-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 28 Sep 2026 14:18:50 +0200
Source: linux-signed-amd64
Architecture: source
Version: 6.12.111+1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Changes:
linux-signed-amd64 (6.12.111+1) trixie-security; urgency=high
.
* Sign kernel from linux 6.12.111-1
.
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.108
- RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
- RDMA/rxe: Fix OOB in free_rd_atomic_resources()
- [amd64] KVM: x86/mmu: Check write tracking in all address spaces
- ext4: don't enable DAX on new encrypted files
- io_uring/io-wq: fix worker accounting when canceling creation callbacks
- nvme-tcp: fix usage of page_frag_cache
- HID: uhid: convert to hid_safe_input_report()
- selinux: use known type instead of void pointer
- selinux: avoid unnecessary indirection in struct level_datum
- selinux: make more use of str_read() when loading the policy
- selinux: use u16 for security classes
- selinux: more strict policy parsing
- selinux: reject a permission value exceeding the class permission count
- selinux: require a class's permission values to cover its permission count
- perf: Reject exited events as group leaders (CVE-2026-74753)
- jfs: add check read-only before truncation in jfs_truncate_nolock()
(CVE-2024-58094)
- jfs: add check read-only before txBeginAnon() call (CVE-2024-58095)
- ibmvnic: Use kernel helpers for hex dumps (CVE-2025-22104)
- jfs: Fix null-ptr-deref in jfs_ioc_trim (CVE-2025-38203)
- exfat: fix double free in delayed_free (CVE-2025-38206)
- media: platform: exynos4-is: Add hardware sync wait to
fimc_is_hw_change_mode() (CVE-2025-38237)
- mISDN: hfcpci: Fix warning when deleting uninitialized timer
(CVE-2025-39833)
- can: j1939: implement NETDEV_UNREGISTER notification handler
(CVE-2025-39925)
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
- can: j1939: make j1939_sk_bind() fail if device is no longer registered
- smc: Fix use-after-free in __pnet_find_base_ndev(). (CVE-2025-40064)
- [arm64] KVM: arm64: Prevent access to vCPU events before init
(CVE-2025-40102)
- smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
(CVE-2025-40139)
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
(CVE-2025-40168)
- [amd64] ASoC: nau8821: Cancel delayed work on component remove
(CVE-2026-45963)
- bpf: Fix use-after-free in offloaded map/prog info fill (CVE-2026-53089)
- [riscv64] Fix register corruption from uninitialized cregs on error
(CVE-2026-64082)
- Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
- [amd64] ASoC: nau8821: Cancel pending work before suspend
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
- selinux: switch two allocations to use kzalloc_objs()
- ring buffer: Propagate __rb_map_vma return value to caller
- veth: fix OOB txq access in veth_poll() with asymmetric queue counts
- [powerpc*] hv-gpci: fix preempt count leak in sysfs show paths
(CVE-2026-64070)
- ksmbd: harden file lifetime during session teardown
- nilfs2: correct return value kernel-doc descriptions for ioctl functions
- nilfs2: reject invalid block index in GC ioctl
- nfc: nci: add data_len bound checks to activation parameter extractors
- HID: pidff: Rework pidff_set_time() to fix warnings
- HID: pidff: Use ARRAY_SIZE macro instead of sizeof
- HID: pidff: clang-format pass
- HID: pidff: fix OOB write when hid->inputs is empty
- HID: asus: simplify RGB init sequence
- HID: asus: fix missing hid_is_usb() check
- HID: ft260: validate i2c input report length
- HID: ft260: fix stack-use-after-return write in I2C read race
- HID: uclogic: fix use-after-free of inrange_timer on remove
- Bluetooth: hci_sync: Use bt_dev_err() to log error message in
hci_update_event_filter_sync()
- Bluetooth: hci_sync: Fix accept list UAF during suspend
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
- accessibility: speakup: unregister tty ldisc on later init failures
- usb: xhci: Handle USB3 port events when there is one roothub
- fuse: fix invalidate lock leak on setattr writeback failure
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure
- usb: usbtest: disable dynamic ID support
- usb: gadget: f_tcm: keep port count until LUN teardown completes
- tls: device: fix out-of-bounds write in tls_append_frag()
- gtp: serialize PDP context updates
- [amd64] x86/CPU/AMD: Carve out a Zen5 models range
- net/tcp: fix TCP-AO key deletion in VRFs
- tcp: fix AO info use-after-free in tcp_ao_connect_init()
- net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
- xfrm: espintcp: fix UAF during close
- xfrm: drop ESP-in-TCP packets with no ingress device
- xfrm: avoid lock inversion in nat keepalive work
- xfrm: ah6: validate routing header segments_left
- xfrm: fix xfrm_state_construct() auth-trunc leak
- xfrm: bound nat keepalive state collection
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast
context
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation
- batman-adv: reject unrepresentable multicast TVLV offsets
- vxlan: keep the last remote linked during FDB flush
- netfilter: nf_tables: don't queue packet path object notifications
- mm/swap: reject swapon() on filesystem-level encrypted files
- [arm64] crypto: qcom-rng - Enable clock in hwrng case
- [arm64] crypto: qcom-rng - Allow zero as a random number
- [arm64] crypto: qcom-rng - Remove crypto_rng interface
- [arm64] crypto: qce - fix CCM AAD buffer underallocation
- [arm64] crypto: qce - Remove unsafe/deprecated algorithms
- [s390x] KVM: s390: vsie: zero stale crypto bits
- usb: core: Add lock to usb_wakeup_notification()
- usb: core: Strengthen error handling in hub_hub_status()
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
- ALSA: usb-audio: Complete cleanup after system-resume errors
- USB: serial: option: fix slab OOB read in interrupt URB callback
- USB: serial: spcp8x5: drop broken carrier detect support
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
- wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
- usb: usbfs: fix use-after-free of usb_device in usbdev_release()
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.109
- bnxt_en: Mask the bd_cnt field in the TX BD properly (CVE-2025-22108)
- md: make rdev_addable usable for rcu mode (CVE-2025-38621)
- f2fs: fix potential deadloop in prepare_compress_overwrite()
(CVE-2025-22127)
- block: mark GFP_NOIO around sysfs ->store() (CVE-2025-21817)
- drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1
(CVE-2025-38205)
- [amd64] perf/x86/intel/uncore: Fix die ID init and look up bugs
(CVE-2026-43344)
- wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
(CVE-2026-53102)
- wifi: ath11k: fix memory leaks in beacon template setup (CVE-2026-53113)
- drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
(CVE-2026-53313)
- clocksource/drivers/timer-sun4i: Advertise a real minimum delta
- fs: fix user path of nested backing files
- [powerpc*] pseries/iommu: switch to Default DMA window during kdump
- timers/itimer: Zero-init old itimerval before copy to userspace
- apparmor: fix cred UAF caused by begin_current_label_crit_section()
- apparmor: fix out-of-bounds write when null terminating a label vec
- include/linux/list.h: mark list_add and __list_add as __always_inline
- mm/kmemleak: avoid soft lockup when scanning task stacks
- mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
- mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
- mm/zswap: fix global shrinker when memory cgroup is disabled
- mm: memcg: stop reclaim when a limit update is superseded
- mm: mempolicy: fix automatic numa balancing for shmem
- tools/compiler: match glibc 2.42 definition of __attribute_const__
- [amd64] x86/tdx: Fix off-by-one in port I/O handling
- [amd64] x86/insn-eval: Move assign_register() out of KVM as
insn_assign_reg()
- [amd64] x86/tdx: Fix zero-extension for 32-bit port I/O
- hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
- tracing/user_events: Clear copied tracing state before fork duplication
- tracing: Fix crash passing ERR_PTR to kthread_stop()
- tracing: Fix logged instance name on creation failure
- tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
- tracing: Fix use-after-free with same-name named triggers
- cdx: Fix double free when sysfs file creation fails
- device property: fix infinite loop in fwnode_for_each_child_node()
- misc: nsm: bound the device-reported response length
- [powerpc*] powermac: fix OF node refcount
- rapidio: mport_cdev: fix use-after-free in dma_req_free()
- Revert "media: v4l2-dev: fix error handling in __video_register_device()"
- serial: imx: serialize imx_uart_ports[] lifetime
- staging: greybus: hid: fix SET_REPORT return value
- usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
- usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
- USB: phy: fsl-usb: fix missing static keywords
- usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
- usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
- usb: gadget: u_audio: Fix use-after-free on sound card disconnect
- usb: gadget: snps_udc_plat: clean up PHY on probe deferral
- usb: gadget: midi2: remove default configfs groups on teardown
- usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
- usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and
uvc_function_unbind()
- usb: gadget: f_fs: Prevent deadlock during ep0 read loop
- fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
- HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
- lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
- media: cec: stm32: prevent out-of-bounds write on RX overflow
- media: vicodec: fix out-of-bounds write in FWHT encoder
- nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
- of: fix out-of-bounds read in of_alias_scan() stem parser
- ubifs: fix out-of-bounds read in signature length check
- zsmalloc: account for handle size in class lookup
- NFSD: check truncate permission under inode lock
- NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
- NFSD: Fix off-by-one in DRC bucket pruning limit
- NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
- NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
- nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
- NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
- pNFS: Fix EBUSY check in pnfs_layout_need_return
- nfsd: release path refs on follow_down() error
- nfsd: Reset write verifier when async COPY writeback fails
- nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
- nfsd: sample writeback error cursor before async COPY loop
- nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
- nfsd: size fh_verify server sockaddr slot by xpt_locallen
- nfsd: validate symlink target length in NFSv4 CREATE
- nfsd: add fh_want_write() for early-verified SETATTR in
nfsd_proc_setattr()
- nfsd: add filehandle match check to nfsd4_delegreturn()
- nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
- nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
- nfsd: check client ownership when cancelling a copy-notify stateid
- nfsd: clear opcnt on compound arg release to prevent OOB read
- nfsd: defer vfree of compound ops to fix rpc_status UAF
- nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
- nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
- nfsd: fix cpntf publish race in nfs4_init_cp_state
- nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
- nfsd: fix nfsd_file leak on inter-server COPY setup failure
- nfsd: fix reply size estimate for GET_DIR_DELEGATION
- nfsd: fix version mismatch loops in nfsd_acl_init_request()
- nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
- nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
- nfsd: gate nfs2 setacl by argp->mask
- nfsd: gate nfs3 setacl by argp->mask
- nfsd: initialize copy-notify stateid before publishing it
- nfsd: initialize DRC hash table before registering shrinker
- nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
- nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
- nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
- nfsd: revoke copy-notify stateids before dropping their reference
- NFSD: Prevent lock owner use-after-free during client teardown
- NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
- libceph: validate OSD extent maps before cursor advance
- libceph: reject buckets with mismatched CRUSH ids
- ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
- ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
- ceph: bound copied dentry name length in NFS export get_name
- ceph: bound MDSCapAuth path and fs_name decode in handle_session()
- ceph: bound num_export_targets array for mds info v2/v3
- ceph: bound xattr value length in __build_xattrs()
- ceph: do not repeat ceph_trim_dentries() if no progress possible
- btrfs: drop recovered reloc root refs on recovery failure
- audit: avoid dropping live tree ref on fsnotify rule autoremove
- cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
- smb: client: clear ce->tgthint in free_tgts()
- smb: client: fix ALIGN() overflow in symlink_data() error context loop
- smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
- smb: client: harden DFS cache against invalid target hints
- HID: picolcd: clamp eeprom debugfs read to bytes actually received
- HID: roccat: free buffered reports when destroying device
- HID: sensor: custom: Fix field sysfs group cleanup on failure
- HID: mcp2221: stop device IO before hid_hw_stop
- HID: mcp2221: validate report size in mcp2221_raw_event()
- eventfs: Initialize ei->children and ei->list in init_ei()
- fs/ntfs3: validate dirty page table on log replay
- fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
- fs/ntfs3: bound page_lcns[] index by the log record
- eCryptfs: bound the packet-length peek to the user buffer
- ecryptfs: fix tag 11 packet exact-fit size check
- ecryptfs: hold msg ctx list lock when cleaning daemon queue
- ecryptfs: pass packet set buffer size to parser
- ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
- ecryptfs: reject too-small tag 70 packets
- ecryptfs: release message context on send failure
- ecryptfs: show filename encryption options
- efivarfs: Rate limit statfs() handler
- fat: restore original value when fat_ent_write failed
- fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
- fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
- fbdev: ssd1307fb: defer I2C transfers from damage callbacks
- fbdev: uvesafb: unregister connector callback on init failure
- forcedeth: fix off-by-one when saving/restoring non-PCI config space
- fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
- [armhf] hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller
device
- ACPI: APEI: Fix ERST timeout unit conversion
- ACPI: APEI: GHES: fix ARM section length accounting after header
- ACPI: pfr_update: fix stack buffer overflow in query_capability()
- alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
- ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
- auxdisplay: charlcd: cancel backlight work on registration failure
- block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
- Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
- Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
- Bluetooth: eir: Fix OOB read in eir_get_service_data()
- bnx2x: fix double free in bnx2x_init_firmware() error path
- bpf, x86: Fix per-CPU address resolution into an extended register
- bpf: Disable preemption in __bpf_get_stack
- bpf: Harden bloom filter sizing and indexing on 32-bit kernels
- dm-era: fix shadowed superblock leak on take-snap failure
- dm raid1: reserve space for NUL-terminator in build_constructor_string()
- dm array: validate array block headers on read
- dm array: reject an array block whose value size is not the caller's
- coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
- cpufreq: schedutil: Fix rate limit overflow
- cxl/pmem: Format the nvdimm serial number as unsigned decimal
- Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
- Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
- Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
- Bluetooth: RFCOMM: serialize security confirmation handling
- Bluetooth: hci_conn: re-enable advertising only for peripheral role
- Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
- Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
- Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
- Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
- jbd2: bound shrinker scans by examined checkpoint buffers
- jbd2: check need_resched() when skipping busy checkpoint buffers
- ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
- ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
- ip6_gre: fix hardware header length for NBMA tunnels
- ipv6: use RCU iterator to dump route exceptions
- libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
- [arm64] mailbox: qcom-ipcc: fix duplicate channel allocation across holes
- md/raid10: fix still_degraded being inverted in raid10_sync_request()
- md: do overflow check for sb->bblog_shift in super_1_load()
- mpls: reload header after pskb_may_pull()
- mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
- nouveau/gem: reserve the bo in the info ioctl around the vma lookup
- params: fix charp corruption on allocation failure
- SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
- SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
- SUNRPC: svcauth_gss: enforce krb5 token minimum length
- sunrpc: route to a populated pool in svc_pool_for_cpu()
- SUNRPC: always drain cache_cleaner before destroying a cache_detail
- SUNRPC: Check svc pool percpu counter allocation
- SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
- SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
- SUNRPC: harden gss_unwrap_resp_priv length checks
- sunrpc: init gssp_lock before publishing proc entry
- SUNRPC: reject duplicate CREDS_VALUE options
- SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
- SUNRPC: wait for in-flight client TLS handshake callback
- svcrdma: Fix offset arithmetic in read_chunk_range
- svcrdma: Fix pcl_for_each_segment for empty chunks
- svcrdma: Fix unmatched rn_unregister on failed accept
- svcrdma: Reject connection when transport allocation fails
- svcrdma: Reject inline replies that overflow the pull-up buffer
- svcrdma: Validate Read chunk positions before reconstruction
- udf: reject VAT indexes equal to the entry count
- wifi: ath6kl: clamp assoc request/response lengths before subtracting IE
offsets
- scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
- rpmsg: glink: smem: order FIFO read after availability check
- [arm64] dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
- [arm64] dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
- [arm64] dts: rockchip: Fix rk3399-roc-pc-plus analog audio
- [riscv64] acpi: Handle LPI architectural context loss flags
- remoteproc: scp: Fix device reference leak on failed lookup
- qede: Fix NULL pointer dereference in TPA fragment processing
- RDMA/cxgb4: Cancel reg_work before freeing device on remove
- RDMA/ucma: Lock the handler in ucma_set_ib_path()
- regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving
dangling of_node pointer
- regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after
ownership transferred to rdata
- regulator: qcom-refgen: correct the regulator type to CURRENT
- ring-buffer: Free cpu_buffer::free_page with subbuf_order
- ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
- orangefs: fix double-free of trailer_buf on readdir copy failure
- orangefs: skip leading spaces before parsing client debug masks
- ocfs2: always run deallocs on copy-on-write completion
- ocfs2: bound namelen in dlm_migrate_request_handler
- ocfs2: validate lengths in dlm_mig_lockres_handler
- ocfs2: validate rl_used against rl_count in refcount block validator
- ocfs2: cluster: don't sleep while holding o2hb_live_lock in
o2hb_region_pin()
- ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from
drop_item
- ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
- ocfs2: fix readdir position truncation on 32-bit kernels
- openvswitch: only skb_tx_error() a packet we are about to drop
- ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
- [arm64] compat: Fix decrementing LDM/STM alignment emulation
- [amd64] ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
- hwmon: (max6621) fix negative temperature offset and crit readings
- hwmon: (max6621) fix temperature clamp range
- lockd: pin next file across nlm_inspect_file lock-drop
- lockd: fix NULL dereference on lockowner allocation failure
- nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error
path
- nvme: zero the discard fallback page
- nvme-pci: disable controller on admin queue IRQ setup failure
- nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
- nvme-tcp: fix host memory disclosure on R2T for a read command
- nvme-tcp: reject a read that transferred too few bytes
- sctp: stop processing a packet once its association is deleted
- sctp: drop a chunk if its transport was removed
- sctp: fix NULL deref on untransmitted RECONF completion
- sctp: distinguish sequence zero from wildcard in reconf lookup
- sctp: fix stream->outcnt underflow on duplicate RECONF responses
- power: supply: bq24257: fix use-after-free on remove
- power: supply: bq256xx: drain usb_work before freeing the charger
- power: supply: bq25890: Fix power_supply reference leak
- power: supply: charger-manager: register regulators before exposing sysfs
- power: supply: cros_usbpd-charger: bound the EC-reported port count
- power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
- power: supply: lp8727: fix use-after-free in lp8727_release_irq()
- power: supply: lp8788-charger: fix use-after-free on remove
- power: supply: qcom_battmgr: terminate the strings from firmware
- power: supply: rt9455: quiesce delayed work before teardown
- power: supply: twl4030_charger: cancel workers via devm
- power: supply: ucs1002: fix use-after-free on remove
- power: supply: max17040: propagate register read errors
- power: supply: max17040: drop incorrect I2C functionality check
- power: supply: max17040: synchronize work cancellation on suspend
- [s390x] cpum_cf: Handle CPU hotplug via prepare/dead callbacks
- [s390x] dasd: Do not complete a failed ESE read as successful
- [s390x] dasd: Guard sysfs discipline callbacks against unallocated private
data
- [s390x] dasd: Propagate partial completion length across ERP recovery
- PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
- PCI: meson: Fix GPIO state while requesting PERST#
- PCI: plda: Fix use-after-free of event IRQs during teardown
- PCI: plda: Fix IRQ domain leaks in the error paths of
plda_init_interrupts()
- PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
- PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
- PCI/MSI: Enable memory decoding before restoring MSI-X messages
- PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
- PCI/proc: Use file_ns_capable() when checking config space read access
- PCI/proc: Warn on writes to kernel-exclusive config space regions
- [amd64] iommu/amd: Put PCI device after handling PPR faults
- [amd64] iommu/sva: Set handle->dev before the SVA handle is visible
- [arm64] iommu/arm-smmu-v3: Manage teardown with devm
- [amd64] iommu/vt-d: Fix no_iommu to disable platform opt-in
- [amd64] iommu/vt-d: Force requesting ACS when tboot is enabled
- [amd64] platform/x86: dell-wmi-sysman: Don't hex dump attribute security
buffer
- [amd64] platform/x86: ISST: Validate level in perf mask ioctls
- [amd64] platform/x86: ISST: Validate socket ID in clos_assoc ioctl
- mmc: via-sdmmc: stop card-detect handling on probe failure
- [amd64] platform/x86: ISST: Add a NULL check for sst_inst[]
- [adm64] platform/x86: ISST: Just allow 2 bits for SST feature enable
- [amd64] platform/x86: ISST: Use PP level enable mask
- [amd64] platform/x86: ISST: Validate logical CPU id and clos id
- [amd64] platform/x86: ISST: Validate parameter for core power state
- [amd64] platform/x86: ISST: Validate parameter for frequency and priority
- [amd64] platform/x86: ISST: Return error during profile addition
- [amd64] platform/x86: ishtp_eclite: Fix ACPI device reference leak in
probe error path
- [amd64,arm64] platform/chrome: sensorhub: Bound the EC-reported sensor
number
- [amd64] platform/x86: hp-bioscfg: accept reduced ACPI packages from older
HP BIOS
- [amd64] platform/x86: hp-bioscfg: advance elem past consumed array
elements
- [amd64] platform/x86: hp-bioscfg: bound ordered-list parsing by the
package count
- [amd64] platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and
kek_store()
- [amd64] platform/x86: hp-bioscfg: fix heap OOB read on empty password
write
- [amd64] platform/x86: hp-bioscfg: fix new_password_store() overwriting
current_password
- [amd64] platform/x86: hp-bioscfg: fix off-by-one write in
hp_get_string_from_buffer()
- [amd64] platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
- [amd64] platform/x86: hp-bioscfg: pass validated element count to package
parsers
- [amd64] platform/x86: hp-bioscfg: warn on element type mismatch instead of
failing
- interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
- ipmi: ipmb: validate write message length
- ipmi: si: Fix NULL pointer dereference after failed registration
- net/iucv: filter frames in afiucv_hs_rcv() by ingress device
- xdp: fix zero-copy frame layout
- slip: fix use-after-free in sl_sync()
- net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
- net: tun: bound receive headroom
- net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
- net: ipa: fix stalled modem TX queue after runtime resume
- net: l2tp: do not propagate multicast notification errors
- net: openvswitch: fix flow mask use-after-free on flow deletion
- net: openvswitch: fix nf_connlabels leak in ovs_ct_init
- net: ravb: avoid dereferencing an invalid PTP clock
- net: ravb: serialize PTP clock teardown
- [amd64] net: thunderbolt: Release the Rx HopID that was handed out on
mismatch
- [amd64] net: thunderbolt: Mark the connection down when bringing it up
fails
- NTB: ntb_transport: Recycle TX entries before client callbacks
- NTB: ntb_transport: Fail TX enqueue when the QP link is down
- NTB: ntb_transport: Reject oversized TX buffers
- net: ntb_netdev: Avoid double-accounting netif_rx() drops
- net: ntb_netdev: Count packets dropped on RX refill failure
- net/smc: do not dereference an unset send buffer on the SMC-D teardown
path
- net/smc: fix socket refcount leak in smc_switch_conns()
- net/smc: fix use-after-free in smc_rx_pipe_buf_release()
- net/smc: unregister the connection before draining the rx tasklet
- net: cap advertised IP tunnel headroom
- net: fix spurious TX timeout after dev_activate()
- net: skbuff: don't touch shared zerocopy state in skb_tx_error()
- seg6: reset IP6CB after IPv6 decapsulation
- mfd: sm501: Fix potential memory leaks during remove
- ALSA: 6fire: bound the MIDI event length from the device
- ALSA: aloop: Check card index validity at probe
- ALSA: bcd2000: clear the URB pointers on disconnect
- ALSA: mpu401: Check card index validity at probe
- ALSA: mts64: Check card index validity at probe
- ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
- ALSA: portman2x4: Check card index validity at probe
- ALSA: serial-u16550: Check card index validity at probe
- ALSA: virmidi: Check card index validity at probe
- ring-buffer: Fix subbuf resize race with ring buffer readers
- [amd64] iommu/amd: remove return value of amd_iommu_detect
- PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
- arch_numa: avoid false positive fortify warning in
setup_node_to_cpumask_map()
- dm-stats: fix a crash if allocation of per-cpu data fails
- dm-switch: use WRITE_ONCE() in switch_region_table_write()
- i3c: master: Fix info leak and UAF in device unregister path
- i3c: master: svc: bound IBI payload to the requested max_payload_len
- wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
- wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
- [arm64] crypto: sun8i-ce - Remove crypto_rng interface (CVE-2026-80834)
- wifi: mwifiex: Detach sync cmd buffer on interrupted wait
- wifi: rtl818x: initialize eeprom_93cx6 struct to zero
- wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
- wifi: rtlwifi: rtl8192du: Fix possible memory leak in
rtl92du_init_sw_vars()
- wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
- wifi: rtw88: pci: fix resource leak on failed NAPI setup
- wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
- vsock/virtio: flush works in dependency order
- w1: ds28e17: reject an oversize length on an I2C block read
- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
- signal: avoid shared siginfo namespace rewrites
- smack: fix cred UAF in smack_file_send_sigiotask()
- taskstats: fix cpumask parsing cutting off the last character
- timer: Keep debugobjects state consistent in migrate_timer_list()
- udf: Fix i_lenExtents truncation on 32-bit kernels
- [amd64,arm64] platform/chrome: sensorhub: Fix dropped timestamp events and
log spam
- mm: avoid unnecessary use of is_swap_pmd()
- mm/rmap: use huge_ptep_get() in try_to_unmap_one()
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.110
- net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
(CVE-2026-90049)
- net: openvswitch: fix kernel-doc warnings in internal headers
- openvswitch: Fix CT limit teardown use-after-free (CVE-2026-89488)
- landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
(CVE-2026-89560)
- xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
(CVE-2026-53250)
- netfs: Fix netfs_read_folio() to wait on writeback (CVE-2026-64058)
- mm/page_vma_mapped: use huge_ptep_get() for hugetlb
- wifi: mt76: mt7996: validate default EEPROM firmware size (CVE-2026-80933)
- hugetlb: only adjust reservation during unmapping if mapcount is 0
(CVE-2026-89593)
- fsnotify: Fix stale object mask after concurrent mark updates
(CVE-2026-89595)
- tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
- entry: Fix seccomp bypass after ptrace with TSYNC (CVE-2026-89603)
- fsnotify: inotify: pass mark connector to fsnotify_recalc_mask()
- net: ntb_netdev: Fix TX busy and drop handling
- drm/amd/display: fix division by zero in get_estimated_bw()
(CVE-2026-90035)
- usb: image: mdc800: change kmalloc() to kzalloc() (CVE-2026-90034)
- ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
(CVE-2026-90033)
- clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
- media: usbtv: keep device alive while ALSA card exists (CVE-2026-90032)
- usb-storage: ene_ub6250: fix race between scan work and probe
(CVE-2026-90031)
- usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
- usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
(CVE-2026-90027)
- usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails
- usb: typec: qcom-pmic: cancel reset_work on stop (CVE-2026-90026)
- usb: typec: ucsi: displayport: Fix OOB altmode array index
(CVE-2026-90025)
- usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
(CVE-2026-90024)
- usb: gadget: f_midi2: fix use-after-free in string attribute show path
(CVE-2026-90022)
- usb: gadget: f_midi: initialize work in f_midi_alloc() (CVE-2026-90021)
- USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
(CVE-2026-90020)
- usb: gadget: fix null pointer dereference in usb_put_function_instance()
(CVE-2026-90019)
- staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
(CVE-2026-90018)
- staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
(CVE-2026-90017)
- thermal/drivers/imx: Disable clock on runtime resume failure
- thermal/drivers/qoriq: Disable clock on resume failure
- ublk: clear VM_MAYWRITE on read-only ublk char device mmap
(CVE-2026-89793)
- spi: bcm63xx-hsspi: disable clocks on resume failure
- spi: bcm63xx: disable clock on resume failure
- spi: bcmbca-hsspi: disable clocks on resume failure
- spi: Fix DMA mapping ownership on partial map failure (CVE-2026-90012)
- scsi: target: iscsi: Reserve a terminator byte for the login payload
(CVE-2026-90011)
- scsi: pm8001: Use rollback index when freeing MSI-X vectors
(CVE-2026-90007)
- mm/damon/sysfs-schemes: kobject_del() scheme dirs
- mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
- mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
- mm/damon/sysfs-schemes: kobject_del() scheme region dirs
- mm/damon/sysfs: kobject_del() region and target (error) dirs
- mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
- mm/damon/core-kunit: check region count before testing in split_at()
- futex: Prevent rcuwait use-after-free during requeue PI (CVE-2026-90003)
- ftrace: Synchronize the initialization of ftrace_ops
- HID: bpf: serialize device reference release in struct_ops destroy path
(CVE-2026-90001)
- HID: rmi: fix OOB access with undersized RMI reports (CVE-2026-90000)
- HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
(CVE-2026-89999)
- dm: fix race when loading and unloading a table (CVE-2026-89998)
- dm: fix resume-vs-remove race (CVE-2026-89997)
- dma-direct: return struct page from dma_direct_alloc_from_pool()
(CVE-2026-89995)
- dmaengine: fsl-edma: tracing: no ptr dereference during log output
(CVE-2026-89994)
- dmaengine: dw-edma: Fix HDMA channel status register access
- dmaengine: dw-edma: Complete descriptors before pausing
- dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
(CVE-2026-89993)
- cpuidle: dt_idle_genpd: kfree() the original name allocation
(CVE-2026-89992)
- block: flag zoned disks with GENHD_FL_NO_PART
- ceph: lock mutex in ceph_mds_check_access() (CVE-2026-89990)
- ata: ahci: work around lost interrupts on Marvell 88SE61xx
- ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
(CVE-2026-89989)
- irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
- kprobes: Protect kprobe_blacklist with RCU (CVE-2026-89988)
- mm/mempolicy: fix sleeping allocation in
alloc_pages_bulk_weighted_interleave() (CVE-2026-89986)
- tcp: clear sock_ops cb flags before force-closing a child socket
(CVE-2026-74268)
- Input: aiptek - validate raw macro indices before updating state
- memcg: make the v1 soft limit knob inert
- rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
- rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
- [amd64] perf/x86/intel: Fix kernel address leakages in LBR stack
(CVE-2026-89984)
- perf trace: Factor out BPF loop body
- perf trace: Refactor augmented_raw_syscalls using bpf_for
- i2c: core: fix debugfs UAF on adapter removal (CVE-2026-89983)
- i2c: mux: Fix channel node leak on adapter add failure (CVE-2026-89982)
- [arm64] mm: Fix the lockless page-table walk in show_pte()
- ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
- ALSA: harmony: initialize locks before requesting IRQ (CVE-2026-89980)
- ALSA: pcm: Fix race between non-atomic ops and trigger-start
(CVE-2026-89979)
- nvme-fabrics: fix DHCHAP secret leak on parse failure (CVE-2026-89975)
- nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
(CVE-2026-89974)
- nvme-tcp: check the data direction of a C2HData PDU (CVE-2026-89973)
- nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
(CVE-2026-89969)
- nvmet-tcp: reject unsolicited H2CData PDUs (CVE-2026-89968)
- Revert "irqchip/mbigen: Fix mbigen node address layout"
- mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
- nvdimm/btt: reject an arena whose nfree is below the lane count
(CVE-2026-89965)
- [powerpc] kexec_file: Fix null-ptr-def in extra size calculation
(CVE-2026-89963)
- [powerpc] kexec_file: Prevent kexec range truncation (CVE-2026-89962)
- [powerpc] mm: fix wrong addr_pfn tracking in compound vmemmap population
(CVE-2026-89961)
- [powerpc] pseries: Handle and log pseries-wdt registration failures
- [powerpc] pseries: Move H_WATCHDOG definitions to a common header
- [powerpc] crash: stop watchdogs before booting kdump kernel
- [s390x] vfio-ap: fix stale pqap_hook pointer on error in
vfio_ap_mdev_set_kvm() (CVE-2026-89960)
- [s390x] vfio-ap: Fix stale do_remove flag across iterations in
vfio_ap_mdev_cfg_remove
- [s390x] vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
(CVE-2026-89959)
- [s390x] vfio-ap: Fix dereference matrix_mdev->kvm without checking for
NULL (CVE-2026-89958)
- [s390x] vfio-ap: Fix hot-unplug skipped when last AP adapter or domain
removed (CVE-2026-89957)
- [s390x] vfio-ap: Fix NULL deref in status_show() during queue probe
(CVE-2026-89955)
- [s390x] vfio-ap: fix potential use of uninitialized apm_filtered bitmap
- [s390x] vfio-ap: Fix required lock not held during update of
ap_matrix_mdev object
- mtd: afs: validate v2 image info bounds (CVE-2026-89954)
- mtd: mtdoops: free page bitmap when the backing MTD is removed
(CVE-2026-89953)
- mtd: rawnand: validate ONFI extended parameter page sections
(CVE-2026-89952)
- batman-adv: fix stale receive device on merged fragments (CVE-2026-89951)
- batman-adv: mcast: ensure unshared skb for multicast packets
- batman-adv: mcast: linearize skbuff for packet generation (CVE-2026-89950)
- batman-adv: dat: avoid unaligned fault in IP extraction (CVE-2026-89949)
- batman-adv: bla: fix freeing of claims on meshif deletion (CVE-2026-89948)
- batman-adv: bla: prevent CRC corruptions after claim flush
- clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src
- clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
- clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
- clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
- clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
- i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
- ASoC: cs35l33: drain threaded IRQ before runtime suspend (CVE-2026-89946)
- ASoC: cs35l34: drain threaded IRQ before runtime suspend (CVE-2026-89945)
- ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
- ASoC: hdac_hda: Fix hlink refcount leak on component registration failure
(CVE-2026-89944)
- AsoC: intel: sst: fix PCI device reference leak on probe failure
- ASoC: loongson: Fix error handling in ACPI property parsing
(CVE-2026-89943)
- ASoC: samsung: aries_audio_probe: double of_node_put due to direct
assignment without of_node_get
- iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig
- iio: adc: pac1921: fix wrong channel used in trigger handler read
- iio: buffer: Fix potential use-after-free in anonymous buffer release
(CVE-2026-89942)
- iio: buffer: Make IIO DMA fence release RCU-safe (CVE-2026-89941)
- iio: buffer: Tie IIO dma fence lock lifetime to the fence (CVE-2026-89940)
- iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
(CVE-2026-89939)
- iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove
UAF (CVE-2026-89938)
- iio: chemical: sgp30: Handle IAQ thread creation failure (CVE-2026-89937)
- iio: dac: m62332: Fix regulator reference count imbalance (CVE-2026-89936)
- iio: gyro: mpu3050: fix sign of raw angular velocity readings
- iio: light: cm32181: return zero after writing calibscale
- iio: light: gp2ap002: Disable regulators on resume failure
- iio: light: ltrf216a: fix runtime PM reference leak in error path
(CVE-2026-89934)
- iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
(CVE-2026-89933)
- iio: pressure: mpl115: Fix runtime PM cleanup
- iio: srf04: fix pm_runtime handling on probe error path
- iio: temperature: hid-sensor-temperature: switch to non-devm
iio_device_register()
- iio: light: opt4001: Fix power down clearing bits of the wrong register
- iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem()
- iio: light: opt4001: Reject integration times with a non-zero seconds part
- iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask
- [amd64] KVM: nVMX: Always flush vpid02 on first use (CVE-2026-89932)
- [amd64] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02
- [amd64] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on
VM-Exit (CVE-2026-89931)
- [amd64] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
(CVE-2026-89930)
- [amd64] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
(CVE-2026-89929)
- [amd64] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into
kvm_arch_flush_shadow_memslot()
- [amd64] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
(CVE-2026-89927)
- [amd64] KVM: x86: Serialize writes to disabled_quirks using kvm->lock
- [amd64] KVM: x86: Ensure runtime reads of disabled_quirks are resolved
once
- [s390x] KVM: s390: Fix length check __import_wp_info() (CVE-2026-89926)
- [s390x] KVM: s390: Fix memory leak in guest debug handling
(CVE-2026-89925)
- [s390x] KVM: s390: Fix old_data leak in guest debug error path
(CVE-2026-89924)
- [s390x] KVM: s390: Free guest debug data on vcpu destroy (CVE-2026-89923)
- [s390x] KVM: s390: Take srcu when importing watchpoint data
(CVE-2026-89922)
- [s390x] KVM: s390: Zero initialize irq in reinject_machine_check
- [s390x ]KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
- [s390x] KVM: s390: Restore sigset on error path
- media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL
deref (CVE-2026-89901)
- media: amphion: Remove obsolete frame_count check in venc_start_session
- media: cec: core: Fix kmemleak due to missed rc_free_device() call
(CVE-2026-89900)
- media: cec: disable delayed work before freeing an interrupted transmit
(CVE-2026-89899)
- media: cec: extron-da-hd-4k-plus: add sanity check (CVE-2026-89898)
- media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs
clash
- media: cec: Serialize exclusive follower delivery (CVE-2026-89897)
- media: cedrus: fix memory leak in cedrus_init_ctrls() (CVE-2026-89896)
- media: cobalt: Avoid freeing ALSA private data twice (CVE-2026-89895)
- media: cx231xx: reject geometry changes while the VBI queue is busy
(CVE-2026-89894)
- media: cx23885: cancel NetUP CI work before teardown (CVE-2026-89893)
- media: em28xx: defer audio-only extension registration (CVE-2026-89892)
- media: em28xx: fix use-after-free of dev_next->devlist on disconnect
(CVE-2026-89891)
- media: go7007: defer the ALSA v4l2 put until card release (CVE-2026-89890)
- media: i2c: alvium: Fix: Correct name of register in
alvium_set_ctrl_auto_exposure
- media: i2c: imx415: Return test pattern write errors
- media: i2c: ov02a10: fix endpoint parsing use-after-free (CVE-2026-89888)
- media: i2c: ov7740: fix use-after-destroy in remove (CVE-2026-89887)
- media: intel/ipu6: fix async notifier cleanup leak on parse error
(CVE-2026-89886)
- media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
- media: platform: mtk-mdp3: Fix SCP device refcounting (CVE-2026-89885)
- media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
(CVE-2026-89884)
- media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing
- media: nxp: imx8-isi: Correct color map between V4L2 and ISI
- media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks
- media: rc: sunxi-cir: Unregister rc device on probe failure
(CVE-2026-89883)
- media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA
leak (CVE-2026-89881)
- media: rtl2832_sdr: release URBs and stream buffers on start_streaming()
failure (CVE-2026-89880)
- media: s2255: bound JPEG frame size before copying into the buffer
(CVE-2026-89879)
- media: s2255: check firmware size before reading trailing marker
(CVE-2026-89878)
- media: saa7164: fix cleanup on resource allocation failure
(CVE-2026-89877)
- media: tda18250: fix possible integer overflow (CVE-2026-89876)
- media: v4l2-async: avoid deleting unlinked ASC entry on link error
(CVE-2026-89874)
- media: v4l2-ctrls: Allow unknown HDR10 white point and luminance
- media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
(CVE-2026-89872)
- media: venus: fix payload size returned by parse_caps() and
parse_alloc_mode()
- media: venus: fix payload size calculation in parse_raw_formats()
- media: video-i2c: fix kthread error pointer left in kthread_vid_cap on
failure (CVE-2026-89871)
- media: vimc: fix pixel format lookup in enum_framesizes
- media: zoran: Avoid freeing a registered video_device twice
(CVE-2026-89870)
- media: chips-media: wave5: Guard bit depth check with
initial_info_obtained
- scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
(CVE-2026-89865)
- scsi: qla2xxx: Bound i2c->length in I2C bsg handlers (CVE-2026-89864)
- scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
(CVE-2026-89863)
- scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters
- scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
(CVE-2026-89861)
- scsi: qla2xxx: Initialize NVMe abort_work once at submission
(CVE-2026-89860)
- scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()
- scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
(CVE-2026-89858)
- scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
(CVE-2026-89857)
- scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
(CVE-2026-89856)
- scsi: qla2xxx: Serialize flash version read in reset handler
(CVE-2026-89855)
- scsi: qla2xxx: Fix cs84xx use-after-free on host teardown (CVE-2026-89854)
- scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
(CVE-2026-89853)
- scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
(CVE-2026-89852)
- scsi: qla2xxx: Fix FCE trace enable parsing in debugfs (CVE-2026-89851)
- scsi: qla2xxx: Don't query firmware state while chip is down
(CVE-2026-89850)
- scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
(CVE-2026-89849)
- scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()
- scsi: qla2xxx: Quiesce response IRQ before freeing request queue
(CVE-2026-89848)
- scsi: qla2xxx: Avoid double completion in async IOCB timeout
(CVE-2026-89847)
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
(CVE-2026-89846)
- scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
(CVE-2026-89845)
- scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort
- scsi: qla2xxx: Drop vport reference under lock in report ID acquisition
- scsi: qla2xxx: Hold vport_slock for host map update in report ID
acquisition (CVE-2026-89844)
- scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics
- scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
(CVE-2026-89843)
- scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
(CVE-2026-89842)
- f2fs: return symlink writeback errors
- f2fs: reject overlapping move range after len expansion
- f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
(CVE-2026-89839)
- f2fs: return writeback error from collapse range
- f2fs: avoid NULL checkpoint thread access in sysfs (CVE-2026-89835)
- f2fs: fix to migrate all curseg types during free_segment_range
(CVE-2026-89834)
- f2fs: fix i_size when pinned fallocate partially fails
- f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()
- f2fs: fix valid block count leak on data block allocation failure
(CVE-2026-89830)
- f2fs: fix to zero post-EOF data when extending file size
- drm/panthor: fix firmware control interface bounds checks (CVE-2026-89825)
- drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure
- drm/panel-edp: fix i2c adapter leak on probe failure (CVE-2026-89824)
- drm: fix race between partial drm_dev_register() failure and ioctl
(CVE-2026-89823)
- [amd64] drm/i915: Guard against NULL driver_data in i915_pci_probe()
(CVE-2026-89822)
- drm/ssd130x: fix column and row end address in partial updates for ssd132x
- drm/sun4i: fix refcount leak in sun4i_backend_init_sat()
- drm/ssd130x: fix column and row end address in partial updates in ssd133x
- drm/hibmc: Fix list of formats on the primary plane
- drm/hibmc: Use drm_atomic_helper_check_plane_state()
- drm/amd/display: avoid divide-by-zero in __is_lut_linear()
(CVE-2026-89821)
- drm/amd/display: validate plane degamma LUT size for private color prop
(CVE-2026-89819)
- drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
(CVE-2026-89818)
- drm/gud: NUL-terminate TV mode names read from the device (CVE-2026-89817)
- drm/gud: validate TV mode names before creating enum property
- drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value
- drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
(CVE-2026-89816)
- drm/amdgpu: check thunderbolt before switcheroo registration
- drm/amdgpu: fix autosuspend cleanup during removal
- drm/amdgpu: Skip accessing psp rum time db for APUs
- drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT
- drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
(CVE-2026-89807)
- drm/amdkfd: Reject zero-sized AQL queue allocations after size halving
- drm/nouveau: unsubscribe the channel-kill event before the fence context
(CVE-2026-89803)
- drm/nouveau: Use write-combined maps for coherent
- drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
(CVE-2026-89802)
- drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
(CVE-2026-89801)
- drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
(CVE-2026-89800)
- afs: Fix leak of ungot volume (CVE-2026-80878)
- xhci: fix lost bounce buffers on TDs spanning several ring segments
(CVE-2026-90015)
- ksmbd: zero pipe read compound padding (CVE-2026-89794)
- net/mlx5e: xsk: Fix unlocked writing to ICOSQ (CVE-2026-64210)
- nvmet-auth: Synchronize timeout work during SQ teardown (CVE-2026-89970)
- mm/damon/vaddr: drop last same folio access check optimization
- mm/damon/ops-common: use nr_accesses moving sum for quota score
- mm/damon/paddr: drop last same folio access check reuse optimization
- mm/damon/vaddr-kunit: check region count in three_regions test
- mm/damon/core-kunit: handle region split failure in filter_out()
- mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()
- of: unittest: Fix memory leak in unittest_data_add() (CVE-2026-23137)
- ksmbd: fix use-after-free in smb2_open during durable reconnect
(CVE-2026-53010)
- ksmbd: fix durable reconnect error path file lifetime
- ksmbd: fix FSCTL permission bypass by adding a permission check for
FSCTL_SET_SPARSE (CVE-2026-52944)
- batman-adv: dat: atomically update mac addresses (CVE-2026-93204)
- batman-adv: bla: avoid CRC corruption due to parallel claim add
(CVE-2026-93203)
- perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
(CVE-2026-80671)
- clk: meson: align gxbb_32k_clk_sel number of parents with actual count
(CVE-2026-89947)
- batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
- mm/damon/core: skip aging from repeated aggressive merging
- Smack: Fix error in capability bypass
- drm: Remove unused header in drm_dumb_buffers.c
- drm: lcdif: Wait for vblank before disabling DMA
- drm/v3d: Replace a global spinlock with a per-queue spinlock
- drm/v3d: Clear queue->active_job when v3d_fence_create() fails
(CVE-2026-93192)
- drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format
- drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure
- smack: fix incorrect task context in smack_msg_queue_msgrcv
