-
Fri Sep 04 2026 Harshvardhan Jha <harshvardhan.j.jha@oracle.com> [5.15.0-324.217.5.2.el9uek]
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39974835] {CVE-2026-80590}
-
Thu Aug 27 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.217.5.1.el9uek]
- crypto: qat: restore misc workqueue lifecycle (Manjunath Patil) [Orabug: 39937535]
- LTS version: v5.15.217 (Vijayendra Suman)
- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu)
- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt)
- jiffies: Cast to unsigned long in secs_to_jiffies() conversion (Easwar Hariharan)
- drm/virtio: Unlock reservations on dma_resv_reserve_fences() error (Dmitry Osipenko)
- drm/vmwgfx: Reserve fence slots on buffer objects in cotables (Zack Rusin)
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner)
- net/x25: fix use-after-free of the socket by its timers (Baul Lee)
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli)
- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet)
- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev)
- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang)
- netfilter: ipset: fix list type element drift bug (Florian Westphal)
- netfilter: flowtable: publish GC-visible tuple last (Jérémy Jean)
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy)
- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei (Microsoft))
- crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu)
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jon Hunter)
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li)
- net/smc: rdma write inline if qp has sufficient inline space (Guangguan Wang)
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen)
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko)
- openvswitch: move key and ovs_cb update out of handle_fragments (Xin Long)
- net: sched: use skb_ip_totlen and iph_totlen (Xin Long)
- openvswitch: use skb_ip_totlen in conntrack (Xin Long)
- net: add a couple of helpers for iph tot_len (Xin Long)
- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes (ARM))
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo)
- drm/amd/pm: fix torn gpu metrics reads (Yang Wang)
- ice: wait for reset completion in ice_resume() (Aaron Ma)
- jiffies: Define secs_to_jiffies() (Easwar Hariharan)
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)
- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)
- i2c: bcm-iproc: remove printout on handled timeouts (Wolfram Sang)
- i2c: imx: Fix slave registration race and error handling (Liem)
- binfmt_misc: restore write access when removing an entry (Christian Brauner)
- fs: don't block write during exec on pre-content watched files (Amir Goldstein)
- fsnotify: opt-in for permission events at file open time (Amir Goldstein)
- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov)
- scsi: scsi_debug: Rename zone type constants (Damien Le Moal)
- scsi: sd: sd_zbc: Return early in sd_zbc_check_zoned_characteristics() (Damien Le Moal)
- scsi: sd: sd_zbc: Introduce struct zoned_disk_info (Bart Van Assche)
- scsi: sd: sd_zbc: Use logical blocks as unit when querying zones (Damien Le Moal)
- scsi: sd: sd_zbc: Improve source code documentation (Bart Van Assche)
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye)
- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)
- igc: remove napi_synchronize() in igc_down() (David Carlier)
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie)
- ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon)
- ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)
- ksmbd: validate minimum PDU size for transform requests (Namjae Jeon)
- smb/server: fix minimum SMB2 PDU size (ChenXiaoSong)
- smb/server: fix minimum SMB1 PDU size (ChenXiaoSong)
- ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon)
- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner)
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu)
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo)
- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery)
- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha)
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann)
- ceph: print cluster fsid and client global_id in all debug logs (Xiubo Li)
- ceph: rename _to_client() to _to_fs_client() (Xiubo Li)
- libceph: add doutc and *_client debug macros support (Xiubo Li)
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei)
- libceph: Amend checking to fix `make W=1` build breakage (Andy Shevchenko)
- ceph: avoid fs reclaim while using current->journal_info (Max Kellermann)
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou)
- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)
- mptcp: fix subflow accounting on close (Paolo Abeni)
- mptcp: cleanup MPJ subflow list handling (Paolo Abeni)
- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)
- serial: sc16is7xx: fix regression with GPIO configuration (Hugo Villeneuve)
- serial: sc16is7xx: remove obsolete out_thread label (Hugo Villeneuve)
- serial: sc16is7xx: Fill in rs485_supported (Ilpo Järvinen)
- sc16is7xx: Properly resume TX after stop (Tomasz Moń)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi)
- serial: 8250_mid: Remove unneeded test for ->setup() presence (Andy Shevchenko)
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu)
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei)
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea)
- media: v4l: async: Set owner for async sub-devices (Sakari Ailus)
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges)
- media: imx219: Fix maximum frame length in lines (Sakari Ailus)
- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)
- media: i2c: imx219: Correct the minimum vblanking value (David Plowman)
- media: i2c: imx219: Drop IMX219_VTS_* macros (Laurent Pinchart)
- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)
- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula)
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas)
- drm/virtio: Return proper error codes instead of -1 (Dmitry Osipenko)
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristóf)
- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)
- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)
- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey)
- dma-buf/drivers: make reserving a shared slot mandatory v4 (Christian König)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai)
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai)
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang)
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai)
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre)
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng)
- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)
- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca)
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)
- bootconfig: do not put quotes on cmdline items unless necessary (Rasmus Villemoes)
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)
- net/sched: taprio: avoid calling child->ops->dequeue(child) twice (Vladimir Oltean)
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao)
- treewide: rename pinctrl_gpio_direction_output_new() (Bartosz Golaszewski)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo)
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui)
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi)
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li)
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: Add helper function to parse netlink msg of ip_tunnel_encap (Liu Jian)
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner)
- mmc: vub300: fix use-after-free on probe failure (Guangshuo Li)
- mmc: vub300: rename probe error labels (Johan Hovold)
- mmc: vub300: fix use-after-free on disconnect (Johan Hovold)
- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov)
- firmware_loader: introduce __free() cleanup hanler (Dmitry Torokhov)
- dm-verity: make error counter atomic (Mikulas Patocka)
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka)
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal)
- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn)
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito)
- thunderbolt: Remove XDomain from the bus without holding tb->lock (Mika Westerberg)
- thunderbolt: Remove service debugfs entries during unregister (Mika Westerberg)
- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg)
- thunderbolt: Update property.c function documentation (Alan Borzeszkowski)
- thunderbolt: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET)
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu)
- can/esd_usb2: Rename esd_usb2.c to esd_usb.c (Frank Jungclaus)
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)
- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)
- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen)
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)
- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)
- taskstats: fill_stats_for_tgid: use for_each_thread() (Oleg Nesterov)
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li)
- dmaengine: dw-edma: Detach the private data and chip info structures (Frank Li)
- dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip (Frank Li)
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal)
- mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle)
- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie)
- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao)
- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito)
- fs/ntfs3: Undo critial modificatins to keep directory consistency (Konstantin Komarov)
- fs/ntfs3: Make ntfs_update_mftmirr return void (Pavel Skripkin)
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani)
- lsm: infrastructure management of the sock security (Casey Schaufler)
- lsm: use default hook return value in call_int_hook() (Ondrej Mosnacek)
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir)
- remoteproc: qcom: pas: Adjust the phys addr wrt the mem region (Yogesh Lal)
- remoteproc: qcom: fix sparse warnings (Mukesh Ojha)
- remoteproc: qcom: replace kstrdup with kstrndup (Mukesh Ojha)
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal)
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal)
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal)
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal)
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso)
- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)
- netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal)
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal)
- ASoC: mediatek: mt8192: Check runtime resume during probe (Cássio Gabriel)
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)
- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (AngeloGioacchino Del Regno)
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie)
- ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet)
- net: dst: add four helpers to annotate data-races around dst->dev (Eric Dumazet)
- net: dst: annotate data-races around dst->output (Eric Dumazet)
- net: dst: annotate data-races around dst->input (Eric Dumazet)
- tcp: convert to dev_net_rcu() (Eric Dumazet)
- ASoC: mediatek: mt8183: Check runtime resume during probe (Cássio Gabriel)
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep)
- octeontx2-af: Fix APR entry mapping based on APR_LMT_CFG (Geetha sowjanya)
- VDUSE: avoid leaking information to userspace (Jason Wang)
- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Pérez)
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Pérez)
- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Wentao Liang)
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong)
- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)
- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)
- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming)
- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)
- serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) (Hugo Villeneuve)
- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina)
- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)
- audit: widen ino fields to u64 (Jeff Layton)
- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)
- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)
- Input: mms114 - reject an oversized device packet size (Bryam Vargas)
- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov)
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives)
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov)
- udmabuf: Do not create malformed scatterlists (Jason Gunthorpe)
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski)
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato)
- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei)
- xfs: check v5 superblock features early (Christoph Hellwig)
- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li)
- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca)
- drm/amdgpu: Implement insert_end for VCE 3 (David Rosca)
- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca)
- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li)
- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca)
- s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman)
- drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li)
- mmc: sdhci: make tuning_err a signed int (Haibo Chen)
- mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak)
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng)
- libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai)
- ceph: fix MDS random selection readiness predicate (Yiming Zhu)
- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer)
- Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov)
- Input: sur40 - fix input device registration ordering (Dmitry Torokhov)
- openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis)
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf)
- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha)
- crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum)
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov)
- Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov)
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas)
- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov)
- powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson)
- Input: iforce - validate input packet lengths (Pengpeng Hou)
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang)
- Input: psxpad-spi - set driver data before use (Linmao Li)
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies)
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov)
- powerpc/pseries: pci - logic bug (George Wilson)
- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid Wróbel)
- ASoC: cs4265: sort the register default table (Peter Ujfalusi)
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan)
- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts (NGI0))
- selinux: do not cancel a policy conversion that never started (Bryam Vargas)
- selinux: reject a class permission count below its inherited common (Bryam Vargas)
- selinux: require every boolean value to be defined (Bryam Vargas)
- ipvs: separate destination availability state (Yizhou Zhao)
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng)
- media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization (Jiasheng Jiang)
- media: mtk-vcodec: potential null pointer deference in SCP (Fullway Wang)
- f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu)
- LTS version: v5.15.216 (Vijayendra Suman)
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas)
- sctp: clear new_transport when removing a peer (Qing Ming)
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang)
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee)
- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye)
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou)
- ipv6: fix Route Information option length validation (Yuejie Shi)
- Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (Rafael J. Wysocki)
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang)
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi)
- vsock/virtio: read virtqueues under worker locks (Weiming Shi)
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee)
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou)
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko)
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen)
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou)
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng)
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel)
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu)
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee)
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)
- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola)
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos)
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal)
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal)
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu)
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye)
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi)
- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- futex: Prevent robust futex exit race some more (Keno Fischer)
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver)
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov)
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers)
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers)
- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee)
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye)
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang)
- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou)
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk)
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng)
- ipvs: properly update the overload flag on dest edit (Julian Anastasov)
- ipvs: add totalconns for dest (Julian Anastasov)
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace)
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan)
- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)
- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh)
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee)
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov)
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)
- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)
- sctp: clear control chunk transport if it is being removed (Xin Long)
- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu)
- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan)
- net: qrtr: ns: Raise lookup limit to 128 (Łukasz Patron)
- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond)
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet)
- net: prestera: validate firmware header length (Pengpeng Hou)
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin)
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen)
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)
- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan)
- bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Michael Chan)
- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)
- selftests/ftrace: Add test case for GRP/ only input (Linyu Yuan)
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Høiland-Jørgensen)
- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo)
- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)
- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik)
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim)
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi)
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen)
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))
- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker)
- nfs4: take a reference on the nfs_client when running FREE_STATEID (Scott Mayhew)
- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger)
- mount: honour SB_NOUSER in the new mount API (Al Viro)
- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao)
- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng)
- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))
- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An)
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin)
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin)
- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)
- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)
- drm/vc4: Zero the tile state data array before each BIN job (Maíra Canal)
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou)
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie)
- can: peak_usb: add bounds check for USB channel index (James Gao)
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou)
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou)
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel)
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li)
- can: ems_usb: validate CPC message lengths (Pengpeng Hou)
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem)
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller)
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets)
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets)
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)
- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler)
- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler)
- s390/dasd: Fix potential NULL pointer dereference (Jan Höppner)
- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally)
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)
- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada)
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)
- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)
- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet)
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet)
- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet)
- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito)
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou)
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou)
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin)
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner)
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li)
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi)
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee)
- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo)
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou)
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath)
- e1000: fix memory leak in e1000_probe() (Dawei Feng)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan)
