-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Jul 2026 11:44:47 +0200
Source: linux-signed-amd64
Architecture: source
Version: 5.10.262+1
Distribution: bullseye-security
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Emilio Pozuelo Monfort <pochu@debian.org>
Changes:
linux-signed-amd64 (5.10.262+1) bullseye-security; urgency=medium
.
* Sign kernel from linux 5.10.262-1
.
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.260
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys
- net/sched: transition act_pedit to rcu and percpu stats
- net/sched: simplify tcf_pedit_act
- net/sched: act_pedit: remove extra check for key type
- net/sched: act_pedit: check static offsets a priori
- net/sched: act_pedit: rate limit datapath messages
- net/sched: act_pedit: Parse L3 Header for L4 offset
- net/sched: fix pedit partial COW leading to page cache corruption
(CVE-2026-46331)
- net/sched: act_pedit: free pedit keys on bail from offset check
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167)
- [arm*] slimbus: qcom-ngd-ctrl: Register callbacks after creating the
ngd
(CVE-2026-53332)
- drm/amd/display: Bound VBIOS record-chain walk loops (CVE-2026-53138)
- net: add skb_header_pointer_careful() helper
- net/sched: cls_u32: use skb_header_pointer_careful() (CVE-2026-23204)
- drm/amd/display: Use krealloc_array() in dal_vector_reserve()
(CVE-2026-53329)
- net: 9p: fix refcount leak in p9_read_work() error handling
(CVE-2022-50114)
- netdevsim: Fix memory leak of nsim_dev->fa_cookie (CVE-2022-49803)
- batman-adv: tt: reject oversized local TVLV buffers
- batman-adv: tt: prevent TVLV entry number overflow
- vfio/iommu_type1: replace kfree with kvfree
- RDMA/bnxt_re: zero shared page before exposing to userspace
- i2c: stub: Reject I2C block transfers with invalid length
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
- [x86] agp/amd64: Fix broken error propagation in agp_amd64_probe()
(CVE-2026-53325)
- regulator: core: fix locking in regulator_resolve_supply() error path
(CVE-2026-46252)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent
vcs_write
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
- [x86] crypto: qat - Replace kzalloc() + copy_from_user() with
memdup_user()
- [x86] crypto: qat - Return pointer directly in
adf_ctl_alloc_resources
- [x86] crypto: qat - remove unused character device and IOCTLs
- net/sched: act_pedit: fix action bind logic
- batman-adv: tp_meter: keep unacked list in ascending ordered
- batman-adv: tp_meter: initialize dup_acks explicitly
- batman-adv: tp_meter: initialize dec_cwnd explicitly
- batman-adv: tp_meter: avoid window underflow
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
- batman-adv: tp_meter: fix fast recovery precondition
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery
detection
- batman-adv: tp_meter: add only finished tp_vars to lists
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
- batman-adv: prevent ELP transmission interval underflow
- batman-adv: tp_meter: initialize last_recv_time during init
- batman-adv: frag: ensure fragment is writable before modifying TTL
- batman-adv: frag: avoid underflow of TTL
- batman-adv: v: prevent OGM aggregation on disabled hardif
- batman-adv: tp_meter: restrict number of unacked list entries
- batman-adv: tp_meter: annotate last_recv_time access with
READ/WRITE_ONCE
- batman-adv: tp_meter: prevent parallel modifications of last_recv
- batman-adv: tp_meter: handle overlapping packets
- batman-adv: tt: don't merge change entries with different VIDs
- batman-adv: tt: track roam count per VID
- batman-adv: dat: prevent false sharing between VLANs
- batman-adv: tvlv: enforce 2-byte alignment
- batman-adv: tvlv: avoid race of cifsnotfound handler state
- ring-buffer: Remove ring_buffer_read_prepare_sync()
- ext4: add bounds check for inline data length in
ext4_read_inline_page
(CVE-2026-31451)
- crypto: af_alg - Set merge to zero early in af_alg_sendmsg
(CVE-2025-39931)
- [armel,armhf] net: cpsw_new: Fix potential unregister of netdev that
has
not been registered yet (CVE-2026-43219)
- mac802154: llsec: add skb_cow_data() before in-place crypto
- KEYS: fix overflow in keyctl_pkey_params_get_2()
- keys: Pin request_key_auth payload in instantiate paths
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
- wifi: ath11k: fix warning when unbinding
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
- bpf: use kvfree() for replaced sysctl write buffer
- exfat: fix potential use-after-free in exfat_find_dir_entry()
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
- pNFS: Fix use-after-free in pnfs_update_layout()
- fpga: region: fix use-after-free in child_regions_with_firmware()
- ocfs2: reject oversized group bitmap descriptors
- [x86] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in
fb_videomode_to_var
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
- NFSD: Fix SECINFO_NO_NAME decode error cleanup
- nfsd: fix posix_acl leak on SETACL decode failure
- nfsd: check get_user() return when reading princhashlen
- dlm: prevent NPD when writing a positive value to event_done
(CVE-2025-23131)
- usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
(CVE-2026-31755)
- bnxt_en: Modify bnxt_disable_int_sync() to be called more than once.
- bnxt_en: Fix NULL pointer dereference (CVE-2026-53177)
- [x86] hv: utils: handle and propagate errors in kvp_register
- mptcp: fix missing wakeups in edge scenarios
- [arm*] misc: fastrpc: Add dma_mask to fastrpc_channel_ctx
- [arm*] misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
(CVE-2026-53158)
- [x86] Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on
Gen2
VMs
- phonet: Pass ifindex to fill_addr().
