-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 07 Sep 2026 21:33:42 +0200
Source: linux
Architecture: source
Version: 6.1.187-1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Changes:
linux (6.1.187-1) bookworm-security; urgency=high
.
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.181
- [x86] bugs: Make Safe-RET robust against interrupt injection
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.182
- Revert "x86/bugs: Make Safe-RET robust against interrupt injection"
- [x86] bugs: Make Safe-RET robust against interrupt injection
(CVE-2026-68480)
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.183
- [x86] platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU
hotplug
- af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361)
- [x86] perf/x86/amd/brs: Fix kernel address leakage (CVE-2026-72237)
- seqlock: Cure some more scoped_seqlock() optimization fails
- seqlock: Allow KASAN to fail optimizing
- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
- [x86] KVM: nVMX: Hide shadow VMCS right after VMCLEAR (CVE-2026-64562)
- [x86] KVM: x86/mmu: Fix use-after-free on vendor module reload
(CVE-2026-68428)
- can: bcm: add locking when updating filter and timer values
(CVE-2026-72121)
- can: bcm: fix CAN frame rx/tx statistics (CVE-2026-72118)
- can: bcm: extend bcm_tx_lock usage for data and timer updates
(CVE-2026-72119)
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies
(CVE-2026-72114)
- can: bcm: add missing device refcount for CAN filter removal
(CVE-2026-72113)
- can: bcm: fix stale rx/tx ops after device removal (CVE-2026-72116)
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
(CVE-2026-72117)
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops
(CVE-2026-72115)
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
(CVE-2026-72125)
- can: isotp: serialize TX state transitions under so->rx_lock
(CVE-2026-72124)
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
(CVE-2026-72146)
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
(CVE-2026-68427)
- xprtrdma: Clear receive-side ownership pointers on release
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
(CVE-2026-64565)
- Input: ims-pcu - fix logic error in packet reset
- [arm64] tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
- IB/mad: Drop unmatched RMPP responses before reassembly (CVE-2026-68425)
- mtd: mtdswap: remove debugfs stats file on teardown
- mtd: nand: mtk-ecc: stop on ECC idle timeouts
- btrfs: reject free space cache with more entries than pages
(CVE-2026-64567)
- btrfs: fix root leak if its reloc root is unexpected in
merge_reloc_roots() (CVE-2026-68422)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
(CVE-2026-68444)
- RDMA/cma: Fix hardware address comparison length in netevent callback
- RDMA/erdma: initialize ret for empty receive WR lists
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp
- RDMA/siw: publish QP after initialization (CVE-2026-68417)
- RDMA/irdma: Prevent overflows in memory contiguity checks
- xfrm6: clear dst.dev on error to avoid double netdev_put in
xfrm6_fill_dst() (CVE-2026-64580)
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
(CVE-2026-64579)
- wifi: cfg80211: cancel sched scan results work on unregister
(CVE-2026-68414)
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
(CVE-2026-68413)
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put
(CVE-2026-68411)
- wifi: libertas: fix memory leak in helper_firmware_cb() (CVE-2026-68410)
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
(CVE-2026-64571)
- wifi: nl80211: free RNR data on MBSSID mismatch (CVE-2026-68407)
- wifi: nl80211: validate nested MBSSID IE blobs
- wifi: cfg80211: validate PMSR measurement type data
- wifi: cfg80211: validate PMSR FTM preamble range (CVE-2026-68406)
- wifi: cfg80211: reject unsupported PMSR FTM location requests
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (CVE-2026-68405)
- wifi: brcmfmac: initialize SDIO data work before cleanup (CVE-2026-68403)
- wifi: cfg80211: bound element ID read when checking non-inheritance
(CVE-2026-68402)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
- [amd6] ASoC: amd: ps: fix wrong ACP version string in
pci_request_regions()
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
(CVE-2026-68398)
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path
(CVE-2026-64572)
- net/iucv: take a reference on the socket found in afiucv_hs_rcv()
(CVE-2026-68397)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is
registered (CVE-2026-68395)
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
interrupts
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
- Bluetooth: qca: fix NVM tag length underflow in TLV parser
(CVE-2026-64573)
- smb/client: handle overlapping allocated ranges in fallocate
(CVE-2026-68388)
- [x86] drm/i915/gt: use correct selftest config symbol
- bpf, sockmap: Reject unhashed UDP sockets on sockmap update
(CVE-2026-68386)
- can: j1939: fix lockless local-destination check
- ksmbd: validate compound request size before reading StructureSize2
(CVE-2026-64578)
- net/sched: act_tunnel_key: Defer dst_release to RCU callback
(CVE-2026-68377)
- sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
(CVE-2026-64569)
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
(CVE-2026-68373)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
(CVE-2026-68370)
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object
(CVE-2026-64584)
- usb: gadget: printer: fix infinite loop in printer_read() (CVE-2026-68369)
- USB: gadget: snps-udc: fix device name leak on probe failure
- USB: gadget: fsl-udc: fix device name leak on probe failure
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
(CVE-2026-68368)
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
(CVE-2026-64583)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
(CVE-2026-68366)
- USB: serial: ftdi_sio: add support for E+H FXA291
- USB: serial: io_edgeport: cap received transmit credits (CVE-2026-68365)
- USB: serial: keyspan_pda: fix data loss on receive throttling
- USB: serial: option: add TDTECH MT5710-CN
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest
- Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
- bpf: Support for hardening against JIT spraying (CVE-2026-64508)
- [x86] bugs: Enable IBPB flush on BPF JIT allocation (CVE-2026-64507)
- bpf: Restrict JIT predictor flush to cBPF
- bpf: Skip redundant IBPB in pack allocator
- bpf: Prefer packs that won't trigger an IBPB flush on allocation
- bpf: Prefer dirty packs for eBPF allocations
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (CVE-2026-53090)
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware
request (CVE-2026-68363)
- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
(CVE-2026-68362)
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
(CVE-2026-68361)
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
(CVE-2026-68360)
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
(CVE-2026-68359)
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
(CVE-2026-68357)
- wifi: ath11k: fix potential buffer underflow in
ath11k_hal_rx_msdu_list_get() (CVE-2026-68355)
- wifi: ath11k: Flush the posted write after writing to
PCIE_SOC_GLOBAL_RESET
- firewire: net: Fix fragmented datagram reassembly (CVE-2026-68354)
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
(CVE-2026-68353)
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
(CVE-2026-68352)
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
(CVE-2026-68351)
- wifi: carl9170: fix OOB read from off-by-two in TX status handler
(CVE-2026-68350)
- wifi: carl9170: fix buffer overflow in rx_stream failover path
(CVE-2026-68349)
- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
- btrfs: free mapping node on duplicate reloc root insert (CVE-2026-68450)
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
- wifi: iwlwifi: mvm: fix read in wake packet notification handler
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
(CVE-2026-68344)
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
- hwmon: (asus-ec-sensors) fix EC read intervals
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM
- smb: client: validate DFS referral PathConsumed (CVE-2026-68343)
