Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Oracle Linux 8: Kernel Important System Threat Advisory ELSA-2025-25757

oracle
Calendar Grey November 12, 2025
Oracle Linux Logo Esm H88
Oracle Linux 8 security advisory covering important kernel updates and vulnerabilities addressed in ELSA-2025-25757.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[5.15.0-314.193.5.3] - Revert "cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry" (Samasth Norway Ananda) [Orabug: 38633525] [5.15.0-314.193.5.2] - i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38607608] {CVE-2025-39973} - i40e: increase max descriptors for XL710 (Justin Bronder) [Orabug: 38607608] - uek-rpm: Enable CONFIG_COMPAT_32BIT_TIME for x86 container kernel (Boris Ostrovsky) [Orabug: 38607625] [5.15.0-314.193.5.1] - crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (Eric Biggers) [Orabug: 38575804] - crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (Herbert Xu) [Orabug: 38575804] {CVE-2025-39964} [5.15.0-314.193.5] - Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set" (Jakub Kicinski) [Orabug: 38545203]

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.15.0-314.193.5.3.el8uek.src.rpm

x86_64

bpftool-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-core-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-debug-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-debug-core-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-debug-devel-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-debug-modules-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-debug-modules-extra-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-devel-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-doc-5.15.0-314.193.5.3.el8uek.noarch.rpm kernel-uek-modules-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-modules-extra-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-container-5.15.0-314.193.5.3.el8uek.x86_64.rpm kernel-uek-container-debug-5.15.0-314.193.5.3.el8uek.x86_64.rpm

aarch64

bpftool-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-core-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-debug-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-debug-core-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-devel-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-doc-5.15.0-314.193.5.3.el8uek.noarch.rpm kernel-uek-modules-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-container-5.15.0-314.193.5.3.el8uek.aarch64.rpm kernel-uek-container-debug-5.15.0-314.193.5.3.el8uek.aarch64.rpm - uek-rpm/config-aarch64: Enable configs for Grace platform support (Vijay Kumar) [Orabug: 38526393] - uek-rpm: mips: Enable CONFIG_TRANSPARENT_HUGEPAGE (Henry Willard) [Orabug: 38526762] - crypto: ccp - Add support for PCI device 0x17D8 (John Allen) [Orabug: 38332429] - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (Yazen Ghannam) [Orabug: 38332429] - x86/cpufeatures: Free up unused feature bits (Sohil Mehta) [Orabug: 38332429] - x86/CPU/AMD: Rename init_amd_zn() to init_amd_zen_common() (Borislav Petkov) [Orabug: 38332429] - x86/CPU/AMD: Call the spectral chicken in the Zen2 init function (Borislav Petkov) [Orabug: 38332429] - x86/CPU/AMD: Move erratum 1076 fix into the Zen1 init function (Borislav Petkov) [Orabug: 38332429] - x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function (Borislav Petkov) [Orabug: 38332429] - x86/CPU/AMD: Carve out the erratum 1386 fix (Borislav Petkov) [Orabug: 38332429] - x86/CPU/AMD: Add X86_FEATURE_ZEN5 (Borislav Petkov) [Orabug: 38332429] - rds: Free all frags when rds_ib_recv_cache_put() fails (Hans Westgaard Ry) [Orabug: 38492233] - cpufreq: CPPC: Fix unused-function warning (Pierre Gondois) [Orabug: 38471683] - PM: EM: Add .get_cost() callback (Lukasz Luba) [Orabug: 38471683] - PM: EM: add macro to set .active_power() callback conditionally (Lukasz Luba) [Orabug: 38471683] - cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry (Beata Michalska) [Orabug: 38471683] - cpufreq: update to sysfs_emit() for safer buffer handling (Perry Yuan) [Orabug: 38471683] - cpufreq: Optimize cpufreq_show_cpus() (Viresh Kumar) [Orabug: 38471683] - PCI: Use downstream bridges for distributing resources (Kai-Heng Feng) [Orabug: 38471683] - PCI: Distribute available resources for root buses, too (Mika Westerberg) [Orabug: 38471683] - PCI: Move pci_assign_unassigned_root_bus_resources() (Mika Westerberg) [Orabug: 38471683] - cppc_cpufreq: Remove HiSilicon CPPC workaround (Jie Zhan) [Orabug: 38471683] - cpufreq: remove useless INIT_LIST_HEAD() (Han Wang) [Orabug: 38471683] - cpufreq/cppc: Don't compare desired_perf in target() (Riwen Lu) [Orabug: 38471683] - cpufreq/cppc: Move and rename cppc_cpufreq_{perf_to_khz|khz_to_perf}() (Vincent Guittot) [Orabug: 38471683] - cpufreq: CPPC: Register EM based on efficiency class information (Pierre Gondois) [Orabug: 38471683] - cpufreq: CPPC: Enable fast_switch (Pierre Gondois) [Orabug: 38471683] - i2c: tegra: check msg length in SMBUS block read (Akhil R) [Orabug: 38254038,38471683] {CVE-2025-38425} - PCI/ACS: Fix 'pci=config_acs=' parameter (Tushar Dave) [Orabug: 38471683] - RDMA/mlx5: Add support to multi-plane device and port (Mark Zhang) [Orabug: 38471683] - net/mlx5: mlx5_ifc update for multi-plane support (Mark Zhang) [Orabug: 38471683] - RDMA/core: Create "issm*" device nodes only when SMI is supported (Mark Zhang) [Orabug: 38471683] - RDMA/mlx5: Limit usage of over-sized mkeys from the MR cache (Michael Guralnik) [Orabug: 38471683] - RDMA/mlx5: Fix counter update on MR cache mkey creation (Michael Guralnik) [Orabug: 38471683] - RDMA/mlx5: Enable ATS when allocating kernel MRs (Maher Sanalla) [Orabug: 38471683] - ACPI: PRM: Remove unnecessary strict handler address checks (Aubrey Li) [Orabug: 38471683] - ACPI/HMAT: Move HMAT messages to pr_debug() (Dan Williams) [Orabug: 38471683] - ACPI: HMAT: Drop unused dev_fmt() and redundant 'HMAT' prefix (Liu Shixin) [Orabug: 38471683] - perf: arm_cspmu: nvidia: monitor all ports by default (Besar Wicaksono) [Orabug: 38471683] - perf: arm_cspmu: nvidia: enable NVLINK-C2C port filtering (Besar Wicaksono) [Orabug: 38471683] - perf: arm_cspmu: nvidia: fix sysfs path in the kernel doc (Besar Wicaksono) [Orabug: 38471683] - perf: arm_cspmu: nvidia: remove unsupported SCF events (Besar Wicaksono) [Orabug: 38471683] - device-dax: correct pgoff align in dax_set_mapping() (Kun(Llfl)) [Orabug: 37206403] {CVE-2024-50022} - vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() (Yishai Hadas) [Orabug: 37434467] {CVE-2024-56742} - sched/fair: add opt-in knob to use runnable_avg in wakeup fast path (Daniel Jordan) [Orabug: 38404517] - RDMA/mlx5: Fix vport loopback forcing for MPV device (Patrisious Haddad) [Orabug: 38225626] [5.15.0-314.193.4] - af_unix: Don't leave consecutive consumed OOB skbs. (Kuniyuki Iwashima) [Orabug: 38528187] {CVE-2025-38236} - Revert "net/mlx5e: Update and set Xon/Xoff upon port speed set" (Tariq Toukan) - NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust) - soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson) - cpufreq: Initialize cpufreq-based invariance before subsys (Christian Loehle) - tracing: Do not add length to print format in synthetic events (Steven Rostedt) - flexfiles/pNFS: fix NULL checks on result of ff_layout_choose_ds_for_read (Tigran Mkrtchyan) - drm/amdgpu: fix a memory leak in fence cleanup when unloading (Alex Deucher) - rtnetlink: Fix L3 stats disable handling in rtnl_offload_xstats_fill() (Vijayendra Suman) [Orabug: 38511910] - Revert "md/raid10: fix missing discard IO accounting" (Richard Li) [Orabug: 38483693] - uek: kabi: Update check-kabi to support namespace checks (Saeed Mirzamohammadi) [Orabug: 38459104] [5.15.0-314.193.3] - LTS version: v5.15.193 (Vijayendra Suman) - LTS version: v5.15.192 (Vijayendra Suman) - dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen) - spi: tegra114: Use value to check for invalid delays (Aaron Kling) - clk: qcom: gdsc: Set retain_ff before moving to HW CTRL (Taniya Das) - perf bpf-event: Fix use-after-free in synthesis (Ian Rogers) - drm/bridge: ti-sn65dsi86: fix REFCLK setting (Michael Walle) - spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore) - spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore) - spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore) - pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang) - ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai) - mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494760] {CVE-2025-39902} - randstruct: gcc-plugin: Fix attribute addition (Kees Cook) - randstruct: gcc-plugin: Remove bogus void member (Kees Cook) - arm64: dts: marvell: uDPU: define pinctrl state for alarm LEDs (Gabor Juhos) - vmxnet3: update MTU after device quiesce (Ronak Doshi) - net: dsa: microchip: linearize skb for tail-tagging switches (Jakob Unterwurzacher) - net: dsa: microchip: update tag_ksz masks for KSZ9477 family (Pieter Van Trappen) - dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen) - dma-buf: insert memory barrier before updating num_fences (Hyejeong Choi) [Orabug: 38152833] {CVE-2025-38095} - gpio: pca953x: fix IRQ storm on system