-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 28 Sep 2026 14:18:50 +0200 Source: linux Architecture: source Version: 6.12.111-1 Distribution: trixie-security Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1108860 Changes: linux (6.12.111-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.108 - RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp - RDMA/rxe: Fix OOB in free_rd_atomic_resources() - [amd64] KVM: x86/mmu: Check write tracking in all address spaces - ext4: don't enable DAX on new encrypted files - io_uring/io-wq: fix worker accounting when canceling creation callbacks - nvme-tcp: fix usage of page_frag_cache - HID: uhid: convert to hid_safe_input_report() - selinux: use known type instead of void pointer - selinux: avoid unnecessary indirection in struct level_datum - selinux: make more use of str_read() when loading the policy - selinux: use u16 for security classes - selinux: more strict policy parsing - selinux: reject a permission value exceeding the class permission count - selinux: require a class's permission values to cover its permission count - perf: Reject exited events as group leaders (CVE-2026-74753) - jfs: add check read-only before truncation in jfs_truncate_nolock() (CVE-2024-58094) - jfs: add check read-only before txBeginAnon() call (CVE-2024-58095) - ibmvnic: Use kernel helpers for hex dumps (CVE-2025-22104) - jfs: Fix null-ptr-deref in jfs_ioc_trim (CVE-2025-38203) - exfat: fix double free in delayed_free (CVE-2025-38206) - media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() (CVE-2025-38237) - mISDN: hfcpci: Fix warning when deleting uninitialized timer (CVE-2025-39833) - can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925) - can: j1939: add missing calls in NETDEV_UNREGISTER notification handler - can: j1939: make j1939_sk_bind() fail if device is no longer registered - smc: Fix use-after-free in __pnet_find_base_ndev(). (CVE-2025-40064) - [arm64] KVM: arm64: Prevent access to vCPU events before init (CVE-2025-40102) - smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). (CVE-2025-40139) - smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). (CVE-2025-40168) - [amd64] ASoC: nau8821: Cancel delayed work on component remove (CVE-2026-45963) - bpf: Fix use-after-free in offloaded map/prog info fill (CVE-2026-53089) - [riscv64] Fix register corruption from uninitialized cregs on error (CVE-2026-64082) - Revert "PM: sleep: Use complete() in device_pm_sleep_init()" - [amd64] ASoC: nau8821: Cancel pending work before suspend - smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). - selinux: switch two allocations to use kzalloc_objs() - ring buffer: Propagate __rb_map_vma return value to caller - veth: fix OOB txq access in veth_poll() with asymmetric queue counts - [powerpc*] hv-gpci: fix preempt count leak in sysfs show paths (CVE-2026-64070) - ksmbd: harden file lifetime during session teardown - nilfs2: correct return value kernel-doc descriptions for ioctl functions - nilfs2: reject invalid block index in GC ioctl - nfc: nci: add data_len bound checks to activation parameter extractors - HID: pidff: Rework pidff_set_time() to fix warnings - HID: pidff: Use ARRAY_SIZE macro instead of sizeof - HID: pidff: clang-format pass - HID: pidff: fix OOB write when hid->inputs is empty - HID: asus: simplify RGB init sequence - HID: asus: fix missing hid_is_usb() check - HID: ft260: validate i2c input report length - HID: ft260: fix stack-use-after-return write in I2C read race - HID: uclogic: fix use-after-free of inrange_timer on remove - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() - Bluetooth: hci_sync: Fix accept list UAF during suspend - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() - accessibility: speakup: unregister tty ldisc on later init failures - usb: xhci: Handle USB3 port events when there is one roothub - fuse: fix invalidate lock leak on setattr writeback failure - fuse: fix invalidate lock leak on open O_TRUNC DAX failure - usb: usbtest: disable dynamic ID support - usb: gadget: f_tcm: keep port count until LUN teardown completes - tls: device: fix out-of-bounds write in tls_append_frag() - gtp: serialize PDP context updates - [amd64] x86/CPU/AMD: Carve out a Zen5 models range - net/tcp: fix TCP-AO key deletion in VRFs - tcp: fix AO info use-after-free in tcp_ao_connect_init() - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer - xfrm: espintcp: fix UAF during close - xfrm: drop ESP-in-TCP packets with no ingress device - xfrm: avoid lock inversion in nat keepalive work - xfrm: ah6: validate routing header segments_left - xfrm: fix xfrm_state_construct() auth-trunc leak - xfrm: bound nat keepalive state collection - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context - ipv6: seg6: clear IPv4 control block on IPIP decapsulation - batman-adv: reject unrepresentable multicast TVLV offsets - vxlan: keep the last remote linked during FDB flush - netfilter: nf_tables: don't queue packet path object notifications - mm/swap: reject swapon() on filesystem-level encrypted files - [arm64] crypto: qcom-rng - Enable clock in hwrng case - [arm64] crypto: qcom-rng - Allow zero as a random number - [arm64] crypto: qcom-rng - Remove crypto_rng interface - [arm64] crypto: qce - fix CCM AAD buffer underallocation - [arm64] crypto: qce - Remove unsafe/deprecated algorithms - [s390x] KVM: s390: vsie: zero stale crypto bits - usb: core: Add lock to usb_wakeup_notification() - usb: core: Strengthen error handling in hub_hub_status() - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - ALSA: usb-audio: Complete cleanup after system-resume errors - USB: serial: option: fix slab OOB read in interrupt URB callback - USB: serial: spcp8x5: drop broken carrier detect support - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb - usb: usbfs: fix use-after-free of usb_device in usbdev_release() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.109 - bnxt_en: Mask the bd_cnt field in the TX BD properly (CVE-2025-22108) - md: make rdev_addable usable for rcu mode (CVE-2025-38621) - f2fs: fix potential deadloop in prepare_compress_overwrite() (CVE-2025-22127) - block: mark GFP_NOIO around sysfs ->store() (CVE-2025-21817) - drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (CVE-2025-38205) - [amd64] perf/x86/intel/uncore: Fix die ID init and look up bugs (CVE-2026-43344) - wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() (CVE-2026-53102) - wifi: ath11k: fix memory leaks in beacon template setup (CVE-2026-53113) - drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths (CVE-2026-53313) - clocksource/drivers/timer-sun4i: Advertise a real minimum delta - fs: fix user path of nested backing files - [powerpc*] pseries/iommu: switch to Default DMA window during kdump - timers/itimer: Zero-init old itimerval before copy to userspace - apparmor: fix cred UAF caused by begin_current_label_crit_section() - apparmor: fix out-of-bounds write when null terminating a label vec - include/linux/list.h: mark list_add and __list_add as __always_inline - mm/kmemleak: avoid soft lockup when scanning task stacks - mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() - mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() - mm/zswap: fix global shrinker when memory cgroup is disabled - mm: memcg: stop reclaim when a limit update is superseded - mm: mempolicy: fix automatic numa balancing for shmem - tools/compiler: match glibc 2.42 definition of __attribute_const__ - [amd64] x86/tdx: Fix off-by-one in port I/O handling - [amd64] x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg() - [amd64] x86/tdx: Fix zero-extension for 32-bit port I/O - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() - tracing/user_events: Clear copied tracing state before fork duplication - tracing: Fix crash passing ERR_PTR to kthread_stop() - tracing: Fix logged instance name on creation failure - tracing: Fix use-after-free in trace_pipe read on sub-buffer order change - tracing: Fix use-after-free with same-name named triggers - cdx: Fix double free when sysfs file creation fails - device property: fix infinite loop in fwnode_for_each_child_node() - misc: nsm: bound the device-reported response length - [powerpc*] powermac: fix OF node refcount - rapidio: mport_cdev: fix use-after-free in dma_req_free() - Revert "media: v4l2-dev: fix error handling in __video_register_device()" - serial: imx: serialize imx_uart_ports[] lifetime - staging: greybus: hid: fix SET_REPORT return value - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up - usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed - USB: phy: fsl-usb: fix missing static keywords - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() - usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion - usb: gadget: u_audio: Fix use-after-free on sound card disconnect - usb: gadget: snps_udc_plat: clean up PHY on probe deferral - usb: gadget: midi2: remove default configfs groups on teardown - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() - usb: gadget: f_fs: Prevent deadlock during ep0 read loop - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() - media: cec: stm32: prevent out-of-bounds write on RX overflow - media: vicodec: fix out-of-bounds write in FWHT encoder - nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation - of: fix out-of-bounds read in of_alias_scan() stem parser - ubifs: fix out-of-bounds read in signature length check - zsmalloc: account for handle size in class lookup - NFSD: check truncate permission under inode lock - NFSD: Encode only the status in NFS-ACL v2 GETACL error replies - NFSD: Fix off-by-one in DRC bucket pruning limit - NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock - NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check - nfsd: guard nfsd_serv deref in nfsd_file_net_dispose - NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path - pNFS: Fix EBUSY check in pnfs_layout_need_return - nfsd: release path refs on follow_down() error - nfsd: Reset write verifier when async COPY writeback fails - nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types - nfsd: sample writeback error cursor before async COPY loop - nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations - nfsd: size fh_verify server sockaddr slot by xpt_locallen - nfsd: validate symlink target length in NFSv4 CREATE - nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() - nfsd: add filehandle match check to nfsd4_delegreturn() - nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry - nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref - nfsd: check client ownership when cancelling a copy-notify stateid - nfsd: clear opcnt on compound arg release to prevent OOB read - nfsd: defer vfree of compound ops to fix rpc_status UAF - nfsd: drop the stateid, not the stateowner, on seqid_op replay retry - nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke - nfsd: fix cpntf publish race in nfs4_init_cp_state - nfsd: fix dentry ref leak on V4ROOT export filehandle lookup - nfsd: fix nfsd_file leak on inter-server COPY setup failure - nfsd: fix reply size estimate for GET_DIR_DELEGATION - nfsd: fix version mismatch loops in nfsd_acl_init_request() - nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget - nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo - nfsd: gate nfs2 setacl by argp->mask - nfsd: gate nfs3 setacl by argp->mask - nfsd: initialize copy-notify stateid before publishing it - nfsd: initialize DRC hash table before registering shrinker - nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops - nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE - nfsd: reject reclaim LOCK after RECLAIM_COMPLETE - nfsd: revoke copy-notify stateids before dropping their reference - NFSD: Prevent lock owner use-after-free during client teardown - NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup - libceph: validate OSD extent maps before cursor advance - libceph: reject buckets with mismatched CRUSH ids - ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock - ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode - ceph: bound copied dentry name length in NFS export get_name - ceph: bound MDSCapAuth path and fs_name decode in handle_session() - ceph: bound num_export_targets array for mds info v2/v3 - ceph: bound xattr value length in __build_xattrs() - ceph: do not repeat ceph_trim_dentries() if no progress possible - btrfs: drop recovered reloc root refs on recovery failure - audit: avoid dropping live tree ref on fsnotify rule autoremove - cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 - smb: client: clear ce->tgthint in free_tgts() - smb: client: fix ALIGN() overflow in symlink_data() error context loop - smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV - smb: client: harden DFS cache against invalid target hints - HID: picolcd: clamp eeprom debugfs read to bytes actually received - HID: roccat: free buffered reports when destroying device - HID: sensor: custom: Fix field sysfs group cleanup on failure - HID: mcp2221: stop device IO before hid_hw_stop - HID: mcp2221: validate report size in mcp2221_raw_event() - eventfs: Initialize ei->children and ei->list in init_ei() - fs/ntfs3: validate dirty page table on log replay - fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() - fs/ntfs3: bound page_lcns[] index by the log record - eCryptfs: bound the packet-length peek to the user buffer - ecryptfs: fix tag 11 packet exact-fit size check - ecryptfs: hold msg ctx list lock when cleaning daemon queue - ecryptfs: pass packet set buffer size to parser - ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet - ecryptfs: reject too-small tag 70 packets - ecryptfs: release message context on send failure - ecryptfs: show filename encryption options - efivarfs: Rate limit statfs() handler - fat: restore original value when fat_ent_write failed - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display - fbdev: pvr2fb: correct user pointer annotation and sentinel initializer - fbdev: ssd1307fb: defer I2C transfers from damage callbacks - fbdev: uvesafb: unregister connector callback on init failure - forcedeth: fix off-by-one when saving/restoring non-PCI config space - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration - [armhf] hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device - ACPI: APEI: Fix ERST timeout unit conversion - ACPI: APEI: GHES: fix ARM section length accounting after header - ACPI: pfr_update: fix stack buffer overflow in query_capability() - alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write() - ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes - auxdisplay: charlcd: cancel backlight work on registration failure - block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead() - Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU - Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU - Bluetooth: eir: Fix OOB read in eir_get_service_data() - bnx2x: fix double free in bnx2x_init_firmware() error path - bpf, x86: Fix per-CPU address resolution into an extended register - bpf: Disable preemption in __bpf_get_stack - bpf: Harden bloom filter sizing and indexing on 32-bit kernels - dm-era: fix shadowed superblock leak on take-snap failure - dm raid1: reserve space for NUL-terminator in build_constructor_string() - dm array: validate array block headers on read - dm array: reject an array block whose value size is not the caller's - coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior - cpufreq: schedutil: Fix rate limit overflow - cxl/pmem: Format the nvdimm serial number as unsigned decimal - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready - Bluetooth: RFCOMM: serialize security confirmation handling - Bluetooth: hci_conn: re-enable advertising only for peripheral role - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request - jbd2: bound shrinker scans by examined checkpoint buffers - jbd2: check need_resched() when skipping busy checkpoint buffers - ipip: fix skb leak in collect_md mode when metadata_dst allocation fails - ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() - ip6_gre: fix hardware header length for NBMA tunnels - ipv6: use RCU iterator to dump route exceptions - libnvdimm/labels: Prevent integer overflow in __nd_label_validate() - [arm64] mailbox: qcom-ipcc: fix duplicate channel allocation across holes - md/raid10: fix still_degraded being inverted in raid10_sync_request() - md: do overflow check for sb->bblog_shift in super_1_load() - mpls: reload header after pskb_may_pull() - mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction - nouveau/gem: reserve the bo in the info ioctl around the vma lookup - params: fix charp corruption on allocation failure - SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow - SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry - SUNRPC: svcauth_gss: enforce krb5 token minimum length - sunrpc: route to a populated pool in svc_pool_for_cpu() - SUNRPC: always drain cache_cleaner before destroying a cache_detail - SUNRPC: Check svc pool percpu counter allocation - SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat - SUNRPC: harden gss_krb5_unwrap_v2 against short tokens - SUNRPC: harden gss_unwrap_resp_priv length checks - sunrpc: init gssp_lock before publishing proc entry - SUNRPC: reject duplicate CREDS_VALUE options - SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field - SUNRPC: wait for in-flight client TLS handshake callback - svcrdma: Fix offset arithmetic in read_chunk_range - svcrdma: Fix pcl_for_each_segment for empty chunks - svcrdma: Fix unmatched rn_unregister on failed accept - svcrdma: Reject connection when transport allocation fails - svcrdma: Reject inline replies that overflow the pull-up buffer - svcrdma: Validate Read chunk positions before reconstruction - udf: reject VAT indexes equal to the entry count - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets - scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() - rpmsg: glink: smem: order FIFO read after availability check - [arm64] dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags - [arm64] dts: rockchip: fix eMMC reset polarity on PX30 Ringneck - [arm64] dts: rockchip: Fix rk3399-roc-pc-plus analog audio - [riscv64] acpi: Handle LPI architectural context loss flags - remoteproc: scp: Fix device reference leak on failed lookup - qede: Fix NULL pointer dereference in TPA fragment processing - RDMA/cxgb4: Cancel reg_work before freeing device on remove - RDMA/ucma: Lock the handler in ucma_set_ib_path() - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata - regulator: qcom-refgen: correct the regulator type to CURRENT - ring-buffer: Free cpu_buffer::free_page with subbuf_order - ring-buffer: Hold cpu_buffer::lock when resizing a subbuf - orangefs: fix double-free of trailer_buf on readdir copy failure - orangefs: skip leading spaces before parsing client debug masks - ocfs2: always run deallocs on copy-on-write completion - ocfs2: bound namelen in dlm_migrate_request_handler - ocfs2: validate lengths in dlm_mig_lockres_handler - ocfs2: validate rl_used against rl_count in refcount block validator - ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() - ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item - ocfs2: cluster: fix o2hb_dependent_users leak on pin failure - ocfs2: fix readdir position truncation on 32-bit kernels - openvswitch: only skb_tx_error() a packet we are about to drop - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion - [arm64] compat: Fix decrementing LDM/STM alignment emulation - [amd64] ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC - hwmon: (max6621) fix negative temperature offset and crit readings - hwmon: (max6621) fix temperature clamp range - lockd: pin next file across nlm_inspect_file lock-drop - lockd: fix NULL dereference on lockowner allocation failure - nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path - nvme: zero the discard fallback page - nvme-pci: disable controller on admin queue IRQ setup failure - nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone - nvme-tcp: fix host memory disclosure on R2T for a read command - nvme-tcp: reject a read that transferred too few bytes - sctp: stop processing a packet once its association is deleted - sctp: drop a chunk if its transport was removed - sctp: fix NULL deref on untransmitted RECONF completion - sctp: distinguish sequence zero from wildcard in reconf lookup - sctp: fix stream->outcnt underflow on duplicate RECONF responses - power: supply: bq24257: fix use-after-free on remove - power: supply: bq256xx: drain usb_work before freeing the charger - power: supply: bq25890: Fix power_supply reference leak - power: supply: charger-manager: register regulators before exposing sysfs - power: supply: cros_usbpd-charger: bound the EC-reported port count - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS - power: supply: lp8727: fix use-after-free in lp8727_release_irq() - power: supply: lp8788-charger: fix use-after-free on remove - power: supply: qcom_battmgr: terminate the strings from firmware - power: supply: rt9455: quiesce delayed work before teardown - power: supply: twl4030_charger: cancel workers via devm - power: supply: ucs1002: fix use-after-free on remove - power: supply: max17040: propagate register read errors - power: supply: max17040: drop incorrect I2C functionality check - power: supply: max17040: synchronize work cancellation on suspend - [s390x] cpum_cf: Handle CPU hotplug via prepare/dead callbacks - [s390x] dasd: Do not complete a failed ESE read as successful - [s390x] dasd: Guard sysfs discipline callbacks against unallocated private data - [s390x] dasd: Propagate partial completion length across ERP recovery - PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk - PCI: meson: Fix GPIO state while requesting PERST# - PCI: plda: Fix use-after-free of event IRQs during teardown - PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] - PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses - PCI/MSI: Enable memory decoding before