ELSA-2026-500374

ELSA-2026-500374 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-10-07

Description


[6.12.0-207.111.5.1]
- selftests/mm/khugepaged: include kselftest.h in khugepaged (Sherry Yang) [Orabug: 40099804]

[6.12.0-207.111.5]
- Rename ONOS kernel flavor to OSP for OL9 and OL10 (Vijay Kumar) [Orabug: 40055216]
- tcp: Remove hashinfo test for inet6?_lookup_run_sk_lookup(). (Kuniyuki Iwashima) [Orabug: 40052306]
- LTS version: v6.12.111 (Sherry Yang)
- mptcp: fix bad accounting in __mptcp_subflow_push_pending() (Paolo Abeni) [Orabug: 40078583] {CVE-2026-97522}
- mptcp: close race between scheduler and state change (Paolo Abeni) [Orabug: 40078588] {CVE-2026-97523}
- mptcp: avoid unneeded actions on subflow reset (Paolo Abeni) [Orabug: 40078594] {CVE-2026-97524}
- SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode (Ameer Hamza)
- workqueue: Update documentation as per system_percpu_wq naming (Mallesh Koujalagi)
- ocfs2: validate directory-index entry counts when reading metadata (Doruk Tan Ozturk) [Orabug: 40020935] {CVE-2026-89492}
- ocfs2: validate dx_root extent list fields during block read (Joseph Qi)
- sched_ext: Fix inverted ops.core_sched_before() invocation (Tejun Heo)
- svcrdma: Reject Write/Reply chunks with segcount 0 (Chris Mason) [Orabug: 40072707] {CVE-2026-93228}
- svcrdma: Adjust the number of entries in svc_rdma_recv_ctxt::rc_pages (Chuck Lever)
- sunrpc: Add a helper to derive maxpages from sv_max_mesg (Chuck Lever)
- svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id (Chuck Lever) [Orabug: 40021075] {CVE-2026-89535}
- svcrdma: Release transport resources synchronously (Chuck Lever)
- rpcrdma: arm rn_done before publishing the notification (Chuck Lever) [Orabug: 40033153] {CVE-2026-89798}
- sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir (Luxiao Xu) [Orabug: 40021120] {CVE-2026-89543}
- rpc_pipe: don't overdo directory locking (Al Viro)
- rpc_mkpipe_dentry(): saner calling conventions (Al Viro)
- rpc_populate(): lift cleanup into callers (Al Viro)
- SUNRPC: fix gssx_dec_option_array error path bugs (Chris Mason) [Orabug: 40021135] {CVE-2026-89544}
- sunrpc: defer rq_argp and rq_resp free until after RCU grace period (Jeff Layton) [Orabug: 40021143] {CVE-2026-89545}
- SUNRPC: Update svcxdr_init_decode() to call xdr_set_scratch_folio() (Anna Schumaker)
- SUNRPC: Introduce xdr_set_scratch_folio() (Anna Schumaker)
- ip: orphan prefetched skbs before multicast forwarding (Zhiling Zou) [Orabug: 40021224] {CVE-2026-89564}
- ipv6: ip6_mc_input() and ip6_mr_input() cleanups (Eric Dumazet)
- ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers (Eric Dumazet)
- ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() (Andrea Mayer) [Orabug: 40021207] {CVE-2026-89561}
- ipv6: annotate data-races around devconf->rpl_seg_enabled (Yue Haibing)
- cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register (Terry Bowman)
- ACPI: TAD: Add locking around AML evaluations (Rafael J. Wysocki)
- ACPI: TAD: Split three functions to untangle runtime PM handling (Rafael J. Wysocki)
- ACPI: TAD: Rearrange RT data validation checking (Rafael J. Wysocki)
- bpf: Disable preemption in bpf_get_stackid (Jiri Olsa) [Orabug: 40033158] {CVE-2026-89799}
- bpf: Use stack id functions instead of __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_new_bucket from __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_fastpath function from __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_init function from __bpf_get_stackid (Jiri Olsa)
- cpufreq: apple-soc: Fix OPP table cleanup (Haoxiang Li)
- acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks (Terry Bowman) [Orabug: 40021333] {CVE-2026-89589}
- efi/cper, cxl: Make definitions and structures global (Smita Koralahalli)
- efi/cper, cxl: Prefix protocol error struct and function names with cxl_ (Smita Koralahalli)
- erofs: skip sufficiently large global buffers when resizing (Nikhil Gurudasani) [Orabug: 40021393] {CVE-2026-89602}
- NFSD: Prevent client use-after-free during close_lru reaping (Chuck Lever) [Orabug: 40034294] {CVE-2026-90037}
- NFSD: Prevent client use-after-free during blocked-lock reaping (Chuck Lever) [Orabug: 40034286] {CVE-2026-90036}
- NFSD: Consolidate the revocation-path client unpin (Chuck Lever)
- HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes (Jiangshan Yi)
- HID: mcp2221: fix OOB write in mcp2221_raw_event() (Florian Pradines)
- HID: sony: clean up device list on probe failure (Doruk Tan Ozturk) [Orabug: 40034309] {CVE-2026-90041}
- HID: sony: use guard() and scoped_guard() (Rosalie Wanders)
- HID: universal-pidff: stop the device when force-feedback init fails (Baul Lee)
- HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind (Doruk Tan Ozturk) [Orabug: 40021493] {CVE-2026-89625}
- btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag (Qu Wenruo)
- btrfs: fix extent map leak in NOCOW direct I/O write (Shuangpeng Bai) [Orabug: 40021561] {CVE-2026-89644}
- btrfs: rename extent map functions to get block start, end and check if in tree (Filipe Manana)
- btrfs: add btrfs prefix to main lock, try lock and unlock extent functions (Filipe Manana)
- btrfs: use BTRFS_PATH_AUTO_FREE in can_nocow_extent() (David Sterba)
- btrfs: prepare btrfs_punch_hole_lock_range() for large data folios (Qu Wenruo)
- btrfs: pass struct btrfs_inode to btrfs_sync_inode_flags_to_i_flags() (David Sterba)
- btrfs: parameter constification in ioctl.c (David Sterba)
- btrfs: update include and forward declarations in headers (David Sterba)
- btrfs: expose per-inode stable writes flag (Qu Wenruo)
- btrfs: move btrfs_alloc_write_mask() into fs.h (Filipe Manana)
- btrfs: move BTRFS_BYTES_TO_BLKS() into fs.h (Filipe Manana)
- btrfs: move btrfs_is_empty_uuid() from ioctl.c into fs.c (Filipe Manana)
- HID: apple: preserve keyboard backlight across T2 resume (Andre Eikmeyer)
- ceph: properly decrypt filenames in vmalloc() buffers (Sam Edwards) [Orabug: 40034317] {CVE-2026-90042}
- NFSD: Guard admin state-revocation walks with NFSD_NET_UP (Chuck Lever) [Orabug: 40034301] {CVE-2026-90039}
- ceph: force a cap message when a deferred revoke can't be acked immediately (Max Kellermann)
- ceph: Remove fs/ceph deadcode (Dr. David Alan Gilbert)
- NFSD: Prevent client use-after-free during delegation revoke (Chuck Lever) [Orabug: 40021620] {CVE-2026-89659}
- nfsd: disallow file locking and delegations for NFSv4 reexport (Mike Snitzer)
- NFSD: Prevent client use-after-free during admin state revocation (Chuck Lever) [Orabug: 40021626] {CVE-2026-89660}
- nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache (Jeff Layton) [Orabug: 40021653] {CVE-2026-89667}
- nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (Jeff Layton) [Orabug: 40021687] {CVE-2026-89676}
- nfsd: update mtime/ctime on COPY in presence of delegated attributes (Olga Kornievskaia)
- nfsd: fix netlink dumpit error handling for rpc_status_get (Jeff Layton)
- nfsd: fix clock domain mismatch in clients_still_reclaiming() (Jeff Layton) [Orabug: 40021710] {CVE-2026-89685}
- nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown (Jeff Layton) [Orabug: 40021778] {CVE-2026-89708}
- nfsd: dedup nfs4_client_to_reclaim inserts (Jeff Layton)
- nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage (Jeff Layton) [Orabug: 40021748] {CVE-2026-89698}
- Revert 'NFSD: Remove the cap on number of operations per NFSv4 COMPOUND' (Chuck Lever) [Orabug: 38686996] {CVE-2025-40210}
- NFSD: Make nfsd_genl_rqstp::rq_ops array best-effort (Chuck Lever)
- NFSD: Rename a function parameter (Chuck Lever)
- nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() (Jeff Layton) [Orabug: 40021727] {CVE-2026-89693}
- nfsd: validate sockaddr length per family in listener_set (Jeff Layton) [Orabug: 40021754] {CVE-2026-89700}
- zram: set default primary compressor in zram_destroy_comps() (Sergey Senozhatsky) [Orabug: 40021806] {CVE-2026-89717}
- zram: switch to guard() for init_lock (Sergey Senozhatsky)
- zram: fix out-of-bounds access in writeback_store() (Longlong Xia) [Orabug: 40021808] {CVE-2026-89718}
- zram: use zram_read_from_zspool() in writeback (Sergey Senozhatsky)
- zram: remove entry element member (Sergey Senozhatsky)
- zram: fix out-of-bounds access in read_block_state() (Longlong Xia) [Orabug: 40021813] {CVE-2026-89719}
- zram: fixup read_block_state() (Sergey Senozhatsky)
- usb: gadget: f_fs: Fix Use-After-Free in AIO error path (Neill Kapron)
- USB: gadget: ffs: fix mm lifetime handling (Gabriel Prostitis)
- cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read (Terry Bowman) [Orabug: 40021856] {CVE-2026-89731}
- cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c (Dave Jiang)
- cxl/pci: Remove unnecessary CXL RCH handling helper functions (Terry Bowman)
- cxl/pci: Remove unnecessary CXL Endpoint handling helper functions (Terry Bowman)
- x86/xen: fix init of balloon stats again (Roger Pau Monne)
- xen/balloon: improve accuracy of initial balloon target for dom0 (Roger Pau Monne)
- x86/locking: Use sfence for wmb() if SSE is available (Yao Zi)
- x86/locking: Remove semicolon from 'lock' prefix (Uros Bizjak)
- mm/slub: fix missing debugfs entries for caches created before sysfs init (Li Xiasong)
- mm/slab: move and refactor __kmem_cache_alias() (Vlastimil Babka)
- mm/migrate_device: clear stale mapping after freeing swapcache (Arvind Yadav) [Orabug: 40021923] {CVE-2026-89755}
- KEYS: trusted: Fix TPM teardown ordering (Chengfeng Ye) [Orabug: 40021952] {CVE-2026-89763}
- mm, swap: ratelimit bad swap entry reports (Breno Leitao)
- mm: fix possible NULL pointer dereference in __swap_duplicate (Gao Xu)
- crypto: iaa - unmap dst before software fallback on decompress (Vinicius Costa Gomes) [Orabug: 40020455] {CVE-2026-80945}
- crypto: atmel-ecc - avoid stale fallback key after set_secret failure (Thorsten Blum)
- KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests (Sean Christopherson)
- KVM: SVM: Move SEV-ES VMSA allocation to a dedicated sev_vcpu_create() helper (Sean Christopherson)
- KVM: SEV: Disable SEV-SNP support on initialization failure (Ashish Kalra)
- KVM: SVM: Invalidate 'next' SNP VMSA GPA even on failure (Sean Christopherson)
- KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates (Sean Christopherson)
- KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa (Sean Christopherson)
- net: advertise TCP MSS from the configured MTU, not the learned PMTU (Jiayuan Chen)
- crypto: virtio - bound the akcipher result length (Bryam Vargas) [Orabug: 39982162] {CVE-2026-80836}
- crypto: virtio - Drop superfluous [as]kcipher_req pointer (Lukas Wunner)
- crypto: virtio - Drop superfluous [as]kcipher_ctx pointer (Lukas Wunner)
- crypto: virtio - Drop sign/verify operations (Lukas Wunner)
- vlan: fix skb_under_panic and races when toggling HW VLAN offload (Eric Dumazet) [Orabug: 40013132] {CVE-2026-80925}
- net/packet: defer vmalloc TX_RING free until skbs finish (Kyle Zeng) [Orabug: 39982175] {CVE-2026-80841}
- tcp: clamp route advmss to TCP_MIN_MSS (Yong Wang) [Orabug: 39982195] {CVE-2026-80847}
- ipv4: use dst4_mtu() instead of dst_mtu() (Eric Dumazet)
- ipv6: use dst6_mtu() instead of dst_mtu() (Eric Dumazet)
- inet: add dst4_mtu() and dst6_mtu() helpers (Eric Dumazet)
- ipv6: add some unlikely()/likely() clauses in ip6_output.c (Eric Dumazet)
- ipv6: pass proto by value to ipv6_push_nfrag_opts() and ipv6_push_frag_opts() (Eric Dumazet)
- KVM: SEV: Add an anonymous 'psc' struct to track current PSC metadata (Sean Christopherson)
- KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (Sean Christopherson)
- KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y (Sean Christopherson)
- fuse: fix race between interrupt and resend (Miklos Szeredi) [Orabug: 39982400] {CVE-2026-80860}
- usb: xhci: bail out of setup if the controller is inaccessible (Breno Leitao) [Orabug: 39982230] {CVE-2026-80861}
- usb: xhci: simplify handling of Structural Parameters 1 values (Niklas Neronin)
- usb: xhci: use cached HCSPARAMS1 value (Niklas Neronin)
- usb: xhci: add USB Port Register Set struct (Niklas Neronin)
- netfilter: nft_set_pipapo_avx2: add missing vzeroupper (Eric Biggers)
- bpf: fix the return value of push_stack (Anton Protopopov)
- xfs: initialise args->total for parent pointer updates (Javier Tia) [Orabug: 40078705] {CVE-2026-97551}
- fou: Fix use-after-free in fou_create() (Luoxuanqiang) [Orabug: 39886929] {CVE-2026-74496}
- net: appletalk: fix NULL pointer dereference in aarp_send_ddp() (Weiming Shi)
- i2c: smbus: reject oversized block transfers in the common path (Weiming Shi) [Orabug: 40073050] {CVE-2026-93287}
- ALSA: us122l: Prevent write upgrades for read mappings (Kazuki Hanai) [Orabug: 40079109] {CVE-2026-97931}
- net: usb: pegasus: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078670] {CVE-2026-97540}
- media: as102: do not rely on id table address comparison (Gary Guo)
- usb: serial: spcp8x5: don't store usb_device_id (Gary Guo)
- usb: usbtmc: don't store usb_device_id (Gary Guo)
- wifi: ath9k_htc: don't store usb_device_id (Gary Guo) [Orabug: 40078677] {CVE-2026-97541}
- usb: xusbatm: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078663] {CVE-2026-97539}
- xdrgen: Fix union declarations (Chuck Lever)
- perf evsel: Add per-thread warning for EOPNOTSUPP open failues (Ian Rogers)
- Revert 'perf tests: Fix flakiness in BPF counters test on hybrid systems' (Sasha Levin)
- Revert 'slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL' (Sasha Levin)
- Revert 'selftests/mm: report unique test names for each cow test' (Sasha Levin)
- Revert 'selftests/mm: skip COW tmpfile cases when fallocate() is unsupported' (Sasha Levin)
- Revert 'selftests: harness: Mark test fixture objects __maybe_unused' (Sasha Levin)
- Revert 'nvme: apple: Add Apple A11 support' (Sasha Levin)
- Revert 'nvme-apple: Drop the PRP null check chicken bit' (Sasha Levin)
- Revert 'nvme-apple: Prevent shared tags across queues on Apple A11' (Sasha Levin)
- Revert 'nvme-apple: Reset q->sq_tail during queue init' (Sasha Levin)
- Revert 'arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries' (Sasha Levin)
- Revert 'arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries' (Sasha Levin)
- iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized (Nicolin Chen)
- crypto: ccp - Fix possible deadlock in SEV init failure path (Atish Patra)
- smb: client: fix UBSAN array-index-out-of-bounds in smb2_copychunk_range (Henrique Carvalho)
- xfs: actually recover intended file sizes in xfs_xmi_item_recover_intent (Darrick J. Wong)
- xfs: advance the findparent inode scan cursor while holding ILOCK (Darrick J. Wong)
- xfs: bail out on bitmap errors in xrep_agfl_fill (Darrick J. Wong) [Orabug: 40078682] {CVE-2026-97542}
- xfs: compute dquot checksum after resetting dd_lsn in repair (Darrick J. Wong)
- xfs: count escaped corruption errors in scrub stats (Darrick J. Wong)
- xfs: destroy seen inode bitmap when we fail to add a dirpath (Darrick J. Wong) [Orabug: 40078684] {CVE-2026-97543}
- xfs: don't leak dqacct if rhashtable insertion fails (Darrick J. Wong) [Orabug: 40078687] {CVE-2026-97544}
- xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails (Darrick J. Wong) [Orabug: 40078689] {CVE-2026-97545}
- xfs: don't modify file attributes or poke fsnotify for dry runs (Darrick J. Wong)
- xfs: don't spin forever on zero-length dirents when salvaging them (Darrick J. Wong) [Orabug: 40078692] {CVE-2026-97546}
- xfs: fix backwards skipping logic in xrep_quota_block (Darrick J. Wong)
- xfs: fix bnobt repair space reservation disposal failure (Darrick J. Wong)
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lin Jiapeng) [Orabug: 39972815,40078696] {CVE-2026-80530,CVE-2026-97547}
- xfs: fix name string recording in slowpath pptr tracepoints (Darrick J. Wong)
- xfs: fix replaying dirent removals into the temporary directory (Darrick J. Wong)
- xfs: initialise error in xfs_defer_finish_one() (Javier Tia) [Orabug: 40078708] {CVE-2026-97552}
- xfs: log the tempip after we convert it to extents format (Darrick J. Wong)
- xfs: preserve owner on in-memory btree creation (Darrick J. Wong)
- xfs: report nonexistent parents as a filesystem corruption (Darrick J. Wong)
- xfs: reset parent pointer args before each dir tree unlink repair (Darrick J. Wong)
- xfs: signal inode btree xref error if get_rec returns an error (Darrick J. Wong)
- xfs: snapshot old AGFL before rewriting it (Darrick J. Wong)
- xfs: snapshot scrub stats when rendering them (Darrick J. Wong)
- xfs: truncate quota file correctly when repairing quota file (Darrick J. Wong)
- smb: client: fix heap overflow in DACL owner/group rewrite (Bjoern Doebel) [Orabug: 40078720] {CVE-2026-97555}
- smb: client: avoid leaking refcount when cifs_sb_tlink() fails (Bjoern Doebel) [Orabug: 40078724] {CVE-2026-97556}
- smb: client: avoid leaking refcount in cifs_queue_oplock_break() (Bjoern Doebel) [Orabug: 40078730] {CVE-2026-97557}
- smb: client: fix file type corruption in wsl_to_fattr() (Paulo Alcantara)
- smb: client: fix file type corruption in cifs_reparse_point_to_fattr() (Paulo Alcantara)
- smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (Paulo Alcantara) [Orabug: 40078747] {CVE-2026-97560}
- smb: client: pin DFS superblock in iterator callback (Karl Mehltretter) [Orabug: 40078757] {CVE-2026-97562}
- smb: client: reject userspace cifs.idmap descriptions (Aohan Mei) [Orabug: 40078772] {CVE-2026-97564}
- selftests: mptcp: fix an UAF in mptcp_connect.c (Gang Yan)
- mptcp: syncookies: remember the request backup flag (Matthieu Baerts) [Orabug: 40078794] {CVE-2026-97568}
- mptcp: subflow: no need to copy thmac during ulp_clone (Matthieu Baerts)
- mptcp: options: handle MPC data + csum reqd + no csum (Matthieu Baerts)
- bnxt_en: Propagate RX ring init failures in bnxt_init_nic() (Joe Damato) [Orabug: 40078806] {CVE-2026-97572}
- bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() (Joe Damato) [Orabug: 40078811] {CVE-2026-97573}
- bnxt_en: bring back rtnl_lock() in the bnxt_open() path (Michael Chan)
- bnxt_en: Only restore LRO if the device supports TPA (Joe Damato)
- media: v4l2-ctrls: validate AV1 tile counts (Michael Bommarito) [Orabug: 40078824] {CVE-2026-97575}
- media: v4l2-ctrls: validate HEVC tile counts (Michael Bommarito) [Orabug: 40078826] {CVE-2026-97576}
- media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity (Michael Bommarito)
- media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer (Michael Bommarito)
- media: v4l2-h264: Fix memcmp() size in B1 reference list comparison (Xu Wang)
- media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity (Michael Bommarito)
- media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity (Michael Bommarito)
- media: hevc: add bounded tile-count helpers (Michael Bommarito)
- hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS (Vishnu Razdan)
- hwmon: (gpio-fan) Fix use-after-free in alarm work (Fan Wu)
- hwmon: (chipcap2) fix channels in humidity alarm notifications (Javier Carrasco)
- hwmon: (applesmc) fix key backlight workqueue leak on register failure (Cong Nguyen)
- afs: Clear stale peer app data after address list changes (Chengfeng Ye) [Orabug: 40078852] {CVE-2026-97583}
- afs: Fix incorrect free in candidate cleanup in afs_lookup_server() (David Howells) [Orabug: 40078858] {CVE-2026-97584}
- perf: RISC-V: use BIT_ULL for u64 overflow masks (Xixin Liu)
- perf: RISC-V: store available counter mask as bitmap (Xixin Liu)
- s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm (Harald Freudenberger)
- s390/crypto: Fix use of mutex in atomic context (Harald Freudenberger)
- s390/crypto: Fix skcipher_walk return code handling in aes_s390 (Harald Freudenberger)
- s390/qeth: allow bridgeport queries despite OS_MISMATCH (Nagamani Pv)
- KVM: PPC: Book3S HV: Set irqfd->producer only on success (Leixiang)
- mac802154: fix use-after-free of sdata via queued RX frames (Ibrahim Hashimov) [Orabug: 40078888] {CVE-2026-97595}
- ipvs: reject invalid states in connection template sync records (Kyle Zeng) [Orabug: 40078891] {CVE-2026-97596}
- ipv4: fib: bound automatic table ID allocation (Zihan Xi) [Orabug: 40078901] {CVE-2026-97598}
- ieee802154: hwsim: serialize pib updates to fix double-free (David Carlier)
- ieee802154: cc2520: fix FIFOP work use-after-free (Fan Wu) [Orabug: 40078912] {CVE-2026-97600}
- ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (Zhiling Zou) [Orabug: 40078919] {CVE-2026-97601}
- inet: frags: invalidate queues before flushing them (Yilin Zhang) [Orabug: 40078925] {CVE-2026-97602}
- fbdev: vfb: defer cleanup until the last reference (Weiming Shi) [Orabug: 40078939] {CVE-2026-97604}
- erofs: preserve LZMA decoders on resize failure (Nikhil Gurudasani) [Orabug: 40078947] {CVE-2026-97605}
- fs: autofs: fix memory leak in autofs_fill_super() (Jeffin Philip) [Orabug: 40078951] {CVE-2026-97606}
- scripts/sorttable: Mark long_size as __maybe_unused (Nathan Chancellor)
- vdpa: solidrun: Free IRQs after request failure (Xiongweimin)
- vdpa: ifcvf: Put device on unsupported feature error (Xiongweimin) [Orabug: 40078955] {CVE-2026-97607}