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan)
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee)
- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)
- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)
- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei)
- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)
- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai)
- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)
- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee)
- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee)
- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu)
- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)
- sctp: validate Adaptation Indication parameter length (Charles Vosburgh)
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai)
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan)
- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)
- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter)
- rhashtable: clear stale iter->p on table restart (Cen Zhang (Microsoft))
- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev)
- octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh)
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))
- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)
- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)
- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao)
- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)
- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao)
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)
- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li)
- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)
- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao)
- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck)
- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An)
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An)
- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))
- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso)
- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito)
- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito)
- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei)
- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)
- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)
- phy: zynqmp: Allow variation in refclk rate (Sean Anderson)
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)
- tls: separate no-async decryption request handling from async (Sabrina Dubroca)
- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)
- net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam)
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)
- gve: fix Rx queue stall on alloc failure (Eddie Phillips)
- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)
- media: uvcvideo: Implement dual stream quirk to fix loss of usb packets (Isaac Scott)
- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee)
- raw: fix a typo in raw_icmp_error() (Eric Dumazet)
- raw: remove unused variables from raw6_icmp_error() (Eric Dumazet)
- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng)
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi)
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun)
- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang)
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher)
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher)
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko)
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada)
- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk)
- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito)
- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)
- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer)
- proc: Fix broken error paths for namespace links (Jann Horn)
- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu)
- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee)
- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas)
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan)
- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)
- net: slip: serialize receive against buffer reallocation (Sungmin Kang)
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)
- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao)
- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)
- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner)
- libceph: remove debugfs files before client teardown (Douya Le)
- libceph: reject zero bucket types in crush_decode (Douya Le)
- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer)
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (Shuangpeng Bai)
- libceph: guard missing CRUSH type name lookup (Zhao Zhang)
- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer)
- libceph: bound get_version reply decode to front len (Douya Le)
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas)
- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" (Will Deacon)
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))
- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))
- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog)
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev (Steven Rostedt)
- intel_th: fix MSC output device reference leak (Guangshuo Li)
- comedi: comedi_parport: deal with premature interrupt (Ian Abbott)
- x86/boot/compressed: Disable jump tables (Nathan Chancellor)
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao)
- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner)
- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner)
- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye)
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker)
- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu)
- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang)
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk)
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani)
- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil)
- media: vimc: fix reference leak on failed device registration (Guangshuo Li)
- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)
- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)
- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)
- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke)
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey)
- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak)
- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky)
- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski)
- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon)
- media: cx23885: add ioremap return check and cleanup (Wang Jun)
- media: cx231xx: fix devres lifetime (Johan Hovold)
- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou)
- media: cedrus: Fix missing cleanup in error path (Samuel Holland)
- media: cedrus: clean up media device on probe failure (Myeonghun Pak)
- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)
- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky)
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes)
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan)
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristóf)
- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen)
- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen)
- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen)
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondračka)
- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp)
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp)
- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp)
- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp)
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp)
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp)
- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp)
- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp)
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones)
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye)
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)
- raw: use more conventional iterators (Eric Dumazet)
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)
- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo)
- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)
- octeontx2-vf: set TC flower flag on MCAM entry allocation (Suman Ghosh)
- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)
- net: stmmac: add tc flower filter for EtherType matching (Ong Boon Leong)
- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana)
- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo)
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet)
- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang)
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi)
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike)
- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))
- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan)
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)
- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing)
- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou)
- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (ギカク))
- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang)
- nfp: Check resource mutex allocation (Ruoyu Wang)
- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li)
- net: dpaa2-eth: assign priv->mac after dpaa2_mac_connect() call (Vladimir Oltean)
- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li)
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou)
- hwmon: (occ) Delay hwmon registration until user request (Eddie James)
- hwmon: (occ) Add sysfs entries for additional extended status bits (Eddie James)
- hwmon: (occ) Add sysfs entry for OCC mode (Eddie James)
- hwmon: (occ) Add sysfs entry for IPS (Idle Power Saver) status (Eddie James)
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez)
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)
- ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the endpoint (Jiaxin Yu)
- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang)
- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani)
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani)
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani)
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani)
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani)
- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang)
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun)
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih)
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis)
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang)
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann)
- Revert "drm/amd/display: Add missing kdoc for ALLM parameters" (Sasha Levin)
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)
- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)
- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)
- USB: serial: io_edgeport: cap received transmit credits (Sunho Park)
- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal)
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu)
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan)
- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)
- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)
- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew)
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu)
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang)
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang)
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi)
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long)
- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim)
- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)
- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))
- can: j1939: fix lockless local-destination check (Shuhao Fu)
- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)
- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)
- sched/vtime: Get rid of generic vtime_task_switch() implementation (Alexander Gordeev)
- powerpc: remove the last remnants of cputime_t (Nicholas Piggin)
- powerpc/time: Fix sparse warnings (He Ying)
- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)
- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He)
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei)
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev)
- ata: sata_dwc_460ex: remove variable num_processed (Colin Ian King)
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev)
- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas)
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi)
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei)
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)
- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (ギカク))
- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao)
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang)
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)
- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li)
- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei)
- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng)
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas)
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal)
- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang)
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))
- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)
- RDMA/siw: publish QP after initialization (Ruoyu Wang)
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (Guoqing Jiang)
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala)
- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana)
- btrfs: reject free space cache with more entries than pages (Xiang Mei)
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)
- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)
- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito)
- KVM: VMX: Make vmread_error_trampoline() uncallable from C code (Sean Christopherson)
- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae)
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea)
- can: isotp: serialize TX state transitions under so->rx_lock (Oliver Hartkopp)
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp)
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal)
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim)
- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko)
- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior)
- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg)
-
Mon Aug 17 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.213.5.el9uek]
- Revert "rseq: Introduce feature size and alignment ELF auxiliary vector entries" (Prakash Sangappa) [Orabug: 39874250]
-
Wed Aug 12 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.213.4.el9uek]
- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047421]
- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047421]
- rseq: Introduce extensible rseq ABI (Prakash Sangappa) [Orabug: 39047421]
- rseq: Introduce feature size and alignment ELF auxiliary vector entries (Mathieu Desnoyers) [Orabug: 39047421]
- Update AT_VA_RESERVATION number (Prakash Sangappa) [Orabug: 39047421]
- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047421]
- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047421]
- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047421]
- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047421]
- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047421]
- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047421]
- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047421]
- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047421]
- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047421]
- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047421]
- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047421]
- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047421]
- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add fields and constants for time slice extension (Thomas Gleixner) [Orabug: 39047421]
- sched/fair: Disable affine wakeups at NUMA domain levels on Exadata (Daniel Jordan) [Orabug: 38770281]
- drivers/soc/pensando/penfw: Added attest_meas and get cert_chain to penfw_util (Rahshekh) [Orabug: 39818086]
- drivers/soc/pensando/penfw_sysfs: fix bl31_show vers buffer size (Rahshekh) [Orabug: 39818086]
- mmc: core: Use HPI to interrupt lengthy cache flush (#494) (Brad Larson) [Orabug: 39818086]
- xen/ovmapi: terminate values passed to xenbus_write (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: free queued events on release (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: prevent duplicate app registration (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: avoid raw user pointer access in get_next_event (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: reject oversized posted event payloads (Joe Jin) [Orabug: 39851069]
- IB/rxe: use rxe_drop_ref to release rxe_pd (Wengang Wang) [Orabug: 39831970]
- IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39831970]
- net/rds: restrict RDS_INFO dumps to caller netns (Praveen Kumar Kannoju) [Orabug: 39832021]
- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668599]
- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668599]
- Revert "x86/alternatives: Add alt_instr.flags" (Harshit Mogalapalli) [Orabug: 39864327]
- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830590,39832946] {CVE-2026-64561}
- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Document the "rules" for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Directly "destroy" PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784615,39853775] {CVE-2026-68480}
- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternatives: Add alt_instr.flags (Borislav Petkov) [Orabug: 39784615] {CVE-2026-68480}
- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}
-
Sat Aug 08 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.213.3.el9uek]
- LTS version: v5.15.213 (Vijayendra Suman)
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807438] {CVE-2026-64560}
- LTS version: v5.15.212 (Vijayendra Suman)
- perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das)
- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39853280] {CVE-2026-64479}
- iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol)
- ALSA: seq: Check UMP support for midi_version change (Takashi Iwai)
- ALSA: seq: Skip event type filtering for UMP events (Takashi Iwai)
- iio: invensense: fix odr switching to same value (Jean-Baptiste Maneyrol)
- iio: imu: inv_mpu6050: fix frequency setting when chip is off (Jean-Baptiste Maneyrol)
- ALSA: seq: Avoid confusion of aligned read size (Takashi Iwai)
- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier)
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng)
- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang)
- audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina)
- audit: add audit_log_nf_skb helper function (Ricardo Robaina)
- btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo)
- crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785885] {CVE-2026-64304}
- btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo)
- crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta)
- btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843586] {CVE-2026-64593}
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron)
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum)
- crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-König)
- crypto: atmel-sha204a - Mark OF related data as maybe unused (Krzysztof Kozlowski)
- usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker)
- usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan)
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira)
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu)
- gpio: pca953x: Make platform teardown callback return void (Uwe Kleine-König)
- leds: lm3601x: Improve error reporting for problems during .remove() (Uwe Kleine-König)
- leds: lm3697: Remove duplicated error reporting in .remove() (Uwe Kleine-König)
- drm/i2c/sil164: Drop no-op remove function (Uwe Kleine-König)
- usb: iowarrior: remove inherent race with minor number (Oliver Neukum)
- bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786046] {CVE-2026-64352}
- bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko)
- bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi)
- bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786052] {CVE-2026-64355}
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani)
- hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko)
- xfs: use null daddr for unset first bad log block (Yousef Alhouseen)
- xfs: Remove dead code (Jiapeng Chong)
- xfs: Remove redundant assignment of mp (Jiapeng Chong)
- serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko)
- serial: 8250_mid: Remove 8250_pci usage (Ilpo Järvinen)
- HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786074] {CVE-2026-64363}
- treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner)
- proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786095] {CVE-2026-64371}
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786078] {CVE-2026-64364}
- HID: add haptics page defines (Angela Czubak)
- proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786112] {CVE-2026-64375}
- proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig)
- proc: Move fdinfo PTRACE_MODE_READ check into the inode .permission operation (Tyler Hicks)
- proc: use generic setattr() for /proc/$PID/net (Thomas Weißschuh)
- X.509: Fix validation of ASN.1 certificate header (Lukas Wunner)
- ksmbd: track the connection owning a byte-range lock (Namjae Jeon)
- ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang)
- ksmbd: destroy async_ida in ksmbd_conn_free() (Daemyung Kang)
- ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc (Greg Kroah-Hartman)
- ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon)
- smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786128] {CVE-2026-64380}
- smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi)
- smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786124] {CVE-2026-64379}
- smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786200] {CVE-2026-64401}
- cifs: Add tracing for the cifs_tcon struct refcounting (David Howells)
- smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786131] {CVE-2026-64381}
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (Runyu Xiao) [Orabug: 39760901] {CVE-2026-64206}
- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim)
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz)
- netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786232] {CVE-2026-64413}
- netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng)
- gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- gpio: sch: use new GPIO line value setter callbacks (Bartosz Golaszewski)
- coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao)
- PCI: Skip Resizable BAR restore on read error (Marco Nenciarini)
- PCI: Move Resizable BAR code to rebar.c (Ilpo Järvinen)
- PCI: Add kerneldoc for pci_resize_resource() (Ilpo Järvinen)
- PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Järvinen)
- PCI: Free saved list without holding pci_bus_sem (Ilpo Järvinen)
- PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Järvinen)
- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu) [Orabug: 39786307] {CVE-2026-64441}
- staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov)
- staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird)
- staging: rtl8723bs: remove redundant braces in if statements (Sevinj Aghayeva)
- staging: rtl8723bs: Remove redundant else branches. (Sevinj Aghayeva)
- PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786366] {CVE-2026-64461}
- PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi)
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby)
- staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu) [Orabug: 39786327] {CVE-2026-64446}
- staging: rtl8723bs: Fix space issues (Franziska Naepelt)
- staging: rtl8723bs: Fix indentation issues (Franziska Naepelt)
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu)
- smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786332] {CVE-2026-64448}
- cifs: remove unused server parameter from calc_smb_size() (Enzo Matsumiya)
- smb2: small refactor in smb2_check_message() (Enzo Matsumiya)
- cifs: remove check of list iterator against head past the loop body (Jakob Koschel)
- cifs: Create a new shared file holding smb2 pdu definitions (Ronnie Sahlberg)
- PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya)
- vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786409] {CVE-2026-64475}
- ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong)
- iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk)
- bitops: make BYTES_TO_BITS() treewide-available (Alexander Lobakin)
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: stabilized timestamp in interrupt (Jean-Baptiste Maneyrol)
- iio: invensense: fix timestamp glitches when switching frequency (Jean-Baptiste Maneyrol)
- iio: invensense: remove redundant initialization of variable period (Colin Ian King)
- iio: imu: inv_mpu6050: use the common inv_sensors timestamp module (Jean-Baptiste Maneyrol)
- iio: make invensense timestamp module generic (Jean-Baptiste Maneyrol)
- iio: move inv_icm42600 timestamp module in common (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: make timestamp module chip independent (Jean-Baptiste Maneyrol)
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu)
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao)
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786502] {CVE-2026-64510}
- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786508] {CVE-2026-64512}
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou)
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou)
- mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou)
- mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao)
- mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou)
- mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou)
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims)
- wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou)
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo)
- reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong)
- ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov)
- memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie)
- macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen)
- llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang)
- Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya)
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789564,39816016,39819143] {CVE-2026-64531}
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha)
- wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng)
- wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao)
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi)
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu)
- drbd: reject data replies with an out-of-range payload size (Michael Bommarito)
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao)
- ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao)
- llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai)
- mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen)
- s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer)
- hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An)
- ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang)
- orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas)
- tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu)
- net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)
- fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li)
- net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li)
- hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou)
- hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou)
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal)
- batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann)
- batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann)
- batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann)
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789573] {CVE-2026-64534}
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi)
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi)
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito)
- ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito)
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng)
- net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- gpios: palmas: add .get_direction() op (Andreas Kemnade)
- cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan)
- cpu: hotplug: Preserve per instance callback errors (Bradley Morgan)
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov)
- Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov)
- Input: ims-pcu - add response length checks (Dmitry Torokhov)
- Input: ims-pcu - validate control endpoint type (Dmitry Torokhov)
- Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov)
- Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov)
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li)
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang)
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas)
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas)
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito)
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito)
- scsi: sg: Report request-table problems when any status is set (Xu Rao)
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li)
- dm-verity: increase sprintf buffer size (Mikulas Patocka)
- dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka)
- dm-stats: fix merge accounting (Mikulas Patocka)
- dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka)
- dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski)
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka)
- dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius)
- dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai)
- dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang)
- net: sparx5: unregister blocking notifier on init failure (Haoxiang Li)
- can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp)
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp)
- can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp)
- nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas)
- sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794431] {CVE-2026-64551}
- spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi)
- time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan)
- tpm: Make the TPM character devices non-seekable (Jaewon Yang)
- tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum)
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan)
- xen/gntdev: fix error handling in ioctl (Xu Wang)
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang)
- i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar)
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi)
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs)
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito)
- ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito)
- ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito)
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges)
- ocfs2: avoid moving extents to occupied clusters (Kyle Zeng)
- mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov)
- net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev)
- mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet)
- ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani)
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck)
- mtd: slram: remove failed entries from the device list (Ruoyu Wang)
- proc: only bump parent nlink when registering directories (Krzysztof Wilczyński)
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin)
- power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang)
- ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani)
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito)
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used (Michael Bommarito)
- fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito)
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito)
- fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov)
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov)
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov)
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng)
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki)
- MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold)
- MIPS: ip22-gio: fix kfree() of static object (Johan Hovold)
- MIPS: ip22-gio: fix gio device memory leak (Johan Hovold)
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever)
- lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever)
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal)
- nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal)
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo)
- Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen)
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen)
- mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski)
- batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann)
- batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann)
- batman-adv: frag: free unfragmentable packet (Sven Eckelmann)
- batman-adv: fix VLAN priority offset (Sven Eckelmann)
- batman-adv: tt: avoid request storms during pending request (Sven Eckelmann)
- batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann)
- batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann)
- batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann)
- batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann)
- batman-adv: access unicast_ttvn skb->data only after skb realloc (Sven Eckelmann)
- batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann)
- x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum)
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum)
- mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li)
- leds: uleds: Fix potential buffer overread (Armin Wolf)
- soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun)
- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli)
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li)
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794442] {CVE-2026-64554}
- netfilter: xt_nat: reject unsupported target families (Wyatt Feng)
- netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao)
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei)
- netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal)
- netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng)
- netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier)
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal)
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal)
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal)
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal)
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal)
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal)
- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal)
- fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal)
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal)
- fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing)
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal)
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal)
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal)
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim)
- arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen)
- net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang)
- net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang)
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito)
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci)
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang)
- smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li)
- net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing)
- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi)
- regulator: core: Make regulator_lock_two() logic easier to follow (Douglas Anderson)
- dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui)
- ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov)
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao)
- ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao)
- ipvs: pass parsed transport offset to state handlers (Yizhou Zhao)
- ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet)
- ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima)
- octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh)
- net/sched: cake: reject overhead values that underflow length (Samuel Moelius)
- net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon)
- ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang)
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794421] {CVE-2026-64549}
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen)
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei)
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei)
- net: qualcomm: rmnet: add tx packets aggregation (Daniele Palmas)
- qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida)
- netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng)
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen)
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu)
- netfilter: xt_u32: reject invalid shift counts (Wyatt Feng)
- gue: validate REMCSUM private option length (Qihang)
- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794412] {CVE-2026-64547}
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual)
- HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones)
- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin)
- ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak)
- afs: Fix unchecked-length string display in debug statement (David Howells)
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells)
- afs: Fix vllist leak (David Howells)
- afs: Fix callback service message parsers to pass through -EAGAIN (David Howells)
- afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter)
- net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius)
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim)
- cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov)
- virtio_net: disable cb when NAPI is busy-polled (Longjun Tang)
- irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi)
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser)
- tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu)
- bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel)
- net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev)
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794387] {CVE-2026-64540}
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang)
- ipv6: remove RTNL protection from inet6_dump_fib() (Eric Dumazet)
- inet: allow ip_valid_fib_dump_req() to be called with RTNL or RCU (Eric Dumazet)
- rtnetlink: add RTNL_FLAG_DUMP_UNLOCKED flag (Eric Dumazet)
- rtnetlink: change nlk->cb_mutex role (Eric Dumazet)
- hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen)
- qede: fix out-of-bounds check for cqe->len_list[] (Matvey Kovalev)
- seg6: validate SRH length before reading fixed fields (Nuoqi Gui)
- gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou)
- gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou)
- spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou)
- tracing: probes: fix typo in a log message (Martin Kaiser)
- net: sungem: fix probe error cleanup (Ruoyu Wang)
- net: mvneta: re-enable percpu interrupt on resume (Yun Zhou)
- rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li)
- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson)
- smb/client: preserve errors from smb2_set_sparse() (Huiwen He)
- ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera)
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787017] {CVE-2026-64530}
- veth: fix NAPI leak in XDP enable error path (Eric Dumazet)
- net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona)
- net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794405] {CVE-2026-64545}
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczyński)
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczyński)
- NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den)
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot (Runyu Xiao)
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera)
- ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima)
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794379] {CVE-2026-64538}
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy)
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794408] {CVE-2026-64546}
- bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar)
- bpf: Fix stack slot index in nospec checks (Nuoqi Gui)
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton)
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski)
- selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan)
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil)
- selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil)
- irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi)
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal)
- netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal)
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik)
- ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh)
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov)
- ACPI: resource: Amend kernel-doc style (Andy Shevchenko)
- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri)
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao)
- dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei)
- sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long)
- net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794438] {CVE-2026-64553}
- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (Ratheesh Kannoth)
- xfrm: validate selector family and prefixlen during match (Eric Dumazet)
- sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou)
- apparmor: fix label can not be immediately before a declaration (John Johansen)
- i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter)
- apparmor: put secmark label after secid lookup (Zygmunt Krynicki)
- apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki)
- apparmor: fix potential UAF in aa_replace_profiles (Maxime Bélair)
- apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee)
- apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki)
- apparmor: check label build before no_new_privs test (Ruoyu Wang)
- PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam)
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee)
- tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo)
- tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo)
- tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo)
- xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason)
- PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar)
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer)
- NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo)
- pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg)
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney)
- dmaengine: Fix possible use after free (Nuno Sa)
- dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng)
- drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam)
- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev)
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda)
- iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts)
- iio: light: si1133: prevent race condition on timeout (Joshua Crofts)
- iio: light: si1133: reset counter to prevent race condition (Joshua Crofts)
- char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim)
- usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae)
- staging: most: video: avoid double free on video register failure (Guangshuo Li)
- phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko)
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki)
- x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki)
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan)
- coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng)
- staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu)
- net/9p: fix race condition on rdma->state in trans_rdma.c (Yizhou Zhao)
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh)
- ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li)
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet)
- tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet)
- KEYS: Use acquire when reading state in keyring search (Gui-Dong Han)
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan)
- powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan)
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan)
- MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan)
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim)