wake up (Emanuele Ghidoli) - iio: light: opt3001: fix deadlock due to concurrent flag access (Luca Ceresoli) [Orabug: 37977027] {CVE-2025-37968} - iio: chemical: pms7003: use aligned_s64 for timestamp (David Lechner) - spi: tegra114: Don't fail set_cs_timing when delays are zero (Aaron Kling) - spi: tegra114: Remove unnecessary NULL-pointer checks (Alexander Danilenko) - KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer (Sean Christopherson) [Orabug: 38494247] - cpufreq/sched: Explicitly synchronize limits_changed flag handling (Rafael J. Wysocki) - mm/khugepaged: fix ->anon_vma race (Jann Horn) - e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits) [Orabug: 38494739] {CVE-2025-39898} - batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort) - scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456753] {CVE-2025-39841} - drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher) - wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494722] {CVE-2025-39891} - mm: move page table sync declarations to linux/pgtable.h (Harry Yoo) [Orabug: 38456763] {CVE-2025-39844} - x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() (Harry Yoo) [Orabug: 38456766] {CVE-2025-39845} - pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke) - ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae) - phy: mscc: Stop taking ts_lock for tx_queue and use its own lock (Horatiu Vultur) - net: phy: mscc: Fix memory leak when using one step timestamping (Horatiu Vultur) [Orabug: 38153076] {CVE-2025-38148} - ptp: Add generic PTP is_sync() function (Kurt Kanzenbach) - ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456780] {CVE-2025-39847} - net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang) - ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet) - ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter) - net: thunder_bgx: decrement cleanup index before use (Rosen Penev) - net: thunder_bgx: add a missing of_node_put (Rosen Penev) - wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter) - wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter) - net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau) - i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456813] {CVE-2025-39853} - icmp: fix icmp_ndo_send address translation for reply direction (Fabian Bläse) - mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin) - xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari) - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456833] {CVE-2025-39860} - netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter) - netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (Wang Liang) [Orabug: 38494730] {CVE-2025-39894} - wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456858] {CVE-2025-39864} - arm64: dts: rockchip: Add vcc-supply to SPI flash on rk3399-pinebook-pro (Peter Robinson) - tee: fix NULL pointer dereference in tee_shm_put (Pei Xiao) [Orabug: 38456865] {CVE-2025-39865} - fs: writeback: fix use-after-free in __mark_inode_dirty() (Jiufei Xue) [Orabug: 38456870,38528183] {CVE-2025-39866} - drm/amd/display: Don't warn when missing DCE encoder caps (Timur Kristóf) - bpf: Fix oob access in cgroup local storage (Daniel Borkmann) [Orabug: 38324117] {CVE-2025-38502} - bpf: Move bpf map owner out of common struct (Daniel Borkmann) - bpf: Move cgroup iterator helpers to bpf.h (Daniel Borkmann) - bpf: Add cookie object to bpf maps (Daniel Borkmann) - LTS version: v5.15.191 (Vijayendra Suman) - xfs: do not propagate ENODATA disk errors into xattr code (Eric Sandeen) [Orabug: 38440385] {CVE-2025-39835} - Revert "drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS" (Imre Deak) - HID: mcp2221: Handle reads greater than 60 bytes (Hamish Martin) - HID: mcp2221: Don't set bus speed on every transfer (Hamish Martin) - drm/nouveau/disp: Always accept linear modifier (James Jones) - net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda) - dma/pool: Ensure DMA_DIRECT_REMAP allocations are decrypted (Shanker Donthineni) - Revert "drm/amdgpu: fix incorrect vm flags to map bo" (Alex Deucher) [Orabug: 38343660] - HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440227] {CVE-2025-39808} - HID: wacom: Add a new Art Pen 2 (Ping Cheng) - HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() (Qasim Ijaz) [Orabug: 38440223] {CVE-2025-39806} - HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440309] {CVE-2025-39824} - efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440276] {CVE-2025-39817} - sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440249] {CVE-2025-39812} - net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas) - net/mlx5e: Set local Xoff after FW update (Alexei Lazar) - net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar) - net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar) - phy: mscc: Fix when PTP clock is register and unregister (Horatiu Vultur) - net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu) - atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440345] {CVE-2025-39828} - Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz) - powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan) - net: ipv4: fix regression in local-broadcast routes (Oscar Maes) [Orabug: 38343660] - vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov) - NFS: Fix a race when updating an existing write (Trond Myklebust) [Orabug: 38401609] {CVE-2025-39697} - nfs: fold nfs_page_group_lock_subrequests into nfs_lock_and_join_requests (Christoph Hellwig) - ASoC: codecs: tx-macro: correct tx_macro_component_drv name (Alexey Klimov) - scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal) - ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440258] {CVE-2025-39813} - pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap) - LTS version: v5.15.190 (Vijayendra Suman) - alloc_fdtable(): change calling conventions. (Al Viro) - wifi: mac80211: check basic rates validity in sta_link_apply_parameters (Mikhail Lobanov) - netfilter: nf_reject: don't leak dst refcount for loopback packets (Florian Westphal) [Orabug: 38401481] {CVE-2025-38732} - s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter) - s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter) - ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai) - bonding: update LACP activity flag after setting lacp_active (Hangbin Liu) - net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu) - net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu) [Orabug: 38423456] {CVE-2025-39766} - ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing) - net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization (Yuichiro Tsuji) [Orabug: 38516727] {CVE-2025-38736} - phy: mscc: Fix timestamping for vsc8584 (Horatiu Vultur) - net: phy: Use netif_rx(). (Sebastian Andrzej Siewior) - ppp: fix race conditions in ppp_fill_forward_path (Qingfang Deng) [Orabug: 38401500] {CVE-2025-39673} - ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong) - drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() (Chenyuan Yang) - ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Dan Carpenter) [Orabug: 38343660] - drm/hisilicon/hibmc: fix the hibmc loaded failed bug (Baihan Li) [Orabug: 38423473] {CVE-2025-39772} - mlxsw: spectrum: Forward packets with an IPv4 link-local source IP (Ido Schimmel) - iommu/amd: Avoid stack buffer overflow from kernel cmdline (Kees Cook) [Orabug: 38360925] {CVE-2025-38676} - scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401513] {CVE-2025-39676} - net: bridge: fix soft lockup in br_multicast_query_expired() (Wang Liang) [Orabug: 38423478] {CVE-2025-39773} - RDMA/bnxt_re: Fix to initialize the PBL array (Anantha Prabhu) - cgroup/cpuset: Use static_branch_enable_cpuslocked() on cpusets_insane_config_key (Waiman Long) - mm/page_alloc: detect allocation forbidden by cpuset and bail out early (Feng Tang) - x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper (Tianxiang Peng) [Orabug: 38401541] {CVE-2025-39681} - iio: light: as73211: Ensure buffer holes are zeroed (Jonathan Cameron) - tracing: Limit access to parser->buffer when trace_get_user failed (Pu Lehui) [Orabug: 38401546] {CVE-2025-39683} - tracing: Remove unneeded goto out logic (Steven Rostedt) - iio: imu: inv_icm42600: change invalid data error to -EBUSY (Jean-Baptiste Maneyrol) - usb: xhci: Fix slot_id resource race conflict (Weitao Wang) - selftests: mptcp: pm: check flush doesn't reset limits (Matthieu Baerts) - pwm: mediatek: Fix duty and period setting (Uwe Kleine-König) - pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-König) - pwm: mediatek: Implement .apply() callback (Uwe Kleine-König) - scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems (Ranjan Kumar) - scsi: mpi3mr: Drop unnecessary volatile from __iomem pointers (Ranjan Kumar) - scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE (André Draszik) - iio: adc: ad_sigma_delta: change to buffer predisable (David Lechner) - soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423523] {CVE-2025-39787} - wifi: ath11k: fix dest ring-buffer corruption when ring is full (Johan Hovold) - asm-generic: Add memory barrier dma_mb() (Kefeng