- netfilter: report NLM_F_DUMP_FILTERED when all is filtered out (Ilya Maximets)
- netfilter: nf_log: unregister loggers before per-net teardown (Chengfeng Ye) [Orabug: 40078958] {CVE-2026-97608}
- net: openvswitch: fix use-after-free of the flow table mask array (Norbert Szetei) [Orabug: 40078968] {CVE-2026-97611}
- net: mpls: clear inner_protocol when the last label is popped (Fourie Zhang) [Orabug: 40078972] {CVE-2026-97612}
- net: mana: Reserve extra CQ slot for the fence completion CQE (Sahil Chandna) [Orabug: 40078976] {CVE-2026-97613}
- net: hso: fix TIOCMIWAIT race (Johan Hovold)
- net/sched: act_api: release all action references on NEWACTION failure (Luoxuanqiang) [Orabug: 40078985] {CVE-2026-97616}
- ring-buffer: Check resize_disabled before publishing the new subbuf order (David Carlier) [Orabug: 40078989] {CVE-2026-97617}
- ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters() (Sebastian Andrzej Siewior)
- io_uring/net: let io_recv_buf_select return the length of the buffer region (Gabriel Krisman Bertazi)
- drm/i915: Fix memory leak in query_perf_config_list() (Thorsten Blum) [Orabug: 40079005] {CVE-2026-97899}
- drm/drm_exec: fix up contended obj when num_objects is 0 (Sunil Khatri) [Orabug: 40079009] {CVE-2026-97900}
- fs: don't return -EINVAL for successful nested thaw (Moritz Tanner) [Orabug: 40079015] {CVE-2026-97902}
- exec: do_close_on_exec() before taking exec_update_lock (Jann Horn)
- cpufreq: initialize policy rwsem before sysfs publication (Runyu Xiao) [Orabug: 40079019] {CVE-2026-97904}
- cpufreq: zero-initialize policy cpumask before sysfs publication (Zhongqiu Han) [Orabug: 40079023] {CVE-2026-97905}
- Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (Rongrong) [Orabug: 40079032] {CVE-2026-97907}
- Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev (Xu Rao)
- ASoC: sti: initialize IRQ lock before requesting IRQ (Runyu Xiao)
- ASoC: sprd: validate compress buffer sizes against fixed allocations (Tianchu Chen)
- accel/ivpu: Limit firmware log name prints to field size (Dawid Osuchowski)
- accel/ivpu: Validate firmware log buffer metadata (Magdalena Schulfer)
- accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (Magdalena Schulfer) [Orabug: 40079055] {CVE-2026-97917}
- tracing: Keep the entry count when the histogram stats allocation fails (Donggeun Yoo) [Orabug: 40079065] {CVE-2026-97920}
- tracing: Let histogram values keep the percent and graph modifiers (Donggeun Yoo)
- tracing: Free histogram the field rejected for a bad modifier (Donggeun Yoo) [Orabug: 40079067] {CVE-2026-97921}
- tracing: Free histogram var refs regardless of how often they are referenced (Donggeun Yoo) [Orabug: 40079069] {CVE-2026-97922}
- tracing: Free histogram the var ref when its initialization fails (Donggeun Yoo) [Orabug: 40079077] {CVE-2026-97923}
- tracing/user_events: Don't destroy fields when event removal fails (Henry Martin)
- tick/broadcast: Plug clockevents replacement race (Thomas Gleixner) [Orabug: 40079083] {CVE-2026-97925}
- tunnels: Drop stale dst when building an ICMP error for PMTUD (Ido Schimmel)
- ufs: validate cylinder group metadata before caching it (Ali Ahmet Memis)
- ufs: create the root dentry after loading cylinder metadata (Ali Ahmet Memis)
- watchdog: sunxi_wdt: preserve boot-enabled watchdog (James Hilliard)
- dm/amdgpu: fix malformed link_settings debugfs output (Harry Wentland)
- ALSA: usbusx2y: validate URB actual_length in interrupt callback (Tristan Madani) [Orabug: 40079099] {CVE-2026-97929}
- ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (Tristan Madani) [Orabug: 40079104] {CVE-2026-97930}
- ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough (Roman Prucha)
- rust: allow unknown_lints in generated bindings for Rust < 1.88 (Miguel Ojeda)
- tracing: Fix memory corruption from the histogram stacktrace modifier (Donggeun Yoo) [Orabug: 40079129] {CVE-2026-97936}
- ipv6: fix fib6 walker UAF on seq stop (Zihan Xi) [Orabug: 40079142] {CVE-2026-97940}
- x86/mm: Fix user-space data loss with MADV_FREE and THP (Vernon Yang) [Orabug: 40079153] {CVE-2026-97945}
- crypto: x86/aria - add missing vzeroupper in AVX-512 code (Eric Biggers)
- crypto: x86/aria - add missing vzeroupper in AVX2 code (Eric Biggers)
- powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver (Shivaprasad G Bhat)
- powerpc/ps3: Fix repository.c build failure (Thorsten Blum)
- ksmbd: prevent out-of-bounds reads in share config responses (Namjae Jeon)
- scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands (Maurizio Lombardi) [Orabug: 40079174] {CVE-2026-97951}
- scripts/mksysmap: fix escape of '$' in the __pi_ pattern (Lorenzo Stoakes)
- sunvdc: unmap LDC cookies when the descriptor send fails (Stian Halseth)
- openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() (Eelco Chaudron)
- net: hsr: enable promiscuous mode on interlink port with fwd offload (Md Danish Anwar)
- net: stmmac: fix TX descriptor availability check for TSO traffic (Lorenzo Bianconi) [Orabug: 40079183] {CVE-2026-97953}
- net: stmmac: add TSO check for header length (Russell King)
- net: stmmac: add stmmac_tso_header_size() (Russell King)
- net: stmmac: fix TSO support when some channels have TBS available (Russell King)
- net: stmmac: TSO: Simplify the code flow of DMA descriptor allocations (Furong Xu)
- octeontx2-af: fix PF/CGX debugfs PCI bus lookup (Ratheesh Kannoth)
- net: phy: mediatek-ge: disable EEE on the MT7530 PHY (Vladislav Karmanov)
- net: phy: add phy_disable_eee (Heiner Kallweit)
- net: phy: mediatek: Re-organize MediaTek ethernet phy drivers (Sky Huang)
- cxgb4: clip_tbl: Fix spelling mistake 'wont' -> 'won't' (Colin Ian King)
- net: hinic: fix mailbox segment buffer overflow (Aamir Ahmed) [Orabug: 40079196] {CVE-2026-97957}
- net: sun4i-emac: fix missing of_node_put() for phy_node (Liyouhong)
- net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). (Kuniyuki Iwashima) [Orabug: 40079199] {CVE-2026-97958}
- net/sched: cls_route: Fix in-place replace (Victor Nogueira)
- net/sched: cls_route: Reject handle aliasing (Victor Nogueira)
- net/sched: cls_route: free emptied bucket on filter move (Victor Nogueira) [Orabug: 40079204] {CVE-2026-97959}
- perf/x86/intel: Correct pt_regs->flags update for PEBS path (Dapeng Mi)
- perf/x86/intel/ds: Factor out PEBS group processing code to functions (Dapeng Mi)
- perf/x86/intel/ds: Remove redundant assignments to sample.period (Changbin Du)
- perf/x86/intel/ds: Clarify adaptive PEBS processing (Kan Liang)
- perf/core: Check sample_type in perf_sample_save_callchain (Yabin Cui)
- selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value (Thibault Ferrante)
- net: stmmac: initialize ptp_lock at probe time (Lorenzo Bianconi) [Orabug: 40079216] {CVE-2026-97963}
- ppp_synctty: ensure a writeable skb header (Qingfang Deng) [Orabug: 40079219] {CVE-2026-97964}
- vxlan: initialize _md in vxlan_xmit_one() (Eric Dumazet) [Orabug: 40079222] {CVE-2026-97965}
- octeontx2-pf: reset HTB scheduler topology before freeing queues (Ratheesh Kannoth)
- hwmon: (corsair-cpro) Remove debugfs entries when probe fails (Linmao Li)
- hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors (Pengpeng Hou)
- hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() (Cong Nguyen)
- hwmon: (corsair-cpro) Create debugfs entries after hwmon registration (Linmao Li)
- net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down (Marek Vasut)
- net/micrel: Fix typos in micrel driver code comments (Yicong Hui)
- net: dsa: lantiq_gswip: fix GSWIP_MDIO_PHY_FCONTX_EN value (Jan Havran)
- net: dsa: lantiq_gswip: move definitions to header (Daniel Golle)
- net: dsa: lantiq_gswip: prepare for more CPU port options (Daniel Golle)
- net: dsa: lantiq_gswip: deduplicate dsa_switch_ops (Daniel Golle)
- watchdog: msc313e: Sync timeout value if WDT was running at boot (Tzung-Bi Shih)
- watchdog: msc313e: Fix undefined behavior (Tzung-Bi Shih)
- watchdog: msc313e: Fix spurious reset on suspend (Tzung-Bi Shih)
- watchdog: msc313e: Enable clock before accessing hardware registers (Tzung-Bi Shih)
- watchdog: msc313e: Fix clock leak and spurious timer in settimeout() (Tzung-Bi Shih)
- watchdog: msc313e: Avoid division by zero (Tzung-Bi Shih)
- watchdog: fix hrtimer start when pretimeout is zero (David Arcari)
- mptcp: remove unneeded READ_ONCE() annotation (Paolo Abeni)
- net: macb: destroy the phylink instance on the probe error path (Nicolai Buchwitz) [Orabug: 40079249] {CVE-2026-97973}
- Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset (Jiajia Liu)
- Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset (Jiajia Liu)
- Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware (Ivan Hu)
- Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one (Kiran K)
- Bluetooth: btintel_pcie: validate packet_len before skb_put_data (Kiran K) [Orabug: 40079258] {CVE-2026-97976}
- Bluetooth: btusb: Fix UAF of btusb_data by rx_work (Luiz Augusto von Dentz) [Orabug: 40079261] {CVE-2026-97977}
- eth: ice: don't dereference pointers from TP_printk() (Jakub Kicinski) [Orabug: 40079263] {CVE-2026-97978}
- ice: add missing xa_destroy for sched_node_ids (Jacob Keller) [Orabug: 40079266] {CVE-2026-97979}
- idpf: account for VLAN header when parsing RSC packet header (Joshua Hay)
- ALSA: hda: Report a change when only the channel status bytes move (Hyeongjun An)
- ALSA: hda/common: Use guard() for mutex locks (Takashi Iwai)
- ALSA: hda/common: Use cleanup macros for PM controls (Takashi Iwai)
- ALSA: hda: Introduce auto cleanup macros for PM (Takashi Iwai)
- drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER (Karl Mehltretter)
- net: ethernet: cortina: Count RX descriptors for freeq refill (Linus Walleij)
- net: ethernet: cortina: Count RX drops once per frame (Linus Walleij)
- net: ethernet: cortina: No mapping is a dropped rx (Linus Walleij)
- net: ethernet: cortina: Count dropped frames as NAPI work (Linus Walleij)
- net: ethernet: cortina: Finish RX updates before NAPI completion (Linus Walleij)
- net: ethernet: cortina: Fix budget accounting (Linus Walleij)
- net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward (Alice Mikityanska)
- net: ipv6: Fix UDP length overflow with PMTU discover and big MTU (Alice Mikityanska) [Orabug: 40079279] {CVE-2026-97984}
- af_unix: Return immediately when manage_oob() returns NULL for 0-length buffer. (Kuniyuki Iwashima)
- af_unix: Update last skb marker in manage_oob(). (Kuniyuki Iwashima) [Orabug: 40079300] {CVE-2026-97985}
- virtio_input: stop callbacks before unregistering input device (Karl Mehltretter) [Orabug: 40079307] {CVE-2026-97986}
- virtio_input: reset device if input_register_device() fails (Xiongweimin) [Orabug: 40079311] {CVE-2026-97987}
- virtio-pci: return IRQ_HANDLED after non-zero ISR (Andrew Stellman)
- vdpa_sim_net: check TX pull result before RX copy (Linfeng Sun) [Orabug: 40079323] {CVE-2026-97990}
- vdpa_sim_blk: reject out-of-range sector starts (Linfeng Sun) [Orabug: 40079328] {CVE-2026-97991}
- vhost-vdpa: protect config_ctx from being freed under the config callback (Yu Zhang) [Orabug: 40079332] {CVE-2026-97992}
- vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx (Yu Zhang) [Orabug: 40079336] {CVE-2026-97993}
- vhost/vdpa: reject VRING_NUM larger than device max (Jia Jia) [Orabug: 40079341] {CVE-2026-97994}
- virtio_console: do not free control-out buffers on remove (Jia Jia) [Orabug: 40079347] {CVE-2026-97995}
- virtio: fix use-after-free in unregister_virtio_device() (Karl Mehltretter) [Orabug: 40079351] {CVE-2026-97996}
- ASoC: mt6351: Publish the OF module alias (Hpp Iscas)
- netfilter: ip6_tables: set F_PROTO when proto value is nonzero (Florian Westphal)
- netfilter: nfnetlink_log: cope with concurrent instance destruction (Florian Westphal) [Orabug: 40079359] {CVE-2026-97998}
- ASoC: Intel: SST: Publish the PCI module aliases (Hpp Iscas)
- ASoC: bcm: bcm63xx: Publish the OF module aliases (Hpp Iscas)
- hwmon: (ina2xx) Parameterize ina2xx_data in ina226_alert_read() (Jared Kangas)
- hwmon: Introduce 64-bit energy attribute support (Guenter Roeck)
- libnvdimm: Replace namespace_match() with device_find_child_by_name() (Zijun Hu)
- hwmon: (ltc4282) Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (Edward Adam Davis) [Orabug: 40079373] {CVE-2026-98006}
- bpf: Reject non-scalar bpf_loop iteration counts (Kumar Kartikeya Dwivedi) [Orabug: 40079377] {CVE-2026-98007}
- net: macb: fix NULL pointer dereference on unbind with fixed-link (Vineeth Karumanchi) [Orabug: 40079379] {CVE-2026-98008}
- net: macb: rename bp->sgmii_phy field to bp->phy (Theo Lebrun)
- net/sched: ets: clamp quantum in parse and fallback paths (Jamal Hadi Salim) [Orabug: 40079383] {CVE-2026-98009}
- net/sched: drr: clamp quantum in change class (Jamal Hadi Salim) [Orabug: 40079387] {CVE-2026-98010}
- net/sched: pie: clamp psched_mtu in pie_drop_early (Jamal Hadi Salim)
- net/sched: hhf: clamp quantum in change and init paths (Jamal Hadi Salim) [Orabug: 40079394] {CVE-2026-98011}
- net/sched: sfq: clamp quantum in change path (Jamal Hadi Salim) [Orabug: 40079398] {CVE-2026-98012}
- net/sched: fq_pie: clamp quantum in change path (Jamal Hadi Salim)
- net/mlx5: E-Switch, prevent mc_list repopulation during vport disable (Lama Kayal) [Orabug: 40079405] {CVE-2026-98014}
- net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put (Yael Chemla) [Orabug: 40079408] {CVE-2026-98015}
- net/mlx5e: Fix use-after-free race in sample_restore_put() (Carolina Jubran) [Orabug: 40079415] {CVE-2026-98016}
- net/mlx5e: Fix ETS zero BW reporting when one TC holds 100% (Carolina Jubran)
- net/mlx5e: Fix setting RS FEC after remapping (Shahar Shitrit)
- net/sched: defer qdisc freeing after failed creation (Weiming Shi) [Orabug: 40079419] {CVE-2026-98017}
- net: mctp: i3c: serialize probe with bus removal (Xingwang Xiang)
- powerpc/kexec_file: Use inclusive range checks in add_usable_mem() (Thorsten Blum)
- pds_core: don't release PCI regions for VFs on reset (Nikhil P. Rao)
- pds_core: fix cmd_regs access racing BAR unmap on reset (Nikhil P. Rao) [Orabug: 40079430] {CVE-2026-98020}
- net: reject oversized tx_queue_len at netlink parse time (Jamal Hadi Salim) [Orabug: 40079434] {CVE-2026-98021}
- net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations (Jamal Hadi Salim) [Orabug: 40079442] {CVE-2026-98022}
- vxlan: reject dynamic fdb entries that reference a nexthop id (Seungwon Bae) [Orabug: 40079446] {CVE-2026-98023}
- s390/ism: folio_put() after error (Alexandra Winter)
- net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (Jason Winter) [Orabug: 40079453] {CVE-2026-98025}
- ionic: use netif_txq_maybe_stop() in ionic_tx() (Nikhil P. Rao)
- octeontx2-af: mcs: Clear stale X2P calibration state before calibration (Viswajith Murali)
- net: bridge: mcast: properly convert mglist to rcu (Nikolay Aleksandrov) [Orabug: 40079458] {CVE-2026-98026}
- net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079463] {CVE-2026-98027}
- eth: nfp: drop the replaced rule from the list when reprogramming fails (Jakub Kicinski) [Orabug: 40079467] {CVE-2026-98028}
- eth: nfp: bound the ntuple rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079470] {CVE-2026-98029}
- eth: nfp: migrate to new RXFH callbacks (Jakub Kicinski)
- net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079473] {CVE-2026-98030}
- bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit() (Eric Dumazet)
- nexthop: Initialize extack in remove_nh_grp_entry() (Ido Schimmel) [Orabug: 40079482] {CVE-2026-98031}
- selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0 (Jiayuan Chen)
- bpf: Reject untrusted allocated-object pointers (Ning Ding) [Orabug: 40079500] {CVE-2026-98037}
- bpf: Require MEM_PERCPU for percpu kptr stores (Kumar Kartikeya Dwivedi) [Orabug: 40079506] {CVE-2026-98039}
- thermal: sysfs: switch to use scnprintf() to suppress truncation warning (Andy Shevchenko)
- bpf: Don't predict JMP32 pointer vs zero comparisons (Eduard Zingerman) [Orabug: 40079510] {CVE-2026-98041}
- bpf: Mark faultable stack helpers as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079520] {CVE-2026-98045}
- bpf: Mark bpf_btf_find_by_name_kind() as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079522] {CVE-2026-98046}
- net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times (Justin Chen) [Orabug: 40079537] {CVE-2026-98051}
- net: bcmasp: clear txcb->last before writing each descriptor (Justin Chen) [Orabug: 40079541] {CVE-2026-98052}
- ASoC: Intel: avs: Fix unbalanced module reference count (Cezary Rojewski) [Orabug: 40079546] {CVE-2026-98054}
- ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology (Cezary Rojewski)
- ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (Cezary Rojewski) [Orabug: 40079548] {CVE-2026-98055}
- nvme-tcp: defer TLS inline send to io_work (Xixin Liu)
- nvme-tcp: open-code nvme_tcp_queue_request() for R2T (Hannes Reinecke)
- nvme: remove stale namespaces by NSID range during scan (Mohamed Khalfella) [Orabug: 40079550] {CVE-2026-98056}
- ring-buffer: Add checking nr_subbufs to persistent ring buffer validation (Steven Rostedt) [Orabug: 40079555] {CVE-2026-98057}
- bpf: Mark sched_process_wait argument as nullable (Kumar Kartikeya Dwivedi) [Orabug: 40079562] {CVE-2026-98059}
- bpf: Fix NULL-ptr-deref in btf_var_show() (Jiayuan Chen) [Orabug: 40079569] {CVE-2026-98063}
- bpf: Fix NULL-ptr-deref when showing a void BTF type (Jiayuan Chen) [Orabug: 40079572] {CVE-2026-98064}
- ALSA: caiaq: Fix potential double-free at error path (Takashi Iwai) [Orabug: 40079576] {CVE-2026-98066}
- selftests/alsa: Fix the step check for INTEGER controls (Hyeongjun An)
- arm64: trans_pgd: clone only the linear map that exists at runtime (Breno Leitao)
- net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list() (Hw He)
- net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset (Lorenzo Bianconi)
- bonding: do not clear curr_active_slave prematurely when releasing all slaves (Eric Dumazet) [Orabug: 40079606] {CVE-2026-98074}
- bpf: reject BPF_PSEUDO_FUNC reference to the main program (Eduard Zingerman) [Orabug: 40079610] {CVE-2026-98075}
- tracing/probes: Fix use-after-free on field name/type of events with multiple probes (Henry Martin) [Orabug: 40079616] {CVE-2026-98076}
- netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() (Joas Antonio Dos Santos) [Orabug: 40079621] {CVE-2026-98077}
- ipvs: fix reversed sequence option serialization (Kyle Zeng) [Orabug: 40079625] {CVE-2026-98078}
- btrfs: do not force reloc root creation during qgroup_account_snapshot() (Qu Wenruo) [Orabug: 40079634] {CVE-2026-98080}
- btrfs: send: fix lost error return value in will_overwrite_ref() (Avi Weiss)
- btrfs: zoned: finish active block group cleanup if call_zone_finish() fails (Johannes Thumshirn) [Orabug: 40079639] {CVE-2026-98081}
- btrfs: return proper negative error code for update_raid_extent_item() (Qu Wenruo)
- btrfs: fix the possible bioc_list memory leak during error (Qu Wenruo) [Orabug: 40079643] {CVE-2026-98082}
- btrfs: fix transaction use-after-free in raid stripe insertion (Shuangpeng Bai) [Orabug: 40079647] {CVE-2026-98083}
- ASoC: ux500: Program the MSP FIFO watermarks (Linus Walleij)
- ASoC: ux500: Allow repeated MSP prepare calls (Linus Walleij)
- ASoC: ux500: Remove obsolete PRCMU QoS calls (Linus Walleij)
- ASoC: ux500: Request the MSP MMIO resource (Linus Walleij)
- ASoC: ux500: Deassert the MSP reset during probe (Linus Walleij)
- mfd: db8500-prcmu: Fold dbx500 header into db8500 (Linus Walleij)
- arm: Handle KCOV __init vs inline mismatches (Kees Cook)
- mfd: db8500-prcmu: Remove needless return in three void APIs (Zijun Hu)
- ASoC: ux500: Validate MSP DAI configuration (Linus Walleij)
- ASoC: ux500: Correct MSP frame and bit clock setup (Linus Walleij)
- ASoC: ux500: Propagate MSP setup errors (Linus Walleij)
- ASoC: ux500: Fix MSP stream lifecycle handling (Linus Walleij)
- printk/nbcon: Change nbcon_irq_work to IRQ_WORK_LAZY (John Ogness)
- ALSA: ump: do not touch legacy_rmidi before it exists (Qingyu Zhang) [Orabug: 40079657] {CVE-2026-98086}
- ALSA: ump: Update rawmidi name per EP name update (Takashi Iwai)
- ALSA: ump: Copy safe string name to rawmidi (Takashi Iwai)
- ALSA: ump: Copy FB name string more safely (Takashi Iwai)
- ALSA: rawmidi: Show substream activity in info ioctl (Takashi Iwai)
- ALSA: rawmidi: Expose the tied device number in info ioctl (Takashi Iwai)
- locking/lockdep: Invalidate stale class_cache entries for zapped classes (Eric Dumazet)
- perf/core: Skip empty AUX records with only format flags (Leo Yan)
- scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() (Ivy Lopez) [Orabug: 40079664] {CVE-2026-98088}
- perf: RISC-V: check cpu_hw_evt before dereference in overflow IRQ (Xixin Liu)
- bonding: alb: fix uninitialized transport header access in alb_determine_nd() (Eric Dumazet) [Orabug: 40079670] {CVE-2026-98089}
- btrfs: restore active device pointers after failed sprout (Guanghui Yang) [Orabug: 40079672] {CVE-2026-98090}
- btrfs: detach failed sprout device from transaction update list (Guanghui Yang) [Orabug: 40079676] {CVE-2026-98091}
- drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() (Lu Yao)
- ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (Wangdicheng) [Orabug: 40079682] {CVE-2026-98092}
- ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits (Wangdicheng)
- s390/boot: Fix physical memory search range (Vasily Gorbik)
- ALSA: hda: restore MFG widget enumeration after core split (Xu Rao)
- ALSA: hda/core: Use guard() for mutex locks (Takashi Iwai)
- staging: fbtft: make dirty_lock IRQ-safe (Sh_Def)
- af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). (Kuniyuki Iwashima) [Orabug: 40079695] {CVE-2026-98095}
- ipv6: sr: restore network header before routing and forwarding (Eric Dumazet) [Orabug: 40079699] {CVE-2026-98096}
- tipc: Dont send random pad bytes in RESET/ACTIVATE messages (David Laight) [Orabug: 40079706] {CVE-2026-98097}
- tipc: fix NULL deref in tipc_named_node_up() on empty publication list (Tung Nguyen) [Orabug: 40079713] {CVE-2026-98098}
- ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit (Eric Dumazet)
- ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() (Eric Dumazet) [Orabug: 40079730] {CVE-2026-98102}
- ppp: ppp_synctty: simplify tty disc_data access (Qingfang Deng)
- ppp: ppp_async: simplify tty disc_data access (Qingfang Deng)
- igmp: convert struct ip_sf_list to RCU (Eric Dumazet) [Orabug: 40079734] {CVE-2026-98103}
- net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted (Jamal Hadi Salim) [Orabug: 40079740] {CVE-2026-98104}
- net: ethernet: oa_tc6: Fix for the wrong data type (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Disable tx queues on fatal error (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Improve the error recovery (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Protect skb pointer used by two different kernel instances (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Add the OA_TC6_ prefix to standard registers (Ciprian Regus)
- net: ethernet: oa_tc6: Export standard defined registers (Ciprian Regus)
- net: ethernet: oa_tc6: Handle the OA TC6 SPI protected mode (Ciprian Regus)
- net: ethernet: oa_tc6: Interrupt is active low, level triggered. (Selvamani Rajagopal)
- ASoC: ab8500: Validate and program TDM slots correctly (Linus Walleij)
- ASoC: ab8500: Correct digital interface format setup (Linus Walleij)
- ASoC: ab8500: Repair the DAPM capture graph (Linus Walleij)
- ASoC: ab8500: Reset the audio block before configuring it (Linus Walleij)
- Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() (Gongwei Li)
- Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM (Pauli Virtanen)
- Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (Pauli Virtanen) [Orabug: 40079748] {CVE-2026-98107}
- Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (Pauli Virtanen) [Orabug: 40079753] {CVE-2026-98108}
- Bluetooth: hci_core: Fix race condition during device registration (Aleksandr Nogikh) [Orabug: 40079757] {CVE-2026-98109}
- Bluetooth: btintel: bound firmware ID by TLV length (Laxman Acharya Padhya) [Orabug: 40079759] {CVE-2026-98110}
- Bluetooth: btintel: validate version TLV value lengths (Laxman Acharya Padhya) [Orabug: 40079761] {CVE-2026-98111}
- workqueue: reject watchdog thresholds that overflow jiffies (Jiacheng Xu)
- workqueue: replace use of system_wq with system_percpu_wq (Marco Crivellari)
- Bluetooth: btintel_pcie: Clear automask on spurious interrupts (Kiran K)
- sched_ext: Fix timer pinning and return value in scx_central (Wanwu Li)
- s390/ipl: Fix NULL deref in dump_reipl without re-IPL parm block (Vasily Gorbik)
- s390/ipl: Fix NULL deref in kdump without re-IPL parm block (Vasily Gorbik)
- s390/time: Use jiffies instead of jiffies_64 (Heiko Carstens)
- s390/vtime: Use __this_cpu_read() / get rid of READ_ONCE() (Heiko Carstens)
- ksmbd: rate limit unmapped SID errors (Namjae Jeon)
- ksmbd: propagate DACL parsing errors (Namjae Jeon)
- ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (Yilin Zhang) [Orabug: 40079779] {CVE-2026-98116}
- OPP: of: Fix potential multiplication overflow when calculating freq (Colin Ian King)
- perf symbol: Do not use debug file as the binary type (Adrian Hunter)
- watchdog: msc313e: Fix NULL pointer dereference in PM callbacks (Tzung-Bi Shih)
- vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() (Baul Lee) [Orabug: 40079802] {CVE-2026-98122}
- net: amd-xgbe: discard rx packets with bad FCS (James Nugraha)
- raw: annotate disconnect-side IPv4 match writers (Luoxuanqiang)
- sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration (Henry Martin) [Orabug: 40079806] {CVE-2026-98123}
- smb: client: transport: Fix debug printing in __release_mid() (Andy Shevchenko)
- smb/client: fix integer truncation in collapse range (Huiwen He)
- smb/client: fix data corruption in emulated insert range (Huiwen He)
- smb: move copychunk definitions to common/smb2pdu.h (Zhangguodong)
- smb: client: batch SRV_COPYCHUNK entries to cut round trips (Henrique Carvalho)
- smb/client: mark file sparse before emulating insert range (Huiwen He)
- smb/client: validate new EOF for zero range (Huiwen He) [Orabug: 40079822] {CVE-2026-98126}
- smb/client: validate new EOF for insert range (Huiwen He) [Orabug: 40079827] {CVE-2026-98127}
- scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug: 40079831] {CVE-2026-98128}
- scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug: 40079837] {CVE-2026-98129}
- sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START (Xin Long) [Orabug: 40079843] {CVE-2026-98130}
- net/sched: act_api: fix skb sizing and action leak on reoffload delete (Victor Nogueira)
- net/sched: act_api: size the RTM_GETACTION reply from the actions (Victor Nogueira)
- net/sched: act_api: budget all shared attributes in notify skbs (Victor Nogueira)
- net: iptunnel: fix stale transport header during tunnel decapsulation (Dong Chenchen)
- tcp: use GFP_ATOMIC in tcp_send_active_reset() (Eric Dumazet)
- net: icmp: avoid invalid transport header access in icmp_send tracepoint (Eric Dumazet)
- drm/cirrus-qemu: Validate BAR0 size during probe (Slawomir Stepien) [Orabug: 40079874] {CVE-2026-98142}
- drm/cirrus: Use video aperture helpers (Thomas Zimmermann)
- ufs: do not treat unreadable directory blocks as empty (Ali Ahmet Memis)
- bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic (Jiayuan Chen) [Orabug: 40079901] {CVE-2026-98151}
- selftests/cgroup: Fix cg_run_in_subcgroups ignoring arg parameter (Hongfu Li)
- sched_ext: Fix nonexistent field in sched-ext.rst example (Liang Luo)
- nvmet-rdma: fix queue leak when connect backlog is exceeded (Xixin Liu) [Orabug: 40079902] {CVE-2026-98152}
- nvme-rdma: fix -EIO cleanup order in queue_rq (Xixin Liu) [Orabug: 40079913] {CVE-2026-98154}
- accel/qaic: Address potential out-of-bounds read in resp_worker() (Youssef Samir)
- drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() (Dan Carpenter)
- EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation (Jad Keskes) [Orabug: 40079927] {CVE-2026-98157}
- EDAC/igen6: Fix channel address decode for non-hash mode (Qiuxu Zhuo)
- EDAC/igen6: Fix channel selection hash (Qiuxu Zhuo)
- EDAC/igen6: Fix interleave boundary condition (Qiuxu Zhuo)
- RAS/AMD/ATL, EDAC/amd64: Only load ATL when needed (Yazen Ghannam)
- ARM: ensure interrupts are enabled in __do_user_fault() (Russell King)
- ARM: 9484/1: enable interrupts when unhandled user faults are triggered (Yuanbin Xie)
- mm/damon/core: avoid infinite kdamond_merge_regions() internal loop (Seongjae Park) [Orabug: 40033139] {CVE-2026-89796}
- Bluetooth: btrtl: Add the support for RTL8761CUV (Max Chou)
- af_unix: Unlink scc_entry in unix_del_edge(). (Kuniyuki Iwashima) [Orabug: 39972794] {CVE-2026-80521}
- l2tp: fix tunnel and session refcount leak on seq_file release (Eric Dumazet) [Orabug: 39972719] {CVE-2026-74735}
- ksmbd: use memcmp() to compare ClientGUIDs (Namjae Jeon)
- ASoC: meson: aiu: Validate written enum values (Hyeongjun An) [Orabug: 39886372] {CVE-2026-74294}
- ASoC: topology: Check PCM and DAI name strings before use (Cassio Gabriel) [Orabug: 39886361] {CVE-2026-74291}
- ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). (Kuniyuki Iwashima) [Orabug: 39886353] {CVE-2026-74289}
- bpf: Guard __get_user acesss with access_ok for uprobe_multi data (Jiri Olsa) [Orabug: 39886262] {CVE-2026-74258}
- RDMA/bnxt_re: Proper rollback if the ioremap fails (Selvin Xavier) [Orabug: 39886234] {CVE-2026-72496}
- coresight: platform: defer connection counter increment until alloc succeeds (Jie Gan)
- md/raid10: fix writes_pending and barrier reference leaks on discard failures (Abd-Alrhman Masalkhi) [Orabug: 39886086] {CVE-2026-72438}
- sctp: fix err_chunk memory leaks in INIT handling (Xin Long) [Orabug: 39886018] {CVE-2026-72413}
- bpf: Mask pseudo pointer values in verifier logs (Nuoqi Gui) [Orabug: 39885989] {CVE-2026-72402}
- Bluetooth: ISO: fix malformed ISO_END/CONT handling (Pauli Virtanen) [Orabug: 39885808] {CVE-2026-72334}
- bpf: Reject redirect helpers without a bpf_net_context (Daniel Borkmann) [Orabug: 39860076] {CVE-2026-68337}
- drm/vc4: hvs/v3d: Fix null dereference in unbind (Gregor Herburger) [Orabug: 39859967] {CVE-2026-68303}
- tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (Cen Zhang) [Orabug: 39859926] {CVE-2026-68289}
- net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (Yehyeong Lee) [Orabug: 39859921] {CVE-2026-68288}
- drop_monitor: fix size calculations for 64-bit attributes (Eric Dumazet) [Orabug: 39859917] {CVE-2026-68287}
- drop_monitor: perform u64_stats updates under IRQ-disabled section (Eric Dumazet) [Orabug: 39859913] {CVE-2026-68286}
- ppp_async: drop the errored frame instead of resetting its headroom (Vlatko Kosturjak) [Orabug: 40079934] {CVE-2026-98158}
- of: dynamic: Fix overlayed devices not probing because of fw_devlink (Saravana Kannan)
- driver core: Export get_dev_from_fwnode() (Ulf Hansson)
- drm/amd/display: clean-up dead code in dml2_mall_phantom (Brahmajit Das)
- wifi: mt76: mt7921: skip unknown CLC firmware records (Laxman Acharya Padhya)
- wifi: mt76: mt7921: validate CLC firmware records (Laxman Acharya Padhya) [Orabug: 40079939] {CVE-2026-98159}
- Revert 'ARM: 9481/2: breakpoint: CFI breakpoints only on demand' (Sasha Levin)
- Revert 'bpf, s390: Clear fetch destination on faulting arena atomic' (Sasha Levin)
- ksmbd: remove stale channels from all sessions on teardown (Gil Portnoy)
- bpftool: Strip all -Wformat* flags from bootstrap libbpf build (Andrii Nakryiko)
- firmware: stratix10-svc: fix FCS SMC call kernel-doc (Genevieve Chan)
- netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state (Florian Westphal) [Orabug: 40073059] {CVE-2026-93288}
- ASoC: amd: yc: Add DMI quirk for HyperX OMEN Gaming Laptop 16-ap1xxx (Lin Xianglin)
- scsi: core: Do not block on tag allocation in scsi_eh_lock_door() (Zizhi Wo) [Orabug: 40073071] {CVE-2026-93781}
- ASoC: rt5645: Perform the initial jack detect at probe (Rudi Heitbaum)
- spi: dw: fix wrong RX_SAMPLE_DLY setting after resume (Jisheng Zhang)
- ata: libata-core: Disable LPM on WDC WD141KFGX-68FH9N0 (Niklas Cassel)
- hwmon: (corsair-psu) Fix linear11 calculation (Guenter Roeck)
- vhost-scsi: flush backend after device ioctls (Jia Jia) [Orabug: 40073076] {CVE-2026-93782}
- ASoC: amd: yc: Add DMI quirk for HP Victus Laptop 16-e1xxx (Zhang Heng)
- Drivers: hv: vmbus: add VTL2 redirect connection ID (Hardik Garg)
- ata: libata-core: Disable LPM on WD Green 2.5 480GB (Niklas Cassel)
- ALSA: hda/realtek: Add mute LED quirk for HP Victus 16-e0xxx (MB 88ED) (Andre Pragosa)
- ata: libata-core: Disable LPM on some WD drives (Niklas Cassel)
- ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) (Robert Abrahamse)
- Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame (Jiale Yao) [Orabug: 40073080] {CVE-2026-93783}
- wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() (Deepanshu Kartikey) [Orabug: 40073087] {CVE-2026-93784}
- cifs: validate idmap key payload length (Li Qiang) [Orabug: 40073095] {CVE-2026-93785}
- powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (Vaibhav Jain)
- ice: pass the return value of skb_checksum_help() (Michal Swiatkowski)
- ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx (Madhavender Singh)
- ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4 (Markus Lindner)
- phonet: check register_netdevice_notifier() error in phonet_device_init() (Heminhong)
- drm/gma500: return errors from Oaktrail HDMI I2C reads (Pengpeng Hou)
- ksmbd: preserve VFS inherited POSIX ACL mask (Namjae Jeon)
- wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO (Ibrahim Hashimov)
- regulator: core: clamp voltage constraints before applying apply_uV (Kamal Wadhwa)
- smb: client: bound dirent name against end of SMB response in cifs_filldir (Jay Vadayath) [Orabug: 40073128] {CVE-2026-93787}
- wifi: mwifiex: replace one-element arrays with flexible array members (Georgi Valkov)
- ALSA: hda/realtek: Add HDA_CODEC_QUIRK for Samsung 750XBE/730XBE (Zhang Heng)
- wifi: iwlwifi: acpi: validate WGDS table revision index (Emmanuel Grumbach) [Orabug: 40073135] {CVE-2026-93788}
- ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless (Daniel C. Ribeiro)
- wifi: iwlwifi: bound aligned TLV advance in FW parser (Emmanuel Grumbach) [Orabug: 40073140] {CVE-2026-93789}
- ALSA: hda/realtek: Add quirk for HP Pavilion x360 (Takashi Iwai)
- drm/amd/pm/si: Don't schedule thermal work when queue isn't initialized (Timur Kristof)
- arm64: kprobes: Allow reentering kprobes while single-stepping (Pu Hu)
- wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif (Emmanuel Grumbach) [Orabug: 40073149] {CVE-2026-93790}
- wifi: iwlwifi: mvm: add a check on the tid coming from the firmware (Emmanuel Grumbach) [Orabug: 40073156] {CVE-2026-93791}
- arm64: fixmap: Allow 256K early_ioremap() at any offset (Yu Peng)
- wifi: iwlwifi: mvm: fix a possible underflow (Emmanuel Grumbach) [Orabug: 40073161] {CVE-2026-93792}
- wifi: iwlwifi: mvm: validate TX_CMD response layout (Emmanuel Grumbach) [Orabug: 40073170] {CVE-2026-93793}
- ASoC: Intel: sof_sdw: Add quirks for new Dell laptops (Charles Keepax)
- smb/client: flush dirty data before punching a hole (Huiwen He) [Orabug: 40073176] {CVE-2026-93794}
- blk-cgroup: fix leaks and online flag on radix_tree_insert failure (Tao Cui) [Orabug: 40073183] {CVE-2026-93795}
- ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs (Marcel Klos)
- wifi: iwlwifi: pcie: null RX pointers after free (Emmanuel Grumbach) [Orabug: 40073195] {CVE-2026-93796}
- wifi: iwlwifi: mvm: fix sched scan IE sizing (Emmanuel Grumbach)
- wifi: iwlwifi: mvm: parse beacon notif per layout (Emmanuel Grumbach)
- wifi: iwlwifi: mvm: fix an off-by-1 boundary check (Emmanuel Grumbach) [Orabug: 40073204] {CVE-2026-93797}
- wifi: iwlwifi: mvm: validate mac_link_id in session protect notif (Emmanuel Grumbach)
- btrfs: fix reloc root cleanup in merge_reloc_roots() (Filipe Manana) [Orabug: 40073215] {CVE-2026-93798}
- wifi: iwlwifi: mvm: validate sta_id in BA window status notif (Emmanuel Grumbach) [Orabug: 40073224] {CVE-2026-93799}
- spi: dw-dma: Wait for controller idle before completing Tx (Wang Yuwei)
- btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() (Filipe Manana) [Orabug: 40073232] {CVE-2026-93800}
- btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr() (Dave Chen)
- cifs: Fix support for creating SFU fifo (Pali Rohar)
- ALSA: hda: cs35l56: Fail if wmfw file is missing (Richard Fitzgerald)
- ALSA: hda/realtek - Add quirk for HP Victus 15-fa0xxx (MB 8A50) (Rohit Sinha)
- ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series (Chen Bowen)
- smb/client: zero-initialize stack-allocated cifs_open_info_data (Chenxiaosong) [Orabug: 40073242] {CVE-2026-93801}
- cifs: Fix support for creating SFU socket (Pali Rohar)
- smb/client: reduce fallocate zero buffer allocation (Huiwen He)
- ASoC: rt712-sdca: reset codec at io_init to fix silent headphone (Tianze Shao)
- wifi: rsi: validate beacon length before fixed buffer copy (Pengpeng Hou) [Orabug: 40073246] {CVE-2026-93802}
- netfilter: ipset: mark the rcu locked areas properly (Jozsef Kadlecsik)
- wifi: libipw: fix key index receive bound checks (Pengpeng Hou) [Orabug: 40073254] {CVE-2026-93803}
- gpio: dwapb: Mask interrupts at hardware initialization (Liang Hao)
- wifi: mac80211: ibss: wait for in-flight TX on disconnect (Anjaneyulu) [Orabug: 40073260] {CVE-2026-93804}
- wifi: cfg80211: validate rx/tx MLME callback frame lengths before access (Catherine) [Orabug: 40073269] {CVE-2026-93805}
- ksmbd: validate SID namespace before mapping IDs (Namjae Jeon)
- ksmbd: mark invalid session responses as signed (Namjae Jeon)
- ksmbd: find bound sessions during reauthentication (Namjae Jeon)
- wifi: cfg80211: validate assoc response length before status and IE access (Catherine) [Orabug: 40073276] {CVE-2026-93806}
- wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers (Pengpeng Hou) [Orabug: 40073284] {CVE-2026-93807}
- wifi: mac80211: validate deauth frame length before reason access (Catherine)
- wifi: ralink: RT2X00: init EEPROM properly (Corentin Labbe)
- ALSA: usb-audio: caiaq: validate EP1 reply lengths (Pengpeng Hou) [Orabug: 40073293] {CVE-2026-93808}
- ksmbd: fix credit charge calculation for SMB2 QUERY_INFO (Namjae Jeon)
- drm/amdgpu: flush pending RCU callbacks on module unload (Perry Yuan) [Orabug: 40073297] {CVE-2026-93809}
- ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table (Jetha Chan)
- netfs: Fix decision whether to disallow write-streaming due to fscache use (David Howells)
- cachefiles: Fix double fput (David Howells) [Orabug: 40073302] {CVE-2026-93810}
- xen/gntalloc: validate grant count before allocation (Yousef Alhouseen)
- freevxfs: don't BUG() on unknown typed-extent type (Farhad Alemi)
- xen/front-pgdir-shbuf: free grant reference head on errors (Yousef Alhouseen)
- ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling (Qiang Liu)
- ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr (Qiang Liu)
- drm/arm/komeda: fix error handling for clk_prepare_enable() and callers (Gustavo Kenji Mendonca Kaneko)
- ALSA: hda/realtek: Add quirk for HP Victus 16-e0xxx (88EE) to enable mute LED (Shubham Nayak)
- ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr (Qiang Liu)
- netfilter: nf_conntrack_expect: zero at allocation time (Florian Westphal)
- drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend (Gustavo Kenji Mendonca Kaneko)
- btrfs: tree-checker: validate INODE_REF's namelen (Weiming Shi) [Orabug: 40073319] {CVE-2026-93813}
- spi: core: Abort active target transfer on controller suspend (Praveen Talari) [Orabug: 40073325] {CVE-2026-93814}
- ASoC: tas2781: Update default register address to TAS2563 (Baojun Xu)
- fbdev: pm2fb: unwind WC setup on probe failure (Haoxiang Li)
- ALSA: hda: Add Lenovo Legion 7i 16IAX7 17AA3874 quirk (Kamlesh Chhetty)
- eth: mlx5: fix macsec dependency (Arnd Bergmann)
- rtc: bq32000: add delay between RTC reads (Adriana Nicolae)
- blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat() (Yu Kuai)
- net: au1000: move free_irq out of the close-time spinlocked section (Runyu Xiao)
- regulator: da9121: Use subvariant ids in the I2C table (Pengpeng Hou)
- PCI/sysfs: Use kstrtobool() to parse the ROM attribute input (Krzysztof Wilczynski)
- PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() (Krzysztof Wilczynski)
- ksmbd: treat read-control opens as stat opens only for leases (Namjae Jeon)
- ksmbd: break RH leases before delete-on-close (Namjae Jeon)
- ksmbd: start file id allocation at 1 (Namjae Jeon)
- ksmbd: deny renaming directory with open children (Namjae Jeon)
- ksmbd: apply create security descriptor first (Namjae Jeon)
- ksmbd: treat unnamed DATA stream as base file (Namjae Jeon)
- ksmbd: use connection ClientGUID for lease lookup (Namjae Jeon)
- ksmbd: align SMB2 oplock break ack handling (Namjae Jeon)
- ksmbd: validate SMB2 lease create contexts (Namjae Jeon)
- ksmbd: fix lease break and ack state handling (Namjae Jeon)
- ceph: harden send_mds_reconnect and handle active-MDS peer reset (Alex Markuze)
- rtc: aspeed: add AST2700 compatible (Tommy Huang)
- rtc: mv: add suspend/resume support for wakeup (Xue Lei)
- f2fs: validate inline dentry name lengths before conversion (Samuel Moelius)
- ALSA: hda/realtek: Add quirk for Lenovo Yoga 7 16IAP7 (Chris Aherin)
- md/raid5: let stripe batch bm_seq comparison wrap-safe (Chen Cheng)
- mailbox: imx: use devm_of_platform_populate() (Sebastian Andrzej Siewior)
- mailbox: imx: Add a channel shutdown field (Sebastian Andrzej Siewior)
- md/raid5: account discard IO (Yu Kuai)
- mailbox: imx: Use devm_pm_runtime_enable() (Sebastian Andrzej Siewior)
- PCI: plda: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: mediatek: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: rockchip: Protect root bus removal with rescan lock (Hans Zhang) [Orabug: 40073356] {CVE-2026-93820}
- PCI: altera: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: iproc: Protect root bus removal with rescan lock (Hans Zhang) [Orabug: 40073373] {CVE-2026-93822}
- drm/amdkfd: Properly acquire queue buffers in CRIU restore (David Francis)
- ALSA: usb-audio: Add quirk for YAMAHA CDS3000 (Jean-Louis Colaco)
- drm/amdgpu: Use system unbound workqueue for soft IH ring (Timur Kristof)
- drm/amdkfd: check find_first_zero_bit before __set_bit on kfd->doorbell_bitmap (Xiaogang Chen)
- drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl (Xiaogang Chen) [Orabug: 40073385] {CVE-2026-93823}
- mfd: rsmu: Add 8a34002 support (Matthew Bystrin)
- leds: trigger: gpio: Use GPIOD_FLAGS_BIT_NONEXCLUSIVE (Piotr Kubik)
- mfd: tps65219: Make poweroff handler conditional on system-power-controller (Akashdeep Kaur)
- leds: pca9532: Don't stop blinking for non-zero brightness (Tobias Deiminger)
- leds: uleds: Return -EFAULT on copy_to_user() failure (Yousef Alhouseen)
- ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10 (Galen Hassen)
- tls: reject the combination of TLS and sockmap (Jakub Kicinski) [Orabug: 40073391] {CVE-2026-93824}
- ALSA: usb-audio: Add quirk flags for SC13A (Ai Chao)
- spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() (Guoqi0226) [Orabug: 40073397] {CVE-2026-93825}
- gpio: pisosr: Read 'ngpios' as u32 (Rob Herring)
- scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block() (Arnd Bergmann)
- fuse: set ff->flock only on success (Zhang Tianci)
- HID: hidpp: fix potential UAF in hidpp_connect_event() (Jiri Kosina) [Orabug: 40073406] {CVE-2026-93826}
- virtio-fs: avoid double-free on failed queue setup (Yung-Tse Cheng) [Orabug: 40073412] {CVE-2026-93827}
- ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT (Viktor Menshin)
- exfat: fix handling of damaged volume in exfat_create_upcase_table() (David Timber) [Orabug: 40073418] {CVE-2026-93828}
- sparc: Disable compat support with LLD (Rosen Penev)
- bpftool: Pass host flags to bootstrap libbpf (Leo Yan)
- i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA (Adrian Hunter)
- smb: client: fix races in cifsd thread creation (Fredric Cover) [Orabug: 40073426] {CVE-2026-93829}
- net/sched: act_csum: don't mangle UDP tunnel GSO packets (Alice Mikityanska)
- apparmor: propagate -ENOMEM correctly in unpack_table (Maxime Belair)
- net: hns3: improve the unused_tuple parameter setting (Jijie Shao)
- e1000e: limit endianness conversion to boundary words (Agalakov Daniil)
- vsock: use sk_acceptq_is_full() helper in all transports (Raf Dickson)
- ptp: ocp: add shutdown callback (Vadim Fedorenko)
- net: stmmac: xgmac2: disable RBUE in default RX interrupt mask (Nazim Amirul)
- sparc64: uprobes: add missing break (Rosen Penev)
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d923 (Zhang Chen)
- Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV (Nils Helmig)
- ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure (Bui Duc Phuc)
- ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence (Bui Duc Phuc)
- ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt (Bui Duc Phuc)
- Bluetooth: btintel_pcie: Add 50 ms delay before MAC init on BlazarIW (Kiran K)
- Bluetooth: L2CAP: validate connectionless PSM length (Samuel Moelius) [Orabug: 40073441] {CVE-2026-97408}
- Bluetooth: btusb: Add support for TP-Link TL-UB250 (Cris)
- Bluetooth: btusb: MT7925: Add VID/PID 0e8d/8c38 (Chris Lu)
- Bluetooth: btmtk: Disable remote wakeup for MT7922/MT7925 (Rongrong)
- Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV (Hrvoje Nuic)
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d922 (Zhang Chen)
- Bluetooth: btusb: Add support for Intel Lizard Peak 2 (0x8087:0x0040) (Ravindra)
- Bluetooth: btusb: MT7922: Add VID/PID 0e8d/223c (Chris Lu)
- spi: xilinx: let transfers timeout in case of no IRQ (Vadim Fedorenko)
- hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i (Potin Lai)
- dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc (Tze Yee Ng)
- dmaengine: altera-msgdma: Use memcpy_toio for descriptor FIFO writes (Adrian Ng Ho Yin)
- PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems (Jose Ignacio Tornos Martinez)
- hwmon: (dell-smm) Add Dell Latitude 7530 to fan control whitelist (Armin Wolf)
- HID: multitouch: Honor ContactCount for Yoga Book 9 to suppress ghost contacts (Dave Carey)
- sctp: Unwind address notifier registration on failure (Yuho Choi)
- nvme-fc: Do not cancel requests in io target before it is initialized (Mohamed Khalfella) [Orabug: 40073446] {CVE-2026-97409}
- platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table (Nikolay Metchev)
- ata: libata-pmp: add JMicron JMS562 quirk (Xu Rao)
- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IRH8 (Moritz Baron)
- ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC (Furst Blumier)
- vdpa/octeon_ep: Use 4 bytes for mailbox signature (Vamsi Attunuru)
- vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add() (Evgenii Burenchev)
- net: lan966x: restore RX state on reload failure (Guangshuo Li)
- net: dsa: qca8k: Add support for force mode for fixed link topology (George Moussalem)
- btrfs: use lockless read in nr_cached_objects shrinker callback (Ben Maurer)
- btrfs: use on-disk uuid for s_uuid in temp_fsid mounts (Anand Jain)
- hwmon: (adt7462) Add of_match_table to support devicetree (Kory Maincent)
- hwmon: (raspberrypi) Fix delayed-work teardown race (Shubham Chakraborty)
- PCI: Avoid FLR for MediaTek MT7925 WiFi (Jose Ignacio Tornos Martinez)
- fbcon: don't suspend/resume when vc is graphics mode (Lu Yao)
- btrfs: protect sb_write_pointer() with invalidate lock (Kangning Liao)
- netconsole: take target_cleanup_list_lock in drop_netconsole_target() (Breno Leitao) [Orabug: 40073452] {CVE-2026-97410}
- wifi: mt76: transform aspm_conf for pci_disable_link_state (Jiajia Liu)
- wifi: mt76: mt7925: add 320MHz bandwidth to bss_rlm_tlv (Javier Tia)
- wifi: mt76: mt7925: populate EHT 320MHz MCS map in sta_rec (Javier Tia)
- wifi: mt76: mt7925: add Netgear A8500 USB device ID (Lucid Duck)
- platform/x86: msi-ec: Add support for MSI Pulse GL66 12th Gen (Luis de Carlos)
- wifi: mt76: mt7925: handle 320MHz bandwidth in RXV and TXS (Javier Tia)
- platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table (Gleb Sonichev)
- tls: Flush backlog before waiting for a new record (Chuck Lever)
- net: ibm: emac: mal: fix potential system hang in mal_remove() (Rosen Penev)
- pds_core: quiesce DMA before freeing resources (Nikhil P. Rao) [Orabug: 40073460] {CVE-2026-97412}
- configfs_depend_prep(): pass configfs_dirent instead of dentry (Al Viro)
- RDMA/mlx5: Create ODP EQ for non-pinned dmabuf MRs (Jason Gunthorpe)
- xprtrdma: Add request-pool slack for delayed recycling (Chuck Lever)
- RDMA/rtrs-srv: Fix integer underflow in process_read and process_write (Aurelien Desbrieres)
- ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend() (Tuo Li)
- NFS: fix eof updates after NFSv4.2 fallocate/zero-range (Dai Ngo)
- btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF (Zhang Cen) [Orabug: 40073476] {CVE-2026-97415}
- btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() (Zhengyuan Huang) [Orabug: 40073481] {CVE-2026-97416}
- riscv: panic if IRQ handler stacks cannot be allocated (Osama Abdelkader)
- netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (Rosen Penev) [Orabug: 40073485] {CVE-2026-97417}
- ALSA: es18xx: check control allocation before private data setup (Ruoyu Wang)
- net: microchip: sparx5: clean up PSFP resources on flower setup failure (Haoxiang Li)
- hsr: broadcast netlink notifications in the device's net namespace (Maoyi Xie) [Orabug: 40073494] {CVE-2026-97419}
- net: cpsw_new: unregister devlink on port registration failure (Guangshuo Li)
- bpf: NUL-terminate replaced sysctl value (Dawei Feng) [Orabug: 40073499] {CVE-2026-97420}
- RDMA/mlx5: Fix state and counter desync on loopback enable failure (Li Rongqing)
- RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() (Jason Gunthorpe) [Orabug: 40073503] {CVE-2026-97421}
- wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications (Thiyagarajan Pandiyan)
- ipv6: use READ_ONCE() for bindv6only default in inet6_create() (Runyu Xiao)
- drm/amdkfd: Unwind debug trap enable on copy_to_user failure (Yongqiang Sun)
- ipmi: si: Use platform_get_irq_optional() to retrieve interrupt (Rosen Penev)
- ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP (Andrei Faleichyk)
- clk: keystone: don't cache clock rate (Michael Walle)
- net/mlx5: E-Switch, align disable sequence with switchdev-to-legacy transition (Shay Drory)
- RDMA/irdma: Fix typo in SQ completions generation (Cyrill Gorcunov)
- net/mlx5e: Verify unique vhca_id count instead of range (Shay Drory)
- drm/amdgpu: fix buffer overflow during vBIOS update (Morris Zhang) [Orabug: 40073529] {CVE-2026-97425}
- drm/amd/pm: bound pp_dpm_set_pp_table() memcpy (Asad Kamal) [Orabug: 40073539] {CVE-2026-97427}
- drm/amdgpu: harden FRU PIA parsing with bounded helpers (Stanley Yang) [Orabug: 40073545] {CVE-2026-97428}
- drm/amdkfd: fix UAF race in destroy_queue_cpsch (Alysa Liu) [Orabug: 40073549] {CVE-2026-97429}
- drm/amd/display: Check for sharpening case when calculating max vtaps for scaler (Samson Tam)
- xhci: Prevent queuing new commands if xhci is inaccessible (Mathias Nyman) [Orabug: 40073554] {CVE-2026-97430}
- usb: xhci: Improve Soft Retries after short transfers (Michal Pecio)
- thermal/drivers/qcom/tsens: Atomic temperature read with hardware-guided retries (Priyansh Jain)
- dpaa2-switch: fix handling of NAPI on the remove path (Ioana Ciornei)
- net: dsa: sja1105: flower: reject cross-chip redirect (David Yang)
- dpaa2-switch: fix the error path in dpaa2_switch_rx() (Ioana Ciornei)
- dpaa2-switch: rework FDB management on the bridge leave path (Ioana Ciornei)
- ALSA: seq: oss: Reject reads that cannot fit the next event (Cassio Gabriel)
- ASoC: codecs: rk3328: Use managed GPIO and clock helpers (Cassio Gabriel)
- ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() (Alessandro Schino)
- fs/ntfs3: validate index entry key bounds (Zhengyuan Huang) [Orabug: 40073602] {CVE-2026-97438}
- nvme: refresh multipath head zoned limits from path limits (Yao Sang)
- fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib (Zhengyuan Huang)
- powerpc/fadump: Add timeout to RTAS busy-wait loops (Adriano Vero)
- iommu/rockchip: disable fetch dte time limit (Simon Xue)
- net: wwan: t7xx: Add delay between MD and SAP suspend (Jose Ignacio Tornos Martinez)
- net: qrtr: fix node refcount leak on ctrl packet alloc failure (Xu Wang) [Orabug: 40073611] {CVE-2026-97440}
- ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach (Chen Pei)
- ACPI: scan: Honor _DEP for ACPI0016 PCI/CXL host bridge (Chen Pei)
- ata: ahci: fail probe if BAR too small for claimed ports (Liyouhong) [Orabug: 40073616] {CVE-2026-97441}
- ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive (Cezary Rojewski)
- ASoC: qcom: q6apm: return error code to consumers on failures (Srinivas Kandagatla)
- wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi (Miaoqing Pan) [Orabug: 40073621] {CVE-2026-97442}
- net: ibm: emac: Reserve VLAN header in MJS limit (Rosen Penev)
- libbpf: Also reset {insn,data}_cur on realloc failure (Daniel Borkmann)
- iio: accel: mma8452: switch to non-devm request_threaded_irq() (Sanjay Chitroda)
- perf/ftrace: Fix WARNING in __unregister_ftrace_function (Rik van Riel) [Orabug: 40073628] {CVE-2026-97443}
- iio: light: stk3310: Deal with the ps interrupt issue in PM (Miao Li)
- mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC (Lad Prabhakar)
- tracing: Disable KCOV instrumentation for trace_irqsoff.o (Karl Mehltretter)
- ARM: tegra: p880: Lower CPU thermal limit (Ion Agorria)
- mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC (Lad Prabhakar)
- mmc: davinci: fix mmc_add_host order in probe (Osama Abdelkader)
- soundwire: only handle alert events when the peripheral is attached (Bard Liao)
- gfs2: page poisoning fix (Andreas Gruenbacher)
- soundwire: dmi-quirks: Disable ghost Realtek devices (Charles Keepax)
- soc/tegra: fuse: Register nvmem lookups at probe (Kartik)
- libbpf: Add __NR_bpf definition for LoongArch (Tiezhu Yang)
- drm/nouveau/bios: skip the IFR header if present (Timur Tabi)
- ASoC: Intel: catpt: Complete coredump handling (Cezary Rojewski)
- scripts: modpost: detect and report truncated buf_printf() output (Alexandre Courbot)
- host1x: bus: Fix missing ops null check in error teardown (Shayderrr)
- pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- net: sfp: add quirk for OEM 2.5G optical modules (Wei Qisen)
- hfs: rework hfsplus_readdir() logic (Viacheslav Dubeyko)
- ACPICA: add boundary checks in two places (Kang Chen) [Orabug: 40073635] {CVE-2026-97444}
- ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() (Kang Chen) [Orabug: 40073643] {CVE-2026-97445}
- ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() (Weiming Shi) [Orabug: 40073651] {CVE-2026-97446}
- ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() (Kang Chen) [Orabug: 40073657] {CVE-2026-97447}
- ACPICA: Add validation for node in acpi_ns_build_normalized_path() (Kang Chen) [Orabug: 40073661] {CVE-2026-97448}
- ACPICA: Add package limit checks in parser functions (Kang Chen) [Orabug: 40073667] {CVE-2026-97449}
- ACPICA: validate handler object type in two places (Kang Chen) [Orabug: 40073672] {CVE-2026-97450}
- ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg() (Kang Chen)
- ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) (Kang Chen) [Orabug: 40073678] {CVE-2026-97451}
- ACPICA: Prevent adding invalid references (Kang Chen) [Orabug: 40073685] {CVE-2026-97452}
- ACPICA: validate byte_count in acpi_ps_get_next_package_length() (Kang Chen) [Orabug: 40073691] {CVE-2026-97453}
- ACPICA: add boundary checks in acpi_ps_get_next_field() (Kang Chen) [Orabug: 40073697] {CVE-2026-97454}
- ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() (Kang Chen) [Orabug: 40073703] {CVE-2026-97455}
- ACPICA: Fix condition check in acpi_ps_parse_loop() (Kang Chen) [Orabug: 40073708] {CVE-2026-97456}
- drm/amd/display: Initialize dsc_caps to 0 (Ivan Lipski)
- drm/amd/pm/si: Fix updating clock limits from power states (Jeremy Klarenbeek)
- drm/dp: Add DSC virtual DPCD quirk for Realtek MST branch device (Imre Deak)
- net: thunderx: fix PTP device ref leak in nicvf_probe() (Haoxiang Li)
- ipv6: addrconf: fix temp address generation after prefix deprecation (Fernando Fernandez Mancera) [Orabug: 40073713] {CVE-2026-97472}
- net: hsr: require valid EOT supervision TLV (Luka Gejak)
- ALSA: usb-audio: Add quirk for Novation Mininova (Uwe Kuchler)
- irqchip/gic-v4: Don't advertise VLPIs if no ITS is probed (Mostafa Saleh)
- iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind (Stepan Ionichev)
- mips: cps: Assemble jr.hb with an R2 ISA level (Rosen Penev)
- drm/panel: simple: Add AM-1280800W8TZQW-T00H (Dario Binacchi)
- powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked() (Sumeet Pawnikar) [Orabug: 40073718] {CVE-2026-97473}
- thermal/drivers/tegra/soctherma: Switch to devm cooling device registration (Daniel Lezcano)
- clk: socfpga: agilex: implement l3_main_free_clk (Adrian Ng Ho Yin)
- s390/zcore: Removed unused variables (Heiko Carstens)
- ALSA: seq: Remove arbitrary prioq insertion limit (Cassio Gabriel)
- netlabel: fix IPv6 unlabeled address add error handling (Chenguang Zhao)
- wifi: rtw89: pci: enable LTR based on pcie control register (Dian-Syuan Yang)
- rcu-tasks: Fix possible boot-time tests failed for the call_rcu_tasks() (Zqiang)
- char/nvram: Remove redundant nvram_mutex (Venkat Rao Bagalkote)
- crypto: atmel-sha204a - remove sysfs group before hwrng (Thorsten Blum)
- usb: host: add ARCH_AIROHA in XHCI MTK dependency (Christian Marangi)
- serial: 8250: fix possible ISR soft lockup (Marco Felsch) [Orabug: 40073758] {CVE-2026-97481}
- usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue (Maoyi Xie)
- USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set (Dave Carey)
- usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log (Stepan Ionichev)
- usb: core: hcd: fix possible deadlock in rh control transfers (Oliver Neukum) [Orabug: 40073767] {CVE-2026-97483}
- usbip: vhci_hcd: fix NULL deref in status_show_vhci (Adrian Wowk) [Orabug: 40073772] {CVE-2026-97484}
- HID: bpf: Add Huion Inspiroy Frego M button quirk (Nikhil Chatterjee)
- isofs: handle set_blocksize failures (Christoph Hellwig)
- omfs: handle set_blocksize failures (Christoph Hellwig)
- hpfs: handle set_blocksize failures (Christoph Hellwig)
- jfs: handle set_blocksize failures (Christoph Hellwig)
- qnx4: handle set_blocksize failures (Christoph Hellwig)
- minix: handle set_blocksize failures (Christoph Hellwig)
- bfs: handle set_blocksize failures (Christoph Hellwig)
- affs: handle set_blocksize failures (Christoph Hellwig)
- ntfs3: handle set_blocksize failures (Christoph Hellwig)
- befs: handle set_blocksize failures (Christoph Hellwig)
- spi: dw-mmio: Add ACPI ID LECA0002 for LECARC SoCs (Thomas Lin)
- net/sched: sch_drr: make cl->quantum lockless (Eric Dumazet)
- net: bridge: remove stale rcu_barrier() in br_multicast_dev_del() (Eric Dumazet)
- net: usb: qmi_wwan: add MeiG SRM813Q (Jan Volckaert)
- nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl (Maurizio Lombardi)
- bitfield: wire __bf_shf to __builtin_ctzll (Yury Norov)
- thunderbolt: Verify Router Ready bit is set after router enumeration (Gil Fine)
- wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed (Miri Korenblit) [Orabug: 40073812] {CVE-2026-97492}
- thunderbolt: Increase timeout for Configuration Ready bit (Gil Fine)
- firmware: arm_scmi: Validate BASE_ERROR_EVENT payload size (Sudeep Holla)
- firmware: arm_scmi: Validate SENSOR_UPDATE payload size (Sudeep Holla)
- thunderbolt: Improve multi-display DisplayPort tunnel allocation (Alan Borzeszkowski)
- thunderbolt: Don't access path config space on Lane 1 adapters in tb_switch_reset_host() (Pooja Katiyar)
- bridge: Add missing READ_ONCE() annotations around FDB destination port (Ido Schimmel)
- drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw (Candice Li) [Orabug: 40073829] {CVE-2026-97494}
- 9p: use kvzalloc for readdir buffer (Pierre Barre)
- drm/imagination: Populate FW common context ID before passing to the FW (Brajesh Gupta)
- arm64/daifflags: Make local_daif_*() helpers __always_inline (Leonardo Bras)
- 9p: invalidate readdir buffer on seek (Pierre Barre)
- iommu: arm-smmu-qcom: Ensure smmu is powered up in set_ttbr0_cfg (Anna Maniscalco)
- sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity (Andrea Righi)
- ALSA: usx2y: Drain pending US-428 pipe-4 output commands (Cassio Gabriel)
- drm/amdkfd: Check bounds on allocate_doorbell (David Francis) [Orabug: 40073835] {CVE-2026-97495}
- drm/amdkfd: Fix OOB memory exposure in get_wave_state() (Sunday Clement) [Orabug: 40073839] {CVE-2026-97496}
- drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id (David Francis) [Orabug: 40073845] {CVE-2026-97497}
- PCI: Wait for device readiness after D3hot -> D0uninitialized transition (Bjorn Helgaas)
- mailbox: Make mbox_send_message() return error code when tx fails (Joonwon Kang)
- iomap: don't make REQ_POLLED imply REQ_NOWAIT (Christoph Hellwig)
- drm/mediatek: dsi: Add compatible for mt8167-dsi (Luca Leonardo Scorcia)
- RDMA/mlx5: Use QP port when decoding responder CQEs (Chenguang Zhao)
- media: imon: Add iMON VFD HID OEM v1.2 key mappings (Alessandro Baldi)
- crypto: atmel-ecc - add support for atecc608b (Thorsten Blum)
- ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally (Bard Liao)
- crypto: ecc - Unbreak the build on arm with CONFIG_KASAN_STACK=y (Lukas Wunner)
- scsi: pm8001: Reject non-fatal dump when controller is crashed (Kumar Meiyappan)
- scsi: pm8001: Reject firmware update in fatal error state (Kumar Meiyappan)
- clk: samsung: exynos850: mark APM I3C clocks as critical (Alexey Klimov)
- soundwire: intel: Move suspend tracking from trigger to pm suspend (Peter Ujfalusi)
- drivers/of: validate status properties in reconfig state changes (Pengpeng Hou)
- integrity: Check for NULL returned by asymmetric_key_public_key (Stefan Berger)
- net: dsa: realtek: rtl8365mb: add support for RTL8367SB (Mieczyslaw Nalewaj)
- wifi: rtw89: phy: check length before parsing PHY status IE (Ping-Ke Shih) [Orabug: 40073866] {CVE-2026-97500}
- HID: multitouch: Fix Yoga Book 9 14IAH10 touchscreen misclassification (Dave Carey)
- media: video-i2c: use vb2_video_unregister_device on driver removal (Arash Golgol)
- media: chips-media: wave5: Add range checks for dec_output_info (Ricardo Ribalda)
- drm/gud: Add RCade Display Adapter VID/PID pair (Sophie D)
- net: phy: motorcomm: use device properties for firmware tuning (Chunzhi Lin)
- hfsplus: rework hfsplus_readdir() logic (Viacheslav Dubeyko)
- PCI: intel-gw: Enable clock before PHY init (Florian Eckert)
- drm/amd/display: Fix CRC open failure during active rendering (Tom Chung)
- platform/x86: sel3350-platform: Retain LED state on load and unload (Brodie Abrew)
- mmc: davinci: avoid NULL deref of host->data in IRQ handler (Stepan Ionichev)
- mmc: core: Add validation for host-provided max_segs (Shawn Lin)
- platform/chrome: Resolve kb_wake_angle visibility race (Tzung-Bi Shih)
- net/mlx5: HWS, Handle destroying table that has a miss table (Yevgeny Kliteynik)
- watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk (Mark Pearson)
- watchdog: imx7ulp_wdt: Keep WDOG running until A55 enters WFI on i.MX94 (Ranjani Vaidyanathan)
- watchdog: lenovo_se10_wdt: Add support for SE10 Gen 2 platform (Mark Pearson)
- ASoC: ti: omap3pandora: update board check to use DT compatible (Ethan Nelson-Moore)
- media: qcom: camss: avoid format string warning (Arnd Bergmann)
- PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() (Krzysztof Wilczynski) [Orabug: 40073891] {CVE-2026-97505}
- dlm: add usercopy whitelist to dlm_cb cache (Ziyi Guo)
- drm/bridge: tc358768: Set pre_enable_prev_first for reverse order (Parth Pancholi)
- clk: renesas: cpg-mssr: Add number of clock cells check (Geert Uytterhoeven)
- crypto: omap - add omap_des_unregister_algs helper (Thorsten Blum)
- crypto: ixp4xx - fix buffer chain unwind on allocation failure (Ruoyu Wang)
- rtase: Fix flow control configuration (Justin Lai)
- wifi: mac80211: explicitly disable FTM responder on AP stop (Johannes Berg)
- media: em28xx-video: fix missing res_free() on init_usb_xfer failure (Haoxiang Li)
- net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family (Marek Behun)
- net: dsa: mv88e6xxx: define .pot_clear() for 6321 (Marek Behun)
- PCI: switchtec: Add Gen6 Device IDs (Ben Reed)
- net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family (Marek Behun)
- media: dm1105: fix missing error check for dma_alloc_coherent (Zhaoyang Yu) [Orabug: 40073902] {CVE-2026-97507}
- drm/panel: Enable GPIOLIB for panels which uses functions from it (David Heidelberger)
- drm/amdgpu: Prefer ROM BAR for default VGA device (Lijo Lazar)
- drm/amd/display: Find link encoder for flexible DIG mapping cases (Ovidiu Bunea)
- thunderbolt: Don't create multiple DMA tunnels on firmware connection manager (Alan Borzeszkowski)
- thunderbolt: Set tb->root_switch to NULL when domain is stopped (Mika Westerberg) [Orabug: 40073909] {CVE-2026-97508}
- thunderbolt: Keep the domain reference while processing hotplug (Mika Westerberg)
- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg) [Orabug: 40073913] {CVE-2026-97509}
- thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() (Mika Westerberg) [Orabug: 40073917] {CVE-2026-97510}
- thunderbolt: Don't disable lane adapter if XDomain lane bonding isn't possible (Mika Westerberg)
- thunderbolt: Avoid reserved fields in path config space for USB4 routers (Gil Fine)
- s390/cio: Purge based on the cdev's online status (Vineeth Vijayan)
- net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (Erni Sri Satya Vennela)
- media: rc: mceusb: Add support for 04eb:e033 (Riccardo Boninsegna)
- spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM (Viken Dadhaniya)
- media: chips-media: wave5: Fix Reports from Kernel Lock Validator (Brandon Brnich)
- soundwire: validate DT compatible before parsing it (Pengpeng Hou)
- soundwire: intel_auxdevice: Add cs42l43b to wake_capable_list (Charles Keepax)
- bridge: Do not suppress ARP probes and DAD NS unconditionally (Danielle Ratson)
- firmware: stratix10-svc: change get provision data to async SMC call (Siew Chin Lim)
- kcsan: Silence -Wmaybe-uninitialized when calling __kcsan_check_access() (Marco Elver)
- ASoC: fsl-asoc-card: reduce WM8904 PLL ratio to meet frequency limit (Shengjiu Wang)
- wifi: rtw89: disable CSI STBC for VHT 160MHz (Dian-Syuan Yang)
- wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() (Panagiotis Petrakopoulos) [Orabug: 40073944] {CVE-2026-97516}
- wifi: mac80211: always allow transmitting null-data on TXQs (Johannes Berg)
- wifi: nl80211: reject beacons with bad HE operation (Johannes Berg) [Orabug: 40073950] {CVE-2026-97517}
- hfsplus: fix issue of direct writes beyond end-of-file (Viacheslav Dubeyko)
- wifi: cfg80211: reject duplicate wiphy cipher suite entries (Yuqi Xu) [Orabug: 40073957] {CVE-2026-97518}
- PCI: Stop setting cached power state to 'unknown' on unbind (Lukas Wunner)
- tools/nolibc: avoid call to wcslen() in _start_c() inserted by clang (Thomas Weissschuh)
- tee: optee: Allow MT_NORMAL_TAGGED shared memory (Hirokazu Honda)
- usb: gadget: udc: skip pullup() if already connected (Xu Yang)
- ima: return error early if file xattr cannot be changed (Goldwyn Rodrigues)
- ALSA: usb-audio: Propagate write errors in generic mixer put callbacks (Cassio Gabriel)
- pinctrl: renesas: rzg2l: Handle RZ/V2H(P) IOLH configuration in PM cache (Lad Prabhakar)
- iio: adc: rtq6056: add i2c_device_id support (Kevin Tung)
- gfs2: move quota_init qc iterator increment (Jie Wang) [Orabug: 40073971] {CVE-2026-97520}
- gfs2: fix quota init duplicate scan (Jie Wang) [Orabug: 40073975] {CVE-2026-97521}
- drm/amd/pm: Check SMUv13.0.6/12 metrics integrity (Lijo Lazar)
- drm/panel: jadard-jd9365da-h3: set prepare_prev_first (Dmitry Baryshkov)
- drm/amd/display: Fix DPMS using partially updated pipe context (Dominik Kaszewski)
- drm: rz-du: Ensure correct suspend/resume ordering with VSP (Tommaso Merciai)
- bus: fsl-mc: wait for the MC firmware to complete its boot (Ioana Ciornei)
- drm/gem: Consider GEM object reclaimable if shrinking fails (Boris Brezillon)
- ksmbd: fix use-after-free in oplock break notification (Abdifatah Suruur)
- LTS version: v6.12.110 (Sherry Yang)
- ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() (Tony W Wang-Oc)
- integrity: Eliminate weak definition of arch_get_secureboot() (Nathan Chancellor)
- slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL (Hao Ge)
- x86/Kconfig: Reenable PTDUMP on i386 (Alexander Popov)
- pinctrl: mediatek: common-v1: Fix error checking in mtk_eint_init() (Dan Carpenter)
- tools/build: Use SYSTEM_BPFTOOL for system bpftool (Tomas Glozar)
- net_sched: add back BH safety to tcf_lock (Eric Dumazet)
- net_sched: act_tunnel_key: use RCU in tunnel_key_dump() (Eric Dumazet)
- net_sched: act_vlan: use RCU in tcf_vlan_dump() (Eric Dumazet)
- net_sched: act_skbedit: use RCU in tcf_skbedit_dump() (Eric Dumazet)
- net_sched: act_ctinfo: use RCU in tcf_ctinfo_dump() (Eric Dumazet)
- net_sched: act_ct: use RCU in tcf_ct_dump() (Eric Dumazet)
- md: fix sync_action incorrect display during resync (Zheng Qixing)
- md: add helper rdev_needs_recovery() (Zheng Qixing)
- kselftest/arm64: mte: Use the correct naming for tag check modes in check_hugetlb_options.c (Catalin Marinas)
- kselftest/arm64: mte: Skip the hugetlb tests if MTE not supported on such mappings (Catalin Marinas)
- net/sched: fq: clamp quantum and initial_quantum in change path (Jamal Hadi Salim) [Orabug: 40081010] {CVE-2026-90050}
- Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array (Arnd Bergmann)
- xsk: Fix offset calculation in unaligned mode (Eryk Kubanski)
- erofs: fix managed cache race for unaligned extents (Gao Xiang) [Orabug: 40081005] {CVE-2026-64031}
- cpuset: fix warning when disabling remote partition (Chen Ridong) [Orabug: 40081001] {CVE-2025-71142}
- nvme-apple: Reset q->sq_tail during queue init (Nick Chan)
- nvme-apple: Prevent shared tags across queues on Apple A11 (Nick Chan)
- powerpc/vdso: Remove unused clockmode asm offsets (Thomas Weissschuh)
- phy: qcom: qmp-combo: Add missing PLL (VCO) configuration on SM8750 (Krzysztof Kozlowski)
- perf test: Don't signal all processes on system when interrupting tests (James Clark)
- fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT (Yongpeng Yang)
- ACPI: processor: Update cpuidle driver check in __acpi_processor_start() (Rafael J. Wysocki)
- md: keep recovery_cp in mdp_superblock_s (Xiao Ni)
- pinctrl: mediatek: common-v1: Fix EINT breakage on older controllers (Chen-Yu Tsai)
- pinctrl: mediatek: Fix new design debounce issue (Hao Chang)
- pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() (Chen-Yu Tsai)
- cpufreq/amd-pstate: Fix prefcore rankings (Mario Limonciello)
- platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)
- net/sched: sch_htb: limit htb_classify inner-class filter hops (Jamal Hadi Salim) [Orabug: 40041293] {CVE-2026-90053}
- tcp: fix corruption of urgent data on multi-segment retransmit (Jiayuan Chen) [Orabug: 40041301] {CVE-2026-90054}
- usb: atm: usbatm: fix invalid ci_range initialization (Deepanshu Kartikey) [Orabug: 40041308] {CVE-2026-90055}
- net: fec: only stop PTP if it was initialized (Bui Duc Phuc)
- slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() (Eric Dumazet) [Orabug: 40041322] {CVE-2026-90057}
- net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup (Jamal Hadi Salim) [Orabug: 40041330] {CVE-2026-90058}
- net: stmmac: selftests: Account for the UC filter list for filtering tests (Maxime Chevallier)
- net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: dwmac4: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: selftests: Check multiple MMC counters (Maxime Chevallier)
- selftests/arm64: Treat KSM merge_across_nodes as optional (Usama Anjum)
- selftests/arm64: Print missing MTE TAP headers (Usama Anjum)
- ALSA: control: Don't add invalid kcontrols to LED layer (Takashi Iwai) [Orabug: 40041339] {CVE-2026-90060}
- netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited() (Pablo Neira Ayuso)
- netfilter: xt_HL: add pr_fmt and checkentry validation (Marino Dzalto)
- netfilter: xt_cgroup: Make it independent from net_cls (Michal Koutny)
- netfilter: nf_tables: move hardware offload step after building the chain blob (Pablo Neira Ayuso) [Orabug: 40041351] {CVE-2026-90062}
- virtio-net: Ensure that TCP packets don't overflow gso_segs (Alice Mikityanska) [Orabug: 40041355] {CVE-2026-90063}
- net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs (Jiawen Wu)
- net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure (Yifei Chu)
- net: ethernet: sun4i-emac: Fix IRQ error handling (Bui Duc Phuc)
- samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify (Xu Wang)
- samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify (Xu Wang)
- libceph: validate banner payload length (Aleksandr Nogikh) [Orabug: 40041366] {CVE-2026-90067}
- ceph: revalidate ki_pos for O_APPEND writes after cap acquisition (Xiubo Li)
- ASoC: dapm: Fix off-by-one check on the second enum channel (Hyeongjun An) [Orabug: 40041369] {CVE-2026-90068}
- apparmor: policy_int make sure list heads are initialized before fail path (John Johansen)
- apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init (Thorsten Blum)
- tpm: st33zp24: Validate locality read result (Ruoyu Wang)
- tpm: st33zp24: Return zero on status read failure (Ruoyu Wang) [Orabug: 40041375] {CVE-2026-90070}
- net/sched: sch_teql: restore skb->dev on the slave failure path (Victor Nogueira) [Orabug: 40043379] {CVE-2026-90071}
- net/sched: sfq: clamp quantum to avoid signed overflow soft lockup (Jamal Hadi Salim) [Orabug: 40041381] {CVE-2026-90072}
- net/sched: hhf: clamp quantum before hhf_change() to avoid overflow (Jamal Hadi Salim) [Orabug: 40041385] {CVE-2026-90073}
- net/sched: fq_pie: clamp default quantum to avoid signed overflow (Jamal Hadi Salim)
- net/sched: sch_codel: clamp default mtu to avoid disabling CoDel (Jamal Hadi Salim)
- net/sched: fq_codel: clamp default quantum and mtu (Jamal Hadi Salim) [Orabug: 40041392] {CVE-2026-90075}
- net/sched: fq: add overflow bounds to quantum and initial quantum (Jamal Hadi Salim) [Orabug: 40041397] {CVE-2026-90076}
- net: core: check skb_frags_readable before uncloning in skb_copy_ubufs (Mina Almasry)
- net/sched: act_skbmod: fix length calculations and avoid invalid header warnings (Eric Dumazet) [Orabug: 40041403] {CVE-2026-90078}
- net_sched: act_skbmod: use RCU in tcf_skbmod_dump() (Eric Dumazet)
- maple_tree: fix argument name in header (Liam R Howlett)
- maple_tree: catch race in mas_alloc_cyclic() (Liam R Howlett)
- selftests/mm: skip COW tmpfile cases when fallocate() is unsupported (Usama Anjum)
- selftests/mm: report unique test names for each cow test (Mark Brown)
- selftests/mm/cow: modify the incorrect checking parameters (Hao Ge)
- cifs: fix clearing stats for fastest execution of each smb2 command (Frank Sorenson)
- octeontx2-af: Fix TL3/TL2 link config ENA clearing (Naveen Mamindlapalli)
- net: qualcomm: rmnet: restore skb->dev on deaggregated frames (Xiang Mei)
- gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free (Cen Zhang) [Orabug: 40033099] {CVE-2026-89789}
- Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (Hyunwoo Kim) [Orabug: 40041440] {CVE-2026-90088}
- Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (Chris Lu)
- Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (Chris Lu)
- Bluetooth: btmtk: Do not discard the subsystem reset timeout (Ismail Tarim)
- Bluetooth: btmtk: Do not report success when subsys reset fails (Ismail Tarim)
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() (Greg Kroah-Hartman)
- Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support (Javier Tia)
- Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference (Pavel Shpakovskiy) [Orabug: 40072795] {CVE-2026-93247}
- Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN (Pauli Virtanen) [Orabug: 40043384] {CVE-2026-90092}
- arm64: ptdump: Make note_page_flush() range aware (Wei-Lin Chang)
- mm/ptdump: split note_page() into level specific callbacks (Anshuman Khandual)
- mm: rename GENERIC_PTDUMP and PTDUMP_CORE (Anshuman Khandual)
- mm: make DEBUG_WX depdendent on GENERIC_PTDUMP (Anshuman Khandual)
- powerpc: Add preempt lazy support (Shrikanth Hegde)
- s390: Add ARCH_HAS_PREEMPT_LAZY support (Heiko Carstens)
- s390: Add missing _TIF defines (Heiko Carstens)
- arm64: Enable ARCH_HAS_NONLEAF_PMD_YOUNG (Yicong Yang)
- scsi: qla2xxx: Fix an loop timeout test (Dan Carpenter)
- net: page_pool: Remove zone/policy GFP flags when allocating XArray entries (Rongrong)
- bnxt_en: Fix call to hardware monitoring event handler (Guenter Roeck) [Orabug: 40041473] {CVE-2026-90101}
- rtc: pcf85363: Add error checking to regmap calls in probe() (Cosmo Chou)
- NFSv4/pnfs: key the data server cache on the NFS version (Junrui Luo) [Orabug: 40041479] {CVE-2026-90102}
- nfs: move the nfs4_data_server_cache into struct nfs_net (Jeff Layton)
- NFSv4.2: fix LAYOUTSTATS send buffer exhaustion (Junrui Luo) [Orabug: 40041485] {CVE-2026-90103}
- net/smc: free pending qentry in smc_llc_flow_stop() before memset (Mahanta Jambigi)
- net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition (Mahanta Jambigi)
- net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue (Jamal Hadi Salim) [Orabug: 40041523] {CVE-2026-90109}
- inetpeer: randomize RB-tree node comparison using SipHash (Eric Dumazet) [Orabug: 40041529] {CVE-2026-90110}
- net: qlcnic: validate unified ROM sections before loading (Pengpeng Hou) [Orabug: 40041540] {CVE-2026-90112}
- net: add missing ref_tracker_dir_exit() to net_passive_dec() (Tetsuo Handa)
- net: ipa: balance runtime PM reference on remove error (Ruoyu Wang)
- forcedeth: stop the tx_timeout register dump past the requested window (Marek Czernohous)
- net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (Fan Ye)
- net/sched: add get_fill_size callbacks for actions missing them (Victor Nogueira)
- net: bridge: Reject descending VLAN tunnel ranges (Ruoyu Wang) [Orabug: 40041548] {CVE-2026-90114}
- xsk: fix NULL pointer dereference in __xsk_rcv() (Cen Zhang) [Orabug: 40041552] {CVE-2026-90115}
- xsk: avoid double checking against rx queue being full (Maciej Fijalkowski)
- xsk: Get rid of xdp_buff_xsk::orig_addr (Maciej Fijalkowski)
- RDMA/ucma: Allow path records to exactly fit the output buffer (Serhat Kumral)
- ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup (Xu Wang) [Orabug: 40041562] {CVE-2026-90119}
- ALSA: core: Add scoped cleanup helper for card references (Cassio Gabriel)
- clk: visconti: Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- clk: ti: Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator (Bradley Morgan)
- rtc: gamecube: check return value of devm_rtc_register_device() (Linkai Gong)
- i2c: ocores: Disable clock on failed resume (Ruoyu Wang)
- irqchip/renesas-rzg2l: Fix loss of interrupt (Biju Das)
- rtc: zynqmp: Return optional clock lookup errors (Pengpeng Hou)
- smb: client: fix request buffer leak in smb2_new_read_req() (Christopher Lusk) [Orabug: 40041584] {CVE-2026-90125}
- rtc: pcf8563: fix clock provider leak on unbind (Yi Ding) [Orabug: 40041588] {CVE-2026-90126}
- vdpa/mlx5: fix wrong list iterated in add_direct_chain error path (Li Rongqing) [Orabug: 40041594] {CVE-2026-90128}
- virtio_pci: fix wrong queue index for admin vq in intx path (Li Rongqing)
- vdpa_sim: fix cleanup after worker creation failure (Linfeng Sun) [Orabug: 40041605] {CVE-2026-90130}
- virtio_balloon: disable indirect descriptors (Michael S. Tsirkin)
- i3c: mipi-i3c-hci: Fix missing STAT_IBI_STATUS_THLD in PIO mode (Jian-Ming Liao)
- i3c: mipi-i3c-hci: Refactor PIO register initialization (Adrian Hunter)
- i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc() (Adrian Hunter)
- i3c: mipi-i3c-hci: Quieten initialization messages (Adrian Hunter)
- net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() (Tetsuo Handa) [Orabug: 40041613] {CVE-2026-90135}
- bonding: initialize err for empty target lists (Ruoyu Wang)
- mlxbf-bootctl: fix the build error with FIELD_PREP() (Nikolay Kulikov)
- platform/x86: hp-bioscfg: fix password encoding bounds check (Guangshuo Li) [Orabug: 40041618] {CVE-2026-90137}
- vsock: use sock_error() to consume sk_err after a failed connect (Nguyen Dinh Phi)
- vsock: don't check the listener's sk_err in vsock_accept() (Nguyen Dinh Phi) [Orabug: 40041620] {CVE-2026-90138}
- vsock: avoid timeout for non-blocking accept() with empty backlog (Laurence Rowe)
- platform/x86: dell-wmi-sysman: Fix instance ID bounds (Hyeongjun An)
- net/smc: hash socket only after full initialisation in smc_sk_init() (Mahanta Jambigi)
- 8139cp: fix Rx and Tx not being disabled in cp_suspend (Karl Mehltretter)
- vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() (Baul Lee) [Orabug: 40072799] {CVE-2026-93250}
- ALSA: hda: Fix connection list comparison in proc output (Xu Rao)
- fuse: check for NULL root inode in fuse_fill_super_submount (Baokun Li) [Orabug: 40041625] {CVE-2026-90139}
- fuse: check attributes staleness on fuse_iget() (Zhang Tianci)
- fuse: convert readdir to use folios (Joanne Koong)
- fuse: support folios in struct fuse_args_pages and fuse_copy_pages() (Joanne Koong)
- fs/ntfs3: validate ef->size covers the record's name and value (Weiming Shi)
- fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() (Konstantin Komarov)
- cuse: wait for pending RCU callbacks on module exit (Baokun Li) [Orabug: 40041628] {CVE-2026-90140}
- net: bridge: vlan: fix inverted default vlan notification (Nikolay Aleksandrov)
- tls: fix RX desync on overlapping skbs (Maximilian Immanuel Brandtner)
- net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error (Ruoyu Wang)
- vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes (Xiang Mei) [Orabug: 40033013] {CVE-2026-89776}
- ipvs: fix integer overflow in ftp helper port/address parsing (Joas Antonio Dos Santos) [Orabug: 40041631] {CVE-2026-90141}
- f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode (Chao Yu)
- f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk} (Chao Yu)
- f2fs:Fix incomplete search range in f2fs_get_victim when f2fs_need_rand_seg is enabled (Liu Jinbao)
- f2fs: fix to parse temperature correctly in f2fs_get_segment_temp() (Chao Yu)
- net: hsr: free learned nodes on device setup failure (Xin Xie) [Orabug: 40079963] {CVE-2026-100071}
- pppox: drain queued packets on channel handoff (Qingfang Deng)
- net: dsa: b53: fix error propagation from b53_fdb_dump() (Vladimir Oltean)
- net: kcm: Hold RCU read lock while running BPF parser (Junseo Lim)
- ionic: fix completion descriptor access with 2x desc size (Prabu Thayalan)
- drm/xe: tests: fix error message in xe_migrate_sanity_test() (Dan Carpenter)
- clk: ti: mux: resolve parent clocks by DT index, not by name (Mathieu Dubois-Briand)
- clk: ti: use kcalloc() instead of kzalloc() (Ethan Carter Edwards)
- clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() (Onur Ozkan) [Orabug: 40041649] {CVE-2026-90147}
- nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3 (Michael Nemanov)
- NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() (Zhansong Gao) [Orabug: 40041651] {CVE-2026-90148}
- pnfs/blocklayout: Fix device leaks on parse failure (Zhangguodong) [Orabug: 40041658] {CVE-2026-90150}
- NFSv4: remove callback IDR entry on client allocation failure (Ruoyu Wang) [Orabug: 40041662] {CVE-2026-90151}
- nfs: refactor pNFS functions using clear_and_wake_up_bit (Arnaud Bonnet)
- nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper (Arnaud Bonnet)
- smb/server: fix session leak in ksmbd_session_register() (Tanze)
- ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size (Hang Nan)
- ksmbd: disconnect on SMB3 decryption failure (Namjae Jeon)
- bpf: Reject negative optlen in cgroup getsockopt hook (Junseo Lim) [Orabug: 40041687] {CVE-2026-90157}
- m68k: nfcon: Do not call console_is_registered() in nfcon_device() (Andreas Schwab)
- bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks (Junseo Lim) [Orabug: 40041692] {CVE-2026-90159}
- erofs: fix unused pcluster_pools for higher page sizes (Ojaswin Mujoo)
- erofs: support unaligned encoded data (Gao Xiang)
- erofs: convert z_erofs_bind_cache() to folios (Gao Xiang)
- lwt_bpf: Restore reserved headroom after xmit program (Junseo Lim) [Orabug: 40041696] {CVE-2026-90160}
- smb/server: preserve error status in smb2_handle_negotiate() (Zhangguodong)
- smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() (Zhangguodong)
- smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() (Zhangguodong)
- ksmbd: free preauth sessions on connection teardown (Namjae Jeon)
- ksmbd: do not advertise unimplemented CA support (Namjae Jeon)
- ksmbd: validate ipc response length before dereferencing its fields (Yunseong Kim)
- smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer (Enzo Matsumiya)
- ksmbd: Do not skip lock checks for single-byte ranges (Guangshuo Li)
- hwmon: (emc1403) Drop hysteresis for low limit temperature (Marius Cristea)
- hwmon: (emc1403) Rely on subsystem locking (Guenter Roeck)
- hwmon: (coretemp) Fix core_data leak on CPUs without PTS (Szymon Wilczek) [Orabug: 40041745] {CVE-2026-90178}
- block: mtip32xx: synchronize ioctls with device removal (Hongyan Xu) [Orabug: 40041748] {CVE-2026-90180}
- ublk: reject non-power-of-2 zone sizes in SET_PARAMS (Yao Sang)
- null_blk: serialize configfs attribute updates with device setup (Niklas Cassel) [Orabug: 40041769] {CVE-2026-90184}
- null_blk: serialize configfs attribute stores with the lock (Zizhi Wo) [Orabug: 40041774] {CVE-2026-90185}
- null_blk: reject per-device queue resize for shared tag set (Zizhi Wo) [Orabug: 40041778] {CVE-2026-90186}
- null_blk: free zones array on device power-off (Zizhi Wo) [Orabug: 40041782] {CVE-2026-90187}
- null_blk: free global tag_set on init error path (Zizhi Wo) [Orabug: 40041786] {CVE-2026-90188}
- null_blk: register configfs subsystem after creating default devices (Zizhi Wo) [Orabug: 40041791] {CVE-2026-90189}
- null_blk: use DEFINE_MUTEX for the file-scope mutex (Zizhi Wo) [Orabug: 40041796] {CVE-2026-90190}
- mailbox: pcc: Fix command timeout due to missed interrupt (Huisong Li)
- Revert 'mailbox/pcc: support mailbox management of the shared buffer' (Sudeep Holla)
- mailbox/pcc: support mailbox management of the shared buffer (Adam Young)
- mailbox: pcc: Always map the shared memory communication address (Sudeep Holla)
- mailbox: rockchip: disable pclk on probe failure and unbind (Linmao Li)
- mailbox: qcom-cpucp: handle NULL data in send_data callback (Jia Yang)
- mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (Jia Yang)
- perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() (Arnaldo Carvalho de Melo)
- perf dso: Use stored fd error instead of stale errno in file_read() and file_size() (Arnaldo Carvalho de Melo)
- perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() (Arnaldo Carvalho de Melo)
- sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry (Tao Cui)
- crypto: lskcipher - propagate errors from unaligned crypt (Karl Mehltretter)
- crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (Zhushuai Yin)
- bpf: Fix pending_pos walk on 32-bit ring position wrap (Israel Tellez Garcia)
- ACPI: scan: fix bus ID cleanup on device_add() failures (Hongyan Xu) [Orabug: 40041803] {CVE-2026-90194}
- ring-buffer: Remove trace_buffer::cpus (Vincent Donnefort)
- riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args (Pu Lehui)
- HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU (Lin Xianglin)
- ASoC: SOF: validate topology volume range before allocation (Pengpeng Hou) [Orabug: 40041809] {CVE-2026-90196}
- tracing: Have trace_event_update_all() only handle module that is loading (Steven Rostedt)
- tracing: Remove '__attribute__()' from the type field of event format (Masami Hiramatsu)
- ALSA: core: Fix use-after-free in snd_card_do_free() (Aleksandr Nogikh) [Orabug: 40041814] {CVE-2026-90198}
- fs/ntfs3: reject out-of-range evcn in mi_enum_attr() (Zhan Xusheng)
- fs/ntfs3: fix integer overflow in MFT cluster validation (Zhan Xusheng)
- net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race (Jijie Shao) [Orabug: 40041824] {CVE-2026-90201}
- scsi: ufs: core: Set task state before io_schedule_timeout() (Bart Van Assche)
- scsi: ufs: core: Remove redundant host_lock calls around UTMRLDBR (Avri Altman)
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Chandrakanth Patil) [Orabug: 40041828] {CVE-2026-90202}
- selftests/bpf: Fix for veristat file/prog filters processing (Eduard Zingerman)
- Squashfs: check block offset is not negative (Phillip Lougher) [Orabug: 40041834] {CVE-2026-90203}
- ocfs2: fix circular locking dependency in ocfs2_init_acl() (Krystian Kaniewski) [Orabug: 40072806] {CVE-2026-93252}
- bpftool: Fix double close in map dump (Yuan Chen)
- x86/pkeys: Fix pkey_alloc() return value when pkeys are not supported (Bijan Tabatabai)
- selftests/cgroup: Preserve CPU hotplug write errors (Rui Qi)
- selftest/cgroup: Clean up and restructure test_cpuset_prs.sh (Waiman Long)
- selftest/cgroup: Update test_cpuset_prs.sh to use | as effective CPUs and state separator (Waiman Long)
- cgroup/cpuset: Remove remote_partition_check() & make update_cpumasks_hier() handle remote partition (Waiman Long)
- cgroup/cpuset: Fix spelling errors in file kernel/cgroup/cpuset.c (Everest K C )
- ALSA: seq: midi: Serialize input teardown with event_input (John Keeping) [Orabug: 40041851] {CVE-2026-90207}
- clocksource/drivers/armada: Unwind timer clock on init failure (Yuho Choi)
- clocksource/drivers/clps711x: Do not unmap clocksource MMIO (Guangshuo Li)
- s390/debug: Fix deadlock during unregister (Peter Oberparleiter)
- xenbus: Unregister reboot notifier on init failure (Yuho Choi)
- power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (Henrik Grimler)
- power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (Henrik Grimler)
- power: supply: bq27xxx: bq27520g4: fix REG_TTES address (Henrik Grimler)
- power: supply: bd99954: Drop bad register fields (Matti Vaittinen)
- PCI/ASPM: Disable/restore ASPM on every function for multi-function devices (Krishna Chaitanya Chundru)
- PCI/ASPM: Cache L0s/L1 Supported so advertised link states can be overridden (Bjorn Helgaas)
- spi: img-spfi: don't disable runtime PM on DMA deferred probe (Felix Gu)
- selftests/bpf: vmtest.sh: Preserve command quoting when running in the VM (Vineet Gupta)
- selftests: harness: Mark test fixture objects __maybe_unused (David Matlack)
- selftests: harness: Restore order of test functions (Thomas Weissschuh)
- bpf, s390: Clear fetch destination on faulting arena atomic (Daniel Borkmann)
- kunit: tool: fix _list_tests filtering wrong variable when list has TAP prefix (Mohammad Abu-Khader)
- super: fix dying superblock warning messages (Karl Mehltretter)
- PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore (Krishna Chaitanya Chundru)
- firewire: core: fix memory leak in error path of build_tree() (Takashi Sakamoto) [Orabug: 40041872] {CVE-2026-90213}
- firewire: core: validate parent port count before allocating nodes in build_tree() (Takashi Sakamoto)
- firewire: core: consolidate port counting in build_tree() (Takashi Sakamoto)
- firewire: core: add KUnit tests for failure of tree building (Takashi Sakamoto)
- firewire: core: add KUnit tests for successful tree building (Takashi Sakamoto)
- firewire: core: add KUnit test skeleton for node tree (Takashi Sakamoto)
- UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC (Ran Hongyun)
- ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (Rosen Penev)
- mtd: ubi: Release device reference on busy detach (Yuho Choi) [Orabug: 40041880] {CVE-2026-90215}
- ubi: Fix rollback for explicit UBI device numbers (Yuho Choi) [Orabug: 40041882] {CVE-2026-90216}
- UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs (Zhihao Cheng)
- UBI: Preserve torture flag when rescheduling failed erasures (Zhihao Cheng)
- ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (Liangcheng Wang)
- ASoC: pxa: Use devm_clk_get_optional() for extclk clock (Bui Duc Phuc)
- ice: clear the default forwarding VSI rule when releasing a VSI (Petr Oros)
- RDMA/cma: Fix WARNING in res_to_rt (Zhu Yanjun) [Orabug: 40041893] {CVE-2026-90218}
- RDMA/cxgb4: Free debugfs on registration failure (Fan Wu) [Orabug: 40041897] {CVE-2026-90219}
- dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (Guangshuo Li)
- nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (Yun Zhou)
- nfc: digital: Do not dump a NULL response in command completion (Linmao Li)
- nfc: pn533: hold a reference to the request skb during send_frame (Yinhao Hu)
- nfc: llcp: bound SNL TLV parsing to the skb and add length checks (Doruk Tan Ozturk)
- nfc: nci: fix double completion race in nci_data_exchange_complete (Zhenghang Xiao)
- nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (Breno Leitao)
- nfc: llcp: avoid userspace overflow on invalid optlen (Breno Leitao)
- nvme: reject passthrough of driver-managed Set Features (Chao Shi)
- nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (Yang Xiuwei) [Orabug: 40041932] {CVE-2026-90227}
- nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() (Guixin Liu) [Orabug: 40041939] {CVE-2026-90228}
- nvme-apple: Drop the PRP null check chicken bit (Sven Peter)
- nvme: apple: Add Apple A11 support (Nick Chan)
- nvme-apple: Never set the opcode in the NVMMU TCB (Sven Peter)
- nvme-apple: Don't set a DMA direction for commands without a data transfer (Sven Peter)
- nvme-apple: Destroy the admin queue on removal (Sven Peter)
- nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() (Guixin Liu) [Orabug: 40041949] {CVE-2026-90230}
- nvme: Add the DHCHAP maximum HD IDs (Alistair Francis)
- nvme: introduce change ptpl and iekey definition (Guixin Liu)
- nvme: add reservation command's defines (Guixin Liu)
- s390/irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN (Ilya Leoshkevich)
- s390: Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT (Coiby Xu)
- integrity: Make arch_ima_get_secureboot integrity-wide (Coiby Xu)
- powerpc: Use str_enabled_disabled() helper function (Thorsten Blum)
- powerpc/vdso: Add a page for non-time data (Christophe Leroy)
- ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (Jorijn van der Graaf)
- spi: sprd-adi: Fix probe succeeding without registering the controller (Babanpreet Singh)
- phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy (Esteban Urrutia)
- phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms (Abel Vesa)
- phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings (Wesley Cheng)
- phy: qualcomm: Update the QMP clamp register for V6 (Wesley Cheng)
- phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for regulator setup (Faisal Hassan)
- phy: qcom: qmp-combo: Add new PHY sequences for SM8750 (Wesley Cheng)
- phy: qualcomm: qmp-combo: add support for SAR2130P (Dmitry Baryshkov)
- phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (Esteban Urrutia)
- iommu/amd: Fix incorrect device ID in invalid PASID error message (Vasant Hegde)
- powerpc/configs: enable CONFIG_RAS to fix EDAC support (Michael Walle)
- sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE (Runyu Xiao) [Orabug: 40041973] {CVE-2026-90235}
- SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 (Weiming Shi) [Orabug: 40033068] {CVE-2026-89784}
- arm64: Disable KCSAN instrumentation in delay.o (Marco Elver)
- xdrgen: Fix opaque and string encoders for unbounded members (Chuck Lever)
- xdrgen: Do not declare union XDR functions in the definitions header (Chuck Lever)
- xdrgen: Address some checkpatch whitespace complaints (Chuck Lever)
- xdrgen: Implement big-endian enums (Chuck Lever)
- xdrgen: Rename 'enum yada' types as just 'yada' (Chuck Lever)
- m68k: Fix backtraces for non-running tasks (Karl Mehltretter)
- iommu/vt-d: Tear down scalable-mode context on probe failure (Lu Baolu) [Orabug: 40041987] {CVE-2026-90241}
- iommu/vt-d: Clear Present bit before tearing down copied context entry (Lu Baolu) [Orabug: 40041992] {CVE-2026-90243}
- iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes)
- fbdev: kyro: Validate overlay viewport coordinates (Danila Chernetsov)
- fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (Myeonghun Pak)
- perf synthetic-events: Fix divide by zero in perf_event__synthesize_threads (Ian Rogers)
- perf python: Check counts_values size in set_values (Ian Rogers)
- perf python: Add support for 'struct perf_counts_values' to return counter data (Gautam Menghani)
- perf python: Remove python 2 scripting support (Ian Rogers)
- perf test: Fix skiplist leak in cmd_test (Ian Rogers)
- perf test: Support dynamic test suites with setup callback and private data (Ian Rogers)
- perf test: Send list output to stdout rather than stderr (Ian Rogers)
- perf test: Rename functions and variables for better clarity (Ian Rogers)
- perf test: Sort tests placing exclusive tests last (Ian Rogers)
- perf test: Add a signal handler to kill forked child processes (Ian Rogers)
- perf test: Run parallel tests in two passes (Ian Rogers)
- perf test: Add a signal handler around running a test (Ian Rogers)
- perf test: Display number of active running tests (Ian Rogers)
- perf test: Introduce workloads__for_each() (Arnaldo Carvalho de Melo)
- perf synthetic-events: Fix uninitialized pthread_join (Ian Rogers)
- perf stat: Fix evsel_list leak in cmd_stat (Ian Rogers)
- ARM: dts: helios4: add SATA regulator supplies (Rosen Penev)
- ARM: dts: helios4: add vcc-supply to GPIO expander (Rosen Penev)
- ARM: dts: helios4: add vcc-supply to EEPROM (Rosen Penev)
- arm64: dts: turris-mox: fix usb3 phys (Tomas Macholda)
- riscv: cpufeature: Clarify ISA spec version for canonical order (Guodong Xu)
- net/sched: cls_api: fix teardown of an adopted proto on insert-race loss (Victor Nogueira) [Orabug: 40042004] {CVE-2026-90248}
- iio: light: gp2ap002: re-enable irq if runtime suspend fails (Nikhil Gautam)
- iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes (Nikhil Gautam)
- Bluetooth: MSFT: validate evt_prefix_len against the response length (Ali Ahmet Memis)
- Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is negative (Guangshuo Li)
- Bluetooth: btmtk: add MT7902 SDIO support (Sean Wang)
- Bluetooth: btmtk: add MT7902 MCU support (Sean Wang)
- mmc: sdio: add MediaTek MT7902 SDIO device ID (Sean Wang)
- Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (Linmao Li) [Orabug: 40042019] {CVE-2026-90253}
- Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (Linmao Li) [Orabug: 40042022] {CVE-2026-90254}
- Bluetooth: hci_conn: fix the SCO setup context lifetime (Linmao Li) [Orabug: 40042026] {CVE-2026-90255}
- Bluetooth: btintel: Fix diagnostics event detection (Zijun Hu)
- Bluetooth: virtio_bt: avoid OOB read of build info string (Hyeongjun An)
- btrfs: retry verity reads for not-uptodate Merkle folios (Chenyichong) [Orabug: 40042045] {CVE-2026-90262}
- scsi: sd: Fix sd_done() sense handling condition (Yang Xiuwei)
- perf trace-event: Fix integer truncation in do_read() and skip() (Tanushree Shah)
- Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices (Zijun Hu)
- Bluetooth: btusb: Record matched usb_device_id into btusb_data (Zijun Hu)
- Bluetooth: btusb: refactor endpoint lookup (Johan Hovold)
- Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (Zijun Hu)
- Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (Zijun Hu)
- sched/fair: Check CPU capacity before comparing group types during load balance (Ricardo Neri)
- ACPI: video: Release PCI device reference after lookup (Yuho Choi)
- regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (Kamal Wadhwa)
- coresight: etm4x: fix leaked trace id (Levi Yun)
- coresight: etm4x: fix underflow for usage of (nrseqstate - 1) (Levi Yun) [Orabug: 40042070] {CVE-2026-90274}
- coresight: Change syncfreq to be a u8 (James Clark)
- coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() (Levi Yun)
- md/raid1: don't set array_frozen in raid1_takeover() (Bruce Johnston) [Orabug: 40042074] {CVE-2026-90275}
- md: avoid stale clone I/O accounting timestamps (Yu Kuai)
- md/raid5: round bitmap stripes with sector division (Yu Kuai) [Orabug: 40042080] {CVE-2026-90279}
- phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads (Mohd Ayaan Anwar)
- phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() (Russell King)
- soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (Linkai Gong)
- hugetlbfs: release subpool on fill_super failure (Chenyichong) [Orabug: 40042090] {CVE-2026-90283}
- pinctrl: rockchip: Reset the pin count when recalculating SoC data (Simon Glass)
- firmware_loader: do not queue completed sysfs fallback requests (Mukesh Ojha) [Orabug: 40042094] {CVE-2026-90284}
- scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path (Manish Rangankar) [Orabug: 40042098] {CVE-2026-90285}
- drm/amdgpu/gfx6: Use PFP on the compute queues too (Timur Kristof)
- drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (Timur Kristof)
- perf trace-event: Fix buffer overflow in read_string() (Tanushree Shah)
- phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (Gerald Loacker)
- phy: sunplus: fix error handling in sp_uphy_init() (Felix Gu)
- arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node (Meghana Malladi)
- ext4: fix spurious message about orphan cleanup on RO fs (Jan Kara)
- drm/amdgpu/gfx6: Fixup emit_cntxcntl() (Timur Kristof)
- mfd: iqs62x: Reject zero-length firmware records (Pengpeng Hou)
- mfd: rave-sp: validate received frame payload lengths (Pengpeng Hou)
- arm64: hibernate: Restore DAIF state on error (Vladimir Murzin) [Orabug: 40042116] {CVE-2026-90290}
- arm64: hibernate: mask DAIF before restoring hibernated kernel (Ada Couprie Diaz) [Orabug: 40072825] {CVE-2026-93256}
- wifi: mac80211: skip default WMM setup for AP_VLAN links (Felix Fietkau)
- RDMA/erdma: restrict the driver to little-endian systems (Leon Romanovsky)
- module/dups: Fix use-after-free in kmod_dup_req lifetime handling (Petr Pavlu)
- module/dups: Inform duplicate requests about the result directly (Petr Pavlu)
- module: use strscpy() to copy module names in stats and dup tracking (Naveen Kumar Chaudhary)
- module: replace use of system_wq with system_dfl_wq (Marco Crivellari)
- RDMA/siw: Fix use-after-free in siw_accept() (Shuangpeng Bai)
- IB/isert: post the full-feature receive buffers after session registration (Yehyeong Lee) [Orabug: 40042125] {CVE-2026-90293}
- IB/isert: delay the final Login Response until the session is registered (Yehyeong Lee) [Orabug: 40042129] {CVE-2026-90294}
- cpufreq: imx6q: fix out-of-bounds write when probed more than once (Karl Mehltretter)
- cpufreq: imx6q: fix devres accumulation across driver rebind (Karl Mehltretter)
- drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (Jernej Skrabec)
- drm/sun4i: dw-hdmi: Drop TCON TOP port reference (Jernej Skrabec)
- drm/sun4i: tcon: Drop remote endpoint reference (Jernej Skrabec)
- drm/sun4i: crtc: Propagate layer initialization error (Jernej Skrabec)
- drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (Jernej Skrabec)
- drm/sun4i: tcon: Drop TCON TOP device reference (Jernej Skrabec)
- drm/sun4i: tcon: Set output mux for DSI and LVDS (Jernej Skrabec)
- of: property: add of_graph_get_next_port_endpoint() (Kuninori Morimoto)
- of: property: add of_graph_get_next_port() (Kuninori Morimoto)
- drm/sun4i: vi scaler: Fix coefficient selection (Jernej Skrabec)
- clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 (Alexey Charkov)
- ocfs2: synchronize heartbeat callbacks with o2net teardown (Cen Zhang) [Orabug: 40042162] {CVE-2026-90302}
- ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults (Yuanbin Xie)
- ARM: 9481/2: breakpoint: CFI breakpoints only on demand (Linus Walleij)
- RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ (Yehyeong Lee) [Orabug: 40042181] {CVE-2026-90307}
- RDMA/erdma: Hold QP references for AE and CM processing (Cheng Xu) [Orabug: 40042186] {CVE-2026-90308}
- RDMA/erdma: Hold CQ references when processing EQ events (Cheng Xu)
- modpost: prevent leak when early return no suffix .o in read_symbols() (Robertus Diawan Chris)
- scripts/tags.sh: Prevent binary files appearing in cscope.files (Sergei Litvin)
- arm64: dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies (Manivannan Sadhasivam)
- arm64: dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies (Manivannan Sadhasivam)
- selftests/mm: fix ternary operator precedence in ksm_tests (Sayali Patil)
- selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes (Sayali Patil)
- selftests/mm: ksm_tests: use kselftest framework (Mike Rapoport)
- ksm_tests: skip hugepage test when Transparent Hugepages are disabled (Li Wang)
- selftests/mm: add new test cases to the migration test (Donet Tom)
- bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed (Pu Lehui) [Orabug: 40042198] {CVE-2026-90313}
- remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() (Mukesh Ojha) [Orabug: 40042201] {CVE-2026-90314}
- remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() (Mukesh Ojha)
- remoteproc: Move resource table data structure to its own header (Mukesh Ojha)
- arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC (Imran Shaik)
- drm/omap: dsi: Do not copy isr table (Andreas Kemnade) [Orabug: 40042210] {CVE-2026-90316}
...


Related CVEs


CVE-2025-21817
CVE-2025-22108
CVE-2025-38205
CVE-2025-38206
CVE-2025-38266
CVE-2025-38525
CVE-2025-38621
CVE-2025-39925
CVE-2025-40074
CVE-2025-40102
CVE-2025-40210
CVE-2025-68299
CVE-2025-71142
CVE-2026-100070
CVE-2026-100071
CVE-2026-100075
CVE-2026-100079
CVE-2026-23459
CVE-2026-43197
CVE-2026-43198
CVE-2026-43344
CVE-2026-45897
CVE-2026-45901
CVE-2026-45963
CVE-2026-53078
CVE-2026-53089
CVE-2026-53090
CVE-2026-53092
CVE-2026-53102
CVE-2026-53113
CVE-2026-53250
CVE-2026-53313
CVE-2026-53364
CVE-2026-64031
CVE-2026-64058
CVE-2026-64205
CVE-2026-64210
CVE-2026-64216
CVE-2026-64290
CVE-2026-64427
CVE-2026-64507
CVE-2026-64520
CVE-2026-64562
CVE-2026-64563
CVE-2026-64564
CVE-2026-64567
CVE-2026-64568
CVE-2026-64569
CVE-2026-64570
CVE-2026-64571
CVE-2026-64572
CVE-2026-64574
CVE-2026-64575
CVE-2026-64576
CVE-2026-64577
CVE-2026-64579
CVE-2026-64580
CVE-2026-64581
CVE-2026-64586
CVE-2026-68082
CVE-2026-68093
CVE-2026-68096
CVE-2026-68102
CVE-2026-68106
CVE-2026-68107
CVE-2026-68108
CVE-2026-68110
CVE-2026-68111
CVE-2026-68112
CVE-2026-68113
CVE-2026-68115
CVE-2026-68116
CVE-2026-68117
CVE-2026-68118
CVE-2026-68119
CVE-2026-68121
CVE-2026-68123
CVE-2026-68125
CVE-2026-68126
CVE-2026-68128
CVE-2026-68129
CVE-2026-68131
CVE-2026-68132
CVE-2026-68133
CVE-2026-68136
CVE-2026-68138
CVE-2026-68139
CVE-2026-68142
CVE-2026-68143
CVE-2026-68145
CVE-2026-68146
CVE-2026-68148
CVE-2026-68149
CVE-2026-68150
CVE-2026-68153
CVE-2026-68154
CVE-2026-68155
CVE-2026-68156
CVE-2026-68157
CVE-2026-68158
CVE-2026-68159
CVE-2026-68160
CVE-2026-68161
CVE-2026-68162
CVE-2026-68164
CVE-2026-68165
CVE-2026-68166
CVE-2026-68169
CVE-2026-68180
CVE-2026-68181
CVE-2026-68184
CVE-2026-68186
CVE-2026-68187
CVE-2026-68188
CVE-2026-68189
CVE-2026-68192
CVE-2026-68193
CVE-2026-68194
CVE-2026-68197
CVE-2026-68198
CVE-2026-68199
CVE-2026-68200
CVE-2026-68201
CVE-2026-68202
CVE-2026-68205
CVE-2026-68206
CVE-2026-68212
CVE-2026-68213
CVE-2026-68214
CVE-2026-68216
CVE-2026-68217
CVE-2026-68218
CVE-2026-68226
CVE-2026-68227
CVE-2026-68234
CVE-2026-68235
CVE-2026-68236
CVE-2026-68243
CVE-2026-68244
CVE-2026-68245
CVE-2026-68246
CVE-2026-68247
CVE-2026-68248
CVE-2026-68249
CVE-2026-68250
CVE-2026-68251
CVE-2026-68252
CVE-2026-68253
CVE-2026-68254
CVE-2026-68255
CVE-2026-68256
CVE-2026-68257
CVE-2026-68259
CVE-2026-68264
CVE-2026-68266
CVE-2026-68267
CVE-2026-68269
CVE-2026-68271
CVE-2026-68272
CVE-2026-68273
CVE-2026-68276
CVE-2026-68277
CVE-2026-68278
CVE-2026-68279
CVE-2026-68284
CVE-2026-68286
CVE-2026-68287
CVE-2026-68288
CVE-2026-68289
CVE-2026-68293
CVE-2026-68294
CVE-2026-68296
CVE-2026-68297
CVE-2026-68299
CVE-2026-68300
CVE-2026-68301
CVE-2026-68303
CVE-2026-68304
CVE-2026-68307
CVE-2026-68309
CVE-2026-68310
CVE-2026-68311
CVE-2026-68313
CVE-2026-68315
CVE-2026-68317
CVE-2026-68318
CVE-2026-68319
CVE-2026-68320
CVE-2026-68325
CVE-2026-68326
CVE-2026-68328
CVE-2026-68329
CVE-2026-68336
CVE-2026-68337
CVE-2026-68338
CVE-2026-68339
CVE-2026-68343
CVE-2026-68346
CVE-2026-68348
CVE-2026-68349
CVE-2026-68350
CVE-2026-68351
CVE-2026-68352
CVE-2026-68353
CVE-2026-68355
CVE-2026-68362
CVE-2026-68363
CVE-2026-68365
CVE-2026-68372
CVE-2026-68373
CVE-2026-68374
CVE-2026-68376
CVE-2026-68377
CVE-2026-68386
CVE-2026-68388
CVE-2026-68391
CVE-2026-68392
CVE-2026-68394
CVE-2026-68398
CVE-2026-68402
CVE-2026-68403
CVE-2026-68405
CVE-2026-68406
CVE-2026-68407
CVE-2026-68410
CVE-2026-68411
CVE-2026-68413
CVE-2026-68414
CVE-2026-68416
CVE-2026-68419
CVE-2026-68422
CVE-2026-68425
CVE-2026-68427
CVE-2026-68428
CVE-2026-68429
CVE-2026-68430
CVE-2026-68432
CVE-2026-68433
CVE-2026-68439
CVE-2026-68442
CVE-2026-68444
CVE-2026-68445
CVE-2026-68446
CVE-2026-68450
CVE-2026-72015
CVE-2026-72017
CVE-2026-72030
CVE-2026-72032
CVE-2026-72040
CVE-2026-72045
CVE-2026-72046
CVE-2026-72051
CVE-2026-72065
CVE-2026-72070
CVE-2026-72101
CVE-2026-72103
CVE-2026-72111
CVE-2026-72113
CVE-2026-72114
CVE-2026-72115
CVE-2026-72116
CVE-2026-72117
CVE-2026-72118
CVE-2026-72119
CVE-2026-72121
CVE-2026-72124
CVE-2026-72125
CVE-2026-72130
CVE-2026-72137
CVE-2026-72175
CVE-2026-72183
CVE-2026-72213
CVE-2026-72244
CVE-2026-72253
CVE-2026-72254
CVE-2026-72299
CVE-2026-72305
CVE-2026-72334
CVE-2026-72402
CVE-2026-72413
CVE-2026-72438
CVE-2026-72496
CVE-2026-74258
CVE-2026-74268
CVE-2026-74289
CVE-2026-74291
CVE-2026-74294
CVE-2026-74334
CVE-2026-74352
CVE-2026-74425
CVE-2026-74436
CVE-2026-74440
CVE-2026-74441
CVE-2026-74442
CVE-2026-74443
CVE-2026-74444
CVE-2026-74445
CVE-2026-74446
CVE-2026-74447
CVE-2026-74448
CVE-2026-74450
CVE-2026-74453
CVE-2026-74454
CVE-2026-74455
CVE-2026-74456
CVE-2026-74457
CVE-2026-74458
CVE-2026-74460
CVE-2026-74464
CVE-2026-74465
CVE-2026-74469
CVE-2026-74470
CVE-2026-74471
CVE-2026-74472
CVE-2026-74473
CVE-2026-74474
CVE-2026-74475
CVE-2026-74476
CVE-2026-74479
CVE-2026-74480
CVE-2026-74481
CVE-2026-74482
CVE-2026-74483
CVE-2026-74484
CVE-2026-74485
CVE-2026-74486
CVE-2026-74487
CVE-2026-74488
CVE-2026-74490
CVE-2026-74492
CVE-2026-74495
CVE-2026-74496
CVE-2026-74497
CVE-2026-74498
CVE-2026-74499
CVE-2026-74500
CVE-2026-74501
CVE-2026-74502
CVE-2026-74504
CVE-2026-74505
CVE-2026-74507
CVE-2026-74508
CVE-2026-74509
CVE-2026-74510
CVE-2026-74512
CVE-2026-74515
CVE-2026-74516
CVE-2026-74517
CVE-2026-74518
CVE-2026-74519
CVE-2026-74523
CVE-2026-74531
CVE-2026-74532
CVE-2026-74535
CVE-2026-74536
CVE-2026-74540
CVE-2026-74541
CVE-2026-74543
CVE-2026-74546
CVE-2026-74547
CVE-2026-74548
CVE-2026-74549
CVE-2026-74550
CVE-2026-74552
CVE-2026-74553
CVE-2026-74555
CVE-2026-74556
CVE-2026-74557
CVE-2026-74564
CVE-2026-74565
CVE-2026-74566
CVE-2026-74567
CVE-2026-74569
CVE-2026-74572
CVE-2026-74574
CVE-2026-74575
CVE-2026-74577
CVE-2026-74579
CVE-2026-74580
CVE-2026-74581
CVE-2026-74582
CVE-2026-74583
CVE-2026-74585
CVE-2026-74586
CVE-2026-74587
CVE-2026-74588
CVE-2026-74589
CVE-2026-74590
CVE-2026-74592
CVE-2026-74594
CVE-2026-74595
CVE-2026-74597
CVE-2026-74598
CVE-2026-74599
CVE-2026-74601
CVE-2026-74602
CVE-2026-74603
CVE-2026-74604
CVE-2026-74606
CVE-2026-74607
CVE-2026-74608
CVE-2026-74609
CVE-2026-74610
CVE-2026-74612
CVE-2026-74613
CVE-2026-74614
CVE-2026-74615
CVE-2026-74616
CVE-2026-74618
CVE-2026-74619
CVE-2026-74620
CVE-2026-74621
CVE-2026-74622
CVE-2026-74623
CVE-2026-74624
CVE-2026-74625
CVE-2026-74626
CVE-2026-74628
CVE-2026-74630
CVE-2026-74632
CVE-2026-74634
CVE-2026-74635
CVE-2026-74636
CVE-2026-74637
CVE-2026-74641
CVE-2026-74642
CVE-2026-74644
CVE-2026-74653
CVE-2026-74654
CVE-2026-74656
CVE-2026-74657
CVE-2026-74658
CVE-2026-74660
CVE-2026-74661
CVE-2026-74662
CVE-2026-74663
CVE-2026-74664
CVE-2026-74665
CVE-2026-74666
CVE-2026-74667
CVE-2026-74668
CVE-2026-74669
CVE-2026-74670
CVE-2026-74671
CVE-2026-74672
CVE-2026-74673
CVE-2026-74675
CVE-2026-74676
CVE-2026-74677
CVE-2026-74678
CVE-2026-74680
CVE-2026-74682
CVE-2026-74683
CVE-2026-74688
CVE-2026-74689
CVE-2026-74691
CVE-2026-74696
CVE-2026-74700
CVE-2026-74701
CVE-2026-74704
CVE-2026-74705
CVE-2026-74710
CVE-2026-74712
CVE-2026-74714
CVE-2026-74717
CVE-2026-74718
CVE-2026-74720
CVE-2026-74722
CVE-2026-74724
CVE-2026-74725
CVE-2026-74726
CVE-2026-74730
CVE-2026-74732
CVE-2026-74735
CVE-2026-74736
CVE-2026-74739
CVE-2026-74740
CVE-2026-74742
CVE-2026-74743
CVE-2026-74744
CVE-2026-74746
CVE-2026-74748
CVE-2026-74753
CVE-2026-80521
CVE-2026-80525
CVE-2026-80527
CVE-2026-80528
CVE-2026-80529
CVE-2026-80530
CVE-2026-80531
CVE-2026-80532
CVE-2026-80533
CVE-2026-80534
CVE-2026-80535
CVE-2026-80536
CVE-2026-80539
CVE-2026-80540
CVE-2026-80541
CVE-2026-80557
CVE-2026-80558
CVE-2026-80561
CVE-2026-80569
CVE-2026-80570
CVE-2026-80572
CVE-2026-80574
CVE-2026-80576
CVE-2026-80578
CVE-2026-80585
CVE-2026-80586
CVE-2026-80587
CVE-2026-80589
CVE-2026-80590
CVE-2026-80681
CVE-2026-80686
CVE-2026-80691
CVE-2026-80695
CVE-2026-80700
CVE-2026-80702
CVE-2026-80703
CVE-2026-80704
CVE-2026-80706
CVE-2026-80707
CVE-2026-80711
CVE-2026-80714
CVE-2026-80715
CVE-2026-80716
CVE-2026-80717
CVE-2026-80722
CVE-2026-80723
CVE-2026-80725
CVE-2026-80726
CVE-2026-80727
CVE-2026-80728
CVE-2026-80730
CVE-2026-80731
CVE-2026-80733
CVE-2026-80736
CVE-2026-80737
CVE-2026-80739
CVE-2026-80742
CVE-2026-80744
CVE-2026-80749
CVE-2026-80754
CVE-2026-80755
CVE-2026-80756
CVE-2026-80757
CVE-2026-80759
CVE-2026-80762
CVE-2026-80763
CVE-2026-80764
CVE-2026-80765
CVE-2026-80766
CVE-2026-80767
CVE-2026-80774
CVE-2026-80779
CVE-2026-80780
CVE-2026-80781
CVE-2026-80782
CVE-2026-80783
CVE-2026-80784
CVE-2026-80788
CVE-2026-80789
CVE-2026-80790
CVE-2026-80791
CVE-2026-80792
CVE-2026-80793
CVE-2026-80805
CVE-2026-80806
CVE-2026-80808
CVE-2026-80809
CVE-2026-80812
CVE-2026-80814
CVE-2026-80815
CVE-2026-80819
CVE-2026-80820
CVE-2026-80824
CVE-2026-80825
CVE-2026-80827
CVE-2026-80828
CVE-2026-80829
CVE-2026-80830
CVE-2026-80836
CVE-2026-80837
CVE-2026-80838
CVE-2026-80839
CVE-2026-80840
CVE-2026-80841
CVE-2026-80842
CVE-2026-80843
CVE-2026-80844
CVE-2026-80845
CVE-2026-80847
CVE-2026-80851
CVE-2026-80852
CVE-2026-80854
CVE-2026-80855
CVE-2026-80856
CVE-2026-80860
CVE-2026-80861
CVE-2026-80862
CVE-2026-80863
CVE-2026-80864
CVE-2026-80878
CVE-2026-80887
CVE-2026-80888
CVE-2026-80889
CVE-2026-80890
CVE-2026-80892
CVE-2026-80893
CVE-2026-80894
CVE-2026-80901
CVE-2026-80903
CVE-2026-80904
CVE-2026-80906
CVE-2026-80907
CVE-2026-80908
CVE-2026-80909
CVE-2026-80911
CVE-2026-80912
CVE-2026-80913
CVE-2026-80914
CVE-2026-80915
CVE-2026-80916
CVE-2026-80917
CVE-2026-80918
CVE-2026-80923
CVE-2026-80925
CVE-2026-80930
CVE-2026-80932
CVE-2026-80940
CVE-2026-80941
CVE-2026-80944
CVE-2026-80945
CVE-2026-80947
CVE-2026-80949
CVE-2026-80963
CVE-2026-80964
CVE-2026-80965
CVE-2026-80967
CVE-2026-80969
CVE-2026-80971
CVE-2026-80972
CVE-2026-80973
CVE-2026-80974
CVE-2026-80976
CVE-2026-80977
CVE-2026-80978
CVE-2026-80987
CVE-2026-80988
CVE-2026-80989
CVE-2026-80990
CVE-2026-80994
CVE-2026-80996
CVE-2026-80999
CVE-2026-81000
CVE-2026-81001
CVE-2026-81002
CVE-2026-81005
CVE-2026-81008
CVE-2026-81011
CVE-2026-81012
CVE-2026-81013
CVE-2026-81014
CVE-2026-81017
CVE-2026-89438
CVE-2026-89439
CVE-2026-89440
CVE-2026-89442
CVE-2026-89443
CVE-2026-89444
CVE-2026-89448
CVE-2026-89451
CVE-2026-89453
CVE-2026-89461
CVE-2026-89462
CVE-2026-89469
CVE-2026-89472
CVE-2026-89476
CVE-2026-89477
CVE-2026-89478
CVE-2026-89479
CVE-2026-89480
CVE-2026-89481
CVE-2026-89482
CVE-2026-89483
CVE-2026-89484
CVE-2026-89485
CVE-2026-89487
CVE-2026-89488
CVE-2026-89490
CVE-2026-89491
CVE-2026-89492
CVE-2026-89493
CVE-2026-89494
CVE-2026-89495
CVE-2026-89496
CVE-2026-89501
CVE-2026-89502
CVE-2026-89508
CVE-2026-89510
CVE-2026-89511
CVE-2026-89515
CVE-2026-89524
CVE-2026-89525
CVE-2026-89526
CVE-2026-89530
CVE-2026-89531
CVE-2026-89532
CVE-2026-89533
CVE-2026-89535
CVE-2026-89536
CVE-2026-89538
CVE-2026-89539
CVE-2026-89540
CVE-2026-89541
CVE-2026-89542
CVE-2026-89543
CVE-2026-89544
CVE-2026-89545
CVE-2026-89547
CVE-2026-89548
CVE-2026-89549
CVE-2026-89550
CVE-2026-89551
CVE-2026-89552
CVE-2026-89553
CVE-2026-89554
CVE-2026-89555
CVE-2026-89557
CVE-2026-89558
CVE-2026-89559
CVE-2026-89560
CVE-2026-89561
CVE-2026-89562
CVE-2026-89563
CVE-2026-89564
CVE-2026-89565
CVE-2026-89566
CVE-2026-89567
CVE-2026-89569
CVE-2026-89573
CVE-2026-89574
CVE-2026-89575
CVE-2026-89576
CVE-2026-89579
CVE-2026-89580
CVE-2026-89581
CVE-2026-89582
CVE-2026-89583
CVE-2026-89585
CVE-2026-89586
CVE-2026-89587
CVE-2026-89588
CVE-2026-89589
CVE-2026-89593
CVE-2026-89595
CVE-2026-89596
CVE-2026-89598
CVE-2026-89602
CVE-2026-89603
CVE-2026-89604
CVE-2026-89606
CVE-2026-89607
CVE-2026-89608
CVE-2026-89618
CVE-2026-89625
CVE-2026-89626
CVE-2026-89627
CVE-2026-89628
CVE-2026-89634
CVE-2026-89636
CVE-2026-89640
CVE-2026-89643
CVE-2026-89644
CVE-2026-89645
CVE-2026-89647
CVE-2026-89649
CVE-2026-89650
CVE-2026-89651
CVE-2026-89652
CVE-2026-89653
CVE-2026-89655
CVE-2026-89656
CVE-2026-89657
CVE-2026-89658
CVE-2026-89659
CVE-2026-89660
CVE-2026-89662
CVE-2026-89663
CVE-2026-89666
CVE-2026-89667
CVE-2026-89669
CVE-2026-89671
CVE-2026-89673
CVE-2026-89674
CVE-2026-89676
CVE-2026-89680
CVE-2026-89683
CVE-2026-89684
CVE-2026-89685
CVE-2026-89686
CVE-2026-89688
CVE-2026-89690
CVE-2026-89691
CVE-2026-89693
CVE-2026-89694
CVE-2026-89696
CVE-2026-89698
CVE-2026-89699
CVE-2026-89700
CVE-2026-89702
CVE-2026-89703
CVE-2026-89704
CVE-2026-89706
CVE-2026-89707
CVE-2026-89708
CVE-2026-89710
CVE-2026-89711
CVE-2026-89712
CVE-2026-89713
CVE-2026-89717
CVE-2026-89718
CVE-2026-89719
CVE-2026-89726
CVE-2026-89729
CVE-2026-89731
CVE-2026-89741
CVE-2026-89744
CVE-2026-89746
CVE-2026-89747
CVE-2026-89749
CVE-2026-89751
CVE-2026-89752
CVE-2026-89753
CVE-2026-89755
CVE-2026-89756
CVE-2026-89762
CVE-2026-89763
CVE-2026-89765
CVE-2026-89768
CVE-2026-89771
CVE-2026-89776
CVE-2026-89777
CVE-2026-89778
CVE-2026-89783
CVE-2026-89784
CVE-2026-89786
CVE-2026-89787
CVE-2026-89789
CVE-2026-89793
CVE-2026-89796
CVE-2026-89798
CVE-2026-89799
CVE-2026-89800
CVE-2026-89801
CVE-2026-89802
CVE-2026-89803
CVE-2026-89807
CVE-2026-89816
CVE-2026-89817
CVE-2026-89818
CVE-2026-89819
CVE-2026-89821
CVE-2026-89822
CVE-2026-89823
CVE-2026-89824
CVE-2026-89842
CVE-2026-89843
CVE-2026-89844
CVE-2026-89845
CVE-2026-89846
CVE-2026-89847
CVE-2026-89848
CVE-2026-89849
CVE-2026-89850
CVE-2026-89851
CVE-2026-89852
CVE-2026-89853
CVE-2026-89854
CVE-2026-89855
CVE-2026-89856
CVE-2026-89857
CVE-2026-89858
CVE-2026-89860
CVE-2026-89861
CVE-2026-89863
CVE-2026-89864
CVE-2026-89865
CVE-2026-89872
CVE-2026-89874
CVE-2026-89876
CVE-2026-89877
CVE-2026-89878
CVE-2026-89879
CVE-2026-89880
CVE-2026-89881
CVE-2026-89886
CVE-2026-89890
CVE-2026-89891
CVE-2026-89892
CVE-2026-89893
CVE-2026-89894
CVE-2026-89897
CVE-2026-89899
CVE-2026-89900
CVE-2026-89927
CVE-2026-89929
CVE-2026-89930
CVE-2026-89931
CVE-2026-89932
CVE-2026-89940
CVE-2026-89941
CVE-2026-89942
CVE-2026-89944
CVE-2026-89945
CVE-2026-89947
CVE-2026-89948
CVE-2026-89950
CVE-2026-89951
CVE-2026-89952
CVE-2026-89953
CVE-2026-89965
CVE-2026-89968
CVE-2026-89969
CVE-2026-89970
CVE-2026-89973
CVE-2026-89974
CVE-2026-89975
CVE-2026-89979
CVE-2026-89982
CVE-2026-89983
CVE-2026-89984
CVE-2026-89986
CVE-2026-89988
CVE-2026-89989
CVE-2026-89990
CVE-2026-89995
CVE-2026-89997
CVE-2026-89998
CVE-2026-89999
CVE-2026-90000
CVE-2026-90003
CVE-2026-90007
CVE-2026-90011
CVE-2026-90012
CVE-2026-90015
CVE-2026-90025
CVE-2026-90031
CVE-2026-90032
CVE-2026-90033
CVE-2026-90034
CVE-2026-90035
CVE-2026-90036
CVE-2026-90037
CVE-2026-90039
CVE-2026-90041
CVE-2026-90042
CVE-2026-90049
CVE-2026-90050
CVE-2026-90053
CVE-2026-90054
CVE-2026-90055
CVE-2026-90057
CVE-2026-90058
CVE-2026-90060
CVE-2026-90062
CVE-2026-90063
CVE-2026-90067
CVE-2026-90068
CVE-2026-90070
CVE-2026-90071
CVE-2026-90072
CVE-2026-90073
CVE-2026-90075
CVE-2026-90076
CVE-2026-90078
CVE-2026-90088
CVE-2026-90091
CVE-2026-90092
CVE-2026-90101
CVE-2026-90102
CVE-2026-90103
CVE-2026-90109
CVE-2026-90110
CVE-2026-90112
CVE-2026-90114
CVE-2026-90115
CVE-2026-90119
CVE-2026-90125
CVE-2026-90126
CVE-2026-90128
CVE-2026-90130
CVE-2026-90135
CVE-2026-90137
CVE-2026-90138
CVE-2026-90139
CVE-2026-90140
CVE-2026-90141
CVE-2026-90147
CVE-2026-90148
CVE-2026-90150
CVE-2026-90151
CVE-2026-90157
CVE-2026-90159
CVE-2026-90160
CVE-2026-90178
CVE-2026-90180
CVE-2026-90184
CVE-2026-90185
CVE-2026-90186
CVE-2026-90187
CVE-2026-90188
CVE-2026-90189
CVE-2026-90190
CVE-2026-90194
CVE-2026-90196
CVE-2026-90198
CVE-2026-90201
CVE-2026-90202
CVE-2026-90203
CVE-2026-90207
CVE-2026-90213
CVE-2026-90215
CVE-2026-90216
CVE-2026-90218
CVE-2026-90219
CVE-2026-90220
CVE-2026-90227
CVE-2026-90228
CVE-2026-90230
CVE-2026-90235
CVE-2026-90241
CVE-2026-90243
CVE-2026-90248
CVE-2026-90253
CVE-2026-90254