restoring MSI-X messages - PCI/proc: Avoid spurious runtime PM wakeup on config space accesses - PCI/proc: Use file_ns_capable() when checking config space read access - PCI/proc: Warn on writes to kernel-exclusive config space regions - [amd64] iommu/amd: Put PCI device after handling PPR faults - [amd64] iommu/sva: Set handle->dev before the SVA handle is visible - [arm64] iommu/arm-smmu-v3: Manage teardown with devm - [amd64] iommu/vt-d: Fix no_iommu to disable platform opt-in - [amd64] iommu/vt-d: Force requesting ACS when tboot is enabled - [amd64] platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer - [amd64] platform/x86: ISST: Validate level in perf mask ioctls - [amd64] platform/x86: ISST: Validate socket ID in clos_assoc ioctl - mmc: via-sdmmc: stop card-detect handling on probe failure - [amd64] platform/x86: ISST: Add a NULL check for sst_inst[] - [adm64] platform/x86: ISST: Just allow 2 bits for SST feature enable - [amd64] platform/x86: ISST: Use PP level enable mask - [amd64] platform/x86: ISST: Validate logical CPU id and clos id - [amd64] platform/x86: ISST: Validate parameter for core power state - [amd64] platform/x86: ISST: Validate parameter for frequency and priority - [amd64] platform/x86: ISST: Return error during profile addition - [amd64] platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path - [amd64,arm64] platform/chrome: sensorhub: Bound the EC-reported sensor number - [amd64] platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS - [amd64] platform/x86: hp-bioscfg: advance elem past consumed array elements - [amd64] platform/x86: hp-bioscfg: bound ordered-list parsing by the package count - [amd64] platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() - [amd64] platform/x86: hp-bioscfg: fix heap OOB read on empty password write - [amd64] platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password - [amd64] platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() - [amd64] platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed - [amd64] platform/x86: hp-bioscfg: pass validated element count to package parsers - [amd64] platform/x86: hp-bioscfg: warn on element type mismatch instead of failing - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() - ipmi: ipmb: validate write message length - ipmi: si: Fix NULL pointer dereference after failed registration - net/iucv: filter frames in afiucv_hs_rcv() by ingress device - xdp: fix zero-copy frame layout - slip: fix use-after-free in sl_sync() - net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition - net: tun: bound receive headroom - net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO - net: ipa: fix stalled modem TX queue after runtime resume - net: l2tp: do not propagate multicast notification errors - net: openvswitch: fix flow mask use-after-free on flow deletion - net: openvswitch: fix nf_connlabels leak in ovs_ct_init - net: ravb: avoid dereferencing an invalid PTP clock - net: ravb: serialize PTP clock teardown - [amd64] net: thunderbolt: Release the Rx HopID that was handed out on mismatch - [amd64] net: thunderbolt: Mark the connection down when bringing it up fails - NTB: ntb_transport: Recycle TX entries before client callbacks - NTB: ntb_transport: Fail TX enqueue when the QP link is down - NTB: ntb_transport: Reject oversized TX buffers - net: ntb_netdev: Avoid double-accounting netif_rx() drops - net: ntb_netdev: Count packets dropped on RX refill failure - net/smc: do not dereference an unset send buffer on the SMC-D teardown path - net/smc: fix socket refcount leak in smc_switch_conns() - net/smc: fix use-after-free in smc_rx_pipe_buf_release() - net/smc: unregister the connection before draining the rx tasklet - net: cap advertised IP tunnel headroom - net: fix spurious TX timeout after dev_activate() - net: skbuff: don't touch shared zerocopy state in skb_tx_error() - seg6: reset IP6CB after IPv6 decapsulation - mfd: sm501: Fix potential memory leaks during remove - ALSA: 6fire: bound the MIDI event length from the device - ALSA: aloop: Check card index validity at probe - ALSA: bcd2000: clear the URB pointers on disconnect - ALSA: mpu401: Check card index validity at probe - ALSA: mts64: Check card index validity at probe - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ - ALSA: portman2x4: Check card index validity at probe - ALSA: serial-u16550: Check card index validity at probe - ALSA: virmidi: Check card index validity at probe - ring-buffer: Fix subbuf resize race with ring buffer readers - [amd64] iommu/amd: remove return value of amd_iommu_detect - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip - arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map() - dm-stats: fix a crash if allocation of per-cpu data fails - dm-switch: use WRITE_ONCE() in switch_region_table_write() - i3c: master: Fix info leak and UAF in device unregister path - i3c: master: svc: bound IBI payload to the requested max_payload_len - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop - [arm64] crypto: sun8i-ce - Remove crypto_rng interface (CVE-2026-80834) - wifi: mwifiex: Detach sync cmd buffer on interrupted wait - wifi: rtl818x: initialize eeprom_93cx6 struct to zero - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids - wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() - wifi: rtw88: pci: fix resource leak on failed NAPI setup - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex - vsock/virtio: flush works in dependency order - w1: ds28e17: reject an oversize length on an I2C block read - xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout - signal: avoid shared siginfo namespace rewrites - smack: fix cred UAF in smack_file_send_sigiotask() - taskstats: fix cpumask parsing cutting off the last character - timer: Keep debugobjects state consistent in migrate_timer_list() - udf: Fix i_lenExtents truncation on 32-bit kernels - [amd64,arm64] platform/chrome: sensorhub: Fix dropped timestamp events and log spam - mm: avoid unnecessary use of is_swap_pmd() - mm/rmap: use huge_ptep_get() in try_to_unmap_one() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.110 - net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() (CVE-2026-90049) - net: openvswitch: fix kernel-doc warnings in internal headers - openvswitch: Fix CT limit teardown use-after-free (CVE-2026-89488) - landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation (CVE-2026-89560) - xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (CVE-2026-53250) - netfs: Fix netfs_read_folio() to wait on writeback (CVE-2026-64058) - mm/page_vma_mapped: use huge_ptep_get() for hugetlb - wifi: mt76: mt7996: validate default EEPROM firmware size (CVE-2026-80933) - hugetlb: only adjust reservation during unmapping if mapcount is 0 (CVE-2026-89593) - fsnotify: Fix stale object mask after concurrent mark updates (CVE-2026-89595) - tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) - entry: Fix seccomp bypass after ptrace with TSYNC (CVE-2026-89603) - fsnotify: inotify: pass mark connector to fsnotify_recalc_mask() - net: ntb_netdev: Fix TX busy and drop handling - drm/amd/display: fix division by zero in get_estimated_bw() (CVE-2026-90035) - usb: image: mdc800: change kmalloc() to kzalloc() (CVE-2026-90034) - ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() (CVE-2026-90033) - clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset - media: usbtv: keep device alive while ALSA card exists (CVE-2026-90032) - usb-storage: ene_ub6250: fix race between scan work and probe (CVE-2026-90031) - usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() - usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop (CVE-2026-90027) - usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails - usb: typec: qcom-pmic: cancel reset_work on stop (CVE-2026-90026) - usb: typec: ucsi: displayport: Fix OOB altmode array index (CVE-2026-90025) - usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs (CVE-2026-90024) - usb: gadget: f_midi2: fix use-after-free in string attribute show path (CVE-2026-90022) - usb: gadget: f_midi: initialize work in f_midi_alloc() (CVE-2026-90021) - USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() (CVE-2026-90020) - usb: gadget: fix null pointer dereference in usb_put_function_instance() (CVE-2026-90019) - staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() (CVE-2026-90018) - staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() (CVE-2026-90017) - thermal/drivers/imx: Disable clock on runtime resume failure - thermal/drivers/qoriq: Disable clock on resume failure - ublk: clear VM_MAYWRITE on read-only ublk char device mmap (CVE-2026-89793) - spi: bcm63xx-hsspi: disable clocks on resume failure - spi: bcm63xx: disable clock on resume failure - spi: bcmbca-hsspi: disable clocks on resume failure - spi: Fix DMA mapping ownership on partial map failure (CVE-2026-90012) - scsi: target: iscsi: Reserve a terminator byte for the login payload (CVE-2026-90011) - scsi: pm8001: Use rollback index when freeing MSI-X vectors (CVE-2026-90007) - mm/damon/sysfs-schemes: kobject_del() scheme dirs - mm/damon/sysfs-schemes: kobject_del() scheme filter dirs - mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs - mm/damon/sysfs-schemes: kobject_del() scheme region dirs - mm/damon/sysfs: kobject_del() region and target (error) dirs - mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs - mm/damon/core-kunit: check region count before testing in split_at() - futex: Prevent rcuwait use-after-free during requeue PI (CVE-2026-90003) - ftrace: Synchronize the initialization of ftrace_ops - HID: bpf: serialize device reference release in struct_ops destroy path (CVE-2026-90001) - HID: rmi: fix OOB access with undersized RMI reports (CVE-2026-90000) - HID: wacom: validate report length in wacom_intuos_pro2_bt_irq (CVE-2026-89999) - dm: fix race when loading and unloading a table (CVE-2026-89998) - dm: fix resume-vs-remove race (CVE-2026-89997) - dma-direct: return struct page from dma_direct_alloc_from_pool() (CVE-2026-89995) - dmaengine: fsl-edma: tracing: no ptr dereference during log output (CVE-2026-89994) - dmaengine: dw-edma: Fix HDMA channel status register access - dmaengine: dw-edma: Complete descriptors before pausing - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (CVE-2026-89993) - cpuidle: dt_idle_genpd: kfree() the original name allocation (CVE-2026-89992) - block: flag zoned disks with GENHD_FL_NO_PART - ceph: lock mutex in ceph_mds_check_access() (CVE-2026-89990) - ata: ahci: work around lost interrupts on Marvell 88SE61xx - ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() (CVE-2026-89989) - irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout - kprobes: Protect kprobe_blacklist with RCU (CVE-2026-89988) - mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() (CVE-2026-89986) - tcp: clear sock_ops cb flags before force-closing a child socket (CVE-2026-74268) - Input: aiptek - validate raw macro indices before updating state - memcg: make the v1 soft limit knob inert - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers - [amd64] perf/x86/intel: Fix kernel address leakages in LBR stack (CVE-2026-89984) - perf trace: Factor out BPF loop body - perf trace: Refactor augmented_raw_syscalls using bpf_for - i2c: core: fix debugfs UAF on adapter removal (CVE-2026-89983) - i2c: mux: Fix channel node leak on adapter add failure (CVE-2026-89982) - [arm64] mm: Fix the lockless page-table walk in show_pte() - ALSA: rawmidi: Return the error from snd_rawmidi_input_params() - ALSA: harmony: initialize locks before requesting IRQ (CVE-2026-89980) - ALSA: pcm: Fix race between non-atomic ops and trigger-start (CVE-2026-89979) - nvme-fabrics: fix DHCHAP secret leak on parse failure (CVE-2026-89975) - nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails (CVE-2026-89974) - nvme-tcp: check the data direction of a C2HData PDU (CVE-2026-89973) - nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU (CVE-2026-89969) - nvmet-tcp: reject unsolicited H2CData PDUs (CVE-2026-89968) - Revert "irqchip/mbigen: Fix mbigen node address layout" - mm/hugetlb: fix missing migratable flag on same-node hugetlb migration - nvdimm/btt: reject an arena whose nfree is below the lane count (CVE-2026-89965) - [powerpc] kexec_file: Fix null-ptr-def in extra size calculation (CVE-2026-89963) - [powerpc] kexec_file: Prevent kexec range truncation (CVE-2026-89962) - [powerpc] mm: fix wrong addr_pfn tracking in compound vmemmap population (CVE-2026-89961) - [powerpc] pseries: Handle and log pseries-wdt registration failures - [powerpc] pseries: Move H_WATCHDOG definitions to a common header - [powerpc] crash: stop watchdogs before booting kdump kernel - [s390x] vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() (CVE-2026-89960) - [s390x] vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove - [s390x] vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove (CVE-2026-89959) - [s390x] vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL (CVE-2026-89958) - [s390x] vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed (CVE-2026-89957) - [s390x] vfio-ap: Fix NULL deref in status_show() during queue probe (CVE-2026-89955) - [s390x] vfio-ap: fix potential use of uninitialized apm_filtered bitmap - [s390x] vfio-ap: Fix required lock not held during update of ap_matrix_mdev object - mtd: afs: validate v2 image info bounds (CVE-2026-89954) - mtd: mtdoops: free page bitmap when the backing MTD is removed (CVE-2026-89953) - mtd: rawnand: validate ONFI extended parameter page sections (CVE-2026-89952) - batman-adv: fix stale receive device on merged fragments (CVE-2026-89951) - batman-adv: mcast: ensure unshared skb for multicast packets - batman-adv: mcast: linearize skbuff for packet generation (CVE-2026-89950) - batman-adv: dat: avoid unaligned fault in IP extraction (CVE-2026-89949) - batman-adv: bla: fix freeing of claims on meshif deletion (CVE-2026-89948) - batman-adv: bla: prevent CRC corruptions after claim flush - clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk - clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk - clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src - clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src - clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src - clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk - clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk - clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure - ASoC: cs35l33: drain threaded IRQ before runtime suspend (CVE-2026-89946) - ASoC: cs35l34: drain threaded IRQ before runtime suspend (CVE-2026-89945) - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (CVE-2026-89944) - AsoC: intel: sst: fix PCI device reference leak on probe failure - ASoC: loongson: Fix error handling in ACPI property parsing (CVE-2026-89943) - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get - iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig - iio: adc: pac1921: fix wrong channel used in trigger handler read - iio: buffer: Fix potential use-after-free in anonymous buffer release (CVE-2026-89942) - iio: buffer: Make IIO DMA fence release RCU-safe (CVE-2026-89941) - iio: buffer: Tie IIO dma fence lock lifetime to the fence (CVE-2026-89940) - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (CVE-2026-89939) - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (CVE-2026-89938) - iio: chemical: sgp30: Handle IAQ thread creation failure (CVE-2026-89937) - iio: dac: m62332: Fix regulator reference count imbalance (CVE-2026-89936) - iio: gyro: mpu3050: fix sign of raw angular velocity readings - iio: light: cm32181: return zero after writing calibscale - iio: light: gp2ap002: Disable regulators on resume failure - iio: light: ltrf216a: fix runtime PM reference leak in error path (CVE-2026-89934) - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (CVE-2026-89933) - iio: pressure: mpl115: Fix runtime PM cleanup - iio: srf04: fix pm_runtime handling on probe error path - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() - iio: light: opt4001: Fix power down clearing bits of the wrong register - iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() - iio: light: opt4001: Reject integration times with a non-zero seconds part - iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask - [amd64] KVM: nVMX: Always flush vpid02 on first use (CVE-2026-89932) - [amd64] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 - [amd64] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit (CVE-2026-89931) - [amd64] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter (CVE-2026-89930) - [amd64] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU (CVE-2026-89929) - [amd64] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() - [amd64] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock (CVE-2026-89927) - [amd64] KVM: x86: Serialize writes to disabled_quirks using kvm->lock - [amd64] KVM: x86: Ensure runtime reads of disabled_quirks are resolved once - [s390x] KVM: s390: Fix length check __import_wp_info() (CVE-2026-89926) - [s390x] KVM: s390: Fix memory leak in guest debug handling (CVE-2026-89925) - [s390x] KVM: s390: Fix old_data leak in guest debug error path (CVE-2026-89924) - [s390x] KVM: s390: Free guest debug data on vcpu destroy (CVE-2026-89923) - [s390x] KVM: s390: Take srcu when importing watchpoint data (CVE-2026-89922) - [s390x] KVM: s390: Zero initialize irq in reinject_machine_check - [s390x ]KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP - [s390x] KVM: s390: Restore sigset on error path - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (CVE-2026-89901) - media: amphion: Remove obsolete frame_count check in venc_start_session - media: cec: core: Fix kmemleak due to missed rc_free_device() call (CVE-2026-89900) - media: cec: disable delayed work before freeing an interrupted transmit (CVE-2026-89899) - media: cec: extron-da-hd-4k-plus: add sanity check (CVE-2026-89898) - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash - media: cec: Serialize exclusive follower delivery (CVE-2026-89897) - media: cedrus: fix memory leak in cedrus_init_ctrls() (CVE-2026-89896) - media: cobalt: Avoid freeing ALSA private data twice (CVE-2026-89895) - media: cx231xx: reject geometry changes while the VBI queue is busy (CVE-2026-89894) - media: cx23885: cancel NetUP CI work before teardown (CVE-2026-89893) - media: em28xx: defer audio-only extension registration (CVE-2026-89892) - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (CVE-2026-89891) - media: go7007: defer the ALSA v4l2 put until card release (CVE-2026-89890) - media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure - media: i2c: imx415: Return test pattern write errors - media: i2c: ov02a10: fix endpoint parsing use-after-free (CVE-2026-89888) - media: i2c: ov7740: fix use-after-destroy in remove (CVE-2026-89887) - media: intel/ipu6: fix async notifier cleanup leak on parse error (CVE-2026-89886) - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common - media: platform: mtk-mdp3: Fix SCP device refcounting (CVE-2026-89885) - media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup (CVE-2026-89884) - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing - media: nxp: imx8-isi: Correct color map between V4L2 and ISI - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks - media: rc: sunxi-cir: Unregister rc device on probe failure (CVE-2026-89883) - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (CVE-2026-89881) - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (CVE-2026-89880) - media: s2255: bound JPEG frame size before copying into the buffer (CVE-2026-89879) - media: s2255: check firmware size before reading trailing marker (CVE-2026-89878) - media: saa7164: fix cleanup on resource allocation failure (CVE-2026-89877) - media: tda18250: fix possible integer overflow (CVE-2026-89876) - media: v4l2-async: avoid deleting unlinked ASC entry on link error (CVE-2026-89874) - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (CVE-2026-89872) - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() - media: venus: fix payload size calculation in parse_raw_formats() - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (CVE-2026-89871) - media: vimc: fix pixel format lookup in enum_framesizes - media: zoran: Avoid freeing a registered video_device twice (CVE-2026-89870) - media: chips-media: wave5: Guard bit depth check with initial_info_obtained - scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers (CVE-2026-89865) - scsi: qla2xxx: Bound i2c->length in I2C bsg handlers (CVE-2026-89864) - scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check (CVE-2026-89863) - scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters - scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() (CVE-2026-89861) - scsi: qla2xxx: Initialize NVMe abort_work once at submission (CVE-2026-89860) - scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() - scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() (CVE-2026-89858) - scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject (CVE-2026-89857) - scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation (CVE-2026-89856) - scsi: qla2xxx: Serialize flash version read in reset handler (CVE-2026-89855) - scsi: qla2xxx: Fix cs84xx use-after-free on host teardown (CVE-2026-89854) - scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump (CVE-2026-89853) - scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() (CVE-2026-89852) - scsi: qla2xxx: Fix FCE trace enable parsing in debugfs (CVE-2026-89851) - scsi: qla2xxx: Don't query firmware state while chip is down (CVE-2026-89850) - scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path (CVE-2026-89849) - scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() - scsi: qla2xxx: Quiesce response IRQ before freeing request queue (CVE-2026-89848) - scsi: qla2xxx: Avoid double completion in async IOCB timeout (CVE-2026-89847) - scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846) - scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() (CVE-2026-89845) - scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort - scsi: qla2xxx: Drop vport reference under lock in report ID acquisition - scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition (CVE-2026-89844) - scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics - scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak (CVE-2026-89843) - scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started (CVE-2026-89842) - f2fs: return symlink writeback errors - f2fs: reject overlapping move range after len expansion - f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() (CVE-2026-89839) - f2fs: return writeback error from collapse range - f2fs: avoid NULL checkpoint thread access in sysfs (CVE-2026-89835) - f2fs: fix to migrate all curseg types during free_segment_range (CVE-2026-89834) - f2fs: fix i_size when pinned fallocate partially fails - f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() - f2fs: fix valid block count leak on data block allocation failure (CVE-2026-89830) - f2fs: fix to zero post-EOF data when extending file size - drm/panthor: fix firmware control interface bounds checks (CVE-2026-89825) - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure - drm/panel-edp: fix i2c adapter leak on probe failure (CVE-2026-89824) - drm: fix race between partial drm_dev_register() failure and ioctl (CVE-2026-89823) - [amd64] drm/i915: Guard against NULL driver_data in i915_pci_probe() (CVE-2026-89822) - drm/ssd130x: fix column and row end address in partial updates for ssd132x - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() - drm/ssd130x: fix column and row end address in partial updates in ssd133x - drm/hibmc: Fix list of formats on the primary plane - drm/hibmc: Use drm_atomic_helper_check_plane_state() - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (CVE-2026-89821) - drm/amd/display: validate plane degamma LUT size for private color prop (CVE-2026-89819) - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (CVE-2026-89818) - drm/gud: NUL-terminate TV mode names read from the device (CVE-2026-89817) - drm/gud: validate TV mode names before creating enum property - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value - drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used (CVE-2026-89816) - drm/amdgpu: check thunderbolt before switcheroo registration - drm/amdgpu: fix autosuspend cleanup during removal - drm/amdgpu: Skip accessing psp rum time db for APUs - drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (CVE-2026-89807) - drm/amdkfd: Reject zero-sized AQL queue allocations after size halving - drm/nouveau: unsubscribe the channel-kill event before the fence context (CVE-2026-89803) - drm/nouveau: Use write-combined maps for coherent - drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op (CVE-2026-89802) - drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE (CVE-2026-89801) - drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE (CVE-2026-89800) - afs: Fix leak of ungot volume (CVE-2026-80878) - xhci: fix lost bounce buffers on TDs spanning several ring segments (CVE-2026-90015) - ksmbd: zero pipe read compound padding (CVE-2026-89794) - net/mlx5e: xsk: Fix unlocked writing to ICOSQ (CVE-2026-64210) - nvmet-auth: Synchronize timeout work during SQ teardown (CVE-2026-89970) - mm/damon/vaddr: drop last same folio access check optimization - mm/damon/ops-common: use nr_accesses moving sum for quota score - mm/damon/paddr: drop last same folio access check reuse optimization - mm/damon/vaddr-kunit: check region count in three_regions test - mm/damon/core-kunit: handle region split failure in filter_out() - mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() - of: unittest: Fix memory leak in unittest_data_add() (CVE-2026-23137) - ksmbd: fix use-after-free in smb2_open during durable reconnect (CVE-2026-53010) - ksmbd: fix durable reconnect error path file lifetime - ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE (CVE-2026-52944) - batman-adv: dat: atomically update mac addresses (CVE-2026-93204) - batman-adv: bla: avoid CRC corruption due to parallel claim add (CVE-2026-93203) - perf sched: Fix register_pid() overflow, strcpy, and BUG_ON (CVE-2026-80671) - clk: meson: align gxbb_32k_clk_sel number of parents with actual count (CVE-2026-89947) - batman-adv: fix TX priority extraction for BATADV_FORW_MCAST - mm/damon/core: skip aging from repeated aggressive merging - Smack: Fix error in capability bypass - drm: Remove unused header in drm_dumb_buffers.c - drm: lcdif: Wait for vblank before disabling DMA - drm/v3d: Replace a global spinlock with a per-queue spinlock - drm/v3d: Clear queue->active_job when v3d_fence_create() fails (CVE-2026-93192) - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure - smack: fix incorrect task context in smack_msg_queue_msgrcv (CVE-2026-93191) - smack: simplify write handlers of sysfs entries - smack: deduplicate smackfs/{direct,mapped} file_operations - smack: restrict smackfs/{direct,mapped} values to 0-255 - sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging - [amd64] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (CVE-2026-93190) - HID: core: quiesce input in hid_hw_stop() to prevent use-after-free (CVE-2026-93189) - HID: nintendo: Fix imu_timestamp_us double increment per report - HID: roccat: bound device-supplied profile index (CVE-2026-93188) - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() - media: cec-pin: Fix event FIFO ordering - cxl: Refactor user ioctl command path from mds to mailbox - cxl/mbox: Clamp mailbox output allocation to the payload size (CVE-2026-93186) - cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() - clk: versaclock7: Fix APLL clock leak on probe failure - clk: moxart: remove unused variables, fix refcount leak - clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation - clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc - clk: nuvoton: ma35d1-pll: convert from round_rate() to determine_rate() - clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic - ASoC: rt700-sdw: always drain jack work on remove (CVE-2026-93185) - ASoC: fsl_audmix: rework runtime PM handling in probe (CVE-2026-93184) - clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller - [armhf] imx: fix device_node refcount leak in imx_src_init() - [armhf] imx: fix device_node refcount leaks in imx7_src_init() - [arm64] dts: imx93-kontron: set memory node to 0x80000000/1GiB - clk: imx: scu: drop redundant init.ops variable assignment - drm/lima: call drm_mm_init() with a valid allocation range (CVE-2026-93183) - mm/mm_init: fix incorrect node_spanned_pages - sched/fair: Fix overflow in update_tg_cfs_runnable() (CVE-2026-93182) - perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails - pinctrl: bcm2835: Don't remove an unregistered GPIO chip - riscv: kexec_file: Split the loading of kernel and others - [riscv64] kexec_file: Fix crashk_low_res not exclude bug - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define - perf test: Update all metrics test like metricgroups test - regulator: tps6594-regulator: Constify struct tps6594_regulator_irq_type - regulator: tps6594-regulator: remove interrupt_count - regulator: tps6594-regulator: remove hardcoded buck config - regulator: tps6594-regulator: refactor variant descriptions - regulator: tps6594: Fix device node reference leaks in multiphase loop - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (CVE-2026-93178) - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (CVE-2026-93177) - tools/bpf/bpftool: Reset vmlinux BTF after map commands - tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands - bpf: Copy per-CPU map value padding in copy_map_value_long() (CVE-2026-93174) - bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks (CVE-2026-93173) - mm: add build-time option for hotplug memory default online type - mm: convert memory block states (MEM_*) macros to enum - mm: change type of state in struct memory_block - mm: name the anonymous MMOP enum as enum mmop - mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug (CVE-2026-93172) - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (CVE-2026-93170) - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure - csky: Fix a4/a5 restoration in syscall trace path (CVE-2026-93167) - platform/chrome: sensorhub: Fix memory overread in ring handler (CVE-2026-93165) - wifi: rtw89: fix HE extended capability length check - perf cs-etm: Queue context packets for frontend - perf cs-etm: Fix thread leaks on trace queue init failure - [amd64] perf/x86/amd/uncore: Add group validation - perf vendor events amd: Update Zen 5 core events - hwrng: core - fix rng list on registration error (CVE-2026-93163) - crypto: qat - cancel work on re-enable SR-IOV timeout (CVE-2026-93162) - crypto: qat - clear AES key schedule from stack (CVE-2026-93161) - crypto: atmel-ecc - replace min_t with min - crypto: atmel-ecc - clean up and improve ECDH comments - crypto: atmel-ecc - reject hardware ECDH without a public key (CVE-2026-93160) - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (CVE-2026-93159) - crypto: sa2ul - stop probe if context pool creation fails (CVE-2026-93158) - crypto: rk3288 - fail ahash requests on HASH idle timeout (CVE-2026-93156) - crypto: keembay - Fix AEAD unregister count in error path (CVE-2026-93155) - nvme-apple: Use acquire/release for queue enabled state (CVE-2026-93152) - nvmet-rdma: factor out response resource cleanup - nvmet-rdma: fix response resource leak on queue teardown (CVE-2026-93151) - bus: ti-sysc: Fix /chosen node reference leak - PM: sleep: Fix off-by-one in wakelocks number limit check - cgroup/cpuset: Make nr_deadline_tasks an atomic_t (CVE-2026-93150) - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name - [arm64] dts: qcom: hamoa: Fix clocks for HSPHYs - bus: qcom-ebi2: Simplify with scoped for each OF child loop - bus: qcom-ebi2: Fix clock leak on probe failure - wifi: mac80211_hwsim: avoid NULL skb in stop queue drain (CVE-2026-93149) - staging: greybus: audio: correct sscanf() return value check - staging: sm750fb: gate dualview dataflow using g_dualview - staging: sm750fb: Add missing Kconfig dependency - greybus: audio: bound the topology section sizes against the fetched size - staging: fbtft: Use sysfs_emit_at() to print to sysfs file - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown - staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown - staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions - staging: octeon: replace pr_warn with dev_warn in fill and rx paths - staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() - irqchip/gic-v3-its: Fix memleak in its_probe_one() - irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() - clocksource: Unregister subsystem on device registration failure - y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 - timekeeping: Account for monotonicity adjustment in ntp_error - clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status - clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains - clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() (CVE-2026-93145) - [arm64] dts: qcom: sc8180x-primus: Rename regulator nodes - [arm64] dts: qcom: sc8180x-primus: Describe the display power net - [arm64] dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes - [arm64] dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net - perf data convert json: Fix trace_seq memory leak in process_sample_event() - thermal/drivers/rcar: Fix error checking in probe() (CVE-2026-93142) - usb: typec: ucsi: unregister debugfs entries on teardown - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (CVE-2026-93141) - udf: Mark LVID buffer as uptodate before marking it dirty (CVE-2026-93140) - perf vendor events amd: Reintroduce deprecated Zen 5 core events - perf dso: Fix kallsyms DSO detection with fallback logic - bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux (CVE-2026-93138) - efi: fix stale reference to efi_recover_from_page_fault() - bpf: Fix use-after-free on mm_struct in bpf_find_vma() (CVE-2026-93137) - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (CVE-2026-93136) - iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX - iommu/msm: Return -ENOMEM on memory allocation failure in probe - [amd64] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors - [amd64] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC - [amd64] iommu/amd: Fix false positive in SB IOAPIC IVRS validation - leds: pca9532: Fix inverted GPIO output polarity - printk/panic: Add option to allow non-panic CPUs to write to the ring buffer. - panic: introduce helper functions for panic state - panic/printk: replace this_cpu_in_panic() with panic_on_this_cpu() - panic/printk: replace other_cpu_in_panic() with panic_on_other_cpu() - printk: Introduce console_flush_one_record - printk: Fix possible console use-after-free (CVE-2026-93134) - [riscv64] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination - [riscv64] ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() (CVE-2026-93133) - [riscv64] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling (CVE-2026-93132) - [amd64] platform/x86: dell-privacy: Fix race condition (CVE-2026-93131) - [amd64] platform/x86: dell-wmi-base: Fix resource leak on module load failure (CVE-2026-93130) - [amd64] platform/x86: lg-laptop: Drop debug-only ACPI notify handler - [amd64] platform/x86: lg-laptop: Convert ACPI driver to a platform one - [amd64] platform/x86: lg-laptop: Fix LED resource handling (CVE-2026-93128) - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (CVE-2026-93126) - hwspinlock: propagate errno when registering single lock - serial: ma35d1: Fix OF node reference leaks in console init - serial: qcom-geni: do not advance stale DMA completions (CVE-2026-93123) - usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths (CVE-2026-93121) - usb: gadget: configfs: fix out-of-bounds read of qw_sign (CVE-2026-93120) - usb: ljca: bound bank_num in ljca_enumerate_gpio() (CVE-2026-93119) - usb: gadget: aspeed_udc: check endpoint DMA allocation (CVE-2026-93118) - USB: make single lock for all usb dynamic id lists - USB: make to_usb_driver() use container_of_const() - usb: fix UAF when probe runs concurrent to dyn ID removal (CVE-2026-93117) - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (CVE-2026-93115) - platform/surface: acpi-notify: Check ACPI companion before use (CVE-2026-93114) - usb: mtu3: allow system suspend during active gadget connection - usb: renesas_usbhs: Fix power-off ordering on unbind - drm/panel: samsung-s6d16d0: Power off on prepare failure - perf metricgroup: Fix metric expression copy leaks - soc: qcom: rpmh-rsc: manage PM notifiers with devres - bus: qcom-ebi2: use managed resources for clocks and children - clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK (CVE-2026-93113) - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE - RDMA/core: Wait for RCU callbacks before unloading ib_core (CVE-2026-93110) - RDMA/mlx5: Drain RCU callbacks during module teardown (CVE-2026-93109) - RDMA/ipoib: Drain RCU callbacks during module teardown (CVE-2026-93108) - RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state (CVE-2026-93107) - crypto: ccp - Fix memory leak in SEV INIT_EX path - hwrng: ks-sa - Fix runtime PM cleanup on registration failure - xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full (CVE-2026-89783) - ALSA: hpi: Check transport errors during HPI6000 adapter initialization - pmdomain: bcm: bcm2835: handle genpd provider registration errors - misc: rtsx_usb: avoid USB I/O in runtime autosuspend - RDMA/hfi1: Preserve unit 0 on allocation failure (CVE-2026-93103) - RDMA/hfi1: Free RX data on late probe failure (CVE-2026-93102) - RDMA/hfi1: Remove redundant PCI device ID validation - RDMA/hfi1: Create workqueues before device initialization - RDMA/hfi1: Stop flushing the global IB workqueue - RDMA/hfi1: Initialize debugfs after probe completes - ASoC: apple: mca: increase SERDES reset delay - isofs: fix out-of-bounds page array access on empty zisofs block (CVE-2026-89778) - media: v4l2-async: Unregister sub-device if asc_list is empty (CVE-2026-93101) - rpmsg: glink: remove duplicate code for rpmsg device remove - rpmsg: glink: fix deadlock in endpoint destroy during driver detach (CVE-2026-93098) - cxl/memdev: Fix firmware upload exact-fit handling - cxl/mbox: Break poison list loop on an empty payload (CVE-2026-93097) - cxl/pci: Honor -EPROBE_DEFER from component register setup - fs/ntfs3: Add more checks in mi_enum_attr (part 2) - fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() (CVE-2024-52560) - fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list - fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() (CVE-2026-90048) - hfsplus: validate thread record before delete key rebuild (CVE-2026-93095) - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate - [amd64] x86/entry/fred: Encode frame pointer on entry - firmware: arm_scmi: Publish channel state before callbacks (CVE-2026-93093) - firmware: arm_scmi: Unregister device notifier before IDR teardown (CVE-2026-93092) - firmware: arm_scmi: Quiesce notifications before teardown (CVE-2026-93091) - firmware: arm_scmi: Clean up channels on setup failure (CVE-2026-93090) - firmware: arm_scmi: Free transport channel on IDR failure (CVE-2026-93089) - firmware: arm_scmi: Avoid IDR updates while cleaning channels (CVE-2026-93086) - firmware: arm_scmi: Reject out of range DT protocol IDs (CVE-2026-93085) - firmware: arm_scmi: Use channel ID for transport teardown - firmware: arm_scmi: Protect device request lookup with RCU - firmware: arm_scmi: Drop handle on protocol bind failures (CVE-2026-93084) - firmware: arm_scmi: Unwind TX receiver mailbox setup failure (CVE-2026-93083) - firmware: arm_scmi: Unwind P2A receiver mailbox setup failure (CVE-2026-93082) - libnvdimm/labels: Bound the on-media label size before the shift - dax: read holder_ops once in dax_holder_notify_failure() (CVE-2026-93073) - cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() - PCI: xgene: Drop XGENE_PCIE_IP_VER_UNKN - PCI: xgene: Drop unnecessary OF node reference - irqchip/renesas-irqc: Fix generic interrupt chip leak on remove (CVE-2026-93072) - media: i2c: rdacm21: Fix missing media_entity_cleanup() - media: bcm2835-unicam: Fix asc leaked in error/remove path (CVE-2026-93071) - media: ipu6: Do not free aux device pdata after init (CVE-2026-93070) - drm/amd/display: Remove unused-but-set variable hubp from - cpufreq: intel_pstate: Fix setting minimum P-state at init time - cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev - drm/bridge: tc358767: clamp the reported AUX read size to the request (CVE-2026-93067) - [arm64] dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO - [arm64] dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin - [arm64] dts: qcom: sm8250: sort out Iris power domains - [arm64] dts: qcom: sm8250: correct frequencies in the Iris OPP table - perf jevents: Add more components to the metric sorting order - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (CVE-2026-93065) - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (CVE-2026-93064) - wifi: iwlwifi: mei: check SAP message length before reading it (CVE-2026-93063) - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (CVE-2026-93062) - wifi: iwlwifi: mei: pass correct argument to function - gpu: host1x: Fix offset calculation in trace_write_gather - gpu: host1x: Avoid stack over-read in debug output helpers (CVE-2026-93061) - drm/msm/a6xx: Fix stale rpmh votes after suspend - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping - ACPI: processor: idle: Expand _LPI package sanity checks - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (CVE-2026-93056) - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 - UDF symlink pathComponent header OOB read (CVE-2026-93055) - uio: Fix stale info pointer in failed registration path (CVE-2026-93054) - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (CVE-2026-93053) - misc: bcm-vk: Use acquire/release for msgq_inited (CVE-2026-93052) - misc: rtsx: add missing write register handling - misc: ad525x_dpot: use driver core groups for sysfs files (CVE-2026-93051) - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) - ppdev: prevent overflow when setting port timeout - ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove (CVE-2026-93050) - char: xilinx_hwicap: unregister class on init errors - vfio/pci: clear vdev->msi_perm after freeing it on init failure (CVE-2026-89777) - mtd: mtdswap: Avoid freeing registered blktrans device twice (CVE-2026-93049) - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (CVE-2026-93048) - perf ui hists: Fix uninitialized stack memory free on pstack allocation failure - software node: Fix software_node_get_reference_args() with index -1 (CVE-2026-93046) - driver core: soc: Unregister bus on early device registration failure - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg - bpf: Reject arena frees below the arena base (CVE-2026-93045) - dmaengine: dw-edma: Terminate all descriptors without callbacks (CVE-2026-93042) - dmaengine: dw-edma: Serialize abort state updates (CVE-2026-93041) - dmaengine: dw-edma: Serialize channel state checks (CVE-2026-93040) - dmaengine: dw-edma: Clear stale requests on termination - ASoC: meson: Keep link pointers valid on realloc failure (CVE-2026-93039) - phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe - phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe - [arm64] dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins - [arm64] dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe - RDMA/hfi1: Propagate sdma_txinit_ahg() errors (CVE-2026-93037) - RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] (CVE-2026-92525) - RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters - kcsan: avoid unintended access checking in NMIs - [arm64] dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 - irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() (CVE-2026-92524) - RDMA/nldev: validate dynamic counter attribute length (CVE-2026-92523) - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer - ACPI: processor: validate MADT IOAPIC entry bounds (CVE-2026-92522) - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (CVE-2026-92521) - ext4: fix circular lock dependency in ext4_ext_migrate - ext4: fix out-of-bounds read in ext4_read_inline_dir() (CVE-2026-89786) - ext4: skip extra isize expansion during mount to prevent deadlock - libbpf: Search /lib64 and /lib in resolve_full_path() - [riscv64] bpf: Fix memory leak in bpf_jit_free (CVE-2026-92519) - ACPI: battery: Adjust charging status validation check - bpf: Preserve unique-field state across nested structs (CVE-2026-92515) - RDMA/srpt: Pass the mapped task attribute to target_init_cmd() - PCI: j721e: Fix incorrect max_lanes for J7200 - RDMA/erdma: Fix CEQ tasklet use-after-free on removal (CVE-2026-92514) - RDMA/restrack: Fix typos in the comments - RDMA/nldev: Fix locking when accessing mr->pd (CVE-2026-74334) - RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations - RDMA/core: Fix use after free in ib_query_qp() (CVE-2026-92512) - RDMA/core: Fix potential use after free in ib_destroy_cq_user() (CVE-2026-92511) - RDMA/core: Fix potential use after free in ib_destroy_srq_user() (CVE-2026-92510) - RDMA/core: Fix potential use after free in counter_release() (CVE-2026-92509) - RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() - RDMA/core: Fix potential use after free in ib_free_cq() (CVE-2026-92508) - RDMA/core: Fix potential use after free in ib_dealloc_pd_user() (CVE-2026-92507) - firmware: arm_scmi: Fix requested device removal race (CVE-2026-92506) - [arm64] iommu/qcom: Remove sysfs device on probe failure path - [arm64] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() - thermal: intel: int3400: clean up ODVP on probe failures (CVE-2026-92504) - ext4: clear stale xarray tags on folios skipped during writeback (CVE-2026-92502) - ext4: drain in-flight DIO before buffered write fallback (CVE-2026-92501) - wifi: ath6kl: avoid buffer overreads in WMI event handlers (CVE-2026-92498) - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (CVE-2026-92497) - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (CVE-2026-92496) - RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap (CVE-2026-92495) - ext4: fix buffer_head leak in ext4_init_orphan_info (CVE-2026-92494) - ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() (CVE-2026-89787) - cpufreq/amd-pstate: Store the boost numerator as highest perf again - ACPI: CPPC: Add IS_OPTIONAL_CPC_REG macro to judge if a cpc_reg is optional - ACPI: CPPC: Optimize cppc_get_perf() - ACPI: CPPC: Rename cppc_get_perf() to cppc_get_reg_val() - ACPI: CPPC: Add cppc_set_reg_val() - ACPI: CPPC: Refactor register value get and set ABIs - ACPI: CPPC: Modify cppc_get_auto_sel_caps() to cppc_get_auto_sel() - cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems - firmware: arm_scmi: Roll back partial protocol table registration (CVE-2026-92491) - firmware: arm_scmi: Unrequest devices if driver registration fails (CVE-2026-92490) - perf cs-etm: Flush thread stacks after decoder reset - perf cs-etm: Avoid truncating AUX buffer sizes to int - xfrm: Fix skb double-free in xfrm_dev_direct_output() (CVE-2026-92489) - RDMA/erdma: Probe the erdma RoCEv2 device - RDMA/erdma: Add GID table management interfaces - RDMA/erdma: Add the erdma_query_pkey() interface - RDMA/erdma: Add address handle implementation - RDMA/erdma: Add erdma_modify_qp_rocev2() interface - RDMA/erdma: Refactor the code of the modify_qp interface - RDMA/erdma: Add the query_qp command to the cmdq - RDMA/erdma: Fix incorrect response returned from query_qp - RDMA/erdma: Support non-sleeping erdma_post_cmd_wait() - RDMA/erdma: complete object teardown when the destroy command fails (CVE-2026-92488) - PM: hibernate: Fix memory leak in snapshot_write_next() error path - leds: pca9532: Fix phantom device registration on missing hardware - drm/tve200: add OF module alias for autoloading - netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet - fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init (CVE-2026-89785) - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() - [arm64] dts: rockchip: Fix Gru WLAN sideband interrupt - cxl/region: Fix use-after-free in find_pos_and_ways() error path (CVE-2026-92484) - pinctrl: mediatek: Add EINT support for multiple addresses - pinctrl: mediatek: Fix the invalid conditions - pinctrl: mediatek: eint: Fix invalid pointer dereference for v1 platforms - pinctrl: mediatek: free EINT resources on unbind (CVE-2026-92481) - tools/build: Add bpftool-skeletons feature test - tools/build: Allow versioning of all LLVM tools defined in Makefile.include - power: supply: sbs-battery: Use a per-device serial number buffer - scsi: ufs: debugfs: Reserve space for a string terminator (CVE-2026-92477) - crypto: keembay - Initialize completion before requesting IRQ (CVE-2026-92476) - crypto: keembay - publish OF module alias for OCS AES/SM4 - RDMA/mlx5: Fix integer overflow of user QP buffer size (CVE-2026-90435) - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe - isofs: release zisofs block pointer buffer head (CVE-2026-90434) - spi: oc-tiny: switch to managed controller allocation (CVE-2026-90433) - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() - remoteproc: core: Drop redundant initialization of 'ret' in rproc_shutdown() - remoteproc: Allow shutdown of crashed processors - remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() - remoteproc: Prevent crash handling to race with rproc_del() (CVE-2026-90431) - staging: rtl8723bs: use kfree_sensitive() for key material - fs/ntfs3: reject restart table growth beyond U16_MAX entries (CVE-2026-89782) - iommu/tegra241-cmdqv: Use request_threaded_irq - iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs (CVE-2026-90428) - iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs (CVE-2026-90426) - RDMA/efa: Fix PBL chunk length computation - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing - [arm64] dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix - clk: tegra: tegra124-emc: put EMC node on register failure - clk: palmas: Manage external-control prepare with devm - clk/x86: pmc_atom: add kasprintf return value check - clk: mediatek: mt8135: Fix inverted gate control for devapc_ck - clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs - nilfs2: fix infinite loop in nilfs_clean_segments() (CVE-2026-90420) - nilfs2: prevent out-of-bounds read in super root block parsing (CVE-2026-90419) - nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch (CVE-2026-90418) - scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches. - RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs (CVE-2026-90416) - RDMA/mlx5: Send cong param changes to the resolved port mdev - RDMA/cxgb4: free STAG index when TPT entry write fails (CVE-2026-90415) - IB/isert: reject PDUs declaring more data than was received (CVE-2026-90414) - IB/isert: reject login PDUs declaring more data than was received (CVE-2026-90413) - nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request (CVE-2026-90411) - spi: davinci: switch to managed controller allocation (CVE-2026-90410) - wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() (CVE-2026-90407) - PCI: starfive: Fix Runtime PM handling and teardown ordering - PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure - platform/chrome: cros_ec_debugfs: Unregister panic notifier (CVE-2026-90404) - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (CVE-2026-90403) - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET - bus: mhi: host: Fix controller cleanup on EDL sysfs failure (CVE-2026-90402) - md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency - md/raid5-ppl: fix use-after-free in ppl_do_flush() - md: ensure resync is prioritized over recovery - md: allow removing faulty rdev during resync - md: rename recovery_cp to resync_offset - md: add a new recovery_flag MD_RECOVERY_LAZY_RECOVER - md/raid5: protect lockless recovery_offset accesses during reshape - tools/nolibc/powerpc: mark ctr and xer as clobbered by system call - md: recheck spare changes before starting sync (CVE-2026-90400) - slab: simplify init_kmem_cache_nodes() error handling - slab: Make slub local_(try)lock more precise for LOCKDEP - slab: Reuse first bit for OBJEXTS_ALLOC_FAIL - wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() (CVE-2026-90399) - wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() (CVE-2026-90398) - rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs - [arm64] dts: qcom: msm8998: Don't pull-up I2C pins by default in sleep - [arm64] dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property - [arm64] dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes - clk: qcom: gcc-qcm2290: don't park QUP RCGs upon registration - [arm64] dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en - firmware: qcom_scm: Add API to get waitqueue IRQ info - firmware: qcom_scm: Support multiple waitq contexts - firmware: qcom: scm: add trace events for the SMC call interface - firmware: qcom: scm: instrument SMC call path with tracepoints - firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published (CVE-2026-90397) - firmware: qcom: scm: Fix tzmem state on probe retry - [arm64] dts: qcom: sm8250-xiaomi-elish: correct the board ID - [arm64] dts: qcom: sc8180x: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sdm845: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8150: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8250: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8350: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8450: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8550: Fix the PCIe iommu-map entries - [arm64] dts: qcom: sm8650: add OPP table support to PCIe - [arm64] dts: qcom: sm8650: Fix the PCIe iommu-map entries - power: supply: isp1704_charger: cancel work on remove (CVE-2026-90395) - power: supply: sc2731_charger: cancel work on remove (CVE-2026-90394) - bpf: Fix potential UAF in bpf_netns_link_update_prog (CVE-2026-90393) - bpf: Fix potential UAF when reading bpf link info (CVE-2026-90392) - clk: qcom: gpucc-qcm2290: Park RCG's clk source at XO during disable - clk: qcom: Return expected ENOMEM error on dynamic allocation failure - md/bitmap: resume array on backlog_store() error path (CVE-2026-90390) - md: remove unused mddev argument from export_rdev - md: skip redundant raid_disks update when value is unchanged - md: scope memalloc_noio to allocation critical sections (CVE-2026-90389) - iommu/dma: Check atomic pool allocation result directly (CVE-2026-90388) - swiotlb: Preserve allocation virtual address for dynamic pools (CVE-2026-90387) - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (CVE-2026-90386) - i3c: master: Fix device_register() error path - md: merge mddev has_superblock into mddev_flags - md: merge mddev faillast_dev into mddev_flags - md: merge mddev serialize_policy into mddev_flags - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (CVE-2026-90385) - locking/lockdep: Fix NULL pointer dereference in __lock_set_class() - [powerpc*] crash: Fix possible memory leak in update_crash_elfcorehdr() - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() - misc: sgi-gru: remove interrupt-context page-table walks (CVE-2026-90383) - fanotify: report full event length for FIONREAD - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (CVE-2026-90382) - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 - wifi: mt76: add init_wiphy callback - wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete (CVE-2026-90380) - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (CVE-2026-90378) - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU - wifi: mt76: fix non-AQL packet accounting for MLO stations (CVE-2026-90375) - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] (CVE-2026-90374) - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset - wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear (CVE-2026-90373) - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (CVE-2026-90372) - wifi: mt76: mt7996: don't report a zero TX bitrate - wifi: mt76: mt7915: write RX header translation bit to the correct register - wifi: mt76: fix stranded frames in mt76_txq_schedule_pending - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie - wifi: mt76: check txfree done event on the WED hw path - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (CVE-2026-90370) - wifi: mt76: mt7915: unwind state on add_interface failure (CVE-2026-90368) - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (CVE-2026-90366) - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields - wifi: mt76: only consume the WO drop bit on WED v2 devices - ACPI: processor: idle: Optimize ACPI idle driver registration - ACPI: processor: Unregister cpufreq notifier on init failure (CVE-2026-90364) - perf: arm_spe: Make wakeup range check overflow safe - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (CVE-2026-90362) - wifi: ath11k: fix leak in ath11k_service_ready_ext_event() (CVE-2026-90361) - regulator: core: use system_freezable_wq for init complete work (CVE-2026-90360) - perf machine: Fix NULL parent dereference in fork event processing - perf machine: Guard against NULL strlist in machines__findnew() - perf machine: Use snprintf() for guestmount path construction - perf machine: Check snprintf truncation in machines__findnew() - perf machine: Don't abort guest map creation on first inaccessible dir - perf machine: Reset errno before strtol in guest kernel map creation - perf machine: Free scandir entries in guest kernel map creation - perf machine: Check snprintf truncation for guest kallsyms path - bpf, x86: Fix trampoline stack size for 128-bit arguments (CVE-2026-90358) - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (CVE-2026-90357) - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (CVE-2026-90354) - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (CVE-2026-90353) - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (CVE-2026-90352) - wifi: mt76: mt7996: fix reg addr remap when addr is 0 - wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 - wifi: mt76: mt7915: report RX chain signal for all RX paths - wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band - wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (CVE-2026-90348) - iommu/arm-smmu-v3: Convert to use atomic poll timeout - perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register - wifi: mac80211: send TWT teardown to peer after setup TX failure - wifi: zd1211rw: reject secondary interfaces to prevent conflicts - wifi: mac80211: skip unused probe response countdown offsets - wifi: mac80211: disconnect on CSA to channel 0 (CVE-2026-90344) - firmware: google: Add bounds checks in coreboot_table_populate() - firmware: coreboot: Validate table bounds (CVE-2026-90341) - [powerpc] smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass - [powerpc] irq: Fix missing r2 clobber in PCREL inline assembly - serial: amba-pl011: unprepare console clock on unregister - tty: clear cdev pointer after cdev_add() failure (CVE-2026-90334) - HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver - HID: synchronize input before cleaning up a failed probe (CVE-2026-90329) - HID: i2c-hid: Fix "(null)" output when reading report descriptor fails - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure - HID: lg4ff: validate report length before fixed offsets - perf thread-stack: Fix heap buffer overflow on branch stack wrap copy - perf auxtrace: Fix queue grow overflow and old array leak - perf intel-pt: Fix off-by-one in auxtrace_info minimum size check - perf intel-bts: Fix off-by-one in auxtrace_info minimum size check - iio: light: tsl2772: fix ALS calibscale readback - iio: light: isl29028: return zero in write_raw() on success - iio: light: tsl2583: return zero in write_raw() on success - net: stmmac: Skip PHY attach if custom PCS is in use - phonet: pep: do not write beyond optlen in getsockopt (CVE-2026-90327) - blk-cgroup: skip dying blkg in blkcg_activate_policy() (CVE-2026-90325) - block/blk-stat: drain per-cpu callback stats over possible CPUs - block/blk-iocost: collect per-cpu latency stats over possible CPUs - block/kyber-iosched: flush per-cpu latency buckets over possible CPUs - ublk: check for ublk_unmap_io() returning 0 - o2hb_region_dev_store(): avoid goto around fdget()/fdput() - ocfs2/cluster: keep heartbeat local node stable (CVE-2026-90322) - lib/string: fix memchr_inv() for large ranges - pps: don't try to wait for negative timeouts in PPS_FETCH - pps: clients: gpio: Bypass edge's direction check when not needed - pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler - pps-gpio: remove dead capture_clear code - rapidio: clear mport->net when rio_add_net() fails (CVE-2026-90319) - fat: release buffer head after rebuilding parent (CVE-2026-90318) - riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller - drm/omap: dsi: Do not copy isr table (CVE-2026-90316) - [arm64] dts: qcom: agatti: Add missing CX power domain to DISPCC - remoteproc: Move resource table data structure to its own header - remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() - remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() (CVE-2026-90314) - bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed (CVE-2026-90313) - [arm64] dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies - scripts/tags.sh: Prevent binary files appearing in cscope.files - modpost: prevent leak when early return no suffix .o in read_symbols() - RDMA/erdma: Hold CQ references when processing EQ events (CVE-2026-90309) - RDMA/erdma: Hold QP references for AE and CM processing (CVE-2026-90308) - RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ (CVE-2026-90307) - [armhf] 9481/2: breakpoint: CFI breakpoints only on demand (CVE-2026-90306) - [armhf] 9485/1: mm: acquire mmap write lock around show_pte() for user faults (CVE-2026-90303) - ocfs2: synchronize heartbeat callbacks with o2net teardown (CVE-2026-90302) - clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 - drm/sun4i: vi scaler: Fix coefficient selection - of: property: add of_graph_get_next_port() - of: property: add of_graph_get_next_port_endpoint() - drm/sun4i: tcon: Set output mux for DSI and LVDS - drm/sun4i: tcon: Drop TCON TOP device reference (CVE-2026-90298) - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control - drm/sun4i: crtc: Propagate layer initialization error (CVE-2026-90297) - drm/sun4i: tcon: Drop remote endpoint reference - drm/sun4i: dw-hdmi: Drop TCON TOP port reference - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz - cpufreq: imx6q: fix devres accumulation across driver rebind (CVE-2026-90296) - cpufreq: imx6q: fix out-of-bounds write when probed more than once (CVE-2026-90295) - IB/isert: delay the final Login Response until the session is registered (CVE-2026-90294) - IB/isert: post the full-feature receive buffers after session registration (CVE-2026-90293) - RDMA/siw: Fix use-after-free in siw_accept() (CVE-2026-90292) - module: replace use of system_wq with system_dfl_wq - module: use strscpy() to copy module names in stats and dup tracking - module/dups: Inform duplicate requests about the result directly - module/dups: Fix use-after-free in kmod_dup_req lifetime handling (CVE-2026-90291) - RDMA/erdma: restrict the driver to little-endian systems - wifi: mac80211: skip default WMM setup for AP_VLAN links - [arm64] hibernate: mask DAIF before restoring hibernated kernel - [arm64] hibernate: Restore DAIF state on error (CVE-2026-90290) - mfd: rave-sp: validate received frame payload lengths - mfd: iqs62x: Reject zero-length firmware records - drm/amdgpu/gfx6: Fixup emit_cntxcntl() - ext4: fix spurious message about orphan cleanup on RO fs - [arm64] dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node - phy: sunplus: fix error handling in sp_uphy_init() (CVE-2026-90287) - phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table - perf trace-event: Fix buffer overflow in read_string() - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets - drm/amdgpu/gfx6: Use PFP on the compute queues too (CVE-2026-90286) - scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path (CVE-2026-90285) - firmware_loader: do not queue completed sysfs fallback requests (CVE-2026-90284) - pinctrl: rockchip: Reset the pin count when recalculating SoC data - hugetlbfs: release subpool on fill_super failure (CVE-2026-90283) - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() - phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() - phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads - phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend (CVE-2026-90282) - phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (CVE-2026-90281) - phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend (CVE-2026-90280) - md/raid5: round bitmap stripes with sector division (CVE-2026-90279) - md: avoid stale clone I/O accounting timestamps - md/raid1: don't set array_frozen in raid1_takeover() (CVE-2026-90275) - coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() - coresight: Change syncfreq to be a u8 - coresight: etm4x: fix underflow for usage of (nrseqstate - 1) (CVE-2026-90274) - coresight: etm4x: fix leaked trace id - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling - ACPI: video: Release PCI device reference after lookup - [amd64] perf/x86/intel/pt: Add support for pause / resume - [amd64] perf/x86/intel/pt: Factor out pt_config_enable() - [amd64] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED - [amd64] perf/x86/intel/pt: Fix stop/start with no update - sched/fair: Check CPU capacity before comparing group types during load balance - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() - Bluetooth: btusb: refactor endpoint lookup - Bluetooth: btusb: Record matched usb_device_id into btusb_data - Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices - perf trace-event: Fix integer truncation in do_read() and skip() - scsi: sd: Fix sd_done() sense