- hwmon: occ: validate poll response sensor blocks (CVE-2026-68340)
- net/packet: avoid fanout hook re-registration after unregister
(CVE-2026-68338)
- bonding: fix devconf_all NULL dereference when IPv6 is disabled
(CVE-2026-68336)
- rds: drop incoming messages that cross network namespace boundaries
(CVE-2026-68335)
- dpaa2-switch: put MAC endpoint device on disconnect (CVE-2026-68333)
- net: dpaa2-eth: assign priv->mac after dpaa2_mac_connect() call
- dpaa2-eth: put MAC endpoint device on disconnect (CVE-2026-68331)
- nfp: Check resource mutex allocation (CVE-2026-68328)
- wan: wanxl: Only reset hardware after BAR mapping (CVE-2026-68327)
- wifi: mwifiex: bound uAP association event IEs to the event buffer
(CVE-2026-68326)
- [amd64] iommu/amd: Bound the early ACPI HID map (CVE-2026-68325)
- [amd64] iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
(CVE-2026-68324)
- wifi: mac80211: recalculate TIM when a station enters power save
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
(CVE-2026-68320)
- sctp: validate stream count in sctp_process_strreset_inreq()
(CVE-2026-68315)
- gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
(CVE-2026-64577)
- nexthop: initialize extack in nh_res_bucket_migrate() (CVE-2026-64576)
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (CVE-2026-68313)
- wifi: mt76: mt7915: guard HE capability lookups (CVE-2026-68310)
- wifi: mt76: connac: fix possible NULL-pointer deref in
mt76_connac_mcu_uni_bss_he_tlv() (CVE-2026-68309)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (CVE-2026-68304)
- amt: re-read skb header pointers after every pull (CVE-2026-68302)
- amt: make the head writable before rewriting the L2 header
- net: bridge: vlan: fix vlan range dumps starting with pvid
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs
(CVE-2026-68301)
- sctp: auth: verify auth requirement when auth_chunk is NULL
(CVE-2026-68300)
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
(CVE-2026-68299)
- tipc: fix u16 MTU truncation in media and bearer MTU validation
(CVE-2026-68297)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests
- net: stmmac: reset residual action in L3L4 filters on delete
- octeontx2-vf: set TC flower flag on MCAM entry allocation
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
- ppp: use IFF_NO_QUEUE in virtual interfaces
- ppp: convert to percpu netstats
- ppp: enable TX scatter-gather
- ppp: annotate data races in ppp_generic
- hinic: remove unused ethtool RSS user configuration buffers
- net: qrtr: restrict socket creation to the initial network namespace
(CVE-2026-68294)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
(CVE-2026-68284)
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
(CVE-2026-68279)
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation
(CVE-2026-68278)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
(CVE-2026-68277)
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
- [x86] drm/i915/gem: Add missing nospec on parallel submit slot
(CVE-2026-68269)
- drm/nouveau/acr: fix missing nvkm_done() in error path of
nvkm_acr_oneinit()
- drm/radeon: fix r100_copy_blit for large BOs
- drm/amdkfd: Check bounds in allocate_event_notification_slot
(CVE-2026-68259)
- drm/virtio: bound EDID block reads to the response buffer (CVE-2026-68255)
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (CVE-2026-68251)
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (CVE-2026-68250)
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (CVE-2026-68249)
- [x86] drm/i915: Return NULL on error in active_instance (CVE-2026-68248)
- [x86] drm/i915/gem: Do not leak siblings[] on proto context error
(CVE-2026-68244)
- [x86] drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
(CVE-2026-68243)
- drm/amdgpu: Fix VFCT bus number matching with soft filter
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
(CVE-2026-68234)
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (CVE-2026-68446)
- media: airspy: Return queued buffers on start_streaming() failure
(CVE-2026-68231)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe
failure
- media: cec: seco: unregister adapter on IR probe failure
- media: cedrus: clean up media device on probe failure
- media: cedrus: Fix missing cleanup in error path
- media: cedrus: skip invalid H.264 reference list entries (CVE-2026-68229)
- media: cx231xx: fix devres lifetime (CVE-2026-68227)
- media: cx23885: add ioremap return check and cleanup (CVE-2026-68226)
- media: marvell-cam: fix missing pci_disable_device() on remove
- media: meson: vdec: Fix memory leak in error path of vdec_open
(CVE-2026-68223)
- media: msi2500: Return queued buffers on start_streaming() failure
(CVE-2026-68222)
- media: pci: dm1105: Free allocated workqueue (CVE-2026-68218)
- media: pwc: Drain fill_buf on start_streaming() failure (CVE-2026-68217)
- media: pwc: Return queued buffers on start_streaming() failure
(CVE-2026-68216)
- media: radio-si476x: Unregister v4l2_device on probe failure
(CVE-2026-68215)
- media: rtl2832: fix use-after-free in rtl2832_remove() (CVE-2026-68214)
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure
(CVE-2026-68213)
- media: saa7134: Fix a possible memory leak in saa7134_video_init1
(CVE-2026-68212)
- media: stm32: dcmi: unregister notifier on probe failure (CVE-2026-68210)
- media: sun4i-csi: Return queued buffers on start_streaming() failure
(CVE-2026-68209)
- media: tegra-video: vi: fix invalid u32 return value in format lookup
- media: ti: vpe: unwind v4l2 device registration on probe error
(CVE-2026-68207)
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
- media: v4l2-ctrls: validate HEVC active reference counts (CVE-2026-68206)
- media: vb2: use ssize_t for vb2_read/vb2_write
- media: vidtv: fix reference leak on failed device registration
- media: vimc: fix reference leak on failed device registration
- media: vivid: add vivid_update_reduced_fps()
- media: vivid: check for vb2_is_busy() when toggling caps (CVE-2026-68204)
- media: vpif_capture: fix OF node reference imbalance
- ALSA: seq: close a re-opened queue timer in the destructor
(CVE-2026-68202)
- wifi: ath6kl: fix OOB access from firmware ADDBA window size
(CVE-2026-68199)
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
(CVE-2026-68197)
- wifi: wilc1000: validate assoc response length before subtracting header
(CVE-2026-68196)
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (CVE-2026-68195)
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (CVE-2026-68194)
- wifi: brcmfmac: make release_scratchbuffers idempotent (CVE-2026-68192)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (CVE-2026-68190)
- staging: rtl8723bs: fix inverted HT40 secondary channel offset
- Bluetooth: hci_sync: Protect UUID list traversal (CVE-2026-68189)
- Bluetooth: RFCOMM: Fix session UAF in set_termios (CVE-2026-68188)
- exec: fix unsigned loop counter wrap in transfer_args_to_stack()
(CVE-2026-68187)
- binfmt_misc: set have_execfd only once the interpreter is opened
(CVE-2026-68186)
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (CVE-2026-68184)
- [x86] boot/compressed: Disable jump tables
- comedi: comedi_parport: deal with premature interrupt (CVE-2026-68182)
- serial: sc16is7xx: implement gpio get_direction() callback
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR
platforms (CVE-2026-68434)
- [x86] intel_th: fix MSC output device reference leak (CVE-2026-68180)
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
(CVE-2026-68176)
- tracing: Fix resource leak on mmiotrace trace_pipe close (CVE-2026-68175)
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
- tracing/probes: Avoid temporary buffer truncation in
trace_probe_match_command_args()
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
- [arm64] syscall: Ensure saved x0 is kept in-sync with tracer updates
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer
updates"
- mptcp: decrement subflows counter on failed passive join
- mptcp: only set DATA_FIN when a mapping is present
- sctp: don't free the ASCONF's own transport in DEL-IP processing
(CVE-2026-64564)
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
(CVE-2026-68160)
- libceph: bound get_version reply decode to front len (CVE-2026-68433)
- libceph: Fix multiplication overflow in decode_new_up_state_weight()
(CVE-2026-68158)
- libceph: guard missing CRUSH type name lookup (CVE-2026-68157)
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update
(CVE-2026-68156)
- libceph: Reject monmaps advertising zero monitors (CVE-2026-68155)
- libceph: reject zero bucket types in crush_decode (CVE-2026-68154)
- libceph: remove debugfs files before client teardown (CVE-2026-68153)
- binfmt_elf_fdpic: only honour the first PT_INTERP (CVE-2026-68151)
- fscrypt: Add missing superblock check in find_or_insert_direct_key()
(CVE-2026-68148)
- ftrace: Add global mutex to serialize trace_parser access (CVE-2026-68146)
- [amd64] iommu/vt-d: Disallow SVA if page walk is not coherent
- phonet: pep: fix use-after-free in pep_get_sb() (CVE-2026-68144)
- vxlan: require CAP_NET_ADMIN in the device netns for changelink
(CVE-2026-68432)
- net: slip: serialize receive against buffer reallocation (CVE-2026-68143)
- geneve: require CAP_NET_ADMIN in the device netns for changelink
(CVE-2026-68142)
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (CVE-2026-68141)
- net/iucv: fix use-after-free of a severed iucv_path (CVE-2026-68140)
- net/x25: fix use-after-free in x25_kill_by_neigh() (CVE-2026-68137)
- net: hip04: fix RX buffer leak on build_skb failure (CVE-2026-68135)
- proc: Fix broken error paths for namespace links
- rbd: Reset positive result codes to zero in object map update path
(CVE-2026-68131)
- ksmbd: defer destroy_previous_session() until after NTLM authentication
(CVE-2026-68130)
- ice: use READ_ONCE() to access cached PHC time
- ila: reload IPv6 header after pskb_may_pull in checksum adjust
(CVE-2026-68127)
- mac802154: llsec: reject frames shorter than the authentication tag
(CVE-2026-68125)
- mctp: serial: handle zero-length frames to prevent rx buffer overflow
(CVE-2026-68124)
- pppoe: reload header pointer after dev_hard_header() (CVE-2026-68121)
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
(CVE-2026-68117)
- drm/amd/pm: make pp_features read-only when scpm is enabled
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (CVE-2026-68115)
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (CVE-2026-68246)
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (CVE-2026-68430)
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (CVE-2026-68111)
- drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
- drm/amdgpu: fix division by zero with invalid uvd dimensions
(CVE-2026-68106)
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (CVE-2026-68104)
- i40e: remove read access to debugfs files (CVE-2025-39901)
- ipv6: ndisc: fix NULL deref in accept_untracked_na() (CVE-2026-64542)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
(CVE-2026-64543)
- openvswitch: fix GSO userspace truncation underflow (CVE-2026-68123)
- fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
(CVE-2026-68147)
- exfat: validate cluster allocation bits of the allocation bitmap
(CVE-2025-40307)
- bpf: drop bpf_lsm_getselfattr from hook list
- [x86] KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision
after hotplug (CVE-2026-68093)
- io_uring/rw: fix missing ERESTARTSYS conversion in read paths
- mm/damon/core: validate ranges in damon_set_regions() (CVE-2026-68165)
- mm/damon/core: disallow overlapping input ranges for damon_set_regions()
(CVE-2026-68164)
- netfilter: nf_conntrack_expect: restore helper propagation via expectation
- netfilter: br_netfilter: Reallocate headroom if necessary in
neigh_hh_bridge()
- net: mpls: initialize rtm_tos in mpls_getroute() (CVE-2026-74577)
- media: uvcvideo: Implement dual stream quirk to fix loss of usb packets
- media: uvcvideo: Fix sequence number when no EOF
- gve: fix Rx queue stall on alloc failure (CVE-2026-68129)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB
write
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
- net: qrtr: ns: Limit the maximum server registration per node
(CVE-2026-43491)
- net: qrtr: ns: Raise node count limit to 512
- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
- ata: sata_mv: accept 1 or 2 resources in platform probe
- ata: libahci_platform: support non-consecutive port numbers
- ahci: Introduce ahci_ignore_port() helper
- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
- phy: zynqmp: Allow variation in refclk rate
- phy-zynqmp: Postpone getting clock rate until actually needed
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
- phy: zynqmp: fix runtime PM leak on probe allocation failure
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in
sip_help_tcp() (CVE-2026-74569)
- drm/mediatek: Check CRTC state before freeing
- keys: fix out-of-bounds read in keyring_get_key_chunk() (CVE-2026-74567)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects()
(CVE-2026-74566)
- assoc_array: trim the final shortcut word using the current chunk end
- netfilter: xt_hashlimit: validate hashtable supports
XT_HASHLIMIT_RATE_MATCH (CVE-2026-74564)
- ipv6: introduce dst_rt6_info() helper
- ipvs: fix the checksum validations
- ipvs: fix places with wrong packet offsets
- ipvs: do not mangle ICMP replies for non-first fragments
- netfilter: nft_payload: fix mask build for partial field offload
(CVE-2026-74579)
- rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
(CVE-2026-68322)
- rds: tcp: hold the RCU lock across ipv6_chk_addr() in
rds_tcp_laddr_check() (CVE-2026-74563)
- pinctrl-amd: Don't clear S4 wake bits at probe
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
(CVE-2026-74557)
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection
buffer (CVE-2026-74556)
- scsi: libsas: Abort all in-flight requests when device is gone
- scsi: libsas: Delete struct scsi_core
- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
(CVE-2026-74555)
- smb: client: fix buffer leaks in SMB1 read and write
- hwmon: (nct6755) Add support for NCT6799D
- hwmon: (nct6775) Fix IN scaling factors for 6798/6799
- hwmon: (nct6775) Increase and reorder ALARM/BEEP bits
- hwmon: (nct6775) Add support for 18 IN readings for nct6799
- hwmon: (nct6775) Additional TEMP registers for nct6799
- hwmon: (nct6775) Fix access to temperature configuration registers
- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
(CVE-2026-74553)
- hwmon: (lm90) Only report alarms if driver is ready (CVE-2026-74552)
- hwmon: (nzxt-smart2) DMA-align output buffer (CVE-2026-74551)
- net: do not send ICMP/NDISC Redirects when peer allocation fails
(CVE-2026-74550)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers
(CVE-2026-74549)
- net: bridge: mrp: fix Option TLV length in MRP_Test frames
- forcedeth: fix UAF of txrx_stats in nv_remove (CVE-2026-74548)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
(CVE-2026-74547)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
- hwmon: (adt7470) Use cached PWM frequency value
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
(CVE-2026-74546)
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check
- [powerpc*] boot: Fix simpleboot CPU node lookup check
- [powerpc*] boot: Fix treeboot-currituck CPU node lookup check
- [powerpc*] boot: Fix treeboot-akebono CPU node lookup check
- wifi: mac80211: validate individual TWT params before driver setup
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (CVE-2026-74540)
- net: phylink: put link_gpio if phylink_create fails
- scsi: zfcp: Fix memory leak during adapter release by destroying
gid_pn_req
- scsi: target: Clear cmd_cnt when initial counter enrollment fails
- net: sxgbe: free TX rings on RX allocation failure (CVE-2026-74525)
- net: sxgbe: check descriptor ring allocation failures
- can: isotp: check register_netdevice_notifier() error in module init
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
- octeontx2-pf: Set correct sequence for carrier off and tx queue stop
- qede: sync udp_tunnel ports outside qede_lock in the recovery path
(CVE-2026-74523)
- ksmbd: return success for deferred final close
- ksmbd: fix use-after-free in __close_file_table_ids() (CVE-2026-74522)
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
(CVE-2026-72392)
- af_unix: Give up GC if MSG_PEEK intervened. (CVE-2026-23394)
- rhashtable: clear stale iter->p on table restart (CVE-2026-64563)
- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
- pinctrl: devicetree: don't free uninitialized dev_name on error path
(CVE-2026-74519)
- pinctrl: bm1880: add missing select GENERIC_PINCONF
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
- mm/hugetlb: fix list corruption in allocate_file_region_entries()
(CVE-2026-74518)
- [x86] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2
is active (CVE-2026-74516)
- sctp: validate Adaptation Indication parameter length
- audit: fix potential integer overflow in audit_log_n_string()
- audit: fix potential use-after-free in audit_del_rule() (CVE-2026-74512)
- Bluetooth: HIDP: reject frames without a transaction header
(CVE-2026-74508)
- Bluetooth: HIDP: validate numbered report payloads (CVE-2026-74507)
- bpf: lwt: Fix dst reference leak on reroute failure
- ALSA: 6fire: Fix UAF at error handling during probe (CVE-2026-74505)
- ALSA: lx6464es: fix period byte count for 16-bit streams
- ALSA: pcm: wake linked drain waiters on unlink
- ASoC: tas2562: fix DVC coefficient write order
- ASoC: tas2562: fix broken entries in the volume lookup table
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
(CVE-2026-74499)
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
(CVE-2026-74498)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode
(CVE-2026-74497)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
- e1000: fix memory leak in e1000_probe()
- igbvf: Fix leak in TX DMA error cleanup (CVE-2026-74495)
- ipvs: do not propagate one-packet flag to synced conns
- net/smc: fix socket use-after-free during link group termination
(CVE-2026-74493)
- netfilter: ipset: do not update comments from kernel-side hash adds
(CVE-2026-74492)
- tipc: avoid use-after-free in poll trace queue dumps (CVE-2026-74490)
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
(CVE-2026-74488)
- binfmt_misc: reject a flag character as the field delimiter
(CVE-2026-74485)
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend
(CVE-2026-74481)
- net: bridge: stop fast-leave after deleting a port group (CVE-2026-74480)
- net: ipv6: clear suppressed fib6 rule result
- [powerpc*] ps3: Fix map failure path in dma_ioc0_map_pages()
- vxlan: re-fetch eth header after route_shortcircuit()
- vxlan: unclone skb head before modifying eth header in
route_shortcircuit()
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (CVE-2026-74475)
- vxlan: use pskb_network_may_pull() in route_shortcircuit()
(CVE-2026-74473)
- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
(CVE-2026-74472)
- tracing: Check return value of __register_event() in
trace_module_add_events() (CVE-2026-74471)
- tracing/filters: Fix false positive match in regex_match_full()
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
(CVE-2026-74470)
- sctp: reject stale cookies with mismatched verification tags
- sctp: prevent peer transport count overflow (CVE-2026-74469)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach
- i2c: amd-mp2: Unregister callback on adapter add failure
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
- power: supply: bq25890: fix the -10 C NTC lookup entry
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
- net: openvswitch: fix potential UAF on meter attach failure
(CVE-2026-74465)
- net: openvswitch: fix skb leak on flow key update failure during ct
(CVE-2026-74464)
- ice: wait for reset completion in ice_resume()
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock
deadlock (CVE-2026-74463)
- i2c: imx: Fix slave registration race and error handling
- i2c: imx: Cancel hrtimer before clearing slave pointer (CVE-2026-74461)
- can: c_can: c_can_chip_config(): keep controller in init mode until
bittiming is configured
- can: ems_usb: validate CPC message lengths (CVE-2026-74460)
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB
resubmit failure (CVE-2026-74459)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive
buffer
- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in
kvaser_usb_hydra_get_busparams()
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received
command extents (CVE-2026-74458)
- can: softing: fw_parse(): validate firmware record spans
- can: peak_usb: add bounds check for USB channel index (CVE-2026-74457)
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB
submit error (CVE-2026-74456)
- can: peak_usb: validate uCAN receive record lengths (CVE-2026-74455)
- can: ctucanfd: add missing MODULE_DEVICE_TABLE()
- can: ctucanfd: use self-test mode for PRESUME_ACK
- can: ctucanfd: unmap BAR0 using base address
- can: ctucanfd: handle bus error interrupts
- can: ctucanfd: mark error-active controller status valid
- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
(CVE-2026-74454)
- drm/vc4: Zero the tile state data array before each BIN job
(CVE-2026-74453)
- drm/amdgpu: restore UMD profile pstate after runtime resume
- drm/amdgpu: cap GTT size to physical RAM on APUs
- drm/amdkfd: Handle invalid event type in CRIU event restore
- drm/amdkfd: hold event_mutex while checkpointing CRIU events
(CVE-2026-74446)
- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
(CVE-2026-74444)
- drm/vmwgfx: bound DMA command body size against suffix pointer
(CVE-2026-74443)
- HID: logitech-dj: Fix maxfield check in DJ short report validation
- ata: libahci_platform: Do not set mask_port_map when not needed
- ata: ahci: Make ahci_ignore_port() handle empty mask_port_map
- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
(CVE-2026-74482)
- net: openvswitch: fix skb leak on flow key update failure during
recirculation
- firmware: stratix10-svc: fix memory leaks and list corruption bugs
(CVE-2026-68183)
- gpio: pch: use raw_spinlock_t for the register lock (CVE-2026-74468)
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
(CVE-2026-64434)
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev
- Bluetooth: hci_conn: fix potential UAF in create_big_sync (CVE-2026-46111)
- mount: honour SB_NOUSER in the new mount API
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
- Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
- netfilter: ipset: switch ext_size to atomic64_t
- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
- ipvs: return the csum validation for forward hook
- btrfs: fix memory leak in btrfs_do_encoded_write()
- bpf: Preserve pointer state for commuted arithmetic
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in
smc_llc_event_handler()
- net/sched: cls_route: fix fastmap use-after-free on filter
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
- net/mlx5: fw_tracer, return NULL on create error
- counter: microchip-tcb-capture: Fix DT channel validation
- tcp: add a scheduling point in established_get_first()
- bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch
- bpf: tcp: Make sure iter->batch always contains a full bucket snapshot
- bpf: tcp: Get rid of st_bucket_done
- bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items
- bpf: tcp: Avoid socket skips and repeats during iteration
- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
- vhost/vdpa: reject overflowing PA map page counts on 32-bit
- udp: fix potential use-after-free in tunnel segmentation
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
- net/openvswitch: check Ethernet header length in key_extract()
- hwmon: (nzxt-smart2) Check return value of init_device() in probe
- hwmon: (lm25066) Use i2c_get_match_data()
- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
- bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
- bnxt_en: Fix PTP PPS setting bug
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure
- tcp: fix TFO max_qlen accounting across reuseport migration
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
- net: prestera: validate firmware header length
- net: remove WARN_ON_ONCE() from sk_mc_loop()
- net/smc: fix TOCTOU race between smc_listen_out() and listener close
- net: qrtr: ns: Raise lookup limit to 128
- net: thunderbolt: Tear down DMA paths before stopping the rings
- ata: pata_sl82c105: fix bridge revision use-after-free
- net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
- sctp: clear control chunk transport if it is being removed
- tls: don't abort the connection on signal-interrupted sends
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string
termination
- regulator: devres: add API for reference voltage supplies
- hwmon: (ads7828) Fix external VREF regulator handling
- [x86] KVM: x86/mmu: Rename __direct_map() to direct_map()
- [x86] KVM: x86: Check for invalid/obsolete root *after* making MMU pages
available (CVE-2026-64561)
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers
- Input: evdev - sanitize event type index when fetching event masks
- ALSA: usb-audio: fix OOB write on Type II inbound URBs
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
- [amd64] thunderbolt: icm: Preserve USB4 proxy data-valid bit
- usb: cdnsp: fix incorrect endian conversions for APB timeout register
- usb: gadget: f_ncm: Use unsigned int for ndp_index
- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
- vt: add permission check for KDSKBMETA ioctl
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
- Input: evdev - fix information leak in evdev_pass_values()
- ima: fix out-of-bounds read in xattr_verify()
- ipvs: add totalconns for dest
- ipvs: properly update the overload flag on dest edit
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors
- net/packet: reset the MAC header on the packet-socket transmit path
- net: openvswitch: reallocate update replies for mismatched IDs
- net/sched: reject overly deep qdisc hierarchies
- net: octeontx2-pf: Fix UB in shift operation
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
- netfilter: ebt_nflog: pin the NFLOG backend
- net: bridge: mrp: fix uninitialised bytes on the wire
- futex: Prevent robust futex exit race some more
- fortify: refactor test_fortify Makefile to fix some build problems
- fortify: Disable -Wstringop-overread in tests
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (CVE-2026-64582)
- fscrypt: Replace mk_users keyring with simple list
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
- ipv4: fix use-after-free in fib_nhc_update_mtu()
- serial: 8250_dma: Clear stale RX state on shutdown
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
- staging: rtl8723bs: fix OOB read in WMM_param_handler()
- staging: rtl8723bs: fix missing shared-key auth challenge length check
- staging: rtl8723bs: validate monitor transmit frame lengths
- misc: fastrpc: fix channel ctx ref leak when session alloc fails
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
- ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
- ALSA: usx2y: bound the hwdep mmap fault offset
- tracing: Fix race between update_event_fields and, event_define_fields
- fbdev: bitblit: bound-check glyph index in bit_cursor()
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev
- netfilter: bridge: release template ct on non-IP path
- net: atlantic: free stranded TX buffers on ring deinit
- net: atlantic: free RX pages of consumed but not refilled buffers
- net/sched: act_gact, act_police: range check the fallback control action
- xdp: reject clones that overrun skb_shared_info tailroom
- vxlan: do not arm the ageing timer on a device that is down
- vsock/virtio: read virtqueues under worker locks
- vsock/virtio: avoid refilling the RX queue after teardown
- vhost: reset the vring metadata cache on vring reconfiguration
- tipc: read le->link under the node lock in tipc_node_link_down()
- smb: client: Fix use-after-free in cifs_try_adding_channels()
- [x86] KVM: x86/mmu: WARN and clear role.invalid when creating a child
shadow page
- Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
- ptp: ocp: Fix board ID over-read
- ipv6: fix Route Information option length validation
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
- bpf, sockmap: Fix sk_redir use-after-free in send verdict
- scsi: scsi_debug: Negate wrapped memcmp() result
- sctp: keep chunk->transport in step with the list it is queued on
- sctp: fix use-after-free of cached ASCONF chunk
- sctp: clear new_transport when removing a peer
- [amd64] thunderbolt: Bound the DROM dual link port number before indexing
sw->ports
- bpf: tcp: fix double sock release on batch realloc
- regulator: devres: fix devm_regulator_get_enable_read_voltage() return
- hwmon: (nct6775) Fix register for nct6799
- hwmon: (nct6775) Fix non-existent ALARM warning
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.184
- block: stop the timeout timer when releasing a never added disk
- kernel/user: Allow user_struct::locked_vm to be usable for iommufd
- f2fs: fix UAF issue in f2fs_merge_page_bio() (CVE-2025-40054)
- fscrypt: use the mount idmap for the owner check in
fscrypt_ioctl_set_policy() (CVE-2026-74595)
- ipvs: separate destination availability state
- selinux: require every boolean value to be defined
- selinux: reject a class permission count below its inherited common
- selinux: do not cancel a policy conversion that never started
- mptcp: options: reset DSS fields in case of unexpected size
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls
- [powerpc*] pseries: pci - logic bug
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
- Input: psxpad-spi - set driver data before use
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
- Input: iforce - validate input packet lengths
- [powerpc* ]pseries: lparcfg - fix kbuf[] underflow
- Input: synaptics-rmi4 - zero report size on F54 work error
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
- Input: synaptics-rmi4 - block s_input when F54 queue is busy
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
- crypto: qce - fix error path in devm_qce_register_algs
- libceph: fix multiple unsafe decodes in decode_locker()
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
- Input: sur40 - fix input device registration ordering
- Input: sur40 - fix V4L error path cleanup
- libceph: Avoid using invalid osd indices from primary_temp
- ceph: fix MDS random selection readiness predicate
- libceph: tolerate addrvecs with multiple entries of the same type
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
- mmc: sdhci: unmap the bounce buffer before device release
- mmc: sdhci: make tuning_err a signed int
- drm/radeon: fix autosuspend cleanup during teardown
- drm/amdgpu: Reject UVD message with invalid number of h265 refs
- drm/amdgpu: validate GEM_CREATE domain combinations
- drm/amdgpu: Reject UVD message with dimensions above 4096
- drm/amdgpu: Implement insert_end for VCE 3
- drm/amdgpu: Fix UVD decode image min size calculation
- xfs: fix ilock leak on error in xfs_dq_get_next_id
- xfs: don't swallow dquot recovery verification errors
- xfs: check v5 superblock features early
- net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419)
- riscv: Don't use PGD entries for the linear mapping
- mm: do file ownership checks with the proper mount idmap (CVE-2026-64294)
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is
uninitialized (CVE-2026-64192)
- [amd64] iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
- udmabuf: Do not create malformed scatterlists
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
(CVE-2026-64590)
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
(CVE-2026-64280)
- i2c: davinci: Unregister cpufreq notifier on probe failure
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (CVE-2026-64272)
- Input: mms114 - reject an oversized device packet size (CVE-2026-64270)
- VFS/audit: introduce kern_path_parent() for audit
- audit: widen ino fields to u64
- audit: use 'unsigned int' instead of 'unsigned'
- audit: fix recursive locking deadlock in audit_dupe_exe() (CVE-2026-68096)
- ALSA: hda: conexant: Remove mic bias threshold override
- ALSA: hda: Fix cached processing coefficient verbs
- serial: max310x: replace bare use of 'unsigned' with 'unsigned int'
(checkpatch)
- serial: max310x: implement gpio_chip::get_direction()
- rxrpc: serialize kernel accept preallocation with socket teardown
(CVE-2026-74436)
- fbcon: Rename struct fbcon_ops to struct fbcon_par
- fbcon: Use correct type for vc_resize() return value
- tipc: restrict socket queue dumps in enqueue tracepoints (CVE-2026-72299)
- vduse: Use fixed 4KB bounce pages for non-4KB page size
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent
- vduse: take out allocations from vduse_dev_alloc_coherent
- VDUSE: avoid leaking information to userspace (CVE-2026-72305)
- mlxsw: spectrum: On port enslavement to a LAG, join upper's bridges
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (CVE-2026-72308)
- octeontx2: Annotate mmio regions as __iomem
- octeontx2-pf: clear stale mailbox IRQ state before request_irq()
- octeontx2-vf: clear stale mailbox IRQ state before request_irq()
- ASoC: mediatek: mt8183: Check runtime resume during probe
- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
(CVE-2026-72262)
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable()
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe()
- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable
- ASoC: mediatek: mt8192: Check runtime resume during probe (CVE-2026-72260)
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
- netfilter: nft_set_pipapo: move prove_locking helper around
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone
- netfilter: nft_set_pipapo: merge deactivate helper into caller
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal
path
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction
(CVE-2026-72252)
- netfilter: nf_conntrack_sip: remove net variable shadowing
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
(CVE-2026-72253)
- lsm: infrastructure management of the sock security
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
(CVE-2026-72242)
- remoteproc: qcom: replace kstrdup with kstrndup
- remoteproc: qcom: fix sparse warnings
- remoteproc: qcom: pas: Adjust the phys addr wrt the mem region
- remoteproc: qcom: Fix leak when custom dump_segments addition fails
(CVE-2026-72216)
- netfilter: nf_tables: pass context structure to nft_parse_register_load
- netfilter: nf_tables: drop unused 3rd argument from validate callback ops
- netfilter: bitwise: rename some boolean operation functions
- netfilter: nf_tables: Remove unused nft_reduce_is_readonly()
- netfilter: nft_objref: validate objref and objrefmap expressions
(CVE-2025-40206)
- mm: move most of core MM initialization to mm/mm_init.c
- mm/vmemmap/devdax: fix kernel crash when probing devdax devices
(CVE-2023-53706)
- mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
(CVE-2026-72172)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (CVE-2026-72170)
- mtd: maps: vmu-flash: fix fault in unaligned fixup
- net: thunderbolt: Fix frags[] overflow by bounding frame_count
(CVE-2026-72157)
- taskstats: fill_stats_for_tgid: use for_each_thread()
- taskstats: retain dead thread stats in TGID queries
- [amd64] thunderbolt: Prevent XDomain delayed work use-after-free on
disconnect (CVE-2026-74575)
- i2c: imx: separate atomic, dma and non-dma use case
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
(CVE-2026-72142)
- bpf,fork: wipe ->bpf_storage before bailouts that access it
(CVE-2026-72110)
- ovl: use linked upper dentry in copy-up tmpfile
- dm-verity: avoid double increment of &use_bh_wq_enabled
- dm: fix trailing statements
- dm crypt: correct 'foo*' to 'foo *'
- dm: add missing empty lines
- dm: remove unnecessary braces from single statement blocks
- dm-integrity: don't increment hash_offset twice (CVE-2026-72099)
- dm-verity: make error counter atomic (CVE-2026-72096)
- firmware_loader: introduce __free() cleanup hanler
- Input: ims-pcu - fix firmware leak in async update (CVE-2026-72077)
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
(CVE-2026-72070)
- mmc: vub300: fix use-after-free on disconnect
- mmc: vub300: rename probe error labels
- mmc: vub300: fix use-after-free on probe failure
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
(CVE-2026-72069)
- net: mana: Validate the packet length reported by the NIC (CVE-2026-72065)
- net/sched: act_ct: preserve tc_skb_cb across defragmentation
(CVE-2026-72057)
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
(CVE-2026-72051)
- treewide: rename pinctrl_gpio_direction_input_new()
- gpio: tegra: do not call pinctrl for GPIO direction (CVE-2026-72063)
- gpio: mt7621: avoid corruption of shared interrupt trigger state
(CVE-2026-72062)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
(CVE-2026-72045)
- net/sched: taprio: avoid calling child->ops->dequeue(child) twice
- net/sched: sch_taprio: Replace direct dequeue call with peek and
qdisc_dequeue_peeked (CVE-2026-72035)
- tcp_bpf: Inline do_tcp_sendpages as it's now a wrapper around tcp_sendmsg
- espintcp: Inline do_tcp_sendpages()
- siw: Inline do_tcp_sendpages()
- tcp_bpf, smc, tls, espintcp, siw: Reduce MSG_SENDPAGE_NOTLAST usage
- espintcp: use sk_msg_free_partial to fix partial send (CVE-2026-72041)
- bootconfig: do not put quotes on cmdline items unless necessary
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
- ipmi: fix refcount leak in i_ipmi_request() (CVE-2026-72040)
- net: macb: drop in-flight Tx SKBs on close (CVE-2026-72017)
- tracing: Rename kvfree_rcu() to kvfree_rcu_mightsleep()
- tracing/osnoise: Call synchronize_rcu() when unregistering
(CVE-2026-72012)
- net: ipa: fix SMEM state handle leaks in SMP2P init
- octeontx2-pf: fix SQB pointer leak on init failure (CVE-2026-72023)
- ata: libata-core: Reject an invalid concurrent positioning ranges count
(CVE-2026-72030)
- pmdomain: imx: Fix i.MX8MP power notifier
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
(CVE-2026-72015)
- Bluetooth: Remove usage of the deprecated ida_simple_xx() API
- Bluetooth: HCI: Remove HCI_AMP support (CVE-2024-38620)
- vfio/pci: Fix racy bitfields and tighten struct layout
- KVM: Introduce vcpu->wants_to_run
- [x86] KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on
KVM_RUN
- usb: musb: omap2430: clean up probe error handling
- usb: musb: omap2430: Do not put borrowed of_node in probe (CVE-2026-68371)
- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
(CVE-2026-68280)
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown
(CVE-2026-68367)
- usb: typec: ucsi: Only enable supported notifications
- usb: typec: ucsi: split connector lock classes
- usb: typec: ucsi: Fix race condition and ordering in port unregistration
(CVE-2026-74441)
- drm/displayid: fix Tiled Display Topology ID size
- drm/tegra: fbdev: Remove offset into framebuffer memory
- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
- [x86] drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
- [x86] drm/i915/vrr: require valid min/max vfreq for VRR (CVE-2026-68254)
- [x86] drm/i915/hdcp: Move to using intel_display in intel_hdcp
- [x86] drm/i915/hdcp: require monotonically increasing seq_num_v
- [x86] drm/i915/hdcp: check streams[] bounds before overflow
(CVE-2026-68253)
- media: i2c: imx219: Drop IMX219_VTS_* macros
- media: i2c: imx219: Correct the minimum vblanking value
- media: i2c: imx219: Rename VTS to FRM_LENGTH
- media: imx219: Fix maximum frame length in lines
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (CVE-2026-68198)
- wifi: brcmfmac: drain bus_reset work on device removal (CVE-2026-64586)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
- mei: bus: access mei_device under device_lock on cleanup (CVE-2026-68181)
- mptcp: pm: avoid code duplication to lookup endp
- mptcp: add mptcp_userspace_pm_lookup_addr helper
- mptcp: pm: use addr entry for get_local_id
- mptcp: pm: userspace: fix use-after-free in get_local_id (CVE-2026-68169)
- sctp: avoid auth_enable sysctl UAF during netns teardown (CVE-2026-68162)
- ceph: avoid fs reclaim while using current->journal_info
- libceph: Amend checking to fix `make W=1` build breakage
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
(CVE-2026-68159)
- libceph: add doutc and *_client debug macros support
- ceph: pass the mdsc to several helpers
- ceph: rename _to_client() to _to_fs_client()
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
- libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082)
- net: move skb_gro_receive_list from udp to core
- net: gro: fix double aggregation of flush-marked skbs (CVE-2026-68136)
- net/sched: serialize qdisc_rtab_list against concurrent get/put
(CVE-2026-68138)
- ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
(CVE-2026-64139)
- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
(CVE-2026-68100)
- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
(CVE-2026-68099)
- super: fix emergency thaw deadlock on frozen block devices
(CVE-2026-68132)
- smb/server: rename include guard in smb_common.h
- ksmbd: rename smb2_get_msg to smb_get_msg
- smb/server: fix minimum SMB1 PDU size
- smb/server: fix minimum SMB2 PDU size
- ksmbd: validate minimum PDU size for transform requests (CVE-2026-68431)
- mm/migrate_device: page_remove_rmap() -> folio_remove_rmap_pte()
- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
- erofs: tidy up internal.h
- erofs: maintain cookies of share domain in self-contained list
- erofs: cap LZMA stream pool size
- Bluetooth: hci_sync: Introduce hci_cmd_sync_run/hci_cmd_sync_run_once
- Bluetooth: MGMT: Fix not generating command complete for
MGMT_OP_DISCONNECT
- Bluetooth: MGMT: Remove unused mgmt_pending_find_data
- Bluetooth: MGMT: Protect mgmt_pending list with its own lock
(CVE-2025-38117)
- Bluetooth: mgmt: fix UAF in pair command cancellation (CVE-2026-74510)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online
- overflow: Change DEFINE_FLEX to take __counted_by member
- Bluetooth: hci_conn, hci_sync: Use __counted_by() to avoid -Wfamnae
warnings
- Bluetooth: hci_core: Fix not handling hdev->le_num_of_adv_sets=1
- Bluetooth: hci_sync: Fix advertising data UAFs (CVE-2026-74509)
- ksmbd: conn lock to serialize smb2 negotiate
- ksmbd: reject repeated SMB2 NEGOTIATE requests (CVE-2026-74494)
- igc: remove napi_synchronize() in igc_down()
- net: pktgen: fix code style (WARNING: Block comments)
- net: pktgen: fix proc entry use-after-free (CVE-2026-74479)
- veth: convert frag_list skbs before running XDP (CVE-2026-74476)
- ice: fix VF interrupts cleanup
- ice: fix memory leak in ice_lbtest_prepare_rings()
- fsnotify: opt-in for permission events at file open time
- fs: don't block write during exec on pre-content watched files
- binfmt_misc: restore write access when removing an entry (CVE-2026-74487)
- i2c: bcm-iproc: remove printout on handled timeouts
- i2c: iproc: reset bus after timeout if START_BUSY is stuck
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb
allocation failure
- drm/amd/pm: fix torn gpu metrics reads
- drm/amd/pm: fix pptable use-after-free (CVE-2026-74450)
- can: rcar_canfd: Invert reset assert order
- can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
- can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
- can: rcar_canfd: change the initializing flow for clocks and resets
- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
- mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
(CVE-2026-74672)
- veth: Introduce veth_xdp_buff wrapper for xdp_buff
- veth: fix skb length accounting after XDP frag adjustment (CVE-2026-74612)
- [x86] KVM: SVM: Serialize accesses to the owner and mirror list with
separate lock (CVE-2026-74607)
- openvswitch: use skb_ip_totlen in conntrack
- net: sched: use skb_ip_totlen and iph_totlen
- openvswitch: move key and ovs_cb update out of handle_fragments
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
(CVE-2026-74621)
- netfilter: conntrack: sctp: use nf log infrastructure for invalid packets
- netfilter: nf_conntrack: defer invalid log until after unlock
(CVE-2026-74624)
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
- crypto: ccm - Set rfc4309 maxauthsize from child
- netfilter: ipset: fix refcount race between list:set GC and swap
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort
path
- netfilter: flowtable: publish GC-visible tuple last
- netfilter: ipset: fix list type element drift bug
- netfilter: ipset: let destroy callbacks adjust ext mem size
- ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
- macvlan: inherit needed_headroom and needed_tailroom from lowerdev
- net: packet: fix wrong transport_header when sending VLAN-tagged frame
- net/tls: Fail tls_sw_splice_read() after a failed async decrypt
- af_packet: Don't send zero-byte data in tpacket_snd().
- net/sched: cls_u32: skip hash tables in u32_bind_class()
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
- net/x25: fix use-after-free of the socket by its timers (CVE-2026-74628)
- mm/huge_memory: fix huge_zero_pfn race (CVE-2026-74632)
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
- Bluetooth: hci_sync: Fix not using correct handle
- RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
- Bluetooth: hci_sock: Prevent race in socket write iter and sock bind
- Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if immediate
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
- Bluetooth: mgmt: fix pending command UAF in EIR updates
- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu()
- ring-buffer: Use current_context for safe per-CPU buffer swap
(CVE-2026-74601)
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.185
- PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
- Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
- rndis_host: add overflow check in rndis_rx_fixup()
- ALSA: dummy: Check card index validity at probe
- ocfs2: fix missing metadata reservation for large xattrs
- null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
- kcov: fix data corruption and race conditions on PREEMPT_RT
- ext4: stop retrying saturated xattr cache entries
- ext4: clear error before retrying inode xattr space fallback
- xfs: validate attr entry pointer before field access
- [arm*] misc: fastrpc: Rework fastrpc_req_munmap
- [arm*] misc: fastrpc: Remove buffer from list prior to unmap operation
(CVE-2026-74647)
- NTB: ntb_netdev: Preserve RX queue depth on allocation failure
(CVE-2026-74626)
- serial: amba-pl011: synchronize DMA teardown
- perf/core: Fix child_total_time_enabled accounting bug at task exit
- perf: Fix cgroup state vs ERROR
- perf: Fix dangling cgroup pointer in cpuctx
- perf/core: Fix group leader use-after-free after sibling detach
(CVE-2026-74637)
- packet: use consistent hard_header_len in non-ring send paths
(CVE-2026-74582)
- packet: use consistent hard_header_len in TX_RING send path
(CVE-2026-74668)
- serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants
- serial: sc16is7xx: convert bitmask definitions to use BIT() macro
- serial: sc16is7xx: rename EFR mutex with generic name
- serial: sc16is7xx: use guards for simple mutex locks
- serial: sc16is7xx: enable THRI before filling TX FIFO
- net/packet: convert po->pressure to an atomic flag
- packet: synchronize pressure clearing with ring reconfiguration
(CVE-2026-74666)
- inet: frags: publish queues before arming timer (CVE-2026-74662)
- drm/amdgpu: disallow multiple FENCE chunks in one submit (CVE-2026-80539)
- xfs: don't use a xfs_log_iovec for ri_buf in log recovery
- xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536)
- drm/amdgpu: check ASPM on the dGPU host link
- gpio: ml-ioh: use raw_spinlock_t for the register lock (CVE-2026-80562)
- tls: fix lockless read of strp->msg_ready in ->poll
- tls: handle data disappearing from under the TLS ULP (CVE-2025-38616)
- iomap: adjust read range correctly for non-block-aligned positions
(CVE-2025-68794)
- nfc: digital: clamp SENSF_RES length to the destination buffer
- nfc: fdp: bound the device-reported read length and fix an skb leak
- nfc: microread: validate target discovery payload lengths
- nfc: llcp: bound the connect_sn TLV walk to the skb
- nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
- nfc: llcp: reject PDUs shorter than the LLCP header
- nfc: pn533: purge fragmented skbs during cleanup
- nfc: st21nfca: validate ATR_REQ length against the received frame
- nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
- nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
- nfc: nci: free destination parameters when closing a connection
- ndisc: ndisc_send_redirect() cleanup
- libceph: fix OOB read in decode_watchers() via missing bounds check
(CVE-2026-80557)
- ipv4: reject undersized MTUs in ip_do_fragment()
- ipv6: fix use-after-free in ip6_finish_output2()
- nvmet-auth: zero the AUTH_RECEIVE response buffer
- nvmet-fc: fix invalid free in LS IOD error path
- nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
- Input: byd - synchronize timer deletion before freeing private data
(CVE-2026-80572)
- ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (CVE-2026-80583)
- mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (CVE-2026-46158)
- mptcp: pm: ADD_ADDR rtx: free sk if last (CVE-2026-46170)
- mptcp: pm: fix data race in add_addr timer callback
- HID: magicmouse: do not keep a stale msc->input if no input is claimed
- HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
- HID: core: fix OOB read of field->usage in hid_set_field()
- xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (CVE-2026-64581)
- Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
- Input: atkbd - skip deactivate for HONOR ZQC-P
- can: use skb hash instead of private variable in headroom
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
- [arm*] misc: fastrpc: Fix double free of 'buf' in error path
- HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
- HID: core: fix number/pointer type confusion on long items
- HID: sensor: custom: Fix use-after-free in enable_sensor
- HID: hyperv: validate initial device info bounds
- Bluetooth: hci_event: fix LE list UAF on reset
- net: gro: properly validate BIG TCP aggregation criteria
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.186
- inet: frags: strip GSO state from fragments before reassembly
(CVE-2026-80590)
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.187
- RDMA/rxe: Fix OOB in free_rd_atomic_resources()
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
(CVE-2026-46266)
- [x86] KVM: x86/mmu: Check write tracking in all address spaces
- ext4: don't enable DAX on new encrypted files
- io_uring/io-wq: fix worker accounting when canceling creation callbacks
- ipvs: reload ip header after head reallocation (CVE-2026-68476)
- Revert "usb: phy: fsl-usb: Fix use-after-free in delayed work during
device removal"
- wifi: ath11k: Add missing hw_ops->get_ring_selector() for IPQ5018
(CVE-2023-54141)
- drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP (CVE-2023-54263)
- bpf: Remove tst_run from lwt_seg6local_prog_ops. (CVE-2024-46754)
- jfs: add check read-only before truncation in jfs_truncate_nolock()
(CVE-2024-58094)
- jfs: add check read-only before txBeginAnon() call (CVE-2024-58095)
- jfs: Fix null-ptr-deref in jfs_ioc_trim (CVE-2025-38203)
- exfat: fix double free in delayed_free (CVE-2025-38206)
- media: platform: exynos4-is: Add hardware sync wait to
fimc_is_hw_change_mode() (CVE-2025-38237)
- mISDN: hfcpci: Fix warning when deleting uninitialized timer
(CVE-2025-39833)
- can: j1939: implement NETDEV_UNREGISTER notification handler
(CVE-2025-39925)
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
- can: j1939: make j1939_sk_bind() fail if device is no longer registered
- smc: Fix use-after-free in __pnet_find_base_ndev(). (CVE-2025-40064)
- [arm64] KVM: arm64: Prevent access to vCPU events before init
(CVE-2025-40102)
- smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
(CVE-2025-40139)
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
(CVE-2025-40168)
- ASoC: nau8821: Cancel delayed work on component remove (CVE-2026-45963)
- bpf: Fix use-after-free in offloaded map/prog info fill (CVE-2026-53089)
- Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
- ASoC: nau8821: Cancel pending work before suspend
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
- selinux: switch two allocations to use kzalloc_objs()
- Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup"
- Revert "smb: client: use kvzalloc() for megabyte buffer in simple
fallocate"
- block: make bio_check_eod work for zero sized devices
- mptcp: pm: fix memory leak from alloc-during-teardown race
- ext4: propagate errors from fast commit range replay
- nilfs2: correct return value kernel-doc descriptions for ioctl functions
- nilfs2: reject invalid block index in GC ioctl
- nfc: nci: add data_len bound checks to activation parameter extractors
- HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
- HID: magicmouse: re-enable multitouch after reset-resume
- nvme: rename CDR/MORE/DNR to NVME_STATUS_*
- nvmet-tcp: bound SGL data length before allocating command buffers
- HID: nintendo: stop device IO before hid_hw_stop on probe failure
- HID: uclogic: fix use-after-free of inrange_timer on remove
- HID: ft260: improve i2c write performance
- HID: ft260: improve i2c large reads performance
- HID: ft260: skip unexpected HID input reports
- HID: ft260: wake up device from power saving mode
- HID: ft260: missed NACK from busy device
- HID: ft260: validate i2c input report length
- HID: ft260: fix stack-use-after-return write in I2C read race
- Bluetooth: hci_sync: Use bt_dev_err() to log error message in
hci_update_event_filter_sync()
- Bluetooth: hci_sync: Fix accept list UAF during suspend
- Bluetooth: hci_conn: Fix not matching by CIS ID
- Bluetooth: ISO: use correct CIS order in Set CIG Parameters event
- Bluetooth: hci_event: fix Set CIG Parameters error status handling
- Bluetooth: hci_event: validate LE Set CIG Parameters response
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (CVE-2026-72323)
- accessibility: speakup: unregister tty ldisc on later init failures
- usb: xhci: Handle USB3 port events when there is one roothub
- fuse: fix invalidate lock leak on setattr writeback failure
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure
- usb: usbtest: disable dynamic ID support
- usb: gadget: f_tcm: keep port count until LUN teardown completes
- tls: device: fix out-of-bounds write in tls_append_frag()
- xfrm: espintcp: fix UAF during close
- xfrm: drop ESP-in-TCP packets with no ingress device
- xfrm: ah6: validate routing header segments_left
- xfrm: fix xfrm_state_construct() auth-trunc leak
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast
context
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation
- mm/swap: reject swapon() on filesystem-level encrypted files
- Bluetooth: hci_core: Fix hci_conn_hash_lookup_cis
- usb: core: Add lock to usb_wakeup_notification()
- usb: core: Strengthen error handling in hub_hub_status()
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
- ALSA: usb-audio: Complete cleanup after system-resume errors
- USB: serial: option: fix slab OOB read in interrupt URB callback
- USB: serial: spcp8x5: drop broken carrier detect support
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
- usb: usbfs: fix use-after-free of usb_device in usbdev_release()
Checksums-Sha1:
bbc82276ce2fdb8ad8e1f2352a6f277262894631 399396 linux_6.1.187-1.dsc
b6b041143c8e50ce0fff42b9cc95704be1a6d36d 137990204 linux_6.1.187.orig.tar.xz
71747677f6350fb1fa8597c644018f15a76b6fcf 1904540 linux_6.1.187-1.debian.tar.xz
04954868d7a49360698d492f4b67e41b137bccc0 6964 linux_6.1.187-1_source.buildinfo
Checksums-Sha256:
9a66f3af2a0d90ad5ae16b059b7e299923d2fd0b1ad88c8f74c500e7abe6171a 399396 linux_6.1.187-1.dsc
bec853ea2b0314c64012478964e10d3e094fa019799c926b8057157afdae23f6 137990204 linux_6.1.187.orig.tar.xz
0d61e19cd8b6dcf83ac5a35a930cc132c37879dfe2f50dd889440d6026104729 1904540 linux_6.1.187-1.debian.tar.xz
955974b558019b20c78f68fd77e952368d3199494fd2a8389bfb2d98e36539bf 6964 linux_6.1.187-1_source.buildinfo
Files:
364aeb20e5f412cfcc1916052bc187ba 399396 kernel optional linux_6.1.187-1.dsc
9f3fc106f0411bec8bb7bbeca43c9c1d 137990204 kernel optional linux_6.1.187.orig.tar.xz
848fad6f4383b405efb54d6daa12d6d0 1904540 kernel optional linux_6.1.187-1.debian.tar.xz
dcb03ad0ef534465fdc781b230fcee1c 6964 kernel optional linux_6.1.187-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqfEvhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EpBQP/21mjmzI8VTMQZzzdEXl5rPKUk2L7SqZ
I9hZalMxY/0hkxADcLTVYpWQX8ImhjNRkBRCibsC6na2GxjU0shdEe8ogtSuaZGj
s5TGpXMneQf7zz8DqygtY/T0wIo5HA34ftpcWamK3b6HAvd1cHWMssKONjQlNp5i
aJ5LEliFtHU4adM3brWXjpgymHP3qtZEM3ARAt+ZtPvgajg6hLFMJhhR9azm7KX7
D1kMSQjZu6bcFtF95BSMLJq2pC9J2CAzCupJKQCEI8kcn4Vw0ae85OljiyAn7KY/
r2It2GWf4zK1YDCuT1UjWlg3bbmqNrjp1OnmwS005rK0IiSIPP3/aTywky1mPtFH
9vfg2jT4ax2spRwjm4kJ/YgXBwMQVoUTlENF2HIakxdQCnSdMSLNV0Ev+W0TrGnB
ClRVDYfEi8K2zfDAZ4mpc6rJ9xG78YZne1bTlWEQWDrzwu/KyOv3+4ckPxqbIdO2
qmP8iybXfnPwjCcF3mO3IcZAiq9kNXf2bPWzBcUdHhJoYtNMlbXKFqKZIDisTOwB
Gtofvv5+i1E7w9QvA2rUglK/9jG5w/ZC3Gj0yu/Zh9V6ImZD9tdh70nlD3bkBntr
WCyKk8t0DWbBTGil59RzBn4HS3923KzyiHMp1Qa8zC2lrL64SSNi/f9tXAHaNiAz
9z8dikwTpesa
=+226
-----END PGP SIGNATURE-----