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794417] {CVE-2026-64548}
- smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He)
- netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal)
- kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao)
- bpf: Run generic devmap egress prog on private skb (Sun Jian)
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg)
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg)
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li)
- spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Pöschel)
- crypto: rng - Free default RNG on module exit (Herbert Xu)
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu)
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu)
- tipc: reject inverted service ranges from peer bindings (Michael Bommarito)
- tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito)
- tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito)
- net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira)
- sctp: validate embedded address parameter length (Xin Long)
- bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei)
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima)
- ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An)
- ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An)
- ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An)
- RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla)
- RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad)
- fs: efs: remove unneeded debug prints (Maxwell Doose)
- s390/process: Fix kernel thread function pointer type (Heiko Carstens)
- bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann)
- selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song)
- bonding: 3ad: fix mux port state on oper down (Louis Scalbert)
- tools/virtio: check mmap return value in vringh_test (Longlong Yan)
- vduse: Requeue failed read to send_list head (Zhang Tianci)
- vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang)
- vduse: hold vduse_lock across IDR lookup in open path (Qihang)
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe)
- fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight)
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana)
- hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang)
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu)
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- watchdog: unregister PM notifier on watchdog unregister (Yuho Choi)
- configfs: fix lockless traversals of ->s_children (Al Viro)
- firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov)
- spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu)
- IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe)
- IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe)
- cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang)
- ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi)
- ALSA: seq: Clear variable event pointer on read (Kyle Zeng)
- ALSA: seq: Add UMP support (Takashi Iwai)
- ALSA: seq: Introduce SNDRV_SEQ_IOCTL_USER_PVERSION ioctl (Takashi Iwai)
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi)
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani)
- bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang)
- RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni)
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe)
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso)
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera)
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera)
- ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi)
- ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen)
- ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen)
- ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov)
- ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen)
- bpftool: Use libbpf error code for flow dissector query (Woojin Ji)
- configfs_lookup(): don't leave ->s_dentry dangling on failure (Al Viro)
- lib/test_meminit: use && for bools (Alexander Potapenko)
- mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon)
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey)
- scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter)
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" (Martin Wilck)
- ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi)
- ARM: imx3: Fix CCM node reference leak (Yuho Choi)
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi)
- md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng)
- media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han)
- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han)
- media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han)
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin)
- drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang)
- drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang)
- crypto: hisilicon/qm - disable error report before flr (Weili Qian)
- ocfs2: kill osb->system_file_mutex lock (Tetsuo Handa)
- ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang)
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter)
- dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso)
- libbpf: Fix UAF in strset__add_str() (Carlos Llamas)
- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi)
- drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen)
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu)
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen)
- ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet)
- workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao)
- nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff)
- mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal)
- mips: n64: add __iomem for writel call (Rosen Penev)
- mips: ralink: mt7621: add missing __iomem (Rosen Penev)
- MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki)
- MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki)
- PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu)
- RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa)
- IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li)
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni)
- bus: sunxi-rsb: Always check register address validity (Samuel Holland)
- pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez)
- cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng)
- cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang)
- device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev)
- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven)
- media: rockchip: rga: fix too small buffer size (Sven Püschel)
- net/sched: sch_drr: annotate data-races around cl->deficit (Eric Dumazet)
- sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman)
- firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla)
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan)
- RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh)
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande)
- RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov)
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li)
- net/sched: sch_htb: annotate data-races (I) (Eric Dumazet)
- net/sched: sch_htb: do not change sch->flags in htb_dump() (Eric Dumazet)
- crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson)
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet)
- thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki)
- evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou)
- drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He)
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He)
- clk: scmi: Fix clock rate rounding (Cristian Marussi)
- iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson)
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794401] {CVE-2026-64544}
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum)
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch)
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu)
- media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland)
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu)
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie)
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi)
- wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani)
- kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng)
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani)
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (Danilo Krummrich)
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi)
- drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen)
- fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges)
- afs: Fix further netns teardown to cancel the preallocation charger (David Howells)
- afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev)
- afs: Fix netns teardown to cancel the preallocation charger (David Howells)
- serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser)
- serial: msm: Disable DMA for kernel console UART (Stephan Gerhold)
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai)
- media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda)
- media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda)
- crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers)
- crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: crypto4xx - Remove ahash-related code (Herbert Xu)
- crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers)
- net: dsa: tag_ksz: do not rely on skb_mac_header() in TX paths (Vladimir Oltean)
- tools/mm/slabinfo: fix total_objects attribute name (Chenyichong)
- crypto: algif_skcipher - force synchronous processing on trees without ctx->state (Muhammet Kaan Kilinç)
- sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li)
- xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760871] {CVE-2026-64187}
- fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785786] {CVE-2026-64266}
- fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz)
- RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito)
- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan)
- Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov)
- Input: maplemouse - set driver data before registering input device (Dmitry Torokhov)
- Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov)
- Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov)
- Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs)
- Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785802] {CVE-2026-64271}
- Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas)
- Input: goodix - clamp the device-reported contact count (Bryam Vargas)
- Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785819] {CVE-2026-64275}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785823] {CVE-2026-64276}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas)
- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li)
- i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodríguez)
- i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785831] {CVE-2026-64279}
- udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov)
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843616] {CVE-2026-64604}
- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den)
- exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785863] {CVE-2026-64296}
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785868] {CVE-2026-64298}
- tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785872] {CVE-2026-64299}
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song)
- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song)
- crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel)
- crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers)
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers)
- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785893] {CVE-2026-64306}
- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785906] {CVE-2026-64312}
- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785910] {CVE-2026-64313}
- crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum)
- isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785923] {CVE-2026-64317}
- partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas)
- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi)
- dm-ioctl: report an error if a device has no table (Mikulas Patocka)
- udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785940] {CVE-2026-64322}
- udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785944] {CVE-2026-64323}
- udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785948] {CVE-2026-64324}
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan)
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M)
- usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski)
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785963] {CVE-2026-64330}
- usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day) [Orabug: 39785967] {CVE-2026-64331}
- usbip: tools: support SuperSpeedPlus devices (Chenyichong)
- USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao)
- USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785971] {CVE-2026-64332}
- USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785975] {CVE-2026-64333}
- USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785979] {CVE-2026-64334}
- USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785983] {CVE-2026-64335}
- USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda)
- USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785987] {CVE-2026-64336}
- usb: mtu3: unmap request DMA on queue failure (Haoxiang Li)
- USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785994] {CVE-2026-64338}
- USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao)
- usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak)
- USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785999] {CVE-2026-64340}
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover)
- USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786007] {CVE-2026-64342}
- USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786012] {CVE-2026-64343}
- USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786017] {CVE-2026-64344}
- usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu) [Orabug: 39786026] {CVE-2026-64346}
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie) [Orabug: 39786030] {CVE-2026-64347}
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang)
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceição Alves)
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li)
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge)
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786042] {CVE-2026-64351}
- xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih)
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey)
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani)
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada)
- HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786071] {CVE-2026-64362}
- HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859299] {CVE-2026-68091}
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786091] {CVE-2026-64370}
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786100] {CVE-2026-64372}
- cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786104] {CVE-2026-64373}
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786108] {CVE-2026-64374}
- cpufreq: intel_pstate: Sync policy->cur during CPU offline (Wangfushuai)
- net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331701] {CVE-2026-43216}
- Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786205] {CVE-2026-64403}
- Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786578] {CVE-2026-64406}
- Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786217] {CVE-2026-64408}
- netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786224] {CVE-2026-64411}
- netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786228] {CVE-2026-64412}
- mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786248] {CVE-2026-64420}
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786254] {CVE-2026-64422}
- ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786259] {CVE-2026-64423}
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786574] {CVE-2026-64425}
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den)
- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian)
- debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner)
- audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786289] {CVE-2026-64435}
- net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786293] {CVE-2026-64436}
- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843604] {CVE-2026-64599}
- staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu) [Orabug: 39786303] {CVE-2026-64440}
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu) [Orabug: 39789581] {CVE-2026-64536}
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu) [Orabug: 39786311] {CVE-2026-64442}
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu) [Orabug: 39786315] {CVE-2026-64443}
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu) [Orabug: 39786319] {CVE-2026-64444}
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu) [Orabug: 39786323] {CVE-2026-64445}
- staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann)
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda)
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786340] {CVE-2026-64450}
- 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786344] {CVE-2026-64452}
- usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao) [Orabug: 39786349] {CVE-2026-64454}
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786352] {CVE-2026-64455}
- hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786356] {CVE-2026-64456}
- virtio-mmio: fix device release warning on module unload (Johan Hovold)
- netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760883] {CVE-2026-64189}
- PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth)
- PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya)
- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786379] {CVE-2026-64465}
- binder: fix UAF in binder_free_transaction() (Carlos Llamas)
- binder: fix UAF in binder_thread_release() (Carlos Llamas)
- Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold)
- Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786393] {CVE-2026-64470}
- Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786397] {CVE-2026-64471}
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Roll back quirk control caches on write errors (Cássio Gabriel)
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cássio Gabriel)
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cássio Gabriel)
- ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786416] {CVE-2026-64478}
- ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie) [Orabug: 39786428] {CVE-2026-64483}
- ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786432] {CVE-2026-64484}
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786439] {CVE-2026-64487}
- ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cássio Gabriel)
- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan)
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko)
- iio: light: veml6030: fix channel type when pushing events (Javier Carrasco)
- iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev)
- iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts)
- iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya)
- iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal)
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe)
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao)
- iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev)
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev)
- iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786462] {CVE-2026-64496}
- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose)
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou)
- iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786478] {CVE-2026-64503}
- iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786482] {CVE-2026-64504}
- usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman)
- usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman)
- ksmbd: fix out-of-bounds read in smb_check_perm_dacl() (Hem Parekh)
- NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753894] {CVE-2026-53392}
- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753924] {CVE-2026-53402}
- i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753916] {CVE-2026-53400}
- i2c: core: fix adapter debugfs creation (Johan Hovold)
- i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold)
- i2c: core: fix hang on adapter registration failure (Johan Hovold)
- i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold)
- block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753985] {CVE-2026-63810}
- f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma)
- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu)
- f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi)
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas)
- f2fs: validate orphan inode entry count (Wenjie Qi)
- device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski)
- f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong)
- f2fs: adjust zone capacity when considering valid block count (Jaegeuk Kim)
- f2fs: validate compress cache inode only when enabled (Wenjie Qi)
- f2fs: fix to detect corrupted meta ino (Chao Yu)
- apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas)
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754045] {CVE-2026-63829}
- apparmor: fix use-after-free in rawdata dedup loop (Ruslan Valiyev)
- net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754049] {CVE-2026-63830}
- skmsg: convert struct sk_msg_sg::copy to a bitmap (Eric Dumazet)
- netfilter: nf_tables: restore set elements when delete set fails (Pablo Neira Ayuso) [Orabug: 36598010] {CVE-2024-27012}
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753972] {CVE-2026-63806}
- nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown)
- nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown)
- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson)
- slimbus: Convert to platform remove callback returning void (Uwe Kleine-König)
- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson)
- dma-buf: remove unused dma-fence-unwrap.c (stable/linux-5.15.y only) (Tudor Ambarus)
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela)
- clk: imx: Add check for kcalloc (Jiasheng Jiang)
- userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786515] {CVE-2026-64514}
- nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753898] {CVE-2026-53393}
- nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753912] {CVE-2026-53399}
- nfc: llcp: protect nfc_llcp_sock_unlink() calls (Krzysztof Kozlowski)
- nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni) [Orabug: 39460310] {CVE-2026-46135}
-
Fri Aug 07 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.211.2.el9uek]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558744] {CVE-2026-74684}
- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39801953]
- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812533]
- net/rds: Add parentheses around conditional operator (Gerd Rausch) [Orabug: 39844638]
- net/rds: remove cached rds_sock->rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832354]
- Revert "rds: cong: Make rds_cong_wait an array to reduce lock contention" (Sharath Srinivasan) [Orabug: 39832354]
- rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772650]
- rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772650]
- net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621715,39638197] {CVE-2026-52995}
- x86/sev: Evict cache lines during SNP memory validation (Tom Lendacky) [Orabug: 38334919] {CVE-2025-38560}
- Revert: uek-rpm: cnic: Trim the SNIC config for a faster boot (Kan Liang) [Orabug: 39825570]
- Revert: uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Kan Liang) [Orabug: 39825570]
- rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818509]
- rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818509]
- drm/amdkfd: fix invalid GTT pointer in DQM cleanup (Imran Khan) [Orabug: 39605741]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick Wong) [Orabug: 39776791] {CVE-2026-64600}
-
Thu Jul 30 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-324.211.1.el9uek]
- signal: Fix use-after-free of wait_chldexit (Aruna Ramakrishna) [Orabug: 39800301]
- mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mm/filemap: make filemap_fault() to retry fault after collapse_file() (Jane Chu) [Orabug: 39778847]
- PM: hibernate: Fix backwards snapshot_test condition for test_resume mode (Jeremy Tang) [Orabug: 39766052]
- PM: hibernate: Do not get block device exclusively in test_resume mode (Chen Yu) [Orabug: 39766052]
- PM: hibernate: Turn snapshot_test into global variable (Chen Yu) [Orabug: 39766052]
- PM: hibernate: fix load_image_and_restore() error path (Ye Bin) [Orabug: 39766052]
- arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation (Catalin Marinas) [Orabug: 39750197]
- net/rds: Don't drop the ball when RDS_MSG_CANCELED is encountered (Gerd Rausch) [Orabug: 39563154]
- uek: kabi: update x86_64 kABI files for a new symbol (Saeed Mirzamohammadi) [Orabug: 39651629]
- iommu/arm-smmu-v3: Fix section mismatch warning: httu_quirk (Dave Kleikamp) [Orabug: 39738961]
- iommu/amd: Fix error path in amd_iommu_probe_device() (Vasant Hegde) [Orabug: 39252877]
- iommu/amd: Enable support for up to 2K interrupts per function (Kishon Vijay Abraham I) [Orabug: 39252877]
- iommu/amd: Rename DTE_INTTABLEN* and MAX_IRQS_PER_TABLE macro (Sairaj Kodilkar) [Orabug: 39252877]
- iommu/amd: Replace slab cache allocator with page allocator (Sairaj Kodilkar) [Orabug: 39252877]
- iommu/amd: Introduce generic function to set multibit feature value (Sairaj Kodilkar) [Orabug: 39252877]
-
Mon Jul 20 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-323.211.3.el9uek]
- LTS version: v5.15.211 (Vijayendra Suman)
- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844553] {CVE-2025-23131}
- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786549] {CVE-2026-64529}
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)
- Documentation: ioctl-number: Extend "Include File" column width (Bagas Sanjaya)
- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)
- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753883] {CVE-2026-53388}
- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri) [Orabug: 39637380] {CVE-2026-53157}
- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)
- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)
- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)
- misc: fastrpc: Add dma_mask to fastrpc_channel_ctx (Abel Vesa)
- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)
- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753890] {CVE-2026-53391}
- nfsd: check get_user() return when reading princhashlen (Dominik Woźniak)
- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753905] {CVE-2026-53397}
- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753909] {CVE-2026-53398}
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753928] {CVE-2026-53403}
- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753936] {CVE-2026-63794}
- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753942] {CVE-2026-63796}
- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)
- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753953] {CVE-2026-63800}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753957] {CVE-2026-63801}
- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753963] {CVE-2026-63803}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753979] {CVE-2026-63808}
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)
- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753982] {CVE-2026-63809}
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)
- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754021] {CVE-2026-63822}
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)
- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754024] {CVE-2026-63823}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754028] {CVE-2026-63824}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754053] {CVE-2026-63831}
- crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503789] {CVE-2025-39931}
- ext4: add bounds check for inline data length in ext4_read_inline_page (Yuto Ohnuki)
- ntfs3: reject direct userspace writes to reserved $LX* xattrs (Konstantin Komarov)
- ring-buffer: Remove ring_buffer_read_prepare_sync() (Bjoern Doebel)
- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)
- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)
- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)
- batman-adv: tt: track roam count per VID (Sven Eckelmann)
- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)
- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)
- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)
- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754066] {CVE-2026-63834}
- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754070] {CVE-2026-63835}
- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)
- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)
- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)
- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)
- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)
- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)
- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754076] {CVE-2026-63836}
- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)
- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)
- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)
- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)
- kselftest/arm64: signal: Skip SVE signal test if not enough VLs supported (Yijia Wang)
- Revert "ptp: add testptp mask test" (Petr Machata)
- Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753856] {CVE-2026-53381}
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753871] {CVE-2026-53385}
- regulator: core: fix locking in regulator_resolve_supply() error path (André Draszik) [Orabug: 39489558] {CVE-2026-46252}
- af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) [Orabug: 39619334] {CVE-2026-52928}
- xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman)
- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662073] {CVE-2026-53325}
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)
- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760892] {CVE-2026-64191}
- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg)
- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)
- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)
- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)
- drm/v3d: Skip CSD when it has zeroed workgroups (Maíra Canal)
- drm/v3d: Store the active job inside the queue's state (Maíra Canal)
- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589885] {CVE-2026-52909}
- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637312] {CVE-2026-53138}
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637410] {CVE-2026-53167}
- LTS version: v5.15.210 (Vijayendra Suman)
- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637279] {CVE-2026-53131}
- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)
- batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann)
- ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev)
- Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz)
- media: rc: igorplugusb: fix control request setup packet (Henri A) [Orabug: 39785220] {CVE-2026-64240}
- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) [Orabug: 39784982] {CVE-2026-64092}
- media: rc: ttusbir: fix inverted error logic (Oliver Neukum)
- apparmor: validate default DFA states are in bounds (Ben Hutchings)
- fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter (Ben Hutchings)
- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754146] {CVE-2026-63867}
- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon) {CVE-2025-10263}
- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni) {CVE-2025-10263}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674327] {CVE-2025-10263,CVE-2026-53354}
- arm64: cputype: Add NVIDIA Olympus definitions (Shanker Donthineni)
- selinux: enable genfscon labeling for securityfs (Christian Göttsche)
- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt)
- ksmbd: Compare MACs in constant time (Eric Biggers)
- net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343685] {CVE-2026-43341}
- batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann)
- batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) [Orabug: 39460622] {CVE-2026-46208}
- blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (Tejun Heo)
- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451541] {CVE-2026-45850}
- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637477] {CVE-2026-53189}
- RDMA/umem: Fix truncation for block sizes >= 4G (Jason Gunthorpe)
- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)
- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)
- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637516] {CVE-2026-53199}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637292] {CVE-2026-53134}
- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)
- tty: serial: qcom-geni-serial: align #define values (Bartosz Golaszewski)
- tty: serial: qcom-geni-serial: remove unused symbols (Bartosz Golaszewski)
- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)
- serial: altera_jtaguart: Use platform_get_irq_optional() to get the interrupt (Lad Prabhakar)
- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786537] {CVE-2026-64524}
- drm/hyperv: Remove support for Hyper-V 2008 and 2008R2/Win7 (Michael Kelley)
- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)
- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754211] {CVE-2026-63891}
- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)
- usb: gadget: f_hid: tidy error handling in hidg_alloc (John Keeping)
- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)
- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786545] {CVE-2026-64528}
- tty: serial: samsung: use u32 for register interactions (Tudor Ambarus)
- serial: samsung_tty: Use port lock wrappers (Thomas Gleixner)
- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)
- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)
- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)
- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)
- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)
- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681273] {CVE-2026-53358}
- phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang)
- phy: tegra: xusb: Disable trk clk when not in use (Wayne Chang)
- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755010] {CVE-2026-63875}
- spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) [Orabug: 39754942] {CVE-2026-64170}
- spi: qup: switch to use modern name (Yang Yingliang)
- octeontx2-pf: avoid double free of pool->stack on AQ init failure (Dawei Feng)
- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly)
- mptcp: do not drop partial packets (Shardul Bankar)
- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)
- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)
- use less confusing names for iov_iter direction initializers (Al Viro)
- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) [Orabug: 39754825] {CVE-2026-64116}
- ipv6/addrconf: annotate data-races around devconf fields (II) (Eric Dumazet)
- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)
- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754840] {CVE-2026-64123}
- Bluetooth: serialize accept_q access (Jiexun Wang) [Orabug: 39619283] {CVE-2026-52918}
- Bluetooth: Init sk_peer_* on bt_sock_alloc (Luiz Augusto von Dentz)
- Bluetooth: Consolidate code around sk_alloc into a helper function (Luiz Augusto von Dentz)
- qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) [Orabug: 39754830] {CVE-2026-64118}
- Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) [Orabug: 39754849] {CVE-2026-64126}
- Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2 (Luiz Augusto von Dentz)
- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)
- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakuş) [Orabug: 39681270] {CVE-2026-53357}
- smb: client: require net admin for CIFS SWN netlink (Michael Bommarito)
- genetlink: Use internal flags for multicast groups (Ido Schimmel)
- spi: lantiq-ssc: fix controller deregistration (Johan Hovold)
- spi: st-ssc4: fix controller deregistration (Johan Hovold)
- f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu)
- f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang)
- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts)
- mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts) [Orabug: 39460320] {CVE-2026-46137}
- mptcp: pm: prio: skip closed subflows (Matthieu Baerts)
- smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva)
- btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) [Orabug: 39460410] {CVE-2026-46160}
- smb: client: validate dacloffset before building DACL pointers (Michael Bommarito)
- pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) [Orabug: 39524579] {CVE-2026-46292}
- tracing/probes: Limit size of event probe to 3K (Steven Rostedt)
- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) [Orabug: 39460405] {CVE-2026-46159}
- spi: topcliff-pch: fix controller deregistration (Johan Hovold)
- spi: topcliff-pch: Convert to platform remove callback returning void (Uwe Kleine-König)
- fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) [Orabug: 39460548] {CVE-2026-46191}
- mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon)
- spi: uniphier: fix controller deregistration (Johan Hovold)
- spi: tegra20-sflash: fix controller deregistration (Johan Hovold)
- spi: tegra114: fix controller deregistration (Johan Hovold)
- spi: sun6i: fix controller deregistration (Johan Hovold)
- spi: zynq-qspi: fix controller deregistration (Johan Hovold)
- spi: ti-qspi: fix controller deregistration (Johan Hovold)
- spi: spi-ti-qspi: Convert to platform remove callback returning void (Uwe Kleine-König)
- spi: sun4i: fix controller deregistration (Johan Hovold)
- spi: syncuacer: fix controller deregistration (Johan Hovold)
- xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) [Orabug: 39460554] {CVE-2026-46193}
- net: ipv6: stop checking crypto_ahash_alignmask (Eric Biggers)
- net: ipv4: stop checking crypto_ahash_alignmask (Eric Biggers)
- usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan)
- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) [Orabug: 39460504] {CVE-2026-46180}
- usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne)
- smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito)
- tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) [Orabug: 39460568] {CVE-2026-46196}
- crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum)
- printk: add print_hex_dump_devel() (Thorsten Blum)
- ALSA: aloop: Fix peer runtime UAF during format-change stop (Cássio Gabriel) [Orabug: 39452424] {CVE-2026-46090}
- ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452292] {CVE-2026-46052}
- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo)
- can: ucan: fix devres lifetime (Johan Hovold)
- can: ucan: fix typos in comments (Julia Lawall)
- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452305] {CVE-2026-46056}
- hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan)
- hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey)
- udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) [Orabug: 39452078] {CVE-2026-45991}
- mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S)
- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin)
- randomize_kstack: Maintain kstack_offset per task (Ryan Roberts)
- fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) [Orabug: 39452332] {CVE-2026-46065}
- net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452412] {CVE-2026-46086}
- net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452124] {CVE-2026-46003}
- net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming)
- net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452247] {CVE-2026-46038}
- net: qrtr: ns: Change servers radix tree to xarray (Vignesh Viswanathan)
- net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452208] {CVE-2026-46026}
- ALSA: core: Fix potential data race at fasync handling (Takashi Iwai)
- sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury)
- media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452433] {CVE-2026-46091}
- erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang)
- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum)
- media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum)
- ALSA: aoa: i2sbus: clear stale prepared state (Cássio Gabriel)
- ALSA: aoa: Use guard() for mutex locks (Takashi Iwai)
- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452344] {CVE-2026-46069}
- thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452187] {CVE-2026-46021}
- wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452438] {CVE-2026-46092}
- rtw88: 8821ce: Disable PCIe ASPM L1 for 8821CE using chip ID (Jimmy Hon)
- arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual)
- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) [Orabug: 39300581] {CVE-2026-31700}
- ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito)
- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito)
- smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito)
- smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang)
- smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito)
- f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() (Yongpeng Yang)
- f2fs: fix to do sanity check on dcc->discard_cmd_cnt conditionally (Chao Yu)
- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner)
- net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343806] {CVE-2026-43383}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) [Orabug: 39619351] {CVE-2026-52933}
- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)
- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655978] {CVE-2026-52946}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674253] {CVE-2026-53329}
- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637296] {CVE-2026-53135}
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637301] {CVE-2026-53136}
- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland)
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (Bjorn Andersson)
- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637337] {CVE-2026-53146}
- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637346] {CVE-2026-53148}
- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637351] {CVE-2026-53149}
- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637356] {CVE-2026-53150}
- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619338] {CVE-2026-52929}
- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619278] {CVE-2026-52917}
- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)
- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)
- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)
- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)
- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674284] {CVE-2026-53337}
- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)
- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)
- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619342] {CVE-2026-52930}
- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)
- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)
- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)
- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodríguez)
- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)
- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637414] {CVE-2026-53168}
- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637428] {CVE-2026-53176}
- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637432] {CVE-2026-53177}
- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637447] {CVE-2026-53181}
- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)
- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)
- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)
- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)
- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637467] {CVE-2026-53186}
- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)
- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637489] {CVE-2026-53192}
- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637496] {CVE-2026-53194}
- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637502] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637506] {CVE-2026-53196}
- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)
- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674335] {CVE-2026-53356}
- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637545] {CVE-2026-53208}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637555] {CVE-2026-53212}
- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637561] {CVE-2026-53213}
- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)
- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637568] {CVE-2026-53215}
- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)
- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637571] {CVE-2026-53216}
- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637575] {CVE-2026-53217}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637578] {CVE-2026-53218}
- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619384] {CVE-2026-52942}
- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637582] {CVE-2026-53219}
- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637592] {CVE-2026-53221}
- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637599] {CVE-2026-53223}
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637609] {CVE-2026-53225}
- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637618] {CVE-2026-53227}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637622] {CVE-2026-53228}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621562] {CVE-2026-52947}
- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637662] {CVE-2026-53238}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637666] {CVE-2026-53239}
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland)
- KVM: arm64: Remove VPIPT I-cache handling (Marc Zyngier)
- nfsd: don't ignore the return code of svc_proc_register() (Jeff Layton) [Orabug: 37844165] {CVE-2025-22026}
- fs/ntfs3: Return error for inconsistent extended attributes (Edward Lo)
- ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250744] {CVE-2026-31449}
- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)
- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674319] {CVE-2026-53352}
- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619311] {CVE-2026-52924}
- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637680] {CVE-2026-53245}
- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754155] {CVE-2026-63870}
- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637694] {CVE-2026-53249}
- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39785002] {CVE-2026-53252}
- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637706] {CVE-2026-53253}
- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)
- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637711] {CVE-2026-53254}
- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637716] {CVE-2026-53255}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637720] {CVE-2026-53256}
- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson)
- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754149] {CVE-2026-63868}
- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)
- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)
- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637741] {CVE-2026-53263}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637748] {CVE-2026-53264}
- dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39784967] {CVE-2026-53265}
- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637753] {CVE-2026-53266}
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637763] {CVE-2026-53268}
- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637768] {CVE-2026-53269}
- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637772] {CVE-2026-53270}
- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)
- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637782] {CVE-2026-53273}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637790] {CVE-2026-53275}
- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621568] {CVE-2026-52948}
- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)
- compiler-clang.h: Add __diag infrastructure for clang (Nathan Chancellor)
- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754236] {CVE-2026-63898}
- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589889] {CVE-2026-52910}
- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michał Pecio)
- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)
- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)
- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754248] {CVE-2026-63901}
- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)
- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)
- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)
- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754408] {CVE-2026-63956}
- serial: zs: Switch to using channel reset (Maciej W. Rozycki)
- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)
- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)
- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)
- serial: sh-sci: fix memory region release in error path (Hongling Zeng)
- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786542] {CVE-2026-64527}
- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754216] {CVE-2026-63892}
- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754220] {CVE-2026-63893}
- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)
- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)
- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754232] {CVE-2026-63897}
- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754240] {CVE-2026-63899}
- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754244] {CVE-2026-63900}
- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754252] {CVE-2026-63902}
- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754256] {CVE-2026-63903}
- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong)
- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)
- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)
- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754260] {CVE-2026-63904}
- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito) [Orabug: 39754264] {CVE-2026-63905}
- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)
- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)
- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michał Pecio)
- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)
- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)
- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)
- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)
- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolás Bazaes)
- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754271] {CVE-2026-63908}
- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754278] {CVE-2026-63912}
- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)
- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754282] {CVE-2026-63913}
- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)
- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754286] {CVE-2026-63914}
- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)
- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)
- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754294] {CVE-2026-63916}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754298] {CVE-2026-63917}
- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754304] {CVE-2026-63919}
- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754307] {CVE-2026-63920}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754311] {CVE-2026-63921}
- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754315] {CVE-2026-63922}
- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754322] {CVE-2026-63924}
- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754326] {CVE-2026-63925}
- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754329] {CVE-2026-63926}
- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785158] {CVE-2026-64237}
- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754333] {CVE-2026-63927}
- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)
- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)
- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754337] {CVE-2026-63928}
- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)
- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)
- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)
- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)
- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)
- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)
- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)
- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)
- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)
- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)
- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)
- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754375] {CVE-2026-63942}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754387] {CVE-2026-63947}
- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754391] {CVE-2026-63948}
- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619307] {CVE-2026-52923}
- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)
- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)
- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)
- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754412] {CVE-2026-63957}
- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)
- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754428] {CVE-2026-63961}
- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)
- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)
- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)
- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher)
- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)
- phy: mscc: Use PHY_ID_MATCH_VENDOR to minimize PHY ID table (Harini Katakam)
- RDMA/rxe: Fix double free in rxe_srq_from_init (Jiasheng Jiang) [Orabug: 39451551] {CVE-2026-45852}
- Revert "RDMA/rxe: Fix double free in rxe_srq_from_init" (Ben Hutchings)
- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Högander)
- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)
- drm/i915/psr: Read Intel DPCD workaround register (Jouni Högander)
- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Högander)
- wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456849] {CVE-2025-39863}
- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754761] {CVE-2026-64095}
- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754744] {CVE-2026-64090}
- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754748] {CVE-2026-64091}
- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)
- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619357] {CVE-2026-52934}
- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754757] {CVE-2026-64094}
- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)
- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann)
- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754456] {CVE-2026-63971}
- gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (Marco Scardovi)
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754468] {CVE-2026-63975}
- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754471] {CVE-2026-63976}
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754489] {CVE-2026-63984}
- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754492] {CVE-2026-63985}
- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754502] {CVE-2026-63990}
- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)
- ASoC: codecs: simple-mux: Fix enum control bounds check (Cássio Gabriel)
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754510] {CVE-2026-63992}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754513] {CVE-2026-63993}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754516] {CVE-2026-63994}
- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cássio Gabriel)
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754536] {CVE-2026-64002}
- net/iucv: fix locking in .getsockopt (Breno Leitao)
- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)
- net: netlink: don't set nsid on local notifications (Ilya Maximets)
- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)
- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619329] {CVE-2026-52927}
- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754553] {CVE-2026-64007}
- nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee)
- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754558] {CVE-2026-64009}
- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)
- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)
- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)
- dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323060] {CVE-2026-43064}
- drm: Remove plane hsub/vsub alignment requirement for core helpers (Carlos Eduardo Gallo Filho)
- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754570] {CVE-2026-64012}
- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr)
- net/sched: cls_fw: fix NULL dereference of "old" filters before change() (Davide Caratti) [Orabug: 39622011] {CVE-2026-53080}
- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754575] {CVE-2026-64014}
- LTS version: v5.15.209 (Samasth Norway Ananda)
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) [Orabug: 39754586] {CVE-2026-64018}
- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski)
- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko)
- string: add mem_is_zero() helper to check if memory area is all zeros (Jani Nikula)
- net: ag71xx: check error for platform_get_irq (Rosen Penev)
- tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) [Orabug: 39784962] {CVE-2026-64028}
- bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) [Orabug: 39754613] {CVE-2026-64032}
- net: bridge: Flush multicast groups when snooping is disabled (Petr Machata)
- RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li)
- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)
- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) [Orabug: 39754619] {CVE-2026-64034}
- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle)
- net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw (Arınç Ünal)
- net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle)
- net: dsa: mt7530: sync driver-specific behavior of MT7531 variants (Daniel Golle)
- drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) [Orabug: 39754629] {CVE-2026-64039}
- net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) [Orabug: 39754638] {CVE-2026-64046}
- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) [Orabug: 39754642] {CVE-2026-64047}
- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) [Orabug: 39754904] {CVE-2026-64153}
- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao)
- HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn)
- wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) [Orabug: 39754909] {CVE-2026-64155}
- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore)
- net: ethernet: cortina: Carry over frag counter (Linus Walleij)
- net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann)
- net: ethernet: cortina: Make RX SKB per-port (Linus Walleij)
- irqchip/ath79-cpu: Remove unused function (Rosen Penev)
- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos)
- ice: fix locking in ice_dcb_rebuild() (Bart Van Assche)
- tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima)
- netfilter: x_tables: unregister the templates first (Florian Westphal)
- ARM: integrator: Fix early initialization (Guenter Roeck)
- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow)
- kunit: config: Enable KUNIT_DEBUGFS by default (David Gow)
- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla)
- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) [Orabug: 39754932] {CVE-2026-64166}
- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain)
- batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) [Orabug: 39754734] {CVE-2026-64088}
- batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) [Orabug: 39754740] {CVE-2026-64089}
- batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) [Orabug: 39619346] {CVE-2026-52931}
- batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann) [Orabug: 39785109] {CVE-2026-64218}
- batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) [Orabug: 39619274] {CVE-2026-52916}
- batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) [Orabug: 39619287] {CVE-2026-52919}
- batman-adv: fix fragment reassembly length accounting (Ruide Cao) [Orabug: 39619266] {CVE-2026-52914}
- batman-adv: dat: handle forward allocation error (Sven Eckelmann)
- batman-adv: clear current gateway during teardown (Ruijie Li) [Orabug: 39619323] {CVE-2026-52926}
- batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) [Orabug: 39754765] {CVE-2026-64096}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) [Orabug: 39785113] {CVE-2026-64219}
- drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland)
- drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader)
- drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau)
- device property: set fwnode->secondary to NULL in fwnode_init() (Bartosz Golaszewski) [Orabug: 39785117] {CVE-2026-64220}
- RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito)
- spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold)
- spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold)
- scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) [Orabug: 39754786] {CVE-2026-64103}
- tracing: Do not call map->ops->elt_free() if elt_alloc() fails (Masami Hiramatsu) [Orabug: 39754948] {CVE-2026-64173}
- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) [Orabug: 39754952] {CVE-2026-64174}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) [Orabug: 39754812] {CVE-2026-64113}
- ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (Michael Bommarito) [Orabug: 39754817] {CVE-2026-64114}
- wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung)
- vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) [Orabug: 39754821] {CVE-2026-64115}
- ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt)
- netfilter: ipset: stop hash:* range iteration at end (Nan Li) [Orabug: 39619299] {CVE-2026-52921}
- netfilter: nf_queue: hold bridge skb->dev while queued (Haoze Xie) [Orabug: 39619255] {CVE-2026-52912}
- netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) [Orabug: 39619270] {CVE-2026-52915}
- net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) [Orabug: 39754845] {CVE-2026-64125}
- phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) [Orabug: 39754963] {CVE-2026-64177}
- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) [Orabug: 39523054] {CVE-2026-46275}
- Bluetooth: bnep: Fix UAF read of dev->name (Jann Horn) [Orabug: 39754967] {CVE-2026-64178}
- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal)
- ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) [Orabug: 39754862] {CVE-2026-64133}
- ALSA: ua101: Reject too-short USB descriptors (Cássio Gabriel)
- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain)
- sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) [Orabug: 39754983] {CVE-2026-64185}
- Revert "s390/cio: Fix device lifecycle handling in css_alloc_subchannel()" (Sasha Levin)
- KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (Sean Christopherson) [Orabug: 37901590] {CVE-2025-23141}
- wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300982] {CVE-2026-43052}
- net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (Vladimir Oltean)
- Revert "x86/vdso: Fix output operand size of RDPID" (Sasha Levin)
- s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou)
- io_uring: prevent opcode speculation (Pavel Begunkov) [Orabug: 37702113] {CVE-2025-21863}
- io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) [Orabug: 39523050] {CVE-2026-46274}
- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold)
- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek)
- drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka)
- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcalá)
- libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) [Orabug: 39621580] {CVE-2026-52954}
- libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) [Orabug: 39621584] {CVE-2026-52955}
- libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) [Orabug: 39621592] {CVE-2026-52957}
- libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) [Orabug: 39621596] {CVE-2026-52958}
- powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke)
- ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) [Orabug: 39621609] {CVE-2026-52962}
- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cássio Gabriel) [Orabug: 39621613] {CVE-2026-52963}
- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah)
- KVM: x86: Fix Xen hypercall tracepoint argument assignment (Maqiang)
- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) [Orabug: 39621628] {CVE-2026-52969}
- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia)
- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski)
- netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) [Orabug: 39621633] {CVE-2026-52970}
- audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia) [Orabug: 39653209] {CVE-2026-53287}
- i40e: Cleanup PTP pins on probe failure (Matt Vollrath)
- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) [Orabug: 39655982] {CVE-2026-52972}
- net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet)
- flow_dissector: Do not count vlan tags inside tunnel payload (Qingqing Yang)
- flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) [Orabug: 39524619] {CVE-2026-46306}
- btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) [Orabug: 39784984] {CVE-2026-64164}
- drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristóf)
- drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristóf)
- ALSA: hda/conexant: Fix missing error check for jack detection (Wangdicheng) [Orabug: 39653220] {CVE-2026-53291}
- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (Wangdicheng)
- ALSA: hda/conexant: fix some typos (Oldherl Oh)
- ALSA: hda/conexant: add a new hda codec SN6140 (Bo Liu)
- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet)
- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) [Orabug: 39451517] {CVE-2026-45846}
- ipv6: rename and move ip6_dst_lookup_tunnel() (Beniamino Galvani)
- ipv4: add new arguments to udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: remove "proto" argument from udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: rename and move ip_route_output_tunnel() (Beniamino Galvani)
- sctp: discard stale INIT after handshake completion (Xin Long)
- netfilter: skip recording stale or retransmitted INIT (Xin Long)
- ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt)
- net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher)
- NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts)
- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Dandan Zhang)
- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Jun Zhan) [Orabug: 39621670] {CVE-2026-52982}
- vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) [Orabug: 39619318] {CVE-2026-52925}
- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet)
- net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet)
- net: sched: choke: remove unused variables in struct choke_sched_data (Zhengchao Shao)
- net/sched: netem: validate slot configuration (Stephen Hemminger)
- net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) [Orabug: 39621677] {CVE-2026-52984}
- net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger)
- net: sched: sch_netem: Refactor code in 4-state loss generator (Harshit Mogalapalli)
- netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) [Orabug: 39621681] {CVE-2026-52985}
- cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer)
- scsi: sr: Add memory allocation failure handling for get_capabilities() (Enze Li)
- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [Orabug: 39621685] {CVE-2026-52986}
- netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) [Orabug: 39619293] {CVE-2026-52920}
- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristóf)
- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristóf)
- drm/amdgpu: fix spelling typos (Alexandre Demers)
- netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) [Orabug: 39451507] {CVE-2026-45844}
- tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao)
- btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone)
- mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang)
- mailbox: mailbox-test: initialize struct earlier (Wolfram Sang)
- mailbox: mailbox-test: don't free the reused channel (Wolfram Sang)
- mailbox: add sanity check for channel array (Wolfram Sang) [Orabug: 39653234] {CVE-2026-53295}
- cgroup/rdma: fix integer overflow in rdmacg_try_charge() (Tao Cui)
- mailbox: mailbox-test: free channels on probe error (Wolfram Sang)
- fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi)
- rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin)
- fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju)
- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju)
- tipc: fix double-free in tipc_buf_append() (Lee Jones) [Orabug: 39621708] {CVE-2026-52993}
- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev)
- net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet)
- net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet)
- net: sched: gred/red: remove unused variables in struct red_stats (Zhengchao Shao)
- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet)
- net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet)
- net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet)
- ksmbd: scope conn->binding slowpath to bound sessions only (Hyunwoo Kim)
- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (Daemyung Kang)
- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Yan Jun)
- slip: bound decode() reads against the compressed packet length (Weiming Shi) [Orabug: 39451500] {CVE-2026-45843}
- slip: reject VJ receive packets on instances with no rstate array (Weiming Shi) [Orabug: 39451493] {CVE-2026-45842}
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) [Orabug: 39621724] {CVE-2026-52998}
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) [Orabug: 39621730] {CVE-2026-52999}
- ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang)
- netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) [Orabug: 39621740] {CVE-2026-53001}
- netfilter: conntrack: remove sprintf usage (Florian Westphal) [Orabug: 39621746] {CVE-2026-53002}
- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) [Orabug: 39451485] {CVE-2026-45841}
- netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso)
- openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) [Orabug: 39451479] {CVE-2026-45840}
- pppoe: drop PFC frames (Qingfang Deng) [Orabug: 39621751] {CVE-2026-53003}
- flow_dissector: Add number of vlan tags dissector (Boris Sukholitko)
- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) [Orabug: 39621757] {CVE-2026-53004}
- ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) [Orabug: 39621765] {CVE-2026-53006}
- e1000e: Unroll PTP in probe error handling (Matt Vollrath)
- i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju)
- tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) (Eric Dumazet)
- net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) [Orabug: 39621780] {CVE-2026-53011}
- net/sched: taprio: rename close_time to end_time (Vladimir Oltean)
- net/sched: taprio: refactor one skb dequeue from TXQ to separate function (Vladimir Oltean)
- net/sched: taprio: continue with other TXQs if one dequeue() failed (Vladimir Oltean)
- net/sched: taprio: replace safety precautions with comments (Vladimir Oltean)
- net/sched: taprio: stop going through private ops for dequeue and peek (Vladimir Oltean)
- nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) [Orabug: 39621784] {CVE-2026-53012}
- net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu)
- PCMCIA: Fix garbled log messages for KERN_CONT (René Rebe)
- crypto: ccp - copy IV using skcipher ivsize (Paul Moses) [Orabug: 39621796] {CVE-2026-53016}
- crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham)
- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven)
- clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio)
- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio)
- clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven)
- clk: qoriq: avoid format string warning (Arnd Bergmann)
- clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak)
- clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu)
- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu)
- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett)
- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett)
- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett)
- scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) [Orabug: 39621811] {CVE-2026-53021}
- scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yangerkun) [Orabug: 39653261] {CVE-2026-53304}
- RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) [Orabug: 39754131] {CVE-2026-63860}
- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) [Orabug: 39621815] {CVE-2026-53022}
- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin)
- fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou)
- nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist() (Andy Shevchenko)
- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal)
- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki)
- tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap)
- tty: hvc: remove HVC_IUCV_MAGIC (Ahelenia Ziemiańska)
- leds: lgm-sso: Remove duplicate assignments for priv->mmap (Chen Ni)
- platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki)
- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni)
- dev_printk: add new dev_err_probe() helpers (Nuno Sa)
- driver core: Move dev_err_probe() to where it belogs (Andy Shevchenko)
- driver core: device.h: remove extern from function prototypes (Greg Kroah-Hartman)
- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai)
- perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo)
- perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan)
- pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin)
- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach)
- perf branch: Avoid incrementing NULL (Ian Rogers)
- pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore)
- HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) [Orabug: 39621857] {CVE-2026-53037}
- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud)
- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav)
- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav)
- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang)
- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen)
- mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni)
- HID: asus: do not abort probe when not necessary (Denis Benato)
- HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato)
- ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges)
- tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou)
- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li)
- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli)
- ocfs2: validate group add input before caching (Zhengyuan Huang) [Orabug: 39621864] {CVE-2026-53039}
- ocfs2: validate bg_bits during freefrag scan (Zhengyuan Huang) [Orabug: 39621868] {CVE-2026-53040}
- ocfs2: fix listxattr handling when the buffer is full (Zhengyuan Huang) [Orabug: 39621872] {CVE-2026-53041}
- soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari)
- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) [Orabug: 39653274] {CVE-2026-53309}
- ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo) [Orabug: 39621878] {CVE-2026-53043}
- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki)
- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberger)
- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov)
- soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov)
- soc: qcom: ocmem: use scoped device node handling to simplify error paths (Krzysztof Kozlowski)
- memory: tegra30-emc: Fix dll_change check (Mikko Perttunen)
- memory: tegra124-emc: Fix dll_change check (Mikko Perttunen)
- ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafał Miłecki)
- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith)
- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) [Orabug: 39621893] {CVE-2026-53047}
- gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) [Orabug: 39621897] {CVE-2026-53048}
- gfs2: add some missing log locking (Andreas Gruenbacher) [Orabug: 39621900] {CVE-2026-53049}
- quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) [Orabug: 39621904] {CVE-2026-53050}
- ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marlière)
- ktest: Honor empty per-test option overrides (Ricardo B. Marlière)
- ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marlière)
- ALSA: sc6000: Keep the programmed board state in card-private data (Cássio Gabriel)
- ALSA: sc6000: Use standard print API (Takashi Iwai)
- PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar)
- PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" (Vidya Sagar)
- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar)
- PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value (Frank Li)
- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long)
- Documentation: fix a hugetlbfs reservation statement (Jane Chu)
- PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer)
- ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang)
- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang)
- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang)
- pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() (Felix Gu)
- pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu)
- drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen)
- drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark)
- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Huanglei)
- ALSA: hda/realtek: Whitespace fix (Luke D. Jones)
- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristóf)
- drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristóf)
- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristóf)
- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristóf)
- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristóf)
- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristóf)
- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristóf)
- ALSA: core: Validate compress device numbers without dynamic minors (Cássio Gabriel)
- drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel)
- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich)
- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao)
- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko)
- dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet)
- drm/sun4i: Fix resource leaks (Ethan Tidmore)
- spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu)
- dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) [Orabug: 39621924] {CVE-2026-53059}
- dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) [Orabug: 39621929] {CVE-2026-53060}
- dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) [Orabug: 39621933] {CVE-2026-53061}
- dm cache: support shrinking the origin device (Ming-Hung Tsai)
- dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai)
- dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) [Orabug: 39621937] {CVE-2026-53062}
- dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai)
- dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) [Orabug: 39621946] {CVE-2026-53064}
- ASoC: sti: use managed regmap_field allocations (Sander Vanheule)
- ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule)
- drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov)
- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) [Orabug: 39621966] {CVE-2026-53069}
- sctp: fix missing encap_port propagation for GSO fragments (Xin Long)
- net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier)
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) [Orabug: 39621973] {CVE-2026-53071}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) [Orabug: 39621976] {CVE-2026-53072}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) [Orabug: 39621980] {CVE-2026-53073}
- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz)
- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) [Orabug: 39621984] {CVE-2026-53074}
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) [Orabug: 39621987] {CVE-2026-53075}
- net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) [Orabug: 39531630] {CVE-2026-46319}
- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen)
- 6pack: propagage new tty types (Jiri Slaby)
- netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal)
- netfilter: xt_socket: enable defrag after all other checks (Florian Westphal)
- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) [Orabug: 39622043] {CVE-2026-53088}
- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi)
- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) [Orabug: 39754142] {CVE-2026-63865}
- bpf-lsm: Make bpf_lsm_userns_create() sleepable (Frederick Lawler)
- wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) [Orabug: 39622061] {CVE-2026-53093}
- bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) [Orabug: 39451462] {CVE-2026-45838}
- macvlan: annotate data-races around port->bc_queue_len_used (Eric Dumazet)
- powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain)
- r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu)
- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) [Orabug: 39622069] {CVE-2026-53096}
- bpf, devmap: Remove unnecessary if check in for loop (Thorsten Blum)
- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu)
- params: Replace __modinit with __init_or_module (Petr Pavlu)
- kernel: globalize lookup_or_create_module_kobject() (Shyam Saini)
- kernel: param: rename locate_module_kobject (Shyam Saini)
- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen)
- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen)
- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) [Orabug: 39622109] {CVE-2026-53112}
- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan)
- firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello)
- locking: Fix rwlock support in <linux/spinlock_up.h> (Bart Van Assche)
- irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney)
- debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han)
- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon)
- devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich)
- pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt)
- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey)
- drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) [Orabug: 39622158] {CVE-2026-53128}
- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (Hyungjung Joo)
- bcache: fix uninitialized closure object (Mingzhe Zou)
- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng)
- vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) [Orabug: 39460646] {CVE-2026-46214}
- vsock: fix buffer size clamping order (Norbert Szetei) [Orabug: 39460717] {CVE-2026-46234}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) [Orabug: 39445785] {CVE-2026-45836}
- batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) [Orabug: 39460707] {CVE-2026-46231}
- batman-adv: bla: only purge non-released claims (Sven Eckelmann) [Orabug: 39460713] {CVE-2026-46233}
- batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) [Orabug: 39460640] {CVE-2026-46212}
- batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) [Orabug: 39460733] {CVE-2026-46238}
- batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) [Orabug: 39460614] {CVE-2026-46206}
- batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) [Orabug: 39460580] {CVE-2026-46198}
- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) [Orabug: 39460689] {CVE-2026-46227}
- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher)
- drm/amdgpu/pm: add missing revision check for CI (Alex Deucher)
- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) [Orabug: 39460668] {CVE-2026-46220}
- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore)
- drm/radeon: add missing revision check for CI (Alex Deucher)
- drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) [Orabug: 39460573] {CVE-2026-46197}
- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) [Orabug: 39460627] {CVE-2026-46209}
- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) [Orabug: 39460702] {CVE-2026-46230}
- spi: mpc52xx: fix use-after-free on unbind (Johan Hovold)
- spi: orion: fix clock imbalance on registration failure (Johan Hovold)
- spi: imx: fix runtime pm leak on probe deferral (Johan Hovold)
- spi: mtk-nor: fix controller deregistration (Johan Hovold)
- media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu)
- media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov)
- regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold)
- regulator: act8945a: fix OF node reference imbalance (Johan Hovold)
- media: rc: streamzap: Error handling in probe (Oliver Neukum)
- media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum)
- regulator: max77650: fix OF node reference imbalance (Johan Hovold)
- staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus)
- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich)
- media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda)
- platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal)
- mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) [Orabug: 39460450] {CVE-2026-46168}
- mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan)
- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar)
- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar)
- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) [Orabug: 39460540] {CVE-2026-46189}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) [Orabug: 39460303] {CVE-2026-46133}
- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) [Orabug: 39460277] {CVE-2026-46127}
- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) [Orabug: 39460496] {CVE-2026-46178}
- power: supply: max17042: avoid overflow when determining health (André Draszik)
- PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner)
- PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue)
- s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik)
- RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe)
- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) [Orabug: 39524613] {CVE-2026-46304}
- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) [Orabug: 39460415] {CVE-2026-46161}
- libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) [Orabug: 39460244] {CVE-2026-46119}
- isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) [Orabug: 39460265] {CVE-2026-46124}
- isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) [Orabug: 39524609] {CVE-2026-46303}
- dm-verity-fec: correctly reject too-small hash devices (Eric Biggers)
- dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers)
- dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) [Orabug: 39524585] {CVE-2026-46294}
- dm: don't report warning when doing deferred remove (Mikulas Patocka)
- dm-thin: fix metadata refcount underflow (Mikulas Patocka) [Orabug: 39460195] {CVE-2026-46107}
- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cássio Gabriel)
- ASoC: fsl_easrc: fix comment typo (Joseph Salisbury)
- cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde)
- spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold)
- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum)
- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum)
- udf: reject descriptors with oversized CRC length (Michael Bommarito) [Orabug: 39753576] {CVE-2026-53369}
- ibmveth: Disable GSO for packets with small MSS (Mingming Cao)
- hv_sock: fix ARM64 support (Hamza Mahfooz)
- extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang)
- hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak)
- hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan)
- hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan)
- parisc: Fix IRQ leak in LASI driver (Hongling Zeng)
- ip6_gre: Use cached t->net in ip6erspan_changelink(). (Maoyi Xie) [Orabug: 39460248] {CVE-2026-46120}
- sound: ua101: fix division by zero at probe (Seungju Cheon) [Orabug: 39460519] {CVE-2026-46184}
- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Aizen) [Orabug: 39460297] {CVE-2026-46132}
- fanotify: fix false positive on permission events (Miklos Szeredi) [Orabug: 39460374] {CVE-2026-46150}
- spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold)
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) [Orabug: 39445772] {CVE-2026-45834}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39445781] {CVE-2026-45835}
- Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito)
- Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito)
- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) [Orabug: 39460469] {CVE-2026-46172}
- xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li)
- ALSA: firewire-tascam: Do not drop unread control events (Cássio Gabriel)
- usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) [Orabug: 39654820] {CVE-2026-46109}
- USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda)
- USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen)
- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cássio Gabriel)
- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai) [Orabug: 39460352] {CVE-2026-46146}
- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) [Orabug: 39460438] {CVE-2026-46167}
- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) [Orabug: 39460379] {CVE-2026-46151}
- wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) [Orabug: 39460257] {CVE-2026-46122}
- wifi: ath5k: do not access array OOB (Jiri Slaby) [Orabug: 39524622] {CVE-2026-46307}
- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) [Orabug: 39460532] {CVE-2026-46187}
- wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) [Orabug: 39460424] {CVE-2026-46163}
- ipmi:ssif: NULL thread on error (Corey Minyard)
- ipmi:ssif: Remove unnecessary indention (Corey Minyard)
- ipmi:ssif: Clean up kthread on errors (Corey Minyard) [Orabug: 39452264] {CVE-2026-46044}
- ipmi:ssif: Fix a shutdown race (Corey Minyard)
- net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) [Orabug: 39425987] {CVE-2026-43496}
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c (Dipendra Khadka)
- um: virt-pci: Fix build failure (Florian Fainelli)
- spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250891] {CVE-2026-31489}
- ksmbd: do not expire session on binding failure (Hyunwoo Kim)
- spi: rockchip: fix controller deregistration (Johan Hovold)
- ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra)
- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan)
- ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li)
- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta)
- ipmi:si: Return state to normal if message allocation fails (Corey Minyard) [Orabug: 39460202] {CVE-2026-46108}
- ipmi: Check event message buffer response for bad data (Corey Minyard) [Orabug: 39460284] {CVE-2026-46128}
- ipmi: Add limits to event and receive message requests (Corey Minyard) [Orabug: 39460490] {CVE-2026-46177}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [Orabug: 39460368] {CVE-2026-46149}
- netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452465] {CVE-2026-46101}
- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452458] {CVE-2026-46099}
- ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39784983] {CVE-2026-46048}
- drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) [Orabug: 39524543] {CVE-2026-46276}
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426004] {CVE-2026-43501}
- ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai)
- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai)
- driver core: Add kernel-doc for DEV_FLAG_COUNT enum value (Douglas Anderson)
- crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452232] {CVE-2026-46033}
- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer)
- ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner)
- ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner)
- ktest: Fix the month in the name of the failure directory (Steven Rostedt)
- IB/core: Fix zero dmac race in neighbor resolution (Chen Zhao)
- dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452197] {CVE-2026-46023}
- crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum)
- crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li)
- crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier)
- crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum)
- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum)
- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers)
- taskstats: set version in TGID exit notifications (Yiyang Chen)
- tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452160] {CVE-2026-46015}
- inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452251] {CVE-2026-46040}
- md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452350] {CVE-2026-46070}
- md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452288] {CVE-2026-46051}
- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452270] {CVE-2026-46046}
- mtd: docg3: fix use-after-free in docg3_release() (James Kim)
- mtd: docg3: Convert to platform remove callback returning void (Uwe Kleine-König)
- io_uring/poll: fix backport of io_poll_add() changes (Jens Axboe)
- io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored (Jens Axboe)
- KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed)
- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed)
- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed)
- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed)
- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson)
- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452395] {CVE-2026-46082}
- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452062] {CVE-2026-45987}
- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed)
- userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov)
- rtc: ntxec: fix OF node reference imbalance (Johan Hovold)
- tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong)
- mmc: block: use single block write in retry (Bin Liu)
- power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski)
- tpm: avoid -Wunused-but-set-variable (Arnd Bergmann)
- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452202] {CVE-2026-46024}
- ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452244] {CVE-2026-46037}
- drm/arcpgu: fix device node leak (Luca Ceresoli)
- net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li)
- iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos)
- ALSA: 6fire: Fix input volume change detection (Cássio Gabriel)
- ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452127] {CVE-2026-46004}
- ALSA: caiaq: Fix control_put() result and cache rollback (Cássio Gabriel)
- selftests/mqueue: Fix incorrectly named file (Simon Liebold)
- parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller)
- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett)
- md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452285] {CVE-2026-46050}
- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cássio Gabriel)
- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452281] {CVE-2026-46049}
- ALSA: aoa: i2sbus: fix OF node lifetime handling (Cássio Gabriel)
- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452120] {CVE-2026-46002}
- net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452275] {CVE-2026-46047}
- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni)
- lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law)
- Revert "ALSA: usb: Increase volume range that triggers a warning" (Rongrong)
- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den)
- net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452469] {CVE-2026-46102}
- net: caif: clear client service pointer on teardown (Zhengchuan Liang)
- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452417] {CVE-2026-46088}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410864] {CVE-2026-43493}
- um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito)
- driver core: Don't let a device probe until it's ready (Douglas Anderson)
- padata: Remove comment for reorder_work (Herbert Xu)
- padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335056] {CVE-2025-38584}
- ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452389] {CVE-2026-46080}
- device property: Make modifications of fwnode "flags" thread safe (Douglas Anderson)
- scsi: ufs: core: Fix use-after free in init error and remove paths (André Draszik)
- firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann)
- ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu)
- ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu)
- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu)
- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452134] {CVE-2026-46006}
- ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai)
- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michał Pecio)
- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cássio Gabriel)
- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cássio Gabriel)
- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cássio Gabriel) [Orabug: 39452171] {CVE-2026-46018}
- ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park)
- tty: n_gsm: fix flow control handling in tx path (Daniel Starke)
- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento)
- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300568] {CVE-2026-31697}
- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300572] {CVE-2026-31698}
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300576] {CVE-2026-31699}
- ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300587] {CVE-2026-31701}
- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae)
- fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong)
- fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300557] {CVE-2026-31694}
- fs/ntfs3: validate rec->used in journal-replay file record check (Greg Kroah-Hartman)
- iommu: fix a reference count leak in iommu_sva_bind_device() (Vasant Karasulli)
- rxrpc: Fix anonymous key handling (David Howells)
- rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39342679,39368252]
- ksmbd: unset conn->binding on failed binding request (Namjae Jeon)
- scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor)
- Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave" (Guocai He)
- drivers: base: Free devm resources when unregistering a device (David Gow)
- cpufreq: Avoid a bad reference count on CPU node (Miquel Sabaté Solà) [Orabug: 37206351] {CVE-2024-50012}
- net: clear the dst when changing skb protocol (Jakub Kicinski) [Orabug: 38158471] {CVE-2025-38192}
- fbdev: efifb: Register sysfs groups through driver core (Thomas Weißschuh) [Orabug: 37205941] {CVE-2024-49925}
- md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Yu Kuai) [Orabug: 37649831] {CVE-2025-21712}
- cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343645] {CVE-2026-43328}
- cpufreq: governor: Free dbs_data directly when gov->init() fails (Liao Chang)
- rxrpc: Fix recvmsg() unconditional requeue (David Howells)
- fs/ntfs3: Add more attributes checks in mi_enum_attr() (Konstantin Komarov) {CVE-2023-45896}
- btrfs: lock the inode in shared mode before starting fiemap (Filipe Manana)
- f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode (Chao Yu)
- can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (Marc Kleine-Budde) [Orabug: 38773752] {CVE-2025-68307}
- Bluetooth: af_bluetooth: Fix deadlock (Luiz Augusto von Dentz) [Orabug: 36544919] {CVE-2024-26886}
- iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol)
- pstore: inode: Only d_invalidate() is needed (Kees Cook) [Orabug: 36598300] {CVE-2024-27389}
- f2fs: fix to wait on block writeback for post_read case (Chao Yu)
- net: stmmac: fix TSO DMA API usage causing oops (Russell King) [Orabug: 37434619] {CVE-2024-56719}
- drm/amdgpu: unmap and remove csa_va properly (Lang Yu)
- binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773485] {CVE-2025-68239}
- gfs2: No more self recovery (Andreas Gruenbacher) [Orabug: 38351909] {CVE-2025-38659}
- bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO (Kumar Kartikeya Dwivedi)
- dlm: fix possible lkb_resource null dereference (Alexander Aring) [Orabug: 37472202] {CVE-2024-47809}
- Bluetooth: hci_core: Fix use-after-free in vhci_flush() (Kuniyuki Iwashima) [Orabug: 38175068] {CVE-2025-38250}
- mailbox: Prevent out-of-bounds access in of_mbox_index_xlate() (Joonwon Kang)
- btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970329] {CVE-2026-23157}
- btrfs: send: check for inline extents in range_is_hole_in_parent() (Qu Wenruo) [Orabug: 38970284] {CVE-2026-23141}
- x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov)
- spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli)
- fs: dlm: fix use after free in midcomms commit (Alexander Aring)
- dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu)
- net/sched: cls_u32: use skb_header_pointer_careful() (Eric Dumazet) [Orabug: 38970488] {CVE-2026-23204}
- net: add skb_header_pointer_careful() helper (Eric Dumazet)
- dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887637] {CVE-2025-71161}
- blk-mq: use quiesced elevator switch when reinitializing queues (Keith Busch)
- wifi: iwlwifi: read txq->read_ptr under lock (Johannes Berg) [Orabug: 36683388] {CVE-2024-36922}
- f2fs: fix null-ptr-deref in f2fs_submit_page_bio() (Ye Bin)
- s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens)
- ALSA: control: Avoid WARN() for symlink errors (Takashi Iwai) [Orabug: 37434224] {CVE-2024-56657}
- nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() (Jaskaran Singh) [Orabug: 38730673] {CVE-2025-40261}
- Revert "nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()" (Jaskaran Singh)
- tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke)
- MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong)
- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586}
- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598}
- fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li) [Orabug: 39273588] {CVE-2026-31598}
- rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu)
- rxrpc: Fix call removal to use RCU safe deletion (David Howells)
- rxrpc: Fix key quota calculation for multitoken keys (David Howells)
- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664}
- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075}
- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076}
- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak)
- Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower" (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak)
- powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini)
- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal)
- PCI/ACPI: Restrict program_hpx_type2() to AER bits (Håkon Bugge)
- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444}
- gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710}
- gfs2: Improve gfs2_consist_inode() usage (Andrew Price)
- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442}
- Revert "net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()" (Sasha Levin)
- Revert "net: ethernet: xscale: Check for PTP support properly" (Sasha Levin)
- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)
- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)
- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)
- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)
- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578}
- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580}
- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581}
- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583}
- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)
- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)
- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588}
- checkpatch: add support for Assisted-by tag (Sasha Levin)
- rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou)
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399}
- smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara)
- fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski)
- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590}
- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596}
- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597}
- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)
- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602}
- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)
- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)
- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brát)
- usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607}
- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman)
- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman)
- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617}
- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619}
- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman)
- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623}
- HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624}
- HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625}
- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626}
- i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman)
- can: raw: fix ro->uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532}
- nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian)
- ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako)
- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki)
- MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki)
- MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki)
- mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler)
- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407}
- i3c: fix uninitialized variable use in i2c setup (Jamie Iles)
- perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079}
- gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda)
- l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080}
- af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673}
- netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685}
- netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681}
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085}
- xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089}
- xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093}
- e1000: check return value of e1000_read_eeprom (Agalakov Daniil)
- tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou)
- nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou)
- ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099}
- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet)
- net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074}
- epoll: use refcount to reduce ep_mutex contention (Paolo Abeni)
- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maíra Canal)
- drm/vc4: Fix a memory leak in hang state error path (Maíra Canal) [Orabug: 39331212] {CVE-2026-43104}
- drm/vc4: Fix memory leak of BO array in hang state (Maíra Canal) [Orabug: 39331216] {CVE-2026-43105}
- PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li)
- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak)
- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai)
- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta)
- wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110}
- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband)
- HID: roccat: fix use-after-free in roccat_report_event (Benoît Sevens) [Orabug: 39331244] {CVE-2026-43111}
- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska)
- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko)
- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover)
- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby)
- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto)
- wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114}
- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (César Montoya)
- btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117}
- can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li)
- ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann)
- LTS version: v5.15.208 (Samasth Norway Ananda)
- LTS version: v5.15.207 (Samasth Norway Ananda)
- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174}
- x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov)
- LTS version: v5.15.206 (Samasth Norway Ananda)
- LTS version: v5.15.205 (Samasth Norway Ananda)
- LTS version: v5.15.204 (Samasth Norway Ananda)
- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787}
- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}
-
Wed Jul 15 2026 Samasth Norway Ananda <samasth.norway.ananda@oracle.com> [5.15.0-323.203.2.el9uek]
- net/mlx5: Add vhca_id_type support to IPsec alias creation (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5: Add vhca_id_type bit to alias context (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman) [Orabug: 38290328]
- net/mlx5e: Fix race condition during IPSec ESN update (Jianbo Liu) [Orabug: 38290328,39167462] {CVE-2026-23440}
- net/mlx5e: Prevent concurrent access to IPSec ASO context (Jianbo Liu) [Orabug: 38290328,39167465] {CVE-2026-23441}
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567286,39668793] {CVE-2026-46331}
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39673870,39753976] {CVE-2026-63807}
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673870,39686460] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39460221,39673870] {CVE-2026-46113}
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Derive shadow MMU page role from parent (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673870]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673870]
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39425999,39751167] {CVE-2026-43499,CVE-2026-53163}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425999,39706512] {CVE-2026-43499}
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659419]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619388,39639981,39648952] {CVE-2026-52943}
- fs/binfmt_elf: validate reserved VA ELF notes (Jianfeng Wang) [Orabug: 39681043]
- mm: preserve page-table boundaries for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- mm: enforce max_map_count for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- fs/kernfs: raise sb->maxbytes to MAX_LFS_FILESIZE (Jane Chu) [Orabug: 39209740]
- uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Dave Kleikamp) [Orabug: 39661609]
- uek-rpm: cnic: Trim the SNIC config for a faster boot (Dave Kleikamp) [Orabug: 39661609]
- net/rds: expand kref coverage to rds_notifier->n_conn (Sharath Srinivasan) [Orabug: 38945572]
- net/rds: fix crash by expanding kref coverage to rds_incoming.i_conn (Sharath Srinivasan) [Orabug: 38945572]
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 39480769]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452260] {CVE-2026-46043}
-
Thu Jun 25 2026 Vijayendra Suman <vijayendra.suman@oracle.com> [5.15.0-323.203.1.el9uek]
- net/rds: Wait for rdma_cm_event background work to finish (Gerd Rausch) [Orabug: 38112000]
- locking/mutex: Make contention tracepoints more consistent wrt adaptive spinning (Peter Zijlstra) [Orabug: 39598217]
- locking: Apply contention tracepoints in the slow path (Namhyung Kim) [Orabug: 39598217]
- locking: Add lock contention tracepoints (Namhyung Kim) [Orabug: 39598217]
- net/mlx5: Fix EQ IRQ affinity notifier debug messages (Praveen Kumar Kannoju) [Orabug: 39594875]
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39460234] {CVE-2026-46116}
- Revert "rds: ib: Add cm_id generation scheme in order to detect new ones" (Sharath Srinivasan) [Orabug: 39226005]