handling condition - btrfs: retry verity reads for not-uptodate Merkle folios (CVE-2026-90262) - Bluetooth: virtio_bt: avoid OOB read of build info string (CVE-2026-90257) - Bluetooth: btintel: Fix diagnostics event detection - Bluetooth: hci_conn: fix the SCO setup context lifetime (CVE-2026-90255) - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (CVE-2026-90254) - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (CVE-2026-90253) - mmc: sdio: add MediaTek MT7902 SDIO device ID - Bluetooth: btmtk: add MT7902 MCU support - Bluetooth: btmtk: add MT7902 SDIO support - Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is negative - Bluetooth: MSFT: validate evt_prefix_len against the response length (CVE-2026-90251) - cgroup: Add bpf prog revisions to struct cgroup_bpf - bpf: Implement mprog API on top of existing cgroup progs - bpf, cgroup: Fix storage null-ptr-deref after replacing prog (CVE-2026-90250) - iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes (CVE-2026-90249) - iio: light: gp2ap002: re-enable irq if runtime suspend fails - net/sched: cls_api: fix teardown of an adopted proto on insert-race loss (CVE-2026-90248) - [riscv64] cpufeature: Clarify ISA spec version for canonical order - [arm64] dts: turris-mox: fix usb3 phys - perf stat: Fix evsel_list leak in cmd_stat - perf synthetic-events: Fix uninitialized pthread_join - perf python: Add support for 'struct perf_counts_values' to return counter data - perf python: Check counts_values size in set_values - perf synthetic-events: Fix divide by zero in perf_event__synthesize_threads - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() - fbdev: kyro: Validate overlay viewport coordinates (CVE-2026-90245) - [amd64] iommu/vt-d: Fix UCTP context table slot when copying root entries - [amd64] iommu/vt-d: Clear Present bit before tearing down copied context entry (CVE-2026-90243) - [amd64] iommu/vt-d: Tear down scalable-mode context on probe failure (CVE-2026-90241) - xdrgen: Rename "enum yada" types as just "yada" - xdrgen: Implement big-endian enums - xdrgen: Address some checkpatch whitespace complaints - xdrgen: Do not declare union XDR functions in the definitions header - xdrgen: Fix opaque and string encoders for unbounded members - SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 (CVE-2026-89784) - sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE (CVE-2026-90235) - [powerpc*] configs: enable CONFIG_RAS to fix EDAC support - [amd64] iommu/amd: Fix incorrect device ID in invalid PASID error message - phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs - phy: qualcomm: qmp-combo: add support for SAR2130P - phy: qcom: qmp-combo: Add new PHY sequences for SM8750 - phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for regulator setup - phy: qualcomm: Update the QMP clamp register for V6 - phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings - phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms - phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy - spi: sprd-adi: Fix probe succeeding without registering the controller - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP - [powerpc*] vdso: Add a page for non-time data - [powerpc] Use str_enabled_disabled() helper function - integrity: Make arch_ima_get_secureboot integrity-wide - [s390x] Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT - [s390x] irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN - nvme: add reservation command's defines - nvme: introduce change ptpl and iekey definition - nvme: Add the DHCHAP maximum HD IDs - nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() (CVE-2026-90230) - nvme-apple: Destroy the admin queue on removal (CVE-2026-90229) - nvme-apple: Don't set a DMA direction for commands without a data transfer - nvme-apple: Never set the opcode in the NVMMU TCB - nvme: apple: Add Apple A11 support - nvme-apple: Drop the PRP null check chicken bit - nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() (CVE-2026-90228) - nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227) - nvme: reject passthrough of driver-managed Set Features - nfc: llcp: avoid userspace overflow on invalid optlen (CVE-2026-90226) - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (CVE-2026-90225) - nfc: nci: fix double completion race in nci_data_exchange_complete (CVE-2026-90224) - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (CVE-2026-90223) - nfc: pn533: hold a reference to the request skb during send_frame (CVE-2026-90222) - nfc: digital: Do not dump a NULL response in command completion - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (CVE-2026-90221) - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (CVE-2026-90220) - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal - RDMA/cxgb4: Free debugfs on registration failure (CVE-2026-90219) - RDMA/cma: Fix WARNING in res_to_rt (CVE-2026-90218) - ice: clear the default forwarding VSI rule when releasing a VSI - ASoC: pxa: Use devm_clk_get_optional() for extclk clock - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready - UBI: Preserve torture flag when rescheduling failed erasures - UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs - ubi: Fix rollback for explicit UBI device numbers (CVE-2026-90216) - mtd: ubi: Release device reference on busy detach (CVE-2026-90215) - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (CVE-2026-90214) - UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC - firewire: core: add KUnit test skeleton for node tree - firewire: core: add KUnit tests for successful tree building - firewire: core: add KUnit tests for failure of tree building - firewire: core: consolidate port counting in build_tree() - firewire: core: validate parent port count before allocating nodes in build_tree() - firewire: core: fix memory leak in error path of build_tree() (CVE-2026-90213) - PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore - super: fix dying superblock warning messages - kunit: tool: fix _list_tests filtering wrong variable when list has TAP prefix - [s390x] bpf, s390: Clear fetch destination on faulting arena atomic (CVE-2026-90211) - spi: img-spfi: don't disable runtime PM on DMA deferred probe - PCI/ASPM: Cache L0s/L1 Supported so advertised link states can be overridden - PCI/ASPM: Disable/restore ASPM on every function for multi-function devices - power: supply: bd99954: Drop bad register fields - power: supply: bq27xxx: bq27520g4: fix REG_TTES address - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address - xenbus: Unregister reboot notifier on init failure - [s390x] debug: Fix deadlock during unregister (CVE-2026-90209) - clocksource/drivers/clps711x: Do not unmap clocksource MMIO - clocksource/drivers/armada: Unwind timer clock on init failure - ALSA: seq: midi: Optimize event_input locking with RCU - ALSA: seq: midi: Serialize input teardown with event_input (CVE-2026-90207) - cgroup/cpuset: Fix spelling errors in file kernel/cgroup/cpuset.c - cgroup/cpuset: Remove remote_partition_check() & make update_cpumasks_hier() handle remote partition - [amd64] x86/pkeys: Fix pkey_alloc() return value when pkeys are not supported - bpftool: Fix double close in map dump - ocfs2: fix circular locking dependency in ocfs2_init_acl() - Squashfs: check block offset is not negative (CVE-2026-90203) - scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (CVE-2026-90202) - scsi: ufs: core: Remove redundant host_lock calls around UTMRLDBR - scsi: ufs: core: Set task state before io_schedule_timeout() - page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() - net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race (CVE-2026-90201) - fs/ntfs3: fix integer overflow in MFT cluster validation (CVE-2026-90200) - fs/ntfs3: reject out-of-range evcn in mi_enum_attr() (CVE-2026-90199) - ALSA: core: Fix use-after-free in snd_card_do_free() (CVE-2026-90198) - tracing: Remove "__attribute__()" from the type field of event format - tracing: Have trace_event_update_all() only handle module that is loading - ASoC: SOF: validate topology volume range before allocation (CVE-2026-90196) - HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU - [riscv64] bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args (CVE-2026-90195) - ring-buffer: Remove trace_buffer::cpus - ACPI: scan: fix bus ID cleanup on device_add() failures (CVE-2026-90194) - bpf: Fix pending_pos walk on 32-bit ring position wrap - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure - crypto: lskcipher - propagate errors from unaligned crypt - sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry - perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() - perf dso: Use stored fd error instead of stale errno in file_read() and file_size() - perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() - mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (CVE-2026-90193) - mailbox: qcom-cpucp: handle NULL data in send_data callback (CVE-2026-90192) - mailbox: rockchip: disable pclk on probe failure and unbind - mailbox: pcc: Always map the shared memory communication address - mailbox/pcc: support mailbox management of the shared buffer - Revert "mailbox/pcc: support mailbox management of the shared buffer" - mailbox: pcc: Fix command timeout due to missed interrupt - null_blk: use DEFINE_MUTEX for the file-scope mutex (CVE-2026-90190) - null_blk: register configfs subsystem after creating default devices (CVE-2026-90189) - null_blk: free global tag_set on init error path (CVE-2026-90188) - null_blk: free zones array on device power-off (CVE-2026-90187) - null_blk: reject per-device queue resize for shared tag set (CVE-2026-90186) - null_blk: serialize configfs attribute stores with the lock (CVE-2026-90185) - null_blk: serialize configfs attribute updates with device setup (CVE-2026-90184) - ublk: reject non-power-of-2 zone sizes in SET_PARAMS - block: mtip32xx: synchronize ioctls with device removal (CVE-2026-90180) - hwmon: (coretemp) Fix core_data leak on CPUs without PTS (CVE-2026-90178) - hwmon: (emc1403) Rely on subsystem locking - hwmon: (emc1403) Drop hysteresis for low limit temperature - ksmbd: Do not skip lock checks for single-byte ranges (CVE-2026-90176) - smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer (CVE-2026-90175) - ksmbd: validate ipc response length before dereferencing its fields (CVE-2026-90170) - ksmbd: do not advertise unimplemented CA support - ksmbd: free preauth sessions on connection teardown (CVE-2026-90169) - smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() (CVE-2026-90166) - smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() (CVE-2026-90165) - smb/server: preserve error status in smb2_handle_negotiate() - lwt_bpf: Restore reserved headroom after xmit program (CVE-2026-90160) - erofs: convert z_erofs_bind_cache() to folios - erofs: support unaligned encoded data - erofs: fix unused pcluster_pools for higher page sizes - bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks (CVE-2026-90159) - bpf: Reject negative optlen in cgroup getsockopt hook (CVE-2026-90157) - ksmbd: disconnect on SMB3 decryption failure - ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size (CVE-2026-90153) - smb/server: fix session leak in ksmbd_session_register() (CVE-2026-90152) - nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper - nfs: refactor pNFS functions using clear_and_wake_up_bit - NFSv4: remove callback IDR entry on client allocation failure (CVE-2026-90151) - pnfs/blocklayout: Fix device leaks on parse failure (CVE-2026-90150) - NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() (CVE-2026-90148) - nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3 - clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() (CVE-2026-90147) - clk: ti: use kcalloc() instead of kzalloc() - clk: ti: mux: resolve parent clocks by DT index, not by name - octeontx2-af: initialize lmac_bmap in rvu_mcs_set_lmac_bmap() - drm/xe: tests: fix error message in xe_migrate_sanity_test() - ionic: fix completion descriptor access with 2x desc size - net: kcm: Hold RCU read lock while running BPF parser (CVE-2026-90143) - net: dsa: b53: fix error propagation from b53_fdb_dump() - pppox: drain queued packets on channel handoff - net: hsr: free learned nodes on device setup failure - f2fs: fix to parse temperature correctly in f2fs_get_segment_temp() - f2fs:Fix incomplete search range in f2fs_get_victim when f2fs_need_rand_seg is enabled - f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk} - f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode - ipvs: fix integer overflow in ftp helper port/address parsing (CVE-2026-90141) - vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes (CVE-2026-89776) - net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error - tls: fix RX desync on overlapping skbs - net: bridge: vlan: fix inverted default vlan notification - cuse: wait for pending RCU callbacks on module exit (CVE-2026-90140) - fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() (CVE-2026-89781) - fs/ntfs3: validate ef->size covers the record's name and value (CVE-2026-89779) - fuse: support folios in struct fuse_args_pages and fuse_copy_pages() - fuse: convert readdir to use folios - fuse: check attributes staleness on fuse_iget() - fuse: check for NULL root inode in fuse_fill_super_submount (CVE-2026-90139) - ALSA: hda: Fix connection list comparison in proc output - vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() - 8139cp: fix Rx and Tx not being disabled in cp_suspend - net/smc: hash socket only after full initialisation in smc_sk_init() - [amd64] platform/x86: dell-wmi-sysman: Fix instance ID bounds - vsock: avoid timeout for non-blocking accept() with empty backlog - vsock: don't check the listener's sk_err in vsock_accept() (CVE-2026-90138) - vsock: use sock_error() to consume sk_err after a failed connect - platform/x86: hp-bioscfg: fix password encoding bounds check (CVE-2026-90137) - mlxbf-bootctl: fix the build error with FIELD_PREP() - bonding: initialize err for empty target lists - net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() (CVE-2026-90135) - i3c: mipi-i3c-hci: Quieten initialization messages - i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc() - i3c: mipi-i3c-hci: Refactor PIO register initialization - i3c: mipi-i3c-hci: Fix missing STAT_IBI_STATUS_THLD in PIO mode - virtio_balloon: disable indirect descriptors - vdpa_sim: fix cleanup after worker creation failure (CVE-2026-90130) - virtio_pci: fix wrong queue index for admin vq in intx path - vdpa/mlx5: fix wrong list iterated in add_direct_chain error path (CVE-2026-90128) - rtc: pcf8563: fix clock provider leak on unbind (CVE-2026-90126) - smb: client: fix request buffer leak in smb2_new_read_req() (CVE-2026-90125) - rtc: zynqmp: Return optional clock lookup errors - irqchip/renesas-rzg2l: Fix loss of interrupt (CVE-2026-90124) - i2c: ocores: Disable clock on failed resume - rtc: gamecube: check return value of devm_rtc_register_device() - prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator - clk: ti: Make sure clk_init_data is fully initialized - clk: visconti: Make sure clk_init_data is fully initialized (CVE-2026-90122) - ALSA: core: Add scoped cleanup helper for card references - ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup (CVE-2026-90119) - RDMA/ucma: Allow path records to exactly fit the output buffer - xsk: Get rid of xdp_buff_xsk::orig_addr - xsk: avoid double checking against rx queue being full - xsk: fix NULL pointer dereference in __xsk_rcv() (CVE-2026-90115) - net: bridge: Reject descending VLAN tunnel ranges (CVE-2026-90114) - net/sched: add get_fill_size callbacks for actions missing them - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes - forcedeth: stop the tx_timeout register dump past the requested window - net: ipa: balance runtime PM reference on remove error - net: add missing ref_tracker_dir_exit() to net_passive_dec() - net: qlcnic: validate unified ROM sections before loading (CVE-2026-90112) - inetpeer: randomize RB-tree node comparison using SipHash (CVE-2026-90110) - net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue (CVE-2026-90109) - net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition (CVE-2026-90108) - net/smc: free pending qentry in smc_llc_flow_stop() before memset (CVE-2026-90107) - NFSv4.2: fix LAYOUTSTATS send buffer exhaustion (CVE-2026-90103) - nfs: move the nfs4_data_server_cache into struct nfs_net - NFSv4/pnfs: key the data server cache on the NFS version (CVE-2026-90102) - rtc: pcf85363: Add error checking to regmap calls in probe() - bnxt_en: Fix call to hardware monitoring event handler (CVE-2026-90101) - net: page_pool: Remove zone/policy GFP flags when allocating XArray entries - scsi: qla2xxx: Fix an loop timeout test - erofs: Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS default logic - [s390x] Add missing _TIF defines - [s390x] Add ARCH_HAS_PREEMPT_LAZY support - mm: make DEBUG_WX depdendent on GENERIC_PTDUMP - mm: rename GENERIC_PTDUMP and PTDUMP_CORE - mm/ptdump: split note_page() into level specific callbacks - [arm64] ptdump: Make note_page_flush() range aware - Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN (CVE-2026-90092) - Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference - Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan (CVE-2026-90091) - Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support - Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() - Bluetooth: btmtk: Do not report success when subsys reset fails - Bluetooth: btmtk: Do not discard the subsystem reset timeout - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (CVE-2026-90090) - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (CVE-2026-90088) - gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free (CVE-2026-89789) - octeontx2-af: fix NULL deref in NIX TM tree debugfs read path (CVE-2026-90085) - net: qualcomm: rmnet: restore skb->dev on deaggregated frames (CVE-2026-89780) - octeontx2-af: Fix TL3/TL2 link config ENA clearing - net/rds: use wq_has_sleeper() in rds_cong_map_updated() (CVE-2026-90081) - cifs: fix clearing stats for fastest execution of each smb2 command - maple_tree: catch race in mas_alloc_cyclic() - maple_tree: fix argument name in header - net_sched: act_skbmod: use RCU in tcf_skbmod_dump() - net/sched: act_skbmod: fix length calculations and avoid invalid header warnings (CVE-2026-90078) - net: core: check skb_frags_readable before uncloning in skb_copy_ubufs - net/sched: fq: add overflow bounds to quantum and initial quantum (CVE-2026-90076) - net/sched: fq_codel: clamp default quantum and mtu (CVE-2026-90075) - net/sched: sch_codel: clamp default mtu to avoid disabling CoDel - net/sched: fq_pie: clamp default quantum to avoid signed overflow (CVE-2026-90074) - net/sched: hhf: clamp quantum before hhf_change() to avoid overflow (CVE-2026-90073) - net/sched: sfq: clamp quantum to avoid signed overflow soft lockup (CVE-2026-90072) - net/sched: sch_teql: restore skb->dev on the slave failure path (CVE-2026-90071) - tpm: st33zp24: Return zero on status read failure (CVE-2026-90070) - tpm: st33zp24: Validate locality read result - apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init - apparmor: policy_int make sure list heads are initialized before fail path - ASoC: dapm: Fix off-by-one check on the second enum channel (CVE-2026-90068) - ceph: revalidate ki_pos for O_APPEND writes after cap acquisition - libceph: validate banner payload length (CVE-2026-90067) - samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify - samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify (CVE-2026-90066) - net: ethernet: sun4i-emac: Fix IRQ error handling - net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure (CVE-2026-90065) - net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs - net: stmmac: selftests: Pass the IP proto mask in the TC selftest - virtio-net: Ensure that TCP packets don't overflow gso_segs (CVE-2026-90063) - netfilter: nf_tables: move hardware offload step after building the chain blob (CVE-2026-90062) - netfilter: xt_cgroup: Make it independent from net_cls - netfilter: xt_HL: add pr_fmt and checkentry validation - netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited() - ALSA: control: Don't add invalid kcontrols to LED layer (CVE-2026-90060) - net: stmmac: selftests: Check multiple MMC counters - net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering - net: stmmac: dwmac4: Account for the primary MAC address for UC filtering - net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering - net: stmmac: selftests: Account for the UC filter list for filtering tests - net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup (CVE-2026-90058) - slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() (CVE-2026-90057) - net: fec: only stop PTP if it was initialized (CVE-2026-90056) - usb: atm: usbatm: fix invalid ci_range initialization (CVE-2026-90055) - tcp: fix corruption of urgent data on multi-segment retransmit (CVE-2026-90054) - net/sched: sch_htb: limit htb_classify inner-class filter hops (CVE-2026-90053) - [amd64] platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL - [amd64] cpufreq/amd-pstate: Fix prefcore rankings - pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() - pinctrl: mediatek: Fix new design debounce issue - pinctrl: mediatek: common-v1: Fix EINT breakage on older controllers - md: keep recovery_cp in mdp_superblock_s - slub: Don't call lockdep_unregister_key() for immature kmem_cache. - ACPI: processor: Update cpuidle driver check in __acpi_processor_start() - fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT - selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries - bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat - perf test: Don't signal all processes on system when interrupting tests - phy: qcom: qmp-combo: Add missing PLL (VCO) configuration on SM8750 - powerpc/vdso: Remove unused clockmode asm offsets - nvme-apple: Prevent shared tags across queues on Apple A11 - nvme-apple: Reset q->sq_tail during queue init - cpuset: fix warning when disabling remote partition - erofs: fix managed cache race for unaligned extents - xsk: Fix offset calculation in unaligned mode - Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array - net/sched: fq: clamp quantum and initial_quantum in change path - md: add helper rdev_needs_recovery() - md: fix sync_action incorrect display during resync - net_sched: act_ct: use RCU in tcf_ct_dump() - net_sched: act_ctinfo: use RCU in tcf_ctinfo_dump() - net_sched: act_skbedit: use RCU in tcf_skbedit_dump() - net_sched: act_vlan: use RCU in tcf_vlan_dump() - net_sched: act_tunnel_key: use RCU in tunnel_key_dump() - net_sched: add back BH safety to tcf_lock - tools/build: Use SYSTEM_BPFTOOL for system bpftool - pinctrl: mediatek: common-v1: Fix error checking in mtk_eint_init() - slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL - integrity: Eliminate weak definition of arch_get_secureboot() - ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.111 - ksmbd: fix use-after-free in oplock break notification (CVE-2026-80926) - drm/gem: Consider GEM object reclaimable if shrinking fails - bus: fsl-mc: wait for the MC firmware to complete its boot - drm: rz-du: Ensure correct suspend/resume ordering with VSP - drm/amd/display: Fix DPMS using partially updated pipe context - drm/panel: jadard-jd9365da-h3: set prepare_prev_first - drm/amd/pm: Check SMUv13.0.6/12 metrics integrity - gfs2: fix quota init duplicate scan - gfs2: move quota_init qc iterator increment - iio: adc: rtq6056: add i2c_device_id support - [arm64] pinctrl: renesas: rzg2l: Handle RZ/V2H(P) IOLH configuration in PM cache - ALSA: usb-audio: Propagate write errors in generic mixer put callbacks - ima: return error early if file xattr cannot be changed - usb: gadget: udc: skip pullup() if already connected - [arm64] tee: optee: Allow MT_NORMAL_TAGGED shared memory - PCI: Stop setting cached power state to 'unknown' on unbind - wifi: cfg80211: reject duplicate wiphy cipher suite entries - hfsplus: fix issue of direct writes beyond end-of-file - wifi: nl80211: reject beacons with bad HE operation - wifi: mac80211: always allow transmitting null-data on TXQs - wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() - wifi: rtw89: disable CSI STBC for VHT 160MHz - ASoC: fsl-asoc-card: reduce WM8904 PLL ratio to meet frequency limit - firmware: stratix10-svc: change get provision data to async SMC call - bridge: Do not suppress ARP probes and DAD NS unconditionally - soundwire: intel_auxdevice: Add cs42l43b to wake_capable_list - soundwire: validate DT compatible before parsing it - media: chips-media: wave5: Fix Reports from Kernel Lock Validator - spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM - media: rc: mceusb: Add support for 04eb:e033 - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG - [s390] cio: Purge based on the cdev's online status - [amd64] thunderbolt: Avoid reserved fields in path config space for USB4 routers - [amd64] thunderbolt: Don't disable lane adapter if XDomain lane bonding isn't possible - [amd64] thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() - [amd64] thunderbolt: Keep XDomain reference during the lifetime of a service - [amd64] thunderbolt: Keep the domain reference while processing hotplug - [amd64] thunderbolt: Set tb->root_switch to NULL when domain is stopped - [amd64] thunderbolt: Don't create multiple DMA tunnels on firmware connection manager - drm/amd/display: Find link encoder for flexible DIG mapping cases - drm/amdgpu: Prefer ROM BAR for default VGA device - drm/panel: Enable GPIOLIB for panels which uses functions from it - media: dm1105: fix missing error check for dma_alloc_coherent - net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family - PCI: switchtec: Add Gen6 Device IDs - net: dsa: mv88e6xxx: define .pot_clear() for 6321 - net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family - media: em28xx-video: fix missing res_free() on init_usb_xfer failure - wifi: mac80211: explicitly disable FTM responder on AP stop - rtase: Fix flow control configuration - crypto: ixp4xx - fix buffer chain unwind on allocation failure - crypto: omap - add omap_des_unregister_algs helper - [arm64] clk: renesas: cpg-mssr: Add number of clock cells check - drm/bridge: tc358768: Set pre_enable_prev_first for reverse order - dlm: add usercopy whitelist to dlm_cb cache - PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() - media: qcom: camss: avoid format string warning - ASoC: ti: omap3pandora: update board check to use DT compatible - watchdog: lenovo_se10_wdt: Add support for SE10 Gen 2 platform - watchdog: imx7ulp_wdt: Keep WDOG running until A55 enters WFI on i.MX94 - watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk - net/mlx5: HWS, Handle destroying table that has a miss table - platform/chrome: Resolve kb_wake_angle visibility race - mmc: core: Add validation for host-provided max_segs - mmc: davinci: avoid NULL deref of host->data in IRQ handler - [amd64] platform/x86: sel3350-platform: Retain LED state on load and unload - drm/amd/display: Fix CRC open failure during active rendering - PCI: intel-gw: Enable clock before PHY init - hfsplus: rework hfsplus_readdir() logic - net: phy: motorcomm: use device properties for firmware tuning - drm/gud: Add RCade Display Adapter VID/PID pair - media: chips-media: wave5: Add range checks for dec_output_info - media: video-i2c: use vb2_video_unregister_device on driver removal - HID: multitouch: Fix Yoga Book 9 14IAH10 touchscreen misclassification - wifi: rtw89: phy: check length before parsing PHY status IE - net: dsa: realtek: rtl8365mb: add support for RTL8367SB - integrity: Check for NULL returned by asymmetric_key_public_key - drivers/of: validate status properties in reconfig state changes - soundwire: intel: Move suspend tracking from trigger to pm suspend - clk: samsung: exynos850: mark APM I3C clocks as critical - scsi: pm8001: Reject firmware update in fatal error state - scsi: pm8001: Reject non-fatal dump when controller is crashed - [amd64] ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally - crypto: atmel-ecc - add support for atecc608b - media: imon: Add iMON VFD HID OEM v1.2 key mappings - RDMA/mlx5: Use QP port when decoding responder CQEs - drm/mediatek: dsi: Add compatible for mt8167-dsi - iomap: don't make REQ_POLLED imply REQ_NOWAIT - mailbox: Make mbox_send_message() return error code when tx fails - PCI: Wait for device readiness after D3hot -> D0uninitialized transition - drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id - drm/amdkfd: Fix OOB memory exposure in get_wave_state() - drm/amdkfd: Check bounds on allocate_doorbell - ALSA: usx2y: Drain pending US-428 pipe-4 output commands - sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity - [arm64] iommu: arm-smmu-qcom: Ensure smmu is powered up in set_ttbr0_cfg - 9p: invalidate readdir buffer on seek - [arm64] daifflags: Make local_daif_*() helpers __always_inline - drm/imagination: Populate FW common context ID before passing to the FW - 9p: use kvzalloc for readdir buffer - drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw - bridge: Add missing READ_ONCE() annotations around FDB destination port - [amd64] thunderbolt: Don't access path config space on Lane 1 adapters in tb_switch_reset_host() - [amd64] thunderbolt: Improve multi-display DisplayPort tunnel allocation - firmware: arm_scmi: Validate SENSOR_UPDATE payload size - firmware: arm_scmi: Validate BASE_ERROR_EVENT payload size - [amd64] thunderbolt: Increase timeout for Configuration Ready bit - wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed - [amd64] thunderbolt: Verify Router Ready bit is set after router enumeration - bitfield: wire __bf_shf to __builtin_ctzll - nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl - net: usb: qmi_wwan: add MeiG SRM813Q - net: bridge: remove stale rcu_barrier() in br_multicast_dev_del() - net/sched: sch_drr: make cl->quantum lockless - net/rds: Don't sleep inside rds_ib_conn_path_shutdown - spi: dw-mmio: Add ACPI ID LECA0002 for LECARC SoCs - befs: handle set_blocksize failures - ntfs3: handle set_blocksize failures - affs: handle set_blocksize failures - bfs: handle set_blocksize failures - minix: handle set_blocksize failures - qnx4: handle set_blocksize failures - jfs: handle set_blocksize failures - hpfs: handle set_blocksize failures - omfs: handle set_blocksize failures - isofs: handle set_blocksize failures - HID: bpf: Add Huion Inspiroy Frego M button quirk - usbip: vhci_hcd: fix NULL deref in status_show_vhci - usb: core: hcd: fix possible deadlock in rh control transfers - usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log - USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set - usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue - serial: 8250: fix possible ISR soft lockup - usb: host: add ARCH_AIROHA in XHCI MTK dependency - crypto: atmel-sha204a - remove sysfs group before hwrng - char/nvram: Remove redundant nvram_mutex - rcu-tasks: Fix possible boot-time tests failed for the call_rcu_tasks() - wifi: rtw89: pci: enable LTR based on pcie control register - netlabel: fix IPv6 unlabeled address add error handling - ALSA: seq: Remove arbitrary prioq insertion limit - rds: filter RDS_INFO_* getsockopt by caller's netns - rds: annotate data-race around rs_seen_congestion - [s390x] zcore: Removed unused variables - clk: socfpga: agilex: implement l3_main_free_clk - thermal/drivers/tegra/soctherma: Switch to devm cooling device registration - [amd64] powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked() - drm/panel: simple: Add AM-1280800W8TZQW-T00H - iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind - irqchip/gic-v4: Don't advertise VLPIs if no ITS is probed - ALSA: usb-audio: Add quirk for Novation Mininova - net: hsr: require valid EOT supervision TLV - ipv6: addrconf: fix temp address generation after prefix deprecation - net: thunderx: fix PTP device ref leak in nicvf_probe() - drm/dp: Add DSC virtual DPCD quirk for Realtek MST branch device - drm/amd/pm/si: Fix updating clock limits from power states - drm/amd/display: Initialize dsc_caps to 0 - ACPICA: Fix condition check in acpi_ps_parse_loop() - ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() - ACPICA: add boundary checks in acpi_ps_get_next_field() - ACPICA: validate byte_count in acpi_ps_get_next_package_length() - ACPICA: Prevent adding invalid references - ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) - ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg() - ACPICA: validate handler object type in two places - ACPICA: Add package limit checks in parser functions - ACPICA: Add validation for node in acpi_ns_build_normalized_path() - ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() - ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() - ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() - ACPICA: add boundary checks in two places - hfs: rework hfsplus_readdir() logic - net: sfp: add quirk for OEM 2.5G optical modules - [arm64] pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP - host1x: bus: Fix missing ops null check in error teardown - scripts: modpost: detect and report truncated buf_printf() output - [amd64] ASoC: Intel: catpt: Complete coredump handling - drm/nouveau/bios: skip the IFR header if present - soc/tegra: fuse: Register nvmem lookups at probe - soundwire: dmi-quirks: Disable ghost Realtek devices - gfs2: page poisoning fix - soundwire: only handle alert events when the peripheral is attached - mmc: davinci: fix mmc_add_host order in probe - mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC - [armhf] tegra: p880: Lower CPU thermal limit - tracing: Disable KCOV instrumentation for trace_irqsoff.o - mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC - iio: light: stk3310: Deal with the ps interrupt issue in PM - perf/ftrace: Fix WARNING in __unregister_ftrace_function - iio: accel: mma8452: switch to non-devm request_threaded_irq() - libbpf: Also reset {insn,data}_cur on realloc failure - net: ibm: emac: Reserve VLAN header in MJS limit - wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi - ASoC: qcom: q6apm: return error code to consumers on failures - ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive - ata: ahci: fail probe if BAR too small for claimed ports - ACPI: scan: Honor _DEP for ACPI0016 PCI/CXL host bridge - ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach - net: qrtr: fix node refcount leak on ctrl packet alloc failure - net: wwan: t7xx: Add delay between MD and SAP suspend - iommu/rockchip: disable fetch dte time limit - [powerpc*] fadump: Add timeout to RTAS busy-wait loops - fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib - nvme: refresh multipath head zoned limits from path limits - fs/ntfs3: validate index entry key bounds - ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() - ASoC: codecs: rk3328: Use managed GPIO and clock helpers - ALSA: seq: oss: Reject reads that cannot fit the next event - dpaa2-switch: rework FDB management on the bridge leave path - dpaa2-switch: fix the error path in dpaa2_switch_rx() - net: dsa: sja1105: flower: reject cross-chip redirect - dpaa2-switch: fix handling of NAPI on the remove path - thermal/drivers/qcom/tsens: Atomic temperature read with hardware-guided retries - usb: xhci: Improve Soft Retries after short transfers - xhci: Prevent queuing new commands if xhci is inaccessible - drm/amd/display: Check for sharpening case when calculating max vtaps for scaler - drm/amdkfd: fix UAF race in destroy_queue_cpsch - drm/amdgpu: harden FRU PIA parsing with bounded helpers - drm/amd/pm: bound pp_dpm_set_pp_table() memcpy - drm/amdgpu: fix buffer overflow during vBIOS update - net/mlx5e: Verify unique vhca_id count instead of range - RDMA/irdma: Fix typo in SQ completions generation - net/mlx5: E-Switch, align disable sequence with switchdev-to-legacy transition - clk: keystone: don't cache clock rate - ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP - ipmi: si: Use platform_get_irq_optional() to retrieve interrupt - drm/amdkfd: Unwind debug trap enable on copy_to_user failure - ipv6: use READ_ONCE() for bindv6only default in inet6_create() - wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications - RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() - RDMA/mlx5: Fix state and counter desync on loopback enable failure - bpf: NUL-terminate replaced sysctl value - net: cpsw_new: unregister devlink on port registration failure - hsr: broadcast netlink notifications in the device's net namespace - net: microchip: sparx5: clean up PSFP resources on flower setup failure - ALSA: es18xx: check control allocation before private data setup - netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() - [riscv64] panic if IRQ handler stacks cannot be allocated - btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() - btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF - NFS: fix eof updates after NFSv4.2 fallocate/zero-range - ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend() - RDMA/rtrs-srv: Fix integer underflow in process_read and process_write - xprtrdma: Add request-pool slack for delayed recycling - RDMA/mlx5: Create ODP EQ for non-pinned dmabuf MRs - configfs_depend_prep(): pass configfs_dirent instead of dentry - pds_core: quiesce DMA before freeing resources - net: ibm: emac: mal: fix potential system hang in mal_remove() - tls: Flush backlog before waiting for a new record - platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table - wifi: mt76: mt7925: handle 320MHz bandwidth in RXV and TXS - platform/x86: msi-ec: Add support for MSI Pulse GL66 12th Gen - wifi: mt76: mt7925: add Netgear A8500 USB device ID - wifi: mt76: mt7925: populate EHT 320MHz MCS map in sta_rec - wifi: mt76: mt7925: add 320MHz bandwidth to bss_rlm_tlv - wifi: mt76: transform aspm_conf for pci_disable_link_state - netconsole: take target_cleanup_list_lock in drop_netconsole_target() - btrfs: protect sb_write_pointer() with invalidate lock - fbcon: don't suspend/resume when vc is graphics mode - PCI: Avoid FLR for MediaTek MT7925 WiFi - hwmon: (raspberrypi) Fix delayed-work teardown race - hwmon: (adt7462) Add of_match_table to support devicetree - btrfs: use on-disk uuid for s_uuid in temp_fsid mounts - btrfs: use lockless read in nr_cached_objects shrinker callback - net: dsa: qca8k: Add support for force mode for fixed link topology - net: lan966x: restore RX state on reload failure - vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add() - vdpa/octeon_ep: Use 4 bytes for mailbox signature - ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IRH8 - ata: libata-pmp: add JMicron JMS562 quirk - [amd64] platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table - nvme-fc: Do not cancel requests in io target before it is initialized - sctp: Unwind address notifier registration on failure - HID: multitouch: Honor ContactCount for Yoga Book 9 to suppress ghost contacts - hwmon: (dell-smm) Add Dell Latitude 7530 to fan control whitelist - PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems - dmaengine: altera-msgdma: Use memcpy_toio for descriptor FIFO writes - dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc - hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i - spi: xilinx: let transfers timeout in case of no IRQ - Bluetooth: btusb: MT7922: Add VID/PID 0e8d/223c - Bluetooth: btusb: Add support for Intel Lizard Peak 2 (0x8087:0x0040) - Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d922 - Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV - Bluetooth: btmtk: Disable remote wakeup for MT7922/MT7925 - Bluetooth: btusb: MT7925: Add VID/PID 0e8d/8c38 - Bluetooth: btusb: Add support for TP-Link TL-UB250 - Bluetooth: L2CAP: validate connectionless PSM length - Bluetooth: btintel_pcie: Add 50 ms delay before MAC init on BlazarIW - ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt - ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence - ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure - Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV - Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d923 - net: stmmac: xgmac2: disable RBUE in default RX interrupt mask - ptp: ocp: add shutdown callback - vsock: use sk_acceptq_is_full() helper in all transports - e1000e: limit endianness conversion to boundary words - [arm64] net: hns3: improve the unused_tuple parameter setting - apparmor: propagate -ENOMEM correctly in unpack_table - net/sched: act_csum: don't mangle UDP tunnel GSO packets - smb: client: fix races in cifsd thread creation - i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA - bpftool: Pass host flags to bootstrap libbpf - exfat: fix handling of damaged volume in exfat_create_upcase_table() - ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT - virtio-fs: avoid double-free on failed queue setup - HID: hidpp: fix potential UAF in hidpp_connect_event() - fuse: set ff->flock only on success - scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block() - gpio: pisosr: Read "ngpios" as u32 - spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() - ALSA: usb-audio: Add quirk flags for SC13A - tls: reject the combination of TLS and sockmap - ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10 - leds: uleds: Return -EFAULT on copy_to_user() failure - leds: pca9532: Don't stop blinking for non-zero brightness - mfd: tps65219: Make poweroff handler conditional on system-power-controller - leds: trigger: gpio: Use GPIOD_FLAGS_BIT_NONEXCLUSIVE - mfd: rsmu: Add 8a34002 support - drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl - drm/amdkfd: check find_first_zero_bit before __set_bit on kfd->doorbell_bitmap - drm/amdgpu: Use system unbound workqueue for soft IH ring - ALSA: usb-audio: Add quirk for YAMAHA CDS3000 - drm/amdkfd: Properly acquire queue buffers in CRIU restore - PCI: iproc: Protect root bus removal with rescan lock - PCI: altera: Protect root bus removal with rescan lock - PCI: rockchip: Protect root bus removal with rescan lock - PCI: mediatek: Protect root bus removal with rescan lock - PCI: plda: Protect root bus removal with rescan lock - perf: Fix addr_filter_ranges lifetime - mailbox: imx: Use devm_pm_runtime_enable() - md/raid5: account discard IO - mailbox: imx: Add a channel shutdown field - mailbox: imx: use devm_of_platform_populate() - md/raid5: let stripe batch bm_seq comparison wrap-safe - ALSA: hda/realtek: Add quirk for Lenovo Yoga 7 16IAP7 - f2fs: validate inline dentry name lengths before conversion - rtc: mv: add suspend/resume support for wakeup - rtc: aspeed: add AST2700 compatible - ceph: harden send_mds_reconnect and handle active-MDS peer reset - ksmbd: fix lease break and ack state handling - ksmbd: validate SMB2 lease create contexts - ksmbd: align SMB2 oplock break ack handling - ksmbd: use connection ClientGUID for lease lookup - ksmbd: treat unnamed DATA stream as base file - ksmbd: apply create security descriptor first - ksmbd: deny renaming directory with open children - ksmbd: start file id allocation at 1 - ksmbd: break RH leases before delete-on-close - ksmbd: treat read-control opens as stat opens only for leases - PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() - PCI/sysfs: Use kstrtobool() to parse the ROM attribute input - regulator: da9121: Use subvariant ids in the I2C table - net: au1000: move free_irq out of the close-time spinlocked section - blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat() - rtc: bq32000: add delay between RTC reads - eth: mlx5: fix macsec dependency - ALSA: hda: Add Lenovo Legion 7i 16IAX7 17AA3874 quirk - fbdev: pm2fb: unwind WC setup on probe failure - ASoC: tas2781: Update default register address to TAS2563 - spi: core: Abort active target transfer on controller suspend - btrfs: tree-checker: validate INODE_REF's namelen - drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend - netfilter: nf_conntrack_expect: zero at allocation time - ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr - ALSA: hda/realtek: Add