ELSA-2026-500249

ELSA-2026-500249 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-09-04

Description


[5.15.0-324.217.5.2]
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39974835] {CVE-2026-80590}

[5.15.0-324.217.5.1]
- crypto: qat: restore misc workqueue lifecycle (Manjunath Patil) [Orabug: 39937535]
- LTS version: v5.15.217 (Vijayendra Suman)
- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu)
- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt)
- jiffies: Cast to unsigned long in secs_to_jiffies() conversion (Easwar Hariharan)
- drm/virtio: Unlock reservations on dma_resv_reserve_fences() error (Dmitry Osipenko)
- drm/vmwgfx: Reserve fence slots on buffer objects in cotables (Zack Rusin)
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner)
- net/x25: fix use-after-free of the socket by its timers (Baul Lee)
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli)
- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet)
- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev)
- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang)
- netfilter: ipset: fix list type element drift bug (Florian Westphal)
- netfilter: flowtable: publish GC-visible tuple last (Jeremy Jean)
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy)
- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei (Microsoft))
- crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu)
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jon Hunter)
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li)
- net/smc: rdma write inline if qp has sufficient inline space (Guangguan Wang)
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen)
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko)
- openvswitch: move key and ovs_cb update out of handle_fragments (Xin Long)
- net: sched: use skb_ip_totlen and iph_totlen (Xin Long)
- openvswitch: use skb_ip_totlen in conntrack (Xin Long)
- net: add a couple of helpers for iph tot_len (Xin Long)
- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes (ARM))
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo)
- drm/amd/pm: fix torn gpu metrics reads (Yang Wang)
- ice: wait for reset completion in ice_resume() (Aaron Ma)
- jiffies: Define secs_to_jiffies() (Easwar Hariharan)
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)
- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)
- i2c: bcm-iproc: remove printout on handled timeouts (Wolfram Sang)
- i2c: imx: Fix slave registration race and error handling (Liem)
- binfmt_misc: restore write access when removing an entry (Christian Brauner)
- fs: don't block write during exec on pre-content watched files (Amir Goldstein)
- fsnotify: opt-in for permission events at file open time (Amir Goldstein)
- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov)
- scsi: scsi_debug: Rename zone type constants (Damien Le Moal)
- scsi: sd: sd_zbc: Return early in sd_zbc_check_zoned_characteristics() (Damien Le Moal)
- scsi: sd: sd_zbc: Introduce struct zoned_disk_info (Bart Van Assche)
- scsi: sd: sd_zbc: Use logical blocks as unit when querying zones (Damien Le Moal)
- scsi: sd: sd_zbc: Improve source code documentation (Bart Van Assche)
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye)
- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)
- igc: remove napi_synchronize() in igc_down() (David Carlier)
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie)
- ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon)
- ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)
- ksmbd: validate minimum PDU size for transform requests (Namjae Jeon)
- smb/server: fix minimum SMB2 PDU size (ChenXiaoSong)
- smb/server: fix minimum SMB1 PDU size (ChenXiaoSong)
- ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon)
- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner)
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu)
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo)
- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery)
- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha)
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann)
- ceph: print cluster fsid and client global_id in all debug logs (Xiubo Li)
- ceph: rename _to_client() to _to_fs_client() (Xiubo Li)
- libceph: add doutc and *_client debug macros support (Xiubo Li)
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei)
- libceph: Amend checking to fix make W=1 build breakage (Andy Shevchenko)
- ceph: avoid fs reclaim while using current->journal_info (Max Kellermann)
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou)
- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)
- mptcp: fix subflow accounting on close (Paolo Abeni)
- mptcp: cleanup MPJ subflow list handling (Paolo Abeni)
- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)
- serial: sc16is7xx: fix regression with GPIO configuration (Hugo Villeneuve)
- serial: sc16is7xx: remove obsolete out_thread label (Hugo Villeneuve)
- serial: sc16is7xx: Fill in rs485_supported (Ilpo Jarvinen)
- sc16is7xx: Properly resume TX after stop (Tomasz Mon)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi)
- serial: 8250_mid: Remove unneeded test for ->setup() presence (Andy Shevchenko)
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu)
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei)
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea)
- media: v4l: async: Set owner for async sub-devices (Sakari Ailus)
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges)
- media: imx219: Fix maximum frame length in lines (Sakari Ailus)
- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)
- media: i2c: imx219: Correct the minimum vblanking value (David Plowman)
- media: i2c: imx219: Drop IMX219_VTS_* macros (Laurent Pinchart)
- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)
- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula)
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas)
- drm/virtio: Return proper error codes instead of -1 (Dmitry Osipenko)
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof)
- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)
- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)
- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey)
- dma-buf/drivers: make reserving a shared slot mandatory v4 (Christian Konig)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai)
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai)
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang)
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai)
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre)
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng)
- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)
- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca)
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)
- bootconfig: do not put quotes on cmdline items unless necessary (Rasmus Villemoes)
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)
- net/sched: taprio: avoid calling child->ops->dequeue(child) twice (Vladimir Oltean)
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao)
- treewide: rename pinctrl_gpio_direction_output_new() (Bartosz Golaszewski)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo)
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui)
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi)
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li)
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: Add helper function to parse netlink msg of ip_tunnel_encap (Liu Jian)
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner)
- mmc: vub300: fix use-after-free on probe failure (Guangshuo Li)
- mmc: vub300: rename probe error labels (Johan Hovold)
- mmc: vub300: fix use-after-free on disconnect (Johan Hovold)
- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov)
- firmware_loader: introduce __free() cleanup hanler (Dmitry Torokhov)
- dm-verity: make error counter atomic (Mikulas Patocka)
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka)
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal)
- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn)
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito)
- thunderbolt: Remove XDomain from the bus without holding tb->lock (Mika Westerberg)
- thunderbolt: Remove service debugfs entries during unregister (Mika Westerberg)
- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg)
- thunderbolt: Update property.c function documentation (Alan Borzeszkowski)
- thunderbolt: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET)
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu)
- can/esd_usb2: Rename esd_usb2.c to esd_usb.c (Frank Jungclaus)
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)
- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)
- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen)
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)
- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)
- taskstats: fill_stats_for_tgid: use for_each_thread() (Oleg Nesterov)
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li)
- dmaengine: dw-edma: Detach the private data and chip info structures (Frank Li)
- dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip (Frank Li)
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal)
- mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle)
- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie)
- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao)
- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito)
- fs/ntfs3: Undo critial modificatins to keep directory consistency (Konstantin Komarov)
- fs/ntfs3: Make ntfs_update_mftmirr return void (Pavel Skripkin)
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani)
- lsm: infrastructure management of the sock security (Casey Schaufler)
- lsm: use default hook return value in call_int_hook() (Ondrej Mosnacek)
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir)
- remoteproc: qcom: pas: Adjust the phys addr wrt the mem region (Yogesh Lal)
- remoteproc: qcom: fix sparse warnings (Mukesh Ojha)
- remoteproc: qcom: replace kstrdup with kstrndup (Mukesh Ojha)
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal)
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal)
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal)
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal)
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso)
- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)
- netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal)
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal)
- ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel)
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)
- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (AngeloGioacchino Del Regno)
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie)
- ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet)
- net: dst: add four helpers to annotate data-races around dst->dev (Eric Dumazet)
- net: dst: annotate data-races around dst->output (Eric Dumazet)
- net: dst: annotate data-races around dst->input (Eric Dumazet)
- tcp: convert to dev_net_rcu() (Eric Dumazet)
- ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel)
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep)
- octeontx2-af: Fix APR entry mapping based on APR_LMT_CFG (Geetha sowjanya)
- VDUSE: avoid leaking information to userspace (Jason Wang)
- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez)
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez)
- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Wentao Liang)
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong)
- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)
- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)
- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming)
- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)
- serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) (Hugo Villeneuve)
- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina)
- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)
- audit: widen ino fields to u64 (Jeff Layton)
- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)
- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)
- Input: mms114 - reject an oversized device packet size (Bryam Vargas)
- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov)
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives)
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov)
- udmabuf: Do not create malformed scatterlists (Jason Gunthorpe)
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski)
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato)
- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei)
- xfs: check v5 superblock features early (Christoph Hellwig)
- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li)
- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca)
- drm/amdgpu: Implement insert_end for VCE 3 (David Rosca)
- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca)
- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li)
- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca)
- s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman)
- drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li)
- mmc: sdhci: make tuning_err a signed int (Haibo Chen)
- mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak)
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng)
- libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai)
- ceph: fix MDS random selection readiness predicate (Yiming Zhu)
- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer)
- Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov)
- Input: sur40 - fix input device registration ordering (Dmitry Torokhov)
- openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis)
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf)
- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha)
- crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum)
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov)
- Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov)
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas)
- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov)
- powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson)
- Input: iforce - validate input packet lengths (Pengpeng Hou)
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang)
- Input: psxpad-spi - set driver data before use (Linmao Li)
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies)
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov)
- powerpc/pseries: pci - logic bug (George Wilson)
- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid Wrobel)
- ASoC: cs4265: sort the register default table (Peter Ujfalusi)
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan)
- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts (NGI0))
- selinux: do not cancel a policy conversion that never started (Bryam Vargas)
- selinux: reject a class permission count below its inherited common (Bryam Vargas)
- selinux: require every boolean value to be defined (Bryam Vargas)
- ipvs: separate destination availability state (Yizhou Zhao)
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng)
- media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization (Jiasheng Jiang)
- media: mtk-vcodec: potential null pointer deference in SCP (Fullway Wang)
- f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu)
- LTS version: v5.15.216 (Vijayendra Suman)
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas)
- sctp: clear new_transport when removing a peer (Qing Ming)
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang)
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee)
- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye)
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou)
- ipv6: fix Route Information option length validation (Yuejie Shi)
- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki)
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang)
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi)
- vsock/virtio: read virtqueues under worker locks (Weiming Shi)
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee)
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou)
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko)
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen)
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou)
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng)
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel)
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu)
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee)
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)
- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola)
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos)
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal)
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal)
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu)
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye)
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi)
- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- futex: Prevent robust futex exit race some more (Keno Fischer)
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver)
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov)
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers)
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers)
- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee)
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye)
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang)
- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou)
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk)