(CVE-2026-93191)
- smack: simplify write handlers of sysfs entries
- smack: deduplicate smackfs/{direct,mapped} file_operations
- smack: restrict smackfs/{direct,mapped} values to 0-255
- sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to
bypass charging
- [amd64] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE()
- platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
(CVE-2026-93190)
- HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
(CVE-2026-93189)
- HID: nintendo: Fix imu_timestamp_us double increment per report
- HID: roccat: bound device-supplied profile index (CVE-2026-93188)
- soc: samsung: exynos-pmu: fix of_node refcount leak in
exynos_get_pmu_regmap()
- media: cec-pin: Fix event FIFO ordering
- cxl: Refactor user ioctl command path from mds to mailbox
- cxl/mbox: Clamp mailbox output allocation to the payload size
(CVE-2026-93186)
- cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox()
- clk: versaclock7: Fix APLL clock leak on probe failure
- clk: moxart: remove unused variables, fix refcount leak
- clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq
calculation
- clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional
calc
- clk: nuvoton: ma35d1-pll: convert from round_rate() to determine_rate()
- clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic
- ASoC: rt700-sdw: always drain jack work on remove (CVE-2026-93185)
- ASoC: fsl_audmix: rework runtime PM handling in probe (CVE-2026-93184)
- clk: hisilicon: reset: Use devm_kzalloc to initialize
hisi_reset_controller
- [armhf] imx: fix device_node refcount leak in imx_src_init()
- [armhf] imx: fix device_node refcount leaks in imx7_src_init()
- [arm64] dts: imx93-kontron: set memory node to 0x80000000/1GiB
- clk: imx: scu: drop redundant init.ops variable assignment
- drm/lima: call drm_mm_init() with a valid allocation range
(CVE-2026-93183)
- mm/mm_init: fix incorrect node_spanned_pages
- sched/fair: Fix overflow in update_tg_cfs_runnable() (CVE-2026-93182)
- perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails
- pinctrl: bcm2835: Don't remove an unregistered GPIO chip
- riscv: kexec_file: Split the loading of kernel and others
- [riscv64] kexec_file: Fix crashk_low_res not exclude bug
- media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define
- media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define
- perf test: Update all metrics test like metricgroups test
- regulator: tps6594-regulator: Constify struct tps6594_regulator_irq_type
- regulator: tps6594-regulator: remove interrupt_count
- regulator: tps6594-regulator: remove hardcoded buck config
- regulator: tps6594-regulator: refactor variant descriptions
- regulator: tps6594: Fix device node reference leaks in multiphase loop
- drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
(CVE-2026-93178)
- drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
(CVE-2026-93177)
- tools/bpf/bpftool: Reset vmlinux BTF after map commands
- tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands
- bpf: Copy per-CPU map value padding in copy_map_value_long()
(CVE-2026-93174)
- bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks (CVE-2026-93173)
- mm: add build-time option for hotplug memory default online type
- mm: convert memory block states (MEM_*) macros to enum
- mm: change type of state in struct memory_block
- mm: name the anonymous MMOP enum as enum mmop
- mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug
(CVE-2026-93172)
- dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation
failure
- dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and
MCDMA interrupt handlers (CVE-2026-93170)
- dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe
- soundwire: qcom: Fix port exhaustion check in stream_alloc_ports
- iio: orientation: hid-sensor-rotation: Avoid race between callback setup
and device exposure
- csky: Fix a4/a5 restoration in syscall trace path (CVE-2026-93167)
- platform/chrome: sensorhub: Fix memory overread in ring handler
(CVE-2026-93165)
- wifi: rtw89: fix HE extended capability length check
- perf cs-etm: Queue context packets for frontend
- perf cs-etm: Fix thread leaks on trace queue init failure
- [amd64] perf/x86/amd/uncore: Add group validation
- perf vendor events amd: Update Zen 5 core events
- hwrng: core - fix rng list on registration error (CVE-2026-93163)
- crypto: qat - cancel work on re-enable SR-IOV timeout (CVE-2026-93162)
- crypto: qat - clear AES key schedule from stack (CVE-2026-93161)
- crypto: atmel-ecc - replace min_t with min
- crypto: atmel-ecc - clean up and improve ECDH comments
- crypto: atmel-ecc - reject hardware ECDH without a public key
(CVE-2026-93160)
- crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
(CVE-2026-93159)
- crypto: sa2ul - stop probe if context pool creation fails (CVE-2026-93158)
- crypto: rk3288 - fail ahash requests on HASH idle timeout (CVE-2026-93156)
- crypto: keembay - Fix AEAD unregister count in error path (CVE-2026-93155)
- nvme-apple: Use acquire/release for queue enabled state (CVE-2026-93152)
- nvmet-rdma: factor out response resource cleanup
- nvmet-rdma: fix response resource leak on queue teardown (CVE-2026-93151)
- bus: ti-sysc: Fix /chosen node reference leak
- PM: sleep: Fix off-by-one in wakelocks number limit check
- cgroup/cpuset: Make nr_deadline_tasks an atomic_t (CVE-2026-93150)
- [arm64] dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name
- [arm64] dts: qcom: hamoa: Fix clocks for HSPHYs
- bus: qcom-ebi2: Simplify with scoped for each OF child loop
- bus: qcom-ebi2: Fix clock leak on probe failure
- wifi: mac80211_hwsim: avoid NULL skb in stop queue drain (CVE-2026-93149)
- staging: greybus: audio: correct sscanf() return value check
- staging: sm750fb: gate dualview dataflow using g_dualview
- staging: sm750fb: Add missing Kconfig dependency
- greybus: audio: bound the topology section sizes against the fetched size
- staging: fbtft: Use sysfs_emit_at() to print to sysfs file
- staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown
- staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown
- staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free
functions
- staging: octeon: replace pr_warn with dev_warn in fill and rx paths
- staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown
- staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
- ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer()
- irqchip/gic-v3-its: Fix memleak in its_probe_one()
- irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its()
- clocksource: Unregister subsystem on device registration failure
- y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32
- timekeeping: Account for monotonicity adjustment in ntp_error
- clk: qcom: gdsc: propagate gdsc_check_status() errors from
gdsc_poll_status
- clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains
- clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()
(CVE-2026-93145)
- [arm64] dts: qcom: sc8180x-primus: Rename regulator nodes
- [arm64] dts: qcom: sc8180x-primus: Describe the display power net
- [arm64] dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes
- [arm64] dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net
- perf data convert json: Fix trace_seq memory leak in
process_sample_event()
- thermal/drivers/rcar: Fix error checking in probe() (CVE-2026-93142)
- usb: typec: ucsi: unregister debugfs entries on teardown
- usb: gadget: r8a66597: avoid double free of ep0_req in probe error path
(CVE-2026-93141)
- udf: Mark LVID buffer as uptodate before marking it dirty (CVE-2026-93140)
- perf vendor events amd: Reintroduce deprecated Zen 5 core events
- perf dso: Fix kallsyms DSO detection with fallback logic
- bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux (CVE-2026-93138)
- efi: fix stale reference to efi_recover_from_page_fault()
- bpf: Fix use-after-free on mm_struct in bpf_find_vma() (CVE-2026-93137)
- bus: mhi: ep: Fix device refcount leak in the error path of MHI device
creation (CVE-2026-93136)
- iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX
- iommu/msm: Return -ENOMEM on memory allocation failure in probe
- [amd64] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation
errors
- [amd64] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC
- [amd64] iommu/amd: Fix false positive in SB IOAPIC IVRS validation
- leds: pca9532: Fix inverted GPIO output polarity
- printk/panic: Add option to allow non-panic CPUs to write to the ring
buffer.
- panic: introduce helper functions for panic state
- panic/printk: replace this_cpu_in_panic() with panic_on_this_cpu()
- panic/printk: replace other_cpu_in_panic() with panic_on_other_cpu()
- printk: Introduce console_flush_one_record
- printk: Fix possible console use-after-free (CVE-2026-93134)
- [riscv64] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination
- [riscv64] ACPI: RISC-V: Check acpi_get_handle() status in
riscv_acpi_add_prt_dep() (CVE-2026-93133)
- [riscv64] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling
(CVE-2026-93132)
- [amd64] platform/x86: dell-privacy: Fix race condition (CVE-2026-93131)
- [amd64] platform/x86: dell-wmi-base: Fix resource leak on module load
failure (CVE-2026-93130)
- [amd64] platform/x86: lg-laptop: Drop debug-only ACPI notify handler
- [amd64] platform/x86: lg-laptop: Convert ACPI driver to a platform one
- [amd64] platform/x86: lg-laptop: Fix LED resource handling
(CVE-2026-93128)
- remoteproc: qcom_q6v5_adsp: Fix reference leak for device node
(CVE-2026-93126)
- hwspinlock: propagate errno when registering single lock
- serial: ma35d1: Fix OF node reference leaks in console init
- serial: qcom-geni: do not advance stale DMA completions (CVE-2026-93123)
- usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths
(CVE-2026-93121)
- usb: gadget: configfs: fix out-of-bounds read of qw_sign (CVE-2026-93120)
- usb: ljca: bound bank_num in ljca_enumerate_gpio() (CVE-2026-93119)
- usb: gadget: aspeed_udc: check endpoint DMA allocation (CVE-2026-93118)
- USB: make single lock for all usb dynamic id lists
- USB: make to_usb_driver() use container_of_const()
- usb: fix UAF when probe runs concurrent to dyn ID removal (CVE-2026-93117)
- platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL
(CVE-2026-93115)
- platform/surface: acpi-notify: Check ACPI companion before use
(CVE-2026-93114)
- usb: mtu3: allow system suspend during active gadget connection
- usb: renesas_usbhs: Fix power-off ordering on unbind
- drm/panel: samsung-s6d16d0: Power off on prepare failure
- perf metricgroup: Fix metric expression copy leaks
- soc: qcom: rpmh-rsc: manage PM notifiers with devres
- bus: qcom-ebi2: use managed resources for clocks and children
- clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK (CVE-2026-93113)
- iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE
- RDMA/core: Wait for RCU callbacks before unloading ib_core
(CVE-2026-93110)
- RDMA/mlx5: Drain RCU callbacks during module teardown (CVE-2026-93109)
- RDMA/ipoib: Drain RCU callbacks during module teardown (CVE-2026-93108)
- RDMA/rxe: Avoid reprocessing the current packet after the QP enters the
error state (CVE-2026-93107)
- crypto: ccp - Fix memory leak in SEV INIT_EX path
- hwrng: ks-sa - Fix runtime PM cleanup on registration failure
- xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
(CVE-2026-89783)
- ALSA: hpi: Check transport errors during HPI6000 adapter initialization
- pmdomain: bcm: bcm2835: handle genpd provider registration errors
- misc: rtsx_usb: avoid USB I/O in runtime autosuspend
- RDMA/hfi1: Preserve unit 0 on allocation failure (CVE-2026-93103)
- RDMA/hfi1: Free RX data on late probe failure (CVE-2026-93102)
- RDMA/hfi1: Remove redundant PCI device ID validation
- RDMA/hfi1: Create workqueues before device initialization
- RDMA/hfi1: Stop flushing the global IB workqueue
- RDMA/hfi1: Initialize debugfs after probe completes
- ASoC: apple: mca: increase SERDES reset delay
- isofs: fix out-of-bounds page array access on empty zisofs block
(CVE-2026-89778)
- media: v4l2-async: Unregister sub-device if asc_list is empty
(CVE-2026-93101)
- rpmsg: glink: remove duplicate code for rpmsg device remove
- rpmsg: glink: fix deadlock in endpoint destroy during driver detach
(CVE-2026-93098)
- cxl/memdev: Fix firmware upload exact-fit handling
- cxl/mbox: Break poison list loop on an empty payload (CVE-2026-93097)
- cxl/pci: Honor -EPROBE_DEFER from component register setup
- fs/ntfs3: Add more checks in mi_enum_attr (part 2)
- fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()
(CVE-2024-52560)
- fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list
- fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
(CVE-2026-90048)
- hfsplus: validate thread record before delete key rebuild (CVE-2026-93095)
- wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate
- [amd64] x86/entry/fred: Encode frame pointer on entry
- firmware: arm_scmi: Publish channel state before callbacks
(CVE-2026-93093)
- firmware: arm_scmi: Unregister device notifier before IDR teardown
(CVE-2026-93092)
- firmware: arm_scmi: Quiesce notifications before teardown (CVE-2026-93091)
- firmware: arm_scmi: Clean up channels on setup failure (CVE-2026-93090)
- firmware: arm_scmi: Free transport channel on IDR failure (CVE-2026-93089)
- firmware: arm_scmi: Avoid IDR updates while cleaning channels
(CVE-2026-93086)
- firmware: arm_scmi: Reject out of range DT protocol IDs (CVE-2026-93085)
- firmware: arm_scmi: Use channel ID for transport teardown
- firmware: arm_scmi: Protect device request lookup with RCU
- firmware: arm_scmi: Drop handle on protocol bind failures (CVE-2026-93084)
- firmware: arm_scmi: Unwind TX receiver mailbox setup failure
(CVE-2026-93083)
- firmware: arm_scmi: Unwind P2A receiver mailbox setup failure
(CVE-2026-93082)
- libnvdimm/labels: Bound the on-media label size before the shift
- dax: read holder_ops once in dax_holder_notify_failure() (CVE-2026-93073)
- cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate()
- PCI: xgene: Drop XGENE_PCIE_IP_VER_UNKN
- PCI: xgene: Drop unnecessary OF node reference
- irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
(CVE-2026-93072)
- media: i2c: rdacm21: Fix missing media_entity_cleanup()
- media: bcm2835-unicam: Fix asc leaked in error/remove path
(CVE-2026-93071)
- media: ipu6: Do not free aux device pdata after init (CVE-2026-93070)
- drm/amd/display: Remove unused-but-set variable hubp from
- cpufreq: intel_pstate: Fix setting minimum P-state at init time
- cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply()
- remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev
- drm/bridge: tc358767: clamp the reported AUX read size to the request
(CVE-2026-93067)
- [arm64] dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO
- [arm64] dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin
- [arm64] dts: qcom: sm8250: sort out Iris power domains
- [arm64] dts: qcom: sm8250: correct frequencies in the Iris OPP table
- perf jevents: Add more components to the metric sorting order
- wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs
(CVE-2026-93065)
- wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (CVE-2026-93064)
- wifi: iwlwifi: mei: check SAP message length before reading it
(CVE-2026-93063)
- wifi: iwlwifi: guard against division by zero in
iwl_dbg_tlv_alloc_fragments (CVE-2026-93062)
- wifi: iwlwifi: mei: pass correct argument to function
- gpu: host1x: Fix offset calculation in trace_write_gather
- gpu: host1x: Avoid stack over-read in debug output helpers
(CVE-2026-93061)
- drm/msm/a6xx: Fix stale rpmh votes after suspend
- crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping
- ACPI: processor: idle: Expand _LPI package sanity checks
- usb: gadget: f_uac1_legacy: remove broken string configfs attributes
(CVE-2026-93056)
- tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64
- UDF symlink pathComponent header OOB read (CVE-2026-93055)
- uio: Fix stale info pointer in failed registration path (CVE-2026-93054)
- accessibility: speakup: Fix incorrect string length computation in
report_char_chartab_status()
- speakup: keyhelp: guard letter_offsets possible out-of-range indexing
(CVE-2026-93053)
- misc: bcm-vk: Use acquire/release for msgq_inited (CVE-2026-93052)
- misc: rtsx: add missing write register handling
- misc: ad525x_dpot: use driver core groups for sysfs files (CVE-2026-93051)
- cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64)
- ppdev: prevent overflow when setting port timeout
- ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on
remove (CVE-2026-93050)
- char: xilinx_hwicap: unregister class on init errors
- vfio/pci: clear vdev->msi_perm after freeing it on init failure
(CVE-2026-89777)
- mtd: mtdswap: Avoid freeing registered blktrans device twice
(CVE-2026-93049)
- mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
(CVE-2026-93048)
- perf ui hists: Fix uninitialized stack memory free on pstack allocation
failure
- software node: Fix software_node_get_reference_args() with index -1
(CVE-2026-93046)
- driver core: soc: Unregister bus on early device registration failure
- drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg
- bpf: Reject arena frees below the arena base (CVE-2026-93045)
- dmaengine: dw-edma: Terminate all descriptors without callbacks
(CVE-2026-93042)
- dmaengine: dw-edma: Serialize abort state updates (CVE-2026-93041)
- dmaengine: dw-edma: Serialize channel state checks (CVE-2026-93040)
- dmaengine: dw-edma: Clear stale requests on termination
- ASoC: meson: Keep link pointers valid on realloc failure (CVE-2026-93039)
- phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe
- phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe
- [arm64] dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins
- [arm64] dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for
PCIe
- RDMA/hfi1: Propagate sdma_txinit_ahg() errors (CVE-2026-93037)
- RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]
(CVE-2026-92525)
- RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
- kcsan: avoid unintended access checking in NMIs
- [arm64] dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0
- irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()
(CVE-2026-92524)
- RDMA/nldev: validate dynamic counter attribute length (CVE-2026-92523)
- ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer
- ACPI: processor: validate MADT IOAPIC entry bounds (CVE-2026-92522)
- ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root
(CVE-2026-92521)
- ext4: fix circular lock dependency in ext4_ext_migrate
- ext4: fix out-of-bounds read in ext4_read_inline_dir() (CVE-2026-89786)
- ext4: skip extra isize expansion during mount to prevent deadlock
- libbpf: Search /lib64 and /lib in resolve_full_path()
- [riscv64] bpf: Fix memory leak in bpf_jit_free (CVE-2026-92519)
- ACPI: battery: Adjust charging status validation check
- bpf: Preserve unique-field state across nested structs (CVE-2026-92515)
- RDMA/srpt: Pass the mapped task attribute to target_init_cmd()
- PCI: j721e: Fix incorrect max_lanes for J7200
- RDMA/erdma: Fix CEQ tasklet use-after-free on removal (CVE-2026-92514)
- RDMA/restrack: Fix typos in the comments
- RDMA/nldev: Fix locking when accessing mr->pd (CVE-2026-74334)
- RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations
- RDMA/core: Fix use after free in ib_query_qp() (CVE-2026-92512)
- RDMA/core: Fix potential use after free in ib_destroy_cq_user()
(CVE-2026-92511)
- RDMA/core: Fix potential use after free in ib_destroy_srq_user()
(CVE-2026-92510)
- RDMA/core: Fix potential use after free in counter_release()
(CVE-2026-92509)
- RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq()
- RDMA/core: Fix potential use after free in ib_free_cq() (CVE-2026-92508)
- RDMA/core: Fix potential use after free in ib_dealloc_pd_user()
(CVE-2026-92507)
- firmware: arm_scmi: Fix requested device removal race (CVE-2026-92506)
- [arm64] iommu/qcom: Remove sysfs device on probe failure path
- [arm64] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault()
- thermal: intel: int3400: clean up ODVP on probe failures (CVE-2026-92504)
- ext4: clear stale xarray tags on folios skipped during writeback
(CVE-2026-92502)
- ext4: drain in-flight DIO before buffered write fallback (CVE-2026-92501)
- wifi: ath6kl: avoid buffer overreads in WMI event handlers
(CVE-2026-92498)
- wifi: ath12k: Correctly copy the hint BSSID in WMI scan request
- wifi: ath11k: Correctly copy the hint BSSID in WMI scan request
- wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (CVE-2026-92497)
- wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx()
(CVE-2026-92496)
- RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap (CVE-2026-92495)
- ext4: fix buffer_head leak in ext4_init_orphan_info (CVE-2026-92494)
- ext4: check dir entry fits before reading the hash trailer in
ext4_search_dir() (CVE-2026-89787)
- cpufreq/amd-pstate: Store the boost numerator as highest perf again
- ACPI: CPPC: Add IS_OPTIONAL_CPC_REG macro to judge if a cpc_reg is
optional
- ACPI: CPPC: Optimize cppc_get_perf()
- ACPI: CPPC: Rename cppc_get_perf() to cppc_get_reg_val()
- ACPI: CPPC: Add cppc_set_reg_val()
- ACPI: CPPC: Refactor register value get and set ABIs
- ACPI: CPPC: Modify cppc_get_auto_sel_caps() to cppc_get_auto_sel()
- cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory
systems
- firmware: arm_scmi: Roll back partial protocol table registration
(CVE-2026-92491)
- firmware: arm_scmi: Unrequest devices if driver registration fails
(CVE-2026-92490)
- perf cs-etm: Flush thread stacks after decoder reset
- perf cs-etm: Avoid truncating AUX buffer sizes to int
- xfrm: Fix skb double-free in xfrm_dev_direct_output() (CVE-2026-92489)
- RDMA/erdma: Probe the erdma RoCEv2 device
- RDMA/erdma: Add GID table management interfaces
- RDMA/erdma: Add the erdma_query_pkey() interface
- RDMA/erdma: Add address handle implementation
- RDMA/erdma: Add erdma_modify_qp_rocev2() interface
- RDMA/erdma: Refactor the code of the modify_qp interface
- RDMA/erdma: Add the query_qp command to the cmdq
- RDMA/erdma: Fix incorrect response returned from query_qp
- RDMA/erdma: Support non-sleeping erdma_post_cmd_wait()
- RDMA/erdma: complete object teardown when the destroy command fails
(CVE-2026-92488)
- PM: hibernate: Fix memory leak in snapshot_write_next() error path
- leds: pca9532: Fix phantom device registration on missing hardware
- drm/tve200: add OF module alias for autoloading
- netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
- fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
(CVE-2026-89785)
- drm/panthor: return PTR_ERR() from devm_drm_dev_alloc()
- [arm64] dts: rockchip: Fix Gru WLAN sideband interrupt
- cxl/region: Fix use-after-free in find_pos_and_ways() error path
(CVE-2026-92484)
- pinctrl: mediatek: Add EINT support for multiple addresses
- pinctrl: mediatek: Fix the invalid conditions
- pinctrl: mediatek: eint: Fix invalid pointer dereference for v1 platforms
- pinctrl: mediatek: free EINT resources on unbind (CVE-2026-92481)
- tools/build: Add bpftool-skeletons feature test
- tools/build: Allow versioning of all LLVM tools defined in
Makefile.include
- power: supply: sbs-battery: Use a per-device serial number buffer
- scsi: ufs: debugfs: Reserve space for a string terminator (CVE-2026-92477)
- crypto: keembay - Initialize completion before requesting IRQ
(CVE-2026-92476)
- crypto: keembay - publish OF module alias for OCS AES/SM4
- RDMA/mlx5: Fix integer overflow of user QP buffer size (CVE-2026-90435)
- powercap: intel_rapl_tpmi: Handle PMU registration failure during probe
- isofs: release zisofs block pointer buffer head (CVE-2026-90434)
- spi: oc-tiny: switch to managed controller allocation (CVE-2026-90433)
- w1: ds2482: Fix signedness bug in ds2482_w1_triplet()
- remoteproc: core: Drop redundant initialization of 'ret' in
rproc_shutdown()
- remoteproc: Allow shutdown of crashed processors
- remoteproc: core: Attach rproc asynchronously in rproc_add() path via
schedule_work()
- remoteproc: Prevent crash handling to race with rproc_del()
(CVE-2026-90431)
- staging: rtl8723bs: use kfree_sensitive() for key material
- fs/ntfs3: reject restart table growth beyond U16_MAX entries
(CVE-2026-89782)
- iommu/tegra241-cmdqv: Use request_threaded_irq
- iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs
(CVE-2026-90428)
- iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
(CVE-2026-90426)
- RDMA/efa: Fix PBL chunk length computation
- wifi: mac80211: fix per-STA profile length in cross-link CSA parsing
- [arm64] dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix
- clk: tegra: tegra124-emc: put EMC node on register failure
- clk: palmas: Manage external-control prepare with devm
- clk/x86: pmc_atom: add kasprintf return value check
- clk: mediatek: mt8135: Fix inverted gate control for devapc_ck
- clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs
- nilfs2: fix infinite loop in nilfs_clean_segments() (CVE-2026-90420)
- nilfs2: prevent out-of-bounds read in super root block parsing
(CVE-2026-90419)
- nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
(CVE-2026-90418)
- scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between
dispatches.
- RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs
(CVE-2026-90416)
- RDMA/mlx5: Send cong param changes to the resolved port mdev
- RDMA/cxgb4: free STAG index when TPT entry write fails (CVE-2026-90415)
- IB/isert: reject PDUs declaring more data than was received
(CVE-2026-90414)
- IB/isert: reject login PDUs declaring more data than was received
(CVE-2026-90413)
- nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
(CVE-2026-90411)
- spi: davinci: switch to managed controller allocation (CVE-2026-90410)
- wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()
(CVE-2026-90407)
- PCI: starfive: Fix Runtime PM handling and teardown ordering
- PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe
- platform/chrome: cros_ec_debugfs: Clean up console log on probe failure
- platform/chrome: cros_ec_debugfs: Unregister panic notifier
(CVE-2026-90404)
- wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (CVE-2026-90403)
- bus: mhi: host: Flush the posted write after writing to
MHI_SOC_RESET_REQ_OFFSET
- bus: mhi: host: Fix controller cleanup on EDL sysfs failure
(CVE-2026-90402)
- md/raid5: protect bitmap batch counters aka seq_flush/seq_write
consistency
- md/raid5-ppl: fix use-after-free in ppl_do_flush()
- md: ensure resync is prioritized over recovery
- md: allow removing faulty rdev during resync
- md: rename recovery_cp to resync_offset
- md: add a new recovery_flag MD_RECOVERY_LAZY_RECOVER
- md/raid5: protect lockless recovery_offset accesses during reshape
- tools/nolibc/powerpc: mark ctr and xer as clobbered by system call
- md: recheck spare changes before starting sync (CVE-2026-90400)
- slab: simplify init_kmem_cache_nodes() error handling
- slab: Make slub local_(try)lock more precise for LOCKDEP
- slab: Reuse first bit for OBJEXTS_ALLOC_FAIL
- wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() (CVE-2026-90399)
- wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() (CVE-2026-90398)
- rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs
- [arm64] dts: qcom: msm8998: Don't pull-up I2C pins by default in sleep
- [arm64] dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property
- [arm64] dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes
- clk: qcom: gcc-qcm2290: don't park QUP RCGs upon registration
- [arm64] dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en
- firmware: qcom_scm: Add API to get waitqueue IRQ info
- firmware: qcom_scm: Support multiple waitq contexts
- firmware: qcom: scm: add trace events for the SMC call interface
- firmware: qcom: scm: instrument SMC call path with tracepoints
- firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is
published (CVE-2026-90397)
- firmware: qcom: scm: Fix tzmem state on probe retry
- [arm64] dts: qcom: sm8250-xiaomi-elish: correct the board ID
- [arm64] dts: qcom: sc8180x: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sdm845: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8150: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8250: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8350: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8450: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8550: Fix the PCIe iommu-map entries
- [arm64] dts: qcom: sm8650: add OPP table support to PCIe
- [arm64] dts: qcom: sm8650: Fix the PCIe iommu-map entries
- power: supply: isp1704_charger: cancel work on remove (CVE-2026-90395)
- power: supply: sc2731_charger: cancel work on remove (CVE-2026-90394)
- bpf: Fix potential UAF in bpf_netns_link_update_prog (CVE-2026-90393)
- bpf: Fix potential UAF when reading bpf link info (CVE-2026-90392)
- clk: qcom: gpucc-qcm2290: Park RCG's clk source at XO during disable
- clk: qcom: Return expected ENOMEM error on dynamic allocation failure
- md/bitmap: resume array on backlog_store() error path (CVE-2026-90390)
- md: remove unused mddev argument from export_rdev
- md: skip redundant raid_disks update when value is unchanged
- md: scope memalloc_noio to allocation critical sections (CVE-2026-90389)
- iommu/dma: Check atomic pool allocation result directly (CVE-2026-90388)
- swiotlb: Preserve allocation virtual address for dynamic pools
(CVE-2026-90387)
- i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices
(CVE-2026-90386)
- i3c: master: Fix device_register() error path
- md: merge mddev has_superblock into mddev_flags
- md: merge mddev faillast_dev into mddev_flags
- md: merge mddev serialize_policy into mddev_flags
- md/raid1: create serial pool adding rdev to array with serialize_policy=1
(CVE-2026-90385)
- locking/lockdep: Fix NULL pointer dereference in __lock_set_class()
- [powerpc*] crash: Fix possible memory leak in update_crash_elfcorehdr()
- misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe()
- misc: sgi-gru: remove interrupt-context page-table walks (CVE-2026-90383)
- fanotify: report full event length for FIONREAD
- wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length
(CVE-2026-90382)
- wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986
- wifi: mt76: add init_wiphy callback
- wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
(CVE-2026-90380)
- wifi: mt76: mt7925: fix msg len mismatch between driver and firmware
- wifi: mt76: mt792x: Fix memory leak in SDIO TX path (CVE-2026-90378)
- wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU
- wifi: mt76: fix non-AQL packet accounting for MLO stations
(CVE-2026-90375)
- wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
(CVE-2026-90374)
- wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full
reset
- wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
(CVE-2026-90373)
- wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss
(CVE-2026-90372)
- wifi: mt76: mt7996: don't report a zero TX bitrate
- wifi: mt76: mt7915: write RX header translation bit to the correct
register
- wifi: mt76: fix stranded frames in mt76_txq_schedule_pending
- wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie
- wifi: mt76: check txfree done event on the WED hw path
- wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config
(CVE-2026-90370)
- wifi: mt76: mt7915: unwind state on add_interface failure (CVE-2026-90368)
- wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
(CVE-2026-90366)
- wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields
- wifi: mt76: only consume the WO drop bit on WED v2 devices
- ACPI: processor: idle: Optimize ACPI idle driver registration
- ACPI: processor: Unregister cpufreq notifier on init failure
(CVE-2026-90364)
- perf: arm_spe: Make wakeup range check overflow safe
- drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0)
- drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (CVE-2026-90362)
- wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
(CVE-2026-90361)
- regulator: core: use system_freezable_wq for init complete work
(CVE-2026-90360)
- perf machine: Fix NULL parent dereference in fork event processing
- perf machine: Guard against NULL strlist in machines__findnew()
- perf machine: Use snprintf() for guestmount path construction
- perf machine: Check snprintf truncation in machines__findnew()
- perf machine: Don't abort guest map creation on first inaccessible dir
- perf machine: Reset errno before strtol in guest kernel map creation
- perf machine: Free scandir entries in guest kernel map creation
- perf machine: Check snprintf truncation for guest kallsyms path
- bpf, x86: Fix trampoline stack size for 128-bit arguments (CVE-2026-90358)
- wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
(CVE-2026-90357)
- wifi: mt76: mt7915: fix double hif2 init on the non-WED path
(CVE-2026-90354)
- wifi: mt76: mt7915: fix ext PHY use-after-free on register error path
(CVE-2026-90353)
- wifi: mt76: mt7915: release hif2 reference on probe IRQ failure
(CVE-2026-90352)
- wifi: mt76: mt7996: fix reg addr remap when addr is 0
- wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1
- wifi: mt76: mt7915: report RX chain signal for all RX paths
- wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band
- wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be
minimum
- wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (CVE-2026-90348)
- iommu/arm-smmu-v3: Convert to use atomic poll timeout
- perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register
- wifi: mac80211: send TWT teardown to peer after setup TX failure
- wifi: zd1211rw: reject secondary interfaces to prevent conflicts
- wifi: mac80211: skip unused probe response countdown offsets
- wifi: mac80211: disconnect on CSA to channel 0 (CVE-2026-90344)
- firmware: google: Add bounds checks in coreboot_table_populate()
- firmware: coreboot: Validate table bounds (CVE-2026-90341)
- [powerpc] smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass
- [powerpc] irq: Fix missing r2 clobber in PCREL inline assembly
- serial: amba-pl011: unprepare console clock on unregister
- tty: clear cdev pointer after cdev_add() failure (CVE-2026-90334)
- HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver
- HID: synchronize input before cleaning up a failed probe (CVE-2026-90329)
- HID: i2c-hid: Fix "(null)" output when reading report descriptor fails
- HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure
- HID: lg4ff: validate report length before fixed offsets
- perf thread-stack: Fix heap buffer overflow on branch stack wrap copy
- perf auxtrace: Fix queue grow overflow and old array leak
- perf intel-pt: Fix off-by-one in auxtrace_info minimum size check
- perf intel-bts: Fix off-by-one in auxtrace_info minimum size check
- iio: light: tsl2772: fix ALS calibscale readback
- iio: light: isl29028: return zero in write_raw() on success
- iio: light: tsl2583: return zero in write_raw() on success
- net: stmmac: Skip PHY attach if custom PCS is in use
- phonet: pep: do not write beyond optlen in getsockopt (CVE-2026-90327)
- blk-cgroup: skip dying blkg in blkcg_activate_policy() (CVE-2026-90325)
- block/blk-stat: drain per-cpu callback stats over possible CPUs
- block/blk-iocost: collect per-cpu latency stats over possible CPUs
- block/kyber-iosched: flush per-cpu latency buckets over possible CPUs
- ublk: check for ublk_unmap_io() returning 0
- o2hb_region_dev_store(): avoid goto around fdget()/fdput()
- ocfs2/cluster: keep heartbeat local node stable (CVE-2026-90322)
- lib/string: fix memchr_inv() for large ranges
- pps: don't try to wait for negative timeouts in PPS_FETCH
- pps: clients: gpio: Bypass edge's direction check when not needed
- pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded
handler
- pps-gpio: remove dead capture_clear code
- rapidio: clear mport->net when rio_add_net() fails (CVE-2026-90319)
- fat: release buffer head after rebuilding parent (CVE-2026-90318)
- riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel
number for DMA controller
- drm/omap: dsi: Do not copy isr table (CVE-2026-90316)
- [arm64] dts: qcom: agatti: Add missing CX power domain to DISPCC
- remoteproc: Move resource table data structure to its own header
- remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources()
- remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()
(CVE-2026-90314)
- bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed
(CVE-2026-90313)
- [arm64] dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY
vdda-phy/vdda-pll supplies
- [arm64] dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY
vdda-phy/vdda-pll supplies
- scripts/tags.sh: Prevent binary files appearing in cscope.files
- modpost: prevent leak when early return no suffix .o in read_symbols()
- RDMA/erdma: Hold CQ references when processing EQ events (CVE-2026-90309)
- RDMA/erdma: Hold QP references for AE and CM processing (CVE-2026-90308)
- RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ
(CVE-2026-90307)
- [armhf] 9481/2: breakpoint: CFI breakpoints only on demand
(CVE-2026-90306)
- [armhf] 9485/1: mm: acquire mmap write lock around show_pte() for user
faults (CVE-2026-90303)
- ocfs2: synchronize heartbeat callbacks with o2net teardown
(CVE-2026-90302)
- clk: rockchip: rk3576: fix source muxes for SPI0..SPI4
- drm/sun4i: vi scaler: Fix coefficient selection
- of: property: add of_graph_get_next_port()
- of: property: add of_graph_get_next_port_endpoint()
- drm/sun4i: tcon: Set output mux for DSI and LVDS
- drm/sun4i: tcon: Drop TCON TOP device reference (CVE-2026-90298)
- drm/sun4i: hdmi: Don't leak sync polarity bits into packet control
- drm/sun4i: crtc: Propagate layer initialization error (CVE-2026-90297)
- drm/sun4i: tcon: Drop remote endpoint reference
- drm/sun4i: dw-hdmi: Drop TCON TOP port reference
- drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz
- cpufreq: imx6q: fix devres accumulation across driver rebind
(CVE-2026-90296)
- cpufreq: imx6q: fix out-of-bounds write when probed more than once
(CVE-2026-90295)
- IB/isert: delay the final Login Response until the session is registered
(CVE-2026-90294)
- IB/isert: post the full-feature receive buffers after session registration
(CVE-2026-90293)
- RDMA/siw: Fix use-after-free in siw_accept() (CVE-2026-90292)
- module: replace use of system_wq with system_dfl_wq
- module: use strscpy() to copy module names in stats and dup tracking
- module/dups: Inform duplicate requests about the result directly
- module/dups: Fix use-after-free in kmod_dup_req lifetime handling
(CVE-2026-90291)
- RDMA/erdma: restrict the driver to little-endian systems
- wifi: mac80211: skip default WMM setup for AP_VLAN links
- [arm64] hibernate: mask DAIF before restoring hibernated kernel
- [arm64] hibernate: Restore DAIF state on error (CVE-2026-90290)
- mfd: rave-sp: validate received frame payload lengths
- mfd: iqs62x: Reject zero-length firmware records
- drm/amdgpu/gfx6: Fixup emit_cntxcntl()
- ext4: fix spurious message about orphan cleanup on RO fs
- [arm64] dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node
- phy: sunplus: fix error handling in sp_uphy_init() (CVE-2026-90287)
- phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table
- perf trace-event: Fix buffer overflow in read_string()
- drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets
- drm/amdgpu/gfx6: Use PFP on the compute queues too (CVE-2026-90286)
- scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
(CVE-2026-90285)
- firmware_loader: do not queue completed sysfs fallback requests
(CVE-2026-90284)
- pinctrl: rockchip: Reset the pin count when recalculating SoC data
- hugetlbfs: release subpool on fill_super failure (CVE-2026-90283)
- soc: fsl: qe: check platform_driver_register() in qe_ic_of_init()
- phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*()
- phy: qcom: sgmii-eth: vote for both voltage rails with correct current
loads
- phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime
suspend (CVE-2026-90282)
- phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend
(CVE-2026-90281)
- phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend
(CVE-2026-90280)
- md/raid5: round bitmap stripes with sector division (CVE-2026-90279)
- md: avoid stale clone I/O accounting timestamps
- md/raid1: don't set array_frozen in raid1_takeover() (CVE-2026-90275)
- coresight: etm4x: fix wrong check of etm4x_sspcicrn_present()
- coresight: Change syncfreq to be a u8
- coresight: etm4x: fix underflow for usage of (nrseqstate - 1)
(CVE-2026-90274)
- coresight: etm4x: fix leaked trace id
- regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling
- ACPI: video: Release PCI device reference after lookup
- [amd64] perf/x86/intel/pt: Add support for pause / resume
- [amd64] perf/x86/intel/pt: Factor out pt_config_enable()
- [amd64] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED
- [amd64] perf/x86/intel/pt: Fix stop/start with no update
- sched/fair: Check CPU capacity before comparing group types during load
balance
- Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event
- Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855()
- Bluetooth: btusb: refactor endpoint lookup
- Bluetooth: btusb: Record matched usb_device_id into btusb_data
- Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled
devices
- perf trace-event: Fix integer truncation in do_read() and skip()
- scsi: sd: Fix sd_done() sense handling condition
- btrfs: retry verity reads for not-uptodate Merkle folios (CVE-2026-90262)
- Bluetooth: virtio_bt: avoid OOB read of build info string (CVE-2026-90257)
- Bluetooth: btintel: Fix diagnostics event detection
- Bluetooth: hci_conn: fix the SCO setup context lifetime (CVE-2026-90255)
- Bluetooth: hci_sync: free the advertising instance on the failure and
cancel paths (CVE-2026-90254)
- Bluetooth: MGMT: free the mesh send cancel command when it is cancelled
(CVE-2026-90253)
- mmc: sdio: add MediaTek MT7902 SDIO device ID
- Bluetooth: btmtk: add MT7902 MCU support
- Bluetooth: btmtk: add MT7902 SDIO support
- Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: MSFT: validate evt_prefix_len against the response length
(CVE-2026-90251)
- cgroup: Add bpf prog revisions to struct cgroup_bpf
- bpf: Implement mprog API on top of existing cgroup progs
- bpf, cgroup: Fix storage null-ptr-deref after replacing prog
(CVE-2026-90250)
- iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
(CVE-2026-90249)
- iio: light: gp2ap002: re-enable irq if runtime suspend fails
- net/sched: cls_api: fix teardown of an adopted proto on insert-race loss
(CVE-2026-90248)
- [riscv64] cpufeature: Clarify ISA spec version for canonical order
- [arm64] dts: turris-mox: fix usb3 phys
- perf stat: Fix evsel_list leak in cmd_stat
- perf synthetic-events: Fix uninitialized pthread_join
- perf python: Add support for 'struct perf_counts_values' to return counter
data
- perf python: Check counts_values size in set_values
- perf synthetic-events: Fix divide by zero in
perf_event__synthesize_threads
- fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device()
- fbdev: kyro: Validate overlay viewport coordinates (CVE-2026-90245)
- [amd64] iommu/vt-d: Fix UCTP context table slot when copying root entries
- [amd64] iommu/vt-d: Clear Present bit before tearing down copied context
entry (CVE-2026-90243)
- [amd64] iommu/vt-d: Tear down scalable-mode context on probe failure
(CVE-2026-90241)
- xdrgen: Rename "enum yada" types as just "yada"
- xdrgen: Implement big-endian enums
- xdrgen: Address some checkpatch whitespace complaints
- xdrgen: Do not declare union XDR functions in the definitions header
- xdrgen: Fix opaque and string encoders for unbounded members
- SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6
(CVE-2026-89784)
- sunrpc: xprtsock: annotate shared socket callbacks with
READ_ONCE/WRITE_ONCE (CVE-2026-90235)
- [powerpc*] configs: enable CONFIG_RAS to fix EDAC support
- [amd64] iommu/amd: Fix incorrect device ID in invalid PASID error message
- phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs
- phy: qualcomm: qmp-combo: add support for SAR2130P
- phy: qcom: qmp-combo: Add new PHY sequences for SM8750
- phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for
regulator setup
- phy: qualcomm: Update the QMP clamp register for V6
- phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings
- phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms
- phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy
- spi: sprd-adi: Fix probe succeeding without registering the controller
- ASoC: qcom: q6apm: keep the graph start count in sync with the DSP
- [powerpc*] vdso: Add a page for non-time data
- [powerpc] Use str_enabled_disabled() helper function
- integrity: Make arch_ima_get_secureboot integrity-wide
- [s390x] Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT
- [s390x] irqflags: Add out-of-line definitions of arch_local_irq_*() for
KMSAN
- nvme: add reservation command's defines
- nvme: introduce change ptpl and iekey definition
- nvme: Add the DHCHAP maximum HD IDs
- nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
(CVE-2026-90230)
- nvme-apple: Destroy the admin queue on removal (CVE-2026-90229)
- nvme-apple: Don't set a DMA direction for commands without a data transfer
- nvme-apple: Never set the opcode in the NVMMU TCB
- nvme: apple: Add Apple A11 support
- nvme-apple: Drop the PRP null check chicken bit
- nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()
(CVE-2026-90228)
- nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227)
- nvme: reject passthrough of driver-managed Set Features
- nfc: llcp: avoid userspace overflow on invalid optlen (CVE-2026-90226)
- nfc: llcp: read llcp_sock->local under the socket lock in getsockopt
(CVE-2026-90225)
- nfc: nci: fix double completion race in nci_data_exchange_complete
(CVE-2026-90224)
- nfc: llcp: bound SNL TLV parsing to the skb and add length checks
(CVE-2026-90223)
- nfc: pn533: hold a reference to the request skb during send_frame
(CVE-2026-90222)
- nfc: digital: Do not dump a NULL response in command completion
- nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing
(CVE-2026-90221)
- ALSA: seq: Don't leak the extension cell pointer in the bounce payload
(CVE-2026-90220)
- dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal
- RDMA/cxgb4: Free debugfs on registration failure (CVE-2026-90219)
- RDMA/cma: Fix WARNING in res_to_rt (CVE-2026-90218)
- ice: clear the default forwarding VSI rule when releasing a VSI
- ASoC: pxa: Use devm_clk_get_optional() for extclk clock
- ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready
- UBI: Preserve torture flag when rescheduling failed erasures
- UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs
- ubi: Fix rollback for explicit UBI device numbers (CVE-2026-90216)
- mtd: ubi: Release device reference on busy detach (CVE-2026-90215)
- ASoC: xilinx: formatter_pcm: fix stream_data leak on open error
(CVE-2026-90214)
- UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC
- firewire: core: add KUnit test skeleton for node tree
- firewire: core: add KUnit tests for successful tree building
- firewire: core: add KUnit tests for failure of tree building
- firewire: core: consolidate port counting in build_tree()
- firewire: core: validate parent port count before allocating nodes in
build_tree()
- firewire: core: fix memory leak in error path of build_tree()
(CVE-2026-90213)
- PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM
disable/restore
- super: fix dying superblock warning messages
- kunit: tool: fix _list_tests filtering wrong variable when list has TAP
prefix
- [s390x] bpf, s390: Clear fetch destination on faulting arena atomic
(CVE-2026-90211)
- spi: img-spfi: don't disable runtime PM on DMA deferred probe
- PCI/ASPM: Cache L0s/L1 Supported so advertised link states can be
overridden
- PCI/ASPM: Disable/restore ASPM on every function for multi-function
devices
- power: supply: bd99954: Drop bad register fields
- power: supply: bq27xxx: bq27520g4: fix REG_TTES address
- power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address
- power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address
- xenbus: Unregister reboot notifier on init failure
- [s390x] debug: Fix deadlock during unregister (CVE-2026-90209)
- clocksource/drivers/clps711x: Do not unmap clocksource MMIO
- clocksource/drivers/armada: Unwind timer clock on init failure
- ALSA: seq: midi: Optimize event_input locking with RCU
- ALSA: seq: midi: Serialize input teardown with event_input
(CVE-2026-90207)
- cgroup/cpuset: Fix spelling errors in file kernel/cgroup/cpuset.c
- cgroup/cpuset: Remove remote_partition_check() & make
update_cpumasks_hier() handle remote partition
- [amd64] x86/pkeys: Fix pkey_alloc() return value when pkeys are not
supported
- bpftool: Fix double close in map dump
- ocfs2: fix circular locking dependency in ocfs2_init_acl()
- Squashfs: check block offset is not negative (CVE-2026-90203)
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (CVE-2026-90202)
- scsi: ufs: core: Remove redundant host_lock calls around UTMRLDBR
- scsi: ufs: core: Set task state before io_schedule_timeout()
- page_pool: rename __page_pool_release_page_dma() to
__page_pool_release_netmem_dma()
- net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg
race (CVE-2026-90201)
- fs/ntfs3: fix integer overflow in MFT cluster validation (CVE-2026-90200)
- fs/ntfs3: reject out-of-range evcn in mi_enum_attr() (CVE-2026-90199)
- ALSA: core: Fix use-after-free in snd_card_do_free() (CVE-2026-90198)
- tracing: Remove "__attribute__()" from the type field of event format
- tracing: Have trace_event_update_all() only handle module that is loading
- ASoC: SOF: validate topology volume range before allocation
(CVE-2026-90196)
- HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU
- [riscv64] bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc
args (CVE-2026-90195)
- ring-buffer: Remove trace_buffer::cpus
- ACPI: scan: fix bus ID cleanup on device_add() failures (CVE-2026-90194)
- bpf: Fix pending_pos walk on 32-bit ring position wrap
- crypto: hisilicon/sec2 - fix CCM algorithm long packet failure
- crypto: lskcipher - propagate errors from unaligned crypt
- sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry
- perf dso: Guard close() against invalid fd in
dso__decompress_kmodule_path()
- perf dso: Use stored fd error instead of stale errno in file_read() and
file_size()
- perf dso: Guard against cache underflow on short reads in
dso_cache__memcpy()
- mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler
(CVE-2026-90193)
- mailbox: qcom-cpucp: handle NULL data in send_data callback
(CVE-2026-90192)
- mailbox: rockchip: disable pclk on probe failure and unbind
- mailbox: pcc: Always map the shared memory communication address
- mailbox/pcc: support mailbox management of the shared buffer
- Revert "mailbox/pcc: support mailbox management of the shared buffer"
- mailbox: pcc: Fix command timeout due to missed interrupt
- null_blk: use DEFINE_MUTEX for the file-scope mutex (CVE-2026-90190)
- null_blk: register configfs subsystem after creating default devices
(CVE-2026-90189)
- null_blk: free global tag_set on init error path (CVE-2026-90188)
- null_blk: free zones array on device power-off (CVE-2026-90187)
- null_blk: reject per-device queue resize for shared tag set
(CVE-2026-90186)
- null_blk: serialize configfs attribute stores with the lock
(CVE-2026-90185)
- null_blk: serialize configfs attribute updates with device setup
(CVE-2026-90184)
- ublk: reject non-power-of-2 zone sizes in SET_PARAMS
- block: mtip32xx: synchronize ioctls with device removal (CVE-2026-90180)
- hwmon: (coretemp) Fix core_data leak on CPUs without PTS (CVE-2026-90178)
- hwmon: (emc1403) Rely on subsystem locking
- hwmon: (emc1403) Drop hysteresis for low limit temperature
- ksmbd: Do not skip lock checks for single-byte ranges (CVE-2026-90176)
- smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer
(CVE-2026-90175)
- ksmbd: validate ipc response length before dereferencing its fields
(CVE-2026-90170)
- ksmbd: do not advertise unimplemented CA support
- ksmbd: free preauth sessions on connection teardown (CVE-2026-90169)
- smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()
(CVE-2026-90166)
- smb/server: fix invalid pointer dereference in
ksmbd_stop_durable_scavenger() (CVE-2026-90165)
- smb/server: preserve error status in smb2_handle_negotiate()
- lwt_bpf: Restore reserved headroom after xmit program (CVE-2026-90160)
- erofs: convert z_erofs_bind_cache() to folios
- erofs: support unaligned encoded data
- erofs: fix unused pcluster_pools for higher page sizes
- bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks
(CVE-2026-90159)
- bpf: Reject negative optlen in cgroup getsockopt hook (CVE-2026-90157)
- ksmbd: disconnect on SMB3 decryption failure
- ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size (CVE-2026-90153)
- smb/server: fix session leak in ksmbd_session_register() (CVE-2026-90152)
- nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper
- nfs: refactor pNFS functions using clear_and_wake_up_bit
- NFSv4: remove callback IDR entry on client allocation failure
(CVE-2026-90151)
- pnfs/blocklayout: Fix device leaks on parse failure (CVE-2026-90150)
- NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in
nfs4_add_lease() (CVE-2026-90148)
- nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3
- clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()
(CVE-2026-90147)
- clk: ti: use kcalloc() instead of kzalloc()
- clk: ti: mux: resolve parent clocks by DT index, not by name
- octeontx2-af: initialize lmac_bmap in rvu_mcs_set_lmac_bmap()
- drm/xe: tests: fix error message in xe_migrate_sanity_test()
- ionic: fix completion descriptor access with 2x desc size
- net: kcm: Hold RCU read lock while running BPF parser (CVE-2026-90143)
- net: dsa: b53: fix error propagation from b53_fdb_dump()
- pppox: drain queued packets on channel handoff
- net: hsr: free learned nodes on device setup failure
- f2fs: fix to parse temperature correctly in f2fs_get_segment_temp()
- f2fs:Fix incomplete search range in f2fs_get_victim when
f2fs_need_rand_seg is enabled
- f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk}
- f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode
- ipvs: fix integer overflow in ftp helper port/address parsing
(CVE-2026-90141)
- vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
(CVE-2026-89776)
- net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error
- tls: fix RX desync on overlapping skbs
- net: bridge: vlan: fix inverted default vlan notification
- cuse: wait for pending RCU callbacks on module exit (CVE-2026-90140)
- fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() (CVE-2026-89781)
- fs/ntfs3: validate ef->size covers the record's name and value
(CVE-2026-89779)
- fuse: support folios in struct fuse_args_pages and fuse_copy_pages()
- fuse: convert readdir to use folios
- fuse: check attributes staleness on fuse_iget()
- fuse: check for NULL root inode in fuse_fill_super_submount
(CVE-2026-90139)
- ALSA: hda: Fix connection list comparison in proc output
- vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()
- 8139cp: fix Rx and Tx not being disabled in cp_suspend
- net/smc: hash socket only after full initialisation in smc_sk_init()
- [amd64] platform/x86: dell-wmi-sysman: Fix instance ID bounds
- vsock: avoid timeout for non-blocking accept() with empty backlog
- vsock: don't check the listener's sk_err in vsock_accept()
(CVE-2026-90138)
- vsock: use sock_error() to consume sk_err after a failed connect
- platform/x86: hp-bioscfg: fix password encoding bounds check
(CVE-2026-90137)
- mlxbf-bootctl: fix the build error with FIELD_PREP()
- bonding: initialize err for empty target lists
- net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()
(CVE-2026-90135)
- i3c: mipi-i3c-hci: Quieten initialization messages
- i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc()
- i3c: mipi-i3c-hci: Refactor PIO register initialization
- i3c: mipi-i3c-hci: Fix missing STAT_IBI_STATUS_THLD in PIO mode
- virtio_balloon: disable indirect descriptors
- vdpa_sim: fix cleanup after worker creation failure (CVE-2026-90130)
- virtio_pci: fix wrong queue index for admin vq in intx path
- vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
(CVE-2026-90128)
- rtc: pcf8563: fix clock provider leak on unbind (CVE-2026-90126)
- smb: client: fix request buffer leak in smb2_new_read_req()
(CVE-2026-90125)
- rtc: zynqmp: Return optional clock lookup errors
- irqchip/renesas-rzg2l: Fix loss of interrupt (CVE-2026-90124)
- i2c: ocores: Disable clock on failed resume
- rtc: gamecube: check return value of devm_rtc_register_device()
- prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator
- clk: ti: Make sure clk_init_data is fully initialized
- clk: visconti: Make sure clk_init_data is fully initialized
(CVE-2026-90122)
- ALSA: core: Add scoped cleanup helper for card references
- ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup
(CVE-2026-90119)
- RDMA/ucma: Allow path records to exactly fit the output buffer
- xsk: Get rid of xdp_buff_xsk::orig_addr
- xsk: avoid double checking against rx queue being full
- xsk: fix NULL pointer dereference in __xsk_rcv() (CVE-2026-90115)
- net: bridge: Reject descending VLAN tunnel ranges (CVE-2026-90114)
- net/sched: add get_fill_size callbacks for actions missing them
- net: thunderbolt: Count delivered packets in rx_packets and rx_bytes
- forcedeth: stop the tx_timeout register dump past the requested window
- net: ipa: balance runtime PM reference on remove error
- net: add missing ref_tracker_dir_exit() to net_passive_dec()
- net: qlcnic: validate unified ROM sections before loading (CVE-2026-90112)
- inetpeer: randomize RB-tree node comparison using SipHash (CVE-2026-90110)
- net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue
(CVE-2026-90109)
- net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK
transition (CVE-2026-90108)
- net/smc: free pending qentry in smc_llc_flow_stop() before memset
(CVE-2026-90107)
- NFSv4.2: fix LAYOUTSTATS send buffer exhaustion (CVE-2026-90103)
- nfs: move the nfs4_data_server_cache into struct nfs_net
- NFSv4/pnfs: key the data server cache on the NFS version (CVE-2026-90102)
- rtc: pcf85363: Add error checking to regmap calls in probe()
- bnxt_en: Fix call to hardware monitoring event handler (CVE-2026-90101)
- net: page_pool: Remove zone/policy GFP flags when allocating XArray
entries
- scsi: qla2xxx: Fix an loop timeout test
- erofs: Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS default logic
- [s390x] Add missing _TIF defines
- [s390x] Add ARCH_HAS_PREEMPT_LAZY support
- mm: make DEBUG_WX depdendent on GENERIC_PTDUMP
- mm: rename GENERIC_PTDUMP and PTDUMP_CORE
- mm/ptdump: split note_page() into level specific callbacks
- [arm64] ptdump: Make note_page_flush() range aware
- Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN
(CVE-2026-90092)
- Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference
- Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan
(CVE-2026-90091)
- Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
- Bluetooth: btmtk: Do not report success when subsys reset fails
- Bluetooth: btmtk: Do not discard the subsystem reset timeout
- Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX
- Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path
(CVE-2026-90090)
- Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite
loop (CVE-2026-90088)
- gtp: add synchronize_net() in gtp_newlink() error path to prevent
use-after-free (CVE-2026-89789)
- octeontx2-af: fix NULL deref in NIX TM tree debugfs read path
(CVE-2026-90085)
- net: qualcomm: rmnet: restore skb->dev on deaggregated frames
(CVE-2026-89780)
- octeontx2-af: Fix TL3/TL2 link config ENA clearing
- net/rds: use wq_has_sleeper() in rds_cong_map_updated() (CVE-2026-90081)
- cifs: fix clearing stats for fastest execution of each smb2 command
- maple_tree: catch race in mas_alloc_cyclic()
- maple_tree: fix argument name in header
- net_sched: act_skbmod: use RCU in tcf_skbmod_dump()
- net/sched: act_skbmod: fix length calculations and avoid invalid header
warnings (CVE-2026-90078)
- net: core: check skb_frags_readable before uncloning in skb_copy_ubufs
- net/sched: fq: add overflow bounds to quantum and initial quantum
(CVE-2026-90076)
- net/sched: fq_codel: clamp default quantum and mtu (CVE-2026-90075)
- net/sched: sch_codel: clamp default mtu to avoid disabling CoDel
- net/sched: fq_pie: clamp default quantum to avoid signed overflow
(CVE-2026-90074)
- net/sched: hhf: clamp quantum before hhf_change() to avoid overflow
(CVE-2026-90073)
- net/sched: sfq: clamp quantum to avoid signed overflow soft lockup
(CVE-2026-90072)
- net/sched: sch_teql: restore skb->dev on the slave failure path
(CVE-2026-90071)
- tpm: st33zp24: Return zero on status read failure (CVE-2026-90070)
- tpm: st33zp24: Validate locality read result
- apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init
- apparmor: policy_int make sure list heads are initialized before fail path
- ASoC: dapm: Fix off-by-one check on the second enum channel
(CVE-2026-90068)
- ceph: revalidate ki_pos for O_APPEND writes after cap acquisition
- libceph: validate banner payload length (CVE-2026-90067)
- samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify
- samples/ftrace: Fix kthread_stop() on ERR_PTR in
ftrace-direct-multi-modify (CVE-2026-90066)
- net: ethernet: sun4i-emac: Fix IRQ error handling
- net/smc: release the internal TCP sock on IPPROTO_SMC socket creation
failure (CVE-2026-90065)
- net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs
- net: stmmac: selftests: Pass the IP proto mask in the TC selftest
- virtio-net: Ensure that TCP packets don't overflow gso_segs
(CVE-2026-90063)
- netfilter: nf_tables: move hardware offload step after building the chain
blob (CVE-2026-90062)
- netfilter: xt_cgroup: Make it independent from net_cls
- netfilter: xt_HL: add pr_fmt and checkentry validation
- netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited()
- ALSA: control: Don't add invalid kcontrols to LED layer (CVE-2026-90060)
- net: stmmac: selftests: Check multiple MMC counters
- net: stmmac: dwmac1000: Account for the primary MAC address for UC
filtering
- net: stmmac: dwmac4: Account for the primary MAC address for UC filtering
- net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering
- net: stmmac: selftests: Account for the UC filter list for filtering tests
- net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup
(CVE-2026-90058)
- slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()
(CVE-2026-90057)
- net: fec: only stop PTP if it was initialized (CVE-2026-90056)
- usb: atm: usbatm: fix invalid ci_range initialization (CVE-2026-90055)
- tcp: fix corruption of urgent data on multi-segment retransmit
(CVE-2026-90054)
- net/sched: sch_htb: limit htb_classify inner-class filter hops
(CVE-2026-90053)
- [amd64] platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL
- [amd64] cpufreq/amd-pstate: Fix prefcore rankings
- pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
- pinctrl: mediatek: Fix new design debounce issue
- pinctrl: mediatek: common-v1: Fix EINT breakage on older controllers
- md: keep recovery_cp in mdp_superblock_s
- slub: Don't call lockdep_unregister_key() for immature kmem_cache.
- ACPI: processor: Update cpuidle driver check in __acpi_processor_start()
- fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT
- selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
- bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
- perf test: Don't signal all processes on system when interrupting tests
- phy: qcom: qmp-combo: Add missing PLL (VCO) configuration on SM8750
- powerpc/vdso: Remove unused clockmode asm offsets
- nvme-apple: Prevent shared tags across queues on Apple A11
- nvme-apple: Reset q->sq_tail during queue init
- cpuset: fix warning when disabling remote partition
- erofs: fix managed cache race for unaligned extents
- xsk: Fix offset calculation in unaligned mode
- Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array
- net/sched: fq: clamp quantum and initial_quantum in change path
- md: add helper rdev_needs_recovery()
- md: fix sync_action incorrect display during resync
- net_sched: act_ct: use RCU in tcf_ct_dump()
- net_sched: act_ctinfo: use RCU in tcf_ctinfo_dump()
- net_sched: act_skbedit: use RCU in tcf_skbedit_dump()
- net_sched: act_vlan: use RCU in tcf_vlan_dump()
- net_sched: act_tunnel_key: use RCU in tunnel_key_dump()
- net_sched: add back BH safety to tcf_lock
- tools/build: Use SYSTEM_BPFTOOL for system bpftool
- pinctrl: mediatek: common-v1: Fix error checking in mtk_eint_init()
- slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL
- integrity: Eliminate weak definition of arch_get_secureboot()
- ACPI: processor: Add cpuidle driver check in
acpi_processor_register_idle_driver()
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.111
- ksmbd: fix use-after-free in oplock break notification (CVE-2026-80926)
- drm/gem: Consider GEM object reclaimable if shrinking fails
- bus: fsl-mc: wait for the MC firmware to complete its boot
- drm: rz-du: Ensure correct suspend/resume ordering with VSP
- drm/amd/display: Fix DPMS using partially updated pipe context
- drm/panel: jadard-jd9365da-h3: set prepare_prev_first
- drm/amd/pm: Check SMUv13.0.6/12 metrics integrity
- gfs2: fix quota init duplicate scan
- gfs2: move quota_init qc iterator increment
- iio: adc: rtq6056: add i2c_device_id support
- [arm64] pinctrl: renesas: rzg2l: Handle RZ/V2H(P) IOLH configuration in PM
cache
- ALSA: usb-audio: Propagate write errors in generic mixer put callbacks
- ima: return error early if file xattr cannot be changed
- usb: gadget: udc: skip pullup() if already connected
- [arm64] tee: optee: Allow MT_NORMAL_TAGGED shared memory
- PCI: Stop setting cached power state to 'unknown' on unbind
- wifi: cfg80211: reject duplicate wiphy cipher suite entries
- hfsplus: fix issue of direct writes beyond end-of-file
- wifi: nl80211: reject beacons with bad HE operation
- wifi: mac80211: always allow transmitting null-data on TXQs
- wifi: rtw88: Add NULL check for chip->edcca_th in
rtw_fw_adaptivity_result()
- wifi: rtw89: disable CSI STBC for VHT 160MHz
- ASoC: fsl-asoc-card: reduce WM8904 PLL ratio to meet frequency limit
- firmware: stratix10-svc: change get provision data to async SMC call
- bridge: Do not suppress ARP probes and DAD NS unconditionally
- soundwire: intel_auxdevice: Add cs42l43b to wake_capable_list
- soundwire: validate DT compatible before parsing it
- media: chips-media: wave5: Fix Reports from Kernel Lock Validator
- spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM
- media: rc: mceusb: Add support for 04eb:e033
- net: mana: hardening: Reject zero max_num_queues from
MANA_QUERY_VPORT_CONFIG
- [s390] cio: Purge based on the cdev's online status
- [amd64] thunderbolt: Avoid reserved fields in path config space for USB4
routers
- [amd64] thunderbolt: Don't disable lane adapter if XDomain lane bonding
isn't possible
- [amd64] thunderbolt: Release request if tb_cfg_request() fails in
__tb_xdomain_response()
- [amd64] thunderbolt: Keep XDomain reference during the lifetime of a
service
- [amd64] thunderbolt: Keep the domain reference while processing hotplug
- [amd64] thunderbolt: Set tb->root_switch to NULL when domain is stopped
- [amd64] thunderbolt: Don't create multiple DMA tunnels on firmware
connection manager
- drm/amd/display: Find link encoder for flexible DIG mapping cases
- drm/amdgpu: Prefer ROM BAR for default VGA device
- drm/panel: Enable GPIOLIB for panels which uses functions from it
- media: dm1105: fix missing error check for dma_alloc_coherent
- net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family
- PCI: switchtec: Add Gen6 Device IDs
- net: dsa: mv88e6xxx: define .pot_clear() for 6321
- net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family
- media: em28xx-video: fix missing res_free() on init_usb_xfer failure
- wifi: mac80211: explicitly disable FTM responder on AP stop
- rtase: Fix flow control configuration
- crypto: ixp4xx - fix buffer chain unwind on allocation failure
- crypto: omap - add omap_des_unregister_algs helper
- [arm64] clk: renesas: cpg-mssr: Add number of clock cells check
- drm/bridge: tc358768: Set pre_enable_prev_first for reverse order
- dlm: add usercopy whitelist to dlm_cb cache
- PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store()
- media: qcom: camss: avoid format string warning
- ASoC: ti: omap3pandora: update board check to use DT compatible
- watchdog: lenovo_se10_wdt: Add support for SE10 Gen 2 platform
- watchdog: imx7ulp_wdt: Keep WDOG running until A55 enters WFI on i.MX94
- watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk
- net/mlx5: HWS, Handle destroying table that has a miss table
- platform/chrome: Resolve kb_wake_angle visibility race
- mmc: core: Add validation for host-provided max_segs
- mmc: davinci: avoid NULL deref of host->data in IRQ handler
- [amd64] platform/x86: sel3350-platform: Retain LED state on load and
unload
- drm/amd/display: Fix CRC open failure during active rendering
- PCI: intel-gw: Enable clock before PHY init
- hfsplus: rework hfsplus_readdir() logic
- net: phy: motorcomm: use device properties for firmware tuning
- drm/gud: Add RCade Display Adapter VID/PID pair
- media: chips-media: wave5: Add range checks for dec_output_info
- media: video-i2c: use vb2_video_unregister_device on driver removal
- HID: multitouch: Fix Yoga Book 9 14IAH10 touchscreen misclassification
- wifi: rtw89: phy: check length before parsing PHY status IE
- net: dsa: realtek: rtl8365mb: add support for RTL8367SB
- integrity: Check for NULL returned by asymmetric_key_public_key
- drivers/of: validate status properties in reconfig state changes
- soundwire: intel: Move suspend tracking from trigger to pm suspend
- clk: samsung: exynos850: mark APM I3C clocks as critical
- scsi: pm8001: Reject firmware update in fatal error state
- scsi: pm8001: Reject non-fatal dump when controller is crashed
- [amd64] ASoC: Intel: sof_sdw: append dai type to dai link name
unconditionally
- crypto: atmel-ecc - add support for atecc608b
- media: imon: Add iMON VFD HID OEM v1.2 key mappings
- RDMA/mlx5: Use QP port when decoding responder CQEs
- drm/mediatek: dsi: Add compatible for mt8167-dsi
- iomap: don't make REQ_POLLED imply REQ_NOWAIT
- mailbox: Make mbox_send_message() return error code when tx fails
- PCI: Wait for device readiness after D3hot -> D0uninitialized transition
- drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id
- drm/amdkfd: Fix OOB memory exposure in get_wave_state()
- drm/amdkfd: Check bounds on allocate_doorbell
- ALSA: usx2y: Drain pending US-428 pipe-4 output commands
- sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity
- [arm64] iommu: arm-smmu-qcom: Ensure smmu is powered up in set_ttbr0_cfg
- 9p: invalidate readdir buffer on seek
- [arm64] daifflags: Make local_daif_*() helpers __always_inline
- drm/imagination: Populate FW common context ID before passing to the FW
- 9p: use kvzalloc for readdir buffer
- drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw
- bridge: Add missing READ_ONCE() annotations around FDB destination port
- [amd64] thunderbolt: Don't access path config space on Lane 1 adapters in
tb_switch_reset_host()
- [amd64] thunderbolt: Improve multi-display DisplayPort tunnel allocation
- firmware: arm_scmi: Validate SENSOR_UPDATE payload size
- firmware: arm_scmi: Validate BASE_ERROR_EVENT payload size
- [amd64] thunderbolt: Increase timeout for Configuration Ready bit
- wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not
needed
- [amd64] thunderbolt: Verify Router Ready bit is set after router
enumeration
- bitfield: wire __bf_shf to __builtin_ctzll
- nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl
- net: usb: qmi_wwan: add MeiG SRM813Q
- net: bridge: remove stale rcu_barrier() in br_multicast_dev_del()
- net/sched: sch_drr: make cl->quantum lockless
- net/rds: Don't sleep inside rds_ib_conn_path_shutdown
- spi: dw-mmio: Add ACPI ID LECA0002 for LECARC SoCs
- befs: handle set_blocksize failures
- ntfs3: handle set_blocksize failures
- affs: handle set_blocksize failures
- bfs: handle set_blocksize failures
- minix: handle set_blocksize failures
- qnx4: handle set_blocksize failures
- jfs: handle set_blocksize failures
- hpfs: handle set_blocksize failures
- omfs: handle set_blocksize failures
- isofs: handle set_blocksize failures
- HID: bpf: Add Huion Inspiroy Frego M button quirk
- usbip: vhci_hcd: fix NULL deref in status_show_vhci
- usb: core: hcd: fix possible deadlock in rh control transfers
- usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log
- USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set
- usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue
- serial: 8250: fix possible ISR soft lockup
- usb: host: add ARCH_AIROHA in XHCI MTK dependency
- crypto: atmel-sha204a - remove sysfs group before hwrng
- char/nvram: Remove redundant nvram_mutex
- rcu-tasks: Fix possible boot-time tests failed for the call_rcu_tasks()
- wifi: rtw89: pci: enable LTR based on pcie control register
- netlabel: fix IPv6 unlabeled address add error handling
- ALSA: seq: Remove arbitrary prioq insertion limit
- rds: filter RDS_INFO_* getsockopt by caller's netns
- rds: annotate data-race around rs_seen_congestion
- [s390x] zcore: Removed unused variables
- clk: socfpga: agilex: implement l3_main_free_clk
- thermal/drivers/tegra/soctherma: Switch to devm cooling device
registration
- [amd64] powercap: intel_rapl: Fix memory leak in
rapl_add_package_cpuslocked()
- drm/panel: simple: Add AM-1280800W8TZQW-T00H
- iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind
- irqchip/gic-v4: Don't advertise VLPIs if no ITS is probed
- ALSA: usb-audio: Add quirk for Novation Mininova
- net: hsr: require valid EOT supervision TLV
- ipv6: addrconf: fix temp address generation after prefix deprecation
- net: thunderx: fix PTP device ref leak in nicvf_probe()
- drm/dp: Add DSC virtual DPCD quirk for Realtek MST branch device
- drm/amd/pm/si: Fix updating clock limits from power states
- drm/amd/display: Initialize dsc_caps to 0
- ACPICA: Fix condition check in acpi_ps_parse_loop()
- ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
- ACPICA: add boundary checks in acpi_ps_get_next_field()
- ACPICA: validate byte_count in acpi_ps_get_next_package_length()
- ACPICA: Prevent adding invalid references
- ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
- ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg()
- ACPICA: validate handler object type in two places
- ACPICA: Add package limit checks in parser functions
- ACPICA: Add validation for node in acpi_ns_build_normalized_path()
- ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op()
- ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package()
- ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()
- ACPICA: add boundary checks in two places
- hfs: rework hfsplus_readdir() logic
- net: sfp: add quirk for OEM 2.5G optical modules
- [arm64] pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP
- host1x: bus: Fix missing ops null check in error teardown
- scripts: modpost: detect and report truncated buf_printf() output
- [amd64] ASoC: Intel: catpt: Complete coredump handling
- drm/nouveau/bios: skip the IFR header if present
- soc/tegra: fuse: Register nvmem lookups at probe
- soundwire: dmi-quirks: Disable ghost Realtek devices
- gfs2: page poisoning fix
- soundwire: only handle alert events when the peripheral is attached
- mmc: davinci: fix mmc_add_host order in probe
- mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC
- [armhf] tegra: p880: Lower CPU thermal limit
- tracing: Disable KCOV instrumentation for trace_irqsoff.o
- mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC
- iio: light: stk3310: Deal with the ps interrupt issue in PM
- perf/ftrace: Fix WARNING in __unregister_ftrace_function
- iio: accel: mma8452: switch to non-devm request_threaded_irq()
- libbpf: Also reset {insn,data}_cur on realloc failure
- net: ibm: emac: Reserve VLAN header in MJS limit
- wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
- ASoC: qcom: q6apm: return error code to consumers on failures
- ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive
- ata: ahci: fail probe if BAR too small for claimed ports
- ACPI: scan: Honor _DEP for ACPI0016 PCI/CXL host bridge
- ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach
- net: qrtr: fix node refcount leak on ctrl packet alloc failure
- net: wwan: t7xx: Add delay between MD and SAP suspend
- iommu/rockchip: disable fetch dte time limit
- [powerpc*] fadump: Add timeout to RTAS busy-wait loops
- fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib
- nvme: refresh multipath head zoned limits from path limits
- fs/ntfs3: validate index entry key bounds
- ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()
- ASoC: codecs: rk3328: Use managed GPIO and clock helpers
- ALSA: seq: oss: Reject reads that cannot fit the next event
- dpaa2-switch: rework FDB management on the bridge leave path
- dpaa2-switch: fix the error path in dpaa2_switch_rx()
- net: dsa: sja1105: flower: reject cross-chip redirect
- dpaa2-switch: fix handling of NAPI on the remove path
- thermal/drivers/qcom/tsens: Atomic temperature read with hardware-guided
retries
- usb: xhci: Improve Soft Retries after short transfers
- xhci: Prevent queuing new commands if xhci is inaccessible
- drm/amd/display: Check for sharpening case when calculating max vtaps for
scaler
- drm/amdkfd: fix UAF race in destroy_queue_cpsch
- drm/amdgpu: harden FRU PIA parsing with bounded helpers
- drm/amd/pm: bound pp_dpm_set_pp_table() memcpy
- drm/amdgpu: fix buffer overflow during vBIOS update
- net/mlx5e: Verify unique vhca_id count instead of range
- RDMA/irdma: Fix typo in SQ completions generation
- net/mlx5: E-Switch, align disable sequence with switchdev-to-legacy
transition
- clk: keystone: don't cache clock rate
- ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP
- ipmi: si: Use platform_get_irq_optional() to retrieve interrupt
- drm/amdkfd: Unwind debug trap enable on copy_to_user failure
- ipv6: use READ_ONCE() for bindv6only default in inet6_create()
- wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer
notifications
- RDMA/umem: Be careful about boundary conditions in
ib_umem_find_best_pgsz()
- RDMA/mlx5: Fix state and counter desync on loopback enable failure
- bpf: NUL-terminate replaced sysctl value
- net: cpsw_new: unregister devlink on port registration failure
- hsr: broadcast netlink notifications in the device's net namespace
- net: microchip: sparx5: clean up PSFP resources on flower setup failure
- ALSA: es18xx: check control allocation before private data setup
- netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
- [riscv64] panic if IRQ handler stacks cannot be allocated
- btrfs: balance: fix potential bg lookup failure in
btrfs_may_alloc_data_chunk()
- btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF
- NFS: fix eof updates after NFSv4.2 fallocate/zero-range
- ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in
mt8365_afe_suspend()
- RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
- xprtrdma: Add request-pool slack for delayed recycling
- RDMA/mlx5: Create ODP EQ for non-pinned dmabuf MRs
- configfs_depend_prep(): pass configfs_dirent instead of dentry
- pds_core: quiesce DMA before freeing resources
- net: ibm: emac: mal: fix potential system hang in mal_remove()
- tls: Flush backlog before waiting for a new record
- platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table
- wifi: mt76: mt7925: handle 320MHz bandwidth in RXV and TXS
- platform/x86: msi-ec: Add support for MSI Pulse GL66 12th Gen
- wifi: mt76: mt7925: add Netgear A8500 USB device ID
- wifi: mt76: mt7925: populate EHT 320MHz MCS map in sta_rec
- wifi: mt76: mt7925: add 320MHz bandwidth to bss_rlm_tlv
- wifi: mt76: transform aspm_conf for pci_disable_link_state
- netconsole: take target_cleanup_list_lock in drop_netconsole_target()
- btrfs: protect sb_write_pointer() with invalidate lock
- fbcon: don't suspend/resume when vc is graphics mode
- PCI: Avoid FLR for MediaTek MT7925 WiFi
- hwmon: (raspberrypi) Fix delayed-work teardown race
- hwmon: (adt7462) Add of_match_table to support devicetree
- btrfs: use on-disk uuid for s_uuid in temp_fsid mounts
- btrfs: use lockless read in nr_cached_objects shrinker callback
- net: dsa: qca8k: Add support for force mode for fixed link topology
- net: lan966x: restore RX state on reload failure
- vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add()
- vdpa/octeon_ep: Use 4 bytes for mailbox signature
- ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC
- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IRH8
- ata: libata-pmp: add JMicron JMS562 quirk
- [amd64] platform/x86: intel-hid: Add HP ProBook x360 440 G1 to
button_array_table
- nvme-fc: Do not cancel requests in io target before it is initialized
- sctp: Unwind address notifier registration on failure
- HID: multitouch: Honor ContactCount for Yoga Book 9 to suppress ghost
contacts
- hwmon: (dell-smm) Add Dell Latitude 7530 to fan control whitelist
- PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems
- dmaengine: altera-msgdma: Use memcpy_toio for descriptor FIFO writes
- dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc
- hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i
- spi: xilinx: let transfers timeout in case of no IRQ
- Bluetooth: btusb: MT7922: Add VID/PID 0e8d/223c
- Bluetooth: btusb: Add support for Intel Lizard Peak 2 (0x8087:0x0040)
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d922
- Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV
- Bluetooth: btmtk: Disable remote wakeup for MT7922/MT7925
- Bluetooth: btusb: MT7925: Add VID/PID 0e8d/8c38
- Bluetooth: btusb: Add support for TP-Link TL-UB250
- Bluetooth: L2CAP: validate connectionless PSM length
- Bluetooth: btintel_pcie: Add 50 ms delay before MAC init on BlazarIW
- ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt
- ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence
- ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure
- Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d923
- net: stmmac: xgmac2: disable RBUE in default RX interrupt mask
- ptp: ocp: add shutdown callback
- vsock: use sk_acceptq_is_full() helper in all transports
- e1000e: limit endianness conversion to boundary words
- [arm64] net: hns3: improve the unused_tuple parameter setting
- apparmor: propagate -ENOMEM correctly in unpack_table
- net/sched: act_csum: don't mangle UDP tunnel GSO packets
- smb: client: fix races in cifsd thread creation
- i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in
DAA
- bpftool: Pass host flags to bootstrap libbpf
- exfat: fix handling of damaged volume in exfat_create_upcase_table()
- ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT
- virtio-fs: avoid double-free on failed queue setup
- HID: hidpp: fix potential UAF in hidpp_connect_event()
- fuse: set ff->flock only on success
- scsi: bfa: Reduce kernel stack usage in
bfa_fcs_lport_fdmi_build_portattr_block()
- gpio: pisosr: Read "ngpios" as u32
- spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data()
- ALSA: usb-audio: Add quirk flags for SC13A
- tls: reject the combination of TLS and sockmap
- ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10
- leds: uleds: Return -EFAULT on copy_to_user() failure
- leds: pca9532: Don't stop blinking for non-zero brightness
- mfd: tps65219: Make poweroff handler conditional on
system-power-controller
- leds: trigger: gpio: Use GPIOD_FLAGS_BIT_NONEXCLUSIVE
- mfd: rsmu: Add 8a34002 support
- drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO
ioctl
- drm/amdkfd: check find_first_zero_bit before __set_bit on
kfd->doorbell_bitmap
- drm/amdgpu: Use system unbound workqueue for soft IH ring
- ALSA: usb-audio: Add quirk for YAMAHA CDS3000
- drm/amdkfd: Properly acquire queue buffers in CRIU restore
- PCI: iproc: Protect root bus removal with rescan lock
- PCI: altera: Protect root bus removal with rescan lock
- PCI: rockchip: Protect root bus removal with rescan lock
- PCI: mediatek: Protect root bus removal with rescan lock
- PCI: plda: Protect root bus removal with rescan lock
- perf: Fix addr_filter_ranges lifetime
- mailbox: imx: Use devm_pm_runtime_enable()
- md/raid5: account discard IO
- mailbox: imx: Add a channel shutdown field
- mailbox: imx: use devm_of_platform_populate()
- md/raid5: let stripe batch bm_seq comparison wrap-safe
- ALSA: hda/realtek: Add quirk for Lenovo Yoga 7 16IAP7
- f2fs: validate inline dentry name lengths before conversion
- rtc: mv: add suspend/resume support for wakeup
- rtc: aspeed: add AST2700 compatible
- ceph: harden send_mds_reconnect and handle active-MDS peer reset
- ksmbd: fix lease break and ack state handling
- ksmbd: validate SMB2 lease create contexts
- ksmbd: align SMB2 oplock break ack handling
- ksmbd: use connection ClientGUID for lease lookup
- ksmbd: treat unnamed DATA stream as base file
- ksmbd: apply create security descriptor first
- ksmbd: deny renaming directory with open children
- ksmbd: start file id allocation at 1
- ksmbd: break RH leases before delete-on-close
- ksmbd: treat read-control opens as stat opens only for leases
- PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device()
- PCI/sysfs: Use kstrtobool() to parse the ROM attribute input
- regulator: da9121: Use subvariant ids in the I2C table
- net: au1000: move free_irq out of the close-time spinlocked section
- blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat()
- rtc: bq32000: add delay between RTC reads
- eth: mlx5: fix macsec dependency
- ALSA: hda: Add Lenovo Legion 7i 16IAX7 17AA3874 quirk
- fbdev: pm2fb: unwind WC setup on probe failure
- ASoC: tas2781: Update default register address to TAS2563
- spi: core: Abort active target transfer on controller suspend
- btrfs: tree-checker: validate INODE_REF's namelen
- drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend
- netfilter: nf_conntrack_expect: zero at allocation time
- ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
- ALSA: hda/realtek: Add quirk for HP Victus 16-e0xxx (88EE) to enable mute
LED
- drm/arm/komeda: fix error handling for clk_prepare_enable() and callers
- ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr
- ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling
- xen/front-pgdir-shbuf: free grant reference head on errors
- freevxfs: don't BUG() on unknown typed-extent type
- xen/gntalloc: validate grant count before allocation
- cachefiles: Fix double fput
- netfs: Fix decision whether to disallow write-streaming due to fscache use
- [amd64] ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table
- drm/amdgpu: flush pending RCU callbacks on module unload
- ksmbd: fix credit charge calculation for SMB2 QUERY_INFO
- ALSA: usb-audio: caiaq: validate EP1 reply lengths
- wifi: ralink: RT2X00: init EEPROM properly
- wifi: mac80211: validate deauth frame length before reason access
- wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers
- wifi: libertas: reject short monitor TX frames
- wifi: cfg80211: validate assoc response length before status and IE access
- ksmbd: find bound sessions during reauthentication
- ksmbd: mark invalid session responses as signed
- ksmbd: validate SID namespace before mapping IDs
- wifi: cfg80211: validate rx/tx MLME callback frame lengths before access
- wifi: mac80211: ibss: wait for in-flight TX on disconnect
- gpio: dwapb: Mask interrupts at hardware initialization
- wifi: libipw: fix key index receive bound checks
- netfilter: ipset: mark the rcu locked areas properly
- wifi: rsi: validate beacon length before fixed buffer copy
- ASoC: rt712-sdca: reset codec at io_init to fix silent headphone
- smb/client: reduce fallocate zero buffer allocation
- cifs: Fix support for creating SFU socket
- smb/client: zero-initialize stack-allocated cifs_open_info_data
- ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series
- ALSA: hda/realtek - Add quirk for HP Victus 15-fa0xxx (MB 8A50)
- ALSA: hda: cs35l56: Fail if wmfw file is missing
- cifs: Fix support for creating SFU fifo
- btrfs: only account delalloc bytes for regular file inodes in
btrfs_getattr()
- btrfs: fix use-after-free on reloc root after error in
insert_dirty_subvol()
- spi: dw-dma: Wait for controller idle before completing Tx
- wifi: iwlwifi: mvm: validate sta_id in BA window status notif
- btrfs: fix reloc root cleanup in merge_reloc_roots()
- wifi: iwlwifi: mvm: validate mac_link_id in session protect notif
- wifi: iwlwifi: mvm: fix an off-by-1 boundary check
- wifi: iwlwifi: mvm: parse beacon notif per layout
- wifi: iwlwifi: mvm: fix sched scan IE sizing
- wifi: iwlwifi: pcie: null RX pointers after free
- ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute
LEDs
- blk-cgroup: fix leaks and online flag on radix_tree_insert failure
- smb/client: flush dirty data before punching a hole
- ASoC: Intel: sof_sdw: Add quirks for new Dell laptops
- wifi: iwlwifi: mvm: validate TX_CMD response layout
- wifi: iwlwifi: mvm: fix a possible underflow
- [arm64] fixmap: Allow 256K early_ioremap() at any offset
- wifi: iwlwifi: mvm: add a check on the tid coming from the firmware
- wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
- [arm64] kprobes: Allow reentering kprobes while single-stepping
- drm/amd/pm/si: Don't schedule thermal work when queue isn't initialized
- ALSA: hda/realtek: Add quirk for HP Pavilion x360
- wifi: iwlwifi: bound aligned TLV advance in FW parser
- ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless
- wifi: iwlwifi: acpi: validate WGDS table revision index
- ALSA: hda/realtek: Add HDA_CODEC_QUIRK for Samsung 750XBE/730XBE
- wifi: mwifiex: replace one-element arrays with flexible array members
- smb: client: bound dirent name against end of SMB response in cifs_filldir
- regulator: core: clamp voltage constraints before applying apply_uV
- wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO
- ksmbd: preserve VFS inherited POSIX ACL mask
- drm/gma500: return errors from Oaktrail HDMI I2C reads
- phonet: check register_netdevice_notifier() error in phonet_device_init()
- ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4
- ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx
- ice: pass the return value of skb_checksum_help()
- [powerpc*] pseries: Ensure vpa,slb_shadow & dtl are unregistered during
crash
- cifs: validate idmap key payload length
- wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
- Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame
- ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision)
- ata: libata-core: Disable LPM on some WD drives
- ALSA: hda/realtek: Add mute LED quirk for HP Victus 16-e0xxx (MB 88ED)
- ata: libata-core: Disable LPM on WD Green 2.5 480GB
- Drivers: hv: vmbus: add VTL2 redirect connection ID
- [amd64] ASoC: amd: yc: Add DMI quirk for HP Victus Laptop 16-e1xxx
- vhost-scsi: flush backend after device ioctls
- hwmon: (corsair-psu) Fix linear11 calculation
- ata: libata-core: Disable LPM on WDC WD141KFGX-68FH9N0
- spi: dw: fix wrong RX_SAMPLE_DLY setting after resume
- ASoC: rt5645: Perform the initial jack detect at probe
- scsi: core: Do not block on tag allocation in scsi_eh_lock_door()
- ASoC: amd: yc: Add DMI quirk for HyperX OMEN Gaming Laptop 16-ap1xxx
- netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet
state
- firmware: stratix10-svc: fix FCS SMC call kernel-doc
- bpftool: Strip all -Wformat* flags from bootstrap libbpf build
- ksmbd: remove stale channels from all sessions on teardown
- Revert "bpf, s390: Clear fetch destination on faulting arena atomic"
- Revert "ARM: 9481/2: breakpoint: CFI breakpoints only on demand"
- wifi: mt76: mt7921: validate CLC firmware records
- wifi: mt76: mt7921: skip unknown CLC firmware records
- drm/amd/display: clean-up dead code in dml2_mall_phantom
- driver core: Export get_dev_from_fwnode()
- of: dynamic: Fix overlayed devices not probing because of fw_devlink
- ppp_async: drop the errored frame instead of resetting its headroom
- drop_monitor: perform u64_stats updates under IRQ-disabled section
(CVE-2026-68286)
- drop_monitor: fix size calculations for 64-bit attributes (CVE-2026-68287)
- net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (CVE-2026-68288)
- tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
(CVE-2026-68289)
- drm/vc4: hvs/v3d: Fix null dereference in unbind (CVE-2026-68303)
- bpf: Reject redirect helpers without a bpf_net_context (CVE-2026-68337)
- Bluetooth: ISO: fix malformed ISO_END/CONT handling (CVE-2026-72334)
- bpf: Mask pseudo pointer values in verifier logs (CVE-2026-72402)
- sctp: fix err_chunk memory leaks in INIT handling (CVE-2026-72413)
- md/raid10: fix writes_pending and barrier reference leaks on discard
failures (CVE-2026-72438)
- coresight: platform: defer connection counter increment until alloc
succeeds (CVE-2026-72485)
- RDMA/bnxt_re: Proper rollback if the ioremap fails (CVE-2026-72496)
- bpf: Guard __get_user acesss with access_ok for uprobe_multi data
(CVE-2026-74258)
- ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
(CVE-2026-74289)
- ASoC: topology: Check PCM and DAI name strings before use (CVE-2026-74291)
- ASoC: meson: aiu: Validate written enum values (CVE-2026-74294)
- ksmbd: use memcmp() to compare ClientGUIDs (CVE-2026-74521)
- l2tp: fix tunnel and session refcount leak on seq_file release
(CVE-2026-74735)
- af_unix: Unlink scc_entry in unix_del_edge(). (CVE-2026-80521)
- Bluetooth: btrtl: Add the support for RTL8761CUV
- mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
(CVE-2026-89796)
- [armhf] 9484/1: enable interrupts when unhandled user faults are triggered
- [armhf] ensure interrupts are enabled in __do_user_fault()
- RAS/AMD/ATL, EDAC/amd64: Only load ATL when needed
- EDAC/igen6: Fix interleave boundary condition
- EDAC/igen6: Fix channel selection hash
- EDAC/igen6: Fix channel address decode for non-hash mode
- EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation
- drm/virtio: Fix a NULL vs ERR_PTR() bug in
virtio_gpu_user_framebuffer_create()
- accel/qaic: Address potential out-of-bounds read in resp_worker()
- nvme-rdma: fix -EIO cleanup order in queue_rq
- nvmet-rdma: fix queue leak when connect backlog is exceeded
- sched_ext: Fix nonexistent field in sched-ext.rst example
- bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic
- ufs: do not treat unreadable directory blocks as empty
- drm/cirrus: Use video aperture helpers
- drm/cirrus-qemu: Validate BAR0 size during probe
- net: icmp: avoid invalid transport header access in icmp_send tracepoint
- tcp: use GFP_ATOMIC in tcp_send_active_reset()
- net: iptunnel: fix stale transport header during tunnel decapsulation
- net/sched: act_api: budget all shared attributes in notify skbs
- net/sched: act_api: size the RTM_GETACTION reply from the actions
- net/sched: act_api: fix skb sizing and action leak on reoffload delete
- sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
- scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add()
- scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add()
- smb/client: validate new EOF for insert range
- smb/client: validate new EOF for zero range
- smb/client: mark file sparse before emulating insert range
- smb: client: batch SRV_COPYCHUNK entries to cut round trips
- smb: move copychunk definitions to common/smb2pdu.h
- smb/client: fix data corruption in emulated insert range
- smb/client: fix integer truncation in collapse range
- smb: client: transport: Fix debug printing in __release_mid()
- sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration
- raw: annotate disconnect-side IPv4 match writers
- net: amd-xgbe: discard rx packets with bad FCS
- vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
- watchdog: msc313e: Fix NULL pointer dereference in PM callbacks
- perf symbol: Do not use debug file as the binary type
- OPP: of: Fix potential multiplication overflow when calculating freq
- ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
- ksmbd: propagate DACL parsing errors
- ksmbd: rate limit unmapped SID errors
- [s390x] vtime: Use __this_cpu_read() / get rid of READ_ONCE()
- [s390x] time: Use jiffies instead of jiffies_64
- [s390x] ipl: Fix NULL deref in kdump without re-IPL parm block
- [s390x] ipl: Fix NULL deref in dump_reipl without re-IPL parm block
- sched_ext: Fix timer pinning and return value in scx_central
- Bluetooth: btintel_pcie: Clear automask on spurious interrupts
- workqueue: replace use of system_wq with system_percpu_wq
- workqueue: reject watchdog thresholds that overflow jiffies
- Bluetooth: btintel: validate version TLV value lengths
- Bluetooth: btintel: bound firmware ID by TLV length
- Bluetooth: hci_core: Fix race condition during device registration
- Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan
- Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect
- Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM
- Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout()
- ASoC: ab8500: Reset the audio block before configuring it
- ASoC: ab8500: Repair the DAPM capture graph
- ASoC: ab8500: Correct digital interface format setup
- ASoC: ab8500: Validate and program TDM slots correctly
- net: ethernet: oa_tc6: Interrupt is active low, level triggered.
- net: ethernet: oa_tc6: Handle the OA TC6 SPI protected mode
- net: ethernet: oa_tc6: Export standard defined registers
- net: ethernet: oa_tc6: Add the OA_TC6_ prefix to standard registers
- net: ethernet: oa_tc6: Protect skb pointer used by two different kernel
instances
- net: ethernet: oa_tc6: Improve the error recovery
- net: ethernet: oa_tc6: Disable tx queues on fatal error
- net: ethernet: oa_tc6: Fix for the wrong data type
- net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted
- igmp: convert struct ip_sf_list to RCU
- ppp: ppp_async: simplify tty disc_data access
- ppp: ppp_synctty: simplify tty disc_data access
- ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src()
- ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit
- tipc: fix NULL deref in tipc_named_node_up() on empty publication list
- tipc: Dont send random pad bytes in RESET/ACTIVATE messages
- ipv6: sr: restore network header before routing and forwarding
- af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header().
- staging: fbtft: make dirty_lock IRQ-safe
- ALSA: hda/core: Use guard() for mutex locks
- ALSA: hda: restore MFG widget enumeration after core split
- [s390x] boot: Fix physical memory search range
- [amd64] ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits
- [amd64] ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close()
- drm/xe/oa: Remove sysfs entry on idr_alloc failure in
xe_oa_add_config_ioctl()
- btrfs: detach failed sprout device from transaction update list
- btrfs: restore active device pointers after failed sprout
- bonding: alb: fix uninitialized transport header access in
alb_determine_nd()
- [riscv64] perf: RISC-V: check cpu_hw_evt before dereference in overflow
IRQ
- scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in
_base_assign_reply_queues()
- perf/core: Skip empty AUX records with only format flags
- locking/lockdep: Invalidate stale class_cache entries for zapped classes
- octeontx2-af: Fix limiting SRIOV VF count logic
- ALSA: rawmidi: Expose the tied device number in info ioctl
- ALSA: rawmidi: Show substream activity in info ioctl
- ALSA: ump: Copy FB name string more safely
- ALSA: ump: Copy safe string name to rawmidi
- ALSA: ump: Update rawmidi name per EP name update
- ALSA: ump: do not touch legacy_rmidi before it exists
- printk/nbcon: Change nbcon_irq_work to IRQ_WORK_LAZY
- ASoC: ux500: Fix MSP stream lifecycle handling
- ASoC: ux500: Propagate MSP setup errors
- ASoC: ux500: Correct MSP frame and bit clock setup
- ASoC: ux500: Validate MSP DAI configuration
- mfd: db8500-prcmu: Remove needless return in three void APIs
- mfd: db8500-prcmu: Fold dbx500 header into db8500
- ASoC: ux500: Deassert the MSP reset during probe
- ASoC: ux500: Request the MSP MMIO resource
- ASoC: ux500: Remove obsolete PRCMU QoS calls
- ASoC: ux500: Allow repeated MSP prepare calls
- ASoC: ux500: Program the MSP FIFO watermarks
- btrfs: fix transaction use-after-free in raid stripe insertion
- btrfs: fix the possible bioc_list memory leak during error
- btrfs: return proper negative error code for update_raid_extent_item()
- btrfs: zoned: finish active block group cleanup if call_zone_finish()
fails
- btrfs: send: fix lost error return value in will_overwrite_ref()
- btrfs: do not force reloc root creation during qgroup_account_snapshot()
- ipvs: fix reversed sequence option serialization
- netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace()
- tracing/probes: Fix use-after-free on field name/type of events with
multiple probes
- bpf: reject BPF_PSEUDO_FUNC reference to the main program
- bonding: do not clear curr_active_slave prematurely when releasing all
slaves
- net/rds: use wq_has_sleeper() in release_in_xmit()
- net/rds: use clear_bit_unlock() in release_refill()
- net/rds: clear cp_flags bits individually in rds_conn_path_reset()
- net/rds: tcp: don't force RDS_CONN_RESETTING over a concurrent shutdown
- net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
- net/rds: acquire the fastpath locks in rds_conn_shutdown()
- net/rds: don't let rds_conn_shutdown() consume a concurrent drop
- net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after
reset
- net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list()
- [arm64] trans_pgd: clone only the linear map that exists at runtime
- ALSA: caiaq: Fix potential double-free at error path
- bpf: Fix NULL-ptr-deref when showing a void BTF type
- bpf: Fix NULL-ptr-deref in btf_var_show()
- bpf: Mark sched_process_wait argument as nullable
- ring-buffer: Add checking nr_subbufs to persistent ring buffer validation
- nvme: remove stale namespaces by NSID range during scan
- nvme-tcp: open-code nvme_tcp_queue_request() for R2T
- nvme-tcp: defer TLS inline send to io_work
- [amd64] ASoC: Intel: avs: Clean up the bus when fetching ML caps fails
- [amd64] ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology
- [amd64] ASoC: Intel: avs: Fix unbalanced module reference count
- net: bcmasp: clear txcb->last before writing each descriptor
- net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times
- bpf: Mark bpf_btf_find_by_name_kind() as sleepable
- bpf: Mark faultable stack helpers as sleepable
- bpf: Don't predict JMP32 pointer vs zero comparisons
- thermal: sysfs: switch to use scnprintf() to suppress truncation warning
- bpf: Require MEM_PERCPU for percpu kptr stores
- bpf: Reject untrusted allocated-object pointers
- nexthop: Initialize extack in remove_nh_grp_entry()
- bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit()
- net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size
- ethtool: Symmetric OR-XOR RSS hash
- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is
requested
- net: ethtool: copy the rxfh flow handling
- net: ethtool: remove the duplicated handling from rxfh and rxnfc
- net: ethtool: require drivers to opt into the per-RSS ctx RXFH
- net: ethtool: add dedicated callbacks for getting and setting rxfh fields
- eth: nfp: migrate to new RXFH callbacks
- eth: nfp: bound the ntuple rule dump by the caller's buffer size
- eth: nfp: drop the replaced rule from the list when reprogramming fails
- net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer
size
- net: bridge: mcast: properly convert mglist to rcu
- octeontx2-af: mcs: Clear stale X2P calibration state before calibration
- ionic: use netif_txq_maybe_stop() in ionic_tx()
- net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent
partial_data heap overflow
- [s390x] ism: folio_put() after error
- vxlan: reject dynamic fdb entries that reference a nexthop id
- net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations
- net: reject oversized tx_queue_len at netlink parse time
- pds_core: fix cmd_regs access racing BAR unmap on reset
- pds_core: don't release PCI regions for VFs on reset
- [powerpc*] kexec_file: Use inclusive range checks in add_usable_mem()
- net: mctp: i3c: serialize probe with bus removal
- net/sched: defer qdisc freeing after failed creation
- net/mlx5e: Fix setting RS FEC after remapping
- net/mlx5e: Fix ETS zero BW reporting when one TC holds 100%
- net/mlx5e: Fix use-after-free race in sample_restore_put()
- net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put
- net/mlx5: E-Switch, prevent mc_list repopulation during vport disable
- net/sched: fq_pie: clamp quantum in change path
- net/sched: sfq: clamp quantum in change path
- net/sched: hhf: clamp quantum in change and init paths
- net/sched: pie: clamp psched_mtu in pie_drop_early
- net/sched: drr: clamp quantum in change class
- net/sched: ets: clamp quantum in parse and fallback paths
- net: macb: rename bp->sgmii_phy field to bp->phy
- net: macb: fix NULL pointer dereference on unbind with fixed-link
- bpf: Reject non-scalar bpf_loop iteration counts
- ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev
- hwmon: (ltc4282) Make sure clk_init_data is fully initialized
- libnvdimm: Replace namespace_match() with device_find_child_by_name()
- hwmon: Introduce 64-bit energy attribute support
- hwmon: (ina2xx) Parameterize ina2xx_data in ina226_alert_read()
- ASoC: bcm: bcm63xx: Publish the OF module aliases
- [amd64] ASoC: Intel: SST: Publish the PCI module aliases
- netfilter: nfnetlink_log: cope with concurrent instance destruction
- netfilter: ip6_tables: set F_PROTO when proto value is nonzero
- ASoC: mt6351: Publish the OF module alias
- virtio: fix use-after-free in unregister_virtio_device()
- virtio_console: do not free control-out buffers on remove
- vhost/vdpa: reject VRING_NUM larger than device max
- vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx
- vhost-vdpa: protect config_ctx from being freed under the config callback
- vdpa_sim_blk: reject out-of-range sector starts
- vdpa_sim_net: check TX pull result before RX copy
- virtio-pci: return IRQ_HANDLED after non-zero ISR
- virtio_input: reset device if input_register_device() fails
- virtio_input: stop callbacks before unregistering input device
- af_unix: Update last skb marker in manage_oob().
- af_unix: Return immediately when manage_oob() returns NULL for 0-length
buffer.
- net: ipv6: Fix UDP length overflow with PMTU discover and big MTU
- net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward
- net: ethernet: cortina: Fix budget accounting
- net: ethernet: cortina: Finish RX updates before NAPI completion
- net: ethernet: cortina: Count dropped frames as NAPI work
- net: ethernet: cortina: No mapping is a dropped rx
- net: ethernet: cortina: Count RX drops once per frame
- net: ethernet: cortina: Count RX descriptors for freeq refill
- drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER
- ALSA: hda: Introduce auto cleanup macros for PM
- ALSA: hda/common: Use cleanup macros for PM controls
- ALSA: hda/common: Use guard() for mutex locks
- ALSA: hda: Report a change when only the channel status bytes move
- idpf: account for VLAN header when parsing RSC packet header
- ice: add missing xa_destroy for sched_node_ids
- eth: ice: don't dereference pointers from TP_printk()
- Bluetooth: btusb: Fix UAF of btusb_data by rx_work
- Bluetooth: btintel_pcie: validate packet_len before skb_put_data
- Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one
- Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware
- Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset
- Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset
- net: macb: destroy the phylink instance on the probe error path
- mptcp: remove unneeded READ_ONCE() annotation
- watchdog: fix hrtimer start when pretimeout is zero
- watchdog: msc313e: Avoid division by zero
- watchdog: msc313e: Fix clock leak and spurious timer in settimeout()
- watchdog: msc313e: Enable clock before accessing hardware registers
- watchdog: msc313e: Fix spurious reset on suspend
- watchdog: msc313e: Fix undefined behavior
- watchdog: msc313e: Sync timeout value if WDT was running at boot
- net: dsa: lantiq_gswip: deduplicate dsa_switch_ops
- net: dsa: lantiq_gswip: prepare for more CPU port options
- net: dsa: lantiq_gswip: move definitions to header
- net: dsa: lantiq_gswip: fix GSWIP_MDIO_PHY_FCONTX_EN value
- net/micrel: Fix typos in micrel driver code comments
- net: ks8851: Fix receiver error in 100BASE-TX mode following software
power-down
- hwmon: (corsair-cpro) Create debugfs entries after hwmon registration
- hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown()
- hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors
- hwmon: (corsair-cpro) Remove debugfs entries when probe fails
- octeontx2-pf: reset HTB scheduler topology before freeing queues
- vxlan: initialize _md in vxlan_xmit_one()
- ppp_synctty: ensure a writeable skb header
- net: stmmac: initialize ptp_lock at probe time
- perf: Supply task information to sched_task()
- perf/core: Allow list_del during perf_event_overflow()
- perf/core: Check sample_type in perf_sample_save_callchain
- [amd64] perf/x86/intel/ds: Clarify adaptive PEBS processing
- [amd64] perf/x86/intel/ds: Remove redundant assignments to sample.period
- [amd64] perf/x86/intel/ds: Factor out PEBS group processing code to
functions
- [amd64] perf/x86/intel: Correct pt_regs->flags update for PEBS path
- net/sched: cls_route: free emptied bucket on filter move
- net/sched: cls_route: Reject handle aliasing
- net/sched: cls_route: Fix in-place replace
- net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain().
- net: sun4i-emac: fix missing of_node_put() for phy_node
- net: hinic: fix mailbox segment buffer overflow
- cxgb4: clip_tbl: Fix spelling mistake "wont" -> "won't"
- net: phy: mediatek: Re-organize MediaTek ethernet phy drivers
- net: phy: add phy_disable_eee
- net: phy: mediatek-ge: disable EEE on the MT7530 PHY
- octeontx2-af: fix PF/CGX debugfs PCI bus lookup
- net/rds: fix tcp stream corruption with large pages
- net: stmmac: TSO: Simplify the code flow of DMA descriptor allocations
- net: stmmac: fix TSO support when some channels have TBS available
- net: stmmac: add stmmac_tso_header_size()
- net: stmmac: add TSO check for header length
- net: stmmac: fix TX descriptor availability check for TSO traffic
- net: hsr: enable promiscuous mode on interlink port with fwd offload
- openvswitch: fix wrong flag value in get_ipv6_ext_hdrs()
- sunvdc: unmap LDC cookies when the descriptor send fails
- scripts/mksysmap: fix escape of '$' in the __pi_ pattern
- scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands
- ksmbd: prevent out-of-bounds reads in share config responses
(CVE-2026-89792)
- [powerpc*] ps3: Fix repository.c build failure
- [powerpc*] eeh: Fix recursive locking on devices without EEH sensitive
driver
- [amd64] crypto: x86/aria - add missing vzeroupper in AVX2 code
- [amd64] crypto: x86/aria - add missing vzeroupper in AVX-512 code
- [amd64] x86/mm: Fix user-space data loss with MADV_FREE and THP
- ipv6: fix fib6 walker UAF on seq stop
- tracing: Fix memory corruption from the histogram stacktrace modifier
- ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough
- ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf
- ALSA: usbusx2y: validate URB actual_length in interrupt callback
- dm/amdgpu: fix malformed link_settings debugfs output
- watchdog: sunxi_wdt: preserve boot-enabled watchdog
- ufs: create the root dentry after loading cylinder metadata
- ufs: validate cylinder group metadata before caching it
- tunnels: Drop stale dst when building an ICMP error for PMTUD
(Closes: #1108860)
- tick/broadcast: Plug clockevents replacement race
- tracing/user_events: Don't destroy fields when event removal fails
- tracing: Free histogram the var ref when its initialization fails
- tracing: Free histogram var refs regardless of how often they are
referenced
- tracing: Free histogram the field rejected for a bad modifier
- tracing: Let histogram values keep the percent and graph modifiers
- tracing: Keep the entry count when the histogram stats allocation fails
- accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr
- accel/ivpu: Validate firmware log buffer metadata
- accel/ivpu: Limit firmware log name prints to field size
- ASoC: sprd: validate compress buffer sizes against fixed allocations
- ASoC: sti: initialize IRQ lock before requesting IRQ
- Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev
- Bluetooth: btrtl: Don't leak return code when parsing firmware format v2
- cpufreq: zero-initialize policy cpumask before sysfs publication
- cpufreq: initialize policy rwsem before sysfs publication
- exec: do_close_on_exec() before taking exec_update_lock
- fs: don't return -EINVAL for successful nested thaw
- drm/drm_exec: fix up contended obj when num_objects is 0
- [amd64] drm/i915: Fix memory leak in query_perf_config_list()
- io_uring/net: let io_recv_buf_select return the length of the buffer
region
- ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters()
- ring-buffer: Check resize_disabled before publishing the new subbuf order
- net/sched: act_api: release all action references on NEWACTION failure
- net: hso: fix TIOCMIWAIT race
- net: mana: Reserve extra CQ slot for the fence completion CQE
- net: mpls: clear inner_protocol when the last label is popped
- net: openvswitch: fix use-after-free of the flow table mask array
- netfilter: nf_log: unregister loggers before per-net teardown
- netfilter: report NLM_F_DUMP_FILTERED when all is filtered out
- vdpa: ifcvf: Put device on unsupported feature error
- vdpa: solidrun: Free IRQs after request failure
- scripts/sorttable: Mark long_size as __maybe_unused
- fs: autofs: fix memory leak in autofs_fill_super()
- erofs: preserve LZMA decoders on resize failure
- fbdev: vfb: defer cleanup until the last reference
- inet: frags: invalidate queues before flushing them
- ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink
- ieee802154: cc2520: fix FIFOP work use-after-free
- ieee802154: hwsim: serialize pib updates to fix double-free
- ipv4: fib: bound automatic table ID allocation
- ipvs: reject invalid states in connection template sync records
- mac802154: fix use-after-free of sdata via queued RX frames
- [powerpc*] KVM: PPC: Book3S HV: Set irqfd->producer only on success
- [s390x] qeth: allow bridgeport queries despite OS_MISMATCH
- [s390x] crypto: Fix skcipher_walk return code handling in aes_s390
- [s390x] crypto: Fix use of mutex in atomic context
- [s390x] crypto: Fix missing scrub of temp buffers with AES ctr and gcm
algorithm
- [riscv64] perf: RISC-V: store available counter mask as bitmap
- [riscv64] perf: RISC-V: use BIT_ULL for u64 overflow masks
- afs: Fix incorrect free in candidate cleanup in afs_lookup_server()
- afs: Clear stale peer app data after address list changes
- hwmon: (applesmc) fix key backlight workqueue leak on register failure
- hwmon: (chipcap2) fix channels in humidity alarm notifications
- hwmon: (gpio-fan) Fix use-after-free in alarm work
- hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS
- media: hevc: add bounded tile-count helpers
- media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity
- media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity
- media: v4l2-h264: Fix memcmp() size in B1 reference list comparison
- media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
- media: verisilicon: rockchip: reject AV1 frames exceeding the tile
capacity
- media: v4l2-ctrls: validate HEVC tile counts
- media: v4l2-ctrls: validate AV1 tile counts
- bnxt_en: Only restore LRO if the device supports TPA
- bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
- bnxt_en: Propagate RX ring init failures in bnxt_init_nic()
- mptcp: options: handle MPC data + csum reqd + no csum
- mptcp: subflow: no need to copy thmac during ulp_clone
- mptcp: syncookies: remember the request backup flag
- smb: client: reject userspace cifs.idmap descriptions
- smb: client: pin DFS superblock in iterator callback
- smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
- smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
- smb: client: fix file type corruption in wsl_to_fattr()
- smb: client: avoid leaking refcount in cifs_queue_oplock_break()
- smb: client: avoid leaking refcount when cifs_sb_tlink() fails
- smb: client: fix heap overflow in DACL owner/group rewrite
- xfs: truncate quota file correctly when repairing quota file
- xfs: snapshot scrub stats when rendering them
- xfs: snapshot old AGFL before rewriting it
- xfs: signal inode btree xref error if get_rec returns an error
- xfs: reset parent pointer args before each dir tree unlink repair
- xfs: report nonexistent parents as a filesystem corruption
- xfs: preserve owner on in-memory btree creation
- xfs: log the tempip after we convert it to extents format
- xfs: initialise error in xfs_defer_finish_one()
- xfs: fix replaying dirent removals into the temporary directory
- xfs: fix name string recording in slowpath pptr tracepoints
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
- xfs: fix bnobt repair space reservation disposal failure
- xfs: fix backwards skipping logic in xrep_quota_block
- xfs: don't spin forever on zero-length dirents when salvaging them
- xfs: don't modify file attributes or poke fsnotify for dry runs
- xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails
- xfs: don't leak dqacct if rhashtable insertion fails
- xfs: destroy seen inode bitmap when we fail to add a dirpath
- xfs: count escaped corruption errors in scrub stats
- xfs: compute dquot checksum after resetting dd_lsn in repair
- xfs: bail out on bitmap errors in xrep_agfl_fill
- xfs: advance the findparent inode scan cursor while holding ILOCK
- xfs: actually recover intended file sizes in xfs_xmi_item_recover_intent
- smb: client: fix UBSAN array-index-out-of-bounds in smb2_copychunk_range
- crypto: ccp - Fix possible deadlock in SEV init failure path
- iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized
(CVE-2026-90430)
- Revert "arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries"
- Revert "arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries"
- Revert "nvme-apple: Reset q->sq_tail during queue init"
- Revert "nvme-apple: Prevent shared tags across queues on Apple A11"
- Revert "nvme-apple: Drop the PRP null check chicken bit"
- Revert "nvme: apple: Add Apple A11 support"
- Revert "slab: reset slab->obj_ext when freeing and it is
OBJEXTS_ALLOC_FAIL"
- Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems"
- perf evsel: Add per-thread warning for EOPNOTSUPP open failues
- xdrgen: Fix union declarations
- usb: xusbatm: don't rely on id table pointer arithmetic
- wifi: ath9k_htc: don't store usb_device_id
- usb: usbtmc: don't store usb_device_id
- usb: serial: spcp8x5: don't store usb_device_id
- media: as102: do not rely on id table address comparison
- net: usb: pegasus: don't rely on id table pointer arithmetic
- ALSA: us122l: Prevent write upgrades for read mappings
- i2c: smbus: reject oversized block transfers in the common path
- net: appletalk: fix NULL pointer dereference in aarp_send_ddp()
- fou: Fix use-after-free in fou_create() (CVE-2026-74496)
- xfs: initialise args->total for parent pointer updates
- bpf: fix the return value of push_stack
- netfilter: nft_set_pipapo_avx2: add missing vzeroupper
- usb: xhci: add USB Port Register Set struct
- usb: xhci: use cached HCSPARAMS1 value
- usb: xhci: simplify handling of Structural Parameters 1 values
- usb: xhci: bail out of setup if the controller is inaccessible
(CVE-2026-80861)
- fuse: fix race between interrupt and resend (CVE-2026-80860)
- [amd64] KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if
CONFIG_KVM_AMD_SEV=y
- [amd64] KVM: SEV: Make it more obvious when KVM is writing back the
current PSC index
- [amd64] KVM: SEV: Add an anonymous "psc" struct to track current PSC
metadata
- ipv6: pass proto by value to ipv6_push_nfrag_opts() and
ipv6_push_frag_opts()
- ipv6: add some unlikely()/likely() clauses in ip6_output.c
- inet: add dst4_mtu() and dst6_mtu() helpers
- ipv6: use dst6_mtu() instead of dst_mtu()
- ipv4: use dst4_mtu() instead of dst_mtu()
- tcp: clamp route advmss to TCP_MIN_MSS (CVE-2026-80847)
- net/packet: defer vmalloc TX_RING free until skbs finish (CVE-2026-80841)
- vlan: fix skb_under_panic and races when toggling HW VLAN offload
(CVE-2026-80925)
- crypto: virtio - Drop sign/verify operations
- crypto: virtio - Drop superfluous [as]kcipher_ctx pointer
- crypto: virtio - Drop superfluous [as]kcipher_req pointer
- crypto: virtio - bound the akcipher result length (CVE-2026-80836)
- net: advertise TCP MSS from the configured MTU, not the learned PMTU
- [amd64] KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa
- [amd64] KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates
- [amd64] KVM: SVM: Invalidate "next" SNP VMSA GPA even on failure
- [amd64] KVM: SEV: Disable SEV-SNP support on initialization failure
- [amd64] KVM: SVM: Move SEV-ES VMSA allocation to a dedicated
sev_vcpu_create() helper
- [amd64] KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP
guests
- crypto: atmel-ecc - avoid stale fallback key after set_secret failure
- crypto: iaa - unmap dst before software fallback on decompress
(CVE-2026-80945)
- mm: fix possible NULL pointer dereference in __swap_duplicate
- mm, swap: ratelimit bad swap entry reports
- KEYS: trusted: Fix TPM teardown ordering (CVE-2026-89763)
- mm: move hugetlb specific things in folio to page[3]
- mm: move _pincount in folio to page[2] on 32bit
- mm/gup: fix always draining LRU caches in
collect_longterm_unpinnable_folios()
- mm/migrate_device: clear stale mapping after freeing swapcache
(CVE-2026-89755)
- mm/slab: move and refactor __kmem_cache_alias()
- mm/slub: fix missing debugfs entries for caches created before sysfs init
- [amd64] x86/locking: Remove semicolon from "lock" prefix
- [amd64] x86/locking: Use sfence for wmb() if SSE is available
- xen/balloon: improve accuracy of initial balloon target for dom0
- [amd64] x86/xen: fix init of balloon stats again
- cxl/pci: Remove unnecessary CXL Endpoint handling helper functions
- cxl/pci: Remove unnecessary CXL RCH handling helper functions
- cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks
from core/pci.c
- cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
(CVE-2026-89731)
- USB: gadget: ffs: fix mm lifetime handling (CVE-2026-90045)
- usb: gadget: f_fs: Fix Use-After-Free in AIO error path (CVE-2026-90044)
- zram: fixup read_block_state()
- zram: fix out-of-bounds access in read_block_state() (CVE-2026-89719)
- zram: remove entry element member
- zram: use zram_read_from_zspool() in writeback
- zram: fix out-of-bounds access in writeback_store() (CVE-2026-89718)
- zram: switch to guard() for init_lock
- zram: set default primary compressor in zram_destroy_comps()
(CVE-2026-89717)
- netlink: introduce type-checking attribute iteration for nlmsg
- nfsd: validate sockaddr length per family in listener_set (CVE-2026-89700)
- nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
(CVE-2026-89693)
- NFSD: Rename a function parameter
- NFSD: Make nfsd_genl_rqstp::rq_ops array best-effort
- Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"
- nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
(CVE-2026-89698)
- nfsd: dedup nfs4_client_to_reclaim inserts
- nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
(CVE-2026-89708)
- nfsd: fix clock domain mismatch in clients_still_reclaiming()
(CVE-2026-89685)
- nfsd: fix netlink dumpit error handling for rpc_status_get
- nfsd: update mtime/ctime on COPY in presence of delegated attributes
- nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (CVE-2026-89676)
- nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
(CVE-2026-89667)
- NFSD: Prevent client use-after-free during admin state revocation
(CVE-2026-89660)
- nfsd: disallow file locking and delegations for NFSv4 reexport
- NFSD: Prevent client use-after-free during delegation revoke
(CVE-2026-89659)
- ceph: Remove fs/ceph deadcode
- ceph: force a cap message when a deferred revoke can't be acked
immediately
- NFSD: Guard admin state-revocation walks with NFSD_NET_UP (CVE-2026-90039)
- ceph: properly decrypt filenames in vmalloc() buffers (CVE-2026-90042)
- HID: apple: preserve keyboard backlight across T2 resume
- btrfs: move btrfs_is_empty_uuid() from ioctl.c into fs.c
- btrfs: move BTRFS_BYTES_TO_BLKS() into fs.h
- btrfs: move btrfs_alloc_write_mask() into fs.h
- btrfs: expose per-inode stable writes flag
- btrfs: update include and forward declarations in headers
- btrfs: parameter constification in ioctl.c
- btrfs: pass struct btrfs_inode to btrfs_sync_inode_flags_to_i_flags()
- btrfs: prepare btrfs_punch_hole_lock_range() for large data folios
- btrfs: use BTRFS_PATH_AUTO_FREE in can_nocow_extent()
- btrfs: add btrfs prefix to main lock, try lock and unlock extent functions
- btrfs: rename extent map functions to get block start, end and check if in
tree
- btrfs: fix extent map leak in NOCOW direct I/O write (CVE-2026-89644)
- btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
- HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
(CVE-2026-89625)
- HID: universal-pidff: stop the device when force-feedback init fails
(CVE-2026-89624)
- HID: sony: use guard() and scoped_guard()
- HID: sony: clean up device list on probe failure (CVE-2026-90041)
- HID: mcp2221: fix OOB write in mcp2221_raw_event()
- HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
(CVE-2026-89622)
- NFSD: Consolidate the revocation-path client unpin
- NFSD: Prevent client use-after-free during blocked-lock reaping
(CVE-2026-90036)
- NFSD: Prevent client use-after-free during close_lru reaping
(CVE-2026-90037)
- erofs: skip sufficiently large global buffers when resizing
(CVE-2026-89602)
- efi/cper, cxl: Prefix protocol error struct and function names with cxl_
- efi/cper, cxl: Make definitions and structures global
- acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
(CVE-2026-89589)
- cpufreq: apple-soc: Fix OPP table cleanup (CVE-2026-89572)
- bpf: Factor stackid_init function from __bpf_get_stackid
- bpf: Factor stackid_fastpath function from __bpf_get_stackid
- bpf: Factor stackid_new_bucket from __bpf_get_stackid
- bpf: Use stack id functions instead of __bpf_get_stackid
- bpf: Disable preemption in bpf_get_stackid (CVE-2026-89799)
- ACPI: TAD: Rearrange RT data validation checking
- ACPI: TAD: Split three functions to untangle runtime PM handling
- ACPI: TAD: Add locking around AML evaluations
- cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register
- ipv6: annotate data-races around devconf->rpl_seg_enabled
- ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
(CVE-2026-89561)
- ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers
- ipv6: ip6_mc_input() and ip6_mr_input() cleanups
- ip: orphan prefetched skbs before multicast forwarding (CVE-2026-89564)
- SUNRPC: Introduce xdr_set_scratch_folio()
- SUNRPC: Update svcxdr_init_decode() to call xdr_set_scratch_folio()
- sunrpc: defer rq_argp and rq_resp free until after RCU grace period
(CVE-2026-89545)
- SUNRPC: fix gssx_dec_option_array error path bugs (CVE-2026-89544)
- rpc_populate(): lift cleanup into callers
- rpc_mkpipe_dentry(): saner calling conventions
- rpc_pipe: don't overdo directory locking
- sunrpc: fix use-after-free in __rpc_clnt_handle_event and
__rpc_clnt_remove_pipedir (CVE-2026-89543)
- rpcrdma: arm rn_done before publishing the notification (CVE-2026-89798)
- svcrdma: Release transport resources synchronously
- svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
(CVE-2026-89535)
- sunrpc: Add a helper to derive maxpages from sv_max_mesg
- svcrdma: Adjust the number of entries in svc_rdma_recv_ctxt::rc_pages
- svcrdma: Reject Write/Reply chunks with segcount 0
- sched_ext: Fix inverted ops.core_sched_before() invocation
- ocfs2: validate dx_root extent list fields during block read
- ocfs2: validate directory-index entry counts when reading metadata
(CVE-2026-89492)
- mm, hugetlb: increment the number of pages to be reset on HVO
- workqueue: Update documentation as per system_percpu_wq naming
- SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
- mptcp: avoid unneeded actions on subflow reset
- mptcp: close race between scheduler and state change
- mptcp: fix bad accounting in __mptcp_subflow_push_pending()
.
[ Salvatore Bonaccorso ]
* Replace MEMORY_HOTPLUG_DEFAULT_ONLINE settings with
MHP_DEFAULT_ONLINE_TYPE_{AUTO,OFFLINE}
* udeb: Exclude i2c-hid-acpi-prp0001 from input-modules udeb
* perf tests: Change shebang for stat_bpf_counters.sh to #!/bin/bash
Checksums-Sha1:
1dc1e1c490f5f5fb9eabbd6d86d1dc5543ab55da 10935 linux-signed-amd64_6.12.111+1.dsc
81dadaaf373f88093c2ba94e3b1460e111d7f6bd 1054416 linux-signed-amd64_6.12.111+1.tar.xz
Checksums-Sha256:
9d363423b9ee129e18e04717bbe5fe0276c499c5539cfa42d88a3bf6032ba869 10935 linux-signed-amd64_6.12.111+1.dsc
8b4e81d1bf892396ab2a0d2a22a6c9dee18518cd0f7f27f6aa9c59dcfeeab850 1054416 linux-signed-amd64_6.12.111+1.tar.xz
Files:
389b7aa987201ab0a0412e660b362122 10935 kernel optional linux-signed-amd64_6.12.111+1.dsc
6c3eab3c637ee5731ffae5dc4443a40a 1054416 kernel optional linux-signed-amd64_6.12.111+1.tar.xz
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQSInBJdRTWyTRy0ztFCTVFtUgONCgUCarqgggAKCRBCTVFtUgON
CloEAP9LGw9KTqkqkCg4eP6SvKi1lL3LryLrGlegUfErIl85ZQEAvrsXa2Et9osM
K7l/asOcLPycukG2sHwxb4AovpqsbgI=
=myBQ
-----END PGP SIGNATURE-----