quirk for HP Victus 16-e0xxx (88EE) to enable mute LED - drm/arm/komeda: fix error handling for clk_prepare_enable() and callers - ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr - ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling - xen/front-pgdir-shbuf: free grant reference head on errors - freevxfs: don't BUG() on unknown typed-extent type - xen/gntalloc: validate grant count before allocation - cachefiles: Fix double fput - netfs: Fix decision whether to disallow write-streaming due to fscache use - [amd64] ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table - drm/amdgpu: flush pending RCU callbacks on module unload - ksmbd: fix credit charge calculation for SMB2 QUERY_INFO - ALSA: usb-audio: caiaq: validate EP1 reply lengths - wifi: ralink: RT2X00: init EEPROM properly - wifi: mac80211: validate deauth frame length before reason access - wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers - wifi: libertas: reject short monitor TX frames - wifi: cfg80211: validate assoc response length before status and IE access - ksmbd: find bound sessions during reauthentication - ksmbd: mark invalid session responses as signed - ksmbd: validate SID namespace before mapping IDs - wifi: cfg80211: validate rx/tx MLME callback frame lengths before access - wifi: mac80211: ibss: wait for in-flight TX on disconnect - gpio: dwapb: Mask interrupts at hardware initialization - wifi: libipw: fix key index receive bound checks - netfilter: ipset: mark the rcu locked areas properly - wifi: rsi: validate beacon length before fixed buffer copy - ASoC: rt712-sdca: reset codec at io_init to fix silent headphone - smb/client: reduce fallocate zero buffer allocation - cifs: Fix support for creating SFU socket - smb/client: zero-initialize stack-allocated cifs_open_info_data - ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series - ALSA: hda/realtek - Add quirk for HP Victus 15-fa0xxx (MB 8A50) - ALSA: hda: cs35l56: Fail if wmfw file is missing - cifs: Fix support for creating SFU fifo - btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr() - btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() - spi: dw-dma: Wait for controller idle before completing Tx - wifi: iwlwifi: mvm: validate sta_id in BA window status notif - btrfs: fix reloc root cleanup in merge_reloc_roots() - wifi: iwlwifi: mvm: validate mac_link_id in session protect notif - wifi: iwlwifi: mvm: fix an off-by-1 boundary check - wifi: iwlwifi: mvm: parse beacon notif per layout - wifi: iwlwifi: mvm: fix sched scan IE sizing - wifi: iwlwifi: pcie: null RX pointers after free - ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs - blk-cgroup: fix leaks and online flag on radix_tree_insert failure - smb/client: flush dirty data before punching a hole - ASoC: Intel: sof_sdw: Add quirks for new Dell laptops - wifi: iwlwifi: mvm: validate TX_CMD response layout - wifi: iwlwifi: mvm: fix a possible underflow - [arm64] fixmap: Allow 256K early_ioremap() at any offset - wifi: iwlwifi: mvm: add a check on the tid coming from the firmware - wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif - [arm64] kprobes: Allow reentering kprobes while single-stepping - drm/amd/pm/si: Don't schedule thermal work when queue isn't initialized - ALSA: hda/realtek: Add quirk for HP Pavilion x360 - wifi: iwlwifi: bound aligned TLV advance in FW parser - ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless - wifi: iwlwifi: acpi: validate WGDS table revision index - ALSA: hda/realtek: Add HDA_CODEC_QUIRK for Samsung 750XBE/730XBE - wifi: mwifiex: replace one-element arrays with flexible array members - smb: client: bound dirent name against end of SMB response in cifs_filldir - regulator: core: clamp voltage constraints before applying apply_uV - wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO - ksmbd: preserve VFS inherited POSIX ACL mask - drm/gma500: return errors from Oaktrail HDMI I2C reads - phonet: check register_netdevice_notifier() error in phonet_device_init() - ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4 - ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx - ice: pass the return value of skb_checksum_help() - [powerpc*] pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash - cifs: validate idmap key payload length - wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() - Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame - ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) - ata: libata-core: Disable LPM on some WD drives - ALSA: hda/realtek: Add mute LED quirk for HP Victus 16-e0xxx (MB 88ED) - ata: libata-core: Disable LPM on WD Green 2.5 480GB - Drivers: hv: vmbus: add VTL2 redirect connection ID - [amd64] ASoC: amd: yc: Add DMI quirk for HP Victus Laptop 16-e1xxx - vhost-scsi: flush backend after device ioctls - hwmon: (corsair-psu) Fix linear11 calculation - ata: libata-core: Disable LPM on WDC WD141KFGX-68FH9N0 - spi: dw: fix wrong RX_SAMPLE_DLY setting after resume - ASoC: rt5645: Perform the initial jack detect at probe - scsi: core: Do not block on tag allocation in scsi_eh_lock_door() - ASoC: amd: yc: Add DMI quirk for HyperX OMEN Gaming Laptop 16-ap1xxx - netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state - firmware: stratix10-svc: fix FCS SMC call kernel-doc - bpftool: Strip all -Wformat* flags from bootstrap libbpf build - ksmbd: remove stale channels from all sessions on teardown - Revert "bpf, s390: Clear fetch destination on faulting arena atomic" - Revert "ARM: 9481/2: breakpoint: CFI breakpoints only on demand" - wifi: mt76: mt7921: validate CLC firmware records - wifi: mt76: mt7921: skip unknown CLC firmware records - drm/amd/display: clean-up dead code in dml2_mall_phantom - driver core: Export get_dev_from_fwnode() - of: dynamic: Fix overlayed devices not probing because of fw_devlink - ppp_async: drop the errored frame instead of resetting its headroom - drop_monitor: perform u64_stats updates under IRQ-disabled section (CVE-2026-68286) - drop_monitor: fix size calculations for 64-bit attributes (CVE-2026-68287) - net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (CVE-2026-68288) - tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (CVE-2026-68289) - drm/vc4: hvs/v3d: Fix null dereference in unbind (CVE-2026-68303) - bpf: Reject redirect helpers without a bpf_net_context (CVE-2026-68337) - Bluetooth: ISO: fix malformed ISO_END/CONT handling (CVE-2026-72334) - bpf: Mask pseudo pointer values in verifier logs (CVE-2026-72402) - sctp: fix err_chunk memory leaks in INIT handling (CVE-2026-72413) - md/raid10: fix writes_pending and barrier reference leaks on discard failures (CVE-2026-72438) - coresight: platform: defer connection counter increment until alloc succeeds (CVE-2026-72485) - RDMA/bnxt_re: Proper rollback if the ioremap fails (CVE-2026-72496) - bpf: Guard __get_user acesss with access_ok for uprobe_multi data (CVE-2026-74258) - ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). (CVE-2026-74289) - ASoC: topology: Check PCM and DAI name strings before use (CVE-2026-74291) - ASoC: meson: aiu: Validate written enum values (CVE-2026-74294) - ksmbd: use memcmp() to compare ClientGUIDs (CVE-2026-74521) - l2tp: fix tunnel and session refcount leak on seq_file release (CVE-2026-74735) - af_unix: Unlink scc_entry in unix_del_edge(). (CVE-2026-80521) - Bluetooth: btrtl: Add the support for RTL8761CUV - mm/damon/core: avoid infinite kdamond_merge_regions() internal loop (CVE-2026-89796) - [armhf] 9484/1: enable interrupts when unhandled user faults are triggered - [armhf] ensure interrupts are enabled in __do_user_fault() - RAS/AMD/ATL, EDAC/amd64: Only load ATL when needed - EDAC/igen6: Fix interleave boundary condition - EDAC/igen6: Fix channel selection hash - EDAC/igen6: Fix channel address decode for non-hash mode - EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation - drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() - accel/qaic: Address potential out-of-bounds read in resp_worker() - nvme-rdma: fix -EIO cleanup order in queue_rq - nvmet-rdma: fix queue leak when connect backlog is exceeded - sched_ext: Fix nonexistent field in sched-ext.rst example - bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic - ufs: do not treat unreadable directory blocks as empty - drm/cirrus: Use video aperture helpers - drm/cirrus-qemu: Validate BAR0 size during probe - net: icmp: avoid invalid transport header access in icmp_send tracepoint - tcp: use GFP_ATOMIC in tcp_send_active_reset() - net: iptunnel: fix stale transport header during tunnel decapsulation - net/sched: act_api: budget all shared attributes in notify skbs - net/sched: act_api: size the RTM_GETACTION reply from the actions - net/sched: act_api: fix skb sizing and action leak on reoffload delete - sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START - scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() - scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() - smb/client: validate new EOF for insert range - smb/client: validate new EOF for zero range - smb/client: mark file sparse before emulating insert range - smb: client: batch SRV_COPYCHUNK entries to cut round trips - smb: move copychunk definitions to common/smb2pdu.h - smb/client: fix data corruption in emulated insert range - smb/client: fix integer truncation in collapse range - smb: client: transport: Fix debug printing in __release_mid() - sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration - raw: annotate disconnect-side IPv4 match writers - net: amd-xgbe: discard rx packets with bad FCS - vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() - watchdog: msc313e: Fix NULL pointer dereference in PM callbacks - perf symbol: Do not use debug file as the binary type - OPP: of: Fix potential multiplication overflow when calculating freq - ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF - ksmbd: propagate DACL parsing errors - ksmbd: rate limit unmapped SID errors - [s390x] vtime: Use __this_cpu_read() / get rid of READ_ONCE() - [s390x] time: Use jiffies instead of jiffies_64 - [s390x] ipl: Fix NULL deref in kdump without re-IPL parm block - [s390x] ipl: Fix NULL deref in dump_reipl without re-IPL parm block - sched_ext: Fix timer pinning and return value in scx_central - Bluetooth: btintel_pcie: Clear automask on spurious interrupts - workqueue: replace use of system_wq with system_percpu_wq - workqueue: reject watchdog thresholds that overflow jiffies - Bluetooth: btintel: validate version TLV value lengths - Bluetooth: btintel: bound firmware ID by TLV length - Bluetooth: hci_core: Fix race condition during device registration - Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan - Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect - Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM - Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() - ASoC: ab8500: Reset the audio block before configuring it - ASoC: ab8500: Repair the DAPM capture graph - ASoC: ab8500: Correct digital interface format setup - ASoC: ab8500: Validate and program TDM slots correctly - net: ethernet: oa_tc6: Interrupt is active low, level triggered. - net: ethernet: oa_tc6: Handle the OA TC6 SPI protected mode - net: ethernet: oa_tc6: Export standard defined registers - net: ethernet: oa_tc6: Add the OA_TC6_ prefix to standard registers - net: ethernet: oa_tc6: Protect skb pointer used by two different kernel instances - net: ethernet: oa_tc6: Improve the error recovery - net: ethernet: oa_tc6: Disable tx queues on fatal error - net: ethernet: oa_tc6: Fix for the wrong data type - net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted - igmp: convert struct ip_sf_list to RCU - ppp: ppp_async: simplify tty disc_data access - ppp: ppp_synctty: simplify tty disc_data access - ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() - ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit - tipc: fix NULL deref in tipc_named_node_up() on empty publication list - tipc: Dont send random pad bytes in RESET/ACTIVATE messages - ipv6: sr: restore network header before routing and forwarding - af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). - staging: fbtft: make dirty_lock IRQ-safe - ALSA: hda/core: Use guard() for mutex locks - ALSA: hda: restore MFG widget enumeration after core split - [s390x] boot: Fix physical memory search range - [amd64] ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits - [amd64] ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() - drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() - btrfs: detach failed sprout device from transaction update list - btrfs: restore active device pointers after failed sprout - bonding: alb: fix uninitialized transport header access in alb_determine_nd() - [riscv64] perf: RISC-V: check cpu_hw_evt before dereference in overflow IRQ - scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() - perf/core: Skip empty AUX records with only format flags - locking/lockdep: Invalidate stale class_cache entries for zapped classes - octeontx2-af: Fix limiting SRIOV VF count logic - ALSA: rawmidi: Expose the tied device number in info ioctl - ALSA: rawmidi: Show substream activity in info ioctl - ALSA: ump: Copy FB name string more safely - ALSA: ump: Copy safe string name to rawmidi - ALSA: ump: Update rawmidi name per EP name update - ALSA: ump: do not touch legacy_rmidi before it exists - printk/nbcon: Change nbcon_irq_work to IRQ_WORK_LAZY - ASoC: ux500: Fix MSP stream lifecycle handling - ASoC: ux500: Propagate MSP setup errors - ASoC: ux500: Correct MSP frame and bit clock setup - ASoC: ux500: Validate MSP DAI configuration - mfd: db8500-prcmu: Remove needless return in three void APIs - mfd: db8500-prcmu: Fold dbx500 header into db8500 - ASoC: ux500: Deassert the MSP reset during probe - ASoC: ux500: Request the MSP MMIO resource - ASoC: ux500: Remove obsolete PRCMU QoS calls - ASoC: ux500: Allow repeated MSP prepare calls - ASoC: ux500: Program the MSP FIFO watermarks - btrfs: fix transaction use-after-free in raid stripe insertion - btrfs: fix the possible bioc_list memory leak during error - btrfs: return proper negative error code for update_raid_extent_item() - btrfs: zoned: finish active block group cleanup if call_zone_finish() fails - btrfs: send: fix lost error return value in will_overwrite_ref() - btrfs: do not force reloc root creation during qgroup_account_snapshot() - ipvs: fix reversed sequence option serialization - netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() - tracing/probes: Fix use-after-free on field name/type of events with multiple probes - bpf: reject BPF_PSEUDO_FUNC reference to the main program - bonding: do not clear curr_active_slave prematurely when releasing all slaves - net/rds: use wq_has_sleeper() in release_in_xmit() - net/rds: use clear_bit_unlock() in release_refill() - net/rds: clear cp_flags bits individually in rds_conn_path_reset() - net/rds: tcp: don't force RDS_CONN_RESETTING over a concurrent shutdown - net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() - net/rds: acquire the fastpath locks in rds_conn_shutdown() - net/rds: don't let rds_conn_shutdown() consume a concurrent drop - net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset - net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list() - [arm64] trans_pgd: clone only the linear map that exists at runtime - ALSA: caiaq: Fix potential double-free at error path - bpf: Fix NULL-ptr-deref when showing a void BTF type - bpf: Fix NULL-ptr-deref in btf_var_show() - bpf: Mark sched_process_wait argument as nullable - ring-buffer: Add checking nr_subbufs to persistent ring buffer validation - nvme: remove stale namespaces by NSID range during scan - nvme-tcp: open-code nvme_tcp_queue_request() for R2T - nvme-tcp: defer TLS inline send to io_work - [amd64] ASoC: Intel: avs: Clean up the bus when fetching ML caps fails - [amd64] ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology - [amd64] ASoC: Intel: avs: Fix unbalanced module reference count - net: bcmasp: clear txcb->last before writing each descriptor - net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times - bpf: Mark bpf_btf_find_by_name_kind() as sleepable - bpf: Mark faultable stack helpers as sleepable - bpf: Don't predict JMP32 pointer vs zero comparisons - thermal: sysfs: switch to use scnprintf() to suppress truncation warning - bpf: Require MEM_PERCPU for percpu kptr stores - bpf: Reject untrusted allocated-object pointers - nexthop: Initialize extack in remove_nh_grp_entry() - bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit() - net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size - ethtool: Symmetric OR-XOR RSS hash - ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested - net: ethtool: copy the rxfh flow handling - net: ethtool: remove the duplicated handling from rxfh and rxnfc - net: ethtool: require drivers to opt into the per-RSS ctx RXFH - net: ethtool: add dedicated callbacks for getting and setting rxfh fields - eth: nfp: migrate to new RXFH callbacks - eth: nfp: bound the ntuple rule dump by the caller's buffer size - eth: nfp: drop the replaced rule from the list when reprogramming fails - net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size - net: bridge: mcast: properly convert mglist to rcu - octeontx2-af: mcs: Clear stale X2P calibration state before calibration - ionic: use netif_txq_maybe_stop() in ionic_tx() - net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow - [s390x] ism: folio_put() after error - vxlan: reject dynamic fdb entries that reference a nexthop id - net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations - net: reject oversized tx_queue_len at netlink parse time - pds_core: fix cmd_regs access racing BAR unmap on reset - pds_core: don't release PCI regions for VFs on reset - [powerpc*] kexec_file: Use inclusive range checks in add_usable_mem() - net: mctp: i3c: serialize probe with bus removal - net/sched: defer qdisc freeing after failed creation - net/mlx5e: Fix setting RS FEC after remapping - net/mlx5e: Fix ETS zero BW reporting when one TC holds 100% - net/mlx5e: Fix use-after-free race in sample_restore_put() - net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put - net/mlx5: E-Switch, prevent mc_list repopulation during vport disable - net/sched: fq_pie: clamp quantum in change path - net/sched: sfq: clamp quantum in change path - net/sched: hhf: clamp quantum in change and init paths - net/sched: pie: clamp psched_mtu in pie_drop_early - net/sched: drr: clamp quantum in change class - net/sched: ets: clamp quantum in parse and fallback paths - net: macb: rename bp->sgmii_phy field to bp->phy - net: macb: fix NULL pointer dereference on unbind with fixed-link - bpf: Reject non-scalar bpf_loop iteration counts - ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev - hwmon: (ltc4282) Make sure clk_init_data is fully initialized - libnvdimm: Replace namespace_match() with device_find_child_by_name() - hwmon: Introduce 64-bit energy attribute support - hwmon: (ina2xx) Parameterize ina2xx_data in ina226_alert_read() - ASoC: bcm: bcm63xx: Publish the OF module aliases - [amd64] ASoC: Intel: SST: Publish the PCI module aliases - netfilter: nfnetlink_log: cope with concurrent instance destruction - netfilter: ip6_tables: set F_PROTO when proto value is nonzero - ASoC: mt6351: Publish the OF module alias - virtio: fix use-after-free in unregister_virtio_device() - virtio_console: do not free control-out buffers on remove - vhost/vdpa: reject VRING_NUM larger than device max - vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx - vhost-vdpa: protect config_ctx from being freed under the config callback - vdpa_sim_blk: reject out-of-range sector starts - vdpa_sim_net: check TX pull result before RX copy - virtio-pci: return IRQ_HANDLED after non-zero ISR - virtio_input: reset device if input_register_device() fails - virtio_input: stop callbacks before unregistering input device - af_unix: Update last skb marker in manage_oob(). - af_unix: Return immediately when manage_oob() returns NULL for 0-length buffer. - net: ipv6: Fix UDP length overflow with PMTU discover and big MTU - net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward - net: ethernet: cortina: Fix budget accounting - net: ethernet: cortina: Finish RX updates before NAPI completion - net: ethernet: cortina: Count dropped frames as NAPI work - net: ethernet: cortina: No mapping is a dropped rx - net: ethernet: cortina: Count RX drops once per frame - net: ethernet: cortina: Count RX descriptors for freeq refill - drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER - ALSA: hda: Introduce auto cleanup macros for PM - ALSA: hda/common: Use cleanup macros for PM controls - ALSA: hda/common: Use guard() for mutex locks - ALSA: hda: Report a change when only the channel status bytes move - idpf: account for VLAN header when parsing RSC packet header - ice: add missing xa_destroy for sched_node_ids - eth: ice: don't dereference pointers from TP_printk() - Bluetooth: btusb: Fix UAF of btusb_data by rx_work - Bluetooth: btintel_pcie: validate packet_len before skb_put_data - Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one - Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware - Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset - Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset - net: macb: destroy the phylink instance on the probe error path - mptcp: remove unneeded READ_ONCE() annotation - watchdog: fix hrtimer start when pretimeout is zero - watchdog: msc313e: Avoid division by zero - watchdog: msc313e: Fix clock leak and spurious timer in settimeout() - watchdog: msc313e: Enable clock before accessing hardware registers - watchdog: msc313e: Fix spurious reset on suspend - watchdog: msc313e: Fix undefined behavior - watchdog: msc313e: Sync timeout value if WDT was running at boot - net: dsa: lantiq_gswip: deduplicate dsa_switch_ops - net: dsa: lantiq_gswip: prepare for more CPU port options - net: dsa: lantiq_gswip: move definitions to header - net: dsa: lantiq_gswip: fix GSWIP_MDIO_PHY_FCONTX_EN value - net/micrel: Fix typos in micrel driver code comments - net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down - hwmon: (corsair-cpro) Create debugfs entries after hwmon registration - hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() - hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors - hwmon: (corsair-cpro) Remove debugfs entries when probe fails - octeontx2-pf: reset HTB scheduler topology before freeing queues - vxlan: initialize _md in vxlan_xmit_one() - ppp_synctty: ensure a writeable skb header - net: stmmac: initialize ptp_lock at probe time - perf: Supply task information to sched_task() - perf/core: Allow list_del during perf_event_overflow() - perf/core: Check sample_type in perf_sample_save_callchain - [amd64] perf/x86/intel/ds: Clarify adaptive PEBS processing - [amd64] perf/x86/intel/ds: Remove redundant assignments to sample.period - [amd64] perf/x86/intel/ds: Factor out PEBS group processing code to functions - [amd64] perf/x86/intel: Correct pt_regs->flags update for PEBS path - net/sched: cls_route: free emptied bucket on filter move - net/sched: cls_route: Reject handle aliasing - net/sched: cls_route: Fix in-place replace - net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). - net: sun4i-emac: fix missing of_node_put() for phy_node - net: hinic: fix mailbox segment buffer overflow - cxgb4: clip_tbl: Fix spelling mistake "wont" -> "won't" - net: phy: mediatek: Re-organize MediaTek ethernet phy drivers - net: phy: add phy_disable_eee - net: phy: mediatek-ge: disable EEE on the MT7530 PHY - octeontx2-af: fix PF/CGX debugfs PCI bus lookup - net/rds: fix tcp stream corruption with large pages - net: stmmac: TSO: Simplify the code flow of DMA descriptor allocations - net: stmmac: fix TSO support when some channels have TBS available - net: stmmac: add stmmac_tso_header_size() - net: stmmac: add TSO check for header length - net: stmmac: fix TX descriptor availability check for TSO traffic - net: hsr: enable promiscuous mode on interlink port with fwd offload - openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() - sunvdc: unmap LDC cookies when the descriptor send fails - scripts/mksysmap: fix escape of '$' in the __pi_ pattern - scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands - ksmbd: prevent out-of-bounds reads in share config responses (CVE-2026-89792) - [powerpc*] ps3: Fix repository.c build failure - [powerpc*] eeh: Fix recursive locking on devices without EEH sensitive driver - [amd64] crypto: x86/aria - add missing vzeroupper in AVX2 code - [amd64] crypto: x86/aria - add missing vzeroupper in AVX-512 code - [amd64] x86/mm: Fix user-space data loss with MADV_FREE and THP - ipv6: fix fib6 walker UAF on seq stop - tracing: Fix memory corruption from the histogram stacktrace modifier - ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough - ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf - ALSA: usbusx2y: validate URB actual_length in interrupt callback - dm/amdgpu: fix malformed link_settings debugfs output - watchdog: sunxi_wdt: preserve boot-enabled watchdog - ufs: create the root dentry after loading cylinder metadata - ufs: validate cylinder group metadata before caching it - tunnels: Drop stale dst when building an ICMP error for PMTUD (Closes: #1108860) - tick/broadcast: Plug clockevents replacement race - tracing/user_events: Don't destroy fields when event removal fails - tracing: Free histogram the var ref when its initialization fails - tracing: Free histogram var refs regardless of how often they are referenced - tracing: Free histogram the field rejected for a bad modifier - tracing: Let histogram values keep the percent and graph modifiers - tracing: Keep the entry count when the histogram stats allocation fails - accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr - accel/ivpu: Validate firmware log buffer metadata - accel/ivpu: Limit firmware log name prints to field size - ASoC: sprd: validate compress buffer sizes against fixed allocations - ASoC: sti: initialize IRQ lock before requesting IRQ - Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev - Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 - cpufreq: zero-initialize policy cpumask before sysfs publication - cpufreq: initialize policy rwsem before sysfs publication - exec: do_close_on_exec() before taking exec_update_lock - fs: don't return -EINVAL for successful nested thaw - drm/drm_exec: fix up contended obj when num_objects is 0 - [amd64] drm/i915: Fix memory leak in query_perf_config_list() - io_uring/net: let io_recv_buf_select return the length of the buffer region - ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters() - ring-buffer: Check resize_disabled before publishing the new subbuf order - net/sched: act_api: release all action references on NEWACTION failure - net: hso: fix TIOCMIWAIT race - net: mana: Reserve extra CQ slot for the fence completion CQE - net: mpls: clear inner_protocol when the last label is popped - net: openvswitch: fix use-after-free of the flow table mask array - netfilter: nf_log: unregister loggers before per-net teardown - netfilter: report NLM_F_DUMP_FILTERED when all is filtered out - vdpa: ifcvf: Put device on unsupported feature error - vdpa: solidrun: Free IRQs after request failure - scripts/sorttable: Mark long_size as __maybe_unused - fs: autofs: fix memory leak in autofs_fill_super() - erofs: preserve LZMA decoders on resize failure - fbdev: vfb: defer cleanup until the last reference - inet: frags: invalidate queues before flushing them - ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink - ieee802154: cc2520: fix FIFOP work use-after-free - ieee802154: hwsim: serialize pib updates to fix double-free - ipv4: fib: bound automatic table ID allocation - ipvs: reject invalid states in connection template sync records - mac802154: fix use-after-free of sdata via queued RX frames - [powerpc*] KVM: PPC: Book3S HV: Set irqfd->producer only on success - [s390x] qeth: allow bridgeport queries despite OS_MISMATCH - [s390x] crypto: Fix skcipher_walk return code handling in aes_s390 - [s390x] crypto: Fix use of mutex in atomic context - [s390x] crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm - [riscv64] perf: RISC-V: store available counter mask as bitmap - [riscv64] perf: RISC-V: use BIT_ULL for u64 overflow masks - afs: Fix incorrect free in candidate cleanup in afs_lookup_server() - afs: Clear stale peer app data after address list changes - hwmon: (applesmc) fix key backlight workqueue leak on register failure - hwmon: (chipcap2) fix channels in humidity alarm notifications - hwmon: (gpio-fan) Fix use-after-free in alarm work - hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS - media: hevc: add bounded tile-count helpers - media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity - media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity - media: v4l2-h264: Fix memcmp() size in B1 reference list comparison - media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer - media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity - media: v4l2-ctrls: validate HEVC tile counts - media: v4l2-ctrls: validate AV1 tile counts - bnxt_en: Only restore LRO if the device supports TPA - bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() - bnxt_en: Propagate RX ring init failures in bnxt_init_nic() - mptcp: options: handle MPC data + csum reqd + no csum - mptcp: subflow: no need to copy thmac during ulp_clone - mptcp: syncookies: remember the request backup flag - smb: client: reject userspace cifs.idmap descriptions - smb: client: pin DFS superblock in iterator callback - smb: client: fix one-byte OOB read in smb2_parse_native_symlink() - smb: client: fix file type corruption in cifs_reparse_point_to_fattr() - smb: client: fix file type corruption in wsl_to_fattr() - smb: client: avoid leaking refcount in cifs_queue_oplock_break() - smb: client: avoid leaking refcount when cifs_sb_tlink() fails - smb: client: fix heap overflow in DACL owner/group rewrite - xfs: truncate quota file correctly when repairing quota file - xfs: snapshot scrub stats when rendering them - xfs: snapshot old AGFL before rewriting it - xfs: signal inode btree xref error if get_rec returns an error - xfs: reset parent pointer args before each dir tree unlink repair - xfs: report nonexistent parents as a filesystem corruption - xfs: preserve owner on in-memory btree creation - xfs: log the tempip after we convert it to extents format - xfs: initialise error in xfs_defer_finish_one() - xfs: fix replaying dirent removals into the temporary directory - xfs: fix name string recording in slowpath pptr tracepoints - xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN - xfs: fix bnobt repair space reservation disposal failure - xfs: fix backwards skipping logic in xrep_quota_block - xfs: don't spin forever on zero-length dirents when salvaging them - xfs: don't modify file attributes or poke fsnotify for dry runs - xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails - xfs: don't leak dqacct if rhashtable insertion fails - xfs: destroy seen inode bitmap when we fail to add a dirpath - xfs: count escaped corruption errors in scrub stats - xfs: compute dquot checksum after resetting dd_lsn in repair - xfs: bail out on bitmap errors in xrep_agfl_fill - xfs: advance the findparent inode scan cursor while holding ILOCK - xfs: actually recover intended file sizes in xfs_xmi_item_recover_intent - smb: client: fix UBSAN array-index-out-of-bounds in smb2_copychunk_range - crypto: ccp - Fix possible deadlock in SEV init failure path - iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized (CVE-2026-90430) - Revert "arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries" - Revert "arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries" - Revert "nvme-apple: Reset q->sq_tail during queue init" - Revert "nvme-apple: Prevent shared tags across queues on Apple A11" - Revert "nvme-apple: Drop the PRP null check chicken bit" - Revert "nvme: apple: Add Apple A11 support" - Revert "slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL" - Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems" - perf evsel: Add per-thread warning for EOPNOTSUPP open failues - xdrgen: Fix union declarations - usb: xusbatm: don't rely on id table pointer arithmetic - wifi: ath9k_htc: don't store usb_device_id - usb: usbtmc: don't store usb_device_id - usb: serial: spcp8x5: don't store usb_device_id - media: as102: do not rely on id table address comparison - net: usb: pegasus: don't rely on id table pointer arithmetic - ALSA: us122l: Prevent write upgrades for read mappings - i2c: smbus: reject oversized block transfers in the common path - net: appletalk: fix NULL pointer dereference in aarp_send_ddp() - fou: Fix use-after-free in fou_create() (CVE-2026-74496) - xfs: initialise args->total for parent pointer updates - bpf: fix the return value of push_stack - netfilter: nft_set_pipapo_avx2: add missing vzeroupper - usb: xhci: add USB Port Register Set struct - usb: xhci: use cached HCSPARAMS1 value - usb: xhci: simplify handling of Structural Parameters 1 values - usb: xhci: bail out of setup if the controller is inaccessible (CVE-2026-80861) - fuse: fix race between interrupt and resend (CVE-2026-80860) - [amd64] KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y - [amd64] KVM: SEV: Make it more obvious when KVM is writing back the current PSC index - [amd64] KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata - ipv6: pass proto by value to ipv6_push_nfrag_opts() and ipv6_push_frag_opts() - ipv6: add some unlikely()/likely() clauses in ip6_output.c - inet: add dst4_mtu() and dst6_mtu() helpers - ipv6: use dst6_mtu() instead of dst_mtu() - ipv4: use dst4_mtu() instead of dst_mtu() - tcp: clamp route advmss to TCP_MIN_MSS (CVE-2026-80847) - net/packet: defer vmalloc TX_RING free until skbs finish (CVE-2026-80841) - vlan: fix skb_under_panic and races when toggling HW VLAN offload (CVE-2026-80925) - crypto: virtio - Drop sign/verify operations - crypto: virtio - Drop superfluous [as]kcipher_ctx pointer - crypto: virtio - Drop superfluous [as]kcipher_req pointer - crypto: virtio - bound the akcipher result length (CVE-2026-80836) - net: advertise TCP MSS from the configured MTU, not the learned PMTU - [amd64] KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa - [amd64] KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates - [amd64] KVM: SVM: Invalidate "next" SNP VMSA GPA even on failure - [amd64] KVM: SEV: Disable SEV-SNP support on initialization failure - [amd64] KVM: SVM: Move SEV-ES VMSA allocation to a dedicated sev_vcpu_create() helper - [amd64] KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests - crypto: atmel-ecc - avoid stale fallback key after set_secret failure - crypto: iaa - unmap dst before software fallback on decompress (CVE-2026-80945) - mm: fix possible NULL pointer dereference in __swap_duplicate - mm, swap: ratelimit bad swap entry reports - KEYS: trusted: Fix TPM teardown ordering (CVE-2026-89763) - mm: move hugetlb specific things in folio to page[3] - mm: move _pincount in folio to page[2] on 32bit - mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios() - mm/migrate_device: clear stale mapping after freeing swapcache (CVE-2026-89755) - mm/slab: move and refactor __kmem_cache_alias() - mm/slub: fix missing debugfs entries for caches created before sysfs init - [amd64] x86/locking: Remove semicolon from "lock" prefix - [amd64] x86/locking: Use sfence for wmb() if SSE is available - xen/balloon: improve accuracy of initial balloon target for dom0 - [amd64] x86/xen: fix init of balloon stats again - cxl/pci: Remove unnecessary CXL Endpoint handling helper functions - cxl/pci: Remove unnecessary CXL RCH handling helper functions - cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c - cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read (CVE-2026-89731) - USB: gadget: ffs: fix mm lifetime handling (CVE-2026-90045) - usb: gadget: f_fs: Fix Use-After-Free in AIO error path (CVE-2026-90044) - zram: fixup read_block_state() - zram: fix out-of-bounds access in read_block_state() (CVE-2026-89719) - zram: remove entry element member - zram: use zram_read_from_zspool() in writeback - zram: fix out-of-bounds access in writeback_store() (CVE-2026-89718) - zram: switch to guard() for init_lock - zram: set default primary compressor in zram_destroy_comps() (CVE-2026-89717) - netlink: introduce type-checking attribute iteration for nlmsg - nfsd: validate sockaddr length per family in listener_set (CVE-2026-89700) - nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() (CVE-2026-89693) - NFSD: Rename a function parameter - NFSD: Make nfsd_genl_rqstp::rq_ops array best-effort - Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" - nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage (CVE-2026-89698) - nfsd: dedup nfs4_client_to_reclaim inserts - nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown (CVE-2026-89708) - nfsd: fix clock domain mismatch in clients_still_reclaiming() (CVE-2026-89685) - nfsd: fix netlink dumpit error handling for rpc_status_get - nfsd: update mtime/ctime on COPY in presence of delegated attributes - nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (CVE-2026-89676) - nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache (CVE-2026-89667) - NFSD: Prevent client use-after-free during admin state revocation (CVE-2026-89660) - nfsd: disallow file locking and delegations for NFSv4 reexport - NFSD: Prevent client use-after-free during delegation revoke (CVE-2026-89659) - ceph: Remove fs/ceph deadcode - ceph: force a cap message when a deferred revoke can't be acked immediately - NFSD: Guard admin state-revocation walks with NFSD_NET_UP (CVE-2026-90039) - ceph: properly decrypt filenames in vmalloc() buffers (CVE-2026-90042) - HID: apple: preserve keyboard backlight across T2 resume - btrfs: move btrfs_is_empty_uuid() from ioctl.c into fs.c - btrfs: move BTRFS_BYTES_TO_BLKS() into fs.h - btrfs: move btrfs_alloc_write_mask() into fs.h - btrfs: expose per-inode stable writes flag - btrfs: update include and forward declarations in headers - btrfs: parameter constification in ioctl.c - btrfs: pass struct btrfs_inode to btrfs_sync_inode_flags_to_i_flags() - btrfs: prepare btrfs_punch_hole_lock_range() for large data folios - btrfs: use BTRFS_PATH_AUTO_FREE in can_nocow_extent() - btrfs: add btrfs prefix to main lock, try lock and unlock extent functions - btrfs: rename extent map functions to get block start, end and check if in tree - btrfs: fix extent map leak in NOCOW direct I/O write (CVE-2026-89644) - btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag - HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind (CVE-2026-89625) - HID: universal-pidff: stop the device when force-feedback init fails (CVE-2026-89624) - HID: sony: use guard() and scoped_guard() - HID: sony: clean up device list on probe failure (CVE-2026-90041) - HID: mcp2221: fix OOB write in mcp2221_raw_event() - HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes (CVE-2026-89622) - NFSD: Consolidate the revocation-path client unpin - NFSD: Prevent client use-after-free during blocked-lock reaping (CVE-2026-90036) - NFSD: Prevent client use-after-free during close_lru reaping (CVE-2026-90037) - erofs: skip sufficiently large global buffers when resizing (CVE-2026-89602) - efi/cper, cxl: Prefix protocol error struct and function names with cxl_ - efi/cper, cxl: Make definitions and structures global - acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks (CVE-2026-89589) - cpufreq: apple-soc: Fix OPP table cleanup (CVE-2026-89572) - bpf: Factor stackid_init function from __bpf_get_stackid - bpf: Factor stackid_fastpath function from __bpf_get_stackid - bpf: Factor stackid_new_bucket from __bpf_get_stackid - bpf: Use stack id functions instead of __bpf_get_stackid - bpf: Disable preemption in bpf_get_stackid (CVE-2026-89799) - ACPI: TAD: Rearrange RT data validation checking - ACPI: TAD: Split three functions to untangle runtime PM handling - ACPI: TAD: Add locking around AML evaluations - cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register - ipv6: annotate data-races around devconf->rpl_seg_enabled - ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() (CVE-2026-89561) - ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers - ipv6: ip6_mc_input() and ip6_mr_input() cleanups - ip: orphan prefetched skbs before multicast forwarding (CVE-2026-89564) - SUNRPC: Introduce xdr_set_scratch_folio() - SUNRPC: Update svcxdr_init_decode() to call xdr_set_scratch_folio() - sunrpc: defer rq_argp and rq_resp free until after RCU grace period (CVE-2026-89545) - SUNRPC: fix gssx_dec_option_array error path bugs (CVE-2026-89544) - rpc_populate(): lift cleanup into callers - rpc_mkpipe_dentry(): saner calling conventions - rpc_pipe: don't overdo directory locking - sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir (CVE-2026-89543) - rpcrdma: arm rn_done before publishing the notification (CVE-2026-89798) - svcrdma: Release transport resources synchronously - svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id (CVE-2026-89535) - sunrpc: Add a helper to derive maxpages from sv_max_mesg - svcrdma: Adjust the number of entries in svc_rdma_recv_ctxt::rc_pages - svcrdma: Reject Write/Reply chunks with segcount 0 - sched_ext: Fix inverted ops.core_sched_before() invocation - ocfs2: validate dx_root extent list fields during block read - ocfs2: validate directory-index entry counts when reading metadata (CVE-2026-89492) - mm, hugetlb: increment the number of pages to be reset on HVO - workqueue: Update documentation as per system_percpu_wq naming - SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode - mptcp: avoid unneeded actions on subflow reset - mptcp: close race between scheduler and state change - mptcp: fix bad accounting in __mptcp_subflow_push_pending() . [ Salvatore Bonaccorso ] * Replace MEMORY_HOTPLUG_DEFAULT_ONLINE settings with MHP_DEFAULT_ONLINE_TYPE_{AUTO,OFFLINE} * udeb: Exclude i2c-hid-acpi-prp0001 from input-modules udeb * perf tests: Change shebang for stat_bpf_counters.sh to #!/bin/bash Checksums-Sha1: c2774f34fc180177a80a02bddb1afac503eee67b 290418 linux_6.12.111-1.dsc 4b675d7515be469cee00db1ad4301ed5d2f4e7b3 151518968 linux_6.12.111.orig.tar.xz 590c4d813787722dcbf6c3c016d309d88cc658ce 1933512 linux_6.12.111-1.debian.tar.xz a3f6281ff0027383e5832f2392b69ba7f23a2c73 5883 linux_6.12.111-1_source.buildinfo Checksums-Sha256: 6935287a25ed12865714b53cb936959db5875ee025abdaadea8df6335fe74d55 290418 linux_6.12.111-1.dsc 716516cd85c3ff9e5c197203730b698ad7c0fb4c6c2d1d1e44ab3ced2faba178 151518968 linux_6.12.111.orig.tar.xz e0146c63a70014f23141fe3e4e830e8a5b2627427d449f3e5415d930016be297 1933512 linux_6.12.111-1.debian.tar.xz ad4e615b3a73ac70ec7c2a9c4745400ece78241f6a03d99ab174c43162047d4b 5883 linux_6.12.111-1_source.buildinfo Files: 554b0a6397d422ed3b191c80efce8cc6 290418 kernel optional linux_6.12.111-1.dsc 4ee1676f17b29678edc45e485d4cfeae 151518968 kernel optional linux_6.12.111.orig.tar.xz 331fc377a1fedc72228213252c6737ae 1933512 kernel optional linux_6.12.111-1.debian.tar.xz fb0c46b25153bc10f0779789c4036dd9 5883 kernel optional linux_6.12.111-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmq6W3pfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EykoP/34jNbr4qsRuevc1aqVsrazaOpcyPP+m l2wvUocgRo3rIUM2KrLCps9XzPFeM/qP1NjsBnc7Z3On9/zKsQrBdHFySeDyAvoZ zA0+1dKw8JWCf3PBYz8tZ27NRciIPIF7YJLhQVOMGmDbO/cnLIGYoersUrOEaVGs rH/iWHyIe5/utxSVznHb6IY4W1TxPiDXp2n9SJO/iQfmdxDG2/xhjyrM/Od6rN/G Hs/51PU6rErow7tZnjyPR+EA1dVvfr4Rjelh18+612N6kc9gfZXHck+FYZ8tjWP5 VGSY4z11X9fQzVD4BHuice9sgwE1gOb68h4Ni72sjbMO/8RkqPrRd/Hloz6RTdMQ iSPp/fNkn5YjC/VkyqhtGpf3+PQCKgsVDlnHkCpfSbWHU12pqzhyBHwLAGxsxNLC tuOjYtCwlz2hEs02rAGSyQZcD0PBnYM1ec0lFdbLBHZsyHNEwGnxMg43+q0qfSBi 5m8QntMKFWTyu41jjRfvNNnmwmv/trt4tQCKf4cDcxilfUpHZYmetTo1u9oq0JQj eM7FdHz4EBzwVrz1tfobD5uLAe9H3YXFpbkxUQ8P3cKsnacSXIeh4awydKkxpJGm MteCwPqIyWMWRJF4mSWAZTJqBN9LqYp2eDteJFV+2PKMRMCN7SeF5X0mfKjDbCEP Ow7/r763pSmh =kQN5 -----END PGP SIGNATURE-----