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng)
- ipvs: properly update the overload flag on dest edit (Julian Anastasov)
- ipvs: add totalconns for dest (Julian Anastasov)
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace)
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan)
- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)
- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh)
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee)
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov)
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)
- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)
- sctp: clear control chunk transport if it is being removed (Xin Long)
- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu)
- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan)
- net: qrtr: ns: Raise lookup limit to 128 (Lukasz Patron)
- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond)
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet)
- net: prestera: validate firmware header length (Pengpeng Hou)
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin)
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen)
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)
- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan)
- bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Michael Chan)
- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)
- selftests/ftrace: Add test case for GRP/ only input (Linyu Yuan)
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen)
- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo)
- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)
- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik)
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim)
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi)
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen)
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))
- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker)
- nfs4: take a reference on the nfs_client when running FREE_STATEID (Scott Mayhew)
- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger)
- mount: honour SB_NOUSER in the new mount API (Al Viro)
- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao)
- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng)
- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))
- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An)
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin)
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin)
- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)
- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)
- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal)
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou)
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie)
- can: peak_usb: add bounds check for USB channel index (James Gao)
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou)
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou)
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel)
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li)
- can: ems_usb: validate CPC message lengths (Pengpeng Hou)
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem)
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller)
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets)
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets)
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)
- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler)
- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler)
- s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner)
- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally)
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)
- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada)
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)
- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)
- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet)
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet)
- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet)
- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito)
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou)
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou)
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin)
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner)
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li)
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi)
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee)
- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo)
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou)
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath)
- e1000: fix memory leak in e1000_probe() (Dawei Feng)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan)
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan)
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee)
- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)
- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)
- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei)
- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)
- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai)
- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)
- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee)
- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee)
- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu)
- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)
- sctp: validate Adaptation Indication parameter length (Charles Vosburgh)
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai)
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan)
- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)
- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter)
- rhashtable: clear stale iter->p on table restart (Cen Zhang (Microsoft))
- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev)
- octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh)
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))
- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)
- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)
- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao)
- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)
- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao)
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)
- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li)
- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)
- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao)
- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck)
- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An)
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An)
- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))
- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso)
- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito)
- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito)
- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei)
- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)
- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)
- phy: zynqmp: Allow variation in refclk rate (Sean Anderson)
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)
- tls: separate no-async decryption request handling from async (Sabrina Dubroca)
- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)
- net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam)
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)
- gve: fix Rx queue stall on alloc failure (Eddie Phillips)
- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)
- media: uvcvideo: Implement dual stream quirk to fix loss of usb packets (Isaac Scott)
- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee)
- raw: fix a typo in raw_icmp_error() (Eric Dumazet)
- raw: remove unused variables from raw6_icmp_error() (Eric Dumazet)
- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng)
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi)
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun)
- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang)
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher)
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher)
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko)
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada)
- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk)
- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito)
- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)
- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer)
- proc: Fix broken error paths for namespace links (Jann Horn)
- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu)
- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee)
- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas)
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan)
- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)
- net: slip: serialize receive against buffer reallocation (Sungmin Kang)
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)
- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao)
- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)
- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner)
- libceph: remove debugfs files before client teardown (Douya Le)
- libceph: reject zero bucket types in crush_decode (Douya Le)
- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer)
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (Shuangpeng Bai)
- libceph: guard missing CRUSH type name lookup (Zhao Zhang)
- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer)
- libceph: bound get_version reply decode to front len (Douya Le)
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas)
- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)
- Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon)
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))
- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))
- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog)
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev (Steven Rostedt)
- intel_th: fix MSC output device reference leak (Guangshuo Li)
- comedi: comedi_parport: deal with premature interrupt (Ian Abbott)
- x86/boot/compressed: Disable jump tables (Nathan Chancellor)
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao)
- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner)
- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner)
- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye)
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker)
- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu)
- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang)
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk)
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani)
- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil)
- media: vimc: fix reference leak on failed device registration (Guangshuo Li)
- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)
- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)
- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)
- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke)
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey)
- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak)
- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky)
- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski)
- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon)
- media: cx23885: add ioremap return check and cleanup (Wang Jun)
- media: cx231xx: fix devres lifetime (Johan Hovold)
- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou)
- media: cedrus: Fix missing cleanup in error path (Samuel Holland)
- media: cedrus: clean up media device on probe failure (Myeonghun Pak)
- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)
- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky)
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes)
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan)
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof)
- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen)
- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen)
- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen)
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher)
- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka)
- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp)
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp)
- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp)
- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp)
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp)
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp)
- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp)
- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp)
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones)
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye)
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)
- raw: use more conventional iterators (Eric Dumazet)
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)
- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo)
- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)
- octeontx2-vf: set TC flower flag on MCAM entry allocation (Suman Ghosh)
- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)
- net: stmmac: add tc flower filter for EtherType matching (Ong Boon Leong)
- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana)
- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo)
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet)
- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang)
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi)
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike)
- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))
- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan)
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)
- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing)
- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou)
- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???))
- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang)
- nfp: Check resource mutex allocation (Ruoyu Wang)
- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li)
- net: dpaa2-eth: assign priv->mac after dpaa2_mac_connect() call (Vladimir Oltean)
- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li)
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou)
- hwmon: (occ) Delay hwmon registration until user request (Eddie James)
- hwmon: (occ) Add sysfs entries for additional extended status bits (Eddie James)
- hwmon: (occ) Add sysfs entry for OCC mode (Eddie James)
- hwmon: (occ) Add sysfs entry for IPS (Idle Power Saver) status (Eddie James)
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez)
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)
- ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the endpoint (Jiaxin Yu)
- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang)
- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani)
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani)
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani)
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani)
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani)
- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang)
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun)
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih)
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis)
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang)
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann)
- Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin)
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)
- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)
- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)
- USB: serial: io_edgeport: cap received transmit credits (Sunho Park)
- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal)
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu)
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan)
- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)
- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)
- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew)
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu)
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang)
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang)
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi)
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long)
- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim)
- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)
- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))
- can: j1939: fix lockless local-destination check (Shuhao Fu)
- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)
- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)
- sched/vtime: Get rid of generic vtime_task_switch() implementation (Alexander Gordeev)
- powerpc: remove the last remnants of cputime_t (Nicholas Piggin)
- powerpc/time: Fix sparse warnings (He Ying)
- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)
- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He)
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei)
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev)
- ata: sata_dwc_460ex: remove variable num_processed (Colin Ian King)
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev)
- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas)
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi)
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei)
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)
- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???))
- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao)
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang)
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)
- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li)
- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei)
- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng)
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas)
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal)
- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang)
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))
- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)
- RDMA/siw: publish QP after initialization (Ruoyu Wang)
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (Guoqing Jiang)
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala)
- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana)
- btrfs: reject free space cache with more entries than pages (Xiang Mei)
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)
- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)
- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito)
- KVM: VMX: Make vmread_error_trampoline() uncallable from C code (Sean Christopherson)
- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae)
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea)
- can: isotp: serialize TX state transitions under so->rx_lock (Oliver Hartkopp)
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp)
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal)
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim)
- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko)
- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior)
- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg)

[5.15.0-324.213.5]
- Revert 'rseq: Introduce feature size and alignment ELF auxiliary vector entries' (Prakash Sangappa) [Orabug: 39874250]

[5.15.0-324.213.4]
- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047421]
- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047421]
- rseq: Introduce extensible rseq ABI (Prakash Sangappa) [Orabug: 39047421]
- rseq: Introduce feature size and alignment ELF auxiliary vector entries (Mathieu Desnoyers) [Orabug: 39047421]
- Update AT_VA_RESERVATION number (Prakash Sangappa) [Orabug: 39047421]
- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047421]
- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047421]
- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047421]
- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047421]
- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047421]
- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047421]
- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047421]
- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047421]
- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047421]
- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047421]
- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047421]
- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047421]
- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047421]
- rseq: Add fields and constants for time slice extension (Thomas Gleixner) [Orabug: 39047421]
- sched/fair: Disable affine wakeups at NUMA domain levels on Exadata (Daniel Jordan) [Orabug: 38770281]
- drivers/soc/pensando/penfw: Added attest_meas and get cert_chain to penfw_util (Rahshekh) [Orabug: 39818086]
- drivers/soc/pensando/penfw_sysfs: fix bl31_show vers buffer size (Rahshekh) [Orabug: 39818086]
- mmc: core: Use HPI to interrupt lengthy cache flush (#494) (Brad Larson) [Orabug: 39818086]
- xen/ovmapi: terminate values passed to xenbus_write (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: free queued events on release (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: prevent duplicate app registration (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: avoid raw user pointer access in get_next_event (Joe Jin) [Orabug: 39851069]
- xen/ovmapi: reject oversized posted event payloads (Joe Jin) [Orabug: 39851069]
- IB/rxe: use rxe_drop_ref to release rxe_pd (Wengang Wang) [Orabug: 39831970]
- IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39831970]
- net/rds: restrict RDS_INFO dumps to caller netns (Praveen Kumar Kannoju) [Orabug: 39832021]
- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668599]
- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668599]
- Revert 'x86/alternatives: Add alt_instr.flags' (Harshit Mogalapalli) [Orabug: 39864327]
- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830590,39832946] {CVE-2026-64561}
- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39830590] {CVE-2026-64561}
- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Document the 'rules' for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- KVM: x86/mmu: Directly 'destroy' PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784615,39853775] {CVE-2026-68480}
- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}
- x86/alternatives: Add alt_instr.flags (Borislav Petkov) [Orabug: 39784615] {CVE-2026-68480}
- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}

[5.15.0-324.213.3]
- LTS version: v5.15.213 (Vijayendra Suman)
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807438] {CVE-2026-64560}
- LTS version: v5.15.212 (Vijayendra Suman)
- perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das)
- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39853280] {CVE-2026-64479}
- iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol)
- ALSA: seq: Check UMP support for midi_version change (Takashi Iwai)
- ALSA: seq: Skip event type filtering for UMP events (Takashi Iwai)
- iio: invensense: fix odr switching to same value (Jean-Baptiste Maneyrol)
- iio: imu: inv_mpu6050: fix frequency setting when chip is off (Jean-Baptiste Maneyrol)
- ALSA: seq: Avoid confusion of aligned read size (Takashi Iwai)
- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier)
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng)
- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang)
- audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina)
- audit: add audit_log_nf_skb helper function (Ricardo Robaina)
- btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo)
- crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785885] {CVE-2026-64304}
- btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo)
- crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta)
- btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843586] {CVE-2026-64593}
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron)
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum)
- crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-Konig)
- crypto: atmel-sha204a - Mark OF related data as maybe unused (Krzysztof Kozlowski)
- usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker)
- usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan)
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira)
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu)
- gpio: pca953x: Make platform teardown callback return void (Uwe Kleine-Konig)
- leds: lm3601x: Improve error reporting for problems during .remove() (Uwe Kleine-Konig)
- leds: lm3697: Remove duplicated error reporting in .remove() (Uwe Kleine-Konig)
- drm/i2c/sil164: Drop no-op remove function (Uwe Kleine-Konig)
- usb: iowarrior: remove inherent race with minor number (Oliver Neukum)
- bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786046] {CVE-2026-64352}
- bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko)
- bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi)
- bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786052] {CVE-2026-64355}
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani)
- hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko)
- xfs: use null daddr for unset first bad log block (Yousef Alhouseen)
- xfs: Remove dead code (Jiapeng Chong)
- xfs: Remove redundant assignment of mp (Jiapeng Chong)
- serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko)
- serial: 8250_mid: Remove 8250_pci usage (Ilpo Jarvinen)
- HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786074] {CVE-2026-64363}
- treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner)
- proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786095] {CVE-2026-64371}
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786078] {CVE-2026-64364}
- HID: add haptics page defines (Angela Czubak)
- proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786112] {CVE-2026-64375}
- proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig)
- proc: Move fdinfo PTRACE_MODE_READ check into the inode .permission operation (Tyler Hicks)
- proc: use generic setattr() for /proc//net (Thomas Weissschuh)
- X.509: Fix validation of ASN.1 certificate header (Lukas Wunner)
- ksmbd: track the connection owning a byte-range lock (Namjae Jeon)
- ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang)
- ksmbd: destroy async_ida in ksmbd_conn_free() (Daemyung Kang)
- ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc (Greg Kroah-Hartman)
- ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon)
- smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786128] {CVE-2026-64380}
- smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi)
- smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786124] {CVE-2026-64379}
- smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786200] {CVE-2026-64401}
- cifs: Add tracing for the cifs_tcon struct refcounting (David Howells)
- smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786131] {CVE-2026-64381}
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (Runyu Xiao) [Orabug: 39760901] {CVE-2026-64206}
- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim)
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz)
- netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786232] {CVE-2026-64413}
- netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng)
- gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- gpio: sch: use new GPIO line value setter callbacks (Bartosz Golaszewski)
- coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao)
- PCI: Skip Resizable BAR restore on read error (Marco Nenciarini)
- PCI: Move Resizable BAR code to rebar.c (Ilpo Jarvinen)
- PCI: Add kerneldoc for pci_resize_resource() (Ilpo Jarvinen)
- PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Jarvinen)
- PCI: Free saved list without holding pci_bus_sem (Ilpo Jarvinen)
- PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Jarvinen)
- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu) [Orabug: 39786307] {CVE-2026-64441}
- staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov)
- staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird)
- staging: rtl8723bs: remove redundant braces in if statements (Sevinj Aghayeva)
- staging: rtl8723bs: Remove redundant else branches. (Sevinj Aghayeva)
- PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786366] {CVE-2026-64461}
- PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi)
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby)
- staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu) [Orabug: 39786327] {CVE-2026-64446}
- staging: rtl8723bs: Fix space issues (Franziska Naepelt)
- staging: rtl8723bs: Fix indentation issues (Franziska Naepelt)
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu)
- smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786332] {CVE-2026-64448}
- cifs: remove unused server parameter from calc_smb_size() (Enzo Matsumiya)
- smb2: small refactor in smb2_check_message() (Enzo Matsumiya)
- cifs: remove check of list iterator against head past the loop body (Jakob Koschel)
- cifs: Create a new shared file holding smb2 pdu definitions (Ronnie Sahlberg)
- PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya)
- vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786409] {CVE-2026-64475}
- ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong)
- iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk)
- bitops: make BYTES_TO_BITS() treewide-available (Alexander Lobakin)
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: stabilized timestamp in interrupt (Jean-Baptiste Maneyrol)
- iio: invensense: fix timestamp glitches when switching frequency (Jean-Baptiste Maneyrol)
- iio: invensense: remove redundant initialization of variable period (Colin Ian King)
- iio: imu: inv_mpu6050: use the common inv_sensors timestamp module (Jean-Baptiste Maneyrol)
- iio: make invensense timestamp module generic (Jean-Baptiste Maneyrol)
- iio: move inv_icm42600 timestamp module in common (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: make timestamp module chip independent (Jean-Baptiste Maneyrol)
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu)
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao)
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786502] {CVE-2026-64510}
- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786508] {CVE-2026-64512}
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou)
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou)
- mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou)
- mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao)
- mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou)
- mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou)
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims)
- wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou)
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo)
- reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong)
- ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov)
- memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie)
- macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen)
- llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang)
- Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya)
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789564,39816016,39819143] {CVE-2026-64531}
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha)
- wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng)
- wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao)
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi)
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu)
- drbd: reject data replies with an out-of-range payload size (Michael Bommarito)
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao)
- ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao)
- llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai)
- mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen)
- s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer)
- hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An)
- ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang)
- orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas)
- tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu)
- net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)
- fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li)
- net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li)
- hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou)
- hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou)
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal)
- batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann)
- batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann)
- batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann)
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789573] {CVE-2026-64534}
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi)
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi)
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito)
- ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito)
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng)
- net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- gpios: palmas: add .get_direction() op (Andreas Kemnade)
- cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan)
- cpu: hotplug: Preserve per instance callback errors (Bradley Morgan)
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov)
- Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov)
- Input: ims-pcu - add response length checks (Dmitry Torokhov)
- Input: ims-pcu - validate control endpoint type (Dmitry Torokhov)
- Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov)
- Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov)
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li)
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang)
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas)
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas)
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito)
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito)
- scsi: sg: Report request-table problems when any status is set (Xu Rao)
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li)
- dm-verity: increase sprintf buffer size (Mikulas Patocka)
- dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka)
- dm-stats: fix merge accounting (Mikulas Patocka)
- dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka)
- dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski)
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka)
- dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius)
- dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai)
- dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang)
- net: sparx5: unregister blocking notifier on init failure (Haoxiang Li)
- can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp)
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp)
- can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp)
- nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas)
- sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794431] {CVE-2026-64551}
- spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi)
- time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan)
- tpm: Make the TPM character devices non-seekable (Jaewon Yang)
- tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum)
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)
- xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan)
- xen/gntdev: fix error handling in ioctl (Xu Wang)
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang)
- i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar)
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi)
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs)
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito)
- ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito)
- ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito)
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges)
- ocfs2: avoid moving extents to occupied clusters (Kyle Zeng)
- mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov)
- net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev)
- mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet)
- ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani)
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck)
- mtd: slram: remove failed entries from the device list (Ruoyu Wang)
- proc: only bump parent nlink when registering directories (Krzysztof Wilczynski)