- phonet: Pass net and ifindex to phonet_address_notify().
- net: phonet: free phonet_device after RCU grace period
(CVE-2026-53157)
- [arm*] misc: fastrpc: fix DMA address corruption due to find_vma
misuse
(CVE-2026-53159)
- virtiofs: fix UAF on submount umount
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.261
- nvmet-tcp: fix race between ICReq handling and queue teardown
(CVE-2026-46135)
- nfsd: release layout stid on setlease failure (CVE-2026-53399)
- nfsd: reset write verifier on deferred writeback errors
(CVE-2026-53393)
- userfaultfd: gate must_wait writability check on pte_present()
(CVE-2026-64514)
- clk: imx: Add check for kcalloc
- nfsd: move name lookup out of nfsd4_list_rec_dir()
- nfsd: change nfs4_client_to_reclaim() to allocate data
- mmc: renesas_sdhi: Add quirk entry for RZ/G2H SoC
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
get_unaligned() (CVE-2026-63806)
- bus: mhi: host: Add alignment check for event ring read pointer
(CVE-2023-52494)
- netfilter: nf_log: validate MAC header was set before dumping it
(CVE-2026-52942)
- skmsg: convert struct sk_msg_sg::copy to a bitmap
- net: skmsg: preserve sg.copy across SG transforms (CVE-2026-63830)
- apparmor: fix use-after-free in rawdata dedup loop (CVE-2026-63827)
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
(CVE-2026-63829)
- apparmor: mediate the implicit connect of TCP fast open sendmsg
(CVE-2026-63828)
- f2fs: adjust zone capacity when considering valid block count
- f2fs: fix to round down start offset of fallocate for pin file
- f2fs: validate orphan inode entry count (CVE-2026-63818)
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
(CVE-2026-63815)
- f2fs: fix potential deadlock in f2fs_balance_fs()
- f2fs: fix listxattr handling of corrupted xattr entries
- NFSv4/flexfiles: reject zero filehandle version count
(CVE-2026-53392)
- fbdev: fbcon: fix out-of-bounds read in err_out of
fbcon_do_set_font() (CVE-2026-53402)
- i2c: core: fix irq domain leak on adapter registration failure
- i2c: core: fix hang on adapter registration failure
- i2c: core: fix NULL-deref on adapter registration failure
- i2c: core: fix adapter debugfs creation
- i2c: core: fix adapter registration race (CVE-2026-53400)
- hdlc_ppp: sync per-proto timers before freeing hdlc state
(CVE-2026-63803)
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
(CVE-2026-46116)
- usb: gadget: function: rndis: add length check to response query
- usb: gadget: function: rndis: add length check for header
(CVE-2026-64505)
- iio: accel: bmc150: clamp the device-reported FIFO frame count
(CVE-2026-64504)
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
(CVE-2026-64503)
- iio: adc: lpc32xx: Initialize completion before requesting IRQ
(CVE-2026-64500)
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors
- iio: chemical: scd30: Cleanup initializations and fix sign-extension
bug (CVE-2026-64497)
- iio: event: Fix event FIFO reset race (CVE-2026-64496)
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table
(CVE-2026-64495)
- iio: gyro: bmg160: wait full startup time after mode change at probe
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami
- iio: light: al3010: fix incorrect scale for the highest gain range
- iio: light: gp2ap002: fix runtime PM leak on read error
(CVE-2026-64494)
- iio: light: opt3001: fix missing state reset on timeout
- iio: light: veml6030: fix channel type when pushing events
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend()
call
- iio: temperature: ltc2983: Fix reinit_completion() called after
conversion start
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input
parser (CVE-2026-64487)
- ALSA: es1938: check snd_ctl_new1() return value (CVE-2026-64484)
- ALSA: firewire: isight: bound the sample count to the packet payload
(CVE-2026-64483)
- ALSA: usb-audio: avoid kobject path lookup in DualSense match
(CVE-2026-64478)
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix
EQ-switch put callbacks
- ALSA: usb-audio: Roll back quirk control caches on write errors
- ALSA: usb-audio: Update Babyface Pro control caches only after
successful writes
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after
successful writes
- Bluetooth: btusb: fix use-after-free on registration failure
(CVE-2026-64471)
- binder: fix UAF in binder_thread_release() (CVE-2026-64469)
- usb: xhci: Fix sleep in atomic context in xhci_free_streams()
(CVE-2026-64465)
- PCI: altera: Do not dispose parent IRQ mapping
- PCI: host-common: Request bus reassignment when not probe-only
- netfilter: ipset: fix race between dump and ip_set_list resize
(CVE-2026-64189)
- virtio-mmio: fix device release warning on module unload
- hwrng: virtio: clamp device-reported used.len at copy_data()
(CVE-2026-64456)
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
(CVE-2026-64455)
- 6lowpan: fix NHC entry use-after-free on error path (CVE-2026-64452)
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks
(CVE-2026-64450)
- media: staging: ipu3-imgu: Add range check for
imgu_css_cfg_acc_stripe
- crypto: amlogic - avoid double cleanup in meson_crypto_probe()
- net: af_key: initialize alg_key_len for IPComp states
(CVE-2026-64436)
- audit: Fix data races of skb_queue_len() readers on audit_queue
(CVE-2026-64435)
- debugobjects: Plug race against a concurrent OOM disable
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path
(CVE-2026-64429)
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
(CVE-2026-64425)
- ipv4: igmp: remove multicast group from hash table on device
destruction (CVE-2026-64423)
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
(CVE-2026-64422)
- mfd: cros_ec: Delay dev_set_drvdata() until probe success
(CVE-2026-64420)
- netfilter: ebtables: module names must be null-terminated
(CVE-2026-64412)
- netfilter: ebtables: terminate table name before find_table_lock()
(CVE-2026-64411)
- Bluetooth: bnep: pin L2CAP connection during netdev registration
(CVE-2026-64408)
- Bluetooth: fix UAF in bt_accept_dequeue() (CVE-2026-64406)
- Bluetooth: L2CAP: validate option length before reading conf opt
value (CVE-2026-64403)
- net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216)
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
(CVE-2026-64374)
- cpufreq: Fix hotplug-suspend race during reboot (CVE-2026-64373)
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
(CVE-2026-64372)
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error
path (CVE-2026-64370)
- HID: wacom: stop hardware after post-start probe failures
- HID: lg-g15: cancel pending work on remove to fix a use-after-free
(CVE-2026-64362)
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for
multi-byte reads
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
(CVE-2026-64360)
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
(CVE-2026-64359)
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
(CVE-2026-64351)
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG
handler (CVE-2026-64347)
- USB: idmouse: fix use-after-free on disconnect race (CVE-2026-64344)
- USB: ldusb: fix use-after-free on disconnect race (CVE-2026-64343)
- USB: iowarrior: fix use-after-free on disconnect (CVE-2026-64342)
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
- USB: legousbtower: fix use-after-free on disconnect race
(CVE-2026-64340)
- usb: sl811-hcd: disable controller wakeup on remove
- USB: storage: include US_FL_NO_SAME in quirks mask
- USB: misc: uss720: unregister parport on probe failure
(CVE-2026-64338)
- usb: mtu3: unmap request DMA on queue failure (CVE-2026-64337)
- USB: serial: option: add Telit Cinterion FE990D50 compositions
- USB: serial: digi_acceleport: fix broken rx after throttle
(CVE-2026-64335)
- USB: serial: digi_acceleport: fix hard lockup on disconnect
(CVE-2026-64334)
- USB: ulpi: fix memory leak on registration failure (CVE-2026-64332)
- USB: usb-storage: ene_ub6250: restore media-ready check
- usbip: tools: support SuperSpeedPlus devices
- usbip: vudc: fix NULL deref in vep_dequeue() (CVE-2026-64331)
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
(CVE-2026-64330)
- usb: typec: ucsi: Invert DisplayPort role assignment
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP
alt mode
- iio: adc: spear: Initialize completion before requesting IRQ
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation
check
- udf: validate free block extents against the partition length
(CVE-2026-64324)
- udf: validate VAT header length against the VAT inode size
(CVE-2026-64323)
- udf: validate sparing table length as an entry count, not a byte
count (CVE-2026-64322)
- dm-ioctl: report an error if a device has no table
- partitions: aix: bound the pp_count scan to the ppe array
(CVE-2026-64318)
- isofs: bound Rock Ridge symlink components to the SL record
(CVE-2026-64317)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps
(CVE-2026-64316) (CVE-2026-64315)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps
(CVE-2026-64316) (CVE-2026-64315) again
- crypto: ecc - Fix carry overflow in vli multiplication
(CVE-2026-64313)
- crypto: pcrypt - restore callback for non-parallel fallback
(CVE-2026-64312)
- crypto: drbg - Fix returning success on failure in CTR_DRBG
(CVE-2026-64306)
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
- crypto: drbg - Fix the fips_enabled priority boost
- crypto: talitos - use dma_sync_single_for_cpu() before reading
descriptor header
- spi: fsl-lpspi: replace dmaengine_terminate_all() with
dmaengine_terminate_sync()
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
(CVE-2026-64303)
- tracing: Prevent out-of-bounds read in glob matching (CVE-2026-64299)
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
(CVE-2026-64298)
- exfat: bound uniname advance in exfat_find_dir_entry()
(CVE-2026-64296)
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest
mode
- udmabuf: fix DMA direction mismatch in release_udmabuf()
- i2c: stm32f7: truncate clock period instead of rounding it
- Input: synaptics-rmi4 - unregister function handlers on physical
driver registration failure
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
(CVE-2026-64277)
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
(CVE-2026-64276)
- Input: elan_i2c - prevent division by zero and arithmetic underflow
(CVE-2026-64275)
- Input: goodix - clamp the device-reported contact count
(CVE-2026-64274)
- Input: iforce - bound the device-reported force-feedback effect index
(CVE-2026-64273)
- Input: touchwin - reset the packet index on every complete packet
(CVE-2026-64271)
- Input: maplemouse - fix NULL pointer dereference in open()
- Input: mms114 - fix multi-touch slot corruption
- Input: maple_keyb - set driver data before registering input device
- Input: maplemouse - set driver data before registering input device
- Input: maplecontrol - set driver data before registering input device
- RDMA/siw: bound Read Response placement to the RREAD length
(CVE-2026-64268)
- fuse: fix device node leak in cuse_process_init_reply()
- fuse: re-lock request before returning from fuse_ref_folio()
(CVE-2026-64266)
- sched/fair: Only update stats for allowed CPUs when looking for dst
group
- crypto: algif_skcipher - force synchronous processing on trees
without ctx->state
- tools/mm/slabinfo: fix total_objects attribute name
- crypto: af_alg - Remove zero-copy support from skcipher and aead
- media: uvcvideo: Avoid partial metadata buffers
- media: uvcvideo: Fix buffer sequence in frame gaps
- serial: msm: Disable DMA for kernel console UART
- serial: 8250_omap: clear rx_running on zero-length DMA completes
- afs: Fix netns teardown to cancel the preallocation charger
- afs: fix NULL pointer dereference in afs_get_tree()
- afs: Fix further netns teardown to cancel the preallocation charger
- drm/tidss: Drop extra drm_mode_config_reset() call
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA
buffer
- kconfig: fix potential NULL pointer dereference in conf_askvalue
- wifi: ath9k: fix OOB access from firmware tx status queue ID
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register
failure
- media: cedrus: Fix failure to clean up hardware on probe failure
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
(CVE-2026-64544)
- iommu/amd: Fix a stale comment about which legacy mode is user
visible
- clk: scmi: Fix clock rate rounding
- thermal: hwmon: Fix critical temperature attribute removal
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
- crypto: ccp - Treat zero-length cert chain as query for blob lengths
- net/sched: sch_htb: annotate data-races (I)
- ipv6: addrconf: bail out of dad_failure when state is no longer
POSTDAD
- RDMA/hns: Fix arithmetic overflow in calc_hem_config()
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
- RDMA/srpt: fix integer overflow in immediate data length check
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
- sysfs: clamp show() return value in sysfs_kf_read()
- net/sched: sch_drr: annotate data-races around cl->deficit
- media: rockchip: rga: fix too small buffer size
- device property: fix fwnode reference leak in
fwnode_graph_get_endpoint_by_id()
- cpufreq: Documentation: fix sampling_down_factor range
- cpufreq: conservative: Simplify frequency limit handling
- pwm: imx27: Fix variable truncation in .apply()
- bus: sunxi-rsb: Always check register address validity
- IB/mlx4: Fix refcount leak in add_port() error path
- RDMA/hns: Fix warning in poll cq direct mode
- PM: sleep: Use complete() in device_pm_sleep_init()
- mtd: spi-nor: Drop duplicate Kconfig dependency
- nvme-multipath: fix flex array size in struct nvme_ns_head
- workqueue: drop spurious '*' from print_worker_info() fn declaration
- ipv6: guard against possible NULL deref in __in6_dev_stats_get()
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback
- drm/tegra: dc: Fix device node reference leak in
tegra_dc_has_output()
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
- ocfs2: don't BUG_ON an invalid journal dinode
- ocfs2: kill osb->system_file_mutex lock
- drm/msm/dp: fix HPD state status bit shift value
- drm/msm/dp: Fix the ISR_* enum values
- media: qcom: venus: drop extra padding in NV12 raw size calculation
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data
writeback
- ARM: imx3: Fix CCM node reference leak
- ARM: imx31: Fix IIM mapping leak in revision check
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and
multi-channel scans"
- scsi: pm8001: Fix error code in non_fatal_log_show()
- mm/fake-numa: fix under-allocation detection in uniform split
- lib/test_meminit: use && for bools
- bpftool: Use libbpf error code for flow dissector query
- ocfs2: rebase copied fsdlm LVB pointers in locking_state
- ocfs2: fix buffer head management in ocfs2_read_blocks()
- ocfs2: reject FITRIM ranges shorter than a cluster
- ocfs2/dlm: require a ref for locking_state debugfs open
- ocfs2: fix race between ocfs2_control_install_private() and
ocfs2_control_release()
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master
helper is pptp
- bpf: Update transport_header when encapsulating UDP tunnel in lwt
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO
indication
- ACPI: IPMI: Fix message kref handling on dead device
- cpufreq: Documentation: fix conservative governor freq_step
description
- spi: ep93xx: fix double-free of zeropage on DMA setup failure
- firmware_loader: Fix recursive lock in device_cache_fw_images()
- configfs: fix lockless traversals of ->s_children
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of
pins 34-39
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of
pins 34-39
- hwspinlock: qcom: avoid uninitialized struct members
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
- fbdev: sm501fb: Fix buffer errors in OF binding code
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not
specified
- vhost/vdpa: validate virtqueue index in mmap and fault paths
- tools/virtio: check mmap return value in vringh_test
- bonding: 3ad: fix mux port state on oper down
- fs: efs: remove unneeded debug prints
- RDMA/mlx5: Fix undefined shift of user RQ WQE size
- ASoC: fsl: fsl_audmix: Validate written enum values
- ASoC: tegra: tegra210_ahub: Validate written enum value
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
- sctp: validate embedded address parameter length
- net/sched: sch_hfsc: Don't make class passive twice
- tipc: require net admin for TIPCv2 netlink mutators
- tipc: prevent snt_unacked underflow on CONN_ACK
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index
- crypto: rng - Free default RNG on module exit
- spi: xilinx: use FIFO occupancy register to determine buffer size
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during
peek before restoring qlen
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during
peek before restoring qlen
- kcm: use WRITE_ONCE() when changing lower socket callbacks
- netfilter: nf_conncount: callers must hold rcu read lock
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
(CVE-2026-64548)
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
- MIPS: mm: Fix out-of-bounds write in maar_res_walk()
- KEYS: Use acquire when reading state in keyring search
- tipc: fix UAF in tipc_l2_send_msg()
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
- net/9p: fix race condition on rdma->state in trans_rdma.c
- staging: nvec: fix use-after-free in nvec_rx_completed()
- coresight: cti: Fix DT filter signals silently ignored
- x86/platform/olpc: xo15: Drop wakeup source on driver removal
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling
- staging: most: video: avoid double free on video register failure
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
- usb: host: max3421: Reject hub port requests for non-existent ports
- char: tlclk: fix use-after-free in tlclk_cleanup()
- iio: light: si1133: reset counter to prevent race condition
- iio: light: si1133: prevent race condition on timeout
- iio: magnetometer: ak8975: fix potential kernel stack memory leak
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
- HID: logitech-hidpp: remove excess kernel-doc member in
hidpp_scroll_counter
- dmaengine: Fix possible use after free
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz
- pNFS/filelayout: fix cheking if a layout is striped
- NFSv4/pnfs: defer return_range callbacks until after inode unlock
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect
errors
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in
pg_get_mirror_count_write
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
- PCI: rcar-host: Remove unused LIST_HEAD(res)
- tools lib api: Fix missing null termination in
filename__read_int/ull()
- tools lib api: Fix filename__write_int() writing uninitialized stack
data
- tools lib api: Fix mount_overload() snprintf truncation and toupper
range
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
- PCI: mediatek: Use actual physical address instead of virt_to_phys()
- apparmor: check label build before no_new_privs test
- apparmor: aa_label_alloc use aa_label_free on alloc failure
- apparmor: grab ns lock and refresh when looking up changehat child
profiles
- apparmor: fix potential UAF in aa_replace_profiles
- apparmor: aa_getprocattr free procattr leak on format failure
- apparmor: put secmark label after secid lookup
- i3c: master: Prevent reuse of dynamic address on device add failure
- apparmor: fix label can not be immediately before a declaration
- sparc: led: avoid trimming a newline from empty writes
- xfrm: validate selector family and prefixlen during match
- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
- net: psample: fix info leak in PSAMPLE_ATTR_DATA (CVE-2026-64553)
- sctp: hold socket lock when dumping endpoints in sctp_diag
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate
BAS
- thermal: intel: Fix dangling resources on thermal_throttle_online()
failure
- ACPI: resource: Amend kernel-doc style
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
- ieee802154: fix kernel-infoleak in dgram_recvmsg()
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
- irqchip/crossbar: Fix parent domain resource leak
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
- bpf: Fix stack slot index in nospec checks
- drm/edid: fix OOB read in drm_parse_tiled_block() (CVE-2026-64546)
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (CVE-2026-64538)
- ipv4: fib: Don't ignore error route in local/main tables.
- netfilter: nf_conncount: prevent connlimit drops for early confirmed
ct
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
- net: dsa: sja1105: round up PTP perout pin duration
- ipv6: fix error handling in disable_ipv6 sysctl
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl
- ipv6: fix error handling in forwarding sysctl
- ipv6: fix error handling in disable_policy sysctl
- smb/client: preserve errors from smb2_set_sparse()
- rtc: ds1307: Fix off-by-one issue with wday for rx8130
- rtc: cmos: unregister HPET IRQ handler on probe failure
- net: mvneta: re-enable percpu interrupt on resume
- net: sungem: fix probe error cleanup
- tracing: probes: fix typo in a log message
- spi: sh-msiof: abort transfers when reset times out
- gpio: mvebu: fail probe if gpiochip registration fails
- gpio: htc-egpio: use managed gpiochip registration
- seg6: validate SRH length before reading fixed fields
- hwmon: adm1275: Prevent reading uninitialized stack
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
(CVE-2026-64540)
- tracing/events: Fix to check the simple_tsk_fn creation
- virtio_net: disable cb when NAPI is busy-polled
- cxgb4: Fix decode strings dump for T6 adapters
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in
probe
- net/sched: hhf: clear heavy-hitter state on reset
- afs: Fix error code in afs_extract_vl_addrs()
- afs: Fix callback service message parsers to pass through -EAGAIN
- afs: Fix vllist leak
- afs: Fix unchecked-length string display in debug statement
- ata: sata_gemini: unwind clocks on IDE pinctrl errors
- HID: picolcd: prevent NULL pointer dereference in
picolcd_send_and_wait()
- HID: core: Fix OOB read in hid_get_report for numbered reports
- net: usb: net1080: validate packet_len before pad-byte access in
rx_fixup (CVE-2026-64547)
- gue: validate REMCSUM private option length
- netfilter: xt_u32: reject invalid shift counts
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
- netfilter: ip6tables: mark malformed IPv6 extension headers for
hotdrop
- qede: fix off-by-one in BD ring consumption on build_skb failure
- net: qualcomm: rmnet: simplify some byte order logic
- net: qualcomm: rmnet: kill RMNET_MAP_GET_*() accessor macros
- net: qualcomm: rmnet: use masks instead of C bit-fields
- net: qualcomm: rmnet: don't use C bit-fields in rmnet checksum header
- net: ethernet: rmnet: Support for ingress MAPv5 checksum offload
- net: qualcomm: rmnet: add tx packets aggregation
- net: qualcomm: rmnet: validate MAP frame length before ingress
parsing (CVE-2026-64550)
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
(CVE-2026-64541)
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
- Bluetooth: bpa10x: avoid OOB read of revision string in
bpa10x_setup() (CVE-2026-64549)
- ring-buffer: Fix event length with forced 8-byte alignment
- net: usb: lan78xx: disable VLAN filter in promiscuous mode
- net/sched: cake: reject overhead values that underflow length
- mld: convert from timer to delayed work
- mld: get rid of inet6_dev->mc_lock
- mld: convert ipv6_mc_socklist->sflist to RCU
- mld: convert ip6_sf_list to RCU
- mld: convert ifmcaddr6 to RCU
- mld: add new workqueues for process mld events
- mld: add mc_lock for protecting per-interface mld data
- ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()
- ipv6: mcast: Replace locking comments with lockdep annotations.
- ipv6: mcast: Fix potential UAF in MLD delayed work
- ipvs: pass parsed transport offset to state handlers
- ipvs: use parsed transport offset in TCP state lookup
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
- ipvs: ensure inner headers in ICMP errors are in headroom
- dm era: fix NULL pointer dereference in metadata_open()
- regulator: core: Make regulator_lock_two() logic easier to follow
- regulator: core: regulator_lock_two() should test for EDEADLK not
EDEADLOCK
- net/mlx5: Fix L3 tunnel entropy refcount leak
- smb: client: fix overflow in passthrough ioctl bounds check
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
- net: atm: reject out-of-range traffic classes in QoS validation
- net: ife: require ETH_HLEN to be pullable in ife_decode()
- arm64: dts: qcom: sdm630: describe adsp_mem region properly
- KVM: arm64: vgic: Check the interrupt is still ours before migrating
it
- fbdev: sm712: Fix operator precedence in big_swap macro
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
- fbdev: i740fb: fix potential memory leak in i740fb_probe()
- fbdev: s3fb: fix potential memory leak in s3_pci_probe()
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
- netfilter: nfnl_cthelper: apply per-class values when updating
policies
- netfilter: xt_cluster: reject template conntracks in hash match
- netfilter: nf_nat_sip: reload possible stale data pointer
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6
defrag
- netfilter: nf_conncount: fix zone comparison in tuple dedup
- netfilter: xt_nat: reject unsupported target families
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
(CVE-2026-64554)
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt()
error path
- soc: ti: k3-ringacc: Fix access mode for
k3_ringacc_ring_pop_tail_io/proxy
- soc: fsl: qe: panic on ioremap() failure in qe_reset()
- leds: uleds: Fix potential buffer overread
- mfd: sm501: Fix reference leak on failed device registration
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang
- x86/boot: Reject too long acpi_rsdp= values
- batman-adv: gw: acquire ethernet header only after skb realloc
- batman-adv: access unicast_ttvn skb->data only after skb realloc
- batman-adv: dat: acquire ARP hw source only after skb realloc
- batman-adv: bla: reacquire gw address after skb realloc
- batman-adv: dat: ensure accessible eth_hdr proto field
- batman-adv: dat: fix tie-break for candidate selection
- batman-adv: tt: avoid request storms during pending request
- batman-adv: fix VLAN priority offset
- batman-adv: frag: free unfragmentable packet
- batman-adv: frag: fix primary_if leak on failed linearization
- batman-adv: tt: prevent TVLV OOB check overflow
- mfd: tps6586x: Fix OF node refcount
- nvdimm/btt: Free arenas on btt_init() error paths
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error
path
- lockd: Plug nlm_file leak when nlm_do_fopen() fails
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
- power: supply: charger-manager: fix refcount leak in
is_full_charged()
- proc: only bump parent nlink when registering directories
- mtd: slram: remove failed entries from the device list
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
- ocfs2: use kzalloc for quota recovery bitmap allocation
- mtd: rawnand: fix condition in 'nand_select_target()'
- ocfs2: avoid moving extents to occupied clusters
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
- ocfs2: reject dinodes with non-canonical i_mode type
- ocfs2: reject dinodes whose i_rdev disagrees with the file type
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
- irqchip/crossbar: Use correct index in crossbar_domain_free()
- i2c: mediatek: fix WRRD for SoCs without auto_restart option
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
- xen/gntdev: fix error handling in ioctl
- xfrm: use compat translator only for u64 alignment mismatch
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
changelink
- tpm: fix event_size output in tpm1_binary_bios_measurements_show
- tpm: Make the TPM character devices non-seekable
- time: Fix off-by-one in compat settimeofday() usec validation
- spi: uniphier: Fix completion initialization order before
devm_request_irq()
- sctp: validate STALE_COOKIE cause length before reading staleness
(CVE-2026-64551)
- nvmet-rdma: handle inline data with a nonzero offset
- can: isotp: use unconditional synchronize_rcu() in isotp_release()
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
- can: bcm: add missing rcu list annotations and operations
- dm thin metadata: fix superblock refcount leak on snapshot shadow
failure
- dm thin metadata: fix metadata snapshot consistency on commit failure
- dm era: fix out-of-bounds memory access for non-zero start sector
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
- dm-log: fix a bitset_size overflow on 32bit machines
- dm-stats: fix dm_jiffies_to_msec64
- dm-stats: fix merge accounting
- dm_early_create: fix freeing used table on dm_resume failure
- dm-verity: increase sprintf buffer size
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
- scsi: sg: Report request-table problems when any status is set
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND
MOVE
- Input: ims-pcu - fix use-after-free and double-free in disconnect
- Input: ims-pcu - release data interface on disconnect
- Input: ims-pcu - validate control endpoint type
- Input: ims-pcu - add response length checks
- Input: ims-pcu - fix DMA mapping violation in line setup
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug
logging
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor
parsing
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing
- cpu: hotplug: Preserve per instance callback errors
- gpios: palmas: add .get_direction() op
- net: sit: require CAP_NET_ADMIN in the device netns for changelink
- net: ena: clean up XDP TX queues when regular TX setup fails
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for
changelink
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for
changelink
- ieee802154: admin-gate legacy LLSEC dump operations
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
path (CVE-2026-64534)
- batman-adv: retrieve ethhdr after potential skb realloc on RX
- batman-adv: ensure minimal ethernet header on TX
- rtmutex: Use waiter::task instead of current in remove_waiter()
(CVE-2026-43499)
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
- hwmon: (w83627hf) remove VID sysfs files on error and remove
- hwmon: (w83793) remove vrm sysfs file on probe failure
- net: liquidio: fix BAR resource leak on PF number failure
- fsl/fman: Free init resources on KeyGen failure in fman_init()
- net/sched: sch_multiq: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
- tracing/probes: Fix double addition of offset for @+FOFFSET
- orangefs: keep the readdir entry size 64-bit in fill_from_part()
- ata: pata_pxa: Fix DMA channel leak on probe error
- hwmon: (asus_atk0110) Check package count before accessing element
- mac802154: remove interfaces with RCU list deletion
- llc: fix SAP refcount leak in llc_ui_autobind()
- ipvs: use parsed transport offset in SCTP state lookup
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
- drbd: reject data replies with an out-of-range payload size
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not
mems_allowed
- wifi: rt2x00: avoid full teardown before work setup in probe
- wifi: mac80211: fix memory leak in ieee80211_register_hw()
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
- Bluetooth: btrtl: validate firmware patch bounds
- llc: fix SAP refcount leak when creating incoming sockets
- macsec: fix promiscuity refcount leak in macsec_dev_open()
- memstick: ms_block: reject a card that reports too many blocks
- ipvs: fix more places with wrong ipv6 transport offsets
- reset: sunxi: fix memory region leak on ioremap failure
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
- wifi: mac80211: free ack status frame on TX header build failure
- wifi: mwifiex: fix permanently busy scans after multiple roam
iterations
- mtd: onenand: samsung: report DMA completion timeouts
- mmc: vub300: defer reset until cmd_mutex is unlocked
- mtd: rawnand: fsl_ifc: return errors for failed page reads
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
- crypto: amcc - fix incorrect kernel-doc comment syntax in files
- crypto: crypto4xx - Remove ahash-related code
- crypto: crypto4xx - Remove insecure and unused rng_alg
- batman-adv: clean untagged VLAN on netdev registration failure
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (CVE-2026-64510)
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw
values
- iio: imu: inv_icm42600: make timestamp module chip independent
- iio: move inv_icm42600 timestamp module in common
- iio: make invensense timestamp module generic
- iio: imu: inv_mpu6050: use the common inv_sensors timestamp module
- iio: invensense: remove redundant initialization of variable period
- iio: invensense: fix timestamp glitches when switching frequency
- iio: imu: inv_icm42600: stabilized timestamp in interrupt
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
- bitops: make BYTES_TO_BITS() treewide-available
- iio: common: st_sensors: honour channel endianness in read_axis_data
- ALSA: aoa: check snd_ctl_new1() return value (CVE-2026-64488)
- Bluetooth: btintel: Fix offset calculation boot address parameter
- Bluetooth: btintel: Check firmware version before download
- Bluetooth: btusb: fix use-after-free on marvell probe failure
(CVE-2026-64470)
- Bluetooth: btusb: fix wakeup source leak on probe failure
- vfio/pci: Release the VGA arbiter client on register_device() failure
(CVE-2026-64475)
- binder: fix UAF in binder_free_transaction() (CVE-2026-64468)
- PCI: altera: Fix resource leaks on probe failure (CVE-2026-64462)
- media: atomisp: replace boolean comparison of values with bool
variables
- media: staging: media: atomisp: Fix sh_css.c brace coding style
issues
- media: staging: media: atomisp: Fix the rest of sh_css.c brace issues
- media: staging: media: atomisp: Replace if else clause with a ternary
- media: staging: media: atomisp: Fix alignment and line length issues
- staging: media: atomisp: reduce load_primary_binaries() stack usage
- cifs: Create a new shared file holding smb2 pdu definitions
- cifs: remove check of list iterator against head past the loop body
- smb2: small refactor in smb2_check_message()
- cifs: remove unused server parameter from calc_smb_size()
- smb: client: restrict implied bcc[0] exemption to responses without
data area (CVE-2026-64448)
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
- staging: rtl8723bs: split too long line
- staging: rtl8723bs: remove commented out RT_ASSERT occurrences
- staging: rtl8723bs: remove all 5Ghz network types
- staging: rtl8723bs: remove 5Ghz code related to channel plan
definition
- staging: rtl8723bs: remove 5Ghz code blocks
- staging: rtl8723bs: remove commented out condition
- staging: rtl8723bs: clean up comparsions to NULL
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
(CVE-2026-64445)
- staging: rtl8723bs: Fix space issues
- staging: rtl8723bs: fix heap buffer overflow in
rtw_cfg80211_set_wpa_ie() (CVE-2026-64446)
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and
join_cmd_hdl() (CVE-2026-64442)
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle()
- PCI: mediatek: Convert bool to single quirks entry and bitmap
- PCI: mediatek: Fix IRQ domain leak when port fails to enable
(CVE-2026-64461)
- staging: rtl8723bs: remove DBG_871X log argument
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
(CVE-2026-64438)
- PCI: Prevent resource tree corruption when BAR resize fails
- PCI: Free saved list without holding pci_bus_sem
- PCI: Fix restoring BARs on BAR resize rollback path
- PCI: Add kerneldoc for pci_resize_resource()
- PCI: Move Resizable BAR code to rebar.c
- PCI: Skip Resizable BAR restore on read error
- coresight: etb10: restore atomic_t for shared reading state
- netfilter: ebtables: Use vmalloc_array() to improve code
- netfilter: ebtables: zero chainstack array (CVE-2026-64413)
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident
- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
(CVE-2026-64206)
- smb: client: Fix next buffer leak in receive_encrypted_standard()
(CVE-2026-64381)
- smb: client: mask server-provided mode to 07777 in modefromsid
(CVE-2026-64379)
- smb: client: use unaligned reads in parse_posix_ctxt()
- smb: client: harden POSIX SID length parsing (CVE-2026-64380)
- writeback: fix race between cgroup_writeback_umount() and
inode_switch_wbs() (CVE-2026-64378)
- X.509: Fix validation of ASN.1 certificate header
- proc: use generic setattr() for /proc/$PID/net
- proc: rename proc_setattr to proc_nochmod_setattr
- proc: protect ptrace_may_access() with exec_update_lock (FD links)
(CVE-2026-64375)
- HID: add haptics page defines
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags
(CVE-2026-64364)
- cpufreq: intel_pstate: Sync policy->cur during CPU offline
- proc: protect ptrace_may_access() with exec_update_lock (part 1)
(CVE-2026-64371)
- HID: appleir: fix UAF on pending key_up_timer in remove()
(CVE-2026-64363)
- serial: 8250_mid: Remove 8250_pci usage
- serial: 8250_mid: Disable DMA for selected platforms
- xfs: reflect sb features in xfs_mount
- xfs: fix unreachable BIGTIME check in dquot flush validation
- xfs: use null daddr for unset first bad log block
- hfs/hfsplus: prevent getting negative values of offset/length
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
(CVE-2026-64361)
- usb: gadget: function: Simplify diagnostic messaging in printer
- usb: gadget: f_printer: take kref only for successful open
(CVE-2026-64345)
- usb: free iso schedules on failed submit (CVE-2026-64348)
- usb: iowarrior: remove inherent race with minor number
- USB: serial: digi_acceleport: fix write buffer corruption
(CVE-2026-64333)
- drm/i2c/sil164: Drop no-op remove function
- leds: lm3697: Remove duplicated error reporting in .remove()
- leds: lm3601x: Improve error reporting for problems during .remove()
- gpio: pca953x: Make platform teardown callback return void
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
(CVE-2026-64329)
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
- usb: typec: tcpm: Fix VDM type for Enter Mode commands
- usb: gadget: f_fs: initialize reset_work at allocation time
- crypto: atmel-sha204a - Mark OF related data as maybe unused
- crypto: atmel - Drop explicit initialization of struct
i2c_device_id::driver_data to 0
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
- btrfs: do not trim a device which is not writeable
- crypto: qat - fix restarting state leak on allocation failure
- crypto: qat - validate RSA CRT component lengths (CVE-2026-64304)
- audit: add audit_log_nf_skb helper function
- audit: fix potential integer overflow in audit_log_n_hex()
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
- Bluetooth: L2CAP: Fix regressions caused by reusing ident
- iio: imu: inv_mpu6050: fix frequency setting when chip is off
- iio: invensense: fix odr switching to same value
- iio: imu: inv_icm42600: fix timestamp clock period by using lower
value
- mld: change lockdep annotation for ip6_sf_socklist and
ipv6_mc_socklist
- ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
- net: ethernet: rmnet: Always subtract MAP header
- ipv6: mcast: use rcu-safe version of ipv6_get_lladdr()
- ipv6: fix lockdep splat in in6_dump_addrs()
- net: mld: fix reference count leak in mld_{query | report}_work()
- ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
- ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down()
- mld: fix suspicious RCU usage in __ipv6_dev_mc_dec()
- perf/x86/amd/core: Always use the NMI latency mitigation
- tools/resolve_btfids: Fix some error messages
- tools/resolve_btfids: Emit warnings and patch zero id for missing
symbols
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.262
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race
(CVE-2026-64560)
.
[ Emilio Pozuelo Monfort ]
* [rt] Update to 5.10.261-rt157
* [rt] Refresh:
- Refresh "signals: Allow rt tasks to cache one sigqueue struct"
Checksums-Sha1:
0f3e11b9141d82f4f0a1d8abaad8d51c56221a3d 8001 linux-signed-amd64_5.10.262+1.dsc
704278e51d538d9bf210301b265a28e3a52d57af 672636 linux-signed-amd64_5.10.262+1.tar.xz
Checksums-Sha256:
0c737a14490bf4dbca75fdd2d902072068c1a6379b21882f837716aff5c92267 8001 linux-signed-amd64_5.10.262+1.dsc
0e3ff03501bc1682440269749849bfd0f36f0bbf590faae40cb29610dfb06179 672636 linux-signed-amd64_5.10.262+1.tar.xz
Files:
5187cc8352e713ed79545bdff4e8d950 8001 kernel optional linux-signed-amd64_5.10.262+1.dsc
06f85b39e0fa80daf9b363b30d500d59 672636 kernel optional linux-signed-amd64_5.10.262+1.tar.xz
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQSInBJdRTWyTRy0ztFCTVFtUgONCgUCanHi0QAKCRBCTVFtUgON
Cm/BAQCc66+dhEwDdBQMU7Kpg1tII8liBXqwNT4KQMAoQ6ZR2AD/XDQ4Kux6C+Vq
FOIYgwwRg/bF7RqGz1WC4BznPgTMfQE=
=BVVZ
-----END PGP SIGNATURE-----