Wang) - locking/barriers, kcsan: Support generic instrumentation (Marco Elver) - media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz) - media: venus: Add support for SSR trigger using fault injection (Dikshita Agarwal) - media: qcom: camss: cleanup media device allocated resource on error path (Sasha Levin) - media: camss: Convert to platform remove callback returning void (Uwe Kleine-König) - f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu) - drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak) - mptcp: disable add_addr retransmission when timeout is 0 (Geliang Tang) - drm/amd/display: Don't overclock DCE 6 by 15% (Timur Kristóf) - usb: dwc3: Remove WARN_ON for device endpoint command timeouts (Selvarasu Ganesan) [Orabug: 38435009] {CVE-2025-39801} - usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai) - USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen) - usb: storage: realtek_cr: Use correct byte order for bcs->Residue (Thorsten Blum) - USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin) - usb: renesas-xhci: Fix External ROM access timeouts (Marek Vasut) - usb: core: hcd: fix accessing unmapped memory in SINGLE_STEP_SET_FEATURE test (Xu Yang) - comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() (Ian Abbott) - comedi: pcl726: Prevent invalid irq number (Edward Adam Davis) - comedi: Make insn_rw_emulate_bits() do insn->n samples (Ian Abbott) - usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li) - most: core: Drop device reference after usage in get_channel() (Miaoqian Lin) - iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner) - iio: pressure: bmp280: Use IS_ERR() in bmp280_common_probe() (Salah Triki) - ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401580] {CVE-2025-39689} - fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun) - use uniform permission checks for all mount propagation changes (Al Viro) - fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401586] {CVE-2025-39691} - drm/amd/display: Fill display clock and vblank time in dce110_fill_display_configs (Timur Kristóf) - drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristóf) - drm/amd/display: Fix DP audio DTO1 clock source on DCE 6. (Timur Kristóf) - drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristóf) - drm/amd/display: Avoid a NULL pointer dereference (Mario Limonciello) [Orabug: 38401596] {CVE-2025-39693} - ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6 and EliteBook 830 G6 (Evgeniy Harchenko) - mm/debug_vm_pgtable: clear page table entries at destroy_args() (Herton Ronaldo Krzesinski) - mmc: sdhci-pci-gli: GL9763e: Rename the gli_set_gl9763e() for consistency (Victor Shih) - memstick: Fix deadlock by moving removing flag earlier (Jiayi Li) - scsi: ufs: ufs-pci: Fix default runtime and system PM levels (Adrian Hunter) - scsi: ufs: ufs-pci: Fix hibernate state transition for Intel MTL-like host controllers (Archana Patni) - mptcp: do not queue data on closed subflows (Paolo Abeni) - mptcp: drop unused sk in mptcp_push_release (Geliang Tang) - selftests: mptcp: Initialize variables to quiet gcc 12 warnings (Mat Martineau) - mptcp: introduce MAPPING_BAD_CSUM (Paolo Abeni) - mptcp: fix error mibs accounting (Paolo Abeni) - selftests: mptcp: add missing join check (Matthieu Baerts) - selftests: mptcp: connect: also cover checksum (Matthieu Baerts) - selftests: mptcp: connect: also cover alt modes (Matthieu Baerts) - selftests: mptcp: make sendfile selftest work (Florian Westphal) - ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value (Li Zhong) - PCI: vmd: Assign VMD IRQ domain before enumeration (Nirmal Patel) - sch_htb: make htb_deactivate() idempotent (Cong Wang) [Orabug: 38516621] {CVE-2025-37953} - codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() (Cong Wang) [Orabug: 37908491] {CVE-2025-37798} - sch_drr: make drr_qlen_notify() idempotent (Cong Wang) - btrfs: populate otime when logging an inode item (Qu Wenruo) - KVM: VMX: Flush shadow VMCS on emergency reboot (Chao Gao) - net/sched: ets: use old 'nbands' while purging unused classes (Davide Caratti) [Orabug: 38394836] {CVE-2025-38684} - net_sched: sch_ets: implement lockless ets_dump() (Eric Dumazet) - net/sched: sch_ets: properly init all active DRR list handles (Davide Caratti) [Orabug: 35290200] - platform/chrome: cros_ec: Unregister notifier in cros_ec_unregister() (Tzung-Bi Shih) - platform/chrome: cros_ec: remove unneeded label and if-condition (Tzung-Bi Shih) - platform/chrome: cros_ec: Use per-device lockdep key (Chen-Yu Tsai) - platform/chrome: cros_ec: Make cros_ec_unregister() return void (Uwe Kleine-König) - usb: dwc3: imx8mp: fix device leak at unbind (Johan Hovold) - bus: mhi: host: Detect events pointing to unexpected TREs (Youssef Samir) [Orabug: 38423539] {CVE-2025-39790} - ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal) - usb: musb: omap2430: fix device leak at unbind (Johan Hovold) - usb: musb: omap2430: Convert to platform remove callback returning void (Uwe Kleine-König) - mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() (Anshuman Khandual) - NFS: Fix the setting of capabilities when automounting a new filesystem (Trond Myklebust) [Orabug: 38429210] {CVE-2025-39798} - NFS: Create an nfs4_server_set_init_caps() function (Anna Schumaker) - net: enetc: fix device and OF node leak at probe (Johan Hovold) - block: Make REQ_OP_ZONE_FINISH a write operation (Damien Le Moal) - PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (Lukas Wunner) - usb: typec: fusb302: cache PD RX state (Sebastian Reichel) - hv_netvsc: Fix panic during namespace deletion with VF (Haiyang Zhang) [Orabug: 38394830] {CVE-2025-38683} - smb: server: Fix extension string in ksmbd_extract_shortname() (Thorsten Blum) - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (Geoffrey D. Bennett) - x86/fpu: Delay instruction pointer fixup until after warning (Dave Hansen) - usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman) - usb: hub: avoid warm port reset during USB3 disconnect (Mathias Nyman) - x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam) - iio: hid-sensor-prox: Fix incorrect OFFSET calculation (Zhang Lixu) - iio: hid-sensor-prox: Restore lost scale assignments (Zhang Lixu) - f2fs: fix to do sanity check on ino and xnid (Chao Yu) - arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() (Ada Couprie Diaz) [Orabug: 38351990] {CVE-2025-38670} - drm/sched: Remove optimization that causes hang when killing dependent jobs (Lin Cao) - ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (Haoxiang Li) [Orabug: 38351929] {CVE-2025-38664} - selftests/memfd: add test for mapping write-sealed memfd read-only (Lorenzo Stoakes) - mm: reinstate ability to map write-sealed memfd mappings read-only (Lorenzo Stoakes) - mm: update memfd seal write check to include F_SEAL_WRITE (Lorenzo Stoakes) - mm: drop the assumption that VM_SHARED always implies writable (Lorenzo Stoakes) - sch_qfq: make qfq_qlen_notify() idempotent (Cong Wang) - sch_hfsc: make hfsc_qlen_notify() idempotent (Cong Wang) [Orabug: 38158395] {CVE-2025-38177} - sch_htb: make htb_qlen_notify() idempotent (Cong Wang) [Orabug: 37976859] {CVE-2025-37932} - mptcp: pm: kernel: flush: do not reset ADD_ADDR limit (Matthieu Baerts) - mptcp: drop skb if MPTCP skb extension allocation fails (Christoph Paasch) - ipv6: sr: Fix MAC comparison to be constant-time (Eric Biggers) - net, hsr: reject HSR frame if skb can't hold tag (Jakub Acs) [Orabug: 38401632] {CVE-2025-39703} - drm/amd/display: Don't overwrite dce60_clk_mgr (Timur Kristóf) - drm/amd: Restore cached power limit during resume (Mario Limonciello) - media: venus: venc: Clamp param smaller than 1fps and bigger than 240 (Ricardo Ribalda) - media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda) - media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz) - media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar) - media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong) - media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401676] {CVE-2025-39713} - media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401683] {CVE-2025-39714} - media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus) - media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li) - media: hi556: correct the test pattern configuration (Bingbu Cao) - media: gspca: Add bounds checking to firmware parser (Dan Carpenter) - soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter) - jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423508] {CVE-2025-39782} - PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal) - PCI: endpoint: Fix configfs group list head handling (Damien Le Moal) - mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier) - mtd: spinand: propagate spinand_wait() errors from spinand_write_page() (Gabor Juhos) - hwmon: (gsc-hwmon) fix fan pwm setpoint show functions (Tim Harvey) - pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea) - wifi: ath11k: fix source ring-buffer corruption (Johan Hovold) - wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor) - zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski) - ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal) - scsi: mpi3mr: Fix race between config read submit and interrupt completion (Ranjan Kumar) - ext4: fix hole length calculation overflow in non-extent inodes (Zhang Yi) - ext4: use kmalloc_array() for array space allocation (Liao Yuanhong) - ext4: don't try to clear the orphan_present feature block device is r/o (Theodore Ts'O) - ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo) - ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo) - ext4: check fast symlink for ea_inode correctly (Andreas Dilger) - lib/crypto: mips/chacha: Fix clang build and remove unneeded byteswap (Eric Biggers) - vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle) - vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle) - bus: mhi: host: Fix endianness of BHI vector table (Alexander Wilhelm) - usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold) - usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold) - usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor) - m68k: Fix lost column on framebuffer debug console (Finn Thain) - cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter) - serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401728] {CVE-2025-39724} - HID: magicmouse: avoid setting up battery timer when not needed (Aditya Garg) - media: uvcvideo: Do not mark valid metadata as invalid (Ricardo Ribalda) - media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (Youngjun Lee) [Orabug: 38394815] {CVE-2025-38680} - mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock (Breno Leitao) - mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() (Waiman Long) - parisc: Makefile: fix a typo in palo.conf (Randy Dunlap) - fbdev: Fix vmalloc out-of-bounds write in fast_imageblit (Sravan Kumar Gundu) [Orabug: 38394843] {CVE-2025-38685} - btrfs: do not allow relocation of partially dropped subvolumes (Qu Wenruo) [Orabug: 38423271] {CVE-2025-39738} - btrfs: fix log tree replay failure due to file with 0 links and extents (Filipe Manana) - cdc-acm: fix race between initial clearing halt and open (Oliver Neukum) - thunderbolt: Fix copy+paste error in match_service_id() (Eric Biggers) - comedi: fix race between polling and detaching (Ian Abbott) - usb: typec: ucsi: Update power_supply on power role change (Myrrh Periwinkle) - misc: rtsx: usb: Ensure mmc child device is active when card is present (Ricky Wu) - usb: core: config: Prevent OOB read in SS endpoint companion parsing (Xinyu Liu) [Orabug: 38423420] {CVE-2025-39760} - ext4: fix largest free orders lists corruption on mb_optimize_scan switch (Baokun Li) - drm/amdgpu: fix incorrect vm flags to map bo (Jack Xiao) - ASoC: fsl_sai: replace regmap_write with regmap_update_bits (Shengjiu Wang) - ASoC: soc-dai.h: merge DAI call back functions into ops (Kuninori Morimoto) - ASoC: soc-dai.c: add missing flag check at snd_soc_pcm_dai_probe() (Kuninori Morimoto) - scsi: lpfc: Remove redundant assignment to avoid memory leak (Jiasheng Jiang) - rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (Meagan Lloyd) - pNFS: Fix uninited ptr deref in block/scsi layout (Sergey Bashirov) [Orabug: 38394865] {CVE-2025-38691} - pNFS: Handle RPC size limit for layoutcommits (Sergey Bashirov) - pNFS: Fix disk addr range check in block/scsi layout (Sergey Bashirov) - pNFS: Fix stripe mapping in block/scsi layout (Sergey Bashirov) - block: avoid possible overflow for chunk_sectors check in blk_stack_limits() (John Garry) [Orabug: 38429192] {CVE-2025-39795} - net: phy: smsc: add proper reset flags for LAN8710A (Csaba Buday) - ipmi: Fix strcpy source and destination the same (Corey Minyard) - kconfig: lxdialog: fix 'space' to (de)select options (Yann E. MORIN) - kconfig: gconf: fix potential memory leak in renderer_edited() (Masahiro Yamada) - kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed() (Masahiro Yamada) - ipmi: Use dev_warn_ratelimited() for incorrect message warnings (Breno Leitao) - scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Garry) - scsi: target: core: Generate correct identifiers for PR OUT transport IDs (Maurizio Lombardi) - scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (Ranjan Kumar) - kconfig: nconf: Ensure null termination where strncpy is used (Shankari Anand) - kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c (Suchit Karunakaran) - i2c: Force DLL0945 touchpad i2c freq to 100khz (Fangzhong Zhou) - dm-mpath: don't print the "loaded" message if registering fails (Mikulas Patocka) - i3c: don't fail if GETHDRCAP is unsupported (Wolfram Sang) - rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (Meagan Lloyd) - i3c: add missing include to internal header (Wolfram Sang) - md: dm-zoned-target: Initialize return variable r to avoid uninitialized use (Purva Yeshi) - crypto: octeontx2 - add timeout for load_fvc completion poll (Bharat Bhushan) - media: uvcvideo: Fix bandwidth issue for Alcor camera (Chenchangcheng) - media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (Alex Guo) [Orabug: 38394879] {CVE-2025-38693} - media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (Alex Guo) [Orabug: 38394886] {CVE-2025-38694} - media: usb: hdpvr: disable zero-length read messages (Wolfram Sang) - media: tc358743: Increase FIFO trigger level to 374 (Dave Stevenson) - media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (Dave Stevenson) - media: tc358743: Check I2C succeeded during probe (Dave Stevenson) - pinctrl: stm32: Manage irq affinity settings (Cheick Traore) - scsi: mpt3sas: Correctly handle ATA device errors (Damien Le Moal) - scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (Justin Tee) [Orabug: 38394893] {CVE-2025-38695} - RDMA/core: reduce stack using in nldev_stat_get_doit() (Arnd Bergmann) - RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (Yury Norov) [Orabug: 38423285] {CVE-2025-39742} - leds: leds-lp50xx: Handle reg to get correct multi_index (Johan Adolfsson) - media: v4l2-common: Reduce warnings about missing V4L2_CID_LINK_FREQ control (Niklas Söderlund) - MIPS: Don't crash in stack_top() for tasks without ABI or vDSO (Thomas Weißschuh) - jfs: upper bound check of tree index in dbAllocAG (Arnaud Lecomte) - jfs: Regular file corruption check (Edward Adam Davis) - jfs: truncate good inode pages when hard link is 0 (Lizhi Xu) - scsi: bfa: Double-free fix (Jackysliu) [Orabug: 38394923] {CVE-2025-38699} - watchdog: iTCO_wdt: Report error if timeout configuration fails (Ziyan Fu) - MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free} (Shiji Yang) - watchdog: dw_wdt: Fix default timeout (Sebastian Reichel) - fs/orangefs: use snprintf() instead of sprintf() (Amir Mohammad Jahangirzad) - scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated (Showrya M N) [Orabug: 38394930] {CVE-2025-38700} - ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (Theodore Ts'O) [Orabug: 38394936] {CVE-2025-38701} - crypto: hisilicon/hpre - fix dma unmap sequence (Zhiqi Song) - cifs: Fix calling CIFSFindFirst() for root path without msearch (Pali Rohár) - watchdog: sbsa: Adjust keepalive timeout to avoid MediaTek WS0 race condition (Aaron Plattner) - vhost: fail early when __vhost_add_used() fails (Jason Wang) - net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325 (Álvaro Fernández Rojas) - drm/ttm: Respect the shrinker core free target (Tvrtko Ursulin) - uapi: in6: restore visibility of most IPv6 socket options (Jakub Kicinski) - drm/ttm: Should to return the evict error (Emily Deng) - net: ncsi: Fix buffer overflow in fetching version id (Hari Kalavakunta) - wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_init_one_rxdesc() (Thomas Fourier) - net: dsa: b53: prevent SWITCH_CTRL access on BCM5325 (Álvaro Fernández Rojas) - net: dsa: b53: prevent DIS_LEARNING access on BCM5325 (Álvaro Fernández Rojas) - net: dsa: b53: prevent GMII_PORT_OVERRIDE_CTRL access on BCM5325 (Álvaro Fernández Rojas) - net: dsa: b53: fix b53_imp_vlan_setup for BCM5325 (Álvaro Fernández Rojas) - gve: Return error for unknown admin queue command (Alok Tiwari) - net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs (Gal Pressman) - drm/amd: Allow printing VanGogh OD SCLK levels without setting dpm to manual (Mario Limonciello) - dpaa_eth: don't use fixed_phy_change_carrier (Heiner Kallweit) - wifi: iwlegacy: Check rate_idx range after addition (Stanislaw Gruszka) - netmem: fix skb_frag_address_safe with unreadable skbs (Mina Almasry) - wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_rx_interrupt(). (Thomas Fourier) - drm/amd/display: Fix 'failed to blank crtc!' (Wen Chen) - wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (Anjaneyulu) - wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (Rand Deeb) - drm/amd/display: Separate set_gsl from set_gsl_source_select (Ilya Bakoulin) - net: fec: allow disable coalescing (Jonas Rebmann) - net: atlantic: add set_power to fw_ops for atl2 to fix wol (Eric Work) - net: thunderbolt: Fix the parameter passing of tb_xdomain_enable_paths()/tb_xdomain_disable_paths() (Jianrong Zhang) - drm/msm: use trylock for debugfs (Rob Clark) - ipv6: mcast: Check inet6_dev->dead under idev->mc_lock in __ipv6_dev_mc_inc(). (Kuniyuki Iwashima) - (powerpc/512) Fix possible dma_unmap_single() on uninitialized pointer (Thomas Fourier) - wifi: mac80211: don't complete management TX on SAE commit (Johannes Berg) - s390/stp: Remove udelay from stp_sync_clock() (Sven Schnelle) - wifi: iwlwifi: mvm: fix scan request validation (Avraham Stern) - sched/deadline: Fix accounting after global limits change (Juri Lelli) - net: thunderx: Fix format-truncation warning in bgx_acpi_match_id() (Alok Tiwari) - net: ipv4: fix incorrect MTU in broadcast routes (Oscar Maes) - wifi: cfg80211: Fix interface type validation (Ilan Peer) - net: mctp: Prevent duplicate binds (Matt Johnston) - rcu: Protect ->defer_qs_iw_pending from data race (Paul E. McKenney) [Orabug: 38423340] {CVE-2025-39749} - arm64: Mark kernel as tainted on SAE and SError panic (Breno Leitao) - net/mlx5e: Properly access RCU protected qdisc_sleeping variable (Leon Romanovsky) - net: ag71xx: Add missing check after DMA map (Thomas Fourier) - et131x: Add missing check after DMA map (Thomas Fourier) - be2net: Use correct byte order and format string for TCP seq and ack_seq (Alok Tiwari) - s390/time: Use monotonic clock in get_cycles() (Sven Schnelle) - wifi: cfg80211: reject HTC bit for management frames (Johannes Berg) - ktest.pl: Prevent recursion of default variable options (Steven Rostedt) - xen/netfront: Fix TX response spurious interrupts (Anthoine Bourgeois) - ASoC: codecs: rt5640: Retry DEVICE_ID verification (Xinxin Wan) - iio: adc: ad7768-1: Ensure SYNC_IN pulse minimum timing requirement (Jonathan Santos) - ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (Cristian Ciocaltea) - ALSA: pcm: Rewrite recalculate_boundary() to avoid costly loop (Christophe Leroy) - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (Lucy Thrun) - platform/chrome: cros_ec_typec: Defer probe on missing EC parent (Tomasz Michalec) - platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (Kees Cook) - pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (Gautham R. Shenoy) - usb: core: usb_submit_urb: downgrade type check (Oliver Neukum) - usb: typec: intel_pmc_mux: Defer probe if SCU IPC isn't present (Tomasz Michalec) - ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() (Peter Ujfalusi) [Orabug: 38394977] {CVE-2025-38706} - ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (Alok Tiwari) - ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (Mark Brown) - x86/bugs: Avoid warning when overriding return thunk (Pawan Gupta) - mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (Ulf Hansson) - reset: brcmstb: Enable reset drivers for ARCH_BCM2835 (Peter Robinson) - pps: clients: gpio: fix interrupt handling order in remove path (Eliav Farber) - ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path (Breno Leitao) - mmc: sdhci-msm: Ensure SD card power isn't ON when card removed (Sarthak Garg) - ACPI: processor: fix acpi_object initialization (Sebastian Ott) - PM: sleep: console: Fix the black screen issue (Tuhaowen) - thermal: sysfs: Return ENODATA instead of EAGAIN for reads (Hsin-Te Yuan) - PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (Rafael J. Wysocki) - ACPI: PRM: Reduce unnecessary printing to avoid user confusion (Zhu Qiyu) - selftests: tracing: Use mutex_unlock for testing glob filter (Masami Hiramatsu) - ARM: tegra: Use I/O memcpy to write to IRAM (Aaron Kling) - gpio: tps65912: check the return value of regmap_update_bits() (Bartosz Golaszewski) - tools/nolibc: define time_t in terms of __kernel_old_time_t (Thomas Weißschuh) - thermal/drivers/qcom-spmi-temp-alarm: Enable stage 2 shutdown when required (David Collins) - ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (Kuninori Morimoto) - EDAC/synopsys: Clear the ECC counters on init (Shubhrajyoti Datta) - PM / devfreq: governor: Replace sscanf() with kstrtoul() in set_freq_store() (Lifeng Zheng) - ARM: rockchip: fix kernel hang during smp initialization (Alexander Kochetkov) - cpufreq: Exit governor when failed to start old governor (Lifeng Zheng) - gpio: wcd934x: check the return value of regmap_update_bits() (Bartosz Golaszewski) - usb: xhci: Avoid showing errors during surprise removal (Mario Limonciello) - usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (Jay Chen) - usb: xhci: Avoid showing warnings for dying controller (Mario Limonciello) - usb: typec: ucsi: psy: Set current max to 100mA for BC 1.2 and Default (Benson Leung) - selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t (Cynthia Huang) - cpufreq: CPPC: Mark driver with NEED_UPDATE_LIMITS flag (Prashant Malani) - usb: xhci: print xhci->xhc_state when queue_command failed (Su Hui) - securityfs: don't pin dentries twice, once is enough... (Al Viro) - ext2: Handle fiemap on empty files to prevent EINVAL (Wei Gao) - fs/ntfs3: correctly create symlink for relative path (Rong Zhang) - fs/ntfs3: Add sanity check for file name (Lizhi Xu) - ata: libata-sata: Disallow changing LPM state if not supported (Damien Le Moal) - better lockdep annotations for simple_recursive_removal() (Al Viro) - hfs: fix not erasing deleted b-tree node issue (Viacheslav Dubeyko) - drbd: add missing kref_get in handle_write_conflicts (Sarah Newman) [Orabug: 38394994] {CVE-2025-38708} - udf: Verify partition map count (Jan Kara) - smb/server: avoid deadlock when linking with ReplaceIfExists (Neil Brown) - arm64: Handle KCOV __init vs inline mismatches (Kees Cook) - hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() (Tetsuo Handa) - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (Viacheslav Dubeyko) - hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (Viacheslav Dubeyko) - hfs: fix slab-out-of-bounds in hfs_bnode_read() (Viacheslav Dubeyko) - ptp: prevent possible ABBA deadlock in ptp_clock_freerun() (Jeongjun Park) - intel_idle: Allow loading ACPI tables for any family (Len Brown) - sctp: linearize cloned gso packets in sctp_rcv (Xin Long) [Orabug: 38395058] {CVE-2025-38718} - netfilter: ctnetlink: fix refcount leak on table dump (Florian Westphal) [Orabug: 38395066] {CVE-2025-38721} - udp: also consider secpath when evaluating ipsec use for checksumming (Sabrina Dubroca) - ACPI: processor: perflib: Move problematic pr->performance check (Rafael J. Wysocki) - ACPI: processor: perflib: Fix initial _PPC limit application (Jiayi Li) - Documentation: ACPI: Fix parent device references (Andy Shevchenko) - eventpoll: Fix semi-unbounded recursion (Jann Horn) [Orabug: 38335161] {CVE-2025-38614} - fs: Prevent file descriptor table allocations exceeding INT_MAX (Sasha Levin) [Orabug: 38423396] {CVE-2025-39756} - sunvdc: Balance device refcount in vdc_port_mpgroup_check (Ma Ke) - NFSD: detect mismatch of file handle and delegation stateid in OPEN op (Dai Ngo) - nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38395080] {CVE-2025-38724} - net: usb: asix_devices: add phy_mask for ax88772 mdio bus (Xu Yang) [Orabug: 38395088] {CVE-2025-38725} - net: dpaa: fix device leak when querying time stamp info (Johan Hovold) - net: gianfar: fix device leak when querying time stamp info (Johan Hovold) - gpio: virtio: Fix config space reading. (Harald Mommer) - ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Takashi Iwai) [Orabug: 38423406] {CVE-2025-39757} - ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Takashi Iwai) [Orabug: 38395100] {CVE-2025-38729} - io_uring: don't use int for ABI (Pavel Begunkov) - usb: gadget : fix use-after-free in composite_dev_cleanup() (Taoxue) [Orabug: 38334897] {CVE-2025-38555} - mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery (Andy Shevchenko) - MIPS: mm: tlb-r4k: Uniquify TLB entries on init (Jiaxun Yang) - ALSA: intel_hdmi: Fix off-by-one error in __hdmi_lpe_audio_probe() (Thorsten Blum) - net: usbnet: Fix the wrong netif_carrier_on() call (Ammar Faizi) - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (John Ernberg) - USB: serial: option: add Foxconn T99W709 (Slark Xiao) - net/packet: fix a race in packet_set_ring() and packet_notifier() (Quang Le) [Orabug: 38351763] {CVE-2025-38617} - selftests/perf_events: Add a mmap() correctness test (Lorenzo Stoakes) - perf/core: Prevent VMA split of buffer mappings (Thomas Gleixner) [Orabug: 38334947] {CVE-2025-38563} - perf/core: Exit early on perf_mmap() fail (Thomas Gleixner) [Orabug: 38334957] {CVE-2025-38565} - perf/core: Don't leak AUX buffer refcount on allocation failure (Thomas Gleixner) - pptp: fix pptp_xmit() error path (Eric Dumazet) - smb: client: let recv_done() cleanup before notifying the callers. (Stefan Metzmacher) - smb: server: let recv_done() avoid touching data_transfer after cleanup/move (Stefan Metzmacher) - smb: server: let recv_done() consistently call put_recvmsg/smb_direct_disconnect_rdma_connection (Stefan Metzmacher) - smb: server: make sure we call ib_dma_unmap_single() only if we called ib_dma_map_single already (Stefan Metzmacher) - smb: server: remove separate empty_recvmsg_queue (Stefan Metzmacher) - ALSA: hda/ca0132: Fix missing error handling in ca0132_alt_select_out() (Takashi Iwai) - net: drop UFO packets in udp_rcv_segment() (Wang Liang) [Orabug: 38351785] {CVE-2025-38622} - ipv6: reject malicious packets in ipv6_gso_segment() (Eric Dumazet) [Orabug: 38334987] {CVE-2025-38572} - net/mlx5: Correctly set gso_segs when LRO is used (Christoph Paasch) - pptp: ensure minimal skb length in pptp_xmit() (Eric Dumazet) [Orabug: 38335003] {CVE-2025-38574} - phy: mscc: Fix parsing of unicast frames (Horatiu Vultur) - netpoll: prevent hanging NAPI when netcons gets enabled (Jakub Kicinski) - NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY (Benjamin Coddington) - XArray: Add calls to might_alloc() (Matthew Wilcox) - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (Trond Myklebust) [Orabug: 38401744] {CVE-2025-39730} - pNFS/flexfiles: don't attempt pnfs on fatal DS errors (Tigran Mkrtchyan) - PCI: pnv_php: Fix surprise plug detection and recovery (Timothy Pearson) - powerpc/eeh: Make EEH driver device hotplug safe (Timothy Pearson) - powerpc/eeh: Rely on dev->link_active_reporting (Maciej W. Rozycki) - powerpc/eeh: Export eeh_unfreeze_pe() (Timothy Pearson) - PCI: pnv_php: Work around switches with broken presence detection (Timothy Pearson) - PCI: pnv_php: Clean up allocated IRQs on unplug (Timothy Pearson) - kconfig: qconf: fix ConfigList::updateListAllforAll() (Masahiro Yamada) - scsi: ufs: core: Use link recovery when h8 exit fails during runtime resume (Seunghui Lee) - scsi: mpt3sas: Fix a fw_event memory leak (Tomas Henzl) - f2fs: fix to avoid out-of-boundary access in devs.path (Chao Yu) - f2fs: fix to avoid panic in f2fs_evict_inode (Chao Yu) - f2fs: fix to avoid UAF in f2fs_sync_inode_meta() (Chao Yu) - f2fs: doc: fix wrong quota mount option description (Chao Yu) - f2fs: fix KMSAN uninit-value in extent_info usage (Abinash Singh) - rtc: rv3028: fix incorrect maximum clock rate handling (Brian Masney) - rtc: pcf8563: fix incorrect maximum clock rate handling (Brian Masney) - rtc: pcf85063: fix incorrect maximum clock rate handling (Brian Masney) - rtc: hym8563: fix incorrect maximum clock rate handling (Brian Masney) - rtc: ds1307: fix incorrect maximum clock rate handling (Brian Masney) - ucount: fix atomic_long_inc_below() argument type (Uros Bizjak) - module: Restore the moduleparam prefix length check (Petr Pavlu) - apparmor: ensure WB_HISTORY_SIZE value is a power of 2 (Ryan Lee) - bpf: Check flow_dissector ctx accesses are aligned (Paul Chaignon) - mtd: rawnand: atmel: set pmecc data setup time (Balamanikandan Gunasundar) - mtd: rawnand: rockchip: Add missing check after DMA map (Thomas Fourier) - mtd: rawnand: atmel: Fix dma_mapping_error() address (Thomas Fourier) - jfs: fix metapage reference count leak in dbAllocCtl (Zheng Yu) - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (Chenyuan Yang) - crypto: qat - fix seq_file position update in adf_ring_next() (Giovanni Cabiddu) - sh: Do not use hyphen in exported variable name (Ben Hutchings) - dmaengine: nbpfaxi: Add missing check after DMA map (Thomas Fourier) - dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (Thomas Fourier) - fs/orangefs: Allow 2 more characters in do_c_string() (Dan Carpenter) - PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem attribute (Manivannan Sadhasivam) - soundwire: stream: restore params when prepare ports fail (Bard Liao) - crypto: img-hash - Fix dma_unmap_sg() nents value (Thomas Fourier) - crypto: keembay - Fix dma_unmap_sg() nents value (Thomas Fourier) - hwrng: mtk - handle devm_pm_runtime_enable errors (Ovidiu Panait) - watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (Dan Carpenter) - scsi: isci: Fix dma_unmap_sg() nents value (Thomas Fourier) - scsi: mvsas: Fix dma_unmap_sg() nents value (Thomas Fourier) - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (Thomas Fourier) - clk: sunxi-ng: v3s: Fix de clock definition (Paul Kocialkowski) - perf tests bp_account: Fix leaked file descriptor (Leo Yan) - kernel: trace: preemptirq_delay_test: use offstack cpu mask (Arnd Bergmann) - RDMA/hns: Fix -Wframe-larger-than issue (Junxian Huang) - crypto: ccp - Fix crash when rebind ccp device for ccp.ko (Mengbiao Xiong) - crypto: inside-secure - Fix dma_unmap_sg() nents value (Thomas Fourier) - perf sched: Fix memory leaks for evsel->priv in timehist (Namhyung Kim) - clk: clk-axi-clkgen: fix fpfd_max frequency for zynq (Nuno Sa) - pinctrl: sunxi: Fix memory leak on krealloc failure (Yuan Chen) - PCI: endpoint: pci-epf-vntb: Return -ENOENT if pci_epc_get_next_free_bar() fails (Jerome Brunet) - power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (Charles Han) - power: supply: cpcap-charger: Fix null check for power_supply_get_by_name (Charles Han) - clk: xilinx: vcu: unregister pll_post only if registered correctly (Rohit Visavalia) - media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check (James Cowgill) - clk: davinci: Add NULL check in davinci_lpsc_clk_register() (Henry Martin) - mtd: fix possible integer overflow in erase_xfer() (Ivan Stepchenko) - crypto: marvell/cesa - Fix engine load inaccuracy (Herbert Xu) - PCI: rockchip-host: Fix "Unexpected Completion" log message (Hans Zhang) - vrf: Drop existing dst reference in vrf_ip6_input_dst (Stanislav Fomichev) - selftests: rtnetlink.sh: remove esp4_offload after test (Xiumei Mu) - netfilter: xt_nfacct: don't assume acct name is null-terminated (Florian Westphal) [Orabug: 38351853] {CVE-2025-38639} - can: kvaser_usb: Assign netdev.dev_port based on device channel index (Jimmy Assarsson) - can: kvaser_pciefd: Store device channel index (Jimmy Assarsson) - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (Gokul Sivakumar) - Reapply "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()" (Remi Pommarel) - wifi: mac80211: Check 802.11 encaps offloading in ieee80211_tx_h_select_key() (Remi Pommarel) - wifi: mac80211: Don't call fq_flow_idx() for management frames (Alexander Wetzel) - mwl8k: Add missing check after DMA map (Thomas Fourier) - wifi: rtl8xxxu: Fix RX skb size for aggregation disabled (Martin Kaistra) - xen/gntdev: remove struct gntdev_copy_batch from stack (Juergen Gross) - net_sched: act_ctinfo: use atomic64_t for three counters (Eric Dumazet) - net/sched: Restrict conditions for adding duplicating netems to qdisc tree (William Liu) [Orabug: 38331465] {CVE-2025-38553} - um: rtc: Avoid shadowing err in uml_rtc_start() (Tiwei Bie) - arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX (Johan Korsnes) - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (Fedor Pchelkin) - m68k: Don't unregister boot console needlessly (Finn Thain) - net/mlx5: Check device memory pointer before usage (Stav Aviram) [Orabug: 38351877] {CVE-2025-38645} - tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range (Xin Guo) - wifi: ath11k: clear initialized flag for deinit-ed srng lists (Sergey Senozhatsky) [Orabug: 38335105] {CVE-2025-38601} - iwlwifi: Add missing check for alloc_ordered_workqueue (Jiasheng Jiang) [Orabug: 38335109] {CVE-2025-38602} - wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (Xiu Jianfeng) - wifi: rtl818x: Kill URBs before clearing tx status queue (Daniil Dulov) [Orabug: 38335118] {CVE-2025-38604} - caif: reduce stack size, again (Arnd Bergmann) - bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (Yuan Chen) - bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (Jiayuan Chen) [Orabug: 38335130] {CVE-2025-38608} - bpf, sockmap: Fix psock incorrectly pointing to sk (Jiayuan Chen) - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed (Andy Yan) - selftests/tracing: Fix false failure of subsystem event test (Steven Rostedt) - staging: nvec: Fix incorrect null termination of battery manufacturer (Alok Tiwari) - samples: mei: Fix building on musl libc (Brahmajit Das) - cpufreq: Init policy->rwsem before it may be possibly used (Lifeng Zheng) - cpufreq: Initialize cpufreq-based frequency-invariance later (Lifeng Zheng) - cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive mode (Rafael J. Wysocki) - PM / devfreq: Check governor before using governor->name (Lifeng Zheng) [Orabug: 38335134] {CVE-2025-38609} - arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed (Adam Ford) - arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed (Adam Ford) - ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface (Annette Kobou) - arm: dts: ti: omap: Fixup pinheader typo (Albin Törnqvist) - usb: early: xhci-dbc: Fix early_ioremap leak (Lucas De Marchi) - Revert "vmci: Prevent the dispatching of uninitialized payloads" (Greg Kroah-Hartman) - pps: fix poll support (Denis Osterland-Heim) - vmci: Prevent the dispatching of uninitialized payloads (Lizhi Xu) - staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (Abdun Nihaal) - usb: misc: apple-mfi-fastcharge: Make power supply names unique (Charalampos Mitrodimas) - ARM: dts: vfxxx: Correctly use two tuples for timer address (Krzysztof Kozlowski) - selftests: Fix errno checking in syscall_user_dispatch test (Dmitry Vyukov) - Revert "fs/ntfs3: Replace inode_trylock with inode_lock" (Konstantin Komarov) - hfsplus: remove mutex_lock check in hfsplus_free_extents (Yangtao Li) - fs_context: fix parameter name in infofc() macro (Rubenkelevra) - ASoC: Intel: fix SND_SOC_SOF dependencies (Arnd Bergmann) - ethernet: intel: fix building with large NR_CPUS (Arnd Bergmann) - usb: phy: mxs: disconnect line when USB charger is attached (Xu Yang) - usb: chipidea: add USB PHY event (Xu Yang) - ALSA: hda: Add missing NVIDIA HDA codec IDs (Daniel Dadap) - comedi: comedi_test: Fix possible deletion of uninitialized timers (Ian Abbott) - jfs: reject on-disk inodes of an unsupported type (Dmitry Antipov) - usb: typec: tcpm: apply vbus before data bringup in tcpm_src_attach (Rd Babiera) - usb: typec: tcpm: allow switching to mode accessory to mux properly (Michael Grzeschik) - usb: typec: tcpm: allow to use sink in accessory mode (Michael Grzeschik) - mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n (Harry Yoo) - nilfs2: reject invalid file types when reading inodes (Ryusuke Konishi) - gve: Fix stuck TX queue for DQ queue format (Praveen Kaligineedi) - e1000e: ignore uninitialized checksum word on tgp (Jacek Kowalski) - e1000e: disregard NVM checksum on tgp when valid checksum bit is not set (Jacek Kowalski) - dpaa2-switch: Fix device reference count leak in MAC endpoint handling (Ma Ke) - dpaa2-eth: Fix device reference count leak in MAC endpoint handling (Ma Ke) - ALSA: hda/realtek - Add mute LED support for HP Pavilion 15-eg0xxx (Dawid Rezler) - bus: fsl-mc: Fix potential double device reference in fsl_mc_get_endpoint() (Ma Ke) - i2c: virtio: Avoid hang by using interruptible completion wait (Viresh Kumar) - i2c: qup: jump out of the loop in case of timeout (Yang Xiwen) [Orabug: 38351993] {CVE-2025-38671} - platform/x86: ideapad-laptop: Fix kbd backlight not remembered among boots (Rongrong) - net: hns3: fixed vf get max channels bug (Jian Shen) - net: hns3: disable interrupt when ptp init failed (Yonglong Liu) - net: hns3: fix concurrent setting vlan filter issue (Jian Shen) - net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (Xiang Mei) - net: appletalk: Fix use-after-free in AARP proxy probe (Kito Xu) - i40e: report VF tx_dropped with tx_errors instead of tx_discards (Dennis Chen) - i40e: Add rx_missed_errors for buffer exhaustion (Yajun Deng) - regmap: fix potential memory leak of regmap_bus (Abdun Nihaal) - interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1 node (Xilin Wu) - RDMA/core: Rate limit GID cache warning messages (Maor Gottlieb) - regulator: core: fix NULL dereference on unbind due to stale coupling data (Alessandro Carminati) [Orabug: 38351977] {CVE-2025-38668} - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT (Fabrice Gasnier) [Orabug: 38180692] {CVE-2025-38335} - platform/x86: think-lmi: Fix kobject cleanup (Kurt Borja) - powercap: intel_rapl: Do not change CLAMPING bit if ENABLE bit cannot be changed (Zhang Rui) - mm/vmalloc: leave lazy MMU mode on PTE mapping error (Alexander Gordeev) - ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan) - usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati) - usb: musb: fix gadget state on disconnect (Drew Hamilton) - usb: musb: Add and use inline functions musb_{get,set}_state (Paul Cercueil) - usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman) - usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman) - usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman) - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254213] {CVE-2025-38468} - net: bridge: Do not offload IGMP/MLD messages (Joseph Huang) - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254224] {CVE-2025-38470} - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz) - ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (Yue Haibing) [Orabug: 38324326] {CVE-2025-38550} - net/mlx5: Correctly set gso_size when LRO is used (Christoph Paasch) - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz) - Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz) - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254240] {CVE-2025-38473} - usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254248] {CVE-2025-38474} - hwmon: (corsair-cpro) Validate the size of the received input buffer (Marius Zachmann) - selftests: net: increase inter-packet timeout in udpgro.sh (Paolo Abeni) - selftests: udpgro: report error when receive failed (Hangbin Liu) - nvme: fix misaccounting of nvme-mpath inflight I/O (Yu Kuai) - smb: client: fix use-after-free in cifs_oplock_break (Wang Zhaolong) - pinctrl: mediatek: moore: check if pin_desc is valid before use (Sam Shih) - rpl: Fix use-after-free in rpl_do_srh_inline(). (Kuniyuki Iwashima) - net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254265] {CVE-2025-38477} - net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari) - bpf: Reject %p% format string in bprintf-like helpers (Paul Chaignon) [Orabug: 38324226] {CVE-2025-38528} - comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott) - comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott) - comedi: Fix some signed shift left operations (Ian Abbott) - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott) - comedi: das6402: Fix bit shift out of bounds (Ian Abbott) - comedi: das16m1: Fix bit shift out of bounds (Ian Abbott) - comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott) - comedi: pcl812: Fix bit shift out of bounds (Ian Abbott) - iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni) - iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam) - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam) - soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery) - soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery) - pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah) - mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez) - mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck) - mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier) - memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor) - isofs: Verify inode mode when loading from disk (Jan Kara) - dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter) - af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu) - af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu) - phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor) - tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324269] {CVE-2025-38539} - HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires) - pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier) - thunderbolt: Fix bit masking in tb_dp_port_set_hops() (Alok Tiwari) - i2c: stm32: fix the device used for the DMA map (Clément Le Goffic) - usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254357] {CVE-2025-38497} - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann) - USB: serial: option: add Foxconn T99W640 (Slark Xiao) - USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda) - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode (Wayne Chang) [Orabug: 38324257] {CVE-2025-38535} [5.15.0-314.189.2] - uek-rpm: Bluefield 3: Enable CONFIG_KEXEC_{FILE,SIG,IMAGE_VERIFY_SIG} and CONFIG_EDAC_GHES (Thomas Tai) [Orabug: 38474014] - uek-rpm: Enable the FWCTL PDS in UEK7 (Joao Martins) [Orabug: 38467344] - pds_core: init viftype default in declaration (Shannon Nelson) [Orabug: 38467344] - pds_core: smaller adminq poll starting interval (Shannon Nelson) [Orabug: 38467344] - pds_core: Allocate pdsc_viftype_defaults copy with ARRAY_SIZE() (Kees Cook) [Orabug: 38467344] - pds_core: remove write-after-free of client_id (Shannon Nelson) [Orabug: 37976798,38467344] {CVE-2025-37916} - pds_core: make wait_context part of q_info (Shannon Nelson) [Orabug: 37937540,38467344] {CVE-2025-37886} - pds_core: Remove unnecessary check in pds_client_adminq_cmd() (Brett Creeley) [Orabug: 38467344] - pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result (Brett Creeley) [Orabug: 37937543,38467344] {CVE-2025-37887} - pds_core: Prevent possible adminq overflow/stuck condition (Brett Creeley) [Orabug: 37977106,38467344] {CVE-2025-37987} - pds_core: fix memory leak in pdsc_debugfs_add_qcq() (Abdun Nihaal) [Orabug: 38467344] - pds_fwctl: Fix type and endian complaints (Shannon Nelson) [Orabug: 38467344] - pds_fwctl: add rpc and query support (Brett Creeley) [Orabug: 38467344] - pds_fwctl: initial driver framework (Shannon Nelson) [Orabug: 38467344] - pds_core: add new fwctl auxiliary_device (Shannon Nelson) [Orabug: 38467344] - pds_core: specify auxiliary_device to be created (Shannon Nelson) [Orabug: 38467344] - pds_core: make pdsc_auxbus_dev_del() void (Shannon Nelson) [Orabug: 38467344] - pds_core: limit loop over fw name list (Shannon Nelson) [Orabug: 38467344] - pds_core: Remove redundant null pointer checks (Li Zetao) [Orabug: 38467344] - pds_core: Fix pdsc_check_pci_health function to use work thread (Brett Creeley) [Orabug: 38467344,38498854] {CVE-2024-35968} - pds_core: use pci_reset_function for health reset (Shannon Nelson) [Orabug: 38467344] - pds_core: delete VF dev on reset (Shannon Nelson) [Orabug: 38467344] - pds_core: add simple AER handler (Shannon Nelson) [Orabug: 38467344] - pds_core: no health-thread in VF path (Shannon Nelson) [Orabug: 38467344] - pds_core: Clean up init/uninit flows to be more readable (Brett Creeley) [Orabug: 38467344] - pds_core: Fix up some minor issues (Brett Creeley) [Orabug: 38467344] - pds_core: Unmask adminq interrupt in work thread (Brett Creeley) [Orabug: 38467344] - pds_core: Don't assign interrupt index/bound_intr to notifyq (Brett Creeley) [Orabug: 38467344] - pds_core: Rework teardown/setup flow to be more common (Brett Creeley) [Orabug: 38467344] - pds_core: Clear BARs on reset (Brett Creeley) [Orabug: 38467344] - pds_core: Use struct pdsc for the pdsc_adminq_isr private data (Brett Creeley) [Orabug: 38467344] - pds_core: Cancel AQ work on teardown (Brett Creeley) [Orabug: 38467344] - pds_core: Prevent health thread from running during reset/remove (Brett Creeley) [Orabug: 38467344] - pds_core: fix up some format-truncation complaints (Shannon Nelson) [Orabug: 38467344] - net: pds_core: Fix possible double free in error handling path (Yongzhi Liu) [Orabug: 36530186] {CVE-2024-26652} - x86/its: ITS impacts performance even when mitigation is disabled (Alexandre Chartre) [Orabug: 38346576] [5.15.0-314.189.1] - net/mlx5: HWS, fix bad parameter in CQ creation (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, fix missing ip_version handling in definer (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5e: Use custom tunnel header for vxlan gbp (Vlad Dogaru) [Orabug: 38253291] - net/mlx5: HWS, Rightsize bwc matcher priority (Vlad Dogaru) [Orabug: 38253291] - net/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS: Properly set bwc queue locks lock classes (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: HWS: Fix memory leak in mlx5hws_definer_calc_layout (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: HWS, don't destroy more bwc queue locks than allocated (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: HWS, fixed double free in error flow of definer layout (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, removed wrong access to a number of rules variable (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, changed E2BIG error to a negative return code (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, fixed double-free in error flow of creating SQ (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: Fix wrong reserved field in hca_cap_2 in mlx5_ifc (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, check the correct variable in hws_send_ring_alloc_sq() (Dan Carpenter) [Orabug: 38253291] - net/mlx5e: Support RX xfrm state selector's UPSPEC for packet offload (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Add pass flow group for IPSec RX status table (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Add num_reserved_entries param for ipsec_ft_create() (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Skip IPSec RX policy check for crypto offload (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Move IPSec policy check after decryption (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Add correct match to check IPSec syndromes for switchdev mode (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Change the destination of IPSec RX SA miss rule (Jianbo Liu) [Orabug: 38253291] - net/mlx5e: Add helper function to update IPSec default destination (Jianbo Liu) [Orabug: 38253291] - net/mlx5: fs, add counter object to flow destination (Moshe Shemesh) [Orabug: 38253291] - net/mlx5: DR, moved all the SWS code into a separate directory (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, use lock classes for bwc locks (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Remove mlx5_fc_create_ex (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Don't maintain a counter count (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Drop unneeded cacheline alignment (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Replace IDR+lists with xarray (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Use kvmalloc for bulk query buffer (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: hw counters: Make fc_stats & fc_pool private (Cosmin Ratiu) [Orabug: 38253291] - net/mlx5: fs, separate action and destination into distinct struct (Mark Bloch) [Orabug: 38253291] - net/mlx5: fs, remove unused member (Mark Bloch) [Orabug: 38253291] - net/mlx5: fs, move hardware fte deletion function reset (Mark Bloch) [Orabug: 38253291] - net/mlx5: fs, make get_root_namespace API function (Moshe Shemesh) [Orabug: 38253291] - net/mlx5: HWS, fixed error flow return values of some functions (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, updated API functions comments to kernel doc (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added API and enabled HWS support (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added send engine and context handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added debug dump and internal headers (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added backward-compatible API handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added memory management handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added vport handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added modify header pattern and args handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added FW commands handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added matchers functionality (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added definers handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added rules handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added tables handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: HWS, added actions handling (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: Added missing definitions in preparation for HW Steering (Yevgeny Kliteynik) [Orabug: 38253291] - net/mlx5: Added missing mlx5_ifc definition for HW Steering (Yevgeny Kliteynik) [Orabug: 38253291] - net/rds: Enforce sibling ToS lanes are not UP when auto reaping a conn (Sharath Srinivasan) [Orabug: 38343380] - net/rds: replace rds_conn_addr_list with reentrant code (Sharath Srinivasan) [Orabug: 38343380] - net/rds: Auto-reap dropped conn via sysctl net.rds.conn_reap_after_drop_secs (Sharath Srinivasan) [Orabug: 38343380] - net/rds: Enable tracing for rds_conn_reap() (Sharath Srinivasan) [Orabug: 38343380] - net/rds: Disallow user conn reap via sysctl net.rds.conn_user_reap_enable (Sharath Srinivasan) [Orabug: 38343380] - net/rds: Add sockopt member all_tos to reset/reap all conns for src-dst (Sharath Srinivasan) [Orabug: 38343380] - net/rds: Reap rds_rdma connections via sockopt RDS_CONN_REAP (Sharath Srinivasan) [Orabug: 38343380] - mm, numa: fix bad pmd by atomically checking is_swap_pmd() in change_prot_numa() (Harry Yoo) [Orabug: 38410500] - scsi: target: Export fabric driver direct submit settings (Mike Christie) [Orabug: 38443422] - scsi: target: core: Unexport target_queue_submission() (Mike Christie) [Orabug: 38443422] - scsi: target: Allow userspace to request direct submissions (Mike Christie) [Orabug: 38443422] - scsi: target: core: Kill transport_handle_cdb_direct() (Mike Christie) [Orabug: 38443422] - scsi: target: core: Move buffer clearing hack (Mike Christie) [Orabug: 38443422] - scsi: target: core: Move core_alua_check_nonop_delay() call (Mike Christie) [Orabug: 38443422] - scsi: target: Have drivers report if they support direct submissions (Mike Christie) [Orabug: 38443422] - scsi: target: iscs: Make write_pending_must_be_called a bit field (Mike Christie) [Orabug: 38443422] - KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero) [Orabug: 38458436]

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2024-26652 CVE-2024-35968 CVE-2024-50022 CVE-2024-56742 CVE-2025-37798 CVE-2025-37886 CVE-2025-37887 CVE-2025-37916 CVE-2025-37932 CVE-2025-37953 CVE-2025-37968 CVE-2025-37987 CVE-2025-38095 CVE-2025-38148 CVE-2025-38177 CVE-2025-38236 CVE-2025-38335 CVE-2025-38425 CVE-2025-38468 CVE-2025-38470 CVE-2025-38473 CVE-2025-38474 CVE-2025-38477 CVE-2025-38497 CVE-2025-38502 CVE-2025-38528 CVE-2025-38535 CVE-2025-38539 CVE-2025-38550 CVE-2025-38553 CVE-2025-38555 CVE-2025-38563 CVE-2025-38565 CVE-2025-38572 CVE-2025-38574 CVE-2025-38601 CVE-2025-38602 CVE-2025-38604 CVE-2025-38608 CVE-2025-38609 CVE-2025-38614 CVE-2025-38617 CVE-2025-38622 CVE-2025-38639 CVE-2025-38645 CVE-2025-38664 CVE-2025-38668 CVE-2025-38670 CVE-2025-38671 CVE-2025-38676 CVE-2025-38680 CVE-2025-38683 CVE-2025-38684 CVE-2025-38685 CVE-2025-38691 CVE-2025-38693 CVE-2025-38694 CVE-2025-38695 CVE-2025-38699 CVE-2025-38700 CVE-2025-38701 CVE-2025-38706 CVE-2025-38708 CVE-2025-38718 CVE-2025-38721 CVE-2025-38724 CVE-2025-38725 CVE-2025-38729 CVE-2025-38732 CVE-2025-38736 CVE-2025-39673 CVE-2025-39676 CVE-2025-39681 CVE-2025-39683 CVE-2025-39689 CVE-2025-39691 CVE-2025-39693 CVE-2025-39697 CVE-2025-39703 CVE-2025-39713 CVE-2025-39714 CVE-2025-39724 CVE-2025-39730 CVE-2025-39738 CVE-2025-39742 CVE-2025-39749 CVE-2025-39756 CVE-2025-39757 CVE-2025-39760 CVE-2025-39766 CVE-2025-39772 CVE-2025-39773 CVE-2025-39782 CVE-2025-39787 CVE-2025-39790 CVE-2025-39795 CVE-2025-39798 CVE-2025-39801 CVE-2025-39806 CVE-2025-39808 CVE-2025-39812 CVE-2025-39813 CVE-2025-39817 CVE-2025-39824 CVE-2025-39828 CVE-2025-39835 CVE-2025-39841 CVE-2025-39844 CVE-2025-39845 CVE-2025-39847 CVE-2025-39853 CVE-2025-39860 CVE-2025-39864 CVE-2025-39865 CVE-2025-39866 CVE-2025-39891 CVE-2025-39894 CVE-2025-39898 CVE-2025-39902 CVE-2025-39964 CVE-2025-39973

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here