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin)
- power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang)
- ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani)
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito)
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used (Michael Bommarito)
- fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito)
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito)
- fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov)
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov)
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov)
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng)
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki)
- MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold)
- MIPS: ip22-gio: fix kfree() of static object (Johan Hovold)
- MIPS: ip22-gio: fix gio device memory leak (Johan Hovold)
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever)
- lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever)
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal)
- nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal)
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo)
- Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen)
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen)
- mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski)
- batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann)
- batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann)
- batman-adv: frag: free unfragmentable packet (Sven Eckelmann)
- batman-adv: fix VLAN priority offset (Sven Eckelmann)
- batman-adv: tt: avoid request storms during pending request (Sven Eckelmann)
- batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann)
- batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann)
- batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann)
- batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann)
- batman-adv: access unicast_ttvn skb->data only after skb realloc (Sven Eckelmann)
- batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann)
- x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum)
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum)
- mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li)
- leds: uleds: Fix potential buffer overread (Armin Wolf)
- soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun)
- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli)
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li)
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794442] {CVE-2026-64554}
- netfilter: xt_nat: reject unsupported target families (Wyatt Feng)
- netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao)
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei)
- netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal)
- netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng)
- netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier)
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal)
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal)
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal)
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal)
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal)
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal)
- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal)
- fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal)
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal)
- fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing)
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal)
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal)
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal)
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim)
- arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen)
- net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang)
- net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang)
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito)
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci)
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang)
- smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li)
- net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing)
- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi)
- regulator: core: Make regulator_lock_two() logic easier to follow (Douglas Anderson)
- dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui)
- ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov)
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao)
- ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao)
- ipvs: pass parsed transport offset to state handlers (Yizhou Zhao)
- ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet)
- ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima)
- octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh)
- net/sched: cake: reject overhead values that underflow length (Samuel Moelius)
- net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon)
- ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang)
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794421] {CVE-2026-64549}
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen)
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei)
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei)
- net: qualcomm: rmnet: add tx packets aggregation (Daniele Palmas)
- qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida)
- netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng)
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen)
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu)
- netfilter: xt_u32: reject invalid shift counts (Wyatt Feng)
- gue: validate REMCSUM private option length (Qihang)
- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794412] {CVE-2026-64547}
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual)
- HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones)
- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin)
- ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak)
- afs: Fix unchecked-length string display in debug statement (David Howells)
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells)
- afs: Fix vllist leak (David Howells)
- afs: Fix callback service message parsers to pass through -EAGAIN (David Howells)
- afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter)
- net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius)
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim)
- cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov)
- virtio_net: disable cb when NAPI is busy-polled (Longjun Tang)
- irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi)
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser)
- tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu)
- bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel)
- net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev)
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794387] {CVE-2026-64540}
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang)
- ipv6: remove RTNL protection from inet6_dump_fib() (Eric Dumazet)
- inet: allow ip_valid_fib_dump_req() to be called with RTNL or RCU (Eric Dumazet)
- rtnetlink: add RTNL_FLAG_DUMP_UNLOCKED flag (Eric Dumazet)
- rtnetlink: change nlk->cb_mutex role (Eric Dumazet)
- hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen)
- qede: fix out-of-bounds check for cqe->len_list[] (Matvey Kovalev)
- seg6: validate SRH length before reading fixed fields (Nuoqi Gui)
- gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou)
- gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou)
- spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou)
- tracing: probes: fix typo in a log message (Martin Kaiser)
- net: sungem: fix probe error cleanup (Ruoyu Wang)
- net: mvneta: re-enable percpu interrupt on resume (Yun Zhou)
- rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li)
- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson)
- smb/client: preserve errors from smb2_set_sparse() (Huiwen He)
- ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera)
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787017] {CVE-2026-64530}
- veth: fix NAPI leak in XDP enable error path (Eric Dumazet)
- net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona)
- net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794405] {CVE-2026-64545}
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczynski)
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczynski)
- NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den)
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot (Runyu Xiao)
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera)
- ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima)
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794379] {CVE-2026-64538}
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy)
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794408] {CVE-2026-64546}
- bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar)
- bpf: Fix stack slot index in nospec checks (Nuoqi Gui)
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton)
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski)
- selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan)
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil)
- selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil)
- irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi)
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal)
- netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal)
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik)
- ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh)
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov)
- ACPI: resource: Amend kernel-doc style (Andy Shevchenko)
- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri)
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao)
- dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei)
- sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long)
- net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794438] {CVE-2026-64553}
- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (Ratheesh Kannoth)
- xfrm: validate selector family and prefixlen during match (Eric Dumazet)
- sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou)
- apparmor: fix label can not be immediately before a declaration (John Johansen)
- i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter)
- apparmor: put secmark label after secid lookup (Zygmunt Krynicki)
- apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki)
- apparmor: fix potential UAF in aa_replace_profiles (Maxime Belair)
- apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee)
- apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki)
- apparmor: check label build before no_new_privs test (Ruoyu Wang)
- PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam)
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee)
- tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo)
- tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo)
- tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo)
- xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason)
- PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar)
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer)
- NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo)
- pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg)
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney)
- dmaengine: Fix possible use after free (Nuno Sa)
- dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng)
- drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam)
- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev)
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda)
- iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts)
- iio: light: si1133: prevent race condition on timeout (Joshua Crofts)
- iio: light: si1133: reset counter to prevent race condition (Joshua Crofts)
- char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim)
- usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae)
- staging: most: video: avoid double free on video register failure (Guangshuo Li)
- phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko)
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki)
- x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki)
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan)
- coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng)
- staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu)
- net/9p: fix race condition on rdma->state in trans_rdma.c (Yizhou Zhao)
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh)
- ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li)
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet)
- tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet)
- KEYS: Use acquire when reading state in keyring search (Gui-Dong Han)
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan)
- powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan)
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan)
- MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan)
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim)
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794417] {CVE-2026-64548}
- smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He)
- netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal)
- kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao)
- bpf: Run generic devmap egress prog on private skb (Sun Jian)
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg)
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg)
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li)
- spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Poschel)
- crypto: rng - Free default RNG on module exit (Herbert Xu)
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu)
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu)
- tipc: reject inverted service ranges from peer bindings (Michael Bommarito)
- tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito)
- tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito)
- net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira)
- sctp: validate embedded address parameter length (Xin Long)
- bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei)
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima)
- ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An)
- ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An)
- ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An)
- RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla)
- RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad)
- fs: efs: remove unneeded debug prints (Maxwell Doose)
- s390/process: Fix kernel thread function pointer type (Heiko Carstens)
- bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann)
- selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song)
- bonding: 3ad: fix mux port state on oper down (Louis Scalbert)
- tools/virtio: check mmap return value in vringh_test (Longlong Yan)
- vduse: Requeue failed read to send_list head (Zhang Tianci)
- vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang)
- vduse: hold vduse_lock across IDR lookup in open path (Qihang)
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe)
- fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight)
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana)
- hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang)
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu)
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- watchdog: unregister PM notifier on watchdog unregister (Yuho Choi)
- configfs: fix lockless traversals of ->s_children (Al Viro)
- firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov)
- spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu)
- IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe)
- IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe)
- cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang)
- ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi)
- ALSA: seq: Clear variable event pointer on read (Kyle Zeng)
- ALSA: seq: Add UMP support (Takashi Iwai)
- ALSA: seq: Introduce SNDRV_SEQ_IOCTL_USER_PVERSION ioctl (Takashi Iwai)
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi)
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani)
- bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang)
- RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni)
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe)
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso)
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera)
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera)
- ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi)
- ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen)
- ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen)
- ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov)
- ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen)
- bpftool: Use libbpf error code for flow dissector query (Woojin Ji)
- configfs_lookup(): don't leave ->s_dentry dangling on failure (Al Viro)
- lib/test_meminit: use && for bools (Alexander Potapenko)
- mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon)
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey)
- scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter)
- scsi: Revert 'scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans' (Martin Wilck)
- ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi)
- ARM: imx3: Fix CCM node reference leak (Yuho Choi)
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi)
- md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng)
- media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han)
- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han)
- media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han)
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin)
- drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang)
- drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang)
- crypto: hisilicon/qm - disable error report before flr (Weili Qian)
- ocfs2: kill osb->system_file_mutex lock (Tetsuo Handa)
- ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang)
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter)
- dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso)
- libbpf: Fix UAF in strset__add_str() (Carlos Llamas)
- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi)
- drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen)
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu)
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen)
- ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet)
- workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao)
- nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff)
- mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal)
- mips: n64: add __iomem for writel call (Rosen Penev)
- mips: ralink: mt7621: add missing __iomem (Rosen Penev)
- MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki)
- MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki)
- PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu)
- RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa)
- IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li)
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni)
- bus: sunxi-rsb: Always check register address validity (Samuel Holland)
- pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez)
- cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng)
- cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang)
- device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev)
- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven)
- media: rockchip: rga: fix too small buffer size (Sven Puschel)
- net/sched: sch_drr: annotate data-races around cl->deficit (Eric Dumazet)
- sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman)
- firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla)
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan)
- RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh)
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande)
- RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov)
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li)
- net/sched: sch_htb: annotate data-races (I) (Eric Dumazet)
- net/sched: sch_htb: do not change sch->flags in htb_dump() (Eric Dumazet)
- crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson)
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet)
- thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki)
- evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou)
- drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He)
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He)
- clk: scmi: Fix clock rate rounding (Cristian Marussi)
- iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson)
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794401] {CVE-2026-64544}
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum)
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch)
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu)
- media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland)
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu)
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie)
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi)
- wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani)
- kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng)
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani)
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (Danilo Krummrich)
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi)
- drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen)
- fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges)
- afs: Fix further netns teardown to cancel the preallocation charger (David Howells)
- afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev)
- afs: Fix netns teardown to cancel the preallocation charger (David Howells)
- serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser)
- serial: msm: Disable DMA for kernel console UART (Stephan Gerhold)
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai)
- media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda)
- media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda)
- crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers)
- crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: crypto4xx - Remove ahash-related code (Herbert Xu)
- crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers)
- net: dsa: tag_ksz: do not rely on skb_mac_header() in TX paths (Vladimir Oltean)
- tools/mm/slabinfo: fix total_objects attribute name (Chenyichong)
- crypto: algif_skcipher - force synchronous processing on trees without ctx->state (Muhammet Kaan Kilinc)
- sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li)
- xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760871] {CVE-2026-64187}
- fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785786] {CVE-2026-64266}
- fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz)
- RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito)
- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan)
- Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov)
- Input: maplemouse - set driver data before registering input device (Dmitry Torokhov)
- Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov)
- Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov)
- Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs)
- Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785802] {CVE-2026-64271}
- Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas)
- Input: goodix - clamp the device-reported contact count (Bryam Vargas)
- Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785819] {CVE-2026-64275}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785823] {CVE-2026-64276}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas)
- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li)
- i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodriguez)
- i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785831] {CVE-2026-64279}
- udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov)
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843616] {CVE-2026-64604}
- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den)
- exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785863] {CVE-2026-64296}
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785868] {CVE-2026-64298}
- tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785872] {CVE-2026-64299}
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song)
- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song)
- crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel)
- crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers)
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers)
- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785893] {CVE-2026-64306}
- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785906] {CVE-2026-64312}
- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785910] {CVE-2026-64313}
- crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum)
- isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785923] {CVE-2026-64317}
- partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas)
- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi)
- dm-ioctl: report an error if a device has no table (Mikulas Patocka)
- udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785940] {CVE-2026-64322}
- udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785944] {CVE-2026-64323}
- udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785948] {CVE-2026-64324}
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan)
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M)
- usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski)
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785963] {CVE-2026-64330}
- usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day) [Orabug: 39785967] {CVE-2026-64331}
- usbip: tools: support SuperSpeedPlus devices (Chenyichong)
- USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao)
- USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785971] {CVE-2026-64332}
- USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785975] {CVE-2026-64333}
- USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785979] {CVE-2026-64334}
- USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785983] {CVE-2026-64335}
- USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda)
- USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785987] {CVE-2026-64336}
- usb: mtu3: unmap request DMA on queue failure (Haoxiang Li)
- USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785994] {CVE-2026-64338}
- USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao)
- usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak)
- USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785999] {CVE-2026-64340}
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover)
- USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786007] {CVE-2026-64342}
- USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786012] {CVE-2026-64343}
- USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786017] {CVE-2026-64344}
- usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu) [Orabug: 39786026] {CVE-2026-64346}
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie) [Orabug: 39786030] {CVE-2026-64347}
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang)
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceicao Alves)
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li)
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge)
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786042] {CVE-2026-64351}
- xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih)
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey)
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani)
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada)
- HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786071] {CVE-2026-64362}
- HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859299] {CVE-2026-68091}
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786091] {CVE-2026-64370}
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786100] {CVE-2026-64372}
- cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786104] {CVE-2026-64373}
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786108] {CVE-2026-64374}
- cpufreq: intel_pstate: Sync policy->cur during CPU offline (Wangfushuai)
- net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331701] {CVE-2026-43216}
- Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786205] {CVE-2026-64403}
- Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786578] {CVE-2026-64406}
- Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786217] {CVE-2026-64408}
- netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786224] {CVE-2026-64411}
- netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786228] {CVE-2026-64412}
- mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786248] {CVE-2026-64420}
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786254] {CVE-2026-64422}
- ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786259] {CVE-2026-64423}
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786574] {CVE-2026-64425}
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den)
- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian)
- debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner)
- audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786289] {CVE-2026-64435}
- net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786293] {CVE-2026-64436}
- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843604] {CVE-2026-64599}
- staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu) [Orabug: 39786303] {CVE-2026-64440}
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu) [Orabug: 39789581] {CVE-2026-64536}
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu) [Orabug: 39786311] {CVE-2026-64442}
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu) [Orabug: 39786315] {CVE-2026-64443}
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu) [Orabug: 39786319] {CVE-2026-64444}
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu) [Orabug: 39786323] {CVE-2026-64445}
- staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann)
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda)
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786340] {CVE-2026-64450}
- 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786344] {CVE-2026-64452}
- usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao) [Orabug: 39786349] {CVE-2026-64454}
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786352] {CVE-2026-64455}
- hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786356] {CVE-2026-64456}
- virtio-mmio: fix device release warning on module unload (Johan Hovold)
- netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760883] {CVE-2026-64189}
- PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth)
- PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya)
- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786379] {CVE-2026-64465}
- binder: fix UAF in binder_free_transaction() (Carlos Llamas)
- binder: fix UAF in binder_thread_release() (Carlos Llamas)
- Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold)
- Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786393] {CVE-2026-64470}
- Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786397] {CVE-2026-64471}
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cassio Gabriel)
- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cassio Gabriel)
- ALSA: usb-audio: Roll back quirk control caches on write errors (Cassio Gabriel)
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cassio Gabriel)
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cassio Gabriel)
- ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786416] {CVE-2026-64478}
- ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie) [Orabug: 39786428] {CVE-2026-64483}
- ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786432] {CVE-2026-64484}
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786439] {CVE-2026-64487}
- ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cassio Gabriel)
- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan)
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko)
- iio: light: veml6030: fix channel type when pushing events (Javier Carrasco)
- iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev)
- iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts)
- iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya)
- iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal)
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe)
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao)
- iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev)
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev)
- iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786462] {CVE-2026-64496}
- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose)
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou)
- iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786478] {CVE-2026-64503}
- iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786482] {CVE-2026-64504}
- usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman)
- usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman)
- ksmbd: fix out-of-bounds read in smb_check_perm_dacl() (Hem Parekh)
- NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753894] {CVE-2026-53392}
- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753924] {CVE-2026-53402}
- i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753916] {CVE-2026-53400}
- i2c: core: fix adapter debugfs creation (Johan Hovold)
- i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold)
- i2c: core: fix hang on adapter registration failure (Johan Hovold)
- i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold)
- block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753985] {CVE-2026-63810}
- f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma)
- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu)
- f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi)
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas)
- f2fs: validate orphan inode entry count (Wenjie Qi)
- device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski)
- f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong)
- f2fs: adjust zone capacity when considering valid block count (Jaegeuk Kim)
- f2fs: validate compress cache inode only when enabled (Wenjie Qi)
- f2fs: fix to detect corrupted meta ino (Chao Yu)
- apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas)
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754045] {CVE-2026-63829}
- apparmor: fix use-after-free in rawdata dedup loop (Ruslan Valiyev)
- net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754049] {CVE-2026-63830}
- skmsg: convert struct sk_msg_sg::copy to a bitmap (Eric Dumazet)
- netfilter: nf_tables: restore set elements when delete set fails (Pablo Neira Ayuso) [Orabug: 36598010] {CVE-2024-27012}
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753972] {CVE-2026-63806}
- nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown)
- nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown)
- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson)
- slimbus: Convert to platform remove callback returning void (Uwe Kleine-Konig)
- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson)
- dma-buf: remove unused dma-fence-unwrap.c (stable/linux-5.15.y only) (Tudor Ambarus)
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela)
- clk: imx: Add check for kcalloc (Jiasheng Jiang)
- userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786515] {CVE-2026-64514}
- nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753898] {CVE-2026-53393}
- nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753912] {CVE-2026-53399}
- nfc: llcp: protect nfc_llcp_sock_unlink() calls (Krzysztof Kozlowski)
- nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni) [Orabug: 39460310] {CVE-2026-46135}

[5.15.0-324.211.2]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558744] {CVE-2026-74684}
- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39801953]
- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812533]
- net/rds: Add parentheses around conditional operator (Gerd Rausch) [Orabug: 39844638]
- net/rds: remove cached rds_sock->rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832354]
- Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832354]
- rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772650]
- rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772650]
- net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621715,39638197] {CVE-2026-52995}
- x86/sev: Evict cache lines during SNP memory validation (Tom Lendacky) [Orabug: 38334919] {CVE-2025-38560}
- Revert: uek-rpm: cnic: Trim the SNIC config for a faster boot (Kan Liang) [Orabug: 39825570]
- Revert: uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Kan Liang) [Orabug: 39825570]
- rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818509]
- rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818509]
- drm/amdkfd: fix invalid GTT pointer in DQM cleanup (Imran Khan) [Orabug: 39605741]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick Wong) [Orabug: 39776791] {CVE-2026-64600}

[5.15.0-324.211.1]
- signal: Fix use-after-free of wait_chldexit (Aruna Ramakrishna) [Orabug: 39800301]
- mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074279]
- mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074279]
- mm/filemap: make filemap_fault() to retry fault after collapse_file() (Jane Chu) [Orabug: 39778847]
- PM: hibernate: Fix backwards snapshot_test condition for test_resume mode (Jeremy Tang) [Orabug: 39766052]
- PM: hibernate: Do not get block device exclusively in test_resume mode (Chen Yu) [Orabug: 39766052]
- PM: hibernate: Turn snapshot_test into global variable (Chen Yu) [Orabug: 39766052]
- PM: hibernate: fix load_image_and_restore() error path (Ye Bin) [Orabug: 39766052]
- arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation (Catalin Marinas) [Orabug: 39750197]
...


Related CVEs


CVE-2024-27012
CVE-2024-58240
CVE-2025-38560
CVE-2026-43216
CVE-2026-43491
CVE-2026-46135
CVE-2026-52995
CVE-2026-53090
CVE-2026-53392
CVE-2026-53393
CVE-2026-53399
CVE-2026-53400
CVE-2026-53402
CVE-2026-63806
CVE-2026-63810
CVE-2026-63829
CVE-2026-63830
CVE-2026-64098
CVE-2026-64187
CVE-2026-64189
CVE-2026-64192
CVE-2026-64206
CVE-2026-64266
CVE-2026-64270
CVE-2026-64271
CVE-2026-64272
CVE-2026-64275
CVE-2026-64276
CVE-2026-64279
CVE-2026-64294
CVE-2026-64296
CVE-2026-64298
CVE-2026-64299
CVE-2026-64304
CVE-2026-64306
CVE-2026-64312
CVE-2026-64313
CVE-2026-64317
CVE-2026-64322
CVE-2026-64323
CVE-2026-64324
CVE-2026-64330
CVE-2026-64331
CVE-2026-64332
CVE-2026-64333
CVE-2026-64334
CVE-2026-64335
CVE-2026-64336
CVE-2026-64338
CVE-2026-64340
CVE-2026-64342
CVE-2026-64343
CVE-2026-64344
CVE-2026-64346
CVE-2026-64347
CVE-2026-64351
CVE-2026-64352
CVE-2026-64355
CVE-2026-64362
CVE-2026-64363
CVE-2026-64364
CVE-2026-64370
CVE-2026-64371
CVE-2026-64372
CVE-2026-64373
CVE-2026-64374
CVE-2026-64375
CVE-2026-64379
CVE-2026-64380
CVE-2026-64381
CVE-2026-64401
CVE-2026-64403
CVE-2026-64406
CVE-2026-64408
CVE-2026-64411
CVE-2026-64412
CVE-2026-64413
CVE-2026-64420
CVE-2026-64422
CVE-2026-64423
CVE-2026-64425
CVE-2026-64427
CVE-2026-64434
CVE-2026-64435
CVE-2026-64436
CVE-2026-64440
CVE-2026-64441
CVE-2026-64442
CVE-2026-64443
CVE-2026-64444
CVE-2026-64445
CVE-2026-64446
CVE-2026-64448
CVE-2026-64450
CVE-2026-64452
CVE-2026-64454
CVE-2026-64455
CVE-2026-64456
CVE-2026-64461
CVE-2026-64465
CVE-2026-64470
CVE-2026-64471
CVE-2026-64475
CVE-2026-64478
CVE-2026-64479
CVE-2026-64483
CVE-2026-64484
CVE-2026-64487
CVE-2026-64496
CVE-2026-64503
CVE-2026-64504
CVE-2026-64510
CVE-2026-64512
CVE-2026-64514
CVE-2026-64530
CVE-2026-64531
CVE-2026-64534
CVE-2026-64535
CVE-2026-64536
CVE-2026-64538
CVE-2026-64540
CVE-2026-64543
CVE-2026-64544
CVE-2026-64545
CVE-2026-64546
CVE-2026-64547
CVE-2026-64548
CVE-2026-64549
CVE-2026-64551
CVE-2026-64553
CVE-2026-64554
CVE-2026-64560
CVE-2026-64561
CVE-2026-64562
CVE-2026-64563
CVE-2026-64567
CVE-2026-64569
CVE-2026-64571
CVE-2026-64572
CVE-2026-64576
CVE-2026-64579
CVE-2026-64586
CVE-2026-64593
CVE-2026-64599
CVE-2026-64600
CVE-2026-64604
CVE-2026-68082
CVE-2026-68091
CVE-2026-68096
CVE-2026-68104
CVE-2026-68106
CVE-2026-68111
CVE-2026-68115
CVE-2026-68117
CVE-2026-68121
CVE-2026-68123
CVE-2026-68125
CVE-2026-68129
CVE-2026-68131
CVE-2026-68132
CVE-2026-68138
CVE-2026-68142
CVE-2026-68143
CVE-2026-68144
CVE-2026-68146
CVE-2026-68153
CVE-2026-68154
CVE-2026-68155
CVE-2026-68156
CVE-2026-68157
CVE-2026-68158
CVE-2026-68159
CVE-2026-68160
CVE-2026-68162
CVE-2026-68180
CVE-2026-68184
CVE-2026-68186
CVE-2026-68187
CVE-2026-68188
CVE-2026-68190
CVE-2026-68192
CVE-2026-68197
CVE-2026-68198
CVE-2026-68199
CVE-2026-68202
CVE-2026-68205
CVE-2026-68212
CVE-2026-68213
CVE-2026-68214
CVE-2026-68216
CVE-2026-68217
CVE-2026-68218
CVE-2026-68226
CVE-2026-68227
CVE-2026-68234
CVE-2026-68243
CVE-2026-68244
CVE-2026-68248
CVE-2026-68249
CVE-2026-68250
CVE-2026-68253
CVE-2026-68254
CVE-2026-68255
CVE-2026-68284
CVE-2026-68294
CVE-2026-68297
CVE-2026-68299
CVE-2026-68300
CVE-2026-68301
CVE-2026-68304
CVE-2026-68309
CVE-2026-68313
CVE-2026-68315
CVE-2026-68320
CVE-2026-68325
CVE-2026-68326
CVE-2026-68328
CVE-2026-68338
CVE-2026-68344
CVE-2026-68349
CVE-2026-68350
CVE-2026-68351
CVE-2026-68352
CVE-2026-68353
CVE-2026-68354
CVE-2026-68355
CVE-2026-68363
CVE-2026-68365
CVE-2026-68367
CVE-2026-68368
CVE-2026-68373
CVE-2026-68376
CVE-2026-68377
CVE-2026-68398
CVE-2026-68402
CVE-2026-68403
CVE-2026-68405
CVE-2026-68406
CVE-2026-68410
CVE-2026-68413
CVE-2026-68414
CVE-2026-68422
CVE-2026-68425
CVE-2026-68428
CVE-2026-68430
CVE-2026-68432
CVE-2026-68433
CVE-2026-68434
CVE-2026-68444
CVE-2026-68446
CVE-2026-68450
CVE-2026-68456
CVE-2026-68461
CVE-2026-68469
CVE-2026-68475
CVE-2026-68477
CVE-2026-68479
CVE-2026-68480
CVE-2026-72004
CVE-2026-72005
CVE-2026-72010
CVE-2026-72014
CVE-2026-72015
CVE-2026-72019
CVE-2026-72020
CVE-2026-72021
CVE-2026-72024
CVE-2026-72035
CVE-2026-72036
CVE-2026-72039
CVE-2026-72045
CVE-2026-72049
CVE-2026-72051
CVE-2026-72052
CVE-2026-72053
CVE-2026-72054
CVE-2026-72055
CVE-2026-72056
CVE-2026-72057
CVE-2026-72061
CVE-2026-72063
CVE-2026-72065
CVE-2026-72066
CVE-2026-72067
CVE-2026-72068
CVE-2026-72070
CVE-2026-72073
CVE-2026-72083
CVE-2026-72084
CVE-2026-72085
CVE-2026-72086
CVE-2026-72087
CVE-2026-72088
CVE-2026-72096
CVE-2026-72099
CVE-2026-72102
CVE-2026-72105
CVE-2026-72107
CVE-2026-72108
CVE-2026-72110
CVE-2026-72113
CVE-2026-72114
CVE-2026-72115
CVE-2026-72116
CVE-2026-72117
CVE-2026-72118
CVE-2026-72119
CVE-2026-72120
CVE-2026-72121
CVE-2026-72122
CVE-2026-72123
CVE-2026-72124
CVE-2026-72125
CVE-2026-72126
CVE-2026-72129
CVE-2026-72135
CVE-2026-72136
CVE-2026-72138
CVE-2026-72142
CVE-2026-72152
CVE-2026-72155
CVE-2026-72159
CVE-2026-72160
CVE-2026-72163
CVE-2026-72164
CVE-2026-72165
CVE-2026-72166
CVE-2026-72170
CVE-2026-72182
CVE-2026-72218
CVE-2026-72219
CVE-2026-72223
CVE-2026-72224
CVE-2026-72225
CVE-2026-72226
CVE-2026-72228
CVE-2026-72229
CVE-2026-72230
CVE-2026-72231
CVE-2026-72232
CVE-2026-72233
CVE-2026-72234
CVE-2026-72235
CVE-2026-72240
CVE-2026-72241
CVE-2026-72242
CVE-2026-72245
CVE-2026-72247
CVE-2026-72250
CVE-2026-72251
CVE-2026-72252
CVE-2026-72253
CVE-2026-72255
CVE-2026-72256
CVE-2026-72265
CVE-2026-72272
CVE-2026-72282
CVE-2026-72289
CVE-2026-72297
CVE-2026-72298
CVE-2026-72299
CVE-2026-72305
CVE-2026-72306
CVE-2026-72310
CVE-2026-72314
CVE-2026-72316
CVE-2026-72319
CVE-2026-72322
CVE-2026-72326
CVE-2026-72339
CVE-2026-72347
CVE-2026-72348
CVE-2026-72349
CVE-2026-72350
CVE-2026-72351
CVE-2026-72389
CVE-2026-72392
CVE-2026-72396
CVE-2026-72400
CVE-2026-72406
CVE-2026-72409
CVE-2026-72418
CVE-2026-72421
CVE-2026-72428
CVE-2026-72433
CVE-2026-72435
CVE-2026-72441
CVE-2026-72447
CVE-2026-72450
CVE-2026-72466
CVE-2026-72476
CVE-2026-72481
CVE-2026-72491
CVE-2026-72502
CVE-2026-74255
CVE-2026-74256
CVE-2026-74265
CVE-2026-74267
CVE-2026-74279
CVE-2026-74281
CVE-2026-74282
CVE-2026-74283
CVE-2026-74284
CVE-2026-74287
CVE-2026-74288
CVE-2026-74295
CVE-2026-74297
CVE-2026-74305
CVE-2026-74312
CVE-2026-74313
CVE-2026-74320
CVE-2026-74321
CVE-2026-74327
CVE-2026-74329
CVE-2026-74330
CVE-2026-74331
CVE-2026-74339
CVE-2026-74340
CVE-2026-74346
CVE-2026-74348
CVE-2026-74349
CVE-2026-74351
CVE-2026-74359
CVE-2026-74363
CVE-2026-74376
CVE-2026-74379
CVE-2026-74382
CVE-2026-74384
CVE-2026-74390
CVE-2026-74394
CVE-2026-74395
CVE-2026-74398
CVE-2026-74399
CVE-2026-74408
CVE-2026-74410
CVE-2026-74416
CVE-2026-74424
CVE-2026-74443
CVE-2026-74444
CVE-2026-74453
CVE-2026-74455
CVE-2026-74456
CVE-2026-74457
CVE-2026-74458
CVE-2026-74460
CVE-2026-74461
CVE-2026-74464
CVE-2026-74465
CVE-2026-74469
CVE-2026-74470
CVE-2026-74471
CVE-2026-74473
CVE-2026-74475
CVE-2026-74479
CVE-2026-74480
CVE-2026-74481
CVE-2026-74482
CVE-2026-74485
CVE-2026-74486
CVE-2026-74487
CVE-2026-74488
CVE-2026-74490
CVE-2026-74492
CVE-2026-74495
CVE-2026-74497
CVE-2026-74498
CVE-2026-74499
CVE-2026-74505
CVE-2026-74507
CVE-2026-74508
CVE-2026-74512
CVE-2026-74517
CVE-2026-74518
CVE-2026-74519
CVE-2026-74523
CVE-2026-74540
CVE-2026-74546
CVE-2026-74547
CVE-2026-74548
CVE-2026-74556
CVE-2026-74557
CVE-2026-74564
CVE-2026-74566
CVE-2026-74567
CVE-2026-74569
CVE-2026-74575
CVE-2026-74577
CVE-2026-74579
CVE-2026-74580
CVE-2026-74581
CVE-2026-74583
CVE-2026-74585
CVE-2026-74586
CVE-2026-74587
CVE-2026-74588
CVE-2026-74589
CVE-2026-74594
CVE-2026-74595
CVE-2026-74597
CVE-2026-74598
CVE-2026-74599
CVE-2026-74601
CVE-2026-74604
CVE-2026-74609
CVE-2026-74613
CVE-2026-74614
CVE-2026-74615
CVE-2026-74616
CVE-2026-74620
CVE-2026-74621
CVE-2026-74622
CVE-2026-74623
CVE-2026-74625
CVE-2026-74630
CVE-2026-74635
CVE-2026-74636
CVE-2026-74641
CVE-2026-74648
CVE-2026-74649
CVE-2026-74650
CVE-2026-74651
CVE-2026-74654
CVE-2026-74656
CVE-2026-74657
CVE-2026-74658
CVE-2026-74660
CVE-2026-74664
CVE-2026-74667
CVE-2026-74669
CVE-2026-74671
CVE-2026-74673
CVE-2026-74675
CVE-2026-74676
CVE-2026-74679
CVE-2026-74680
CVE-2026-74682
CVE-2026-74683
CVE-2026-74684
CVE-2026-74688
CVE-2026-74696
CVE-2026-74697
CVE-2026-74701
CVE-2026-74704
CVE-2026-74705
CVE-2026-74717
CVE-2026-74720
CVE-2026-74726
CVE-2026-74730
CVE-2026-74746
CVE-2026-74748
CVE-2026-80527
CVE-2026-80528
CVE-2026-80534
CVE-2026-80540
CVE-2026-80541
CVE-2026-80558
CVE-2026-80561
CVE-2026-80574
CVE-2026-80586
CVE-2026-80590
CVE-2026-80593
CVE-2026-80599
CVE-2026-80601
CVE-2026-80603
CVE-2026-80604
CVE-2026-80605
CVE-2026-80609
CVE-2026-80613
CVE-2026-80622
CVE-2026-80630
CVE-2026-80644
CVE-2026-80646
CVE-2026-80652
CVE-2026-80659
CVE-2026-80664
CVE-2026-80677
CVE-2026-80678
CVE-2026-80681
CVE-2026-80706
CVE-2026-80707
CVE-2026-80714
CVE-2026-80715
CVE-2026-80716
CVE-2026-80717
CVE-2026-80722
CVE-2026-80731
CVE-2026-80733
CVE-2026-80742
CVE-2026-80744
CVE-2026-80754
CVE-2026-80756
CVE-2026-80757

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-uek-5.15.0-324.217.5.2.el8uek.src.rpm96c0148982c83d1aa240e47bf2c09a6da828bf78c25134eb61bfa9bde2015292-ol8_aarch64_UEKR7
bpftool-5.15.0-324.217.5.2.el8uek.aarch64.rpm4052a95bf905209d9bebf39a443627245f0f1f374e0d2d7d150548a3b64737b2-ol8_aarch64_UEKR7
kernel-uek-5.15.0-324.217.5.2.el8uek.aarch64.rpm956f00b6d667e326b842f0506da4283539b205441c4a463b479acf748c486e9c-ol8_aarch64_UEKR7
kernel-uek-container-5.15.0-324.217.5.2.el8uek.aarch64.rpm51f2c0a602feb9c4862f38080b60324d4c1c96c7cc6b60d4aa085494e48e0d32-ol8_aarch64_UEKR7
kernel-uek-container-debug-5.15.0-324.217.5.2.el8uek.aarch64.rpmbd9911c823df3228ee81170f982c43fc1f992c09c73df46843fc37e382cb91fe-ol8_aarch64_UEKR7
kernel-uek-core-5.15.0-324.217.5.2.el8uek.aarch64.rpm06d98a24d3ebf724eaea6ddcab0c33320bfe7a759cb2211bd650e783fcee1185-ol8_aarch64_UEKR7
kernel-uek-debug-5.15.0-324.217.5.2.el8uek.aarch64.rpmf7bdfa8d2b80268aa24f442e200ae493b181da463805f7329bbc2644b1d739c1-ol8_aarch64_UEKR7
kernel-uek-debug-core-5.15.0-324.217.5.2.el8uek.aarch64.rpmf3fd90abe3444775fc50272bbc6904f80475166bc3085f5784ccbd8cecb8d27b-ol8_aarch64_UEKR7
kernel-uek-debug-devel-5.15.0-324.217.5.2.el8uek.aarch64.rpmf5e30a4f88803ed283dd67ebc84b3e5d0ab44759d162cf0fa84f6096c5075602-ol8_aarch64_UEKR7
kernel-uek-debug-modules-5.15.0-324.217.5.2.el8uek.aarch64.rpmf1bd46fe63bf8a2d87193b3471547cc5688a274b4f8ac1aea457e3ee14292a0c-ol8_aarch64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-324.217.5.2.el8uek.aarch64.rpm7e0be93343056b61b87851bbdecd184f0f85717f31e092d01317301e17c5d80b-ol8_aarch64_UEKR7
kernel-uek-devel-5.15.0-324.217.5.2.el8uek.aarch64.rpm56cd664748d74ae1c956e913c2cba309a96bec12e5d72d92a648a6b2508680d1-ol8_aarch64_UEKR7
kernel-uek-doc-5.15.0-324.217.5.2.el8uek.noarch.rpmd7e41c37681ddc7e7d38938692961738b05cba84c1939086cdba57e91f160d75-ol8_aarch64_UEKR7
kernel-uek-modules-5.15.0-324.217.5.2.el8uek.aarch64.rpmd6e9c4999b96aa01b421af7769a79996fa9d334408b1c2f3c57755ebae7763e5-ol8_aarch64_UEKR7
kernel-uek-modules-extra-5.15.0-324.217.5.2.el8uek.aarch64.rpm96d3dd881bc59a3faaa6f29a069e90c44812890b09b6987f621cd51035e1b5f2-ol8_aarch64_UEKR7
Oracle Linux 8 (x86_64) kernel-uek-5.15.0-324.217.5.2.el8uek.src.rpm96c0148982c83d1aa240e47bf2c09a6da828bf78c25134eb61bfa9bde2015292-ol8_x86_64_UEKR7
bpftool-5.15.0-324.217.5.2.el8uek.x86_64.rpmaa96ec5bfa4ee44bbb66bd627e72464ca9ce637e0cd195a9e999d1239c9f8761-ol8_x86_64_UEKR7
kernel-uek-5.15.0-324.217.5.2.el8uek.x86_64.rpm165e944f24480845905261c34aedd1995fd5ec4209e536075304a0b7e4fea46b-ol8_x86_64_UEKR7
kernel-uek-container-5.15.0-324.217.5.2.el8uek.x86_64.rpm09c0bd782c93c388f324ed0b63a8ffaa11ead46e811e37783bfac4f0d2ded154-ol8_x86_64_UEKR7
kernel-uek-container-debug-5.15.0-324.217.5.2.el8uek.x86_64.rpm612271507e4a6b63430587e1885312351b34c8eac6d716c9d1ba17f692bab2e4-ol8_x86_64_UEKR7
kernel-uek-core-5.15.0-324.217.5.2.el8uek.x86_64.rpm191cba4fbe6547af898b66078b3ef9fe16b6dd8ccb6ec46605f7ea6ea1b82ecb-ol8_x86_64_UEKR7
kernel-uek-debug-5.15.0-324.217.5.2.el8uek.x86_64.rpmf069964136e9c4bf0bb99f7ee214a363d17112e73c08c6dad275d69dcfa0c877-ol8_x86_64_UEKR7
kernel-uek-debug-core-5.15.0-324.217.5.2.el8uek.x86_64.rpmfffa10ff115dcc08d934e7653dc29ff39bcdd02546bb6964212d370ea4594d5e-ol8_x86_64_UEKR7
kernel-uek-debug-devel-5.15.0-324.217.5.2.el8uek.x86_64.rpm9737a992e5abc54e1f3b8b5e339c1256935e0694d0f5fa11f89ab4db9c2f2d38-ol8_x86_64_UEKR7
kernel-uek-debug-modules-5.15.0-324.217.5.2.el8uek.x86_64.rpma38d7c36a3a32438f611f13b3b9bc89a9882b1111eb002442089a34133634a24-ol8_x86_64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-324.217.5.2.el8uek.x86_64.rpm9412ed0ca4fc8f10b57eed4fc35dd83b2639221626a809dfe53c8ff09f355a2b-ol8_x86_64_UEKR7
kernel-uek-devel-5.15.0-324.217.5.2.el8uek.x86_64.rpm6842c815a3f25df4b37eed51acd72225c638cf0a12c2f3c3754b13b783e00333-ol8_x86_64_UEKR7
kernel-uek-doc-5.15.0-324.217.5.2.el8uek.noarch.rpmd7e41c37681ddc7e7d38938692961738b05cba84c1939086cdba57e91f160d75-ol8_x86_64_UEKR7
kernel-uek-modules-5.15.0-324.217.5.2.el8uek.x86_64.rpmcd415f9e10f8da5dd869b3ee12f3042f20a84a0443d50ec65f64c826847e0bd3-ol8_x86_64_UEKR7
kernel-uek-modules-extra-5.15.0-324.217.5.2.el8uek.x86_64.rpm2b1d451ce5209b36616862423e86e5c86adeb4257512046da41dc6f405315fb7-ol8_x86_64_UEKR7
Oracle Linux 9 (x86_64) kernel-uek-5.15.0-324.217.5.2.el9uek.src.rpm95fb844da111b19882f8668b1244d36f1b6511e06b2482dc8b87ba3e08d85fab-ol9_x86_64_UEKR7
bpftool-5.15.0-324.217.5.2.el9uek.x86_64.rpma733abb464400bdd6f0dde52829693a497c90a01e0c523331c66c76d0f95121a-ol9_x86_64_UEKR7
kernel-uek-5.15.0-324.217.5.2.el9uek.x86_64.rpm0a35517fcb1b5686f9fd80b359bbe134b42b7428ffdc84089c1a90fa714f67fa-ol9_x86_64_UEKR7
kernel-uek-container-5.15.0-324.217.5.2.el9uek.x86_64.rpm219918c802991ec3779eb30681f12b6df04af1479904495393bff8388839aed5-ol9_x86_64_UEKR7
kernel-uek-container-debug-5.15.0-324.217.5.2.el9uek.x86_64.rpm8181b9e03d2e55c4a9b86b943c0762e57474aecbbcf71c7f0fcc9513cc4c91f2-ol9_x86_64_UEKR7
kernel-uek-core-5.15.0-324.217.5.2.el9uek.x86_64.rpmbcd7ef9eff1635a80509193a63b939f60a08cc1263280f748437fd10dea00242-ol9_x86_64_UEKR7
kernel-uek-debug-5.15.0-324.217.5.2.el9uek.x86_64.rpmd355c3031a073f95ead1bb17b2d9c4de3fa8dc97fdf82a707a0e2e7f901448c6-ol9_x86_64_UEKR7
kernel-uek-debug-core-5.15.0-324.217.5.2.el9uek.x86_64.rpm7a3a5b2aead25942f2d9bf7e5a6611076439fe4429ef070396c4a5ac8330f537-ol9_x86_64_UEKR7
kernel-uek-debug-devel-5.15.0-324.217.5.2.el9uek.x86_64.rpmc39813c79060ea3218cc6258ca0b799d2e79511e6d42d0a27f37994ef5029e6e-ol9_x86_64_UEKR7
kernel-uek-debug-modules-5.15.0-324.217.5.2.el9uek.x86_64.rpm045c2bd9e65a355965894c312952f3aa1cc5d7fcaa72a1d1a149e04dcf1c8129-ol9_x86_64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-324.217.5.2.el9uek.x86_64.rpm58e4cad7a535dbe93e5cdbf183ab7a9078caf722e66fffe3de004a8973459715-ol9_x86_64_UEKR7
kernel-uek-devel-5.15.0-324.217.5.2.el9uek.x86_64.rpmf098ad5f0081ed1e58df85a84daad87520c056edc0e247dbdf8945ac81b8d8a6-ol9_x86_64_UEKR7
kernel-uek-doc-5.15.0-324.217.5.2.el9uek.noarch.rpm13be85d9a8cde26c3412a667fb80204e771457475873c0f608eb80197fb3d546-ol9_x86_64_UEKR7
kernel-uek-modules-5.15.0-324.217.5.2.el9uek.x86_64.rpm0b45d4d55ffaa88d34ace1651bd1b83bb7c116ff0ea7de189b89b3b2a40deacd-ol9_x86_64_UEKR7
kernel-uek-modules-extra-5.15.0-324.217.5.2.el9uek.x86_64.rpm929d427dcdafaff97901f14a0bfdb2a4e5db8cbf3012034de91367f5c6dfc62c-ol9_x86_64_UEKR7



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete