ELSA-2026-500377

ELSA-2026-500377 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-10-07

Description


[5.15.0-325.220.5]
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) [Orabug: 39951718]
- batman-adv: Remove stale reason member from batadv_tp_vars (Vijayendra Suman) [Orabug: 39966037]
- Revert 'octeontx2-pf: Fix leak of SQ timestamp buffer on teardown' (Vijayendra Suman) [Orabug: 39967930]
- tcp: fix potential race in tcp_v6_syn_recv_sock() (Eric Dumazet) [Orabug: 39331624] {CVE-2026-43198}
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (Bjoern Doebel) [Orabug: 39886288] {CVE-2026-74268}
- tcp: clear sock_ops cb flags before force-closing a child socket (Sechang Lim) [Orabug: 39886588] {CVE-2026-74378}
- net: af_key: zero aligned sockaddr tail in PF_KEY exports (Zhengchuan Liang) [Orabug: 39331155] {CVE-2026-43088}
- uek-rpm: clean up failed kernel installation (Sagar Sagar) [Orabug: 39735711]
- vhost-scsi: use kvzalloc for vq array allocation (Dongli Zhang) [Orabug: 40015348]
- x86/cpuid: move X86_FEATURE_NT_GOOD to word 2 (Aruna Ramakrishna) [Orabug: 39966615]
- bpf: Fix combination of jit blinding and pointers to bpf subprogs. (Alexei Starovoitov) [Orabug: 39965261]
- net: Work around Marvell NIC TX stalls (Wengang Wang) [Orabug: 39766660]
- uek: kabi: update x86_64 kABI files for new symbols (Saeed Mirzamohammadi) [Orabug: 39940294]
- Revert 'net/mlx5: Add poll-eq API to be used by ULP's' (Praveen Kumar Kannoju) [Orabug: 39890590]

[5.15.0-325.220.4]
- LTS version: v5.15.220 (Vijayendra Suman)
- usb: usbfs: fix use-after-free of usb_device in usbdev_release() (Miguel Penaranda) [Orabug: 39982120] {CVE-2026-80824}
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (Shuangpeng Bai)
- USB: serial: spcp8x5: drop broken carrier detect support (Johan Hovold)
- USB: serial: option: fix slab OOB read in interrupt URB callback (Jiale Yao) [Orabug: 39982131] {CVE-2026-80827}
- ALSA: usb-audio: Complete cleanup after system-resume errors (Will Porter) [Orabug: 39982135] {CVE-2026-80828}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (Marouane El Moufid) [Orabug: 39982139] {CVE-2026-80829}
- usb: core: Strengthen error handling in hub_hub_status() (Griffin Kroah-Hartman)
- usb: core: Add lock to usb_wakeup_notification() (Griffin Kroah-Hartman) [Orabug: 39982143] {CVE-2026-80830}
- KVM: s390: vsie: zero stale crypto bits (Christian Borntraeger)
- crypto: qce - Remove unsafe/deprecated algorithms (Bartosz Golaszewski)
- crypto: mxs-dcp - fix source scatterlist length access (Thorsten Blum)
- crypto: qce - fix CCM AAD buffer underallocation (Md Sadre Alam)
- crypto: atmel-tdes - use scatterlist length before DMA mapping (Thorsten Blum)
- mm/swap: reject swapon() on filesystem-level encrypted files (Eric Biggers)
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation (Kyle Zeng) [Orabug: 39982172] {CVE-2026-80840}
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (Norbert Szetei) [Orabug: 39982180] {CVE-2026-80842}
- xfrm: fix xfrm_state_construct() auth-trunc leak (Zihan Xi) [Orabug: 39982183] {CVE-2026-80843}
- xfrm: ah6: validate routing header segments_left (Asim Viladi Oglu Manizada) [Orabug: 39982187,40035522] {CVE-2026-80844}
- xfrm: drop ESP-in-TCP packets with no ingress device (Zhiling Zou)
- xfrm: espintcp: fix UAF during close (Sabrina Dubroca)
- usb: gadget: f_tcm: keep port count until LUN teardown completes (Shuangpeng Bai) [Orabug: 39982217] {CVE-2026-80854}
- usb: usbtest: disable dynamic ID support (Aleksandr Nogikh)
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure (Baokun Li) [Orabug: 39982221] {CVE-2026-80855}
- fuse: fix invalidate lock leak on setattr writeback failure (Baokun Li) [Orabug: 39982224] {CVE-2026-80856}
- xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (Lucas De Marchi)
- xhci: dbgtty: Fix unregister on tty_register_driver() failure (Lucas De Marchi) [Orabug: 40010372] {CVE-2026-80923}
- accessibility: speakup: unregister tty ldisc on later init failures (Haoxiang Li)
- fpga: dfl: fme: add error handling (Griffin Kroah-Hartman)
- HID: input: read battery capacity from its actual report offset (Jose Villasenor Montfort)
- HID: ft260: fix stack-use-after-return write in I2C read race (Raman Varabets)
- HID: ft260: validate i2c input report length (Michael Zaidman)
- HID: ft260: missed NACK from busy device (Michael Zaidman)
- HID: ft260: wake up device from power saving mode (Michael Zaidman)
- HID: ft260: skip unexpected HID input reports (Michael Zaidman)
- HID: ft260: improve i2c large reads performance (Michael Zaidman)
- HID: ft260: improve i2c write performance (Michael Zaidman)
- HID: ft260: fix i2c probing for hwmon devices (Michael Zaidman)
- nvmet-tcp: bound SGL data length before allocating command buffers (Ibrahim Hashimov) [Orabug: 39982006] {CVE-2026-80789}
- nvme: rename CDR/MORE/DNR to NVME_STATUS_* (Weiwen Hu)
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (Jose Villasenor Montfort) [Orabug: 39981987] {CVE-2026-80783}
- nfc: nci: add data_len bound checks to activation parameter extractors (Bryam Vargas)
- nilfs2: reject invalid block index in GC ioctl (Ryusuke Konishi)
- nilfs2: correct return value kernel-doc descriptions for ioctl functions (Ryusuke Konishi)
- ext4: propagate errors from fast commit range replay (Guanghui Yang)
- kcov: fix data corruption and race conditions on PREEMPT_RT (Tetsuo Handa) [Orabug: 40010347] {CVE-2026-80916}
- kcov: replace local_irq_save() with a local_lock_t (Sebastian Andrzej Siewior)
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (Eric Dumazet) [Orabug: 39885781] {CVE-2026-72323}
- ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (Ji'An Zhou) [Orabug: 40017137] {CVE-2026-53242}
- ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (Mehul Rao) [Orabug: 39343942] {CVE-2026-43437}
- ASoC: tegra: Fix Master Volume Control (Jonathan Hunter)
- ALSA: pcm: fix wait_time calculations (Oswald Buddenhagen)
- Revert 'smb: client: use kvzalloc() for megabyte buffer in simple fallocate' (Sasha Levin)
- Revert 'mtd: maps: vmu-flash: fix fault in unaligned fixup' (Sasha Levin) [Orabug: 39967936]
- selinux: switch two allocations to use kzalloc_objs() (Stephen Smalley)
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). (Kuniyuki Iwashima)
- Revert 'PM: sleep: Use complete() in device_pm_sleep_init()' (Sasha Levin)
- bpf: Fix use-after-free in offloaded map/prog info fill (Jiayuan Chen) [Orabug: 39622047] {CVE-2026-53089}
- KVM: arm64: Prevent access to vCPU events before init (Oliver Upton) [Orabug: 38601896] {CVE-2025-40102}
- can: j1939: make j1939_sk_bind() fail if device is no longer registered (Tetsuo Handa)
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (Tetsuo Handa)
- can: j1939: implement NETDEV_UNREGISTER notification handler (Tetsuo Handa) [Orabug: 38494827] {CVE-2025-39925}
- jfs: add check read-only before txBeginAnon() call (Vasiliy Kovalev)
- jfs: add check read-only before truncation in jfs_truncate_nolock() (Vasiliy Kovalev)
- bpf: Remove tst_run from lwt_seg6local_prog_ops. (Sebastian Andrzej Siewior) [Orabug: 37074553] {CVE-2024-46754}
- ipvs: reload ip header after head reallocation (Florian Westphal) [Orabug: 39884703] {CVE-2026-68476}
- io_uring/io-wq: fix worker accounting when canceling creation callbacks (Vishnu Razdan)
- ext4: don't enable DAX on new encrypted files (Eric Biggers) [Orabug: 39982070] {CVE-2026-80806}
- RDMA/rxe: Fix OOB in free_rd_atomic_resources() (Peiyang He) [Orabug: 39982237] {CVE-2026-80863}
- LTS version: v5.15.219 (Vijayendra Suman)
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39972531,39974835] {CVE-2026-80590}
- LTS version: v5.15.218 (Vijayendra Suman)
- Revert 'ALSA: aoa: Use guard() for mutex locks' (Sasha Levin)
- HID: hyperv: validate initial device info bounds (Michael Bommarito) [Orabug: 39981945] {CVE-2026-80765}
- HID: sensor: custom: Fix use-after-free in enable_sensor (Haoxiang Li) [Orabug: 39981954] {CVE-2026-80767}
- HID: core: fix number/pointer type confusion on long items (Jann Horn) [Orabug: 40010353] {CVE-2026-80918}
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp) [Orabug: 39982403] {CVE-2026-80889}
- can: use skb hash instead of private variable in headroom (Oliver Hartkopp)
- mptcp: pm: fix data race in add_addr timer callback (Luoqing)
- mptcp: pm: ADD_ADDR rtx: free sk if last (Matthieu Baerts) [Orabug: 39460461] {CVE-2026-46170}
- mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (Matthieu Baerts) [Orabug: 39460401] {CVE-2026-46158}
- mptcp: pm: ADD_ADDR rtx: allow ID 0 (Matthieu Baerts)
- Input: atkbd - skip deactivate for HONOR ZQC-P (Donglin Lyu)
- Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard (Cryolitia Pukngae)
- s390/vfio_ccw: Free all memory if cp_init() fails (Eric Farman)
- iomap: adjust read range correctly for non-block-aligned positions (Joanne Koong) [Orabug: 38847820] {CVE-2025-68794}
- xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (Xiang Mei) [Orabug: 39839297] {CVE-2026-64581}
- HID: core: fix OOB read of field->usage in hid_set_field() (Baul Lee) [Orabug: 39981979] {CVE-2026-80781}
- HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (Lee Jones)
- HID: magicmouse: do not keep a stale msc->input if no input is claimed (Jose Villasenor Montfort) [Orabug: 39981983] {CVE-2026-80782}
- ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (Dawid WroBel)
- mptcp: avoid combining some incoming suboptions (Matthieu Baerts) [Orabug: 39973016] {CVE-2026-80587}
- s390/vfio_ccw: Implement a crw lock (Eric Farman)
- s390/vfio_ccw: Selectively expand io_mutex (Eric Farman)
- s390/vfio_ccw: Ensure index for read/write regions are within range (Eric Farman)
- nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations (Greg Kroah-Hartman) [Orabug: 39982002] {CVE-2026-80788}
- nvmet-fc: fix invalid free in LS IOD error path (Honghui Jiang) [Orabug: 39982010] {CVE-2026-80790}
- ipv6: fix use-after-free in ip6_finish_output2() (Luxiao Xu) [Orabug: 39982017] {CVE-2026-80792}
- ipv4: reject undersized MTUs in ip_do_fragment() (Yong Wang) [Orabug: 39982021] {CVE-2026-80793}
- drm/amdgpu: check ASPM on the dGPU host link (Yang Wang)
- libceph: fix OOB read in decode_watchers() via missing bounds check (Pavitra Jha) [Orabug: 39972906] {CVE-2026-80557}
- nfc: nci: free destination parameters when closing a connection (Linmao Li)
- nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (Samuel Page)
- nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (Samuel Page)
- nfc: st21nfca: validate ATR_REQ length against the received frame (Doruk Tan Ozturk)
- nfc: pn533: purge fragmented skbs during cleanup (Xu Rao)
- nfc: llcp: reject PDUs shorter than the LLCP header (Doruk Tan Ozturk)
- nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (Muhammad Bilal)
- nfc: llcp: bound the connect_sn TLV walk to the skb (Doruk Tan Ozturk)
- nfc: microread: validate target discovery payload lengths (Pengpeng Hou)
- nfc: fdp: bound the device-reported read length and fix an skb leak (Bryam Vargas)
- nfc: digital: clamp SENSF_RES length to the destination buffer (Doruk Tan Ozturk)
- xfs: bounds-check buffer log item's dirty bitmap (Ibrahim Hashimov) [Orabug: 39972835] {CVE-2026-80536}
- s390/vfio_ccw: Cancel existing workqueues (Eric Farman)
- inet: frags: publish queues before arming timer (Zhiling Zou) [Orabug: 39919187] {CVE-2026-74662}
- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) [Orabug: 39919201] {CVE-2026-74666}
- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) [Orabug: 39919191] {CVE-2026-74663}
- packet: use consistent hard_header_len in TX_RING send path (Qihang) [Orabug: 39919209] {CVE-2026-74668}
- packet: use consistent hard_header_len in non-ring send paths (Qihang) [Orabug: 39917533] {CVE-2026-74582}
- serial: amba-pl011: synchronize DMA teardown (Fan Wu) [Orabug: 39973443] {CVE-2026-80737}
- NTB: ntb_netdev: Preserve RX queue depth on allocation failure (Koichiro Den) [Orabug: 39919082] {CVE-2026-74626}
- perf/core: Fix group leader use-after-free after sibling detach (Aditya Chillara) [Orabug: 39919114] {CVE-2026-74637}
- perf: Fix dangling cgroup pointer in cpuctx (Levi Yun)
- perf: Fix cgroup state vs ERROR (Peter Zijlstra)
- perf/core: Fix child_total_time_enabled accounting bug at task exit (Levi Yun)
- misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta)
- misc: fastrpc: Rework fastrpc_req_munmap (Abel Vesa)
- misc: fastrpc: separate fastrpc device from channel context (Srinivas Kandagatla)
- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes) [Orabug: 39919100] {CVE-2026-74632}
- gpio: ml-ioh: use raw_spinlock_t for the register lock (Junjie Cao)
- xfs: validate attr entry pointer before field access (Hongling Zeng) [Orabug: 39982067] {CVE-2026-80805}
- ext4: clear error before retrying inode xattr space fallback (Guanghui Yang)
- ext4: stop retrying saturated xattr cache entries (Matthias Goergens) [Orabug: 39982077] {CVE-2026-80808}
- null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows (Rik van Riel)
- ocfs2: fix missing metadata reservation for large xattrs (Ian Bridges) [Orabug: 39982081] {CVE-2026-80809}
- ALSA: dummy: Check card index validity at probe (Takashi Iwai) [Orabug: 39982087] {CVE-2026-80812}
- rndis_host: add overflow check in rndis_rx_fixup() (Griffin Kroah-Hartman) [Orabug: 39982092] {CVE-2026-80814}
- Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (Ali Ahmet Memis) [Orabug: 39982102] {CVE-2026-80819}
- PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems (Steffen Persvold) [Orabug: 40010350] {CVE-2026-80917}

[5.15.0-325.217.3]
- LTS version: v5.15.217 (Vijayendra Suman)
- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu) [Orabug: 39919010] {CVE-2026-74601}
- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt)
- jiffies: Cast to unsigned long in secs_to_jiffies() conversion (Easwar Hariharan)
- drm/virtio: Unlock reservations on dma_resv_reserve_fences() error (Dmitry Osipenko)
- drm/vmwgfx: Reserve fence slots on buffer objects in cotables (Zack Rusin)
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) [Orabug: 39974107] {CVE-2026-74486}
- net/x25: fix use-after-free of the socket by its timers (Baul Lee) [Orabug: 39919087] {CVE-2026-74628}
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli)
- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet) [Orabug: 39973457] {CVE-2026-80742}
- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev)
- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang) [Orabug: 39982352] {CVE-2026-80906}
- netfilter: ipset: fix list type element drift bug (Florian Westphal)
- netfilter: flowtable: publish GC-visible tuple last (Jeremy Jean) [Orabug: 39972761] {CVE-2026-74746}
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy) [Orabug: 39973466] {CVE-2026-80744}
- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei) [Orabug: 39972772] {CVE-2026-74748}
- crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu)
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jonathan Hunter)
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Li Daming)
- net/smc: rdma write inline if qp has sufficient inline space (Guangguan Wang)
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) [Orabug: 39919072] {CVE-2026-74623}
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) [Orabug: 39919065] {CVE-2026-74621}
- openvswitch: move key and ovs_cb update out of handle_fragments (Xin Long)
- net: sched: use skb_ip_totlen and iph_totlen (Xin Long)
- openvswitch: use skb_ip_totlen in conntrack (Xin Long)
- net: add a couple of helpers for iph tot_len (Xin Long)
- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes) [Orabug: 39919004] {CVE-2026-74599}
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) [Orabug: 39918989] {CVE-2026-74594}
- drm/amd/pm: fix torn gpu metrics reads (Yang Wang)
- ice: wait for reset completion in ice_resume() (Aaron Ma)
- jiffies: Define secs_to_jiffies() (Easwar Hariharan)
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)
- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)
- i2c: bcm-iproc: remove printout on handled timeouts (Wolfram Sang)
- i2c: imx: Fix slave registration race and error handling (Liem) [Orabug: 39973286] {CVE-2026-80678}
- binfmt_misc: restore write access when removing an entry (Christian Brauner) [Orabug: 39886902] {CVE-2026-74487}
- fs: don't block write during exec on pre-content watched files (Amir Goldstein)
- fsnotify: opt-in for permission events at file open time (Amir Goldstein)
- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) [Orabug: 39886847] {CVE-2026-74470}
- scsi: scsi_debug: Rename zone type constants (Damien Le Moal)
- scsi: sd: sd_zbc: Return early in sd_zbc_check_zoned_characteristics() (Damien Le Moal)
- scsi: sd: sd_zbc: Introduce struct zoned_disk_info (Bart Van Assche)
- scsi: sd: sd_zbc: Use logical blocks as unit when querying zones (Damien Le Moal)
- scsi: sd: sd_zbc: Improve source code documentation (Bart Van Assche)
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye) [Orabug: 39886875] {CVE-2026-74479}
- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)
- igc: remove napi_synchronize() in igc_down() (David Carlier) [Orabug: 39973387] {CVE-2026-80715}
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) [Orabug: 39884956] {CVE-2026-72070}
- ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon)
- ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)
- ksmbd: validate minimum PDU size for transform requests (Namjae Jeon)
- smb/server: fix minimum SMB2 PDU size (Chenxiaosong)
- smb/server: fix minimum SMB1 PDU size (Chenxiaosong)
- ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon)
- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner) [Orabug: 39859442] {CVE-2026-68132}
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) [Orabug: 39859492] {CVE-2026-68146}
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) [Orabug: 39859462] {CVE-2026-68138}
- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery)
- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha) [Orabug: 39852162] {CVE-2026-68082}
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann) [Orabug: 39972807] {CVE-2026-80527}
- ceph: print cluster fsid and client global_id in all debug logs (Xiubo Li)
- ceph: rename _to_client() to _to_fs_client() (Xiubo Li)
- libceph: add doutc and *_client debug macros support (Xiubo Li)
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei) [Orabug: 39859534] {CVE-2026-68159}
- libceph: Amend checking to fix make W=1 build breakage (Andy Shevchenko)
- ceph: avoid fs reclaim while using current->journal_info (Max Kellermann) [Orabug: 39972810] {CVE-2026-80528}
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) [Orabug: 39859549] {CVE-2026-68162}
- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)
- mptcp: fix subflow accounting on close (Paolo Abeni)
- mptcp: cleanup MPJ subflow list handling (Paolo Abeni)
- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)
- serial: sc16is7xx: fix regression with GPIO configuration (Hugo Villeneuve)
- serial: sc16is7xx: remove obsolete out_thread label (Hugo Villeneuve)
- serial: sc16is7xx: Fill in rs485_supported (Ilpo Jarvinen)
- sc16is7xx: Properly resume TX after stop (Tomasz Mon)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (Liangcheng Wang)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868565] {CVE-2026-68434}
- serial: 8250_mid: Remove unneeded test for ->setup() presence (Andy Shevchenko)
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) [Orabug: 39843565] {CVE-2026-64586}
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) [Orabug: 39859660] {CVE-2026-68202}
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) [Orabug: 39859672] {CVE-2026-68205}
- media: v4l: async: Set owner for async sub-devices (Sakari Ailus)
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) [Orabug: 39859648] {CVE-2026-68198}
- media: imx219: Fix maximum frame length in lines (Sakari Ailus)
- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)
- media: i2c: imx219: Correct the minimum vblanking value (David Plowman)
- media: i2c: imx219: Drop IMX219_VTS_* macros (Laurent Pinchart)
- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)
- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) [Orabug: 39859828] {CVE-2026-68253}
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) [Orabug: 39859832] {CVE-2026-68254}
- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) [Orabug: 39859836] {CVE-2026-68255}
- drm/virtio: Return proper error codes instead of -1 (Dmitry Osipenko)
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof)
- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)
- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)
- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey) [Orabug: 39754773] {CVE-2026-64098}
- dma-buf/drivers: make reserving a shared slot mandatory v4 (Christian Konig)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) [Orabug: 39859888] {CVE-2026-68277}
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) [Orabug: 39859896] {CVE-2026-68279}
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) [Orabug: 39860172] {CVE-2026-68367}
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) [Orabug: 39859892] {CVE-2026-68278}
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) [Orabug: 39884753] {CVE-2026-72015}
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng)
- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)
- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca)
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)
- bootconfig: do not put quotes on cmdline items unless necessary (Rasmus Villemoes)
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) [Orabug: 39884827] {CVE-2026-72035}
- net/sched: taprio: avoid calling child->ops->dequeue(child) twice (Vladimir Oltean)
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao) [Orabug: 39884922] {CVE-2026-72063}
- treewide: rename pinctrl_gpio_direction_output_new() (Bartosz Golaszewski)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) [Orabug: 39884855] {CVE-2026-72045}
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884875] {CVE-2026-72051}
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) [Orabug: 39884929] {CVE-2026-72065}
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi) [Orabug: 39884899] {CVE-2026-72057}
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li)
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884883] {CVE-2026-72053}
- net: Add helper function to parse netlink msg of ip_tunnel_encap (Liu Jian)
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner)
- mmc: vub300: fix use-after-free on probe failure (Guangshuo Li) [Orabug: 39884968] {CVE-2026-72073}
- mmc: vub300: rename probe error labels (Johan Hovold)
- mmc: vub300: fix use-after-free on disconnect (Johan Hovold)
- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov)
- firmware_loader: introduce __free() cleanup hanler (Dmitry Torokhov)
- dm-verity: make error counter atomic (Mikulas Patocka) [Orabug: 39885054] {CVE-2026-72096}
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka) [Orabug: 39885064] {CVE-2026-72099}
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal) [Orabug: 39885038] {CVE-2026-72087}
- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn) [Orabug: 39885094] {CVE-2026-72110}
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) [Orabug: 39887152] {CVE-2026-74575}
- thunderbolt: Remove XDomain from the bus without holding tb->lock (Mika Westerberg)
- thunderbolt: Remove service debugfs entries during unregister (Mika Westerberg)
- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg)
- thunderbolt: Update property.c function documentation (Alan Borzeszkowski)
- thunderbolt: Remove usage of the deprecated ida_simple_xx() API (Christophe Jaillet)
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu) [Orabug: 39843561] {CVE-2026-64585}
- can/esd_usb2: Rename esd_usb2.c to esd_usb.c (Frank Jungclaus)
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin) [Orabug: 39885191] {CVE-2026-72142}
- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)
- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen) [Orabug: 39885221] {CVE-2026-72152}
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)
- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)
- taskstats: fill_stats_for_tgid: use for_each_thread() (Oleg Nesterov)
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li)
- dmaengine: dw-edma: Detach the private data and chip info structures (Frank Li)
- dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip (Frank Li)
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal) [Orabug: 39885230] {CVE-2026-72155}
- mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle)
- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie)
- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao) [Orabug: 39885290] {CVE-2026-72170}
- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito)
- fs/ntfs3: Undo critial modificatins to keep directory consistency (Konstantin Komarov)
- fs/ntfs3: Make ntfs_update_mftmirr return void (Pavel Skripkin)
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani) [Orabug: 39885551] {CVE-2026-72242}
- lsm: infrastructure management of the sock security (Casey Schaufler)
- lsm: use default hook return value in call_int_hook() (Ondrej Mosnacek)
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir)
- remoteproc: qcom: pas: Adjust the phys addr wrt the mem region (Yogesh Lal)
- remoteproc: qcom: fix sparse warnings (Mukesh Ojha)
- remoteproc: qcom: replace kstrdup with kstrndup (Mukesh Ojha)
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) [Orabug: 39885581] {CVE-2026-72252}
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal)
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal)
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal)
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal)
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) [Orabug: 39885585] {CVE-2026-72253}
- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)
- netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal)
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal)
- ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel)
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)
- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (AngeloGioacchino Del Regno)
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (AngeloGioacchino Del Regno)
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie) [Orabug: 39885591] {CVE-2026-72255}
- ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet)
- net: dst: add four helpers to annotate data-races around dst->dev (Eric Dumazet)
- net: dst: annotate data-races around dst->output (Eric Dumazet)
- net: dst: annotate data-races around dst->input (Eric Dumazet)
- tcp: convert to dev_net_rcu() (Eric Dumazet)
- ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel)
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep)
- octeontx2-af: Fix APR entry mapping based on APR_LMT_CFG (Geetha Sowjanya)
- VDUSE: avoid leaking information to userspace (Jason Wang) [Orabug: 39885723] {CVE-2026-72305}
- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez)
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez)
- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Xu Wang)
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) [Orabug: 39885709] {CVE-2026-72299}
- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)
- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)
- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming)
- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)
- serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) (Hugo Villeneuve)
- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) [Orabug: 39859311] {CVE-2026-68096}
- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)
- audit: widen ino fields to u64 (Jeff Layton)
- VFS/audit: introduce kern_path_parent() for audit (Neil Brown)
- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)
- Input: mms114 - reject an oversized device packet size (Bryam Vargas) [Orabug: 39785798] {CVE-2026-64270}
- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov) [Orabug: 39785807] {CVE-2026-64272}
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives)
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov)
- udmabuf: Do not create malformed scatterlists (Jason Gunthorpe)
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski) [Orabug: 39760896] {CVE-2026-64192}
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato) [Orabug: 39785859] {CVE-2026-64294}
- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei)
- xfs: check v5 superblock features early (Christoph Hellwig)
- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li) [Orabug: 39972825] {CVE-2026-80534}
- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca) [Orabug: 39972847] {CVE-2026-80540}
- drm/amdgpu: Implement insert_end for VCE 3 (David Rosca)
- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca) [Orabug: 39982361] {CVE-2026-80908}
- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li) [Orabug: 39972852] {CVE-2026-80541}
- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca) [Orabug: 39982365] {CVE-2026-80909}
- s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman)
- drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li)
- mmc: sdhci: make tuning_err a signed int (Haibo Chen)
- mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak)
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng)
- libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai)
- ceph: fix MDS random selection readiness predicate (Yiming Zhu)
- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer) [Orabug: 39972915] {CVE-2026-80558}
- Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov)
- Input: sur40 - fix input device registration ordering (Dmitry Torokhov)
- openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis)
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf)
- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha) [Orabug: 39972927] {CVE-2026-80561}
- crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum)
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov)
- Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov)
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas) [Orabug: 39972955] {CVE-2026-80569}
- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov) [Orabug: 39972960] {CVE-2026-80570}
- powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson)
- Input: iforce - validate input packet lengths (Pengpeng Hou)
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang)
- Input: psxpad-spi - set driver data before use (Linmao Li)
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies) [Orabug: 39972975] {CVE-2026-80574}
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov) [Orabug: 39973486] {CVE-2026-80754}
- powerpc/pseries: pci - logic bug (George Wilson)
- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid WroBel)
- ASoC: cs4265: sort the register default table (Peter Ujfalusi)
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan)
- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts) [Orabug: 39973013] {CVE-2026-80586}
- selinux: do not cancel a policy conversion that never started (Bryam Vargas) [Orabug: 39973494] {CVE-2026-80756}
- selinux: reject a class permission count below its inherited common (Bryam Vargas) [Orabug: 39973498] {CVE-2026-80757}
- selinux: require every boolean value to be defined (Bryam Vargas) [Orabug: 39982381] {CVE-2026-80913}
- ipvs: separate destination availability state (Yizhou Zhao)
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) [Orabug: 39918992] {CVE-2026-74595}
- media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization (Jiasheng Jiang)
- media: mtk-vcodec: potential null pointer deference in SCP (Fullway Wang)
- f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu)
- LTS version: v5.15.216 (Vijayendra Suman)
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas) [Orabug: 39918961] {CVE-2026-74585}
- sctp: clear new_transport when removing a peer (Qing Ming) [Orabug: 39918965] {CVE-2026-74586}
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) [Orabug: 39918969] {CVE-2026-74587}
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee) [Orabug: 39918973] {CVE-2026-74588}
- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) [Orabug: 39918977] {CVE-2026-74589}
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou) [Orabug: 39918996] {CVE-2026-74597}
- ipv6: fix Route Information option length validation (Yuejie Shi) [Orabug: 39919000] {CVE-2026-74598}
- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) [Orabug: 39919019] {CVE-2026-74604}
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang) [Orabug: 39919032] {CVE-2026-74609}
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) [Orabug: 39917525] {CVE-2026-74580}
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) [Orabug: 39919042] {CVE-2026-74613}
- vsock/virtio: read virtqueues under worker locks (Weiming Shi) [Orabug: 39919046] {CVE-2026-74614}
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) [Orabug: 39919049] {CVE-2026-74615}
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) [Orabug: 39919053] {CVE-2026-74616}
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) [Orabug: 39919061] {CVE-2026-74620}
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) [Orabug: 39919068] {CVE-2026-74622}
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) [Orabug: 39919078] {CVE-2026-74625}
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) [Orabug: 39919092] {CVE-2026-74630}
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) [Orabug: 39919107] {CVE-2026-74635}
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) [Orabug: 39919111] {CVE-2026-74636}
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) [Orabug: 39919124] {CVE-2026-74641}
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)
- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) [Orabug: 39919138] {CVE-2026-74648}
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) [Orabug: 39919142] {CVE-2026-74649}
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) [Orabug: 39919146] {CVE-2026-74650}
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) [Orabug: 39919150] {CVE-2026-74651}
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) [Orabug: 39919159] {CVE-2026-74654}
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) [Orabug: 39919165] {CVE-2026-74656}
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) [Orabug: 39919169] {CVE-2026-74657}
- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- futex: Prevent robust futex exit race some more (Keno Fischer) [Orabug: 39919174] {CVE-2026-74658}
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver) [Orabug: 39786570] {CVE-2026-64434}
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) [Orabug: 39919227] {CVE-2026-74673}
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) [Orabug: 39919232] {CVE-2026-74675}
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) [Orabug: 39919236] {CVE-2026-74676}
- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee)
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) [Orabug: 39919181] {CVE-2026-74660}
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang) [Orabug: 39973427] {CVE-2026-80731}
- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) [Orabug: 39919195] {CVE-2026-74664}
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) [Orabug: 39919205] {CVE-2026-74667}
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) [Orabug: 39919213] {CVE-2026-74669}
- ipvs: properly update the overload flag on dest edit (Julian Anastasov)
- ipvs: add totalconns for dest (Julian Anastasov)
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) [Orabug: 39919219] {CVE-2026-74671}
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) [Orabug: 39919247] {CVE-2026-74679}
- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)
- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) [Orabug: 39919251] {CVE-2026-74680}
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) [Orabug: 39919256] {CVE-2026-74682}
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) [Orabug: 39919260] {CVE-2026-74683}
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)
- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)
- sctp: clear control chunk transport if it is being removed (Xin Long) [Orabug: 39919275] {CVE-2026-74688}
- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu)
- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan Xinran)
- net: qrtr: ns: Raise lookup limit to 128 (Lukasz Patron)
- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond)
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) [Orabug: 39973435] {CVE-2026-80733}
- net: prestera: validate firmware header length (Pengpeng Hou)
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin)
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) [Orabug: 39919306] {CVE-2026-74696}
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Luoqing)
- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan) [Orabug: 39919309] {CVE-2026-74697}
- bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Michael Chan)
- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)
- selftests/ftrace: Add test case for GRP/ only input (Linyu Yuan)
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang) [Orabug: 39919320] {CVE-2026-74701}
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) [Orabug: 39919330] {CVE-2026-74704}
- udp: fix potential use-after-free in tunnel segmentation (Luoxuanqiang) [Orabug: 39919334] {CVE-2026-74705}
- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)
- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) [Orabug: 39919359] {CVE-2026-74717}
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) [Orabug: 39917538] {CVE-2026-74583}
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi)
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) [Orabug: 39919369] {CVE-2026-74720}
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei) [Orabug: 39919388] {CVE-2026-74726}
- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) [Orabug: 39919399] {CVE-2026-74730}
- nfs4: take a reference on the nfs_client when running FREE_STATEID (Scott Mayhew)
- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger)
- mount: honour SB_NOUSER in the new mount API (Al Viro)
- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao)
- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng)
- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau) [Orabug: 39886887] {CVE-2026-74482}
- HID: logitech-dj: Fix maxfield check in DJ short report validation (Hyeongjun An) [Orabug: 39974286] {CVE-2026-64427}
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) [Orabug: 39886755] {CVE-2026-74443}
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) [Orabug: 39886759] {CVE-2026-74444}
- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)
- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)
- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) [Orabug: 39886787] {CVE-2026-74453}
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) [Orabug: 39886795] {CVE-2026-74455}
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) [Orabug: 39886799] {CVE-2026-74456}
- can: peak_usb: add bounds check for USB channel index (James Gao) [Orabug: 39886804] {CVE-2026-74457}
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) [Orabug: 39973358] {CVE-2026-80706}
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) [Orabug: 39886808] {CVE-2026-74458}
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) [Orabug: 39973363] {CVE-2026-80707}
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li)
- can: ems_usb: validate CPC message lengths (Pengpeng Hou) [Orabug: 39886813] {CVE-2026-74460}
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) [Orabug: 39886817] {CVE-2026-74461}
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller)
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) [Orabug: 39886825] {CVE-2026-74464}
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) [Orabug: 39886829] {CVE-2026-74465}
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava Kishore Manne)
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava Kishore Manne)
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava Kishore Manne)
- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler)
- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler)
- s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner)
- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin K)
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)
- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) [Orabug: 39886842,40035526] {CVE-2026-74469}
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang) [Orabug: 39982313] {CVE-2026-80890}
- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)
- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu)
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu) [Orabug: 39886850] {CVE-2026-74471}
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886856] {CVE-2026-74473}
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886864] {CVE-2026-74475}
- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) [Orabug: 39973297] {CVE-2026-80681}
- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito)
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) [Orabug: 39917530] {CVE-2026-74581}
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) [Orabug: 39886879] {CVE-2026-74480}
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) [Orabug: 39886883] {CVE-2026-74481}
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) [Orabug: 39886897] {CVE-2026-74485}
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Catherine) [Orabug: 39886906] {CVE-2026-74488}
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) [Orabug: 39886911] {CVE-2026-74490}
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) [Orabug: 39886916] {CVE-2026-74492}
- net/smc: fix socket use-after-free during link group termination (Luoxuanqiang)
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) [Orabug: 39973383] {CVE-2026-80714}
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) [Orabug: 39886926] {CVE-2026-74495}
- e1000: fix memory leak in e1000_probe() (Dawei Feng)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) [Orabug: 39886934] {CVE-2026-74497}
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) [Orabug: 39886938] {CVE-2026-74498}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) [Orabug: 39886942] {CVE-2026-74499}
- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)
- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)
- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) [Orabug: 39973390] {CVE-2026-80716}
- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)
- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) [Orabug: 39886955] {CVE-2026-74505}
- bpf: lwt: Fix dst reference leak on reroute failure (Luoxuanqiang)
- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) [Orabug: 39886962] {CVE-2026-74507}
- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) [Orabug: 39886966] {CVE-2026-74508}
- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) [Orabug: 39886979] {CVE-2026-74512}
- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)
- sctp: validate Adaptation Indication parameter length (Charles Vosburgh) [Orabug: 39973394] {CVE-2026-80717}
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) [Orabug: 39886994] {CVE-2026-74518}
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan)
- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)
- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) [Orabug: 39886997] {CVE-2026-74519}
- rhashtable: clear stale iter->p on table restart (Cen Zhang) [Orabug: 39830601] {CVE-2026-64563}
- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) [Orabug: 39887010] {CVE-2026-74523}
- octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh)
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu)
- can: isotp: check register_netdevice_notifier() error in module init (Heminhong)
- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)
- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao)
- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)
- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) [Orabug: 39887048] {CVE-2026-74540}
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)
- wifi: mac80211: validate individual TWT params before driver setup (Catherine) [Orabug: 39973406] {CVE-2026-80722}
- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) [Orabug: 39887070] {CVE-2026-74546}
- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) [Orabug: 39887075] {CVE-2026-74547}
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)
- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) [Orabug: 39887079] {CVE-2026-74548}
- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) [Orabug: 39887083] {CVE-2026-74549}
- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (Hyeongjun An) [Orabug: 39887102] {CVE-2026-74556}
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (Hyeongjun An) [Orabug: 39887106] {CVE-2026-74557}
- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei) [Orabug: 39890485] {CVE-2026-74579}
- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) [Orabug: 39887122] {CVE-2026-74564}
- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) [Orabug: 39887130] {CVE-2026-74566}
- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) [Orabug: 39887134] {CVE-2026-74567}
- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) [Orabug: 39887139] {CVE-2026-74569}
- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)
- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)
- phy: zynqmp: Allow variation in refclk rate (Sean Anderson)
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)
- tls: separate no-async decryption request handling from async (Sabrina Dubroca) [Orabug: 38369769] {CVE-2024-58240}
- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)
- net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam) [Orabug: 39410852] {CVE-2026-43491}
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)
- gve: fix Rx queue stall on alloc failure (Eddie Phillips) [Orabug: 39859432] {CVE-2026-68129}
- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)
- media: uvcvideo: Implement dual stream quirk to fix loss of usb packets (Isaac Scott)
- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) [Orabug: 39887158] {CVE-2026-74577}
- raw: fix a typo in raw_icmp_error() (Eric Dumazet)
- raw: remove unused variables from raw6_icmp_error() (Eric Dumazet)
- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) [Orabug: 39859412] {CVE-2026-68123}
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Lucid Duck)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi) [Orabug: 39794397] {CVE-2026-64543}
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) [Orabug: 39859340] {CVE-2026-68104}
- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) [Orabug: 39859350] {CVE-2026-68106}
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859370] {CVE-2026-68111}
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) [Orabug: 39868459] {CVE-2026-68430}
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859388] {CVE-2026-68115}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) [Orabug: 39859394] {CVE-2026-68117}
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) [Orabug: 39859407,40035525] {CVE-2026-68121}
- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) [Orabug: 39859418] {CVE-2026-68125}
- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito)
- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)
- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) [Orabug: 39859438] {CVE-2026-68131}
- proc: Fix broken error paths for namespace links (Jann Horn)
- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu)
- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee)
- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas)
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan)
- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) [Orabug: 39859477] {CVE-2026-68142}
- net: slip: serialize receive against buffer reallocation (Sungmin Kang) [Orabug: 39859481] {CVE-2026-68143}
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) [Orabug: 39868466] {CVE-2026-68432}
- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) [Orabug: 39859485] {CVE-2026-68144}
- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)
- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner)
- libceph: remove debugfs files before client teardown (Douya Le) [Orabug: 39859511] {CVE-2026-68153}
- libceph: reject zero bucket types in crush_decode (Douya Le) [Orabug: 39859515] {CVE-2026-68154}
- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) [Orabug: 39859519] {CVE-2026-68155}
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) [Orabug: 39859523] {CVE-2026-68156}
- libceph: guard missing CRUSH type name lookup (Zhao Zhang) [Orabug: 39859527] {CVE-2026-68157}
- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) [Orabug: 39859530] {CVE-2026-68158}
- libceph: bound get_version reply decode to front len (Douya Le) [Orabug: 39868471] {CVE-2026-68433}
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) [Orabug: 39859539] {CVE-2026-68160}
- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)
- Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon)
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu)
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu)
- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu)
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu)
- tracing: Fix resource leak on mmiotrace trace_pipe close (Deepakraog)
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev (Steven Rostedt)
- intel_th: fix MSC output device reference leak (Guangshuo Li) [Orabug: 39860420] {CVE-2026-68180}
- comedi: comedi_parport: deal with premature interrupt (Ian Abbott)
- x86/boot/compressed: Disable jump tables (Nathan Chancellor)
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) [Orabug: 39859601] {CVE-2026-68184}
- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) [Orabug: 39859611] {CVE-2026-68186}
- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) [Orabug: 39859614] {CVE-2026-68187}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) [Orabug: 39859618] {CVE-2026-68188}
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (Minjea Kim)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) [Orabug: 39859624] {CVE-2026-68190}
- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) [Orabug: 39859629] {CVE-2026-68192}
- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang)
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) [Orabug: 39859644] {CVE-2026-68197}
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) [Orabug: 39859652] {CVE-2026-68199}
- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil)
- media: vimc: fix reference leak on failed device registration (Guangshuo Li)
- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)
- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)
- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)
- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) [Orabug: 39859695] {CVE-2026-68212}
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) [Orabug: 39859699] {CVE-2026-68213}
- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) [Orabug: 39859704] {CVE-2026-68214}
- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak)
- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) [Orabug: 39859713] {CVE-2026-68216}
- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) [Orabug: 39859717] {CVE-2026-68217}
- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) [Orabug: 39859721] {CVE-2026-68218}
- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon)
- media: cx23885: add ioremap return check and cleanup (Wang Jun) [Orabug: 39859742] {CVE-2026-68226}
- media: cx231xx: fix devres lifetime (Johan Hovold) [Orabug: 39859746] {CVE-2026-68227}
- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou)
- media: cedrus: Fix missing cleanup in error path (Samuel Holland)
- media: cedrus: clean up media device on probe failure (Myeonghun Pak)
- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)
- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky)
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) [Orabug: 39868511] {CVE-2026-68446}
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) [Orabug: 39859766] {CVE-2026-68234}
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof)
- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) [Orabug: 39859792] {CVE-2026-68243}
- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) [Orabug: 39859795] {CVE-2026-68244}
- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) [Orabug: 39859809] {CVE-2026-68248}
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859812] {CVE-2026-68249}
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859816] {CVE-2026-68250}
- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka)
- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Xu Wang)
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) [Orabug: 39885108] {CVE-2026-72115}
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) [Orabug: 39885116] {CVE-2026-72117}
- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) [Orabug: 39885112] {CVE-2026-72116}
- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) [Orabug: 39885100] {CVE-2026-72113}
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) [Orabug: 39885104] {CVE-2026-72114}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) [Orabug: 39885124] {CVE-2026-72119}
- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) [Orabug: 39885120] {CVE-2026-72118}
- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) [Orabug: 39885133] {CVE-2026-72121}
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones) [Orabug: 39885141] {CVE-2026-72123}
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) [Orabug: 39859909] {CVE-2026-68284}
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li Rongqing)
- raw: use more conventional iterators (Eric Dumazet)
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)
- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) [Orabug: 39859940] {CVE-2026-68294}
- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)
- octeontx2-vf: set TC flower flag on MCAM entry allocation (Suman Ghosh)
- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)
- net: stmmac: add tc flower filter for EtherType matching (Ong Boon Leong)
- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang) [Orabug: 39859950] {CVE-2026-68297}
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) [Orabug: 39859955] {CVE-2026-68299}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Luoqing) [Orabug: 39859959] {CVE-2026-68300}
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) [Orabug: 39859963] {CVE-2026-68301}
- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) [Orabug: 39859973] {CVE-2026-68304}
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) [Orabug: 39859984] {CVE-2026-68309}
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) [Orabug: 39859996] {CVE-2026-68313}
- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei) [Orabug: 39837138] {CVE-2026-64576}
- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang) [Orabug: 39860003] {CVE-2026-68315}
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (Ji'An Zhou) [Orabug: 39860018] {CVE-2026-68320}
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar K R)
- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li Rongqing)
- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) [Orabug: 39860037] {CVE-2026-68325}
- wifi: mwifiex: bound uAP association event IEs to the event buffer (He Wei) [Orabug: 39860041] {CVE-2026-68326}
- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang)
- nfp: Check resource mutex allocation (Ruoyu Wang) [Orabug: 39860050] {CVE-2026-68328}
- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li)
- net: dpaa2-eth: assign priv->mac after dpaa2_mac_connect() call (Vladimir Oltean)
- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li)
- net/packet: avoid fanout hook re-registration after unregister (David Lee) [Orabug: 39860080] {CVE-2026-68338}
- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou)
- hwmon: (occ) Delay hwmon registration until user request (Eddie James)
- hwmon: (occ) Add sysfs entries for additional extended status bits (Eddie James)
- hwmon: (occ) Add sysfs entry for OCC mode (Eddie James)
- hwmon: (occ) Add sysfs entry for IPS (Idle Power Saver) status (Eddie James)
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860412] {CVE-2026-68344}
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)
- ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the endpoint (Jiaxin Yu)
- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) [Orabug: 39868530] {CVE-2026-68450}
- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) [Orabug: 39860107] {CVE-2026-68349}
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) [Orabug: 39860111] {CVE-2026-68350}
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) [Orabug: 39860115] {CVE-2026-68351}
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) [Orabug: 39860120] {CVE-2026-68352}
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) [Orabug: 39860124] {CVE-2026-68353}
- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) [Orabug: 39860128] {CVE-2026-68354}
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) [Orabug: 39860133] {CVE-2026-68355}
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih)
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis)
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) [Orabug: 39860156] {CVE-2026-68363}
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Zhang Xincheng)
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) [Orabug: 39622051] {CVE-2026-53090}
- Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin)
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)
- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)
- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)
- USB: serial: io_edgeport: cap received transmit credits (Sunho Park) [Orabug: 39860164] {CVE-2026-68365}
- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal)
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu)
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) [Orabug: 39860176] {CVE-2026-68368}
- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)
- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)
- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew)
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu)
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Wang Jinchao)
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) [Orabug: 39860193] {CVE-2026-68373}
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) [Orabug: 39837114] {CVE-2026-64569}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [Orabug: 39860205] {CVE-2026-68376}
- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) [Orabug: 39860209] {CVE-2026-68377}
- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)
- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei)
- can: j1939: fix lockless local-destination check (Shuhao Fu)
- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)
- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)
- sched/vtime: Get rid of generic vtime_task_switch() implementation (Alexander Gordeev)
- powerpc: remove the last remnants of cputime_t (Nick Piggin)
- powerpc/time: Fix sparse warnings (He Ying)
- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)
- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) [Orabug: 39860232] {CVE-2026-68388}
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei)
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev)
- ata: sata_dwc_460ex: remove variable num_processed (Colin Ian King)
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev)
- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas)
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) [Orabug: 39837128] {CVE-2026-64572}
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) [Orabug: 39860258] {CVE-2026-68398}
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)
- wifi: cfg80211: bound element ID read when checking non-inheritance (He Wei) [Orabug: 39860271] {CVE-2026-68402}
- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) [Orabug: 39860275] {CVE-2026-68403}
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) [Orabug: 39860283] {CVE-2026-68405}
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Catherine)
- wifi: cfg80211: validate PMSR FTM preamble range (Catherine) [Orabug: 39860288] {CVE-2026-68406}
- wifi: cfg80211: validate PMSR measurement type data (Catherine)
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) [Orabug: 39837123] {CVE-2026-64571}
- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) [Orabug: 39860298] {CVE-2026-68410}
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) [Orabug: 39860302] {CVE-2026-68411}
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) [Orabug: 39860309] {CVE-2026-68413}
- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) [Orabug: 39860313] {CVE-2026-68414}
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei) [Orabug: 39837149] {CVE-2026-64579}
- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)
- RDMA/siw: publish QP after initialization (Ruoyu Wang)
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (Guoqing Jiang)
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) [Orabug: 39868502] {CVE-2026-68444}
- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) [Orabug: 39860335] {CVE-2026-68422}
- btrfs: reject free space cache with more entries than pages (Xiang Mei) [Orabug: 39837107] {CVE-2026-64567}
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)
- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)
- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) [Orabug: 39860340] {CVE-2026-68425}
- KVM: VMX: Make vmread_error_trampoline() uncallable from C code (Sean Christopherson)
- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae)
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea)
- can: isotp: serialize TX state transitions under so->rx_lock (Oliver Hartkopp) [Orabug: 39885145] {CVE-2026-72124}
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) [Orabug: 39885148] {CVE-2026-72125}
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) [Orabug: 39860352] {CVE-2026-68428}
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) [Orabug: 39830595] {CVE-2026-64562}
- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko) [Orabug: 39884765] {CVE-2026-72019}
- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior) [Orabug: 39621655] {CVE-2026-52977}
- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg) [Orabug: 39789577] {CVE-2026-64535}

[5.15.0-325.213.2]
- crypto: qat: restore misc workqueue lifecycle (Manjunath Patil) [Orabug: 39899668]
- net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) [Orabug: 39859466,39925131] {CVE-2026-68139}
- proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (Zijie Wang) [Orabug: 39768459,39943963] {CVE-2025-38653}
- take care to handle NULL ->proc_lseek() (Al Viro) [Orabug: 39768459]
- sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) [Orabug: 39830606] {CVE-2026-64564}
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Zhu Yanjun) [Orabug: 39839301] {CVE-2026-64582}

[5.15.0-325.213.1]
- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi) [Orabug: 39651843,39918569] {CVE-2026-74517}
- KVM: x86: Free vCPUs before freeing VM state (Sean Christopherson) [Orabug: 39651843]
- KVM: x86: avoid loading a vCPU after .vm_destroy was called (Maxim Levitsky) [Orabug: 39651843]
- KVM: Move wiping of the kvm->vcpus array to common code (Marc Zyngier) [Orabug: 39651843]
- x86/alternatives: Guard struct alt_instr kABI layout (Saeed Mirzamohammadi) [Orabug: 39860417]
- ACPI: resource: Add TongFang GM6BGEQ, GM6BG5Q and GM6BG0Q to irq1_edge_low_force_override[] (Hans de Goede) [Orabug: 39838820]
- ACPI: resource: Fix IRQ override quirk for PCSpecialist Elimina Pro 16 M (Hans de Goede) [Orabug: 39838820]
- ACPI: resource: Add IRQ override quirk for PCSpecialist Elimina Pro 16 M (Hans de Goede) [Orabug: 39838820]
- ACPI: resource: Honor MADT INT_SRC_OVR settings for IRQ1 on AMD Zen (Hans de Goede) [Orabug: 39838820]


Related CVEs


CVE-2024-46754
CVE-2024-58240
CVE-2025-38653
CVE-2025-39925
CVE-2025-40102
CVE-2025-68794
CVE-2026-43088
CVE-2026-43198
CVE-2026-43437
CVE-2026-43491
CVE-2026-46158
CVE-2026-46170
CVE-2026-52977
CVE-2026-53089
CVE-2026-53090
CVE-2026-53242
CVE-2026-64098
CVE-2026-64192
CVE-2026-64270
CVE-2026-64272
CVE-2026-64294
CVE-2026-64427
CVE-2026-64434
CVE-2026-64535
CVE-2026-64543
CVE-2026-64562
CVE-2026-64563
CVE-2026-64564
CVE-2026-64567
CVE-2026-64569
CVE-2026-64571
CVE-2026-64572
CVE-2026-64576
CVE-2026-64579
CVE-2026-64581
CVE-2026-64582
CVE-2026-64585
CVE-2026-64586
CVE-2026-68082
CVE-2026-68096
CVE-2026-68104
CVE-2026-68106
CVE-2026-68111
CVE-2026-68115
CVE-2026-68117
CVE-2026-68121
CVE-2026-68123
CVE-2026-68125
CVE-2026-68129
CVE-2026-68131
CVE-2026-68132
CVE-2026-68138
CVE-2026-68139
CVE-2026-68142
CVE-2026-68143
CVE-2026-68144
CVE-2026-68146
CVE-2026-68153
CVE-2026-68154
CVE-2026-68155
CVE-2026-68156
CVE-2026-68157
CVE-2026-68158
CVE-2026-68159
CVE-2026-68160
CVE-2026-68162
CVE-2026-68180
CVE-2026-68184
CVE-2026-68186
CVE-2026-68187
CVE-2026-68188
CVE-2026-68190
CVE-2026-68192
CVE-2026-68197
CVE-2026-68198
CVE-2026-68199
CVE-2026-68202
CVE-2026-68205
CVE-2026-68212
CVE-2026-68213
CVE-2026-68214
CVE-2026-68216
CVE-2026-68217
CVE-2026-68218
CVE-2026-68226
CVE-2026-68227
CVE-2026-68234
CVE-2026-68243
CVE-2026-68244
CVE-2026-68248
CVE-2026-68249
CVE-2026-68250
CVE-2026-68253
CVE-2026-68254
CVE-2026-68255
CVE-2026-68277
CVE-2026-68278
CVE-2026-68279
CVE-2026-68284
CVE-2026-68294
CVE-2026-68297
CVE-2026-68299
CVE-2026-68300
CVE-2026-68301
CVE-2026-68304
CVE-2026-68309
CVE-2026-68313
CVE-2026-68315
CVE-2026-68320
CVE-2026-68325
CVE-2026-68326
CVE-2026-68328
CVE-2026-68338
CVE-2026-68344
CVE-2026-68349
CVE-2026-68350
CVE-2026-68351
CVE-2026-68352
CVE-2026-68353
CVE-2026-68354
CVE-2026-68355
CVE-2026-68363
CVE-2026-68365
CVE-2026-68367
CVE-2026-68368
CVE-2026-68373
CVE-2026-68376
CVE-2026-68377
CVE-2026-68388
CVE-2026-68398
CVE-2026-68402
CVE-2026-68403
CVE-2026-68405
CVE-2026-68406
CVE-2026-68410
CVE-2026-68411
CVE-2026-68413
CVE-2026-68414
CVE-2026-68422
CVE-2026-68425
CVE-2026-68428
CVE-2026-68430
CVE-2026-68432
CVE-2026-68433
CVE-2026-68434
CVE-2026-68444
CVE-2026-68446
CVE-2026-68450
CVE-2026-68476
CVE-2026-72015
CVE-2026-72019
CVE-2026-72035
CVE-2026-72045
CVE-2026-72051
CVE-2026-72053
CVE-2026-72057
CVE-2026-72063
CVE-2026-72065
CVE-2026-72070
CVE-2026-72073
CVE-2026-72087
CVE-2026-72096
CVE-2026-72099
CVE-2026-72110
CVE-2026-72113
CVE-2026-72114
CVE-2026-72115
CVE-2026-72116
CVE-2026-72117
CVE-2026-72118
CVE-2026-72119
CVE-2026-72121
CVE-2026-72123
CVE-2026-72124
CVE-2026-72125
CVE-2026-72142
CVE-2026-72152
CVE-2026-72155
CVE-2026-72170
CVE-2026-72242
CVE-2026-72252
CVE-2026-72253
CVE-2026-72255
CVE-2026-72299
CVE-2026-72305
CVE-2026-72323
CVE-2026-74268
CVE-2026-74378
CVE-2026-74443
CVE-2026-74444
CVE-2026-74453
CVE-2026-74455
CVE-2026-74456
CVE-2026-74457
CVE-2026-74458
CVE-2026-74460
CVE-2026-74461
CVE-2026-74464
CVE-2026-74465
CVE-2026-74469
CVE-2026-74470
CVE-2026-74471
CVE-2026-74473
CVE-2026-74475
CVE-2026-74479
CVE-2026-74480
CVE-2026-74481
CVE-2026-74482
CVE-2026-74485
CVE-2026-74486
CVE-2026-74487
CVE-2026-74488
CVE-2026-74490
CVE-2026-74492
CVE-2026-74495
CVE-2026-74497
CVE-2026-74498
CVE-2026-74499
CVE-2026-74505
CVE-2026-74507
CVE-2026-74508
CVE-2026-74512
CVE-2026-74517
CVE-2026-74518
CVE-2026-74519
CVE-2026-74523
CVE-2026-74540
CVE-2026-74546
CVE-2026-74547
CVE-2026-74548
CVE-2026-74549
CVE-2026-74556
CVE-2026-74557
CVE-2026-74564
CVE-2026-74566
CVE-2026-74567
CVE-2026-74569
CVE-2026-74575
CVE-2026-74577
CVE-2026-74579
CVE-2026-74580
CVE-2026-74581
CVE-2026-74582
CVE-2026-74583
CVE-2026-74585
CVE-2026-74586
CVE-2026-74587
CVE-2026-74588
CVE-2026-74589
CVE-2026-74594
CVE-2026-74595
CVE-2026-74597
CVE-2026-74598
CVE-2026-74599
CVE-2026-74601
CVE-2026-74604
CVE-2026-74609
CVE-2026-74613
CVE-2026-74614
CVE-2026-74615
CVE-2026-74616
CVE-2026-74620
CVE-2026-74621
CVE-2026-74622
CVE-2026-74623
CVE-2026-74625
CVE-2026-74626
CVE-2026-74628
CVE-2026-74630
CVE-2026-74632
CVE-2026-74635
CVE-2026-74636
CVE-2026-74637
CVE-2026-74641
CVE-2026-74648
CVE-2026-74649
CVE-2026-74650
CVE-2026-74651
CVE-2026-74654
CVE-2026-74656
CVE-2026-74657
CVE-2026-74658
CVE-2026-74660
CVE-2026-74662
CVE-2026-74663
CVE-2026-74664
CVE-2026-74666
CVE-2026-74667
CVE-2026-74668
CVE-2026-74669
CVE-2026-74671
CVE-2026-74673
CVE-2026-74675
CVE-2026-74676
CVE-2026-74679
CVE-2026-74680
CVE-2026-74682
CVE-2026-74683
CVE-2026-74688
CVE-2026-74696
CVE-2026-74697
CVE-2026-74701
CVE-2026-74704
CVE-2026-74705
CVE-2026-74717
CVE-2026-74720
CVE-2026-74726
CVE-2026-74730
CVE-2026-74746
CVE-2026-74748
CVE-2026-80527
CVE-2026-80528
CVE-2026-80534
CVE-2026-80536
CVE-2026-80540
CVE-2026-80541
CVE-2026-80557
CVE-2026-80558
CVE-2026-80561
CVE-2026-80569
CVE-2026-80570
CVE-2026-80574
CVE-2026-80586
CVE-2026-80587
CVE-2026-80590
CVE-2026-80678
CVE-2026-80681
CVE-2026-80706
CVE-2026-80707
CVE-2026-80714
CVE-2026-80715
CVE-2026-80716
CVE-2026-80717
CVE-2026-80722
CVE-2026-80731
CVE-2026-80733
CVE-2026-80737
CVE-2026-80742
CVE-2026-80744
CVE-2026-80754
CVE-2026-80756
CVE-2026-80757
CVE-2026-80765
CVE-2026-80767
CVE-2026-80781
CVE-2026-80782
CVE-2026-80783
CVE-2026-80788
CVE-2026-80789
CVE-2026-80790
CVE-2026-80792
CVE-2026-80793
CVE-2026-80805
CVE-2026-80806
CVE-2026-80808
CVE-2026-80809
CVE-2026-80812
CVE-2026-80814
CVE-2026-80819
CVE-2026-80824
CVE-2026-80827
CVE-2026-80828
CVE-2026-80829
CVE-2026-80830
CVE-2026-80840
CVE-2026-80842
CVE-2026-80843
CVE-2026-80844
CVE-2026-80854
CVE-2026-80855
CVE-2026-80856
CVE-2026-80863
CVE-2026-80889
CVE-2026-80890
CVE-2026-80906
CVE-2026-80908
CVE-2026-80909
CVE-2026-80913
CVE-2026-80916
CVE-2026-80917
CVE-2026-80918
CVE-2026-80923
CVE-2026-97509

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-uek-5.15.0-325.220.5.el8uek.src.rpm57b187c001d7c0a4d4d21fdeaafb517c7771fa36fdee0d70bdd8aa4e63120e90-ol8_aarch64_UEKR7
bpftool-5.15.0-325.220.5.el8uek.aarch64.rpm514ea2c1c35b295431fccadae7be8a92e6f1d615f39184847424a25fd5e44c5d-ol8_aarch64_UEKR7
kernel-uek-5.15.0-325.220.5.el8uek.aarch64.rpm96a17baa555990e42589d8377582cffedb5fe555b1e6dad101c2a0be215b61aa-ol8_aarch64_UEKR7
kernel-uek-container-5.15.0-325.220.5.el8uek.aarch64.rpm36ee13aa00722ae6ddbd955378eb3bfe3793361ba850594c510eca3d9eb4d8e7-ol8_aarch64_UEKR7
kernel-uek-container-debug-5.15.0-325.220.5.el8uek.aarch64.rpm26f794c78bfd2de0f00889b0dc8857bb826a95bc320e750421cb683791032e3a-ol8_aarch64_UEKR7
kernel-uek-core-5.15.0-325.220.5.el8uek.aarch64.rpm33b3a7aebb36164dc6bf42c93f056c9eca06a05fc28510968c10ea46610a9e54-ol8_aarch64_UEKR7
kernel-uek-debug-5.15.0-325.220.5.el8uek.aarch64.rpmc9801fc69a801ddbec8715eb4f9ca225300fce9d71f2157d01aa03a6aa054de1-ol8_aarch64_UEKR7
kernel-uek-debug-core-5.15.0-325.220.5.el8uek.aarch64.rpm4771c10e3b7318e57f38e7cd43a1deba7fc77d571b0526e4df9605f209a909b7-ol8_aarch64_UEKR7
kernel-uek-debug-devel-5.15.0-325.220.5.el8uek.aarch64.rpmc01d03df8eda54ffac59fda6d1c8e4b9516b0f4bc61af6482f6a94ae830ce105-ol8_aarch64_UEKR7
kernel-uek-debug-modules-5.15.0-325.220.5.el8uek.aarch64.rpm847fb31a12b09e894a005755c805a1ff00a30cfe36603537656b6c9c0c1fa67b-ol8_aarch64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-325.220.5.el8uek.aarch64.rpma75713068c6f50b2fd4051e275d819d6848eaf10c4dcd5afb345c3ec6fdabe97-ol8_aarch64_UEKR7
kernel-uek-devel-5.15.0-325.220.5.el8uek.aarch64.rpmf0da144a68adc8ca48eff097890c94fa5b360bbc64607feab0244ec62245c26f-ol8_aarch64_UEKR7
kernel-uek-doc-5.15.0-325.220.5.el8uek.noarch.rpmade317169797e694a27152121e5809cfd8008a91d742f2ae3ca541e210648815-ol8_aarch64_UEKR7
kernel-uek-modules-5.15.0-325.220.5.el8uek.aarch64.rpmddf1bfc70df5cf3a9c8c91d7dbe224b01f9fa5e2ca47c974a2ce7e8093143970-ol8_aarch64_UEKR7
kernel-uek-modules-extra-5.15.0-325.220.5.el8uek.aarch64.rpmfc4dd17a50dbc7b9c567bc5ed216fbaa15c07ef4cb1bb96e3833349bbec9657b-ol8_aarch64_UEKR7
Oracle Linux 8 (x86_64) kernel-uek-5.15.0-325.220.5.el8uek.src.rpm57b187c001d7c0a4d4d21fdeaafb517c7771fa36fdee0d70bdd8aa4e63120e90-ol8_x86_64_UEKR7
bpftool-5.15.0-325.220.5.el8uek.x86_64.rpm40e6dffe5183602a88802b50eedd372c662fbcdbf9fe744840eee6c3d7d32757-ol8_x86_64_UEKR7
kernel-uek-5.15.0-325.220.5.el8uek.x86_64.rpm2db2f544ba4beff563b4fdf459807c15777863ddf0e2957144d984dd315ff004-ol8_x86_64_UEKR7
kernel-uek-container-5.15.0-325.220.5.el8uek.x86_64.rpm183dc2f7cf358968cb9df5d551f00eb23ddcbaf1e5ca700b0ef1a3c8784b00c9-ol8_x86_64_UEKR7
kernel-uek-container-debug-5.15.0-325.220.5.el8uek.x86_64.rpme3711ea0231e204c76880a7ed7cfe6b33142bd918177ecf6d9db62df4d9b9c58-ol8_x86_64_UEKR7
kernel-uek-core-5.15.0-325.220.5.el8uek.x86_64.rpmd5082f20e7d06bf90f2c86980569db13c276dabb8a46a8ffd40bc8bdf57709c0-ol8_x86_64_UEKR7
kernel-uek-debug-5.15.0-325.220.5.el8uek.x86_64.rpm768af14c5fba8b840d538def6e4fb1326d41a9bcb59d892cb2bcdfe5b3619374-ol8_x86_64_UEKR7
kernel-uek-debug-core-5.15.0-325.220.5.el8uek.x86_64.rpm02ae8b5e8ae3235a317b2ae1caea9f2356aaecc197a4f469c8aa6711f0df3965-ol8_x86_64_UEKR7
kernel-uek-debug-devel-5.15.0-325.220.5.el8uek.x86_64.rpm70da38e25dbf7d81c7e69b1d571686b7264cae5f571538bef1d9db4d7bd71cdf-ol8_x86_64_UEKR7
kernel-uek-debug-modules-5.15.0-325.220.5.el8uek.x86_64.rpm4bc3864bdd3ca64052c7f017519121efa53a5f058e29c296d85ed8ede5b61e00-ol8_x86_64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-325.220.5.el8uek.x86_64.rpme2c207dd8c22a8b768c4cc9549cca8756f4778dccccc1892c2b22d3b407c8883-ol8_x86_64_UEKR7
kernel-uek-devel-5.15.0-325.220.5.el8uek.x86_64.rpm024de4fa4a7261bd59e21648a02e7a14bce72ff950dd84a05d6e4d10a9c5cdd0-ol8_x86_64_UEKR7
kernel-uek-doc-5.15.0-325.220.5.el8uek.noarch.rpmade317169797e694a27152121e5809cfd8008a91d742f2ae3ca541e210648815-ol8_x86_64_UEKR7
kernel-uek-modules-5.15.0-325.220.5.el8uek.x86_64.rpm0dfa47988c9b1086e38d0c1515110ce8a965795931872918bcce84bf89844e2c-ol8_x86_64_UEKR7
kernel-uek-modules-extra-5.15.0-325.220.5.el8uek.x86_64.rpmdc3c4e763de85aca68550a6ca4a963b465e43f2f98b2b7cbaee72ba0d81e5218-ol8_x86_64_UEKR7
Oracle Linux 9 (aarch64) kernel-uek-5.15.0-325.220.5.el9uek.src.rpm0887cef0e244f9e3ada7ccc2cb8587be1190faa57146c1e2daddec8f8393c5a9-ol9_aarch64_baseos_latest
kernel-uek-5.15.0-325.220.5.el9uek.src.rpm0887cef0e244f9e3ada7ccc2cb8587be1190faa57146c1e2daddec8f8393c5a9-ol9_aarch64_u8_baseos_patch
bpftool-5.15.0-325.220.5.el9uek.aarch64.rpmf595f414dcaea7b10ca0856e53b7bf57298460b834392ec5239b5f2ca21d89c7-ol9_aarch64_baseos_latest
bpftool-5.15.0-325.220.5.el9uek.aarch64.rpmf595f414dcaea7b10ca0856e53b7bf57298460b834392ec5239b5f2ca21d89c7-ol9_aarch64_u8_baseos_patch
kernel-uek-5.15.0-325.220.5.el9uek.aarch64.rpmd28980b14ca47e907719066568c9f9d994e51cad1e610aa3585001824b1bb3d7-ol9_aarch64_baseos_latest
kernel-uek-5.15.0-325.220.5.el9uek.aarch64.rpmd28980b14ca47e907719066568c9f9d994e51cad1e610aa3585001824b1bb3d7-ol9_aarch64_u8_baseos_patch
kernel-uek-container-5.15.0-325.220.5.el9uek.aarch64.rpmcaa9d56d4b1a8e3150d66277f77fb75869a66c4f5b6cee8b1512b29bbf63e449-ol9_aarch64_baseos_latest
kernel-uek-container-5.15.0-325.220.5.el9uek.aarch64.rpmcaa9d56d4b1a8e3150d66277f77fb75869a66c4f5b6cee8b1512b29bbf63e449-ol9_aarch64_u8_baseos_patch
kernel-uek-container-debug-5.15.0-325.220.5.el9uek.aarch64.rpmb072bce96ddcc9d4e49aea5ab8fd715e73f2d39a06b9bfa9cfdd1ff0dda4e35a-ol9_aarch64_baseos_latest
kernel-uek-container-debug-5.15.0-325.220.5.el9uek.aarch64.rpmb072bce96ddcc9d4e49aea5ab8fd715e73f2d39a06b9bfa9cfdd1ff0dda4e35a-ol9_aarch64_u8_baseos_patch
kernel-uek-core-5.15.0-325.220.5.el9uek.aarch64.rpm6669aaf48456edbd0c2cf90a99f27f455a45d142774a26244c50f08567985469-ol9_aarch64_baseos_latest
kernel-uek-core-5.15.0-325.220.5.el9uek.aarch64.rpm6669aaf48456edbd0c2cf90a99f27f455a45d142774a26244c50f08567985469-ol9_aarch64_u8_baseos_patch
kernel-uek-debug-5.15.0-325.220.5.el9uek.aarch64.rpm5d906d95fac76e7bd7f916370edee38d86fcbf45572debff6fe486b20a44598f-ol9_aarch64_baseos_latest
kernel-uek-debug-5.15.0-325.220.5.el9uek.aarch64.rpm5d906d95fac76e7bd7f916370edee38d86fcbf45572debff6fe486b20a44598f-ol9_aarch64_u8_baseos_patch
kernel-uek-debug-core-5.15.0-325.220.5.el9uek.aarch64.rpmc412a473840ee85be6b7c2e96513a47753f259c753bcbf129ff006dc519a4061-ol9_aarch64_baseos_latest
kernel-uek-debug-core-5.15.0-325.220.5.el9uek.aarch64.rpmc412a473840ee85be6b7c2e96513a47753f259c753bcbf129ff006dc519a4061-ol9_aarch64_u8_baseos_patch
kernel-uek-debug-devel-5.15.0-325.220.5.el9uek.aarch64.rpmb792856cfaba91cb647de865f956212b2070eef34fb673753d1c69e0f7f571a9-ol9_aarch64_baseos_latest
kernel-uek-debug-devel-5.15.0-325.220.5.el9uek.aarch64.rpmb792856cfaba91cb647de865f956212b2070eef34fb673753d1c69e0f7f571a9-ol9_aarch64_u8_baseos_patch
kernel-uek-debug-modules-5.15.0-325.220.5.el9uek.aarch64.rpm9180be64eef432ec0f9472b3e6fa4ad1cd46b0ec251298e5fd946aba161364cf-ol9_aarch64_baseos_latest
kernel-uek-debug-modules-5.15.0-325.220.5.el9uek.aarch64.rpm9180be64eef432ec0f9472b3e6fa4ad1cd46b0ec251298e5fd946aba161364cf-ol9_aarch64_u8_baseos_patch
kernel-uek-debug-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpmae76e69fbe65439eb44d2209dace69f325638469e633f47649407e446197d919-ol9_aarch64_baseos_latest
kernel-uek-debug-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpmae76e69fbe65439eb44d2209dace69f325638469e633f47649407e446197d919-ol9_aarch64_u8_baseos_patch
kernel-uek-devel-5.15.0-325.220.5.el9uek.aarch64.rpm9ed0cb34d45111c91fda002a406b4b7c23c97ff426db90902f48c8505963c641-ol9_aarch64_baseos_latest
kernel-uek-devel-5.15.0-325.220.5.el9uek.aarch64.rpm9ed0cb34d45111c91fda002a406b4b7c23c97ff426db90902f48c8505963c641-ol9_aarch64_u8_baseos_patch
kernel-uek-doc-5.15.0-325.220.5.el9uek.noarch.rpmd90c8826199df8ff0a2339c4970a1e62f856b0a00f53b0028443b5576a2d74c7-ol9_aarch64_baseos_latest
kernel-uek-doc-5.15.0-325.220.5.el9uek.noarch.rpmd90c8826199df8ff0a2339c4970a1e62f856b0a00f53b0028443b5576a2d74c7-ol9_aarch64_u8_baseos_patch
kernel-uek-modules-5.15.0-325.220.5.el9uek.aarch64.rpmb20b2ab33fe23a015e97dbb504052dc834a5d1ba7a65ae517bae74c5c7c4cce2-ol9_aarch64_baseos_latest
kernel-uek-modules-5.15.0-325.220.5.el9uek.aarch64.rpmb20b2ab33fe23a015e97dbb504052dc834a5d1ba7a65ae517bae74c5c7c4cce2-ol9_aarch64_u8_baseos_patch
kernel-uek-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpm2074d066962fc7c2144f6651c553d5c3adf2f37031e921493f983384b306351e-ol9_aarch64_baseos_latest
kernel-uek-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpm2074d066962fc7c2144f6651c553d5c3adf2f37031e921493f983384b306351e-ol9_aarch64_u8_baseos_patch
kernel-uek64k-5.15.0-325.220.5.el9uek.aarch64.rpm7232074e544755bb5a37364775dddb5ae51b6cb8da5d610a08df1f1e4b85f5bf-ol9_aarch64_baseos_latest
kernel-uek64k-5.15.0-325.220.5.el9uek.aarch64.rpm7232074e544755bb5a37364775dddb5ae51b6cb8da5d610a08df1f1e4b85f5bf-ol9_aarch64_u8_baseos_patch
kernel-uek64k-core-5.15.0-325.220.5.el9uek.aarch64.rpm337fac3f86a4735291aabecee3ea57e8384f55b7d50b92df0cd7e3f215c5b9c6-ol9_aarch64_baseos_latest
kernel-uek64k-core-5.15.0-325.220.5.el9uek.aarch64.rpm337fac3f86a4735291aabecee3ea57e8384f55b7d50b92df0cd7e3f215c5b9c6-ol9_aarch64_u8_baseos_patch
kernel-uek64k-devel-5.15.0-325.220.5.el9uek.aarch64.rpmf6fd3c93467ce56d68385d0960d0e377e779a16dfbcfd4a5438840049ccea2de-ol9_aarch64_baseos_latest
kernel-uek64k-devel-5.15.0-325.220.5.el9uek.aarch64.rpmf6fd3c93467ce56d68385d0960d0e377e779a16dfbcfd4a5438840049ccea2de-ol9_aarch64_u8_baseos_patch
kernel-uek64k-modules-5.15.0-325.220.5.el9uek.aarch64.rpm24155fa31005adb555da35f4f83249e05fb1483990368701cf55c695e0e80f7f-ol9_aarch64_baseos_latest
kernel-uek64k-modules-5.15.0-325.220.5.el9uek.aarch64.rpm24155fa31005adb555da35f4f83249e05fb1483990368701cf55c695e0e80f7f-ol9_aarch64_u8_baseos_patch
kernel-uek64k-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpm4c77f5016ad087662f48e671a45013238782049aa25ef162b514c37387a8f314-ol9_aarch64_baseos_latest
kernel-uek64k-modules-extra-5.15.0-325.220.5.el9uek.aarch64.rpm4c77f5016ad087662f48e671a45013238782049aa25ef162b514c37387a8f314-ol9_aarch64_u8_baseos_patch
Oracle Linux 9 (x86_64) kernel-uek-5.15.0-325.220.5.el9uek.src.rpm0887cef0e244f9e3ada7ccc2cb8587be1190faa57146c1e2daddec8f8393c5a9-ol9_x86_64_UEKR7
bpftool-5.15.0-325.220.5.el9uek.x86_64.rpmead6321c99986f6260382cea8a451a57de7aa39c3a25750081be89fd927c6218-ol9_x86_64_UEKR7
kernel-uek-5.15.0-325.220.5.el9uek.x86_64.rpmcfbb01f95218299a5df3d2fbb09b51af93ca04068f643c5abfc06b49d295b8dd-ol9_x86_64_UEKR7
kernel-uek-container-5.15.0-325.220.5.el9uek.x86_64.rpmd47d656becfe2af000adf4f10044b15ffda5c769a9cd6453d3733053ff55086f-ol9_x86_64_UEKR7
kernel-uek-container-debug-5.15.0-325.220.5.el9uek.x86_64.rpmdd86e13f952fe2273164c95f8cd86f1112aac018f563845a1082828d4ef2d612-ol9_x86_64_UEKR7
kernel-uek-core-5.15.0-325.220.5.el9uek.x86_64.rpm6651c3998f6bad23184d7cc4c44e1295dcf6fb2e3a85dc897dfee459bd43c487-ol9_x86_64_UEKR7
kernel-uek-debug-5.15.0-325.220.5.el9uek.x86_64.rpm2b64ded1887fe958ba760fd596e8c71007d4c50cfb8aa23262807c437d279699-ol9_x86_64_UEKR7
kernel-uek-debug-core-5.15.0-325.220.5.el9uek.x86_64.rpm228fa12055b5f4c911b850e2bf3ff060ef8e63646ca7326a4a161a8f62e61ea2-ol9_x86_64_UEKR7
kernel-uek-debug-devel-5.15.0-325.220.5.el9uek.x86_64.rpmb2e8051d336f69e271a075796962b9c31a8c8bf0285e7dd5189a99bf7deb86dc-ol9_x86_64_UEKR7
kernel-uek-debug-modules-5.15.0-325.220.5.el9uek.x86_64.rpm2b2e9d47d7b09762d756ea86ab3e511980f48ed399ea457ecd8ad5d313597940-ol9_x86_64_UEKR7
kernel-uek-debug-modules-extra-5.15.0-325.220.5.el9uek.x86_64.rpm6ed1e7d03c02581afeafa3d828507d9b4394504e842958fbbb84a776c6ba6adb-ol9_x86_64_UEKR7
kernel-uek-devel-5.15.0-325.220.5.el9uek.x86_64.rpmcf12b53ebb18e2cf5046d14c08cc246e0f371d22466dd80d70a8dfc54d5cfd7e-ol9_x86_64_UEKR7
kernel-uek-doc-5.15.0-325.220.5.el9uek.noarch.rpmd90c8826199df8ff0a2339c4970a1e62f856b0a00f53b0028443b5576a2d74c7-ol9_x86_64_UEKR7
kernel-uek-modules-5.15.0-325.220.5.el9uek.x86_64.rpm28ebc9c0f3fb69f1d0e9c5490db8f5080b2206876510028b72c762d8985df9d6-ol9_x86_64_UEKR7
kernel-uek-modules-extra-5.15.0-325.220.5.el9uek.x86_64.rpm1ab5ac8f3a90b5a02a5e2f69ad0cdcfdd793167ae8eddd292b2840163bdfcb03-ol9_x86_64_UEKR7



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete