Orabug: 39785930] {CVE-2026-64319}
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (Bryam Vargas) [Orabug: 39785933] {CVE-2026-64320}
- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi)
- dm-ioctl: report an error if a device has no table (Mikulas Patocka)
- nvme: target: rdma: fix ndev refcount leak on queue connect (Xu Wang) [Orabug: 39785937] {CVE-2026-64321}
- hwrng: jh7110 - fix refcount leak in starfive_trng_read() (Xu Wang)
- udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785939] {CVE-2026-64322}
- udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785943] {CVE-2026-64323}
- udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785947] {CVE-2026-64324}
- x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (Reinette Chatre) [Orabug: 39786413] {CVE-2026-64477}
- block: skip sync_blockdev() on surprise removal in bdev_mark_dead() (Chao Shi) [Orabug: 39785953] {CVE-2026-64326}
- usb: gadget: f_fs: Fix DMA fence leak (Paul Cercueil) {CVE-2026-64328}
- usb: typec: ucsi: cancel pending work on system suspend (Paul Menzel)
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu) {CVE-2026-64329}
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M)
- usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski)
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785962] {CVE-2026-64330}
- usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan)
- usb: typec: class: drop PD lookup reference (Shuangpeng Bai)
- usb: typec: anx7411: use devm_pm_runtime_enable() (Myeonghun Pak)
- usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day) {CVE-2026-64331}
- usbip: tools: support SuperSpeedPlus devices (Chenyichong)
- USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao)
- USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785970] {CVE-2026-64332}
- USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785974] {CVE-2026-64333}
- USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785978] {CVE-2026-64334}
- USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785982] {CVE-2026-64335}
- USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda)
- USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785986] {CVE-2026-64336}
- usb: mtu3: unmap request DMA on queue failure (Haoxiang Li) {CVE-2026-64337}
- USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785993] {CVE-2026-64338}
- USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao)
- usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak)
- USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785998] {CVE-2026-64340}
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover)
- USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786006] {CVE-2026-64342}
- USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786011] {CVE-2026-64343}
- USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786016] {CVE-2026-64344}
- usb: gadget: f_printer: take kref only for successful open (Xu Rao) {CVE-2026-64345}
- usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu) {CVE-2026-64346}
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie) {CVE-2026-64347}
- usb: free iso schedules on failed submit (Dawei Feng) [Orabug: 39786033] {CVE-2026-64348}
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang)
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceição Alves)
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li) {CVE-2026-64350}
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge)
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786041] {CVE-2026-64351}
- bpf: Validate BTF repeated field counts before expansion (Paul Moses) [Orabug: 39786049] {CVE-2026-64354}
- bpf: Restore sysctl new-value from 1 to 0 (Dawei Feng)
- bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786051] {CVE-2026-64355}
- xfs: fix exchmaps reservation limit check (Gao Yingjie) [Orabug: 39786055] {CVE-2026-64357}
- xfs: fix pointer arithmetic error on 32-bit systems (Darrick J. Wong)
- xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih)
- xfs: release dquot buffer after dqflush failure (Gao Yingjie)
- xfs: use null daddr for unset first bad log block (Yousef Alhouseen)
- serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko)
- media: mtk-jpeg: cancel workqueue on release for supported platforms only (Louis-Alexis Eyraud) {CVE-2026-64358}
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey) {CVE-2026-64359}
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani) {CVE-2026-64360}
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada)
- HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786070] {CVE-2026-64362}
- HID: letsketch: fix UAF on inrange_timer at driver unbind (Manish Khadka) [Orabug: 39786080] {CVE-2026-64365}
- HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859298] {CVE-2026-68091}
- HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (Tianchu Chen) {CVE-2026-64367}
- tools/mm/slabinfo: fix total_objects attribute name (Chenyichong)
- tools/mm/slabinfo: Fix trace disable logic inversion (Xuewen Wang)
- mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (Vlastimil Babka) [Orabug: 39786085] {CVE-2026-64368}
- X.509: Fix validation of ASN.1 certificate header (Lukas Wunner)
- perf/arm-cmn: Fix DVM node events (Robin Murphy)
- clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances (Kartik)
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786090] {CVE-2026-64370}
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786099] {CVE-2026-64372}
- cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786103] {CVE-2026-64373}
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786107] {CVE-2026-64374}
- cpufreq: intel_pstate: Sync policy->cur during CPU offline (Wangfushuai)
- firmware_loader: fix device reference leak in firmware_upload_register() (Guangshuo Li) [Orabug: 39786115] {CVE-2026-64376}
- cpufreq: qcom-cpufreq-hw: Fix possible double free (Guangshuo Li) {CVE-2026-64377}
- OPP: of: Fix potential memory leak in opp_parse_supplies() (Abdun Nihaal)
- writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (Baokun Li) [Orabug: 39786119] {CVE-2026-64378}
- smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786123] {CVE-2026-64379}
- smb: client: fix atime clamp check in read completion (Xu Rao)
- smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786127] {CVE-2026-64380}
- smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi)
- smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786130] {CVE-2026-64381}
- smb: client: fix double-free in SMB2_close() replay (Henrique Carvalho) [Orabug: 39843598] {CVE-2026-64597}
- smb: client: fix double-free in SMB2_open() replay (Henrique Carvalho) [Orabug: 39786135] {CVE-2026-64382}
- smb: client: fix double-free in SMB2_flush() replay (Zhao Zhang) [Orabug: 39786137] {CVE-2026-64383}
- smb: client: fix change notify replay double-free (Henrique Carvalho) [Orabug: 39786139] {CVE-2026-64384}
- smb: client: fix double-free in SMB2_ioctl() replay (Henrique Carvalho) [Orabug: 39786141] {CVE-2026-64385}
- smb: client: fix query_info() replay double-free (Henrique Carvalho) [Orabug: 39786143] {CVE-2026-64386}
- smb: client: fix query directory replay double-free (Henrique Carvalho) [Orabug: 39786145] {CVE-2026-64387}
- ksmbd: use opener credentials for ADS I/O (Namjae Jeon) {CVE-2026-64391}
- ksmbd: use opener credentials for delete-on-close (Namjae Jeon) {CVE-2026-64392}
- ksmbd: add per-handle permission check to FILE_LINK_INFORMATION (Gil Portnoy)
- ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION (Gil Portnoy)
- ksmbd: run set info with opener credentials (Namjae Jeon) {CVE-2026-64393}
- ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY (Gil Portnoy) {CVE-2026-64394}
- ksmbd: require source read access for duplicate extents (Namjae Jeon) {CVE-2026-64395}
- ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation (Davide Ornaghi) {CVE-2026-64396}
- ksmbd: serialize QUERY_DIRECTORY requests per file (Namjae Jeon) {CVE-2026-64397}
- ksmbd: add a permission check for FSCTL_SET_ZERO_DATA (Gil Portnoy) {CVE-2026-64398}
- ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE (Gil Portnoy) {CVE-2026-64399}
- smb/client: Fix error code in smb2_aead_req_alloc() (Dan Carpenter) [Orabug: 39843601] {CVE-2026-64598}
- coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() (Junrui Luo) {CVE-2026-64402}
- fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() (Deepanshu Kartikey)
- fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio() (Konstantin Komarov)
- fs/ntfs3: fsync files by syncing parent inodes (Konstantin Komarov)
- fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr (Konstantin Komarov)
- Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786204] {CVE-2026-64403}
- Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (Muhammad Bilal) [Orabug: 39786209] {CVE-2026-64404}
- Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (Pauli Virtanen) [Orabug: 39860413] {CVE-2026-68085}
- Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786577] {CVE-2026-64406}
- Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (Maoyi Xie) {CVE-2026-64407}
- Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786216] {CVE-2026-64408}
- Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (Sergey Senozhatsky) {CVE-2026-64409}
- netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786223] {CVE-2026-64411}
- netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786227] {CVE-2026-64412}
- netfilter: handle unreadable frags (Florian Westphal) [Orabug: 39786235] {CVE-2026-64414}
- netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump (Pratham Gupta)
- mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup (Zijiang Huang) [Orabug: 39786237] {CVE-2026-64415}
- mm: shrinker: fix NULL pointer dereference in debugfs (Qi Zheng) {CVE-2026-64417}
- mm: shrinker: fix shrinker_info teardown race with expansion (Qi Zheng) [Orabug: 39786243] {CVE-2026-64418}
- mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() (Shakeel Butt) {CVE-2026-64419}
- mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786247] {CVE-2026-64420}
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786253] {CVE-2026-64422}
- ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786258] {CVE-2026-64423}
- netpoll: fix a use-after-free on shutdown path (Breno Leitao) [Orabug: 39786263] {CVE-2026-64424}
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786573] {CVE-2026-64425}
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao) {CVE-2026-64429}
- NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den) {CVE-2026-64430}
- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian) {CVE-2026-64432}
- debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner) {CVE-2026-68090}
- coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao)
- Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (Samuel Page) [Orabug: 39786285] {CVE-2026-64433}
- audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786288] {CVE-2026-64435}
- net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786292] {CVE-2026-64436}
- ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL (Gil Portnoy) {CVE-2026-64437}
- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843603] {CVE-2026-64599}
- staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu) {CVE-2026-64440}
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu) {CVE-2026-64536}
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu) {CVE-2026-64442}
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu) {CVE-2026-64443}
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu) {CVE-2026-64444}
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu) {CVE-2026-64445}
- staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu) {CVE-2026-64446}
- staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann)
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda)
- staging: vme_user: fix location monitor leak in tsi148 bridge (Hao-Qun Huang) {CVE-2026-68084}
- staging: vme_user: fix location monitor leak in fake bridge (Hao-Qun Huang)
- smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786331] {CVE-2026-64448}
- staging: vme_user: bound slave read/write to the kern_buf size (Michael Tautschnig) {CVE-2026-64449}
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786339] {CVE-2026-64450}
- 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786343] {CVE-2026-64452}
- usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao) {CVE-2026-64454}
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786351] {CVE-2026-64455}
- hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786355] {CVE-2026-64456}
- virtio-mmio: fix device release warning on module unload (Johan Hovold)
- netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760881] {CVE-2026-64189}
- mm/damon/ops-common: handle extreme intervals in damon_hot_score() (Seongjae Park) [Orabug: 39786361] {CVE-2026-64458}
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu)
- PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth)
- PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya)
- PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000 series (Ziyao Li)
- usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (Myeonghun Pak) {CVE-2026-64463}
- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786378] {CVE-2026-64465}
- binder: fix UAF in binder_free_transaction() (Carlos Llamas) {CVE-2026-64468}
- binder: fix UAF in binder_thread_release() (Carlos Llamas) {CVE-2026-64469}
- Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold)
- Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786392] {CVE-2026-64470}
- Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786396] {CVE-2026-64471}
- Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (Zenm Chen)
- vfio: Remove device debugfs before releasing devres (Alex Williamson) [Orabug: 39786403] {CVE-2026-64473}
- vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc (Junrui Luo) [Orabug: 39786405] {CVE-2026-64474}
- vfio/pci: Fix racy bitfields and tighten struct layout (Alex Williamson)
- vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786408] {CVE-2026-64475}
- vfio/pci: Latch disable_idle_d3 per device (Alex Williamson) [Orabug: 39786411] {CVE-2026-64476}
- vfio/pci: Use a private flag to prevent power state change with VFs (Raghavendra Rao Ananta)
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Roll back quirk control caches on write errors (Cássio Gabriel)
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cássio Gabriel)
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cássio Gabriel)
- ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786415] {CVE-2026-64478}
- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39786419] {CVE-2026-64479}
- ALSA: ice1712: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786421] {CVE-2026-64480}
- ALSA: gus: check snd_ctl_new1() return value (Zhao Dongdong) {CVE-2026-64482}
- ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie) {CVE-2026-64483}
- ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786431] {CVE-2026-64484}
- ALSA: cmipci: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786436] {CVE-2026-64486}
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786438] {CVE-2026-64487}
- ALSA: ymfpci: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786446] {CVE-2026-64489}
- ALSA: virtio: Validate control metadata from the device (Cássio Gabriel) [Orabug: 39786448] {CVE-2026-64490}
- ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cássio Gabriel)
- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan)
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan)
- iio: temperature: Build mlx90635 with CONFIG_MLX90635 (Pengpeng Hou)
- iio: resolver: ad2s1210: notify trigger and clear state on fault read error (Stepan Ionichev)
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko)
- iio: light: veml6030: fix channel type when pushing events (Javier Carrasco)
- iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev)
- iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts)
- iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya) {CVE-2026-64494}
- iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal)
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe)
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol)
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao)
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao)
- iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev)
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev) {CVE-2026-64495}
- iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786461] {CVE-2026-64496}
- iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk)
- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose) {CVE-2026-64497}
- iio: backend: fix uninitialized data in debugfs (Dan Carpenter)
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou)
- iio: adc: ti-ads1119: fix PM reference leak in buffer preenable (Guangshuo Li) {CVE-2026-64499}
- iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose) {CVE-2026-64602}
- iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose) {CVE-2026-64500}
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786477] {CVE-2026-64503}
- iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786481] {CVE-2026-64504}
- usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman) {CVE-2026-64505}
- usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman) {CVE-2026-68088}
- drm/i915: ensure segment offset never exceeds allowed max (Krzysztof Karas)
- rust: kasan: KASAN+RUST requires clang (Alice Ryhl)
- perf/core: Detach event groups during remove_on_exec (Taeyang Lee) [Orabug: 39802877] {CVE-2026-64556}
- rust: Kbuild: set frame-pointer llvm module flag for CONFIG_FRAME_POINTER (Alice Ryhl)
- LoongArch: Add PIO for early access before ACPI PCI root register (Huacai Chen)
- platform/x86: intel-hid: Protect ACPI notify handler against recursion (Hyeongjun An) [Orabug: 39843612] {CVE-2026-64603}
- ACPI: NFIT: core: Fix possible NULL pointer dereference (Rafael J. Wysocki) [Orabug: 39786505] {CVE-2026-64511}
- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786507] {CVE-2026-64512}
- perf trace beauty fcntl: Fix build with older kernel headers (Florian Fainelli)
- mm/khugepaged: write all dirty file folios when collapsing (Pedro Falcato)
- block: fix queue freeze vs limits lock order in sysfs store methods (Christoph Hellwig) [Orabug: 37650414] {CVE-2025-21807}
- block: add a store_limit operations for sysfs entries (Christoph Hellwig)
- bonding: fix xfrm offload feature setup on active-backup mode (Hangbin Liu)
- nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown)
- nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown)
- apparmor: advertise the tcp fast open fix is applied (John Johansen)
- locking/rtmutex: Make sure we wake anything on the wake_q when we release the lock->wait_lock (John Stultz)
- NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753893] {CVE-2026-53392}
- NFSv4/flexfiles: Add data structure support for striped layouts (Jonathan Curley)
- NFSv4/flexfiles: Remove cred local variable dependency (Jonathan Curley)
- nfs_common: rename functions that invalidate LOCALIO nfs_clients (Mike Snitzer)
- nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations (Mike Snitzer)
- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753923] {CVE-2026-53402}
- f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma) {CVE-2026-80591}
- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu) {CVE-2026-68459}
- f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi) {CVE-2026-68460}
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas)
- f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode (Chao Yu)
- f2fs: validate orphan inode entry count (Wenjie Qi)
- device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski) {CVE-2026-68461}
- mm/vmalloc: take vmap_purge_lock in shrinker (Uladzislau Rezki) [Orabug: 39452440] {CVE-2026-46093}
- gpio: rockchip: fix generic IRQ chip leak on remove (Marco Scardovi) [Orabug: 39637612] {CVE-2026-53226}
- gpio: rockchip: teardown bugs and resource leaks (Marco Scardovi) [Orabug: 39785165] {CVE-2026-64241}
- gpio: rockchip: change the GPIO version judgment logic (Ye Zhang)
- drm/amd: Fix set but not used warnings (Tiezhu Yang)
- bcachefs: avoid truncating fiemap extent length (Mikhail Dmitrichenko)
- perf: Fix dangling cgroup pointer in cpuctx backport (Guan Wentao)
- userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786514] {CVE-2026-64514}
- nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753911] {CVE-2026-53399}
- nfsd: fix file change detection in CB_GETATTR (Scott Mayhew)
- bpf, arm64: Reject out-of-range B.cond targets (Daniel Borkmann)
- LTS version: v6.12.95 (Sherry Yang)
- bonding: do not set usable_slaves for broadcast mode (Hangbin Liu)
- bonding: annotate data-races arcound churn variables (Eric Dumazet)
- net: bonding: update the slave array for broadcast mode (Tonghao Zhang)
- locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex (John Stultz)
- net/tcp-ao: fix use-after-free of key in del_async path (Ji'An Zhou)
- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786548] {CVE-2026-64529}
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)
- Documentation: ioctl-number: Extend "Include File" column width (Bagas Sanjaya)
- Documentation: ioctl-number: Fix linuxppc-dev mailto link (Bagas Sanjaya)
- drivers/base/memory: set mem->altmap after successful device registration (Georgi Djakov) [Orabug: 39785174] {CVE-2026-64244}
- serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails (Stepan Ionichev) [Orabug: 39753867] {CVE-2026-53384}
- NFS: Prevent resource leak in nfs_alloc_server() (Markus Elfring)
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753889] {CVE-2026-53391}
- nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753897] {CVE-2026-53393}
- nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race (Jeff Layton) [Orabug: 39753900] {CVE-2026-53394}
- nfsd: check get_user() return when reading princhashlen (Dominik Woźniak)
- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753904] {CVE-2026-53397}
- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753908] {CVE-2026-53398}
- i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753915] {CVE-2026-53400}
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)
- fbdev: modedb: fix a possible UAF in fb_find_mode() (Tuo Li) [Orabug: 39785177] {CVE-2026-64245}
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753927] {CVE-2026-53403}
- riscv: kfence: Call mark_new_valid_map() for kfence_unprotect() (Vivian Wang)
- riscv: mm: Extract helper mark_new_valid_map() (Vivian Wang)
- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753935] {CVE-2026-63794}
- KVM: x86: hyper-v: Bound the bank index when querying sparse banks (Hyunwoo Kim) [Orabug: 39785185] {CVE-2026-64247}
- 9p: avoid putting oldfid in p9_client_walk() error path (Yizhou Zhao) [Orabug: 39753939] {CVE-2026-63795}
- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753941] {CVE-2026-63796}
- rpmsg: char: Fix use-after-free on probe error path (Yuho Choi)
- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)
- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753952] {CVE-2026-63800}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753956] {CVE-2026-63801}
- blk-cgroup: fix UAF in __blkcg_rstat_flush() (Michal Koutný) [Orabug: 39753959] {CVE-2026-63802}
- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753962] {CVE-2026-63803}
- pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() (Xu Wang) [Orabug: 39785195] {CVE-2026-64251}
- gfs2: fix use-after-free in gfs2_qd_dealloc (Tristan Madani) [Orabug: 39753966] {CVE-2026-63804}
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753971] {CVE-2026-63806}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753978] {CVE-2026-63808}
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)
- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753981] {CVE-2026-63809}
- block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753984] {CVE-2026-63810}
- f2fs: keep atomic write retry from zeroing original data (Wenjie Qi)
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)
- f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong)
- f2fs: validate compress cache inode only when enabled (Wenjie Qi)
- wifi: iwlwifi: mvm: fix race condition in PTP removal (Junjie Cao)
- wifi: rtw88: usb: fix memory leaks on USB write failures (Luka Gejak) [Orabug: 39754018] {CVE-2026-63821}
- wifi: rtw88: increase TX report timeout to fix race condition (Luka Gejak)
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)
- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754020] {CVE-2026-63822}
- wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (Elxreno)
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)
- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754023] {CVE-2026-63823}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754027] {CVE-2026-63824}
- err.h: use __always_inline on all error pointer helpers (Arnd Bergmann)
- block: invalidate cached plug timestamp after task switch (Usama Arif)
- kernel/fork: clear PF_BLOCK_TS in copy_process() (Usama Arif) [Orabug: 39785201] {CVE-2026-64253}
- fbdev: fix use-after-free in store_modes() (Ian Bridges) [Orabug: 39754035] {CVE-2026-63826}
- NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR (Koichiro Den)
- apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas)
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754044] {CVE-2026-63829}
- net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754048] {CVE-2026-63830}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754052] {CVE-2026-63831}
- mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (Cheng Ming Lin)
- mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (Cheng Ming Lin)
- af_unix: Set gc_in_progress to true in unix_gc(). (Kuniyuki Iwashima) [Orabug: 39686465] {CVE-2026-53361}
- KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (Sean Christopherson)
- KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (Sean Christopherson)
- ntfs3: reject direct userspace writes to reserved $LX* xattrs (Konstantin Komarov)
- selinux: fix overlayfs mmap() and mprotect() access checks (Paul Moore) [Orabug: 39452299] {CVE-2026-46054}
- lsm: add backing_file LSM hooks (Paul Moore)
- fs: constify file ptr in backing_file accessor helpers (Amir Goldstein)
- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)
- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)
- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)
- batman-adv: tt: track roam count per VID (Sven Eckelmann)
- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)
- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)
- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)
- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754065] {CVE-2026-63834}
- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754069] {CVE-2026-63835}
- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)
- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)
- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)
- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)
- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)
- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)
- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754075] {CVE-2026-63836}
- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)
- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)
- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)
- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)
- KVM: SEV: Ignore Port I/O requests of length '0' (Sean Christopherson) [Orabug: 39754368] {CVE-2026-63940}
- KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (Sean Christopherson)
- KVM: SEV: Ignore MMIO requests of length '0' (Sean Christopherson)
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39753975] {CVE-2026-63807}
- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753855] {CVE-2026-53381}
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)
- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)
- serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (Viken Dadhaniya)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753870] {CVE-2026-53385}
- iio: adc: ti-ads1298: add bounds check to pga_settings index (Sam Daly)
- iio: light: veml6075: add bounds check to veml6075_it_ms index (Sam Daly)
- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753882] {CVE-2026-53388}
- rxrpc: Fix the ACK parser to extract the SACK table for parsing (David Howells) [Orabug: 39637359] {CVE-2026-53151}
- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri)
- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)
- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)
- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)
- fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (Jann Horn) [Orabug: 39674292] {CVE-2026-53341}
- staging: rtl8723bs: fix buffer over-read in rtw_update_protection (Salman Alghamdi)
- bonding: fix NULL pointer dereference in actor_port_prio setting (Hangbin Liu)
- net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39205989,39556377] {CVE-2026-31419}
- bonding: 3ad: implement proper RCU rules for port->aggregator (Eric Dumazet) [Orabug: 39621644] {CVE-2026-52975}
- bonding: print churn state via netlink (Hangbin Liu)
- bonding: add support for per-port LACP actor priority (Hangbin Liu)
- net: bonding: add broadcast_neighbor option for 802.3ad (Tonghao Zhang)
- xfs: fix error returns in CoW fork repair (Gao Yingjie)
- xfs: remove the expr argument to XFS_TEST_ERROR (Christoph Hellwig)
- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844552] {CVE-2025-23131}
- regulator: core: fix locking in regulator_resolve_supply() error path (André Draszik) [Orabug: 39489557] {CVE-2026-46252}
- ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() (Yicong Yang)
- selftests/bpf: Add test to ensure kprobe_multi is not sleepable (Varun R Mallya)
- bpf: Reject sleepable kprobe_multi programs at attach time (Varun R Mallya) [Orabug: 39300836] {CVE-2026-43010}
- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662072] {CVE-2026-53325}
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)
- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760891] {CVE-2026-64191}
- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg) {CVE-2026-74584}
- debugobjects: Dont call fill_pool() in early boot hardirq context (Waiman Long)
- debugobjects: Do not fill_pool() if pi_blocked_on (Helen Koike)
- debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP (Sebastian Andrzej Siewior)
- debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING (Sebastian Andrzej Siewior)
- Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589884] {CVE-2026-52909}
- net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331700] {CVE-2026-43216}
- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)
- drm/v3d: Skip CSD when it has zeroed workgroups (Maíra Canal)
- drm/v3d: Store the active job inside the queue's state (Maíra Canal)
- drm/xe/display: fix oops in suspend/shutdown without display (Jani Nikula) [Orabug: 39637326] {CVE-2026-53142}
- io_uring/net: Avoid msghdr on op_connect/op_bind async data (Gabriel Krisman Bertazi)
- gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (Tzung-Bi Shih) [Orabug: 39300677] {CVE-2026-31732}
- gpiolib: Remove redundant assignment of return variable (Andy Shevchenko)
- gpiolib: Extract gpiochip_choose_fwnode() for wider use (Andy Shevchenko)
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637409] {CVE-2026-53167}
- wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (Sean Wang) [Orabug: 39622080] {CVE-2026-53101}
- wifi: mt76: mt7921: fix a potential scan no APs (Quan Zhou)
- wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (Leon Yen)
- LTS version: v6.12.94 (Sherry Yang)
- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637278] {CVE-2026-53131}
- vsock/virtio: fix skb overhead overflow on 32-bit builds (Stefano Garzarella)
- Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation (Tao Cui)
- tcp: secure_seq: add back ports to TS offset (Eric Dumazet) [Orabug: 39103122] {CVE-2026-23247}
- tcp: use EXPORT_IPV6_MOD[_GPL]() (Eric Dumazet)
- net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() (Eric Dumazet)
- vsock/virtio: fix skb overhead accounting to preserve full buf_alloc (Stefano Garzarella)
- vsock/virtio: fix potential unbounded skb queue (Eric Dumazet) [Orabug: 39637282] {CVE-2026-53132}
- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451540] {CVE-2026-45850}
- ipmi:ssif: NULL thread on error (Corey Minyard)
- ipmi:ssif: Remove unnecessary indention (Corey Minyard)
- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)
- mm/hugetlb: avoid false positive lockdep assertion (Lorenzo Stoakes)
- RDMA/umem: Fix truncation for block sizes >= 4G (Jason Gunthorpe)
- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)
- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)
- RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (Jason Gunthorpe) [Orabug: 39589882] {CVE-2026-52908}
- RDMA/umem: Add helpers for umem dmabuf revoke lock (Jacob Moroni)
- RDMA/umem: Move umem dmabuf revoke logic into helper function (Jacob Moroni)
- RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper (Jacob Moroni)
- mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (Ma Wupeng) [Orabug: 39637537] {CVE-2026-53207}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637291] {CVE-2026-53134}
- sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() (Tejun Heo) [Orabug: 39674249] {CVE-2026-53328}
- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637515] {CVE-2026-53199}
- mailbox: Fix NULL message support in mbox_send_message() (Jassi Brar)
- driver core: reject devices with unregistered buses (Johan Hovold)
- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655977] {CVE-2026-52946}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674252] {CVE-2026-53329}
- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637295] {CVE-2026-53135}
- drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (Leorize)
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637300] {CVE-2026-53136}
- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland) [Orabug: 39637306] {CVE-2026-53137}
- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637310] {CVE-2026-53138}
- drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (Priya Hosur)
- drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (Yang Wang)
- drm/amd/pm: fix smu13 power limit default/cap calculation (Yang Wang)
- drm/amdgpu: restart the CS if some parts of the VM are still invalidated (Christian König)
- drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (Maíra Canal)
- drm/xe: Clear pending_disable before signaling suspend fence (Tangudu Tilak Tirumalesh)
- drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (Andrew Martin) [Orabug: 39637328] {CVE-2026-53143}
- drm/amdkfd: fix NULL dereference in get_queue_ids() (Muhammad Bilal) [Orabug: 39637330] {CVE-2026-53144}
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: fix OF node refcount (Bartosz Golaszewski)
- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637336] {CVE-2026-53146}
- thunderbolt: Validate XDomain request packet size before type cast (Michael Bommarito) [Orabug: 39637341] {CVE-2026-53147}
- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637345] {CVE-2026-53148}
- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637350] {CVE-2026-53149}
- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637355] {CVE-2026-53150}
- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619337] {CVE-2026-52929}
- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619277] {CVE-2026-52917}
- rtase: Reset TX subqueue when clearing TX ring (Justin Lai)
- rtase: Avoid sleeping in get_stats64() (Justin Lai)
- pmdomain: imx: fix OF node refcount (Bartosz Golaszewski)
- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)
- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)
- mmc: litex_mmc: Set mandatory idle clocks before CMD0 (Inochi Amaoto)
- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)
- mm/hugetlb: restore reservation on error in hugetlb folio copy paths (David Carlier) [Orabug: 39637364] {CVE-2026-53154}
- io_uring/wait: fix min_timeout behavior (Christian A. Ehrhardt)
- io_uring/kbuf: don't truncate end buffer for bundles (Jens Axboe)
- octeontx2-af: fix memory leak in rvu_setup_hw_resources() (Dawei Feng)
- nvmem: layouts: onie-tlv: fix hang on unknown types (Andre Heider)
- nvmem: core: fix use-after-free bugs in error paths (Bartosz Golaszewski) [Orabug: 39637368] {CVE-2026-53156}
- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)
- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674283] {CVE-2026-53337}
- net/mlx5: Reorder completion before putting command entry in cmd_work_handler (Nikolay Kuratov)
- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)
- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)
- misc: fastrpc: fix use-after-free race in fastrpc_map_create (Zhenghang Xiao)
- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)
- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619341] {CVE-2026-52930}
- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)
- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)
- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)
- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodríguez)
- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)
- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637413] {CVE-2026-53168}
- fs/qnx6: fix pointer arithmetic in directory iteration (Arpith Kalaginanavoor)
- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)
- inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (Hyunwoo Kim) [Orabug: 39839050] {CVE-2026-53175}
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637427] {CVE-2026-53176}
- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637431] {CVE-2026-53177}
- ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write (Chancel Liu)
- timers/migration: Fix livelock in tmigr_handle_remote_up() (Amit Matityahu) [Orabug: 39637444] {CVE-2026-53180}
- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637446] {CVE-2026-53181}
- wifi: nl80211: reject oversized EMA RNR lists (Yuqi Xu) [Orabug: 39637453] {CVE-2026-53182}
- mptcp: add-addr: always drop other suboptions (Matthieu Baerts)
- selftests: mptcp: add test for extra_subflows underflow on userspace PM (Tao Cui)
- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)
- mptcp: allow subflow rcv wnd to shrink (Paolo Abeni) [Orabug: 39637456] {CVE-2026-53183}
- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754145] {CVE-2026-63867}
- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)
- ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow (Karl Mehltretter)
- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)
- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)
- udp: clear skb->dev before running a sockmap verdict (Sechang Lim) [Orabug: 39637458] {CVE-2026-53184}
- zram: fix use-after-free in zram_bvec_write_partial() (Cunlong Li) [Orabug: 39637460] {CVE-2026-53185}
- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637466] {CVE-2026-53186}
- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)
- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637476] {CVE-2026-53189}
- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)
- drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (Xu Wang) [Orabug: 39637480] {CVE-2026-53190}
- io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries (Clément Léger) [Orabug: 39637484] {CVE-2026-53191}
- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637488] {CVE-2026-53192}
- ALSA: timer: Forcibly close timer instances at closing (Takashi Iwai) [Orabug: 39637492] {CVE-2026-53193}
- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637495] {CVE-2026-53194}
- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637501] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637505] {CVE-2026-53196}
- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)
- ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL (Gil Portnoy)
- pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init (Judith Mendez) {CVE-2026-53344}
- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674334] {CVE-2026-53356}
- KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (Sean Christopherson)
- KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (Sean Christopherson) [Orabug: 39674302] {CVE-2026-53345}
- mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (Inochi Amaoto)
- rust: kasan/kbuild: fix rustc-option when cross-compiling (Alice Ryhl)
- rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES (Alice Ryhl)
- rust: x86: support Rust >= 1.98.0 target spec (Miguel Ojeda)
- tracing/probes: Point the error offset correctly for eprobe argument error (Masami Hiramatsu)
- accel/ivpu: Fix signed integer truncation in IPC receive (Andrzej Kacprowski)
- accel/ivpu: Add buffer overflow check in MS get_info_ioctl (Andrzej Kacprowski)
- accel/ivpu: Add bounds checks for firmware log indices (Andrzej Kacprowski)
- soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (Manivannan Sadhasivam)
- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637544] {CVE-2026-53208}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (Yuqi Xu) [Orabug: 39637549] {CVE-2026-53209}
- tee: shm: fix shm leak in register_shm_helper() (Georgiy Osokin) [Orabug: 39637551] {CVE-2026-53210}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637554] {CVE-2026-53212}
- drm/xe: fix refcount leak in xe_range_fence_insert() (Xu Wang)
- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637560] {CVE-2026-53213}
- drm/virtio: Fix driver removal with disabled KMS (Dmitry Osipenko) [Orabug: 39674308] {CVE-2026-53347}
- clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time (Pengyu Luo)
- clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs (Kuan-Wei Chiu)
- clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked (Hans de Goede)
- KVM: VMX: Update SVI during runtime APICv activation (Dongli Zhang)
- netfilter: ctnetlink: ensure safe access to master conntrack (Pablo Neira Ayuso) [Orabug: 39331275] {CVE-2026-43116}
- ipv6: Fix a potential NPD in cleanup_prefix_route() (Ido Schimmel) [Orabug: 39639429] {CVE-2026-53214}
- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)
- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637567] {CVE-2026-53215}
- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)
- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637570] {CVE-2026-53216}
- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637574] {CVE-2026-53217}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637577] {CVE-2026-53218}
- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619383] {CVE-2026-52942}
- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637581] {CVE-2026-53219}
- netfilter: nf_conntrack: destroy stale expectfn expectations on unregister (Weiming Shi) [Orabug: 39674311] {CVE-2026-53349}
- netfilter: revalidate bridge ports (Florian Westphal) [Orabug: 39637585] {CVE-2026-53220}
- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637591] {CVE-2026-53221}
- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637598] {CVE-2026-53223}
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637608] {CVE-2026-53225}
- gpio: zynq: fix runtime PM leak on remove (Ruoyu Wang)
- r8152: handle the return value of usb_reset_device() (Chih Kai Hsu)
- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637617] {CVE-2026-53227}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637621] {CVE-2026-53228}
- net/mlx5: Use effective affinity mask for IRQ selection (Wangfushuai)
- net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (Dragos Tatulea) [Orabug: 39637626] {CVE-2026-53229}
- net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (Dragos Tatulea) [Orabug: 39637631] {CVE-2026-53230}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621561] {CVE-2026-52947}
- net: phy: clean the sfp upstream if phy probing fails (Maxime Chevallier) [Orabug: 39637636] {CVE-2026-53232}
- netdev: fix double-free in netdev_nl_bind_rx_doit() (Jakub Kicinski) [Orabug: 39637640] {CVE-2026-53233}
- net: ibm: emac: Fix use-after-free during device removal (Rosen Penev)
- net/mlx4: avoid GCC 10 __bad_copy_from() false positive (Yao Sang)
- net: add pskb_may_pull() to skb_gro_receive_list() (Ji'An Zhou) [Orabug: 39637645] {CVE-2026-53235}
- tcp: restrict SO_ATTACH_FILTER to priv users (Eric Dumazet) [Orabug: 39637647] {CVE-2026-53236}
- ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (Richard Fitzgerald) [Orabug: 39674315] {CVE-2026-53350}
- gpio: mvebu: fix NULL pointer dereference in suspend/resume (Yun Zhou) [Orabug: 39637652] {CVE-2026-53237}
- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637661] {CVE-2026-53238}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637665] {CVE-2026-53239}
- dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device (Li Rongqing)
- iomap: don't revert iov_iter on partially completed buffered writes (Brian Foster)
- tools/rv: Fix cleanup after failed trace setup (Gabriele Monaco)
- spi: cadence-quadspi: fix unclocked access on unbind (Johan Hovold)
- ALSA: seq: dummy: fix UMP event stack overread (Kyle Zeng) [Orabug: 39637671] {CVE-2026-53241}
- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)
- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674318] {CVE-2026-53352}
- ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp (Rui Qi)
- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619310] {CVE-2026-52924}
- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637678] {CVE-2026-53245}
- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754154] {CVE-2026-63870}
- vxlan: vnifilter: fix spurious notification on VNI update (Andy Roulin)
- vxlan: vnifilter: send notification on VNI add (Andy Roulin)
- net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown (Lorenzo Bianconi)
- ptp: vclock: Switch from RCU to SRCU (Kurt Kanzenbach)
- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637693] {CVE-2026-53249}
- Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (Seungju Cheon) [Orabug: 39754158] {CVE-2026-63871}
- Bluetooth: ISO: Fix not using bc_sid as advertisement SID (Luiz Augusto von Dentz)
- Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (Luiz Augusto von Dentz) [Orabug: 39637699] {CVE-2026-53251}
- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39637702] {CVE-2026-53252}
- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637704] {CVE-2026-53253}
- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)
- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637710] {CVE-2026-53254}
- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637715] {CVE-2026-53255}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637719] {CVE-2026-53256}
- net: fec: fix pinctrl default state restore order on resume (Tapio Reijonen)
- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754148] {CVE-2026-63868}
- hsr: Remove WARN_ONCE() in hsr_addr_is_self(). (Kuniyuki Iwashima) [Orabug: 39674322] {CVE-2026-53353}
- net: Annotate sk->sk_write_space() for UDP SOCKMAP. (Kuniyuki Iwashima)
- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)
- wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Deepanshu Kartikey) [Orabug: 39754152] {CVE-2026-63869}
- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)
- devlink: Release nested relation on devlink free (Mark Bloch) [Orabug: 39637732] {CVE-2026-53261}
- l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (Lee Jones) [Orabug: 39637736] {CVE-2026-53262}
- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637740] {CVE-2026-53263}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637746] {CVE-2026-53264}
- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637752] {CVE-2026-53266}
- netfilter: nft_ct: bail out on template ct in get eval (Jiayuan Chen) [Orabug: 39637758] {CVE-2026-53267}
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637762] {CVE-2026-53268}
- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637767] {CVE-2026-53269}
- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637771] {CVE-2026-53270}
- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)
- ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers (Gil Portnoy)
- erofs: fix use-after-free on sbi->sync_decompress (Gao Xiang) [Orabug: 39637779] {CVE-2026-53272}
- erofs: tidy up synchronous decompression (Gao Xiang)
- erofs: add sysfs node to drop internal caches (Chunhai Guo)
- soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (Manivannan Sadhasivam)
- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637781] {CVE-2026-53273}
- net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (Nicolò Coccia)
- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637789] {CVE-2026-53275}
- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621567] {CVE-2026-52948}
- wifi: remove zero-length arrays (Johannes Berg)
- net: phy: micrel: fix LAN8814 QSGMII soft reset (Robert Marko)
- ARM: fix branch predictor hardening (Russell King)
- ARM: fix hash_name() fault (Russell King)
- ARM: allow __do_kernel_fault() to report execution of memory faults (Russell King)
- ARM: group is_permission_fault() with is_translation_fault() (Russell King)
- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754235] {CVE-2026-63898}
- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589888] {CVE-2026-52910}
- LTS version: v6.12.93 (Sherry Yang)
- net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow (Kito Xu) [Orabug: 39838946] {CVE-2026-63981}
- ethtool: cmis_cdb: Fix incorrect read / write length extension (Ido Schimmel)
- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michał Pecio)
- memfd: deny writeable mappings when implying SEAL_WRITE (Pratyush Yadav) [Orabug: 39754398] {CVE-2026-63952}
- mm/memfd: fix spelling and grammatical issues (Liu Ye)
- mm: perform all memfd seal checks in a single place (Lorenzo Stoakes)
- x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines (Alexis Lothoré) [Orabug: 39785154] {CVE-2026-64235}
- x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' (Ingo Molnar)
- usb: typec: ucsi: Don't update power_supply on power role change if not connected (Myrrh Periwinkle)
- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754209] {CVE-2026-63891}
- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)
- usb: musb: omap2430: Fix use-after-free in omap2430_probe() (Xu Wang)
- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)
- ALSA: firewire-motu: Protect register DSP event queue positions (Cássio Gabriel)
- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)
- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)
- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)
- mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() (Seongjae Park) [Orabug: 39785162] {CVE-2026-64239}
- mptcp: do not drop partial packets (Shardul Bankar)
- mptcp: handle first subflow closing consistently (Paolo Abeni)
- mptcp: introduce the mptcp_init_skb helper (Paolo Abeni)
- octeontx2-pf: avoid double free of pool->stack on AQ init failure (Dawei Feng)
- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755009] {CVE-2026-63875}
- mptcp: reset rcv wnd on disconnect (Paolo Abeni)
- mptcp: cleanup fallback dummy mapping generation (Paolo Abeni)
- ring-buffer: Flush and stop persistent ring buffer on panic (Masami Hiramatsu)
- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)
- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)
- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)
- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754839] {CVE-2026-64123}
- platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery (Lukas Wunner)
- mm/memory: fix spurious warning when unmapping device-private/exclusive pages (Alistair Popple) [Orabug: 39754857] {CVE-2026-64131}
- ALSA: scarlett2: Allow flash writes ending at segment boundary (Cássio Gabriel)
- ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (Geoffrey D. Bennett)
- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)
- Bluetooth: hci_qca: Migrate to serdev specific shutdown function (Uwe Kleine-König)
- serdev: Provide a bustype shutdown function (Uwe Kleine-König)
- x86/kexec: Disable KCOV instrumentation after load_segments() (Aleksandr Nogikh)
- x86/boot: Disable stack protector for early boot code (Brian Gerst)
- iommu: Skip PASID validation for devices without PASID capability (Tushar Dave)
- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)
- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754247] {CVE-2026-63901}
- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754407] {CVE-2026-63956}
- serial: zs: Convert to use a platform device (Maciej W. Rozycki)
- serial: zs: Switch to using channel reset (Maciej W. Rozycki)
- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Convert to use a platform device (Maciej W. Rozycki)
- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)
- drm/amdkfd: Check for pdd drm file first in CRIU restore path (David Francis)
- drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (Eric Huang) [Orabug: 39754177] {CVE-2026-63881}
- drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (Eric Huang) [Orabug: 39754181] {CVE-2026-63882}
- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)
- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)
- serial: sh-sci: fix memory region release in error path (Hongling Zeng)
- serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (Viken Dadhaniya)
- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)
- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)
- drm/i915: Fix potential UAF in TTM object purge (Janusz Krzysztofik) [Orabug: 39754187] {CVE-2026-63884}
- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786541] {CVE-2026-64527}
- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786536] {CVE-2026-64524}
- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754215] {CVE-2026-63892}
- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754219] {CVE-2026-63893}
- usb: gadget: f_fs: serialize DMABUF cancel against request completion (Michael Bommarito)
- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)
- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (Jeremy Erazo)
- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)
- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)
- usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (Kai Aizen)
- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754231] {CVE-2026-63897}
- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754239] {CVE-2026-63899}
- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754243] {CVE-2026-63900}
- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754251] {CVE-2026-63902}
- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754255] {CVE-2026-63903}
- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)
- usb: typec: tcpm: improve handling of DISCOVER_MODES failures (Sebastian Reichel)
- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)
- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754259] {CVE-2026-63904}
- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito)
- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)
- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)
- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michał Pecio)
- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)
- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786544] {CVE-2026-64528}
- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)
- counter: Fix refcount leak in counter_alloc() error path (Guangshuo Li)
- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)
- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)
- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolás Bazaes)
- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754270] {CVE-2026-63908}
- Input: xpad - add support for ASUS ROG RAIKIRI II (Dmitriy Zharov)
- Input: xpad - add "Nova 2 Lite" from GameSir (Qbeliw Tanaka)
- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754277] {CVE-2026-63912}
- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)
- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754281] {CVE-2026-63913}
- ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (Geoffrey D. Bennett)
- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)
- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754285] {CVE-2026-63914}
- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)
- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)
- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754293] {CVE-2026-63916}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754297] {CVE-2026-63917}
- l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (Michael Bommarito) [Orabug: 39754301] {CVE-2026-63918}
- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754303] {CVE-2026-63919}
- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754306] {CVE-2026-63920}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754310] {CVE-2026-63921}
- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754314] {CVE-2026-63922}
- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754321] {CVE-2026-63924}
- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754325] {CVE-2026-63925}
- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754328] {CVE-2026-63926}
- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)
- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785157] {CVE-2026-64237}
- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754332] {CVE-2026-63927}
- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)
- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)
- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)
- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754336] {CVE-2026-63928}
- iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (Benoît Monin) [Orabug: 39754340] {CVE-2026-63929}
- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)
- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)
- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)
- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)
- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)
- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)
- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)
- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)
- iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (Salah Triki)
- iio: dac: ad5686: acquire lock when doing powerdown control (Rodrigo Alencar)
- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)
- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)
- iio: adc: npcm: fix unbalanced clk_disable_unprepare() (David Carlier)
- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)
- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)
- KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (Sean Christopherson)
- KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (Sean Christopherson) [Orabug: 39754362] {CVE-2026-63937}
- KVM: SEV: Check PSC request indices against the actual size of the buffer (Sean Christopherson) [Orabug: 39754364] {CVE-2026-63938}
- KVM: SEV: Compute the correct max length of the in-GHCB scratch area (Sean Christopherson) [Orabug: 39754366] {CVE-2026-63939}
- KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (Sean Christopherson)
- KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (Sean Christopherson)
- KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (Michael Roth) [Orabug: 39686463] {CVE-2026-53360}
- KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (Sean Christopherson)
- KVM: arm64: PMU: Preserve AArch32 counter low bits (Maqiang)
- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754374] {CVE-2026-63942}
- Input: xpad - fix out-of-bounds access for Share button (Dmitry Torokhov)
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (Doruk Tan Ozturk) [Orabug: 39754380] {CVE-2026-63944}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (Muhammad Bilal) [Orabug: 39754382] {CVE-2026-63945}
- Bluetooth: ISO: fix UAF in iso_recv_frame (Muhammad Bilal) [Orabug: 39754384] {CVE-2026-63946}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754386] {CVE-2026-63947}
- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754390] {CVE-2026-63948}
- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681272] {CVE-2026-53358}
- auxdisplay: line-display: fix OOB read on zero-length message_store() (Stepan Ionichev) [Orabug: 39754394] {CVE-2026-63949}
- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619306] {CVE-2026-52923}
- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)
- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)
- HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (Hlleng)
- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)
- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754411] {CVE-2026-63957}
- usb: typec: ucsi: validate connector number in ucsi_connector_change() (Greg Kroah-Hartman) [Orabug: 39754415] {CVE-2026-63958}
- usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (Greg Kroah-Hartman)
- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)
- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754427] {CVE-2026-63961}
- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)
- usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (Greg Kroah-Hartman) [Orabug: 39754431] {CVE-2026-63962}
- usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (Greg Kroah-Hartman) [Orabug: 39754436] {CVE-2026-63963}
- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)
- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)
- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)
- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)
- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Högander)
- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)
- drm/i915/psr: Read Intel DPCD workaround register (Jouni Högander)
- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Högander)
- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)
- HID: core: introduce hid_safe_input_report() (Benjamin Tissoires)
- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)
- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)
- inet: frags: flush pending skbs in fqdir_pre_exit() (Jakub Kicinski) [Orabug: 38847669] {CVE-2025-68768}
- inet: frags: add inet_frag_queue_flush() (Jakub Kicinski)
- mm/page_alloc: clear page->private in free_pages_prepare() (Mikhail Gavrilov) [Orabug: 39343575] {CVE-2026-43303}
- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754760] {CVE-2026-64095}
- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754743] {CVE-2026-64090}
- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754747] {CVE-2026-64091}
- batman-adv: tp_meter: directly shut down timer on cleanup (Sven Eckelmann) [Orabug: 39754752] {CVE-2026-64093}
- s390/cio: Restore GFP_DMA for CHSC allocation (Peter Oberparleiter)
- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)
- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)
- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619356] {CVE-2026-52934}
- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754756] {CVE-2026-64094}
- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)
- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)
- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann)
- perf: Fix dangling cgroup pointer in cpuctx (Levi Yun)
- net: skbuff: fix pskb_carve leaking zcopy pages (Pavel Begunkov)
- ipv6: fix possible infinite loop in fib6_select_path() (Jiayuan Chen) [Orabug: 39754449] {CVE-2026-63968}
- ipv6: fix possible infinite loop in rt6_fill_node() (Jiayuan Chen) [Orabug: 39754451] {CVE-2026-63969}
- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754455] {CVE-2026-63971}
- net: mana: Add NULL guards in teardown path to prevent panic on attach failure (Dipayaan Roy) [Orabug: 39754460] {CVE-2026-63973}
- gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (Marco Scardovi)
- gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (Dan Carpenter)
- Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (Heitor Alves de Siqueira) [Orabug: 39754465] {CVE-2026-63974}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754467] {CVE-2026-63975}
- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754470] {CVE-2026-63976}
- net/handshake: Drain pending requests at net namespace exit (Chuck Lever) [Orabug: 39754474] {CVE-2026-63978}
- net/handshake: Take a long-lived file reference at submit (Chuck Lever) [Orabug: 39786532] {CVE-2026-64523}
(Al Viro)
- net/handshake: Pass negative errno through handshake_complete() (Chuck Lever)
- nvme-tcp: store negative errno in queue->tls_err (Chuck Lever)
- net/handshake: Use spin_lock_bh for hn_lock (Chuck Lever) [Orabug: 39754480] {CVE-2026-63980}
- net/sched: act_mirred: Fix return code in early mirred redirect error paths (Victor Nogueira)
- net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop (Jamal Hadi Salim) [Orabug: 39839075] {CVE-2026-63982}
- net: Introduce skb tc depth field to track packet loops (Jamal Hadi Salim)
- net/sched: act_mirred: add loop detection (Eric Dumazet)
- net/sched: act_mirred: Move the recursion counter struct netdev_xmit (Sebastian Andrzej Siewior)
- net/sched: fix packet loop on netem when duplicate is on (Jamal Hadi Salim) [Orabug: 39754484] {CVE-2026-63983}
- net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" (Jamal Hadi Salim)
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754488] {CVE-2026-63984}
- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754491] {CVE-2026-63985}
- ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback (Jakub Kicinski)
- ethtool: strset: fix header attribute index in ethnl_req_get_phydev() (Jakub Kicinski)
- ethtool: pse-pd: fix missing ethnl_ops_complete() (Jakub Kicinski)
- ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error (Jakub Kicinski)
- ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (Jakub Kicinski) [Orabug: 39754495] {CVE-2026-63987}
- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754501] {CVE-2026-63990}
- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)
- ASoC: codecs: simple-mux: Fix enum control bounds check (Cássio Gabriel)
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754509] {CVE-2026-63992}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754512] {CVE-2026-63993}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754515] {CVE-2026-63994}
- cxl/test: Update mock dev array before calling platform_device_add() (Li Ming)
- ethtool: cmis: validate fw->size against start_cmd_payload_size (Jakub Kicinski)
- ethtool: cmis: validate start_cmd_payload_size from module (Jakub Kicinski) [Orabug: 39754518] {CVE-2026-63995}
- net: ethtool: Add support for writing firmware blocks using EPL payload (Danielle Ratson)
- net: ethtool: Add new parameters and a function to support EPL (Danielle Ratson)
- ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl (Jakub Kicinski)
- ethtool: cmis: require exact CDB reply length (Jakub Kicinski) [Orabug: 39754520] {CVE-2026-63996}
- ethtool: module: fix cleanup if socket used for flashing multiple devices (Jakub Kicinski)
- ethtool: module: check fw_flash_in_progress under rtnl_lock (Jakub Kicinski)
- ethtool: module: avoid leaking a netdev ref on module flash errors (Jakub Kicinski) [Orabug: 39754522] {CVE-2026-63997}
- ethtool: rss: fix hkey leak when indir_size is 0 (Jakub Kicinski)
- net: Avoid checksumming unreadable skb tail on trim (Björn Töpel)
- gpio: mxc: fix irq_high handling (Alexander Stein)
- accel/ivpu: prevent uninitialized data bug in debugfs (Dan Carpenter)
- net: hsr: fix potential OOB access in supervision frame handling (Luka Gejak) [Orabug: 39754529] {CVE-2026-64000}
- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cássio Gabriel)
- ALSA: pcm: oss: Fix setup list UAF on proc write error (Cássio Gabriel)
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754535] {CVE-2026-64002}
- scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues (David Jeffery) [Orabug: 39754539] {CVE-2026-64003}
- net/iucv: fix locking in .getsockopt (Breno Leitao)
- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)
- net: netlink: don't set nsid on local notifications (Ilya Maximets)
- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)
- vsock: keep poll shutdown state consistent (Ziyu Zhang)
- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619328] {CVE-2026-52927}
- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754552] {CVE-2026-64007}
- kunit: fix use-after-free in debugfs when using kunit.filter (Florian Schmaus)
- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754557] {CVE-2026-64009}
- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)
- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)
- arm64: debug: always unmask interrupts in el0_softstp() (Ada Couprie Diaz)
- arm64: debug: remove debug exception registration infrastructure (Ada Couprie Diaz)
- arm64: debug: split bkpt32 exception entry (Ada Couprie Diaz)
- arm64: debug: split brk64 exception entry (Ada Couprie Diaz)
- arm64: debug: split hardware watchpoint exception entry (Ada Couprie Diaz)
- arm64: debug: split single stepping exception entry (Ada Couprie Diaz)
- arm64: debug: refactor reinstall_suspended_bps() (Ada Couprie Diaz)
- arm64: debug: split hardware breakpoint exception entry (Ada Couprie Diaz)
- arm64: entry: Add entry and exit functions for debug exceptions (Ada Couprie Diaz)
- arm64: debug: remove break/step handler registration infrastructure (Ada Couprie Diaz)
- arm64: debug: call step handlers statically (Ada Couprie Diaz)
- arm64: debug: call software breakpoint handlers statically (Ada Couprie Diaz)
- arm64: refactor aarch32_break_handler() (Ada Couprie Diaz)
- arm64: debug: clean up single_step_handler logic (Ada Couprie Diaz)
- arm64: Introduce esr_is_ubsan_brk() (Mostafa Saleh)
- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)
- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754569] {CVE-2026-64012}
- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr)
- drm/v3d: Release indirect CSD GEM reference on CPU job free (Maíra Canal)
- drm/v3d: Fix use-after-free of CPU job query arrays on error path (Maíra Canal)
- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754574] {CVE-2026-64014}
- uek-rpm/config-x86_64-onos: Enable Nexthop SONiC config options (Dara Stotland) [Orabug: 39583981]
- hwmon:(pmbus/xdpe1a2g7b) Add support for xdpe1a2g5b/7b controllers (Ashish Yadav) [Orabug: 39583981]
- hwmon: (pmbus/core) Add support for NVIDIA nvidia195mv mode (Ashish Yadav) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add rtc debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add powerup_counter debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add clear_blackbox debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add firmware_revision debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: don't clobber msg->len to signal block-read completion (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: preserve PEC byte length in SMBus block read setup (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: skip input clock setup on non-OF systems (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: use numbered adapter registration (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: cosmetic: use resource format specifier in debug log (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: cosmetic cleanup (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: switch to generic device property accessors (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: remove duplicate error message (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: switch to devres managed APIs (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: i2c-xiic: Replace dev_err() with dev_err_probe() in probe function (Enrico Zanda) [Orabug: 39583981]
- i2c: xiic: Add atomic transfer support (Manikanta Guntupalli) [Orabug: 39583981]
- i2c: xiic: Relocate xiic_i2c_runtime_suspend and xiic_i2c_runtime_resume to facilitate atomic mode (Manikanta Guntupalli) [Orabug: 39583981]
- serial: 8250_fintek: Add support for F81214E (Ravi Rama) [Orabug: 39583981]
- spi: xilinx: use device property accessors. (Abdurrahman Hussain) [Orabug: 39583981]
- spi: xilinx: make irq optional (Abdurrahman Hussain) [Orabug: 39583981]
- spi: dt-bindings: xilinx: make interrupts optional (Abdurrahman Hussain) [Orabug: 39583981]
- x86/CPU/AMD: Ignore invalid reset reason value (Yazen Ghannam) [Orabug: 39583981]
- x86/CPU/AMD: Print the reason for the last reset (Yazen Ghannam) [Orabug: 39583981]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776790] {CVE-2026-64600}
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674326,39779060] {CVE-2025-10263,CVE-2026-53354}
- Revert "arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC" (Saeed Mirzamohammadi) [Orabug: 39779060]
- Revert "arm64: errata: Mitigate TLBI errata on various Arm CPUs" (Saeed Mirzamohammadi) [Orabug: 39779060]
- rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818507]
- rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818507]

[6.12.0-206.92.1]
- rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772649]
- rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772649]
- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson) [Orabug: 39765744]
- net: lan743x: avoid netdev-based logging before netdev registration (David Thompson) [Orabug: 39765744]
- Revert "arm64: acpi: Enable ACPI CCEL support" (Will Deacon) [Orabug: 39760492]
- virtio_pci: fix vq info pointer lookup via wrong index (Ammar Faizi) [Orabug: 39751599,39786359] {CVE-2026-64457}
- iommu/arm-smmu-v3: Fix section mismatch warning: httu_quirk (Dave Kleikamp) [Orabug: 39738971]
- IB/rxe: unlink pd before free it (Wengang Wang) [Orabug: 39674346]
- IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39674346]
- net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621714,39638196] {CVE-2026-52995}
- uek: kabi: update x86_64/aarch64 kABI files for new symbols (Saeed Mirzamohammadi) [Orabug: 39621432]
- net/rds: Don't drop the ball when RDS_MSG_CANCELED is encountered (Gerd Rausch) [Orabug: 39563153]
- PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining (Maciej W. Rozycki) [Orabug: 38120425]
- mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074277]




More information about the El-errata mailing list