CVE-2026-90255
CVE-2026-90262
CVE-2026-90274
CVE-2026-90275
CVE-2026-90279
CVE-2026-90283
CVE-2026-90284
CVE-2026-90285
CVE-2026-90290
CVE-2026-90293
CVE-2026-90294
CVE-2026-90302
CVE-2026-90307
CVE-2026-90308
CVE-2026-90313
CVE-2026-90314
CVE-2026-90316
CVE-2026-90318
CVE-2026-90322
CVE-2026-90325
CVE-2026-90329
CVE-2026-90334
CVE-2026-90344
CVE-2026-90352
CVE-2026-90353
CVE-2026-90354
CVE-2026-90357
CVE-2026-90358
CVE-2026-90360
CVE-2026-90361
CVE-2026-90362
CVE-2026-90364
CVE-2026-90368
CVE-2026-90372
CVE-2026-90373
CVE-2026-90375
CVE-2026-90380
CVE-2026-90382
CVE-2026-90383
CVE-2026-90385
CVE-2026-90387
CVE-2026-90388
CVE-2026-90389
CVE-2026-90390
CVE-2026-90392
CVE-2026-90393
CVE-2026-90395
CVE-2026-90397
CVE-2026-90398
CVE-2026-90399
CVE-2026-90400
CVE-2026-90402
CVE-2026-90403
CVE-2026-90404
CVE-2026-90407
CVE-2026-90411
CVE-2026-90413
CVE-2026-90414
CVE-2026-90415
CVE-2026-90416
CVE-2026-90431
CVE-2026-90434
CVE-2026-90435
CVE-2026-92477
CVE-2026-92481
CVE-2026-92484
CVE-2026-92489
CVE-2026-92494
CVE-2026-92495
CVE-2026-92496
CVE-2026-92497
CVE-2026-92498
CVE-2026-92501
CVE-2026-92502
CVE-2026-92504
CVE-2026-92507
CVE-2026-92508
CVE-2026-92509
CVE-2026-92510
CVE-2026-92511
CVE-2026-92512
CVE-2026-92515
CVE-2026-92521
CVE-2026-92522
CVE-2026-92523
CVE-2026-92524
CVE-2026-92525
CVE-2026-93037
CVE-2026-93039
CVE-2026-93045
CVE-2026-93046
CVE-2026-93048
CVE-2026-93049
CVE-2026-93051
CVE-2026-93053
CVE-2026-93054
CVE-2026-93055
CVE-2026-93056
CVE-2026-93061
CVE-2026-93062
CVE-2026-93064
CVE-2026-93065
CVE-2026-93067
CVE-2026-93070
CVE-2026-93073
CVE-2026-93093
CVE-2026-93097
CVE-2026-93098
CVE-2026-93101
CVE-2026-93102
CVE-2026-93103
CVE-2026-93107
CVE-2026-93108
CVE-2026-93109
CVE-2026-93110
CVE-2026-93117
CVE-2026-93119
CVE-2026-93130
CVE-2026-93137
CVE-2026-93138
CVE-2026-93140
CVE-2026-93145
CVE-2026-93149
CVE-2026-93150
CVE-2026-93151
CVE-2026-93161
CVE-2026-93162
CVE-2026-93163
CVE-2026-93165
CVE-2026-93172
CVE-2026-93173
CVE-2026-93174
CVE-2026-93177
CVE-2026-93178
CVE-2026-93182
CVE-2026-93185
CVE-2026-93186
CVE-2026-93188
CVE-2026-93189
CVE-2026-93190
CVE-2026-93203
CVE-2026-93204
CVE-2026-93205
CVE-2026-93206
CVE-2026-93207
CVE-2026-93209
CVE-2026-93210
CVE-2026-93211
CVE-2026-93212
CVE-2026-93213
CVE-2026-93219
CVE-2026-93222
CVE-2026-93224
CVE-2026-93226
CVE-2026-93228
CVE-2026-93229
CVE-2026-93234
CVE-2026-93239
CVE-2026-93240
CVE-2026-93242
CVE-2026-93247
CVE-2026-93250
CVE-2026-93252
CVE-2026-93256
CVE-2026-93262
CVE-2026-93264
CVE-2026-93268
CVE-2026-93269
CVE-2026-93271
CVE-2026-93274
CVE-2026-93281
CVE-2026-93287
CVE-2026-93288
CVE-2026-93781
CVE-2026-93782
CVE-2026-93783
CVE-2026-93784
CVE-2026-93785
CVE-2026-93787
CVE-2026-93788
CVE-2026-93789
CVE-2026-93790
CVE-2026-93791
CVE-2026-93792
CVE-2026-93793
CVE-2026-93794
CVE-2026-93795
CVE-2026-93796
CVE-2026-93797
CVE-2026-93798
CVE-2026-93799
CVE-2026-93800
CVE-2026-93801
CVE-2026-93802
CVE-2026-93803
CVE-2026-93804
CVE-2026-93805
CVE-2026-93806
CVE-2026-93807
CVE-2026-93808
CVE-2026-93809
CVE-2026-93810
CVE-2026-93813
CVE-2026-93814
CVE-2026-93820
CVE-2026-93822
CVE-2026-93823
CVE-2026-93824
CVE-2026-93825
CVE-2026-93826
CVE-2026-93827
CVE-2026-93828
CVE-2026-93829
CVE-2026-97408
CVE-2026-97409
CVE-2026-97410
CVE-2026-97412
CVE-2026-97415
CVE-2026-97416
CVE-2026-97417
CVE-2026-97419
CVE-2026-97420
CVE-2026-97421
CVE-2026-97425
CVE-2026-97427
CVE-2026-97428
CVE-2026-97429
CVE-2026-97430
CVE-2026-97438
CVE-2026-97440
CVE-2026-97441
CVE-2026-97442
CVE-2026-97443
CVE-2026-97444
CVE-2026-97445
CVE-2026-97446
CVE-2026-97447
CVE-2026-97448
CVE-2026-97449
CVE-2026-97450
CVE-2026-97451
CVE-2026-97452
CVE-2026-97453
CVE-2026-97454
CVE-2026-97455
CVE-2026-97456
CVE-2026-97472
CVE-2026-97473
CVE-2026-97481
CVE-2026-97483
CVE-2026-97484
CVE-2026-97492
CVE-2026-97494
CVE-2026-97495
CVE-2026-97496
CVE-2026-97497
CVE-2026-97500
CVE-2026-97505
CVE-2026-97507
CVE-2026-97508
CVE-2026-97509
CVE-2026-97510
CVE-2026-97516
CVE-2026-97517
CVE-2026-97518
CVE-2026-97520
CVE-2026-97521
CVE-2026-97522
CVE-2026-97523
CVE-2026-97524
CVE-2026-97539
CVE-2026-97540
CVE-2026-97541
CVE-2026-97542
CVE-2026-97543
CVE-2026-97544
CVE-2026-97545
CVE-2026-97546
CVE-2026-97547
CVE-2026-97551
CVE-2026-97552
CVE-2026-97555
CVE-2026-97556
CVE-2026-97557
CVE-2026-97560
CVE-2026-97562
CVE-2026-97564
CVE-2026-97568
CVE-2026-97572
CVE-2026-97573
CVE-2026-97575
CVE-2026-97576
CVE-2026-97583
CVE-2026-97584
CVE-2026-97595
CVE-2026-97596
CVE-2026-97598
CVE-2026-97600
CVE-2026-97601
CVE-2026-97602
CVE-2026-97604
CVE-2026-97605
CVE-2026-97606
CVE-2026-97607
CVE-2026-97608
CVE-2026-97611
CVE-2026-97612
CVE-2026-97613
CVE-2026-97616
CVE-2026-97617
CVE-2026-97899
CVE-2026-97900
CVE-2026-97902
CVE-2026-97904
CVE-2026-97905
CVE-2026-97907
CVE-2026-97917
CVE-2026-97920
CVE-2026-97921
CVE-2026-97922
CVE-2026-97923
CVE-2026-97925
CVE-2026-97929
CVE-2026-97930
CVE-2026-97931
CVE-2026-97936
CVE-2026-97940
CVE-2026-97945
CVE-2026-97951
CVE-2026-97953
CVE-2026-97957
CVE-2026-97958
CVE-2026-97959
CVE-2026-97963
CVE-2026-97964
CVE-2026-97965
CVE-2026-97973
CVE-2026-97976
CVE-2026-97977
CVE-2026-97978
CVE-2026-97979
CVE-2026-97984
CVE-2026-97985
CVE-2026-97986
CVE-2026-97987
CVE-2026-97990
CVE-2026-97991
CVE-2026-97992
CVE-2026-97993
CVE-2026-97994
CVE-2026-97995
CVE-2026-97996
CVE-2026-97998
CVE-2026-98006
CVE-2026-98007
CVE-2026-98008
CVE-2026-98009
CVE-2026-98010
CVE-2026-98011
CVE-2026-98012
CVE-2026-98014
CVE-2026-98015
CVE-2026-98016
CVE-2026-98017
CVE-2026-98020
CVE-2026-98021
CVE-2026-98022
CVE-2026-98023
CVE-2026-98025
CVE-2026-98026
CVE-2026-98027
CVE-2026-98028
CVE-2026-98029
CVE-2026-98030
CVE-2026-98031
CVE-2026-98037
CVE-2026-98039
CVE-2026-98041
CVE-2026-98045
CVE-2026-98046
CVE-2026-98051
CVE-2026-98052
CVE-2026-98054
CVE-2026-98055
CVE-2026-98056
CVE-2026-98057
CVE-2026-98059
CVE-2026-98063
CVE-2026-98064
CVE-2026-98066
CVE-2026-98074
CVE-2026-98075
CVE-2026-98076
CVE-2026-98077
CVE-2026-98078
CVE-2026-98080
CVE-2026-98081
CVE-2026-98082
CVE-2026-98083
CVE-2026-98086
CVE-2026-98088
CVE-2026-98089
CVE-2026-98090
CVE-2026-98091
CVE-2026-98092
CVE-2026-98095
CVE-2026-98096
CVE-2026-98097
CVE-2026-98098
CVE-2026-98102
CVE-2026-98103
CVE-2026-98104
CVE-2026-98107
CVE-2026-98108
CVE-2026-98109
CVE-2026-98110
CVE-2026-98111
CVE-2026-98116
CVE-2026-98122
CVE-2026-98123
CVE-2026-98126
CVE-2026-98127
CVE-2026-98128
CVE-2026-98129
CVE-2026-98130
CVE-2026-98142
CVE-2026-98151
CVE-2026-98152
CVE-2026-98154
CVE-2026-98157
CVE-2026-98158
CVE-2026-98159

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) kernel-uek-6.12.0-207.111.5.1.el9uek.src.rpm5359ad71026575e3c48422ecb333417baed798961a698e2f29fd4f136b38610b-ol9_aarch64_UEKR8
kernel-uek-6.12.0-207.111.5.1.el9uek.aarch64.rpm1915cbd31531bf469152c61e981c5689758ea19df5cb12252bc75eed4841e41a-ol9_aarch64_UEKR8
kernel-uek-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm24d700b84fb27f7f52c2255cc1b33f3b5ec820353ff1eb123ade8243a7c90285-ol9_aarch64_UEKR8
kernel-uek-debug-6.12.0-207.111.5.1.el9uek.aarch64.rpma681be49d3569c9ae964c0afcf66dabe8ebb08e6fa8921f1efa28cc12729b381-ol9_aarch64_UEKR8
kernel-uek-debug-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm2024b27b2e55d7eb5050ae82feee29696ee9db200414c69ee7f4ce704dced68a-ol9_aarch64_UEKR8
kernel-uek-debug-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpmd0734614f67fff6d927b6fd4b16e891ffef7abe1693b8949065a9f34c66e18c5-ol9_aarch64_UEKR8
kernel-uek-debug-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpma5b74261df45193b14cd70e772da161abfd3ffe417f9e7333f591b3b51cdfef4-ol9_aarch64_UEKR8
kernel-uek-debug-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpma2080b85dc602213a744abedad0ca9055b47f8b80c3bfc5162e9e8d366841b67-ol9_aarch64_UEKR8
kernel-uek-debug-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpm63a536c48d3f0bf0d1baa0cd7f60748759951ffbb080f211f756885737a89bf6-ol9_aarch64_UEKR8
kernel-uek-debug-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpm77127bd3dcbca965ef59a18c1b9016c99724010a021556a28934beb4fb6f7d50-ol9_aarch64_UEKR8
kernel-uek-debug-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpmfaaccb401676d789cf809e8546618b606b763b1af25b3ba7f74deb53cf9fe20d-ol9_aarch64_UEKR8
kernel-uek-debug-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpm9751c5b090a91a6a0e564ef5b843af894aa438cfa4b15c4912a729ce2f97dcfa-ol9_aarch64_UEKR8
kernel-uek-debug-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpm1558b3f8db4b669420a1f0783904773aea6657d8d1ef1406276d05f9825628fb-ol9_aarch64_UEKR8
kernel-uek-debug-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm84bdce0ca3ef1bf8b1414a50e6767750e9a5ed2a1f4b39a5dc8221ebfcf89671-ol9_aarch64_UEKR8
kernel-uek-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpme2aae1ce7ea3ac5a3db2cb8e72a29b2e44296a4b4cea77e5cbc4cfdc22535070-ol9_aarch64_UEKR8
kernel-uek-doc-6.12.0-207.111.5.1.el9uek.noarch.rpm0c5ba8bb9fb68f566f4c8d6739799cf3b25be126f000606c0dd49cc3e07f4560-ol9_aarch64_UEKR8
kernel-uek-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpm636d342b80d6d7ee2ea4ff5b89b6d17fff08235cad5707e39910cb51316b2a60-ol9_aarch64_UEKR8
kernel-uek-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm03f5aee4e2446f61643c6bf924eb1c0bcb68ee5ab41362b9b7f9a4922fa6a13f-ol9_aarch64_UEKR8
kernel-uek-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpmca32eb05d9989f81d9afab69dbab7ab8a95029abfed6b11fd2b13b1e7549fc27-ol9_aarch64_UEKR8
kernel-uek-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpm2aea12e5fe39a2d8e668ace9f9e051f0165e537a80fedf2f96f2886b270324fb-ol9_aarch64_UEKR8
kernel-uek-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpm53982fa48b02e9d73df5b49dfc5d1645c1556353a4f1f5ac0c09d8968b2741fe-ol9_aarch64_UEKR8
kernel-uek-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpm052d53bc5feb87f13a76b94ec46cda4a15f063ab7007472f4807ebfcdb474e31-ol9_aarch64_UEKR8
kernel-uek-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpma29650b48f903c1f10ecd538eafc49ab4eb434ab59f885f2a33a80df9bf6d87d-ol9_aarch64_UEKR8
kernel-uek-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm382f7b4fc04d053aceefe624d688a25edcbf060d8f56619c1d4627ef67d7e596-ol9_aarch64_UEKR8
kernel-uek-tools-6.12.0-207.111.5.1.el9uek.aarch64.rpmb44eb7c831ef34097a2054804858820d35c92b46aed7e7593b782e7f4442df3f-ol9_aarch64_UEKR8
kernel-uek64k-6.12.0-207.111.5.1.el9uek.aarch64.rpm4a00c2f5006a7eefcb13cafdc29878d45c08ac97e2140c37ef53a80cb25a6292-ol9_aarch64_UEKR8
kernel-uek64k-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm664712d0af20df5f4c743bcac2f278f9fd29be0d4af8ef187227f297a3a35ac9-ol9_aarch64_UEKR8
kernel-uek64k-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpm1e13d8f5ce91528defd778a9604da72194aba020fe9cb09e62b972f66ca39d09-ol9_aarch64_UEKR8
kernel-uek64k-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpmc5124476b807337222b25cbb663446156eb2952ced6f9b60add3c677b463a483-ol9_aarch64_UEKR8
kernel-uek64k-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm4bb0af6908c27a4ed4b539dc19258cdc937865ed2d8824b51003b27941153b5b-ol9_aarch64_UEKR8
kernel-uek64k-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpmbada66e2518ddbe226c29cbacf79c7ba5294dc630dd8c6f2798a23dcd8b4b5dc-ol9_aarch64_UEKR8
kernel-uek64k-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpmaeb69d0a11a72a253b8c25b44e261c4174d1eb6caa275ce6343a4edbae200469-ol9_aarch64_UEKR8
kernel-uek64k-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpmeec978dd429c39f2448d6ab90bbdd24e8d6de616573bb4dcef2e3194cbba03ff-ol9_aarch64_UEKR8
kernel-uek64k-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpmf7d87ebf9ff7b53e19ee260c3ac7b80cfd3825285f0d44a614f3645a3d90ab63-ol9_aarch64_UEKR8
kernel-uek64k-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpm22a88ca6b51a5d7dd774bacce732eec16d7fd0b9de03d07fb2c531ab4df1035f-ol9_aarch64_UEKR8
kernel-uek64k-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm9fa24377a21f2561ecb9a3494bdc012d62e0bbc31c8c3a41461421370f75e9ae-ol9_aarch64_UEKR8
Oracle Linux 9 (x86_64) kernel-uek-6.12.0-207.111.5.1.el9uek.src.rpm5359ad71026575e3c48422ecb333417baed798961a698e2f29fd4f136b38610b-ol9_x86_64_UEKR8
kernel-uek-6.12.0-207.111.5.1.el9uek.x86_64.rpmd9ead799fb8bb357eae506cf37058ac9f4c357b80e0173f3ecaa561f9e133525-ol9_x86_64_UEKR8
kernel-uek-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm3ad634c33d8b59f55e90c48f8849b0d2ef857668f1974fb6167f9104381b9c92-ol9_x86_64_UEKR8
kernel-uek-debug-6.12.0-207.111.5.1.el9uek.x86_64.rpme0fd075ce5e0970e2d8ea8b7f7efbf7df72384c4cacdf3991266b2e13a2a949c-ol9_x86_64_UEKR8
kernel-uek-debug-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm168a74ce5ab099ecc3fb54dbf1901f8abdc742bb11ba5cb31f586137d74b63a5-ol9_x86_64_UEKR8
kernel-uek-debug-devel-6.12.0-207.111.5.1.el9uek.x86_64.rpm092d162dac57b7b7b4c507e415b9a2d133b076361795fe183d7db290af8297dc-ol9_x86_64_UEKR8
kernel-uek-debug-modules-6.12.0-207.111.5.1.el9uek.x86_64.rpm5e5086967e6fe023a8e3c850b28438d68c16e95503534fb2010fb56e37211f46-ol9_x86_64_UEKR8
kernel-uek-debug-modules-core-6.12.0-207.111.5.1.el9uek.x86_64.rpme9dda5c6096c199db1a79cd51f8c18774e11fedaf07d9172060df96e8151c63b-ol9_x86_64_UEKR8
kernel-uek-debug-modules-deprecated-6.12.0-207.111.5.1.el9uek.x86_64.rpm1faa1381a18a2aebcd030a0ecc10f19d064c88fa020561e721add499096c8c67-ol9_x86_64_UEKR8
kernel-uek-debug-modules-desktop-6.12.0-207.111.5.1.el9uek.x86_64.rpmae77cc085f4397f3d367481e9e372f3b8c8d122ad165702b3043cd8aa2f145ec-ol9_x86_64_UEKR8
kernel-uek-debug-modules-extra-6.12.0-207.111.5.1.el9uek.x86_64.rpmdb4452daf69c7c774032952097e45b3a764e4ed572dac096dc809dc227a49c70-ol9_x86_64_UEKR8
kernel-uek-debug-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.x86_64.rpm05aa7c20b64cd4605cbfffe6b9489f391606fade416da253e1f24e1bac6d3721-ol9_x86_64_UEKR8
kernel-uek-debug-modules-usb-6.12.0-207.111.5.1.el9uek.x86_64.rpm3807ced29cea5d4f44e039e55ef6e2f1e6b153083ad72159b30182ea95672025-ol9_x86_64_UEKR8
kernel-uek-debug-modules-wireless-6.12.0-207.111.5.1.el9uek.x86_64.rpmd6937c124fec141ecc9349e9a1bed2e5f3c1940a1ff578bedfefc3649b3e38ae-ol9_x86_64_UEKR8
kernel-uek-devel-6.12.0-207.111.5.1.el9uek.x86_64.rpm8e9aca54aef0e907cae5baa9b8c5e9fd9774f388f82b297b580e11df604609a9-ol9_x86_64_UEKR8
kernel-uek-doc-6.12.0-207.111.5.1.el9uek.noarch.rpm0c5ba8bb9fb68f566f4c8d6739799cf3b25be126f000606c0dd49cc3e07f4560-ol9_x86_64_UEKR8
kernel-uek-modules-6.12.0-207.111.5.1.el9uek.x86_64.rpm8d2b39e9b16d0fb0739055f233cc92726a968edb65f050e79245a9ee725dc33a-ol9_x86_64_UEKR8
kernel-uek-modules-core-6.12.0-207.111.5.1.el9uek.x86_64.rpmd3364da3e0f952b667ea6eb0736376cd8cbd6b23c0c128f5f3e6b574522b26ac-ol9_x86_64_UEKR8
kernel-uek-modules-deprecated-6.12.0-207.111.5.1.el9uek.x86_64.rpmb233ab9aa2c5bec374a136cf85816b62c77daf1e77028d82137cb409b1b67a89-ol9_x86_64_UEKR8
kernel-uek-modules-desktop-6.12.0-207.111.5.1.el9uek.x86_64.rpm133d2c43e4b732759312c51e5e52fb61c7a2e101f879ac93bdc1f0df6348d2b2-ol9_x86_64_UEKR8
kernel-uek-modules-extra-6.12.0-207.111.5.1.el9uek.x86_64.rpm5c99cac547697ff0a4a708f1e981df7e4e63dfd186f8d1ebe1c2169513d75160-ol9_x86_64_UEKR8
kernel-uek-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.x86_64.rpm0b441425e433638f3f28816c9c4a4de049315515aefeff4994ec8fd816f0e9ae-ol9_x86_64_UEKR8
kernel-uek-modules-usb-6.12.0-207.111.5.1.el9uek.x86_64.rpm27ca16cb4637f5dde4f3918768954d6be09aa93c40f2b74227d43cedbc083ee8-ol9_x86_64_UEKR8
kernel-uek-modules-wireless-6.12.0-207.111.5.1.el9uek.x86_64.rpm50e6253f2d248a551f756ff1cf14115f43c04fbb30b217e7845995e26914c819-ol9_x86_64_UEKR8
kernel-uek-tools-6.12.0-207.111.5.1.el9uek.x86_64.rpmb9d99ab61662fd0c7075174ceee1f4b4ee80919e226fe35f7e8f4d201ccf21a9-ol9_x86_64_UEKR8



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete