Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50372 http://linux.oracle.com/errata/ELSA-2026-50372.html The following updated rpms for have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-uek-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-core-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-devel-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-doc-6.12.0-204.92.4.2.el10uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-core-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-tools-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-core-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.2.el10uek.x86_64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.2.el10uek.x86_64.rpm aarch64: kernel-uek-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-devel-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-doc-6.12.0-204.92.4.2.el10uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-tools-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-devel-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-core-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-deprecated-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-desktop-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-extra-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-extra-netfilter-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-usb-6.12.0-204.92.4.2.el10uek.aarch64.rpm kernel-uek64k-modules-wireless-6.12.0-204.92.4.2.el10uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-204.92.4.2.el10uek.src.rpm RelatedCVEs: CVE-2024-14027 CVE-2024-58096 CVE-2024-58097 CVE-2025-10263 CVE-2025-21709 CVE-2025-21717 CVE-2025-21882 CVE-2025-22116 CVE-2025-38426 CVE-2025-38431 CVE-2025-38584 CVE-2025-39764 CVE-2025-39816 CVE-2025-39832 CVE-2025-39858 CVE-2025-39979 CVE-2025-40135 CVE-2025-40147 CVE-2025-40219 CVE-2025-54518 CVE-2025-68209 CVE-2025-68239 CVE-2025-68333 CVE-2025-68334 CVE-2025-68351 CVE-2025-68358 CVE-2025-68725 CVE-2025-68736 CVE-2025-68737 CVE-2025-71152 CVE-2025-71161 CVE-2025-71197 CVE-2025-71222 CVE-2025-71224 CVE-2025-71225 CVE-2025-71229 CVE-2025-71231 CVE-2025-71232 CVE-2025-71234 CVE-2025-71235 CVE-2025-71236 CVE-2025-71238 CVE-2025-71268 CVE-2025-71269 CVE-2025-71273 CVE-2025-71274 CVE-2025-71286 CVE-2025-71294 CVE-2025-71295 CVE-2025-71297 CVE-2025-71305 CVE-2026-22981 CVE-2026-22985 CVE-2026-22986 CVE-2026-22993 CVE-2026-23004 CVE-2026-23057 CVE-2026-23058 CVE-2026-23059 CVE-2026-23060 CVE-2026-23061 CVE-2026-23062 CVE-2026-23069 CVE-2026-23071 CVE-2026-23072 CVE-2026-23073 CVE-2026-23074 CVE-2026-23076 CVE-2026-23078 CVE-2026-23082 CVE-2026-23083 CVE-2026-23084 CVE-2026-23085 CVE-2026-23086 CVE-2026-23087 CVE-2026-23088 CVE-2026-23089 CVE-2026-23091 CVE-2026-23095 CVE-2026-23097 CVE-2026-23099 CVE-2026-23100 CVE-2026-23101 CVE-2026-23103 CVE-2026-23104 CVE-2026-23105 CVE-2026-23107 CVE-2026-23108 CVE-2026-23110 CVE-2026-23111 CVE-2026-23112 CVE-2026-23113 CVE-2026-23119 CVE-2026-23120 CVE-2026-23123 CVE-2026-23124 CVE-2026-23125 CVE-2026-23126 CVE-2026-23128 CVE-2026-23129 CVE-2026-23131 CVE-2026-23133 CVE-2026-23138 CVE-2026-23146 CVE-2026-23148 CVE-2026-23151 CVE-2026-23154 CVE-2026-23155 CVE-2026-23156 CVE-2026-23157 CVE-2026-23159 CVE-2026-23161 CVE-2026-23163 CVE-2026-23164 CVE-2026-23166 CVE-2026-23168 CVE-2026-23173 CVE-2026-23177 CVE-2026-23178 CVE-2026-23179 CVE-2026-23188 CVE-2026-23189 CVE-2026-23190 CVE-2026-23191 CVE-2026-23193 CVE-2026-23198 CVE-2026-23199 CVE-2026-23200 CVE-2026-23201 CVE-2026-23202 CVE-2026-23204 CVE-2026-23205 CVE-2026-23207 CVE-2026-23209 CVE-2026-23210 CVE-2026-23212 CVE-2026-23213 CVE-2026-23214 CVE-2026-23215 CVE-2026-23216 CVE-2026-23219 CVE-2026-23223 CVE-2026-23229 CVE-2026-23230 CVE-2026-23231 CVE-2026-23237 CVE-2026-23240 CVE-2026-23243 CVE-2026-23244 CVE-2026-23245 CVE-2026-23246 CVE-2026-23249 CVE-2026-23250 CVE-2026-23251 CVE-2026-23252 CVE-2026-23253 CVE-2026-23254 CVE-2026-23255 CVE-2026-23260 CVE-2026-23261 CVE-2026-23262 CVE-2026-23264 CVE-2026-23266 CVE-2026-23270 CVE-2026-23271 CVE-2026-23273 CVE-2026-23274 CVE-2026-23276 CVE-2026-23277 CVE-2026-23278 CVE-2026-23279 CVE-2026-23281 CVE-2026-23285 CVE-2026-23286 CVE-2026-23289 CVE-2026-23290 CVE-2026-23292 CVE-2026-23293 CVE-2026-23296 CVE-2026-23297 CVE-2026-23300 CVE-2026-23302 CVE-2026-23303 CVE-2026-23304 CVE-2026-23306 CVE-2026-23307 CVE-2026-23309 CVE-2026-23310 CVE-2026-23312 CVE-2026-23313 CVE-2026-23315 CVE-2026-23316 CVE-2026-23317 CVE-2026-23318 CVE-2026-23319 CVE-2026-23321 CVE-2026-23335 CVE-2026-23336 CVE-2026-23340 CVE-2026-23343 CVE-2026-23351 CVE-2026-23352 CVE-2026-23354 CVE-2026-23356 CVE-2026-23357 CVE-2026-23359 CVE-2026-23360 CVE-2026-23362 CVE-2026-23365 CVE-2026-23367 CVE-2026-23368 CVE-2026-23369 CVE-2026-23370 CVE-2026-23373 CVE-2026-23374 CVE-2026-23375 CVE-2026-23379 CVE-2026-23380 CVE-2026-23381 CVE-2026-23382 CVE-2026-23383 CVE-2026-23386 CVE-2026-23388 CVE-2026-23389 CVE-2026-23390 CVE-2026-23391 CVE-2026-23392 CVE-2026-23395 CVE-2026-23396 CVE-2026-23397 CVE-2026-23398 CVE-2026-23399 CVE-2026-23401 CVE-2026-23412 CVE-2026-23413 CVE-2026-23414 CVE-2026-23417 CVE-2026-23420 CVE-2026-23434 CVE-2026-23438 CVE-2026-23439 CVE-2026-23440 CVE-2026-23441 CVE-2026-23442 CVE-2026-23443 CVE-2026-23444 CVE-2026-23445 CVE-2026-23447 CVE-2026-23448 CVE-2026-23449 CVE-2026-23452 CVE-2026-23454 CVE-2026-23455 CVE-2026-23456 CVE-2026-23457 CVE-2026-23458 CVE-2026-23461 CVE-2026-23462 CVE-2026-23465 CVE-2026-23468 CVE-2026-23473 CVE-2026-23474 CVE-2026-23475 CVE-2026-31389 CVE-2026-31392 CVE-2026-31393 CVE-2026-31394 CVE-2026-31396 CVE-2026-31399 CVE-2026-31400 CVE-2026-31402 CVE-2026-31403 CVE-2026-31405 CVE-2026-31406 CVE-2026-31407 CVE-2026-31408 CVE-2026-31411 CVE-2026-31413 CVE-2026-31414 CVE-2026-31415 CVE-2026-31416 CVE-2026-31418 CVE-2026-31419 CVE-2026-31421 CVE-2026-31422 CVE-2026-31423 CVE-2026-31424 CVE-2026-31426 CVE-2026-31427 CVE-2026-31428 CVE-2026-31429 CVE-2026-31430 CVE-2026-31431 CVE-2026-31434 CVE-2026-31436 CVE-2026-31438 CVE-2026-31440 CVE-2026-31441 CVE-2026-31446 CVE-2026-31447 CVE-2026-31448 CVE-2026-31449 CVE-2026-31450 CVE-2026-31451 CVE-2026-31452 CVE-2026-31453 CVE-2026-31454 CVE-2026-31455 CVE-2026-31456 CVE-2026-31458 CVE-2026-31462 CVE-2026-31466 CVE-2026-31467 CVE-2026-31469 CVE-2026-31470 CVE-2026-31473 CVE-2026-31474 CVE-2026-31479 CVE-2026-31480 CVE-2026-31487 CVE-2026-31488 CVE-2026-31489 CVE-2026-31492 CVE-2026-31494 CVE-2026-31495 CVE-2026-31496 CVE-2026-31497 CVE-2026-31498 CVE-2026-31500 CVE-2026-31503 CVE-2026-31504 CVE-2026-31505 CVE-2026-31506 CVE-2026-31508 CVE-2026-31510 CVE-2026-31511 CVE-2026-31512 CVE-2026-31513 CVE-2026-31514 CVE-2026-31515 CVE-2026-31516 CVE-2026-31518 CVE-2026-31519 CVE-2026-31520 CVE-2026-31521 CVE-2026-31522 CVE-2026-31523 CVE-2026-31524 CVE-2026-31525 CVE-2026-31527 CVE-2026-31528 CVE-2026-31530 CVE-2026-31531 CVE-2026-31532 CVE-2026-31533 CVE-2026-31540 CVE-2026-31542 CVE-2026-31546 CVE-2026-31548 CVE-2026-31550 CVE-2026-31551 CVE-2026-31552 CVE-2026-31554 CVE-2026-31555 CVE-2026-31556 CVE-2026-31557 CVE-2026-31561 CVE-2026-31563 CVE-2026-31565 CVE-2026-31566 CVE-2026-31570 CVE-2026-31575 CVE-2026-31578 CVE-2026-31580 CVE-2026-31581 CVE-2026-31583 CVE-2026-31586 CVE-2026-31588 CVE-2026-31590 CVE-2026-31593 CVE-2026-31596 CVE-2026-31597 CVE-2026-31598 CVE-2026-31602 CVE-2026-31604 CVE-2026-31607 CVE-2026-31614 CVE-2026-31624 CVE-2026-31625 CVE-2026-31628 CVE-2026-31634 CVE-2026-31638 CVE-2026-31639 CVE-2026-31642 CVE-2026-31647 CVE-2026-31648 CVE-2026-31649 CVE-2026-31651 CVE-2026-31656 CVE-2026-31657 CVE-2026-31658 CVE-2026-31659 CVE-2026-31661 CVE-2026-31662 CVE-2026-31664 CVE-2026-31665 CVE-2026-31666 CVE-2026-31667 CVE-2026-31668 CVE-2026-31669 CVE-2026-31670 CVE-2026-31671 CVE-2026-31672 CVE-2026-31673 CVE-2026-31674 CVE-2026-31675 CVE-2026-31676 CVE-2026-31677 CVE-2026-31678 CVE-2026-31679 CVE-2026-31680 CVE-2026-31681 CVE-2026-31682 CVE-2026-31683 CVE-2026-31684 CVE-2026-31685 CVE-2026-31688 CVE-2026-31689 CVE-2026-31693 CVE-2026-31694 CVE-2026-31696 CVE-2026-31697 CVE-2026-31698 CVE-2026-31699 CVE-2026-31700 CVE-2026-31701 CVE-2026-31708 CVE-2026-31709 CVE-2026-31729 CVE-2026-31731 CVE-2026-31733 CVE-2026-31738 CVE-2026-31752 CVE-2026-31758 CVE-2026-31759 CVE-2026-31761 CVE-2026-31762 CVE-2026-31763 CVE-2026-31765 CVE-2026-31767 CVE-2026-31772 CVE-2026-31773 CVE-2026-31774 CVE-2026-31776 CVE-2026-31778 CVE-2026-31779 CVE-2026-31781 CVE-2026-31786 CVE-2026-31787 CVE-2026-31788 CVE-2026-43012 CVE-2026-43013 CVE-2026-43014 CVE-2026-43015 CVE-2026-43016 CVE-2026-43017 CVE-2026-43018 CVE-2026-43019 CVE-2026-43020 CVE-2026-43023 CVE-2026-43024 CVE-2026-43025 CVE-2026-43026 CVE-2026-43027 CVE-2026-43028 CVE-2026-43030 CVE-2026-43033 CVE-2026-43035 CVE-2026-43036 CVE-2026-43037 CVE-2026-43038 CVE-2026-43040 CVE-2026-43041 CVE-2026-43043 CVE-2026-43046 CVE-2026-43047 CVE-2026-43049 CVE-2026-43050 CVE-2026-43051 CVE-2026-43052 CVE-2026-43054 CVE-2026-43056 CVE-2026-43057 CVE-2026-43059 CVE-2026-43060 CVE-2026-43061 CVE-2026-43062 CVE-2026-43063 CVE-2026-43064 CVE-2026-43065 CVE-2026-43066 CVE-2026-43068 CVE-2026-43069 CVE-2026-43071 CVE-2026-43072 CVE-2026-43073 CVE-2026-43074 CVE-2026-43075 CVE-2026-43076 CVE-2026-43077 CVE-2026-43078 CVE-2026-43079 CVE-2026-43080 CVE-2026-43084 CVE-2026-43085 CVE-2026-43086 CVE-2026-43089 CVE-2026-43090 CVE-2026-43091 CVE-2026-43092 CVE-2026-43093 CVE-2026-43094 CVE-2026-43099 CVE-2026-43104 CVE-2026-43105 CVE-2026-43107 CVE-2026-43110 CVE-2026-43111 CVE-2026-43112 CVE-2026-43113 CVE-2026-43114 CVE-2026-43117 CVE-2026-43119 CVE-2026-43120 CVE-2026-43123 CVE-2026-43124 CVE-2026-43125 CVE-2026-43126 CVE-2026-43128 CVE-2026-43129 CVE-2026-43130 CVE-2026-43132 CVE-2026-43133 CVE-2026-43134 CVE-2026-43135 CVE-2026-43136 CVE-2026-43137 CVE-2026-43139 CVE-2026-43140 CVE-2026-43143 CVE-2026-43147 CVE-2026-43150 CVE-2026-43152 CVE-2026-43153 CVE-2026-43156 CVE-2026-43158 CVE-2026-43161 CVE-2026-43163 CVE-2026-43167 CVE-2026-43168 CVE-2026-43169 CVE-2026-43170 CVE-2026-43171 CVE-2026-43177 CVE-2026-43178 CVE-2026-43180 CVE-2026-43186 CVE-2026-43187 CVE-2026-43189 CVE-2026-43190 CVE-2026-43194 CVE-2026-43199 CVE-2026-43201 CVE-2026-43206 CVE-2026-43210 CVE-2026-43211 CVE-2026-43214 CVE-2026-43215 CVE-2026-43218 CVE-2026-43220 CVE-2026-43223 CVE-2026-43231 CVE-2026-43233 CVE-2026-43238 CVE-2026-43239 CVE-2026-43243 CVE-2026-43246 CVE-2026-43248 CVE-2026-43251 CVE-2026-43252 CVE-2026-43253 CVE-2026-43255 CVE-2026-43257 CVE-2026-43260 CVE-2026-43261 CVE-2026-43262 CVE-2026-43264 CVE-2026-43265 CVE-2026-43266 CVE-2026-43271 CVE-2026-43273 CVE-2026-43275 CVE-2026-43277 CVE-2026-43278 CVE-2026-43279 CVE-2026-43281 CVE-2026-43284 CVE-2026-43287 CVE-2026-43288 CVE-2026-43289 CVE-2026-43292 CVE-2026-43304 CVE-2026-43306 CVE-2026-43313 CVE-2026-43314 CVE-2026-43315 CVE-2026-43316 CVE-2026-43318 CVE-2026-43319 CVE-2026-43320 CVE-2026-43328 CVE-2026-43329 CVE-2026-43332 CVE-2026-43333 CVE-2026-43334 CVE-2026-43336 CVE-2026-43338 CVE-2026-43339 CVE-2026-43341 CVE-2026-43350 CVE-2026-43357 CVE-2026-43359 CVE-2026-43360 CVE-2026-43361 CVE-2026-43362 CVE-2026-43363 CVE-2026-43365 CVE-2026-43366 CVE-2026-43368 CVE-2026-43370 CVE-2026-43371 CVE-2026-43374 CVE-2026-43381 CVE-2026-43382 CVE-2026-43383 CVE-2026-43392 CVE-2026-43393 CVE-2026-43394 CVE-2026-43395 CVE-2026-43397 CVE-2026-43403 CVE-2026-43405 CVE-2026-43406 CVE-2026-43407 CVE-2026-43408 CVE-2026-43409 CVE-2026-43411 CVE-2026-43413 CVE-2026-43415 CVE-2026-43419 CVE-2026-43420 CVE-2026-43425 CVE-2026-43427 CVE-2026-43428 CVE-2026-43429 CVE-2026-43430 CVE-2026-43432 CVE-2026-43436 CVE-2026-43437 CVE-2026-43438 CVE-2026-43439 CVE-2026-43441 CVE-2026-43444 CVE-2026-43445 CVE-2026-43448 CVE-2026-43449 CVE-2026-43450 CVE-2026-43451 CVE-2026-43452 CVE-2026-43453 CVE-2026-43456 CVE-2026-43459 CVE-2026-43466 CVE-2026-43468 CVE-2026-43469 CVE-2026-43470 CVE-2026-43471 CVE-2026-43472 CVE-2026-43473 CVE-2026-43475 CVE-2026-43482 CVE-2026-43483 CVE-2026-43484 CVE-2026-43486 CVE-2026-43487 CVE-2026-43488 CVE-2026-43491 CVE-2026-43493 CVE-2026-43499 CVE-2026-43500 CVE-2026-43501 CVE-2026-43503 CVE-2026-45847 CVE-2026-45851 CVE-2026-45852 CVE-2026-45853 CVE-2026-45855 CVE-2026-45856 CVE-2026-45857 CVE-2026-45858 CVE-2026-45859 CVE-2026-45860 CVE-2026-45861 CVE-2026-45862 CVE-2026-45868 CVE-2026-45870 CVE-2026-45871 CVE-2026-45872 CVE-2026-45873 CVE-2026-45877 CVE-2026-45878 CVE-2026-45886 CVE-2026-45888 CVE-2026-45890 CVE-2026-45892 CVE-2026-45894 CVE-2026-45895 CVE-2026-45898 CVE-2026-45899 CVE-2026-45905 CVE-2026-45910 CVE-2026-45912 CVE-2026-45913 CVE-2026-45914 CVE-2026-45915 CVE-2026-45916 CVE-2026-45917 CVE-2026-45919 CVE-2026-45920 CVE-2026-45922 CVE-2026-45923 CVE-2026-45925 CVE-2026-45933 CVE-2026-45941 CVE-2026-45942 CVE-2026-45943 CVE-2026-45947 CVE-2026-45948 CVE-2026-45949 CVE-2026-45957 CVE-2026-45962 CVE-2026-45964 CVE-2026-45968 CVE-2026-45970 CVE-2026-45972 CVE-2026-45973 CVE-2026-45974 CVE-2026-45976 CVE-2026-45982 CVE-2026-45983 CVE-2026-45984 CVE-2026-45985 CVE-2026-45987 CVE-2026-45988 CVE-2026-45992 CVE-2026-45997 CVE-2026-45998 CVE-2026-46000 CVE-2026-46002 CVE-2026-46003 CVE-2026-46004 CVE-2026-46005 CVE-2026-46006 CVE-2026-46015 CVE-2026-46018 CVE-2026-46021 CVE-2026-46023 CVE-2026-46024 CVE-2026-46026 CVE-2026-46028 CVE-2026-46033 CVE-2026-46037 CVE-2026-46038 CVE-2026-46040 CVE-2026-46043 CVE-2026-46046 CVE-2026-46047 CVE-2026-46048 CVE-2026-46049 CVE-2026-46050 CVE-2026-46051 CVE-2026-46052 CVE-2026-46056 CVE-2026-46061 CVE-2026-46069 CVE-2026-46070 CVE-2026-46076 CVE-2026-46078 CVE-2026-46079 CVE-2026-46080 CVE-2026-46082 CVE-2026-46083 CVE-2026-46084 CVE-2026-46085 CVE-2026-46086 CVE-2026-46088 CVE-2026-46089 CVE-2026-46091 CVE-2026-46092 CVE-2026-46094 CVE-2026-46099 CVE-2026-46101 CVE-2026-46102 CVE-2026-46109 CVE-2026-46165 CVE-2026-46242 CVE-2026-46243 CVE-2026-46300 CVE-2026-46331 CVE-2026-46333 CVE-2026-52943 Description of changes: [6.12.0-204.92.4.2] - KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673880] - net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) {CVE-2026-46331} - net_sched: act_pedit: use RCU in tcf_pedit_dump() (Eric Dumazet) [Orabug: 39668752] - eventpoll: fix ep_remove struct eventpoll / struct file UAF (Christian Brauner) [Orabug: 39668743] {CVE-2026-46242} - eventpoll: move epi_fget() up (Christian Brauner) [Orabug: 39668743] - eventpoll: rename ep_remove_safe() back to ep_remove() (Christian Brauner) [Orabug: 39668743] - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() (Christian Brauner) [Orabug: 39668743] - eventpoll: kill __ep_remove() (Christian Brauner) [Orabug: 39668743] - eventpoll: split __ep_remove() (Christian Brauner) [Orabug: 39668743] - eventpoll: use hlist_is_singular_node() in __ep_remove() (Christian Brauner) [Orabug: 39668743] [6.12.0-204.92.4.1] - net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39656679] {CVE-2026-52943} - md: fix array_state=clear sysfs deadlock (Yu Kuai) [Orabug: 39656688] - md: fix return value of mddev_trylock (Xiao Ni) [Orabug: 39656688] - md: avoid repeated calls to del_gendisk (Xiao Ni) [Orabug: 39656688] - md: delete mddev kobj before deleting gendisk kobj (Xiao Ni) [Orabug: 39656688] - md: add legacy_async_del_gendisk mode (Xiao Ni) [Orabug: 39656688] - md: fix create on open mddev lifetime regression (Yu Kuai) [Orabug: 39656688] - md: Don't clear MD_CLOSING until mddev is freed (Xiao Ni) [Orabug: 39656688] - md: call del_gendisk in control path (Xiao Ni) [Orabug: 39656688] [6.12.0-204.92.4] - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548792] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548792] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug:39548792] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548792] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548792] - net/rds: Make "rds_send_xmit" fairer (Gerd Rausch) [Orabug: 38144694] - net/rds: Schedule rds_send_worker if there's more work to do (Gerd Rausch) [Orabug: 38144694] - Revert "rds: Change return code from rds_send_xmit() when lock is taken" (Gerd Rausch) [Orabug: 38144694] - vfio/type1: optimize vfio_unpin_pages_remote() (Li Zhe) [Orabug: 39058056] - vfio/type1: introduce a new member has_rsvd for struct vfio_dma (Li Zhe) [Orabug: 39058056] - vfio/type1: batch vfio_find_vpfn() in function vfio_unpin_pages_remote() (Li Zhe) [Orabug: 39058056] - vfio/type1: optimize vfio_pin_pages_remote() (Li Zhe) [Orabug: 39058056] - mm: introduce num_pages_contiguous() (Li Zhe) [Orabug: 39058056] - vfio/type1: Use mapping page mask for pfnmaps (Alex Williamson) [Orabug: 39058056] - mm: Provide address mask in struct follow_pfnmap_args (Alex Williamson) [Orabug: 39058056] - vfio/type1: Use consistent types for page counts (Alex Williamson) [Orabug: 39058056] - vfio/type1: Use vfio_batch for vaddr_get_pfns() (Alex Williamson) [Orabug: 39058056] - vfio/type1: Convert all vaddr_get_pfns() callers to use vfio_batch (Alex Williamson) [Orabug: 39058056] - vfio/type1: Catch zero from pin_user_pages_remote() (Alex Williamson) [Orabug: 39058056] - rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39179362] - mmc: dwcmshc_bf3_hw_reset: Log eMMC reset calls (Satyansh Shukla) [Orabug: 39341694] - net: lan743x: rename chip_rev to fpga_rev (Thangaraj Samynathan) [Orabug: 39369482] - net: lan743x: fix SGMII detection on PCI1xxxx B0+ during warm reset (Thangaraj Samynathan) [Orabug: 39369482] - net: microchip: lan743x: add ethtool nway_reset support (Nicolai Buchwitz) [Orabug: 39369482] - net: lan743x: implement ndo_hwtstamp_get() (Vladimir Oltean) [Orabug: 39369482] - net: lan743x: convert to ndo_hwtstamp_set() (VladimirOltean) [Orabug: 39369482] - net: lan743x: use netdev in lan743x_phylink_mac_link_down() (Russell King (Oracle)) [Orabug: 39369482] - net/rds: Add parentheses around conditional operator (Gerd Rausch) [Orabug: 39399490] - uek-rpm: avoid final module link in early FIPS symvers pass (Sherry Yang) [Orabug: 39454846] - net/ethernet/pensando: Add out-of-tree network drivers (Joseph Dobosenski) [Orabug: 39479413] - ima: kexec: move IMA log copy from kexec load to execute (Steven Chen) [Orabug: 39517375] - ima: kexec: skip IMA segment validation after kexec soft reboot (Steven Chen) [Orabug: 39517375] - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer (David Howells) - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg (David Howells) - drm/amd/pm/si: Disregard vblank time when no displays are connected (Timur Kristóf) - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong) - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev) - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (Wentao Guan) - media: rc: igorplugusb: fix control request setup packet (Henri A) - media: rc: ttusbir: fix inverted error logic (Oliver Neukum) - media: rc: fix race between unregister and urb/irq callbacks (Sean Young) - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee) - bcache: fix uninitialized closure object (Mingzhe Zou) - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit (Usama Arif) - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (Davide Caratti) - LTS version: v6.12.92 (Saeed Mirzamohammadi) - security/keys: fix missed RCU read section on lookup (Linus Torvalds) - landlock: Fix TCP handling of short AF_UNSPEC addresses (Matthieu Buffet) - LoongArch: kprobes: Fix handling of fatal unrecoverable recursions (Tiezhu Yang) - net: gro: don't merge zcopy skbs (Sabrina Dubroca) - pds_core: ensure null-termination for firmware version strings (Nikhil P.Rao) - net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) - octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs (Ratheesh Kannoth) - drm/xe/oa: Fix exec_queue leak on width check in stream open (Shuicheng Lin) - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (Richard Fitzgerald) - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski) - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko) - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (Xingwang Xiang) - net: ag71xx: check error for platform_get_irq (Rosen Penev) - Bluetooth: btmtk: fix urb-> setup_packet leak in error paths (Jiajia Liu) - tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) - ALSA: seq: Serialize UMP output teardown with event_input (Zhang Cen) - wifi: mac80211: fix MLE defragmentation (Johannes Berg) - pds_core: fix debugfs_lookup dentry leak and error handling (Nikhil P. Rao) - pds_core: fix error handling in pdsc_devcmd_wait (Nikhil P. Rao) - bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) - net: bridge: Flush multicast groups when snooping is disabled (Petr Machata) - RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li) - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki) - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (Oliver White) - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) - net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle) - net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle) - kbuild: pacman-pkg:make "rc" releases adhere to pacman versioning scheme (Viktor Jägersküpper) - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (Ankit Nautiyal) - ice: ptp: serialize E825 PHY timer start with PTP lock (Grzegorz Nitka) - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (Matthew Leach) - drm/xe/pf: Fix CFI failure in debugfs access (Mohanram Meenakshisundaram) - drm/xe/vf: Fix signature of print functions (Michal Wajdeczko) - drm/xe/gsc: Fix double-free of managed BO in error path (Shuicheng Lin) - drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (Felix Gu) - btrfs: fix squota accounting during enable generation (Boris Burkov) - io_uring/net: punt IORING_OP_BIND async if it needs file create (Jens Axboe) - ALSA: scarlett2: Add missing error check when initialise Autogain Status (Robertus Diawan Chris) - scsi: sd: Fix return code handling in sd_spinup_disk() (Mike Christie) - net/mlx5: Do not restore destination-less TC rules (Jeroen Massar) - tls: Preserve sk_err across recvmsg() when data has been copied (Chuck Lever) - x86/xen: Fix xen_e820_swap_entry_with_ram() (Juergen Gross) - net: phy: DP83TC811: add reading of abilities (Sven Schuchmann) - net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei) - powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (Sayali Patil) - drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) - drm/msm/dsi: don't dump registers past the mapped region (Dmitry Baryshkov) - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao) - net/smc: avoid NULL deref of conn-> lnk in smc_msg_event tracepoint (Xiang Mei) - accel/qaic: Add overflow check to remap_pfn_range during mmap (Zack McKevitt) - block:bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (Sungwoo Kim) - blk-integrity: enable p2p source and destination (Keith Busch) - blk-integrity: use simpler alignment check (Keith Busch) - block: drop direction param from bio_integrity_copy_user() (Caleb Sander Mateos) - HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn) - block: recompute nr_integrity_segments in blk_insert_cloned_request (Casey Chen) - block: don't overwrite bip_vcnt in bio_integrity_copy_user() (David Carlier) - wifi: ath10k: skip WMI and beacon transmission when device is wedged (Kang Yang) - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (Nicolas Escande) - wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore) - net: ethernet: cortina: Carry over frag counter (Linus Walleij) - net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann) - net: ethernet: cortina: Make RX SKB per-port (Linus Walleij) - netfs: Fix folio-> private handling in netfs_perform_write() (David Howells) - netfs: Remove unnecessary references to pages (Matthew Wilcox (Oracle)) - netfs: Fix a few minor bugs in netfs_page_mkwrite() (Matthew Wilcox (Oracle)) - netfs: Fix partial invalidation of streaming-write folio (David Howells) - netfs: Fix early put of sink folio in netfs_read_gaps() (David Howells) - netfs: Fix write streaming disablement if fd open O_RDWR (David Howells) - netfs: Fix potential deadlock in write-through mode (David Howells) - netfs: Fix streaming write being overwritten (David Howells) - netfs: Defer the emission of trace_netfs_folio() (David Howells) - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone (David Howells) - netfs: Fix overrun check in netfs_extract_user_iter() (David Howells) - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call (Viacheslav Dubeyko) - powerpc: fix dead default for GUEST_STATE_BUFFER_TEST (JulianBraha) - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). (Kuniyuki Iwashima) - zonefs: handle integer overflow in zonefs_fname_to_fno (Johannes Thumshirn) - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (Jiayuan Chen) - nsfs: fix wrong error code returned for pidns ioctls (Zhihao Cheng) - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation (Ming Lei) - irqchip/ath79-cpu: Remove unused function (Rosen Penev) - NFSD: Fix infinite loop in layout state revocation (Chuck Lever) - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos) - net: lan966x: avoid unregistering netdev on register failure (Myeonghun Pak) - ice: fix locking in ice_dcb_rebuild() (Bart Van Assche) - ice: fix setting RSS VSI hash for E830 (Marcin Szycik) - tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima) - test_kprobes: clear kprobes between test runs (Martin Kaiser) - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() (Jianpeng Chang) - netfilter: x_tables: unregister the templates first (Florian Westphal) - ALSA: hda: cs35l41: Put ACPI device on missing physical node (Shuhao Fu) - ALSA: hda: cs35l56: Put ACPI device after setting companion (Shuhao Fu) - ARM: integrator: Fix early initialization (Guenter Roeck) - firmware: arm_ffa: Fix sched-recv callback partition lookup (Sudeep Holla) - firmware: arm_ffa: Align RxTx buffer size before mapping (Sudeep Holla) - pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 (Maulik Shah) - kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow) - kunit: config: Enable KUNIT_DEBUGFS by default (David Gow) - riscv: mm: Fixup no5lvl failure when vaddr is invalid (Guo Ren (Alibaba DAMO Academy)) - firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0 (Sudeep Holla) - firmware: arm_ffa: Allow multiple UUIDs per partition to register SRI callback (Sudeep Holla) - firmware: arm_ffa: Remove unnecessary declaration of ffa_partitions_cleanup()(Sudeep Holla) - firmware: arm_ffa: Unregister the FF-A devices when cleaning up the partitions (Sudeep Holla) - firmware: arm_ffa: Refactor addition of partition information into XArray (Viresh Kumar) - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (Sudeep Holla) - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla) - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) - HID: uclogic: Fix regression of input name assignment (Takashi Iwai) - pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume (Biju Das) - ARM: dts: renesas: rskrza1: Drop superfluous cells (Marek Vasut) - ARM: dts: renesas: genmai: Drop superfluous cells (Marek Vasut) - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain) - batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) - batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) - batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann) - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) - batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) - batman-adv: bla: fixreport_work leak on backbone_gw purge (Sven Eckelmann) - batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) - batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) - batman-adv: fix fragment reassembly length accounting (Ruide Cao) - batman-adv: dat: handle forward allocation error (Sven Eckelmann) - batman-adv: clear current gateway during teardown (Ruijie Li) - batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) - drm/amd/display: Validate GPIO pin LUT table size before iterating (Harry Wentland) - drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland) - drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader) - drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau) - drm/amdgpu/vpe: Force collaborate sync after TRAP (Alan Liu) - drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey) - device property: set fwnode-> secondary to NULL in fwnode_init() (Bartosz Golaszewski) - LoongArch: Remove unused code to avoid build warning (Huacai Chen) - RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito) - spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold) - spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold) - spi: ep93xx: fix error pointer deref after DMA setup failure (Johan Hovold) - scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) - phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang) - spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (Osama Abdelkader) - riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM (Osama Abdelkader) - KVM: arm64: vgic: Free private_irqs when init fails after allocation (Michael Bommarito) - KVM:arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (Michael Bommarito) - arm64: probes: Handle probes on hinted conditional branch instructions (Vladimir Murzin) - tracing: Do not call map-> ops-> elt_free() if elt_alloc() fails (Masami Hiramatsu (Google)) - wifi: mac80211: consume only present negotiated TTLM maps (Michael Bommarito) - af_unix: Fix UAF read of tail-> len in unix_stream_data_wait() (Jann Horn) - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) - ice: restore PTP Rx timestamp config after ethtool set-channels (Grzegorz Nitka) - ice: fix setting promisc mode while adding VID filter (Marcin Szycik) - octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly) - lsm: hold cred_guard_mutex for lsm_set_self_attr() (Stephen Smalley) - rbd: eliminate a race in lock_dwork draining on unmap (Ilya Dryomov) - ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (Michael Bommarito) - wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung) - vsock/virtio: reset connection on receiving queue overflow (Stefano Garzarella) - vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) - ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt) - qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) - l2tp: use list_del_rcu in l2tp_session_unhash (Michael Bommarito) - fs/ntfs3: handle attr_set_size() errors when truncating files (Konstantin Komarov) - cgroup/cpuset: Reset DL migration state on can_attach() failure (Guopeng Zhang) - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path (Tejun Heo) - sched_ext: Fix missing warning in scx_set_task_state() default case (Samuele Mariotti) - netfilter: nft_inner: Fix IPv6 inner_thoff desync (Yizhou Zhao) - netfilter: ipset: stop hash:* range iteration at end (Nan Li) - netfilter: nf_queue: holdbridge skb-> dev while queued (Haoze Xie) - netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() (Jonas Jelonek) - net: ifb: report ethtool stats over num_tx_queues (Michael Bommarito) - net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) - phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) - Bluetooth: serialize accept_q access (Jiexun Wang) - Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (Michael Bommarito) - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) - Bluetooth: bnep: Fix UAF read of dev-> name (Jann Horn) - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (David Carlier) - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakuş) - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal) - selftests/mm: run_vmtests.sh: fix destructive tests invocation (Luiz Capitulino) - mm/memory_hotplug: fix memory block reference leak on remove (Muchun Song) - ipv6: ioam: refresh hdr pointer before ioam6_event() (Justin Iurman) - drivers/base/memory: fix memory block reference leak in poison accounting (Muchun Song) - io_uring/waitid: clear waitid info before copying it to userspace (Heechan Kang) - efi: Allocate runtime workqueue before ACPI init (Ard Biesheuvel) - ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) - ALSA: pcm: Don't setup bogus iov_iter for silencing (Takashi Iwai) - ALSA: ua101: Reject too-short USB descriptors (Cássio Gabriel) - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain) - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close (ChenXiaoSong) - smb: client: use data_len for SMB2 READ encrypted folioq copy (Jeremy Erazo) - smb: client: require net admin for CIFS SWN netlink (MichaelBommarito) - ksmbd: validate SID in parent security descriptor during ACL inheritance (Junyi Liu) - ksmbd: fix null pointer dereference in compare_guid_key() (Jeremy Laratro) - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() (SeongJae Park) - sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) - hwmon: (pmbus/core) Protect regulator operations with mutex (Guenter Roeck) - Revert "ice: Remove jumbo_remove step from TX path" (Sasha Levin) - Revert "ice: fix double-free of tx_buf skb" (Sasha Levin) - perf parse-events: Expose/rename config_term_name (Ian Rogers) - drm/imagination: Synchronize interrupts before suspending the GPU (Alessio Belle) - af_unix: Give up GC if MSG_PEEK intervened. (Kuniyuki Iwashima) - ksmbd: close durable scavenger races against m_fp_list lookups (DaeMyung Kang) - Revert "x86/vdso: Fix output operand size of RDPID" (Sasha Levin) - spi: spi-dw-dma: fix print error log when wait finish transaction (Vladimir Yakovlev) - bridge: mrp: reject zero test interval to avoid OOM panic (Xiang Mei) - Revert "perf tool_pmu: Factor tool events into their own PMU" (Sasha Levin) - Revert "perf python: Add parse_events function" (Sasha Levin) - Revert "perf tool_pmu: Fix aggregation on duration_time" (Sasha Levin) - Revert "perf cgroup: Update metric leader in evlist__expand_cgroup" (Sasha Levin) - s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou) - drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (Gustavo Sousa) - ksmbd: validate owner of durable handle on reconnect (Namjae Jeon) - mptcp: pm: ADD_ADDR rtx: free sk if last (Matthieu Baerts (NGI0)) - mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (Matthieu Baerts (NGI0)) - mptcp: pm: ADD_ADDR rtx: allow ID 0 (Matthieu Baerts (NGI0)) - mptcp: sync the msk-> sndbuf at accept() time (Gang Yan) - LTS version: v6.12.91 (Saeed Mirzamohammadi) - netfs: Fix potential uninitialised var in netfs_extract_user_iter() (David Howells) - mptcp: pm: ADD_ADDR rtx: reschedblocked ADD_ADDR quicker (Matthieu Baerts (NGI0)) - mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts (NGI0)) - mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 (Matthieu Baerts (NGI0)) - spi: sifive: fix controller deregistration (Johan Hovold) - spi: sifive: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao) - f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu) - f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang) - mptcp: fix rx timestamp corruption on fastopen (Paolo Abeni) - mptcp: drop __mptcp_fastopen_gen_msk_ackseq() (Paolo Abeni) - mptcp: pm: prio: skip closed subflows (Matthieu Baerts (NGI0)) - sched_ext: Guard scx_dsq_move() against NULL kit-> dsq after failed iter_new (Tejun Heo) - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (Jason Gunthorpe) - btrfs: do not mark inode incompressible after inline attempt fails (Qu Wenruo) - smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva) - btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) - btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() (Filipe Manana) - btrfs: use inode already stored in local variable at btrfs_rmdir() (Filipe Manana) - drm/v3d: Reject empty multisync extension to prevent infinite loop (Ashutosh Desai) - eventfs: Use list_add_tail_rcu() for SRCU-protected children list (David Carlier) - iommufd: Fix return value of iommufd_fault_fops_write() (Zhenzhong Duan) - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (Johan Hovold) - drm/gma500/oaktrail_lvds: fix hang on init failure (Johan Hovold) - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold) - drm/xe/dma-buf: handle empty bo and UAF races (Matthew Auld) - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek) - drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka) - iommu/vt-d:Disable DMAR for Intel Q35 IGFX (Naval Alcalá) - libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) - libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) - libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) - libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) - irqchip/riscv-imsic: Clear interrupt move state during CPU offlining (Yong-Xuan Wang) - netfs: fix error handling in netfs_extract_user_iter() (Paulo Alcantara) - powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke) - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) - ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (Viacheslav Dubeyko) - ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cássio Gabriel) - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (Cássio Gabriel) - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah) - drm/loongson: Use managed KMS polling (Myeonghun Pak) - smb/client: fix possible infinite loop and oob read in symlink_data() (Ye Bin) - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Pauli Virtanen) - netfilter: nf_tables: unconditionally bump set-> nelems before insertion (Pablo Neira Ayuso) - KVM: x86: Fix Xen hypercall tracepoint argument assignment (Qiang Ma) - KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic (Junrui Luo) - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia) - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski) - netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (Mario Limonciello) - audit: fix incorrect inheritable capability in CAPSET records (SergioCorreia) - netfilter: nf_conntrack_sip: get helper before allocating expectation (Li Xiasong) - workqueue: Fix wq-> cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path (Breno Leitao) - i40e: Cleanup PTP pins on probe failure (Matt Vollrath) - crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) - page_pool: fix incorrect mp_ops error handling (Mina Almasry) - netpoll: pass buffer size to egress_dev() to avoid MAC truncation (Breno Leitao) - netpoll: Extract IPv6 address retrieval function (Breno Leitao) - net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet) - perf tool_pmu: Fix aggregation on duration_time (Ian Rogers) - iommu/amd: Put list_add/del(dev_data) back under the domain-> lock (Jason Gunthorpe) - iommu/amd: Reorder attach device code (Vasant Hegde) - net: bcmgenet: fix leaking free_bds (Justin Chen) - net: bcmgenet: Initialize u64 stats seq counter (Ryo Takakura) - PCI: Initialize temporary device in new_id_store() (Samiullah Khawaja) - ntfs: -> d_compare() must not block (Al Viro) - LoongArch: KVM: Compile switch.S directly into the kernel (Xianglai Li) - smb: client: fix OOB reads parsing symlink error response (Greg Kroah-Hartman) - smb: client: correctly handle ErrorContextData as a flexible array (Liang Jie) - arm64: Reserve an extra page for early kernel mapping (Zhaoyang Huang) - net/sched: cls_flower: revert unintended changes (Paolo Abeni) - sfc: fix error code in efx_devlink_info_running_versions() (Dan Carpenter) - net: tls: fix strparser anchor skb leak on offload RX setup failure (Jakub Kicinski) - ice: fix NULL pointer dereference in ice_reset_all_vfs() (Petr Oros) - iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler (Petr Oros) - iavf: wait for PF confirmation before removing VLAN filters (Petr Oros) - iavf: stop removing VLAN filters from PF on interface down (Petr Oros) - iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING (Petr Oros) - page_pool: fix memory-provider leak in page_pool_create_percpu() error path (Hasan Basbunar) - net:page_pool: create hooks for custom memory providers (Pavel Begunkov) - page_pool: Set dma_sync to false for devmem memory provider (Samiullah Khawaja) - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (Shuicheng Lin) - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (Shuicheng Lin) - drm/xe/debugfs: Correct printing of register whitelist ranges (Matt Roper) - drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristóf) - drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristóf) - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior) - ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() (Richard Fitzgerald) - ALSA: hda/conexant: Fix missing error check for jack detection (wangdicheng) - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (wangdicheng) - netconsole: propagate device name truncation in dev_name_store() (Breno Leitao) - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet) - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) - sctp: discard stale INIT after handshake completion (Xin Long) - netfilter: skip recording stale or retransmitted INIT (Xin Long) - ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt) - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (Yinjie Yao) - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3enc ring (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (Yinjie Yao) - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (Yinjie Yao) - net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher) - net: mctp i2c: check length before marking flow active (William A. Kennington III) - sched/fair: Clear rel_deadline when initializing forked entities (Zicheng Qu) - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (Takashi Iwai) - netpoll: fix IPv6 local-address corruption (Breno Leitao) - netpoll: extract IPv4 address retrieval into helper function (Breno Leitao) - netpoll: Extract carrier wait function (Breno Leitao) - netconsole: allow selection of egress interface via MAC address (Uday Shankar) - net, treewide: define and use MAC_ADDR_STR_LEN (Uday Shankar) - tcp: make probe0 timer handle expired user timeout (Altan Hacigumus) - neigh: let neigh_xmit take skb ownership (Florian Westphal) - net/sched: taprio: fix NULL pointer dereference in class dump (Weiming Shi) - NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts) - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Morduan Zang) - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Zhan Jun) - vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet) - net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet) - net/sched: netem: check for negative latency and jitter (Stephen Hemminger) - net/sched: netem: fix slot delay calculation overflow (Stephen Hemminger) - net/sched: netem: validate slot configuration (Stephen Hemminger) - net/sched: netem: only reseed PRNG when seed is explicitly provided (Stephen Hemminger) - net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) - net/sched: netem: fix probability gaps in 4-state lossmodel (Stephen Hemminger) - netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer) - drm/sysfb: ofdrm: fix PCI device reference leaks (Yuho Choi) - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (John Madieu) - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (Guilherme G. Piccoli) - netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) - netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristóf) - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristóf) - drm/amdgpu: fix spelling typos (Alexandre Demers) - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (Christian König) - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (Timur Kristóf) - nvme-pci: fix missed admin queue sq doorbell write (Keith Busch) - netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (Maurizio Lombardi) - tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao) - cgroup: Increment nr_dying_subsys_* from rmdir context (Petr Malat) - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone) - fsnotify: fix inode reference leak in fsnotify_recalc_mask() (Amir Goldstein) - mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang) - mailbox: mailbox-test: initialize struct earlier (Wolfram Sang) - mailbox: mailbox-test: don't free the reused channel (Wolfram Sang) - mailbox: add sanity check for channel array (Wolfram Sang) - cgroup/rdma: fix integer overflow in rdmacg_try_charge() (cuitao) - mailbox: mailbox-test: free channels on probe error (Wolfram Sang) - mailbox: mtk-cmdq: Fix CURR and END addr for task insert case (Jason-JH Lin) - fbdev: offb: fix PCI device referenceleak on probe failure (Yuho Choi) - kbuild: builddeb - avoid recompiles for non-cross-compiles (Mathias Krause) - rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin (Nokia)) - fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju) - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju) - tipc: fix double-free in tipc_buf_append() (Lee Jones) - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev) - virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET (Brett Creeley) - virtio_net: Use new RSS config structs (Akihiko Odaki) - virtio_net: Fix endian with virtio_net_ctrl_rss (Akihiko Odaki) - virtio_net: Split struct virtio_net_rss_config (Akihiko Odaki) - net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() (Lorenzo Bianconi) - net: dsa: realtek: rtl8365mb: fix mode mask calculation (Mieczyslaw Nalewaj) - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet) - net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet) - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet) - net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet) - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet) - ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g (Jacob Keller) - ice: fix timestamp interrupt configuration for E825C (Grzegorz Nitka) - ksmbd: scope conn-> binding slowpath to bound sessions only (Hyunwoo Kim) - ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open (DaeMyung Kang) - ksmbd: destroy async_ida in ksmbd_conn_free() (DaeMyung Kang) - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (DaeMyung Kang) - pwm: atmel-tcb: Cache clock rates and mark chip as atomic (Sangyun Kim) - arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Jun Yan) - slip: bound decode() reads against the compressed packet length (Weiming Shi) - slip: reject VJ receive packets oninstances with no rstate array (Weiming Shi) - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) - ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang) - netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) - netfilter: conntrack: remove sprintf usage (Florian Westphal) - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) - netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso) - openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) - net/mlx5: Fix HCA caps leak on notifier init failure (Prathamesh Deshpande) - pppoe: drop PFC frames (Qingfang Deng) - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) - ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) - e1000e: Unroll PTP in probe error handling (Matt Vollrath) - i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju) - ice: fix ICE_AQ_LINK_SPEED_M for 200G (Paul Greenwalt) - ice: fix double-free of tx_buf skb (Michal Schmidt) - ice: Remove jumbo_remove step from TX path (Alice Mikityanska) - ice: update PCS latency settings for E825 10G/25Gb modes (Grzegorz Nitka) - tcp: annotate data-races around tp-> plb_rehash (Eric Dumazet) - tcp: annotate data-races around (tp-> write_seq - tp-> snd_nxt) (Eric Dumazet) - tcp: annotate data-races around tp-> dsack_dups (Eric Dumazet) - tcp: annotate data-races around tp-> bytes_retrans (Eric Dumazet) - tcp: annotate data-races around tp-> bytes_sent (Eric Dumazet) - tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE (Eric Dumazet) - tcp: add data-race annotations around tp-> data_segs_out and tp-> total_retrans (Eric Dumazet) - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) - nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) - net/sched: sch_cake: fix NAT destination port not beingupdated in cake_update_flowkeys (Dudu Lu) - macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (Dudu Lu) - net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir (Dudu Lu) - arm64: dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names (Gabor Juhos) - arm64: dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT (Peng Fan) - PCMCIA: Fix garbled log messages for KERN_CONT (René Rebe) - arm64: dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT (Peng Fan) - arm64: dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT (Peng Fan) - erofs: unify lcn as u64 for 32-bit platforms (Gao Xiang) - erofs: avoid infinite loops due to corrupted subpage compact indexes (Gao Xiang) - erofs: do sanity check on m-> type in z_erofs_load_compact_lcluster() (Chao Yu) - erofs: add encoded extent on-disk definition (Gao Xiang) - crypto: ccp - copy IV using skcipher ivsize (Paul Moses) - crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham) - drm/i915/wm: Verify the correct plane DDB entry (Ville Syrjälä) - drm/i915: Relocate the SKL wm sanitation code (Ville Syrjälä) - f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() (Yongpeng Yang) - clk: visconti: pll: initialize clk_init_data to zero (Brian Masney) - clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON (Jagadeesh Kona) - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven) - clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio) -dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio) - clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven) - clk: qoriq: avoid format string warning (Arnd Bergmann) - x86/um: fix vDSO installation (Thomas Weißschuh) - x86/um/vdso: Drop VDSO64-y from Makefile (Thomas Weißschuh) - clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak) - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu) - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu) - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett) - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett) - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett) - clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett) - clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett) - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett) - scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) - clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting (Konrad Dybcio) - clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers (White Lewis) - scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yang Erkun) - scsi: sg: Fix sysctl sg-big-buff register during sg_init() (Yang Erkun) - clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source (Dmitry Baryshkov) - RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) - platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) - platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin) - fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou) - tty: serial: ip22zilog: Fix section mispatch warning (Thomas Bogendoerfer) - platform/x86: asus-wmi: fix screenpad brightness range (Denis Benato) - platform/x86: asus-wmi: adjust screenpad power/brightness handling (Denis Benato) - nfs/blocklayout:Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko) - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal) - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki) - tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap) - leds: lgm-sso: Remove duplicate assignments for priv-> mmap (Chen Ni) - platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki) - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni) - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai) - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() (Felix Gu) - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback (Felix Gu) - reset: Add devres helpers to request pre-deasserted reset controls (Philipp Zabel) - reset: replace boolean parameters with flags parameter (Philipp Zabel) - perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo) - perf maps: Fix copy_from that can break sorted by name order (Ian Rogers) - perf cgroup: Update metric leader in evlist__expand_cgroup (Ian Rogers) - perf python: Add parse_events function (Ian Rogers) - perf tool_pmu: Factor tool events into their own PMU (Ian Rogers) - perf evsel: Add alternate_hw_config and use in evsel__match (Ian Rogers) - ipmi: ssif_bmc: change log level to dbg in irq callback (Jian Zhang) - ipmi: ssif_bmc: fix message desynchronization after truncated response (Jian Zhang) - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure (Jian Zhang) - perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan) - perf tools: Fix module symbol resolution for non-zero .text sh_addr (Chuck Lever) - perf stat: Fix opt-> value type for parse_cache_level (Ian Rogers) - perf lock: Fix option value type in parse_max_stack (Ian Rogers) - pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT}registers (Biju Das) - pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin) - pinctrl: realtek: Fix function signature for config argument (Yu-Chun Lin) - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach) - perf branch: Avoid incrementing NULL (Ian Rogers) - pinctrl: cy8c95x0: Avoid returning positive values to user space (Andy Shevchenko) - pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() (Andy Shevchenko) - pinctrl: cy8c95x0: remove duplicate error message (Andy Shevchenko) - pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore) - bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT (Puranjay Mohan) - bpf: Validate node_id in arena_alloc_pages() (Puranjay Mohan) - bpf: allow UTF-8 literals in bpf_bprintf_prepare() (Yihan Ding) - bpf: Fix NULL deref in map_kptr_match_type for scalar regs (Mykyta Yatsenko) - bpf: Fix precedence bug in convert_bpf_ld_abs alignment check (Daniel Borkmann) - bpf, sockmap: Take state lock for af_unix iter (Michal Luczaj) - bpf, sockmap: Fix af_unix null-ptr-deref in proto update (Michal Luczaj) - bpf, sockmap: Fix af_unix iter deadlock (Michal Luczaj) - bpf, arm64: Fix off-by-one in check_imm signed range check (Daniel Borkmann) - ext4: fix possible null-ptr-deref in mbt_kunit_exit() (Ye Bin) - HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud) - cxl/pci: Check memdev driver binding status in cxl_reset_done() (Li Ming) - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav) - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang) - mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation (Jonas Gorski) - mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook (Takahiro Kuwano) - mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook (Takahiro Kuwano) - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen) - dt-bindings: interrupt-controller:arm,gic-v3: Fix EPPI range (Geert Uytterhoeven) - ima_fs: Correctly create securityfs files for unsupported hash algos (Dmitry Safonov) - ima_fs: get rid of lookup-by-dentry stuff (Al Viro) - ima_fs: don't bother with removal of files in directory we'll be removing (Al Viro) - mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni) - HID: asus: do not abort probe when not necessary (Denis Benato) - HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato) - ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges) - remoteproc: xlnx: Fix sram property parsing (Tim Michals) - hte: tegra194: remove Kconfig dependency on Tegra194 SoC (Francesco Lavra) - tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou) - soundwire: cadence: Clear message complete before signaling waiting thread (Richard Fitzgerald) - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li) - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() (Cole Leavitt) - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli) - ocfs2: validate group add input before caching (ZhengYuan Huang) - ocfs2: validate bg_bits during freefrag scan (ZhengYuan Huang) - ocfs2: fix listxattr handling when the buffer is full (ZhengYuan Huang) - firmware: arm_ffa: Use the correct buffer size during RXTX_MAP (Sebastian Ene) - ARM: dts: imx27-eukrea: replace interrupts with interrupts-extended (Frank Li) - arm64/xor: fix conflicting attributes for xor_block_template (Christoph Hellwig) - ARM: OMAP1: Fix DEBUG_LL and earlyprintk on OMAP16XX (Aaro Koskinen) - arm64: dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP (Alexander Koskovich) - soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari) - soc: qcom: llcc: fix v1 SB syndrome register offset (Alok Tiwari) - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) - ocfs2/dlm: validate qr_numregions in dlm_match_regions()(Junrui Luo) - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki) - soc/tegra: cbb: Set ERD on resume for err interrupt (Sumit Gupta) - arm64: dts: imx8qxp-mek: switch Type-C connector power-role to dual (Xu Yang) - arm64: dts: imx8qm-mek: switch Type-C connector power-role to dual (Xu Yang) - arm64: dts: lx2160a: complete pinmux for rcwsr12 configuration word (Josua Mayer) - arm64: dts: lx2160a: change zeros to hexadecimal in pinmux nodes (Josua Mayer) - arm64: dts: lx2160a: add sda gpio references for i2c bus recovery (Josua Mayer) - arm64: dts: lx2160a: rename pinmux nodes for readability (Josua Mayer) - arm64: dts: lx2160a: remove duplicate pinmux nodes (Josua Mayer) - arm64: dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit (Josua Mayer) - arm64: dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing (Nora Schiffer) - arm64: dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label (Francesco Dolcini) - arm64: dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins (Judith Mendez) - arm64: dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins (Judith Mendez) - arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberg) - arm64: dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl (Luca Weiss) - arm64: dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy) - arm64: dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy) - arm64: dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy) - arm64: dts: qcom: sm8650: Fix xo clock supply of SD host controller (Vladimir Zapolskiy) - arm64: dts: qcom: sm8550: Fix xo clock supply of platform SD host controller (Vladimir Zapolskiy) - arm64: dts: qcom: sm8650: Fix GIC_ITS range length (Konrad Dybcio) - arm64: dts: qcom: sm8550: Fix GIC_ITS range length (Konrad Dybcio) - arm64: dts: qcom: sm8450: Fix GIC_ITS range length (Konrad Dybcio) - bus: rifsc:fix RIF configuration check for peripherals (Gatien Chevallier) - soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov) - soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov) - soc: qcom: ocmem: make the core clock optional (Dmitry Baryshkov) - arm64: dts: rockchip: Correct Joystick Axes on Gameforce Ace (Chris Morgan) - arm64: dts: rockchip: Correct Fan Supply for Gameforce Ace (Chris Morgan) - arm64: dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi (Ming Wang) - arm64: dts: qcom: msm8953-xiaomi-daisy: fix backlight (Barnabás Czémán) - arm64: dts: qcom: msm8953-xiaomi-vince: correct wled ovp value (Barnabás Czémán) - arm64: dts: mediatek: mt7986a: Fix gpio-ranges pin count (Akari Tsuyukusa) - arm64: dts: mediatek: mt7981b: Fix gpio-ranges pin count (Akari Tsuyukusa) - arm64: dts: mediatek: mt6795: Fix gpio-ranges pin count (Akari Tsuyukusa) - iommufd: vfio compatibility extension check for noiommu mode (Jacob Pan) - arm64: dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) (Sherry Sun) - arm64: dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config (Heiko Stuebner) - arm64: dts: imx8-apalis: Fix LEDs name collision (Francesco Dolcini) - memory: tegra30-emc: Fix dll_change check (Mikko Perttunen) - memory: tegra124-emc: Fix dll_change check (Mikko Perttunen) - ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafał Miłecki) - arm64: dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon (Nícolas F. R. A. Prado) - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith) - efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) - gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) - gfs2: add some missing log locking (Andreas Gruenbacher) - quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) - ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marlière) - ktest: Honorempty per-test option overrides (Ricardo B. Marlière) - ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marlière) - fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() (Ondrej Mosnacek) - fdget(), trivial conversions (Al Viro) - net/socket.c: switch to CLASS(fd) (Al Viro) - gfs2: Call unlock_new_inode before d_instantiate (Andreas Gruenbacher) - ALSA: hda/realtek - fixed speaker no sound update (Kailang Yang) - crypto: jitterentropy - replace long-held spinlock with mutex (Haixin Xu) - dm cache: fix missing return in invalidate_committed's error path (Ming-Hung Tsai) - ALSA: sc6000: Keep the programmed board state in card-private data (Cássio Gabriel) - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback (Pei Xiao) - PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on (Manikanta Maddireddy) - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well (Manikanta Maddireddy) - PCI: tegra194: Use DWC IP core version (Manikanta Maddireddy) - PCI: tegra194: Free up Endpoint resources during remove() (Vidya Sagar) - PCI: tegra194: Allow system suspend when the Endpoint link is not up (Vidya Sagar) - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode (Vidya Sagar) - PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar) - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" (Vidya Sagar) - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode (Manikanta Maddireddy) - PCI: tegra194: Don't force the device into the D0 state before L2 (Vidya Sagar) - PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() (Manivannan Sadhasivam) - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy) - PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy) - PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar) - PCI/NPEM: Set LED_HW_PLUGGABLEfor hotplug-capable ports (Richard Cheng) - ASoC: SOF: compress: return the configured codec from get_params (Cássio Gabriel) - ALSA: scarlett2: Add missing sentinel initializer field (Panagiotis Petrakopoulos) - selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long) - Documentation: fix a hugetlbfs reservation statement (Jane Chu) - selftests/mm: skip migration tests if NUMA is unavailable (AnishMulay) - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found (Chen-Yu Tsai) - PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer) - ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] (Denis Rastyogin) - crypto: qat - use swab32 macro (Giovanni Cabiddu) - crypto: qat - fix type mismatch in RAS sysfs show functions (Giovanni Cabiddu) - crypto: qat - disable 420xx AE cluster when lead engine is fused off (Ahsan Atta) - crypto: qat - disable 4xxx AE cluster when lead engine is fused off (Ahsan Atta) - crypto: qat - introduce fuse array (Suman Kumar Chakraborty) - ASoC: qcom: qdsp6: topology: check widget type before accessing data (Srinivas Kandagatla) - iommu/amd: Fix clone_alias() to use the original device's devid (Vasant Hegde) - iommu/amd: Convert dev_data lock from spinlock to mutex (Vasant Hegde) - iommu/amd: Rearrange attach device code (Vasant Hegde) - iommu/amd: Reduce domain lock scope in attach device path (Vasant Hegde) - iommu/amd: Do not detach devices in domain free path (Vasant Hegde) - iommu/amd: xarray to track protection_domain-> iommu list (Vasant Hegde) - iommu/amd: Remove protection_domain.dev_cnt variable (Vasant Hegde) - ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang) - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang) - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang) - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang) - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (ShengjiuWang) - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() (Shengjiu Wang) - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() (Shengjiu Wang) - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() (Shengjiu Wang) - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() (Shengjiu Wang) - ASoC: fsl_micfil: Add access property for "VAD Detected" (Shengjiu Wang) - PM: domains: De-constify fields in struct dev_pm_domain_attach_data (Dmitry Baryshkov) - pmdomain: imx: scu-pd: Fix device_node reference leak during -> probe() (Felix Gu) - pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu) - drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen) - drm/msm/a6xx: Fix dumping A650+ debugbus blocks (Connor Abbott) - drm/msm/shrinker: Fix can_block() logic (Rob Clark) - drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark) - ASoC: SOF: Intel: hda: Place check before dereference (Ethan Tidmore) - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Lei Huang) - hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback (Billy Tsai) - hwmon: Switch back to struct platform_driver::remove() (Uwe Kleine-König) - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (Timur Kristóf) - drm/amdgpu: update the handle ptr in early_init (Sunil Khatri) - drm/amdgpu: update the handle ptr in dump_ip_state (Sunil Khatri) - drm/amdgpu: add amdgpu_device reference in ip block (Sunil Khatri) - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristóf) - drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristóf) - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristóf) - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristóf) - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristóf) - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristóf) - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (TimurKristóf) - ALSA: core: Validate compress device numbers without dynamic minors (Cássio Gabriel) - PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support (Krishna Chaitanya Chundru) - drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel) - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first (Dmitry Baryshkov) - drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich) - drm/msm/dpu: fix mismatch between power and frequency (Yuanjie Yang) - iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() (Nicolin Chen) - drm/imagination: Switch reset_reason fields from enum to u32 (Alexandru Dadu) - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao) - drm/amdgpu/gfx11: look at the right prop for gfx queue priority (Alex Deucher) - drm/amdgpu/gfx10: look at the right prop for gfx queue priority (Alex Deucher) - PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation (Koichiro Den) - padata: Remove cpu online check from cpu add and removal (Chuyi Zhou) - crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs (Thorsten Blum) - crypto: atmel - Use unregister_{aeads,ahashes,skciphers} (Thorsten Blum) - crypto: tegra - Disable softirqs before finalizing request (Herbert Xu) - crypto: tegra - Reserve keyslots to allocate dynamically (Akhil R) - crypto: tegra - Transfer HASH init function to crypto engine (Akhil R) - crypto: tegra - finalize crypto req on error (Akhil R) - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko) - dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet) - drm/amdgpu: Add default case in DVI mode validation (Srinivasan Shanmugam) - drm/sun4i: Fix resource leaks (Ethan Tidmore) - drm/v3d: Handle error from drm_sched_entity_init() (Maíra Canal) - selftests/sched_ext: Add missing error check for exit__load() (David Carlier) - media: i2c: og01a1b: Fix V4L2 subdevice datainitialization on probe (Vladimir Zapolskiy) - media: i2c: og01a1b: Replace client-> dev usage (Laurent Pinchart) - spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu) - spi: nxp-fspi: Use reinit_completion() for repeated operations (Felix Gu) - spi: spi-nxp-fspi: enable runtime pm for fspi (Haibo Chen) - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check (Harikrishna Shenoy) - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs (Jayesh Choudhary) - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() (Jayesh Choudhary) - dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) - dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() (Manivannan Sadhasivam) - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() (Richard Zhu) - PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() (Aksh Garg) - PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding (Niklas Cassel) - platform/chrome: chromeos_tbmc: Drop wakeup source on remove (Rafael J. Wysocki) - dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) - dm cache: support shrinking the origin device (Ming-Hung Tsai) - dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai) - dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) - dm cache: fix write hang in passthrough mode (Ming-Hung Tsai) - dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai) - dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) - ASoC: sti: use managed regmap_field allocations (Sander Vanheule) - ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule) - drm/sun4i: backend: fix error pointer dereference (Ethan Tidmore) - ASoC: soc-compress: use function to clear symmetricparams (Kuninori Morimoto) - ASoC: add symmetric_ prefix for dai-> rate/channels/sample_bits (Kuninori Morimoto) - ASoC: SOF: ipc3: Use standard dev_dbg API (Daniel Baluta) - drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov) - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) - sctp: fix missing encap_port propagation for GSO fragments (Xin Long) - tcp: Don't set treq-> req_usec_ts in cookie_tcp_reqsk_init(). (Kuniyuki Iwashima) - udp: Force compute_score to always inline (Gabriel Krisman Bertazi) - ipv6: udp: fix typos in comments (Alok Tiwari) - ipv4: udp: fix typos in comments (Alok Tiwari) - net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier) - Bluetooth: SCO: check for codecs-> num_codecs == 1 before assigning to sco_pi(sk)-> codec (Stefan Metzmacher) - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) - net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman) - net/mlx5e: Fix features not applied during netdev registration (Gal Pressman) - net: phy: fix a return path in get_phy_c45_ids() (Charles Perry) - dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 (Josua Mayer) - net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ (Luca Weiss) - net: ipa: Fix programming of QTIME_TIMESTAMP_CFG (Luca Weiss) - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) - bpf: Fix OOB in pcpu_init_value (Lang Xu) - bpf: Allow instructions with arena source and non-arena dest registers (Emil Tsalapatis) - selftests: netfilter: nft_tproxy.sh: adjust to socat changes (Florian Westphal) - net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) - selftests/bpf: fix__jited_unpriv tag name (Eduard Zingerman) - bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (Daniel Borkmann) - bpf: Relax scalar id equivalence for state pruning (Puranjay Mohan) - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen) - bpf: Fix RCU stall in bpf_fd_array_map_clear() (Sechang Lim) - bpf: return VMA snapshot from task_vma iterator (Puranjay Mohan) - bpf: switch task_vma iterator from mmap_lock to per-VMA locks (Puranjay Mohan) - bpf: fix mm lifecycle in open-coded task_vma iterator (Puranjay Mohan) - netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal) - netfilter: xt_socket: enable defrag after all other checks (Florian Westphal) - eth: fbnic: Use wake instead of start (Mohsin Bashir) - net: bcmgenet: fix racing timeout handler (Justin Chen) - net: bcmgenet: switch to use 64bit statistics (Zak Kemble) - net: bcmgenet: support reclaiming unsent Tx packets (Doug Berger) - net: bcmgenet: move DESC_INDEX flow to ring 0 (Doug Berger) - net: bcmgenet: add bcmgenet_has_* helpers (Doug Berger) - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) - arm64: kexec: Remove duplicate allocation for trans_pgd (Wang Wensheng) - ACPI: AGDI: fix missing newline in error message (Haoyu Lu) - wifi: ath10k: fix station lookup failure during disconnect (Baochen Qiang) - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi) - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() (Nicolas Escande) - wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) - bpf: Fix stale offload-> prog pointer after constant blinding (MingTao Huang) - bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) - macvlan: annotate data-races around port-> bc_queue_len_used (Eric Dumazet) - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15 (Amit Machhiwal) - powerpc/crash: Updatebackup region offset in elfcorehdr on memory hotplug (Sourabh Jain) - powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain) - r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu) - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() (Alexey Velichayshiy) - bpf,arc_jit: Fix missing newline in pr_err messages (haoyu.lu) - bpf: Fix variable length stack write over spilled pointers (Alexei Starovoitov) - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) - wifi: mt76: mt7921: fix 6GHz regulatory update on connection (Michael Lo) - wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() (Duoming Zhou) - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() (Duoming Zhou) - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event (StanleyYP Wang) - arm64: cpufeature: Make PMUVer and PerfMon unsigned (James Clark) - wifi: mt76: mt7921: Place upper limit on station AID (Rory Little) - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor (Alok Tiwari) - wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi (Ming Yen Hsieh) - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() (Ming Yen Hsieh) - wifi: mt76: mt7915: fix use_cts_prot support (Ryder Lee) - wifi: mt76: mt7615: fix use_cts_prot support (Ryder Lee) - wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control (Leon Yen) - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() (Sean Wang) - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu) - params: Replace __modinit with __init_or_module (Petr Pavlu) - s390/bpf: Zero-extend bpf prog return values and kfunc arguments (Ilya Leoshkevich) - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen) - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen) - bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (FengYang) - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan) - firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello (AMD)) (Bart Van Assche) - sparc64: vdso: Link with -z noexecstack (Thomas Weißschuh) - sparc/vdso: Always reject undefined references during linking (Thomas Weißschuh) - hrtimer: Reduce trace noise in hrtimer_start() (Thomas Gleixner) - hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() (Peter Zijlstra) - hrtimers: Update the return type of enqueue_hrtimer() (Richard Clark) - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney) - bus: fsl-mc: use generic driver_override infrastructure (Danilo Krummrich) - s390/cio: use generic driver_override infrastructure (Danilo Krummrich) - platform/wmi: use generic driver_override infrastructure (Danilo Krummrich) - PCI: use generic driver_override infrastructure (Danilo Krummrich) - soundwire: debugfs: initialize firmware_file to empty string (Gui-Dong Han) - debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() (Gui-Dong Han) - debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han) - thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon) - devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich) - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (Rafael J. Wysocki) - ACPI: x86: cmos_rtc: Clean up address space handler driver (Rafael J. Wysocki) - btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (Filipe Manana) - btrfs: pass struct btrfs_inode to clone_copy_inline_extent() (David Sterba) - md: wake raid456 reshape waiters before suspend (Yu Kuai) - pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt) - blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (Jackie Liu) - nilfs2: reject zerobd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey) - loop: fix partition scan race between udev and loop_reread_partitions() (Daan De Meyer) - drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) - md/raid1: fix the comparing region of interval tree (Xiao Ni) - fs/mbcache: cancel shrink work before destroying the cache (HyungJung Joo) - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (HyungJung Joo) - blk-cgroup: wait for blkcg cleanup before initializing new disk (Ming Lei) - io_uring/kbuf: use mem_is_zero() (Pavel Begunkov) - LTS version: v6.12.90 (Saeed Mirzamohammadi) - drm/amdgpu/vcn4: Avoid overflow on msg bound check (Benjamin Cheng) - drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng) - vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) - vsock/virtio: fix empty payload in tap skb for non-linear buffers (Stefano Garzarella) - vsock/virtio: fix length and offset in tap skb for split packets (Stefano Garzarella) - vsock: fix buffer size clamping order (Norbert Szetei) - batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann) - batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) - tracing/probes: Limit size of event probe to 3K (Steven Rostedt) - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) - btrfs: fix double free in create_space_info_sub_group() error path (Guangshuo Li) - btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() (Filipe Manana) - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) - io_uring/kbuf: support min length left for incremental buffers (Martin Michaelis) - bonding: fix use-after-free due to enslave fail after slave array update (Nikolay Aleksandrov) - rust: allow clippy::collapsible_if globally (Miguel Ojeda) - rust: allow clippy::collapsible_match globally (Miguel Ojeda) - mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values (SeongJae Park) -mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values (SeongJae Park) - mm/damon/core: implement damon_kdamond_pid() (SeongJae Park) - mm/damon/core: disallow time-quota setting zero esz (SeongJae Park) - rust: pin-init: fix incorrect accessor reference lifetime (Gary Guo) - fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) - tracefs: Fix default permissions not being applied on initial mount (David Carlier) - block: fix zone write plug removal (Damien Le Moal) - block: reorganize struct blk_zone_wplug (Damien Le Moal) - block: cleanup blkdev_report_zones() (Damien Le Moal) - mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon) - spi: uniphier: fix controller deregistration (Johan Hovold) - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao) - spi: tegra114: fix controller deregistration (Johan Hovold) - spi: tegra20-sflash: fix controller deregistration (Johan Hovold) - spi: zynq-qspi: fix controller deregistration (Johan Hovold) - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao) - Bluetooth: hci_conn: fix potential UAF in create_big_sync (David Carlier) - ALSA: seq: Fix UMP group 16 filtering (Cássio Gabriel) - ALSA: seq: Notify client and port info changes (Takashi Iwai) - ALSA: hda: cs35l56: Propagate ASP TX source control errors (Cássio Gabriel) - usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan) - usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne) - batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) - batman-adv: bla: only purge non-released claims (Sven Eckelmann) - batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) - batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) - batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) - batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) - sctp: revalidate list cursor aftersctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) - arm64: dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 (Siddharth Vadapalli) - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher) - drm/amdgpu/pm: add missing revision check for CI (Alex Deucher) - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) - drm/amdkfd: Make all TLB-flushes heavy-weight (Felix Kuehling) - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (Icenowy Zheng) - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore) - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (Icenowy Zheng) - drm/exynos: remove bridge when component_add fails (Osama Abdelkader) - drm/amdgpu: zero-initialize GART table on allocation (Philip Yang) - drm/radeon: add missing revision check for CI (Alex Deucher) - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (Shuicheng Lin) - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (Shuicheng Lin) - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (Shuicheng Lin) - drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) - drm/amd/display: Change dither policy for 10 bpc output back to dithering (Mario Kleiner) - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (Benjamin Cheng) - drm/amdgpu/vce: Prevent partial address patches (Benjamin Cheng) - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (Benjamin Cheng) - drm/amdgpu: Add bounds checking to ib_{get,set}_value (Benjamin Cheng) - drm/amdkfd: Add upper bound check for num_of_nodes (Alysa Liu) - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (Yang Wang) - drm/amdgpu: gate VM CPU HDP flush on reset lock (Chenglei Xie) - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upperand lower count. (Ramalingeswara Reddy, Kanala) - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (Amir Shetaia) - drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() (Yasuaki Torimaru) - spi: cadence: fix unclocked access on unbind (Johan Hovold) - spi: cadence: fix controller deregistration (Johan Hovold) - spi: mpc52xx: fix use-after-free on unbind (Johan Hovold) - spi: mpc52xx: fix controller deregistration (Johan Hovold) - spi: mpc52xx: fix use-after-free on registration failure (Johan Hovold) - spi: orion: fix clock imbalance on registration failure (Johan Hovold) - spi: orion: fix runtime pm leak on unbind (Johan Hovold) - spi: orion: fix controller deregistration (Johan Hovold) - spi: mxic: fix controller deregistration (Johan Hovold) - spi: imx: fix runtime pm leak on probe deferral (Johan Hovold) - spi: img-spfi: fix controller deregistration (Johan Hovold) - spi: rspi: fix controller deregistration (Johan Hovold) - spi: sprd: fix controller deregistration (Johan Hovold) - spi: pic32-sqi: fix controller deregistration (Johan Hovold) - spi: npcm-pspi: fix controller deregistration (Johan Hovold) - spi: coldfire-qspi: fix controller deregistration (Johan Hovold) - spi: bcmbca-hsspi: fix controller deregistration (Johan Hovold) - spi: fsl: fix controller deregistration (Johan Hovold) - spi: sh-hspi: fix controller deregistration (Johan Hovold) - spi: pl022: fix controller deregistration (Johan Hovold) - spi: mtk-nor: fix controller deregistration (Johan Hovold) - spi: pic32: fix controller deregistration (Johan Hovold) - spi: omap2-mcspi: fix controller deregistration (Johan Hovold) - spi: fsl-espi: fix controller deregistration (Johan Hovold) - spi: s3c64xx: fix controller deregistration (Johan Hovold) - spi: dln2: fix controller deregistration (Johan Hovold) - spi: mxs: fix controller deregistration (Johan Hovold) - media: omap3isp: drop the use count of v4l2 pipeline (Haoxiang Li) - media: i2c: ov08d10: fix image vertical start setting (Matthias Fend) - media:staging: imx: request mbus_config in csi_start (Michael Tretter) - media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu) - media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov) - media: pci: zoran: fix potential memory leak in zoran_probe() (Abdun Nihaal) - vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy (Luigi Leonardi) - platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal) - spi: aspeed-smc: fix controller deregistration (Johan Hovold) - media: saa7164: add ioremap return checks and cleanups (Wang Jun) - spi: at91-usart: fix controller deregistration (Johan Hovold) - spi: qup: fix controller deregistration (Johan Hovold) - spi: meson-spicc: fix controller deregistration (Johan Hovold) - spi: lantiq-ssc: fix controller deregistration (Johan Hovold) - regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold) - regulator: act8945a: fix OF node reference imbalance (Johan Hovold) - media: i2c: imx283: Fix hang when going from large to small resolution (Jai Luthra) - media: intel/ipu6: fix error pointer dereference (Ethan Tidmore) - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap (Janne Grunau) - regulator: rk808: fix OF node reference imbalance (Johan Hovold) - media: i2c: imx283: Enter full standby when stopping streaming (Jai Luthra) - media: rc: streamzap: Error handling in probe (Oliver Neukum) - media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum) - regulator: max77650: fix OF node reference imbalance (Johan Hovold) - spi: st-ssc4: fix controller deregistration (Johan Hovold) - regulator: mt6357: fix OF node reference imbalance (Johan Hovold) - staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus) - arm64: dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd & gpio pinmux (Josua Mayer) - spi: atmel: fix controller deregistration (Johan Hovold) - spi: bcm63xx: fix controller deregistration (Johan Hovold) - media: chips-media: wave5: add missing spinlock protection forhandle_dynamic_resolution_change() (Ziyi Guo) - media: chips-media: wave5: add missing spinlock protection for send_eos_event() (Ziyi Guo) - media: chips-media: wave5: fix a potential memory leak in wave5_vdi_init() (Haoxiang Li) - media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich) - media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0 (Guoniu Zhou) - media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda) - HID: playstation: Clamp num_touch_reports (T.J. Mercier) - LTS version: v6.12.89 (Saeed Mirzamohammadi) - LTS version: v6.12.88 (Saeed Mirzamohammadi) - ksmbd: validate inherited ACE SID length (Shota Zaizen) - KVM: arm64: Wake-up from WFI when iqrchip is in userspace (Marc Zyngier) - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) - wifi: mt76: mt7925: fix incorrect TLV length in CLC command (Quan Zhou) - net: stmmac: Prevent NULL deref when RX memory exhausted (Sam Edwards) - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (Russell King (Oracle)) - net: stmmac: avoid shadowing global buf_sz (Russell King (Oracle)) - ALSA: aloop: Fix peer runtime UAF during format-change stop (Cássio Gabriel) - crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum) - printk: add print_hex_dump_devel() (Thorsten Blum) - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo) - erofs: tidy up z_erofs_lz4_handle_overlap() (Gao Xiang) - erofs: move {in,out}pages into struct z_erofs_decompress_req (Gao Xiang) - crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (Thorsten Blum) - hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan) - hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey) - mtd: spinand: winbond: Declare the QE bit on W25NxxJW (Miquel Raynal) - udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs(Luke Wang) - octeon_ep_vf: add NULL check for napi_build_skb() (David Carlier) - hwmon: (powerz) Avoid cacheline sharing for DMA buffer (Thomas Weißschuh) - dma-mapping: add __dma_from_device_group_begin()/end() (Michael S. Tsirkin) - dma-mapping: drop unneeded includes from dma-mapping.h (Christoph Hellwig) - fs: prepare for adding LSM blob to backing_file (Amir Goldstein) - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) - bpf: Fix use-after-free in arena_vm_close on fork (Alexei Starovoitov) - LoongArch: Use per-root-bridge PCIH flag to skip mem resource fixup (Huacai Chen) - LoongArch: KVM: Use kvm_set_pte() in kvm_flush_pte() (Tao Cui) - LoongArch: KVM: Move unconditional delay into timer clear scenery (Bibo Mao) - LoongArch: KVM: Fix HW timer interrupt lost when inject interrupt by software (Bibo Mao) - LoongArch: KVM: Fix "unreliable stack" for kvm_exc_entry (Xianglai Li) - LoongArch: KVM: Cap KVM_CAP_NR_VCPUS by KVM_CAP_MAX_VCPUS (Qiang Ma) - KVM: arm64: Fix initialisation order in __pkvm_init_finalise() (Quentin Perret) - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (David Woodhouse) - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() (Guangshuo Li) - f2fs: fix node_cnt race between extent node destroy and writeback (Yongpeng Yang) - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() (Yongpeng Yang) - f2fs: fix fiemap boundary handling when read extent cache is incomplete (Yongpeng Yang) - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() (Cen Zhang) - mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) - mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan) - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar) - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar) - mptcp: fastclose msk when linger time is 0 (Matthieu Baerts (NGI0)) - selftests: mptcp: pm: restrict 'unknown' check to pm_nl_ctl (Matthieu Baerts (NGI0)) -selftests: mptcp: check output: catch cmd errors (Matthieu Baerts (NGI0)) - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) - RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (Michael Bommarito) - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (Junrui Luo) - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) - RDMA/mana: Validate rx_hash_key_len (Jason Gunthorpe) - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (Jason Gunthorpe) - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (Jason Gunthorpe) - power: supply: max17042: avoid overflow when determining health (André Draszik) - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage (Lukas Wunner) - PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner) - PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue) - PCI: Update saved_config_space upon resource assignment (Lukas Wunner) - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock (SeongJae Park) - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (Paolo Bonzini) - smb: client: validate dacloffset before building DACL pointers (Michael Bommarito) - smb: client: use kzalloc to zero-initialize security descriptor buffer (Bjoern Doebel) - smb/client: fix out-of-bounds read in symlink_data() (Zisen Ye) - smb/client: fix out-of-bounds read in smb2_compound_op() (Zisen Ye) - s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik) - RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe) - pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) - nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni) -nvme-apple: drop invalid put of admin queue reference count (Fedor Pchelkin) - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) - libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) - lib/scatterlist: fix temp buffer in extract_user_to_sg() (Christian A. Ehrhardt) - lib/scatterlist: fix length calculations in extract_kvec_to_sg (Christian A. Ehrhardt) - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner) - iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update (Nicolin Chen) - isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) - isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) - dm-verity-fec: correctly reject too-small hash devices (Eric Biggers) - dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers) - eventfs: Hold eventfs_mutex and SRCU when remount walks events (David Carlier) - dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) - dm: don't report warning when doing deferred remove (Mikulas Patocka) - dm-thin: fix metadata refcount underflow (Mikulas Patocka) - btrfs: fix double free in create_space_info() error path (Guangshuo Li) - ASoC: qcom: q6apm: remove child devices when apm is removed (Srinivas Kandagatla) - ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens (Srinivas Kandagatla) - ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop (Srinivas Kandagatla) - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cássio Gabriel) - ASoC: fsl_easrc: fix comment typo (Joseph Salisbury) - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (Tommaso Soncin) - cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde) - clk: microchip: mpfs-ccc: fix out of bounds access during output registration (Conor Dooley) - clk: imx: imx8-acm: fix flags for acm clocks (Stefan Eichenberger) - spi: topcliff-pch: fix use-after-free on unbind(Johan Hovold) - spi: topcliff-pch: fix controller deregistration (Johan Hovold) - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum) - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum) - thermal: core: Free thermal zone ID later during removal (Rafael J. Wysocki) - udf: reject descriptors with oversized CRC length (Michael Bommarito) - spi: microchip-core-qspi: fix controller deregistration (Johan Hovold) - ice: fix double free in ice_sf_eth_activate() error path (Guangshuo Li) - ibmveth: Disable GSO for packets with small MSS (Mingming Cao) - hv_sock: fix ARM64 support (Hamza Mahfooz) - gpio: of: clear OF_POPULATED on hog nodes in remove path (Bartosz Golaszewski) - extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang) - cifs: change_conf needs to be called for session setup (Shyam Prasad N) - cifs: abort open_cached_dir if we don't request leases (Shyam Prasad N) - block: add pgmap check to biovec_phys_mergeable (Naman Jain) - af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) - hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak) - clk: rk808: fix OF node reference imbalance (Johan Hovold) - hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan) - hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan) - parisc: Fix IRQ leak in LASI driver (Hongling Zeng) - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (Pavitra Jha) - ip6_gre: Use cached t-> net in ip6erspan_changelink(). (Maoyi Xie) - net: libwx: fix VF illegal register access (Jiawen Wu) - sound: ua101: fix division by zero at probe (SeungJu Cheon) - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Zen) - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (Tudor Ambarus) - KVM: arm64: Fix kvm_vcpu_initialized() macro parameter (Fuad Tabba) - fanotify: fix false positive on permission events(Miklos Szeredi) - staging: vme_user: fix root device leak on init failure (Johan Hovold) - spi: s3c64xx: fix NULL-deref on driver unbind (Johan Hovold) - spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold) - spi: sun6i: fix controller deregistration (Johan Hovold) - spi: ti-qspi: fix controller deregistration (Johan Hovold) - spi: sun4i: fix controller deregistration (Johan Hovold) - spi: syncuacer: fix controller deregistration (Johan Hovold) - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (Luiz Augusto von Dentz) - Bluetooth: btmtk: validate WMT event SKB length before struct access (Tristan Madani) - Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito) - Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito) - LoongArch: KVM: Fix missing EMULATE_FAIL in kvm_emu_mmio_read() (Tao Cui) - selinux: prune /sys/fs/selinux/disable (Stephen Smalley) - selinux: shrink critical section in sel_write_load() (Stephen Smalley) - selinux: don't reserve xattr slot when we won't fill it (David Windsor) - xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) - xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li) - powerpc/kdump: fix KASAN sanitization flag for core_$(BITS).o (Sourabh Jain) - ALSA: firewire-tascam: Do not drop unread control events (Cássio Gabriel) - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (Takashi Iwai) - USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda) - USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen) - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cássio Gabriel) - ALSA: usb-audio: Avoidpotential endless loop in convert_chmap_v3() (Takashi Iwai) - ALSA: usb-audio: midi2: Restart output URBs on resume (Cássio Gabriel) - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) - wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) - wifi: mac80211: remove station if connection prep fails (Johannes Berg) - wifi: ath5k: do not access array OOB (Jiri Slaby (SUSE)) - wifi: mac80211: use safe list iteration in radar detect work (Benjamin Berg) - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) - wifi: mac80211: drop stray 'static' from fast-RX rx_result (Catherine) - wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work (Quan Zhou) - wifi: mt76: mt7921: fix a potential clc buffer length underflow (Leon Yen) - wifi: mt76: mt7925: fix incorrect length field in txpower command (Ming Yen Hsieh) - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr (Quan Zhou) - exit: prevent preemption of oopsing TASK_DEAD task (Jann Horn) - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim) - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) - KVM: SVM: check validity of VMCB controls when returning from SMM (Paolo Bonzini) - net: af_key: zero aligned sockaddr tail in PF_KEY exports (Zhengchuan Liang) - net: txgbe: fix RTNL assertion warning when remove module (Jiawen Wu) - flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) - x86/shstk: Prevent deadlock during shstk sigreturn (Rick Edgecombe) - x86: shadow stacks: proper error handling for mmap lock(Linus Torvalds) - mm: convert mm_lock_seq to a proper seqcount (Suren Baghdasaryan) - ksmbd: rewrite stop_sessions() with restartable iteration (DaeMyung Kang) - spi: rockchip: fix controller deregistration (Johan Hovold) - ASoC: SOF: Don't allow pointer operations on unconfigured streams (Mark Brown) - iommufd: Fix a race with concurrent allocation and unmap (Sina Hassani) - ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra) - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (Jan Schär) - ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li) - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta) - ipmi:si: Return state to normal if message allocation fails (Corey Minyard) - ipmi: Check event message buffer response for bad data (Corey Minyard) - ipmi: Add limits to event and receive message requests (Corey Minyard) - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [6.12.0-204.87.3] - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) - cifs: Fix busy dentry used after unmounting (Zhihao Cheng) - smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (Henrique Carvalho) - net/mlx5e: Trigger neighbor resolution for unresolved destinations (Jianbo Liu) - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init (Jianbo Liu) - x86/fgraph: Fix return_to_handler regs.rsp value (Jiri Olsa) - tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 (Feng Yang) - iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set (Lu Baolu) - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow (Ferry Meng) - arm64: Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL (Lukas Bulwahn) - riscv: fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (Pu Lehui) - riscv: fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends onHAVE_DYNAMIC_FTRACE_WITH_ARGS (Pu Lehui) - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS (Niklas Cassel) - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS (Niklas Cassel) - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT (Niklas Cassel) - ata: libata-scsi: improve readability of ata_scsi_qc_issue() (Niklas Cassel) - ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands (Igor Pylypiv) - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav) - arm64/scs: Fix potential sign extension issue of advance_loc4 (Wentao Guan) - net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() (Lorenzo Bianconi) - net: airoha: Implement BQL support (Lorenzo Bianconi) - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz) - drm/msm/dsi: fix hdisplay calculation for CMD mode panel (Pengyu Luo) - drm/msm/dsi: fix bits_per_pclk (Pengyu Luo) - drm/msm/dsi: add the missing parameter description (Pengyu Luo) - ALSA: core: Serialize deferred fasync state checks (Cássio Gabriel) - ALSA: misc: Use guard() for spin locks (Takashi Iwai) - drm/i915/psr: Init variable to avoid early exit from et alignment loop (Jouni Högander) - LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() (Wentao Guan) - gtp: disable BH before calling udp_tunnel_xmit_skb() (David Carlier) - openvswitch: vport: fix self-deadlock on release of tunnel ports (Ilya Maximets) {CVE-2026-46165} - LoongArch: Fix SYM_SIGFUNC_START definition for 32BIT (Huacai Chen) - iommu/amd: serialize sequence allocation under concurrent TLB invalidations (Ankit Soni) {CVE-2026-43220} - iommu/amd: Use atomic64_inc_return() in iommu.c (Uros Bizjak) - usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) {CVE-2026-46109} - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan) - scsi: target: iscsi: Validate CHAP_R length before base64 decode (AlexandruHossu) [Orabug: 39445550] - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39445550] - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (Michael Bommarito) [Orabug: 39445550] - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39445550] - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39445550] - arm64: io: Fix ioremap_encrypted() argument type (Vijay Kumar) [Orabug: 39387242] - uek-rpm/config-aarch64: Enable Vera firmware and memory attribute support (Vijay Kumar) [Orabug: 39387242] - NVIDIA: VR: SAUCE: arm64: Add workaround to convert MT_NORMAL_NC to Device-nGnRE (Shanker Donthineni) [Orabug: 39387242] - NVIDIA: VR: SAUCE: firmware: smccc: lfa: fix work item re-initialization race (Nirmoy Das) [Orabug: 39387242] - NVIDIA: VR: SAUCE: firmware: smccc: lfa: handle LFA_BUSY and improve SMC retry pacing (Vedashree Vidwans) [Orabug: 39387242] - NVIDIA: VR: CCA: SAUCE: arm_pmu: Provide a mechanism for disabling the physical IRQ (Steven Price) [Orabug: 39387242] - NVIDIA: VR: SAUCE: firmware: smccc: register as platform driver (Vedashree Vidwans) [Orabug: 39387242] - NVIDIA: VR: SAUCE: firmware: smccc: add timeout, touch wdt (Vedashree Vidwans) [Orabug: 39387242] - NVIDIA: VR: SAUCE: firmware: smccc: add support for Live Firmware Activation (LFA) (Salman Nabi) [Orabug: 39387242] - NVIDIA: VR: SAUCE: iommu/arm-smmu-v3: Allow ATS to be always on (Nicolin Chen) [Orabug: 39387242] - NVIDIA: VR: SAUCE: PCI: Allow ATS to be always on for non-CXL NVIDIA GPUs (Nicolin Chen) [Orabug: 39387242] - NVIDIA: VR: SAUCE: PCI: Allow ATS to be always on for CXL.cache capable devices (Nicolin Chen) [Orabug: 39387242] - NVIDIA: VR: SAUCE: soc/tegra: pmc: Add PMC support for Tegra410 (Kartik Rajput) [Orabug: 39387242] - soc/tegra: pmc: Add Tegra264 support (Thierry Reding) [Orabug: 39387242] - NVIDIA: VR: SAUCE: soc/tegra: misc: Use SMCCC toget chipid (Kartik Rajput) [Orabug: 39387242] - tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429137] - tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429137] - tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429137] - uek-rpm: disable kABI size checks in debug configs (Saeed Mirzamohammadi) [Orabug: 39442662] - smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463671] {CVE-2026-46243} [6.12.0-204.87.2] - Reapply "x86/kexec: add a sanity check on previous kernel's ima kexec buffer" (Harshit Mogalapalli) [Orabug: 39419018] - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368826,39441323] {CVE-2026-43503,CVE-2026-46300} - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368826] {CVE-2026-46300} - LTS version: v6.12.87 (Sherry Yang) - LTS version: v6.12.86 (Sherry Yang) - netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452464] {CVE-2026-46101} - net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452457] {CVE-2026-46099} - ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39452739] {CVE-2026-46048} - drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426003] {CVE-2026-43501} - ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai) - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai) [Orabug: 39452746] {CVE-2026-45992} - net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39205989] {CVE-2026-31419} - crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452231] {CVE-2026-46033} - mm: prevent droppable mappings from being locked (Anthony Yznaga) - spi: fix resource leaks ondevice setup failure (Johan Hovold) [Orabug: 39452400] {CVE-2026-46083} - net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452123] {CVE-2026-46003} - net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming) - net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452411] {CVE-2026-46086} - net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452207] {CVE-2026-46026} - net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam) [Orabug: 39410851] {CVE-2026-43491} - iio: frequency: admv1013: fix NULL pointer dereference on str (Antoniu Miclaus) - iio: frequency: admv1013: add dev variable (Antoniu Miclaus) - block: relax pgmap check in bio_add_page for compatible zone device pages (Naman Jain) - RDMA/mana_ib: Disable RX steering on RSS QP destroy (Long Li) [Orabug: 39452406] {CVE-2026-46084} - media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452432] {CVE-2026-46091} - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum) - media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum) - mm/zsmalloc: copy KMSAN metadata in zs_page_migrate() (Shigeru Yoshida) - ALSA: aoa: i2sbus: clear stale prepared state (Cássio Gabriel) - ALSA: aoa: Use guard() for mutex locks (Takashi Iwai) - mm: migrate: requeue destination folio on deferred split queue (Usama Arif) - mm/migrate: move movable_ops page handling out of move_to_new_folio() (David Hildenbrand) - mm/migrate: factor out movable_ops page handling into migrate_movable_ops_page() (David Hildenbrand) - wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452343] {CVE-2026-46069} - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (Sean Wang) - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (Sean Wang) - thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452186] {CVE-2026-46021} -ksmbd: reset rcount per connection in ksmbd_conn_wait_idle_sess_id() (Daemyung Kang) - ksmbd: replace connection list with hash table (Namjae Jeon) - ksmbd: use msleep instaed of schedule_timeout_interruptible() (Namjae Jeon) - f2fs: fix to do sanity check on dcc-> discard_cmd_cnt conditionally (Chao Yu) - lib: test_hmm: evict device pages on file close to avoid use-after-free (Alistair Popple) - f2fs: fix UAF caused by decrementing sbi-> nr_pages[] in f2fs_write_end_io() (Yongpeng Yang) - smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito) [Orabug: 39300611] {CVE-2026-31709} - seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer) - scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (Yang Xiuwei) [Orabug: 39452100] {CVE-2026-45997} - rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425998] {CVE-2026-43499} - ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner) - ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner) - ktest: Fix the month in the name of the failure directory (Steven Rostedt) - ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452291] {CVE-2026-46052} - dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452196] {CVE-2026-46023} - crypto: nx - Fix packed layout in struct nx842_crypto_header (Gustavo A R Silva) - crypto: atmel-sha204a - Fix uninitialized data access on OTP read error (Thorsten Blum) - crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path (Thorsten Blum) - crypto: atmel-sha204a - Fix error codes in OTP reads (Thorsten Blum) - crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum) - crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li) - crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier) - crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum) - crypto: atmel-aes - Fix 3-page memory leak inatmel_aes_buff_cleanup (Thorsten Blum) - crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers) - can: ucan: fix devres lifetime (Johan Hovold) - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (Qiang Yu) - Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452304] {CVE-2026-46056} - apparmor: use target task's context in apparmor_getprocattr() (Cengiz Can) - mfd: core: Preserve OF node when ACPI handle is present (Brian Mak) - taskstats: set version in TGID exit notifications (Yiyang Chen) - tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452159] {CVE-2026-46015} - wifi: rtl8xxxu: fix potential use of uninitialized value (Yi Cong) - x86/cpu: Disable FRED when PTI is forced on (Dave Hansen) - inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452250] {CVE-2026-46040} - HID: apple: ensure the keyboard backlight is off if suspending (Aditya Garg) - check-uapi: link into shared objects (Arnd Bergmann) - md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452349] {CVE-2026-46070} - md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452287] {CVE-2026-46051} - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (David (Ming Qiang) Wu) - mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S) - ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452269] {CVE-2026-46046} - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (Deepanshu Kartikey) [Orabug: 39452442] {CVE-2026-46094} - perf annotate: Use jump__delete when freeing LoongArch jumps (Rong Bao) - io_uring/poll: fix multishot recv missing EOF on wakeup race (Jens Axboe) {CVE-2026-23473} - KVM: nSVM: Always intercept VMMCALL when L2 is active (Sean Christopherson) - KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (KevinCheng) [Orabug: 39452372] {CVE-2026-46076} - KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed) - KVM: nSVM: Add missing consistency check for EFER, CR0, CR4, and CS (Yosry Ahmed) - KVM: nSVM: Clear tracking of L1-> L2 NMI and soft IRQ on nested #VMEXIT (Yosry Ahmed) - KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT (Yosry Ahmed) - KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed) - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed) - KVM: nSVM: Use vcpu-> arch.cr2 when updating vmcb12 on nested #VMEXIT (Yosry Ahmed) - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed) - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson) - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452394] {CVE-2026-46082} - KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452061] {CVE-2026-45987} - KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed) - KVM: x86: Defer non-architectural deliver of exception payload to userspace read (Sean Christopherson) - userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov) - mm/damon/core: use time_in_range_open() for damos quota window start (Seongjae Park) - rtc: ntxec: fix OF node reference imbalance (Johan Hovold) - tpm: tpm_tis: stop transmit if retries are exhausted (Jacqueline Wong) - tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong) - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (Gunnar Kudrjavets) - tpm: Fix auth session leak in tpm2_get_random() error path (Gunnar Kudrjavets) - pwm: imx-tpm: Count the number of enabled channels in probe (Viorel Suman) - crypto: talitos - rename first/last to first_desc/last_desc (Paul Louvel) - crypto: talitos - fix SEC1 32k ahash request limitation (Paul Louvel) -firmware: google: framebuffer: Do not unregister platform device (Thomas Zimmermann) - xfs: fix a resource leak in xfs_alloc_buftarg() (Haoxiang Li) [Orabug: 39452131] {CVE-2026-46005} - arm64: dts: ti: am62-verdin: Enable pullup for eMMC data pins (Francesco Dolcini) - mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin) - mmc: block: use single block write in retry (Bin Liu) - randomize_kstack: Maintain kstack_offset per task (Ryan Roberts) - hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data() (Sanman Pradhan) - power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski) - LoongArch: Show CPU vulnerabilites correctly (Huacai Chen) - tpm: avoid -Wunused-but-set-variable (Arnd Bergmann) - extract-cert: Wrap key_pass with '#ifdef USE_PKCS11_ENGINE' (Nathan Chancellor) - libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452201] {CVE-2026-46024} - ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452243] {CVE-2026-46037} - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452259] {CVE-2026-46043} - drm/arcpgu: fix device node leak (Luca Ceresoli) - net: ks8851: Avoid excess softirq scheduling (Marek Vasut) - netconsole: avoid out-of-bounds access on empty string in trim_newline() (Breno Leitao) - net: ks8851: Reinstate disabling of BHs around IRQ handler (Marek Vasut) - net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li) - net: txgbe: fix firmware version check (Jiawen Wu) - net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452246] {CVE-2026-46038} - arm64: dts: marvell: uDPU: add ethernet aliases (Robert Marko) - tools/accounting: handle truncated taskstats netlink messages (Yiyang Chen) - rxrpc: Fix rxkad crypto unalignment handling (David Howells) [Orabug: 39452728] {CVE-2026-46085} - rxrpc: Fix memory leaks in rxkad_verify_response() (David Howells) - iio: adc: ad7768-1: fix one-shot modedata acquisition (Jonathan Santos) - ALSA: pcmtest: Fix resource leaks in module init error paths (Cássio Gabriel) - ALSA: pcmtest: fix reference leak on failed device registration (Guangshuo Li) - ALSA: 6fire: Fix input volume change detection (Cássio Gabriel) - ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452126] {CVE-2026-46004} - ALSA: caiaq: Fix control_put() result and cache rollback (Cássio Gabriel) - ALSA: core: Fix potential data race at fasync handling (Takashi Iwai) - io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (Jens Axboe) - io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (David Lechner) - io_uring/timeout: check unused sqe fields (Pavel Begunkov) - block: fix zone write plugs refcount handling in disk_zone_wplug_schedule_bio_work() (Damien Le Moal) - rbd: fix null-ptr-deref when device_add_disk() fails (Dawei Feng) [Orabug: 39452385] {CVE-2026-46079} - selftests/landlock: Fix format warning for __u64 in net_test (Mickaël Salaün) - selftests/mqueue: Fix incorrectly named file (Simon Liebold) - sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury) - remoteproc: xlnx: Only access buffer information if IPI is buffered (Ben Levinsky) - parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller) - nvme: respect NVME_QUIRK_DISABLE_WRITE_ZEROES when wzsl is set (Robert Beckett) - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett) - mtd: docg3: fix use-after-free in docg3_release() (James Kim) - mfd: stpmic1: Attempt system shutdown twice in case PMIC is confused (Marek Vasut) - md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452284] {CVE-2026-46050} - jbd2: fix deadlock in jbd2_journal_cancel_revoke() (Zhang Yi) [Orabug: 39452318] {CVE-2026-46061} - erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang) [Orabug: 39452380]{CVE-2026-46078} - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cássio Gabriel) - ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452280] {CVE-2026-46049} - ALSA: aoa: i2sbus: fix OF node lifetime handling (Cássio Gabriel) - ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452119] {CVE-2026-46002} - net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452274] {CVE-2026-46047} - media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni) - lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law) - PCI: epf-mhi: Return 0, not remaining timeout, when eDMA ops complete (Daniel Hodges) - Revert "ALSA: usb: Increase volume range that triggers a warning" (Rongrong) - PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den) - crypto: atmel-sha204a - Fix OTP sysfs read and error handling (Thorsten Blum) - media: mtk-jpeg: fix use-after-free in release path due to uncancelled work (Fan Wu) - net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452468] {CVE-2026-46102} - net: caif: clear client service pointer on teardown (Zhengchuan Liang) - ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452416] {CVE-2026-46088} - media: amphion: Fix race between m2m job_abort and device_run (Ming Qian) - hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt (Sanman Pradhan) - of: unittest: fix use-after-free in testdrv_probe() (Xu Wang) - of: unittest: fix use-after-free in of_unittest_changeset() (Xu Wang) - crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410863] {CVE-2026-43493} - mm/memory_hotplug: fix hwpoisoned large folio handling in do_migrate_range() (Tu Jinjiang) - spi: ch341: fix memory leaks on probe failures (Johan Hovold) - spi: imx: fix use-after-free on unbind (Johan Hovold) - um: drivers: callkernel_strrchr() explicitly in cow_user.c (Michael Bommarito) - vfio/cdx: Fix NULL pointer dereference in interrupt trigger path (Prasanna Kumar T S M) - vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex (Alex Williamson) - wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452437] {CVE-2026-46092} - zram: do not forget to endio for partial discard requests (Sergey Senozhatsky) [Orabug: 39452420] {CVE-2026-46089} - ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452388] {CVE-2026-46080} - device property: Make modifications of fwnode "flags" thread safe (Douglas Anderson) - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (Jesse Zhang) [Orabug: 39167551] {CVE-2026-23468} - drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array (Tvrtko Ursulin) - rust: init: fix clippy::undocumented_unsafe_blocks warnings (Miguel Ojeda) - padata: Remove comment for reorder_work (Herbert Xu) - padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335055] {CVE-2025-38584} - arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual) - firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann) - kbuild: rust: allow clippy::uninlined_format_args (Miguel Ojeda) - drm/nouveau: fix nvkm_device leak on aperture removal failure (David Carlier) - ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu) - ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu) - misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu) - greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames() (Weigang He) - greybus: gb-beagleplay: bound bootloader receive buffering (Pengpeng Hou) - leds: qcom-lpg: Check for array overflow when selecting the high resolution (Greg Kroah-Hartman) - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452133] {CVE-2026-46006} - LoongArch:Add spectre boundry for syscall dispatch table (Greg Kroah-Hartman) - ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai) - usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (Xu Yang) - usb: chipidea: otg: not wait vbus drop if use role_switch (Xu Yang) - usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michał Pecio) - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cássio Gabriel) - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cássio Gabriel) - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cássio Gabriel) [Orabug: 39452170] {CVE-2026-46018} - LTS version: v6.12.85 (Sherry Yang) - Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305898] {CVE-2026-31786} - xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305908] {CVE-2026-31787} - LTS version: v6.12.84 (Sherry Yang) - rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento) [Orabug: 39300563] {CVE-2026-31696} - crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31697} - crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31698} - crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31699} - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) {CVE-2026-31700} - ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300586] {CVE-2026-31701} - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae) - f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() (George Saad) - ksmbd: use check_add_overflow() to prevent u16 DACL size overflow (Tristan Madani) - ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment (Tristan Madani) - ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() (Michael Bommarito) -ksmbd: validate response sizes in ipc_validate_msg() (Michael Bommarito) - smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito) [Orabug: 39300607] {CVE-2026-31708} - smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito) [Orabug: 39343707] {CVE-2026-43350} - smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang) - smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito) - ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito) - fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong) - fuse: Check for large folio with SPLICE_F_MOVE (Bernd Schubert) - fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300556] {CVE-2026-31694} - f2fs: fix to avoid memory leak in f2fs_rename() (Chao Yu) - fs/ntfs3: validate rec-> used in journal-replay file record check (Greg Kroah-Hartman) - scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor) - ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon) - mm/pagewalk: fix race between concurrent split and refault (Max Boone) [Orabug: 39250782] {CVE-2026-31456} - scripts: generate_rust_analyzer.py: define scripts (Tamir Duberstein) - drm/amdgpu: replace PASID IDR with XArray (Mikhail Gavrilov) - net: ethernet: mtk_eth_soc: initialize PPE per-tag-layer MTU registers (Daniel Golle) - rust: warn on bindgen < 0.69.5 and libclang > = 19.1 (Miguel Ojeda) - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167472] {CVE-2026-23444} - ima: do not copy measurement list to kdump kernel (Steven Chen) - ima: verify if the segment size has changed (Steven Chen) - PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den) - mm/userfaultfd: fix hugetlb fault mutex hash calculation (Jianhui Zhou) [Orabug: 39273453] {CVE-2026-31575} - LTS version: v6.12.83 (Sherry Yang) - ipv6: add NULL checks for idev in SRv6paths (Heminhong) [Orabug: 39167467] {CVE-2026-23442} - PCI: Fix placement of pci_save_state() in pci_bus_add_device() (Lukas Wunner) - rxrpc: Fix key quota calculation for multitoken keys (David Howells) - ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331090] {CVE-2026-43075} - ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331097] {CVE-2026-43076} - ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov) - media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park) - media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi) - nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey) - media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273467] {CVE-2026-31578} - bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273481] {CVE-2026-31580} - ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273486] {CVE-2026-31581} - hwmon: (powerz) Fix use-after-free on USB disconnect (Sanman Pradhan) - media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273493] {CVE-2026-31583} - media: mediatek: vcodec: fix use-after-free in encoder release path (Fan Wu) - media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev) - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273507] {CVE-2026-31586} - mm/kasan: fix double free for kasan pXds (Ritesh Harjani) - ASoC: qcom: q6apm: move component registration to unmanaged version (Srinivas Kandagatla) - KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273521] {CVE-2026-31588} - x86-64/arm64/powerpc: clean up and rename __copy_from_user_flushcache (Linus Torvalds) - x86: rename and clean up__copy_from_user_inatomic_nocache() (Linus Torvalds) - x86-64: rename misleadingly named '__copy_user_nocache()' function (Linus Torvalds) [Orabug: 39323162] {CVE-2026-43073} - checkpatch: add support for Assisted-by tag (Sasha Levin) - KVM: x86: Use __DECLARE_FLEX_ARRAY() for UAPI structures with VLAs (David Woodhouse) - KVM: Remove subtle "struct kvm_stats_desc" pseudo-overlay (Sean Christopherson) - kernel: be more careful about dup_mmap() failures and uprobe registering (Liam R. Howlett) {CVE-2025-21709} - net: sched: fix TCF_LAYER_TRANSPORT handling in tcf_get_base_ptr() (Eric Dumazet) - gpiolib: fix race condition for gdev-> srcu (Paweł Narewski) [Orabug: 38887677] {CVE-2026-22986} - gpiolib: unify two loops initializing GPIO descriptors (Bartosz Golaszewski) - KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273529] {CVE-2026-31590} - KVM: SEV: Disallow LAUNCH_FINISH if vCPUs are actively being created (Sean Christopherson) - KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (Sean Christopherson) [Orabug: 39273553] {CVE-2026-31593} - PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup (Koichiro Den) - ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273569] {CVE-2026-31596} - ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273578] {CVE-2026-31597} - ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273586] {CVE-2026-31598} - media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev) - dcache: Limit the minimal number of bucket to two (Zhihao Cheng) [Orabug: 39323133] {CVE-2026-43071} - ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273608] {CVE-2026-31602} - Docs/admin-guide/mm/damon/reclaim: warn commit_inputs vs param updates race (Seongjae Park) - USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda) - staging:sm750fb: fix division by zero in ps_to_hz() (Junrui Luo) - wifi: rtw88: fix device leak on probe failure (Johan Hovold) [Orabug: 39273620] {CVE-2026-31604} - scripts: generate_rust_analyzer.py: avoid FD leak (Tamir Duberstein) - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman) - usb: port: add delay after usb_hub_set_port_power() (Xu Yang) - usb: gadget: f_hid: don't call cdev_init while cdev in use (Michael Zimmermann) - USB: cdc-acm: Add quirks for Yoga Book 9 14IAH10 INGENIC touchscreen (Dave Carey) - usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brát) - usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273631] {CVE-2026-31607} - ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc (Greg Kroah-Hartman) - ksmbd: require 3 sub-authorities before reading sub_auth[2] (Greg Kroah-Hartman) - ksmbd: validate EaNameLength in smb2_get_ea() (Greg Kroah-Hartman) - smb: client: fix off-by-8 bounds check in check_wsl_eas() (Greg Kroah-Hartman) [Orabug: 39273654] {CVE-2026-31614} - usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman) - usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman) - usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman) - ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) - drm/vc4: platform_get_irq_byname() returns an int (Greg Kroah-Hartman) [Orabug: 39323149] {CVE-2026-43072} - NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman) - net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) - HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273696] {CVE-2026-31624} - HID: alps: fix NULL pointer dereference in alps_raw_event() (GregKroah-Hartman) [Orabug: 39273704] {CVE-2026-31625} - staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) - i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman) - can: raw: fix ro-> uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273446] {CVE-2026-31532} - nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian) - idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (Emil Tantilov) [Orabug: 39262348] {CVE-2026-31647} - ALSA: usb-audio: Improve Focusrite sample rate filtering (Geoffrey D. Bennett) - thermal: core: Address thermal zone removal races with resume (Rafael J. Wysocki) [Orabug: 39300675] {CVE-2026-31731} - thermal: core: Mark thermal zones as exiting before unregistration (Rafael J. Wysocki) - netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171449] {CVE-2026-31407} - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39331103] {CVE-2026-43077} - perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331114] {CVE-2026-43079} - crypto: af_alg - limit RX SG extraction by receive buffer budget (Douya Le) [Orabug: 39263372] {CVE-2026-31677} - gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda) - l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331124] {CVE-2026-43080} - net: ipa: fix event ring index not programmed for IPA v5.0+ (Alexander Koskovich) - net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (Alexander Koskovich) - af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263355] {CVE-2026-31673} - net: txgbe: leave space for null terminators on property_entry (Fabio Baltieri) - netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263405] {CVE-2026-31685} - netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263387] {CVE-2026-31681} -netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331144] {CVE-2026-43085} - ipvs: fix NULL deref in ip_vs_add_service error path (Weiming Shi) [Orabug: 39331151] {CVE-2026-43086} - selftests: net: bridge_vlan_mcast: wait for h1 before querier check (Daniel Golle) - xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331162] {CVE-2026-43089} - xfrm: fix refcount leak in xfrm_migrate_policy_find (Kotlyarov Mihail) [Orabug: 39331168] {CVE-2026-43090} - xfrm: Wait for RCU readers during policy netns exit (Steffen Klassert) [Orabug: 39331170] {CVE-2026-43091} - xsk: validate MTU against usable frame size on bind (Maciej Fijalkowski) [Orabug: 39331178] {CVE-2026-43092} - xsk: fix XDP_UMEM_SG_FLAG issues (Maciej Fijalkowski) - xsk: respect tailroom for ZC setups (Maciej Fijalkowski) - xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331180] {CVE-2026-43093} - e1000: check return value of e1000_read_eeprom (Agalakov Daniil) - ixgbevf: add missing negotiate_features op to Hyper-V ops table (Michal Schmidt) [Orabug: 39331185] {CVE-2026-43094} - tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou) - dt-bindings: net: Fix Tegra234 MGBE PTP clock (Jonathan Hunter) - net: stmmac: Fix PTP ref clock for Tegra234 (Jonathan Hunter) - nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou) - net: increase IP_TUNNEL_RECURSION_LIMIT to 5 (Chris J Arges) - ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331197] {CVE-2026-43099} - ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (Fernando Fernandez Mancera) [Orabug: 39257881] {CVE-2026-31531} - ipv4: nexthop: avoid duplicate NHA_HW_STATS_ENABLE on nexthop group dump (Fernando Fernandez Mancera) - net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet) - net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263400] {CVE-2026-31684} - eventpoll: defer struct eventpollfree to RCU grace period (Nicholas Carlini) [Orabug: 39331087] {CVE-2026-43074} - drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maíra Canal) - drm/vc4: Fix a memory leak in hang state error path (Maíra Canal) [Orabug: 39331211] {CVE-2026-43104} - drm/vc4: Fix memory leak of BO array in hang state (Maíra Canal) [Orabug: 39331215] {CVE-2026-43105} - drm/vc4: Release runtime PM reference after binding V3D (Maíra Canal) - xfrm: account XFRMA_IF_ID in aevent size calculation (Keenan Dong) [Orabug: 39331223] {CVE-2026-43107} - HID: amd_sfh: don't log error when device discovery fails with -EOPNOTSUPP (Maximilian Pezzullo) - PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li) - tools/power/turbostat: Fix microcode patch level output for AMD/Hygon (Serhii Pievniev) - soc: qcom: pd-mapper: Fix element length in servreg_loc_pfr_req_ei (Mukesh Ojha) - arm64: dts: imx93-tqma9352: improve eMMC pad configuration (Markus Niebel) - arm64: dts: imx93-9x9-qsb: change usdhc tuning step for eMMC and SD (Luke Wang) - arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak) - arm64: dts: qcom: hamoa/x1: fix idle exit latency (Daniel J Blueman) - soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai) - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta) - net: sfp: add quirks for Hisense and HSGQ GPON ONT SFP modules (John Pavlick) - wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331236] {CVE-2026-43110} - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband) - HID: roccat: fix use-after-free in roccat_report_event (Benoît Sevens) [Orabug: 39331243] {CVE-2026-43111} - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (Songxiebing) - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska) - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (Mario Limonciello) - pinctrl: intel: Fix the revision for new features(1kOhm PD, HW debouncer) (Andy Shevchenko) - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IMH9 (Alexander Savenko) - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (Gilson Marquato Júnior) - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover) [Orabug: 39331248] {CVE-2026-43112} - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby) - ALSA: hda/realtek: Add quirk for Samsung Book2 Pro 360 (NP950QED) (Takashi Iwai) - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto) - wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331253] {CVE-2026-43113} - ALSA: hda/realtek: add quirk for Framework F111:000F (Dustin L. Howett) - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) {CVE-2026-43114} - drm/amdgpu: Handle GPU page faults correctly on non-4K page systems (Donet Tom) - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (César Montoya) - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331279] {CVE-2026-43117} - platform/x86: asus-nb-wmi: add DMI quirk for ASUS ROG Flow Z13-KJP GZ302EAC (Matthew Schwartz) - can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li) - ASoC: SOF: topology: reject invalid vendor array size in token parser (Cássio Gabriel) - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (Zhang Heng) - Bluetooth: hci_sync: annotate data-races around hdev-> req_status (Cen Zhang) [Orabug: 39331291] {CVE-2026-43119} - ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann) - media: rkvdec: reduce stack usage in rkvdec_init_v4l2_vp9_count_tbl() (Arnd Bergmann) - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (Matthew Schwartz) - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (Andrii Kovalchuk) - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (Vee Satayamas) - RDMA/irdma: Fix double freerelated to rereg_user_mr (Jacob Moroni) [Orabug: 39331295] {CVE-2026-43120} - LTS version: v6.12.82 (Sherry Yang) - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt) - net: skb: fix cross-cache free of KFENCE-allocated skb head (Jiayuan Chen) [Orabug: 39238726] {CVE-2026-31429} - rxrpc: Fix missing error checks for rxkad encryption/decryption failure (David Howells) - rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING) (David Howells) - rxrpc: fix reference count leak in rxrpc_server_keyring() (Luxiao Xu) [Orabug: 39262320] {CVE-2026-31634} - rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu) - rxrpc: Only put the call ref if one was acquired (Douya Le) [Orabug: 39262331] {CVE-2026-31638} - rxrpc: Fix key reference count leak from call-> key (Anderson Nascimento) [Orabug: 39262333] {CVE-2026-31639} - rxrpc: Fix call removal to use RCU safe deletion (David Howells) [Orabug: 39262337] {CVE-2026-31642} - rxrpc: Fix anonymous key handling (David Howells) - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (David Carlier) - net: lan966x: fix page pool leak in error paths (David Carlier) - net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (David Carlier) - idpf: set the payload size before calling the async handler (Emil Tantilov) - idpf: improve locking around idpf_vc_xn_push_free() (Emil Tantilov) - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (Baolin Wang) [Orabug: 39262350] {CVE-2026-31648} - net: stmmac: fix integer underflow in chain mode (Tyllis Xu) [Orabug: 39262352] {CVE-2026-31649} - net: qualcomm: qca_uart: report the consumed byte on RX skb allocation failure (Pengpeng Hou) - mmc: vub300: fix NULL-deref on disconnect (Johan Hovold) [Orabug: 39262358] {CVE-2026-31651} - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (Jacky Bai) - net/mlx5: Update the list of the PCI supported devices (Michael Guralnik) - drm/i915/psr: Do not use pipe_src as borders for SU area (Jouni Högander) -drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (Sebastian Brzezinka) [Orabug: 39262370] {CVE-2026-31656} - batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262373] {CVE-2026-31657} - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (David Carlier) [Orabug: 39262377] {CVE-2026-31658} - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (M A Ramdhan) [Orabug: 39257890] {CVE-2026-31533} - EDAC/mc: Fix error path ordering in edac_mc_alloc() (Borislav Petkov) [Orabug: 39273747] {CVE-2026-31689} - X.509: Fix out-of-bounds access when parsing extensions (Lukas Wunner) [Orabug: 39238730] {CVE-2026-31430} - batman-adv: reject oversized global TT response buffers (Ruide Cao) [Orabug: 39262381] {CVE-2026-31659} - nfc: pn533: allocate rx skb before consuming bytes (Pengpeng Hou) - arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges (Shawn Guo) - arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity (Shawn Guo) - arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak) - Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower" (Sebastian Krzyszkowiak) - platform/x86/intel-uncore-freq: Handle autonomous UFS status bit (Srinivas Pandruvada) - wifi: brcmsmac: Fix dma_free_coherent() size (Thomas Fourier) [Orabug: 39262389] {CVE-2026-31661} - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (Oleh Konko) [Orabug: 39262393] {CVE-2026-31662} - xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262401] {CVE-2026-31664} - workqueue: Add pool_workqueue to pending_pwqs list when unplugging multiple inactive works (Matthew Brost) - netfilter: nft_ct: fix use-after-free in timeout object destroy (Tuan Do) [Orabug: 39262406] {CVE-2026-31665} - LoongArch: Handle percpu handler address for ORC unwinder (Tiezhu Yang) - LoongArch: Remove unnecessary checks for ORC unwinder (Tiezhu Yang) - net: annotate data-races around sk-> sk_{data_ready,write_space} (EricDumazet) [Orabug: 39130795] {CVE-2026-23302} - Revert "mptcp: add needs_id for netlink appending addr" (Matthieu Baerts) - sched_ext: Fix stale direct dispatch state in ddsp_dsq_id (Andrea Righi) [Orabug: 39300679] {CVE-2026-31733} - misc: fastrpc: check qcom_scm_assign_mem() return in rpmsg_probe (Xingjing Deng) - arm64: dts: renesas: white-hawk-cpu-common: Add pin control for DSI-eDP IRQ (Geert Uytterhoeven) - nfc: nci: complete pending data exchange on device close (Jakub Kicinski) - blktrace: fix __this_cpu_read/write in preemptible context (Chaitanya Kulkarni) [Orabug: 39131032] {CVE-2026-23374} - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (Robbie Ko) [Orabug: 39262410] {CVE-2026-31666} - btrfs: remove pointless out labels from extent-tree.c (Filipe Manana) - btrfs: remove unused flag EXTENT_BUFFER_CORRUPT (Daniel Vacek) - btrfs: remove unused flag EXTENT_BUFFER_READAHEAD (Daniel Vacek) - btrfs: split waiting from read_extent_buffer_pages(), drop parameter wait (David Sterba) - btrfs: remove unused define WAIT_PAGE_LOCK for extent io (David Sterba) - btrfs: make wait_on_extent_buffer_writeback() static inline (David Sterba) - ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() (Kuninori Morimoto) - MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki) - MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki) - MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki) - Input: uinput - take event lock when submitting FF request "event" (Dmitry Torokhov) - Input: uinput - fix circular locking dependency with ff-core (Mikhail Gavrilov) [Orabug: 39262412] {CVE-2026-31667} - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (Andrea Mayer) [Orabug: 39262416] {CVE-2026-31668} - mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen) [Orabug: 39262421] {CVE-2026-31669} - net: rfkill: prevent unlimited numbers of rfkill events from being created (GregKroah-Hartman) [Orabug: 39262424] {CVE-2026-31670} - xfrm_user: fix info leak in build_report() (Greg Kroah-Hartman) [Orabug: 39262428] {CVE-2026-31671} - wifi: rt2x00usb: fix devres lifetime (Johan Hovold) [Orabug: 39262432] {CVE-2026-31672} - usb: typec: ucsi: skip connector validation before init (Nathan Rebello) - lib/crypto: chacha: Zeroize permuted_state before it leaves scope (Eric Biggers) [Orabug: 39343666] {CVE-2026-43336} - LTS version: v6.12.81 (Sherry Yang) - selftests/bpf: test refining u32/s32 bounds when ranges cross min/max boundary (Eduard Zingerman) - bpf: Fix u32/s32 bounds when ranges cross min/max boundary (Eduard Zingerman) - bpf: Add third round of bounds deduction (Paul Chaignon) - selftests/bpf: Test invariants on JSLT crossing sign (Paul Chaignon) - selftests/bpf: Test cross-sign 64bits range refinement (Paul Chaignon) - bpf: Improve bounds when s64 crosses sign boundary (Paul Chaignon) - drm/amd/display: Correct logic check error for fastboot (Charlene Liu) - drm/amd: Disable ASPM on SI (Timur Kristóf) - drm/amd/display: Disable scaling on DCE6 for now (Timur Kristóf) - drm/amd/display: Adjust DCE 8-10 clock, don't overclock by 15% (Timur Kristóf) - drm/amd/display: Fix DCE 6.0 and 6.4 PLL programming. (Timur Kristóf) - drm/amd/display: Keep PLL0 running on DCE 6.0 and 6.4 (Timur Kristóf) - drm/amd/display: Disable fastboot on DCE 6 too (Timur Kristóf) - drm/amd/amdgpu: disable ASPM in some situations (Kenneth Feng) - drm/amd/amdgpu: decouple ASPM with pcie dpm (Kenneth Feng) - x86/CPU/AMD: Add additional fixed RDSEED microcode revisions (Mario Limonciello) - MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong) - s390/cpum_sf: Cap sampling rate to prevent lsctl exception (Thomas Richter) - s390/perf_cpum_sf: Convert to use try_cmpxchg128() (Heiko Carstens) - ext4: publish jinode after initialization (Li Chen) [Orabug: 39250748] {CVE-2026-31450} - drm/amd/pm: disable OD_FAN_CURVE if temp or pwm range invalid for smu v13 (Yang Wang) - mm/memory: fix PMD/PUDchecks in follow_pfnmap_start() (David Hildenbrand) - mm: replace READ_ONCE() with standard page table accessors (Anshuman Khandual) - mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (Tu Jinjiang) {CVE-2026-31466} - x86/fred: Fix early boot failures on SEV-ES/SNP guests (Nikunj A Dadhania) - scsi: target: tcm_loop: Drain commands in target_reset handler (Josef Bacik) [Orabug: 39300989] {CVE-2026-43054} - net: mana: fix use-after-free in add_adev() error path (Guangshuo Li) [Orabug: 39302308] {CVE-2026-43056} - net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (Willem de Bruijn) [Orabug: 39302311] {CVE-2026-43057} - spi: cadence-qspi: Fix exec_mem_op error handling (Emanuele Ghidoli) - wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free (Alexander Popov) - usb: gadget: f_uac1_legacy: validate control request size (Taegu Ha) - usb: gadget: f_hid: move list and spinlock inits from bind to alloc (Michael Zimmermann) - usb: gadget: f_rndis: Fix net_device lifecycle with device_move (Kuen-Han Tsai) - usb: gadget: f_subset: Fix net_device lifecycle with device_move (Kuen-Han Tsai) - usb: gadget: f_eem: Fix net_device lifecycle with device_move (Kuen-Han Tsai) - usb: gadget: f_ecm: Fix net_device lifecycle with device_move (Kuen-Han Tsai) - usb: gadget: f_rndis: Protect RNDIS options with mutex (Kuen-Han Tsai) - usb: gadget: f_subset: Fix unbalanced refcnt in geth_free (Kuen-Han Tsai) - usb: gadget: uvc: fix NULL pointer dereference during unbind race (Jimmy Hu) - usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (Kuen-Han Tsai) - usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop (Kuen-Han Tsai) - btrfs: do not free data reservation in fallback from inline due to -ENOSPC (Filipe Manana) [Orabug: 39103088] {CVE-2025-71269} - btrfs: fix the qgroup data free range for inline data extents (Qu Wenruo) - ice: Fix memory leak in ice_set_ringparam() (Zilin Guan) [Orabug: 39131082] {CVE-2026-23389} - usb: typec: ucsi: validate connector number inucsi_notify_common() (Nathan Rebello) [Orabug: 39300670] {CVE-2026-31729} - usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer (Sebastian Urban) - USB: dummy-hcd: Fix interrupt synchronization error (Alan Stern) - USB: dummy-hcd: Fix locking/synchronization error (Alan Stern) - thunderbolt: Fix property read in nhi_wake_supported() (Konrad Dybcio) - misc: fastrpc: possible double-free of cctx-> remote_heap (Xingjing Deng) - thermal: core: Fix thermal zone device registration error path (Rafael J. Wysocki) [Orabug: 39343655] {CVE-2026-43332} - gpio: mxc: map Both Edge pad wakeup to Rising Edge (Shenwei Wang) - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343644] {CVE-2026-43328} - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (Sven Eckelmann) - net: ftgmac100: fix ring allocation unwind on open failure (Yufan Chen) - vxlan: validate ND option lengths in vxlan_na_create (Ao Zhou) [Orabug: 39300689] {CVE-2026-31738} - crypto: tegra - Add missing CRYPTO_ALG_ASYNC (Eric Biggers) - counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev member (Cosmin Tanislav) - counter: rz-mtu3-cnt: prevent counter from being toggled multiple times (Cosmin Tanislav) - netfilter: ipset: drop logically empty buckets in mtype_del (Yifan Wu) [Orabug: 39205984] {CVE-2026-31418} - nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (Ivan Vera) - nvmem: imx: assign nvmem_cell_info::raw_len (Christian Eggers) - dt-bindings: connector: add pd-disable dependency (Xu Yang) - firmware: microchip: fail auto-update probe if no flash found (Conor Dooley) - comedi: me4000: Fix potential overrun of firmware buffer (Ian Abbott) - comedi: me_daq: Fix potential overrun of firmware buffer (Ian Abbott) - comedi: ni_atmio16d: Fix invalid clean-up after failed attach (Ian Abbott) - comedi: Reinit dev-> spinlock between attachments to low-level drivers (Ian Abbott) - comedi: dt2815: add hardware detection to prevent crash (DeepanshuKartikey) - cdc-acm: new quirk for EPSON HMD (Oliver Neukum) - bridge: br_nd_send: validate ND option lengths (Ao Zhou) [Orabug: 39300723] {CVE-2026-31752} - Revert "LoongArch/orc: Use RCU in all users of __module_address()." (Sasha Levin) - Revert "LoongArch: Remove unnecessary checks for ORC unwinder" (Sasha Levin) - Revert "LoongArch: Handle percpu handler address for ORC unwinder" (Sasha Levin) - usb: cdns3: gadget: fix state inconsistency on gadget init failure (Yongchao Wu) - usb: cdns3: gadget: fix NULL pointer dereference in ep_queue (Yongchao Wu) - usb: core: phy: avoid double use of 'usb3-phy' (Gabor Juhos) - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() (Juneho Choi) - usb: ehci-brcm: fix sleep during atomic (Justin Chen) - usb: usbtmc: Flush anchored URBs in usbtmc_release (Heitor Alves de Siqueira) [Orabug: 39300741] {CVE-2026-31758} - usb: ulpi: fix double free in ulpi_register_interface() error path (Guangshuo Li) [Orabug: 39300745] {CVE-2026-31759} - usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive (Miao Li) - iio: gyro: mpu3050: Fix out-of-sequence free_irq() (Ethan Tidmore) - iio: gyro: mpu3050: Move iio_device_register() to correct location (Ethan Tidmore) [Orabug: 39300750] {CVE-2026-31761} - iio: gyro: mpu3050: Fix irq resource leak (Ethan Tidmore) [Orabug: 39300755] {CVE-2026-31762} - iio: gyro: mpu3050: Fix incorrect free_irq() variable (Ethan Tidmore) [Orabug: 39300760] {CVE-2026-31763} - iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only (Francesco Lavra) - iio: imu: bmi160: Remove potential undefined behavior in bmi160_config_pin() (Josh Poimboeuf) - iio: light: vcnl4035: fix scan buffer on big-endian (David Lechner) - iio: dac: ad5770r: fix error return in ad5770r_read_raw() (Antoniu Miclaus) - iio: accel: adxl380: fix FIFO watermark bit 8 always written as 0 (Antoniu Miclaus) - iio: accel: fix ADXL355 temperature signature value (Valek Andrej) - iio: adc: aspeed: clear reference voltage bits before configuringvref (Billy Tsai) - Input: xpad - add support for Razer Wolverine V3 Pro (Zoltan Illes) - Input: xpad - add support for BETOP BTP-KP50B/C controller's wireless mode (Shengyu Qu) - Input: bcm5974 - recover from failed mode switch (Liam Mitchell) - Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table (Christoffer Sandberg) - Input: synaptics-rmi4 - fix a locking bug in an error path (Bart Van Assche) - USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam (Jp Hein) - USB: serial: option: add support for Rolling Wireless RW135R-GL (Wanquan Zhong) - USB: serial: io_edgeport: add support for Blackbox IC135A (Frej Drejhammar) - drm/amdgpu/pm: drop SMU driver if version not matched messages (Alex Deucher) - drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB (Donet Tom) [Orabug: 39300766] {CVE-2026-31765} - drm/i915/dp: Use crtc_state-> enhanced_framing properly on ivb/hsw CPU eDP (Ville Syrjälä) - drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (Ville Syrjälä) {CVE-2026-31767} - drm/ast: dp501: Fix initialization of SCU2C (Thomas Zimmermann) - iio: adc: ti-ads1119: Replace IRQF_ONESHOT with IRQF_NO_THREAD (Felix Gu) - iio: adc: ti-ads1119: Reinit completion before wait_for_completion_timeout() (Felix Gu) - iio: adc: ti-ads1119: Fix unbalanced pm reference count in ds1119_single_conversion() (Felix Gu) - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() (David Lechner) - iio: adc: ti-adc161s626: fix buffer read on big-endian (David Lechner) - drm/amdgpu: fix the idr allocation flags (Prike Liang) - mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler) - hwmon: (occ) Fix division by zero in occ_show_power_1() (Sanman Pradhan) - MIPS: Fix the GCC version check for __multi3' workaround (Maciej W. Rozycki) - MIPS: SiByte: Bring back cache initialisation (Maciej W. Rozycki) - ksmbd: fix OOB write in QUERY_INFO for compound requests (Asim Viladi Oglu Manizada) - Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (Hkbinbin)[Orabug: 39300788] {CVE-2026-31772} - Bluetooth: SMP: force responder MITM requirements before building the pairing response (Oleh Konko) [Orabug: 39343661] {CVE-2026-43334} - Bluetooth: SMP: derive legacy responder STK authentication from MITM state (Oleh Konko) [Orabug: 39300792] {CVE-2026-31773} - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (Junxi Qian) [Orabug: 39300796] {CVE-2026-31774} - ALSA: ctxfi: Fix missing SPDIFI1 index handling (Takashi Iwai) [Orabug: 39300799] {CVE-2026-31776} - ALSA: caiaq: fix stack out-of-bounds read in init_card (Berk Cem Goksel) [Orabug: 39300807] {CVE-2026-31778} - USB: serial: option: add MeiG Smart SRM825WN (Ernestas Kulik) - wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() (Alexey Velichayshiy) [Orabug: 39300811] {CVE-2026-31779} - wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation (Yasuaki Torimaru) - drm/ioc32: stop speculation on the drm_compat_ioctl path (Greg Kroah-Hartman) [Orabug: 39300819] {CVE-2026-31781} - riscv: kgdb: fix several debug register assignment bugs (Paul Walmsley) - sched/fair: Fix zero_vruntime tracking fix (Peter Zijlstra) - sched/fair: Use protect_slice() instead of direct comparison (Vincent Guittot) - mips: ralink: update CPU clock index (Shiji Yang) - hwmon: (occ) Fix missing newline in occ_show_extended() (Sanman Pradhan) - hwmon: (tps53679) Fix device ID comparison and printing in tps53676_identify() (Sanman Pradhan) - dt-bindings: gpio: fix microchip #interrupt-cells (Jamie Gibbons) - hwmon: (ltc4286) Add missing MODULE_IMPORT_NS("PMBUS") (Sanman Pradhan) - hwmon: (pxe1610) Check return value of page-select write in probe (Sanman Pradhan) - accel/qaic: Handle DBC deactivation if the owner went away (Youssef Samir) - iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one (David Lechner) - Revert "drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug" (Maarten Lankhorst) - bpf: reject direct access to nullable PTR_TO_BUF pointers (QiTang) [Orabug: 39343658] {CVE-2026-43333} - ipv6: avoid overflows in ip6_datagram_send_ctl() (Eric Dumazet) [Orabug: 39205970] {CVE-2026-31415} - net: hsr: fix VLAN add unwind on slave errors (Luka Gejak) - net/sched: cls_flow: fix NULL pointer dereference on shared blocks (Xiang Mei) [Orabug: 39206002] {CVE-2026-31422} - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (Xiang Mei) [Orabug: 39205998] {CVE-2026-31421} - net/x25: Fix overflow when accumulating packets (Martin Schiller) - net/x25: Fix potential double free of skb (Martin Schiller) - bnxt_en: Restore default stat ctxs for ULP when resource is available (Pavan Chebbi) - net/mlx5: Fix switchdev mode rollback in case of failure (Saeed Mahameed) [Orabug: 39300842] {CVE-2026-43012} - net/mlx5: Avoid "No data available" when FW version queries fail (Saeed Mahameed) - net/mlx5: lag: Check for LAG device before creating debugfs (Shay Drory) [Orabug: 39300845] {CVE-2026-43013} - net: macb: properly unregister fixed rate clocks (Fedor Pchelkin) [Orabug: 39300848] {CVE-2026-43014} - net: macb: fix clk handling on PCI glue driver removal (Fedor Pchelkin) [Orabug: 39300852] {CVE-2026-43015} - net/sched: sch_netem: fix out-of-bounds access in packet corruption (Yucheng Lu) [Orabug: 39263363] {CVE-2026-31675} - bpf: sockmap: Fix use-after-free of sk-> sk_socket in sk_psock_verdict_data_ready(). (Kuniyuki Iwashima) [Orabug: 39300856] {CVE-2026-43016} - Bluetooth: MGMT: validate mesh send advertising payload length (Keenan Dong) [Orabug: 39300859] {CVE-2026-43017} - Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt (Pauli Virtanen) [Orabug: 39300861] {CVE-2026-43018} - Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (Pauli Virtanen) [Orabug: 39300863] {CVE-2026-43019} - Bluetooth: MGMT: validate LTK enc_size on load (Keenan Dong) [Orabug: 39300865] {CVE-2026-43020} - Bluetooth: SCO: fix race conditions in sco_sock_connect() (Cen Zhang) [Orabug: 39300878] {CVE-2026-43023} - Bluetooth: hci_sync: call destroy inhci_cmd_sync_run if immediate (Pauli Virtanen) - netfilter: nf_tables: reject immediate NF_QUEUE verdict (Pablo Neira Ayuso) [Orabug: 39300880] {CVE-2026-43024} - netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (Pablo Neira Ayuso) [Orabug: 39206016] {CVE-2026-31424} - netfilter: ctnetlink: ignore explicit helper on new expectations (Pablo Neira Ayuso) [Orabug: 39300884] {CVE-2026-43025} - netfilter: nf_conntrack_expect: store netns and zone in expectation (Pablo Neira Ayuso) - netfilter: nf_conntrack_expect: use expect-> helper (Pablo Neira Ayuso) [Orabug: 39205964] {CVE-2026-31414} - netfilter: nf_conntrack_expect: honor expectation helper field (Pablo Neira Ayuso) - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (Qi Tang) [Orabug: 39300888] {CVE-2026-43026} - netfilter: nf_conntrack_helper: pass helper to expect cleanup (Qi Tang) [Orabug: 39300892] {CVE-2026-43027} - netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr (Florian Westphal) - netfilter: x_tables: ensure names are nul-terminated (Florian Westphal) [Orabug: 39300896] {CVE-2026-43028} - netfilter: nfnetlink_log: account for netlink header size (Florian Westphal) [Orabug: 39205975] {CVE-2026-31416} - netfilter: flowtable: strictly check for maximum number of actions (Pablo Neira Ayuso) [Orabug: 39343648] {CVE-2026-43329} - net: ipv6: flowlabel: defer exclusive option free until RCU teardown (Zhengchuan Liang) [Orabug: 39263383] {CVE-2026-31680} - bpf: Fix regsafe() for pointers to packet (Alexei Starovoitov) [Orabug: 39300902] {CVE-2026-43030} - net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec (Suraj Gupta) - NFC: pn533: bound the UART receive buffer (Pengpeng Hou) - net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (Yochai Eisenrich) [Orabug: 39300916] {CVE-2026-43035} - net: use skb_header_pointer() for TCPv4 GSO frag_off check (Guoyu Su) [Orabug: 39300920] {CVE-2026-43036} - net: introduce mangleid_features(Paolo Abeni) - net: airoha: Add missing cleanup bits in airoha_qdma_cleanup_rx_queue() (Lorenzo Bianconi) - ipv6: prevent possible UaF in addrconf_permanent_addr() (Paolo Abeni) [Orabug: 39343676] {CVE-2026-43339} - ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add rollback on failure (Jihed Chaibi) - net: enetc: check whether the RSS algorithm is Toeplitz (Wei Fang) - net: sfp: Fix Ubiquiti U-Fiber Instant SFP module on mvneta (Marek Behún) - net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (Xiang Mei) [Orabug: 39206010] {CVE-2026-31423} - bridge: br_nd_send: linearize skb before parsing ND options (Ao Zhou) [Orabug: 39263392] {CVE-2026-31682} - eth: fbnic: Account for page fragments when updating BDQ tail (Dimitri Daskalakis) - ip6_tunnel: clear skb2-> cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300924] {CVE-2026-43037} - ipv6: icmp: clear skb2-> cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300928] {CVE-2026-43038} - tg3: Fix race for querying speed/duplex (Thomas Bogendoerfer) - net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343684] {CVE-2026-43341} - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (Yochai Eisenrich) [Orabug: 39300933] {CVE-2026-43040} - net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak (Jiayuan Chen) [Orabug: 39300937] {CVE-2026-43041} - net: fec: fix the PTP periodic output sysfs interface (Csaba Buday) - crypto: af-alg - fix NULL pointer dereference in scatterwalk (Norbert Szetei) [Orabug: 39300945] {CVE-2026-43043} - crypto: caam - fix overflow on long hmac keys (Horia Geantă) - crypto: caam - fix DMA corruption on long hmac keys (Horia Geantă) - wifi: ath11k: Pass the correct value of each TID during a stop AMPDU session (Reshma Immaculate Rajkumar) - dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix common property warning (Frank Li) - spi: geni-qcom: Check DMA interrupts early in ISR (Praveen Talari) - btrfs:reject root items with drop_progress and zero drop_level (Zhengyuan Huang) [Orabug: 39300957] {CVE-2026-43046} - i2c: tegra: Don't mark devices with pins as IRQ safe (Mikko Perttunen) - btrfs: reserve enough transaction items for qgroup ioctls (Filipe Manana) [Orabug: 39343672] {CVE-2026-43338} - HID: multitouch: Check to ensure report responses match the request (Lee Jones) [Orabug: 39300961] {CVE-2026-43047} - HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (Lee Jones) [Orabug: 39300969] {CVE-2026-43049} - objtool: Fix Clang jump table detection (Josh Poimboeuf) - tg3: replace placeholder MAC address with device property (Paul Sage) - btrfs: don't take device_list_mutex when querying zone info (Johannes Thumshirn) - atm: lec: fix use-after-free in sock_def_readable() (Deepanshu Kartikey) [Orabug: 39300973] {CVE-2026-43050} - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (Benoît Sevens) [Orabug: 39300977] {CVE-2026-43051} - wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300981] {CVE-2026-43052} - HID: logitech-hidpp: Enable MX Master 4 over bluetooth (Adrian Freund) - arm64/scs: Fix handling of advance_loc4 (Pepper Gray) - io_uring/kbuf: propagate BUF_MORE through early buffer commit path (Jens Axboe) - io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (Jens Axboe) - io_uring/kbuf: use WRITE_ONCE() for userspace-shared buffer ring fields (Joanne Koong) - io_uring/kbuf: use READ_ONCE() for userspace-mapped memory (Caleb Sander) - io_uring/kbuf: always use READ_ONCE() to read ring provided buffer lengths (Jens Axboe) [Orabug: 38440272] {CVE-2025-39816} - io_uring/kbuf: enable bundles for incrementally consumed buffers (Jens Axboe) - io_uring/rw: check for NULL io_br_sel when putting a buffer (Jens Axboe) - io_uring/net: correct type for min_not_zero() cast (Jens Axboe) - io_uring: remove async/poll related provided buffer recycles (Jens Axboe) - io_uring/kbuf: switch to storing struct io_buffer_list locally(Jens Axboe) - io_uring/net: use struct io_br_sel-> val as the send finish value (Jens Axboe) - io_uring/net: use struct io_br_sel-> val as the recv finish value (Jens Axboe) - io_uring/kbuf: use struct io_br_sel for multiple buffers picking (Jens Axboe) - io_uring/kbuf: introduce struct io_br_sel (Jens Axboe) - io_uring/kbuf: pass in struct io_buffer_list to commit/recycle helpers (Jens Axboe) - io_uring/net: clarify io_recv_buf_select() return value (Jens Axboe) - io_uring/net: don't use io_net_kbuf_recyle() for non-provided cases (Jens Axboe) - io_uring/kbuf: drop 'issue_flags' from io_put_kbuf(s)() arguments (Jens Axboe) - io_uring/kbuf: uninline __io_put_kbufs (Pavel Begunkov) - io_uring/kbuf: introduce io_kbuf_drop_legacy() (Pavel Begunkov) - io_uring/kbuf: open code __io_put_kbuf() (Pavel Begunkov) - io_uring/kbuf: remove legacy kbuf caching (Pavel Begunkov) - io_uring/kbuf: simplify __io_put_kbuf (Pavel Begunkov) - io_uring/kbuf: remove legacy kbuf kmem cache (Pavel Begunkov) - io_uring/kbuf: remove legacy kbuf bulk allocation (Pavel Begunkov) - LTS version: v6.12.80 (Sherry Yang) - idpf: nullify pointers after they are freed (Li Li) - net: bcmasp: Fix network filter wake for asp-3.0 (Justin Chen) - net: bcmasp: Restore programming of TX map vector register (Florian Fainelli) - dmaengine: idxd: Fix leaking event log memory (Vinicius Costa Gomes) [Orabug: 39250715] {CVE-2026-31440} - futex: Require sys_futex_requeue() to have identical flags (Peter Zijlstra) [Orabug: 39262271] {CVE-2026-31554} - xen/privcmd: unregister xenstore notifier on module exit (Guohan Zhao) - btrfs: fix lost error when running device stats on multiple devices fs (Filipe Manana) - btrfs: fix leak of kobject name for sub-group space_info (Shin'Ichiro Kawasaki) [Orabug: 39250698] {CVE-2026-31434} - btrfs: fix super block offset in error message in btrfs_validate_super() (Mark Harmstone) - dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA (Tomi Valkeinen) - dmaengine: xilinx: xilinx_dma: Fix unmasked residuesubtraction (Marek Vasut) - dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA (Marek Vasut) - dmaengine: xilinx: xilinx_dma: Fix dma_device directions (Marek Vasut) - dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() (Tuo Li) [Orabug: 39250704] {CVE-2026-31436} - netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (Deepanshu Kartikey) [Orabug: 39250710] {CVE-2026-31438} - dmaengine: xilinx: xdma: Fix regmap init error handling (Alexander Stein) - dmaengine: dw-edma: Fix multiple times setting of the CYCLE_STATE and CYCLE_BIT bits for HDMA. (Luo Haowen) - phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types() (Felix Gu) - dmaengine: idxd: Fix freeing the allocated ida too late (Vinicius Costa Gomes) - dmaengine: idxd: Fix memory leak when a wq is reset (Vinicius Costa Gomes) [Orabug: 39250719] {CVE-2026-31441} - dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323059] {CVE-2026-43064} - ASoC: ak4458: Convert to RUNTIME_PM_OPS() & co (Takashi Iwai) - idpf: Fix RSS LUT NULL ptr issue after soft reset (Sreedevi Joshi) [Orabug: 38887699] {CVE-2026-22993} - idpf: Fix RSS LUT NULL pointer crash on early ethtool operations (Sreedevi Joshi) [Orabug: 38887675] {CVE-2026-22985} - idpf: detach and close netdevs while handling a reset (Emil Tantilov) [Orabug: 38887666] {CVE-2026-22981} - idpf: check error for register_netdev() on init (Emil Tantilov) [Orabug: 37844511] {CVE-2025-22116} - ice: Fix PTP NULL pointer dereference during VSI rebuild (Aaron Ma) [Orabug: 38970514] {CVE-2026-23210} - landlock: Fix handling of disconnected directories (Mickaël Salaün) [Orabug: 38798915] {CVE-2025-68736} - landlock: Optimize file path walks and prepare for audit support (Mickaël Salaün) - net: add proper RCU protection to /proc/net/ptype (Eric Dumazet) [Orabug: 39103146] {CVE-2026-23255} - virt: tdx-guest: Fix handling of host controlled 'quote' buffer length (Zubin Mithra) [Orabug: 39250829]{CVE-2026-31470} - xfs: avoid dereferencing log items after push callbacks (Yuto Ohnuki) [Orabug: 39250765] {CVE-2026-31453} - ovl: make fsync after metadata copy-up opt-in mount option (Fei Lv) - ovl: Use str_on_off() helper in ovl_show_options() (Thorsten Blum) - rust: pin-init: internal: init: document load-bearing fact of field accessors (Benno Lossin) - rust: pin-init: add references to previously initialized fields (Benno Lossin) - mm/damon/sysfs: check contexts-> nr before accessing contexts_arr[0] (Josh Law) [Orabug: 39250786] {CVE-2026-31458} - media: nxp: imx8-isi: Fix streaming cleanup on release (Richard Leitner) - LoongArch: vDSO: Emit GNU_EH_FRAME correctly (Xi Ruoyao) - drm/xe: always keep track of remap prev/next (Matthew Auld) [Orabug: 39250860] {CVE-2026-31479} - tracing: Fix potential deadlock in cpu hotplug with osnoise (Luo Haiyang) [Orabug: 39250862] {CVE-2026-31480} - tracing: Switch trace_osnoise.c code over to use guard() and __free() (Steven Rostedt) - ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() (Werner Kasselman) - powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini) - arm64: dts: imx8mn-tqma8mqnl: fix LDO5 power off (Markus Niebel) - ext4: always drain queued discard work in ext4_mb_release() (Theodore Ts'O) [Orabug: 39323070] {CVE-2026-43065} - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (Baokun Li) [Orabug: 39323077] {CVE-2026-43066} - ext4: handle wraparound when searching for blocks for indirect mapped blocks (Theodore Ts'O) - ext4: fix the might_sleep() warnings in kvfree() (Zqiang) - ext4: fix use-after-free in update_super_work when racing with umount (Jiayuan Chen) [Orabug: 39250726] {CVE-2026-31446} - ext4: reject mount if bigalloc with s_first_data_block != 0 (Helen Koike) [Orabug: 39250729] {CVE-2026-31447} - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (Ye Bin) [Orabug: 39323085] {CVE-2026-43068} - ext4: avoid infinite loops caused by residual data (Edward Adam Davis) [Orabug:39250734] {CVE-2026-31448} - ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250743] {CVE-2026-31449} - ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio (Yuto Ohnuki) [Orabug: 39250756] {CVE-2026-31451} - ext4: make recently_deleted() properly work with lazy itable initialization (Jan Kara) - ext4: fix fsync(2) for nojournal mode (Jan Kara) - ext4: fix stale xarray tags after writeback (Jan Kara) - ext4: convert inline data to extents when truncate exceeds inline size (Deepanshu Kartikey) [Orabug: 39250761] {CVE-2026-31452} - ext4: fix journal credit check when setting fscrypt context (Simon Weber) - xfs: remove file_path tracepoint data (Darrick J. Wong) - xfs: don't irele after failing to iget in xfs_attri_recover_work (Darrick J. Wong) {CVE-2026-43063} - xfs: fix ri_total validation in xlog_recover_attri_commit_pass2 (Long Li) - xfs: scrub: unlock dquot before early return in quota scrub (Hongao) [Orabug: 39262277] {CVE-2026-31556} - xfs: save ailp before dropping the AIL lock in push callbacks (Yuto Ohnuki) [Orabug: 39250774] {CVE-2026-31454} - xfs: stop reclaim before pushing AIL during unmount (Yuto Ohnuki) [Orabug: 39250777] {CVE-2026-31455} - LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust (Huacai Chen) - LoongArch: Workaround LS2K/LS7A GPU DMA hang bug (Huacai Chen) - LoongArch: Fix missing NULL checks for kstrdup() (Lijun) - drm/i915/dp_tunnel: Fix error handling when clearing stream BW in atomic state (Imre Deak) - drm/amdgpu: prevent immediate PASID reuse case (Eric Huang) [Orabug: 39250796] {CVE-2026-31462} - dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock (Claudiu Beznea) - dmaengine: sh: rz-dmac: Protect the driver specific lists (Claudiu Beznea) - dmaengine: fsl-edma: fix channel parameter config for fixed channel requests (Joy Zou) - futex: Clear stale exiting pointer in futex_lock_pi() retry path (Davidlohr Bueso) [Orabug: 39262273] {CVE-2026-31555} - irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment(Jassi Brar) - jbd2: gracefully abort on checkpointing state corruptions (Milos Nikic) - net: macb: Use dev_consume_skb_any() to free TX SKBs (Kevin Hao) [Orabug: 39262293] {CVE-2026-31563} - net: macb: Protect access to net_device::ip_ptr with RCU lock (Kevin Hao) - net: macb: Move devm_{free,request}_irq() out of spin lock area (Kevin Hao) - scsi: ses: Handle positive SCSI error from ses_recv_diag() (Greg Kroah-Hartman) - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (Tyllis Xu) - ovl: fix wrong detection of 32bit inode numbers (Amir Goldstein) - phy: qcom: qmp-ufs: Fix SM8650 PCS table for Gear 4 (Abel Vesa) - x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask (Borislav Petkov) [Orabug: 39262289] {CVE-2026-31561} - x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling() (Nikunj A Dadhania) - alarmtimer: Fix argument order in alarm_timer_forward() (Zhan Xusheng) - erofs: add GFP_NOIO in the bio completion if needed (Jiucheng Xu) [Orabug: 39250817] {CVE-2026-31467} - virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (Xietangxin) [Orabug: 39250824] {CVE-2026-31469} - media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (Yuchan Nam) [Orabug: 39250836] {CVE-2026-31473} - hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible() (Sanman Pradhan) - hwmon: (peci/cputemp) Fix crit_hyst returning delta instead of absolute temperature (Sanman Pradhan) - hwmon: (pmbus/isl68137) Add mutex protection for AVS enable sysfs attributes (Sanman Pradhan) - KVM: arm64: Discard PC update state on vcpu reset (Marc Zyngier) - platform/x86: ISST: Correct locked bit width (Srinivas Pandruvada) - cpufreq: conservative: Reset requested_freq on limits change (Viresh Kumar) - can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (Oliver Hartkopp) [Orabug: 39250840] {CVE-2026-31474} - can: gw: fix OOB heap access in cgw_csum_crc8_rel() (Ali Norouzi) [Orabug: 39262306] {CVE-2026-31570} - ALSA: firewire-lib: fix uninitialized local variable (AlexeyNepomnyashih) - ksmbd: do not expire session on binding failure (Hyunwoo Kim) - ksmbd: fix memory leaks and NULL deref in smb2_lock() (Werner Kasselman) - ksmbd: fix potencial OOB in get_file_all_info() for compound requests (Namjae Jeon) - ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() (Namjae Jeon) - s390/entry: Scrub r12 register on kernel entry (Vasily Gorbik) - s390/barrier: Make array_index_mask_nospec() __always_inline (Vasily Gorbik) - s390/syscalls: Add spectre boundary for syscall dispatch table (Greg Kroah-Hartman) - spi: spi-fsl-lpspi: fix teardown order issue (UAF) (Marc Kleine-Budde) - ASoC: adau1372: Fix clock leak on PLL lock failure (Jihed Chaibi) - ASoC: adau1372: Fix unchecked clk_prepare_enable() return value (Jihed Chaibi) - sysctl: fix uninitialized variable in proc_do_large_bitmap (Marc Buerg) - hwmon: (pmbus) Introduce the concept of "write-only" attributes (Guenter Roeck) - hwmon: (pmbus) Mark lowest/average/highest/rated attributes as read-only (Guenter Roeck) - hwmon: (pmbus/core) Fix various coding style issues (Guenter Roeck) - hwmon: (adm1177) fix sysfs ABI violation and current unit conversion (Sanman Pradhan) - drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (Srinivasan Shanmugam) [Orabug: 39262299] {CVE-2026-31566} - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() (Weiming Shi) [Orabug: 39206026] {CVE-2026-31426} - spi: use generic driver_override infrastructure (Danilo Krummrich) [Orabug: 39250884] {CVE-2026-31487} - spi: Group CS related fields in struct spi_device (Andy Shevchenko) - drm/amd/display: Do not skip unrelated mode changes in DSC validation (Yussuf Khalil) [Orabug: 39250888] {CVE-2026-31488} - spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250890] {CVE-2026-31489} - ASoC: Intel: catpt: Fix the device initialization (Cezary Rojewski) - spi: sn-f-ospi: Fix resource leak in f_ospi_probe() (Felix Gu) - PM: hibernate: Drain trailing zero pages on userspace restore (AlbertoGarcia) - drm/i915/gmbus: fix spurious timeout on 512-byte burst reads (Samasth Norway Ananda) - x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size (Mike Rapoport) - scsi: scsi_transport_sas: Fix the maximum channel scanning issue (Yihang Li) - RDMA/irdma: Return EINVAL for invalid arp index error (Tatyana Nikolova) - RDMA/irdma: Fix deadlock during netdev reset with active connections (Anil Samal) [Orabug: 39262296] {CVE-2026-31565} - RDMA/irdma: Remove reset check from irdma_modify_qp_to_err() (Tatyana Nikolova) - RDMA/irdma: Clean up unnecessary dereference of event-> cm_node (Ivan Barrera) - RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce() (Tatyana Nikolova) - RDMA/irdma: Update ibqp state to error if QP is already in error state (Tatyana Nikolova) - RDMA/irdma: Initialize free_qp completion before using it (Jacob Moroni) [Orabug: 39250897] {CVE-2026-31492} - RDMA/rw: Fall back to direct SGE on MR pool exhaustion (Chuck Lever) - ALSA: hda/realtek: Sequence GPIO2 on Star Labs StarFighter (Sean Rhodes) - regmap: Synchronize cache for the page selector (Andy Shevchenko) - net: macb: use the current queue number for stats (Paolo Valerio) [Orabug: 39250905] {CVE-2026-31494} - netfilter: ctnetlink: use netlink policy range checks (David Carlier) [Orabug: 39250911] {CVE-2026-31495} - netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (Weiming Shi) [Orabug: 39206029] {CVE-2026-31427} - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (Pablo Neira Ayuso) [Orabug: 39250915] {CVE-2026-31496} - netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (Ao Zhou) [Orabug: 39263359] {CVE-2026-31674} - netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (Weiming Shi) [Orabug: 39206033] {CVE-2026-31428} - tls: Purge async_hold in tls_decrypt_async_wait() (Chuck Lever) [Orabug: 39164144] {CVE-2026-23414} - Bluetooth: btusb: clamp SCO altsetting table indices (Pengpeng Hou) [Orabug: 39250921] {CVE-2026-31497} -Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (Hyunwoo Kim) [Orabug: 39250925] {CVE-2026-31498} - Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (Cen Zhang) [Orabug: 39250931] {CVE-2026-31500} - Bluetooth: L2CAP: Fix send LE flow credits in ACL link (Zhang Chen) - dma-mapping: add missing inline for dma_free_attrs (Miguel Ojeda) - net: lan743x: fix duplex configuration in mac_link_up (Thangaraj Samynathan) - net: enetc: fix the output issue of 'ethtool --show-ring' (Wei Fang) - udp: Fix wildcard bind conflict check when using hash2 (Martin Kafai Lau) [Orabug: 39250946] {CVE-2026-31503} - tcp: optimize inet_use_bhash2_on_bind() (Eric Dumazet) - net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250951] {CVE-2026-31504} - ipv6: Don't remove permanent routes with exceptions from tb6_gc_hlist. (Kuniyuki Iwashima) - ipv6: Remove permanent routes from tb6_gc_hlist when all exceptions expire. (Kuniyuki Iwashima) - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (Kohei Enju) [Orabug: 39250955] {CVE-2026-31505} - ice: use ice_update_eth_stats() for representor stats (Petr Oros) - ice: fix inverted ready check for VF representors (Petr Oros) - platform/x86: intel-hid: disable wakeup_mode during hibernation (David Mcfarland) - platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen (Alok Tiwari) - net: bcmasp: fix double disable of clk (Justin Chen) - net: bcmasp: Add support for asp-v3.0 (Justin Chen) - net: bcmasp: fix double free of WoL irq (Justin Chen) [Orabug: 39250960] {CVE-2026-31506} - net: bcmasp: streamline early exit in probe (Justin Chen) - net: bcmasp: Remove support for asp-v2.0 (Justin Chen) - net: bcm: asp2: convert to phylib managed EEE (Russell King) - net: bcm: asp2: remove tx_lpi_enabled (Russell King) - net: bcm: asp2: fix LPI timer handling (Russell King) - rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size (Sabrina Dubroca) - net/smc: fix double-free of smc_spd_priv when tee() duplicatessplice pipe buffer (Qi Tang) - openvswitch: validate MPLS set/set_masked payload length (Ao Zhou) [Orabug: 39263380] {CVE-2026-31679} - openvswitch: defer tunnel netdev_put to RCU release (Ao Zhou) [Orabug: 39263376] {CVE-2026-31678} - net: openvswitch: Avoid releasing netdev before teardown completes (Toke Høiland-Jørgensen) [Orabug: 39251167] {CVE-2026-31508} - nfc: nci: fix circular locking dependency in nci_close_device (Jakub Kicinski) - ionic: fix persistent MAC address override on PF (Mohammad Heib) - pinctrl: mediatek: common: Fix probe failure for devices without EINT (Luca Leonardo Scorcia) - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb (Helen Koike) [Orabug: 39250972] {CVE-2026-31510} - Bluetooth: hci_ll: Fix firmware leak on error path (Anas Iqbal) [Orabug: 39323106] {CVE-2026-43069} - Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete (Luiz Augusto von Dentz) [Orabug: 39250978] {CVE-2026-31511} - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (Hyunwoo Kim) [Orabug: 39171453] {CVE-2026-31408} - Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (Hyunwoo Kim) [Orabug: 39250981] {CVE-2026-31512} - can: statistics: add missing atomic access in hot path (Oliver Hartkopp) - dma: swiotlb: add KMSAN annotations to swiotlb_bounce() (Shigeru Yoshida) - af_key: validate families in pfkey_send_migrate() (Eric Dumazet) [Orabug: 39250996] {CVE-2026-31515} - xfrm: prevent policy_hthresh.work from racing with netns teardown (Minwoo Ra) [Orabug: 39251000] {CVE-2026-31516} - xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (Hyunwoo Kim) [Orabug: 39171446] {CVE-2026-31406} - esp: fix skb leak with espintcp and async crypto (Sabrina Dubroca) [Orabug: 39251008] {CVE-2026-31518} - xfrm: Fix the usage of skb-> sk (Steffen Klassert) - xfrm: call xdo_dev_state_delete during state update (Sabrina Dubroca) - xfrm: fix the condition on x-> pcpu_num in xfrm_sa_len (Sabrina Dubroca) -xfrm: add missing extack for XFRMA_SA_PCPU in add_acquire and allocspi (Sabrina Dubroca) - i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter (Peter Yin) - ALSA: hda/realtek: add quirk for ASUS UM6702RC (Zhang Heng) - spi: intel-pci: Add support for Nova Lake mobile SPI flash (Alan Borzeszkowski) - usb: core: new quirk to handle devices with zero configurations (Jie Deng) - drm/amdgpu: fix gpu idle power consumption issue for gfx v12 (Yang Wang) - nvmet: move async event work off nvmet-wq (Chaitanya Kulkarni) [Orabug: 39262279] {CVE-2026-31557} - objtool: Handle Clang RSP musical chairs (Josh Poimboeuf) - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390 (Uzair Mughal) - ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk (Liucheng Lu) - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (Boris Burkov) [Orabug: 39251012] {CVE-2026-31519} - sched_ext: Use WRITE_ONCE() for the write side of dsq-> seq update (Zhidao Su) - HID: apple: avoid memory leak in apple_report_fixup() (Günther Noack) [Orabug: 39251018] {CVE-2026-31520} - drm/ttm/tests: Fix build failure on PREEMPT_RT (Maarten Lankhorst) - ALSA: hda/senary: Ensure EAPD is enabled during init (Wangdicheng) - dma-buf: Include ioctl.h in UAPI header (Isaac J. Manjarres) - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits() (Mark Brown) - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (Florian Fuchs) - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (Ranjan Kumar) - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg() (Mark Brown) - module: Fix kernel panic when a symbol st_shndx is out of bounds (Ihor Solodrai) [Orabug: 39251025] {CVE-2026-31521} - HID: asus: add xg mobile 2023 external hardware support (Denis Benato) - HID: mcp2221: cancel last I2C command on read error (Romain Sioen) - kbuild: install-extmod-build: Package resolve_btfids if necessary (Thomas Weißschuh) - net: usb: r8152: add TRENDnet TUC-ET2G (Valentin Spreckels) - HID: apple: Add EPOMAKERTH87 to the non-apple keyboards list (Takashi Iwai) - HID: magicmouse: avoid memory leak in magicmouse_report_fixup() (Günther Noack) [Orabug: 39251031] {CVE-2026-31522} - HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2 (Julius Lehmann) - nvme-pci: ensure we're polling a polled queue (Keith Busch) {CVE-2026-31523} - platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10 (Hans de Goede) - platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1 (Leif Skunberg) - nvme-fabrics: use kfree_sensitive() for DHCHAP secrets (Daniel Hodges) - nvme-pci: cap queue creation to used queues (Keith Busch) - platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list (Peter Metz) - HID: asus: avoid memory leak in asus_report_fixup() (Günther Noack) [Orabug: 39251044] {CVE-2026-31524} - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (Jenny Guanni Qu) [Orabug: 39251049] {CVE-2026-31525} - bpf: Release module BTF IDR before module unload (Kumar Kartikeya Dwivedi) - driver core: platform: use generic driver_override infrastructure (Danilo Krummrich) [Orabug: 39251055] {CVE-2026-31527} - driver core: generalize driver_override in struct device (Danilo Krummrich) - sh: platform_early: remove pdev-> driver_override check (Danilo Krummrich) - hwmon: axi-fan: don't use driver_override as IRQ name (Danilo Krummrich) - cxl/hdm: Avoid incorrect DVSEC fallback when HDM decoders are enabled (Smita Koralahalli) - perf: Make sure to use pmu_ctx-> pmu for groups (Peter Zijlstra) [Orabug: 39251060] {CVE-2026-31528} - bpf: Fix constant blinding for PROBE_MEM32 stores (Sachin Kumar) [Orabug: 39164149] {CVE-2026-23417} - cxl/port: Fix use after free of parent_port in cxl_detach_ep() (Alison Schofield) [Orabug: 39251064] {CVE-2026-31530} - LTS version: v6.12.79 (Sherry Yang) - Revert "LoongArch: Add machine_kexec_mask_interrupts() implementation" (Huacai Chen) - LTS version: v6.12.78 (Sherry Yang) - xen/privcmd: add boot control for restricted usagein domU (Juergen Gross) - xen/privcmd: restrict usage in unprivileged domU (Juergen Gross) [Orabug: 39142871] {CVE-2026-31788} - perf/x86/intel: Add missing branch counters constraint apply (Dapeng Mi) - hwmon: (max6639) Fix pulses-per-revolution implementation (Guenter Roeck) - tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure (Josh Law) - lib/bootconfig: check xbc_init_node() return in override path (Josh Law) - fs/tests: exec: Remove bad test vector (Kees Cook) - drm/i915/gt: Check set_default_submission() before deferencing (Rahul Bukte) [Orabug: 39262234] {CVE-2026-31540} - ksmbd: fix use-after-free in durable v2 replay of active file handles (Hyunwoo Kim) - ksmbd: fix use-after-free of share_conf in compound request (Hyunwoo Kim) - drm/amd: fix dcn 2.01 check (Andy Nguyen) - drm/amd/display: Fix DisplayID not-found handling in parse_edid_displayid_vrr() (Srinivasan Shanmugam) - mtd: rawnand: brcmnand: skip DMA during panic write (Kamal Dasu) - mtd: rawnand: serialize lock/unlock against other NAND operations (Kamal Dasu) [Orabug: 39167445] {CVE-2026-23434} - mm/shmem, swap: avoid redundant Xarray lookup during swapin (Kairui Song) - mm/shmem, swap: improve cached mTHP handling and fix potential hang (Kairui Song) - mm: shmem: avoid unpaired folio_unlock() in shmem_swapin_folio() (Kemeng Shi) - mm: shmem: fix potential data corruption during shmem swapin (Baolin Wang) - mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D mode (Pratyush Yadav) - mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D mode (Pratyush Yadav) - x86/platform/uv: Handle deconfigured sockets (Kyle Meyer) [Orabug: 39262240] {CVE-2026-31542} - ring-buffer: Fix to update per-subbuf entries of persistent ring buffer (Masami Hiramatsu) - i2c: pxa: defer reset on Armada 3700 when recovery is used (Gabor Juhos) - i2c: fsi: Fix a potential leak in fsi_i2c_probe() (Christophe Jaillet) - i2c: cp2615: fix serial string NULL-deref at probe (Johan Hovold) - USB: serial: f81232: fix incomplete serial portgeneration (Ji-Ze Hong) - drm/i915/psr: Compute PSR entry_setup_frames into intel_crtc_state (Jouni Högander) - hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit() (Sanman Pradhan) - hwmon: (pmbus/mp2975) Add error check for pmbus_read_word_data() return value (Sanman Pradhan) - icmp: fix NULL pointer dereference in icmp_tag_validation() (Weiming Shi) [Orabug: 39136286] {CVE-2026-23398} - net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths (Anas Iqbal) - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (Muhammad Hammad Ijaz) [Orabug: 39167454] {CVE-2026-23438} - nfnetlink_osf: validate individual option lengths in fingerprints (Weiming Shi) [Orabug: 39136282] {CVE-2026-23397} - netfilter: nf_tables: release flowtable after rcu grace period on error (Pablo Neira Ayuso) [Orabug: 39131092] {CVE-2026-23392} - netfilter: bpf: defer hook memory release until rcu readers are done (Florian Westphal) [Orabug: 39164139] {CVE-2026-23412} - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (Xiang Mei) [Orabug: 39262249] {CVE-2026-31546} - udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n (Xiang Mei) [Orabug: 39167457] {CVE-2026-23439} - net/mlx5e: Fix race condition during IPSec ESN update (Jianbo Liu) [Orabug: 39167461] {CVE-2026-23440} - net/mlx5e: Prevent concurrent access to IPSec ASO context (Jianbo Liu) [Orabug: 39167464] {CVE-2026-23441} - net/mlx5: qos: Restrict RTNL area to avoid a lock cycle (Cosmin Ratiu) - net: macb: fix uninitialized rx_fs_lock (Fedor Pchelkin) - wifi: mac80211: fix NULL deref in mesh_matches_local() (Xiang Mei) [Orabug: 39136278] {CVE-2026-23396} - iavf: fix VLAN filter lost on add/delete race (Petr Oros) - igc: fix page fault in XDP TX timestamps handling (Zdenek Bouska) [Orabug: 39167476] {CVE-2026-23445} - igc: fix missing update of skb-> tail in igc_xmit_frame() (Kohei Enju) - net: usb: aqc111: Do not perform PM inside suspend callback (Nikola Z. Ivanov) - clsact: Fix use-after-free ininit/destroy rollback asymmetry (Daniel Borkmann) [Orabug: 39164141] {CVE-2026-23413} - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check (Tobi Gaertner) [Orabug: 39167482] {CVE-2026-23447} - net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check (Tobi Gaertner) [Orabug: 39167487] {CVE-2026-23448} - net: airoha: Remove airoha_dev_stop() in airoha_remove() (Lorenzo Bianconi) - net: airoha: Read completion queue data in airoha_qdma_tx_napi_poll() (Lorenzo Bianconi) - net: airoha: fix PSE memory configuration in airoha_fe_pse_ports_init() (Lorenzo Bianconi) - net: airoha: read default PSE reserved pages value before updating (Lorenzo Bianconi) - net/sched: teql: Fix double-free in teql_master_xmit (Jamal Hadi Salim) [Orabug: 39167491] {CVE-2026-23449} - net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() (Jiayuan Chen) - PM: runtime: Fix a race condition related to device removal (Bart Van Assche) [Orabug: 39167500] {CVE-2026-23452} - sched: idle: Consolidate the handling of two special cases (Rafael J. Wysocki) - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (Dipayaan Roy) [Orabug: 39167505] {CVE-2026-23454} - net: bcmgenet: increase WoL poll timeout (Justin Chen) - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (Jenny Guanni Qu) [Orabug: 39167509] {CVE-2026-23455} - netfilter: xt_time: use unsigned int for monthday bit shift (Jenny Guanni Qu) - netfilter: xt_CT: drop pending enqueued packets on template removal (Pablo Neira Ayuso) [Orabug: 39131088] {CVE-2026-23391} - netfilter: nft_ct: drop pending enqueued packets on removal (Pablo Neira Ayuso) [Orabug: 39322991] {CVE-2026-43060} - nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139839] {CVE-2026-23399} - netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (Jenny Guanni Qu) [Orabug: 39167513] {CVE-2026-23456} - netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()(Lukas Johannes Möller) [Orabug: 39167517] {CVE-2026-23457} - netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (Hyunwoo Kim) [Orabug: 39167521] {CVE-2026-23458} - netfilter: ctnetlink: remove refcounting in expectation dumpers (Florian Westphal) [Orabug: 38423445] {CVE-2025-39764} - mpls: add missing unregister_netdevice_notifier to mpls_init (Sabrina Dubroca) - net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect (Jiayuan Chen) - bridge: cfm: Fix race condition in peer_mep deletion (Hyunwoo Kim) - Bluetooth: qca: fix ROM version reading on WCN3998 chips (Dmitry Baryshkov) - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (Shaurya Rane) [Orabug: 39167531] {CVE-2026-23461} - Bluetooth: HIDP: Fix possible UAF (Luiz Augusto von Dentz) [Orabug: 39167533] {CVE-2026-23462} - Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers (Wang Tao) [Orabug: 39322983] {CVE-2026-43059} - Bluetooth: hci_sync: Fix hci_le_create_conn_sync (Michael Grzeschik) - Bluetooth: ISO: Fix defer tests being unstable (Luiz Augusto von Dentz) - Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (Christian Eggers) - Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU (Christian Eggers) - Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU (Christian Eggers) - firmware: arm_scpi: Fix device_node reference leak in probe path (Felix Gu) - firmware: arm_ffa: Remove vm_id argument in ffa_rxtx_unmap() (Levi Yun) - arm64: dts: renesas: r9a09g057: Remove wdt{0,2,3} nodes (Fabrizio Castro) - arm64: dts: renesas: r9a09g057: Add RTC node (Ovidiu Panait) - wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down (Peddolla Harshavardhan Reddy) [Orabug: 39262255] {CVE-2026-31548} - wifi: mac80211: Fix static_branch_dec() underflow for aql_disable. (Kuniyuki Iwashima) [Orabug: 39262266] {CVE-2026-31551} - soc: fsl: cpm1: qmc: Fix error check for devm_ioremap_resource() in qmc_qe_init_resources() (Chen Ni) - soc: fsl: qbman: fix race condition inqman_destroy_fq (Richard Genoud) - cache: ax45mp: Fix device node reference leak in ax45mp_cache_init() (Felix Gu) - cache: starfive: fix device node leak in starlink_cache_init() (Felix Gu) - soc: microchip: mpfs: Fix memory leak in mpfs_sys_controller_probe() (Zilin Guan) - btrfs: tree-checker: fix misleading root drop_level error message (Zhengyuan Huang) - btrfs: log new dentries when logging parent dir of a conflicting inode (Filipe Manana) [Orabug: 39167544] {CVE-2026-23465} - ata: libata-scsi: report correct sense field pointer in ata_scsiop_maint_in() (Damien Le Moal) - ata: libata-scsi: Return residual for emulated SCSI commands (Damien Le Moal) - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ (Luiz Augusto von Dentz) [Orabug: 39131104] {CVE-2026-23395} - drm/xe: Open-code GGTT MMIO access protection (Matthew Brost) - drm/xe/oa: Allow reading after disabling OA stream (Ashutosh Dixit) - drm/amdgpu: apply state adjust rules to some additional HAINAN vairants (Alex Deucher) - drm/radeon: apply state adjust rules to some additional HAINAN vairants (Alex Deucher) - drm/imagination: Fix deadlock in soft reset sequence (Alessio Belle) - drm/amdgpu/mmhub4.1.0: add bounds checking for cid (Alex Deucher) - drm/amdgpu/mmhub3.0: add bounds checking for cid (Alex Deucher) - drm/amdgpu/mmhub3.0.2: add bounds checking for cid (Alex Deucher) - drm/amdgpu/mmhub3.0.1: add bounds checking for cid (Alex Deucher) - drm/amdgpu/mmhub2.3: add bounds checking for cid (Alex Deucher) - drm/amdgpu/mmhub2.0: add bounds checking for cid (Alex Deucher) - drm/amdgpu/gmc9.0: add bounds checking for cid (Alex Deucher) - drm/amd/display: Wrap dcn32_override_min_req_memclk() in DC_FP_{START, END} (Xi Ruoyao) - drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug (Maarten Lankhorst) - io_uring/kbuf: propagate BUF_MORE through early buffer commit path (Jens Axboe) - serial: uartlite: fix PM runtime usage count underflow on probe (Maciej Andrzejewski Iceye) - serial: 8250: Add latesynchronize_irq() to shutdown to handle DW UART BUSY (Ilpo Järvinen) - serial: 8250: Fix TX deadlock when using DMA (Raul E Rangel) [Orabug: 39323000] {CVE-2026-43061} - serial: 8250_pci: add support for the AX99100 (Martin Roukala) - iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry (Guanghui Feng) - mtd: Avoid boot crash in RedBoot partition table parser (Finn Thain) [Orabug: 39167570] {CVE-2026-23474} - mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init() (Chen Ni) - mtd: rawnand: pl353: make sure optimal timings are applied (Olivier Sobrie) - spi: fix statistics allocation (Johan Hovold) [Orabug: 39167574] {CVE-2026-23475} - spi: fix use-after-free on controller registration failure (Johan Hovold) [Orabug: 39167576] {CVE-2026-31389} - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (Maíra Canal) [Orabug: 39262262] {CVE-2026-31550} - mmc: sdhci: fix timing selection for 1-bit bus width (Luke Wang) - mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (Matthew Schwartz) - ata: libata-core: disable LPM on ADATA SU680 SSD (Damien Le Moal) - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (Ao Zhou) [Orabug: 39263396] {CVE-2026-31683} - btrfs: fix transaction abort when snapshotting received subvolumes (Filipe Manana) [Orabug: 39343743] {CVE-2026-43361} - kprobes: Remove unneeded warnings from __arm_kprobe_ftrace() (Masami Hiramatsu) - kprobes: Remove unneeded goto (Masami Hiramatsu) - powerpc64/bpf: fix kfunc call support (Hari Bathini) - powerpc64/bpf: Fold bpf_jit_emit_func_call_hlp() into bpf_jit_emit_func_call_rel() (Naveen N Rao) - s390/zcrypt: Enable AUTOSEL_DOM for CCA serialnr sysfs attribute (Harald Freudenberger) - drm/i915/psr: Write DSC parameters on Selective Update in ET mode (Jouni Högander) - drm/i915/dsc: Add helper for writing DSC Selective Update ET parameters (Jouni Högander) - drm/i915/dsc: Add Selective Update register definitions (Jouni Högander) - ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION (NamjaeJeon) - ksmbd: unset conn-> binding on failed binding request (Namjae Jeon) - smb: client: fix krb5 mount with username option (Paulo Alcantara) [Orabug: 39167586] {CVE-2026-31392} - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (Lukas Johannes Möller) [Orabug: 39167590] {CVE-2026-31393} - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() (Lukas Johannes Möller) [Orabug: 39323031] {CVE-2026-43062} - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations (Felix Fietkau) [Orabug: 39167595] {CVE-2026-31394} - parisc: Flush correct cache in cacheflush() syscall (Helge Deller) - net: macb: fix use-after-free access to PTP clock (Fedor Pchelkin) [Orabug: 39167599] {CVE-2026-31396} - NFC: nxp-nci: allow GPIOs to sleep (Ian Ray) - LoongArch: Give more information if kmem access failed (Tiezhu Yang) - nvdimm/bus: Fix potential use after free in asynchronous initialization (Ira Weiny) [Orabug: 39167605] {CVE-2026-31399} - sunrpc: fix cache_request leak in cache_release (Jeff Layton) [Orabug: 39167609] {CVE-2026-31400} - HID: bpf: prevent buffer overflow in hid_hw_request (Benjamin Tissoires) - selftests/hid: fix compilation when bpf_wq and hid_device are not exported (Benjamin Tissoires) - NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (Chuck Lever) [Orabug: 39167619] {CVE-2026-31403} - drm/amdgpu: Add basic validation for RAS header (Lijo Lazar) [Orabug: 38254044] {CVE-2025-38426} - drm/amd/pm: Use pm_display_cfg in legacy DPM (v2) (Timur Kristóf) - drm/amd/display: Add pixel_clock to amd_pp_display_configuration (Timur Kristóf) - drm/i915/psr: Repeat Selective Update area alignment (Jouni Högander) - drm/i915/alpm: ALPM disable fixes (Jouni Högander) - s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens) - s390/stackleak: Fix __stackleak_poison() inline assembly constraint (Heiko Carstens) - sched/fair: Fix zero_vruntime tracking (Peter Zijlstra) - sched_ext: Remove redundant css_put() in scx_cgroup_init() (Cheng-YangChou) [Orabug: 39343945] {CVE-2026-43438} - mm: thp: deny THP for files on anonymous inodes (Deepanshu Kartikey) [Orabug: 39131037] {CVE-2026-23375} - erofs: fix inline data read failure for ztailpacking pclusters (Gao Xiang) [Orabug: 39451908] {CVE-2026-45943} - xfs: get rid of the xchk_xfile_*_descr calls (Darrick J. Wong) [Orabug: 39103135] {CVE-2026-23252} - binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773484] {CVE-2025-68239} - net: dsa: properly keep track of conduit reference (Vladimir Oltean) [Orabug: 38887610] {CVE-2025-71152} - dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu) - blk-throttle: fix access race during throttle policy activation (Han Guangjiang) [Orabug: 38649132] {CVE-2025-40147} - f2fs: fix to avoid migrating empty section (Chao Yu) - f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic (Zhiguo Niu) - f2fs: compress: change the first parameter of page_array_{alloc,free} to sbi (Zhiguo Niu) - net: stmmac: remove support for lpi_intr_o (Russell King) - mptcp: pm: in-kernel: always set ID as avail when rm endp (Matthieu Baerts) [Orabug: 39331851] {CVE-2026-43252} - platform/x86/amd/pmc: Add support for Van Gogh SoC (Antheas Kapenekakis) [Orabug: 38792613] {CVE-2025-68334} - x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov) - io_uring/uring_cmd: fix too strict requirement on ioctl (Asbjoern Sloth Toennesen) - tracing: Add recursion protection in kernel stack trace recording (Steven Rostedt) [Orabug: 38970274] {CVE-2026-23138} - ice: fix devlink reload call trace (Paul Greenwalt) [Orabug: 38931107] {CVE-2026-23104} - btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970327] {CVE-2026-23157} - rxrpc: Fix recvmsg() unconditional requeue (David Howells) - dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887636] {CVE-2025-71161} - drm/xe/sync: Cleanup partially initialized sync on parse failure(Shuicheng Lin) [Orabug: 39343830] {CVE-2026-43395} - xfs: fix integer overflow in bmap intent sort comparator (Long Li) - crypto: atmel-sha204a - Fix OOM -> tfm_count leak (Thorsten Blum) - cifs: open files should not hold ref on superblock (Shyam Prasad N) - drm/bridge: ti-sn65dsi83: halve horizontal syncs for dual LVDS output (Luca Ceresoli) - ksmbd: Don't log keys in SMB3 signing and encryption key generation (Thorsten Blum) - KVM: x86: Introduce KVM_X86_QUIRK_VMCS12_ALLOW_FREEZE_IN_SMM (Jim Mattson) - KVM: nVMX: Add consistency checks for CR0.WP and CR4.CET (Chao Gao) - fgraph: Fix thresh_return clear per-task notrace (Shengming Hu) - iomap: reject delalloc mappings during writeback (Darrick J. Wong) - sched_ext: Fix starvation of scx_enable() under fair-class saturation (Tejun Heo) [Orabug: 39343824] {CVE-2026-43392} - sched_ext: Disable preemption between scx_claim_exit() and kicking helper work (Tejun Heo) [Orabug: 39386852] {CVE-2026-43482} - nsfs: tighten permission checks for ns iteration ioctls (Christian Brauner) [Orabug: 39343840] {CVE-2026-43403} - mm/kfence: fix KASAN hardware tag faults during late enablement (Alexander Potapenko) - mm/page_alloc: forward the gfp flags from alloc_contig_range() to post_alloc_hook() (David Hildenbrand) - mm/page_alloc: sort out the alloc_contig_range() gfp flags mess (David Hildenbrand) - mm/page_alloc: move set_page_refcounted() to callers of post_alloc_hook() (Matthew Wilcox) - mmc: dw_mmc-rockchip: Fix runtime PM support for internal phase support (Shawn Lin) - mmc: dw_mmc-rockchip: Add memory clock auto-gating support (Shawn Lin) - mmc: dw_mmc-rockchip: use modern PM macros (Jisheng Zhang) - KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (Sean Christopherson) [Orabug: 39386854] {CVE-2026-43483} - KVM: SVM: Add a helper to look up the max physical ID for AVIC (Naveen N Rao) - KVM: SVM: Limit AVIC physical max index based on configured max_vcpu_ids (Naveen N Rao) - usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling(Jiasheng Jiang) - usb: gadget: f_ncm: Fix net_device lifecycle with device_move (Kuen-Han Tsai) - cleanup: Provide retain_and_null_ptr() (Thomas Gleixner) - can: gs_usb: gs_can_open(): always configure bitrates before starting device (Marc Kleine-Budde) - xfs: Fix error pointer dereference (Ethan Tidmore) - net/sched: act_gate: snapshot parameters with RCU on replace (Paul Moses) [Orabug: 39103117] {CVE-2026-23245} - selftests: mptcp: join: check RM_ADDR not sent over same subflow (Matthieu Baerts) - selftests: mptcp: add a check for 'add_addr_accepted' (Gang Yan) - drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink (Natalie Vock) - mptcp: pm: avoid sending RM_ADDR over same subflow (Matthieu Baerts) - mptcp: pm: in-kernel: always mark signal+subflow endp as used (Matthieu Baerts) [Orabug: 39130868] {CVE-2026-23321} - perf/x86/intel/uncore: Add per-scheduler IMC CAS count events (Zide Chen) - perf/x86/intel/uncore: Support more units on Granite Rapids (Kan Liang) - wifi: libertas: fix use-after-free in lbs_free_adapter() (Daniel Hodges) [Orabug: 39130708] {CVE-2026-23281} - platform/x86: hp-bioscfg: Support allocations of larger data (Mario Limonciello) - x86/sev: Allow IBPB-on-Entry feature for SNP guests (Kim Phillips) - net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (Andrew Lunn) [Orabug: 39131008] {CVE-2026-23368} - gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL (Ankit Garg) [Orabug: 39131072] {CVE-2026-23386} - spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli) - ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths (Fedor Pchelkin) - smb: client: Compare MACs in constant time (Eric Biggers) - ksmbd: Compare MACs in constant time (Eric Biggers) - net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343805] {CVE-2026-43383} - drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode with HPD (John Ripple) - i3c: mipi-i3c-hci: Add missing TID field to no-op commanddescriptor (Adrian Hunter) - i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort (Adrian Hunter) - i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors (Adrian Hunter) - iio: proximity: hx9023s: Protect against division by zero in set_samp_freq (Yasin Lee) - iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol) - iio: imu: inv_icm42600: fix odr switch to the same value (Jean-Baptiste Maneyrol) - iio: gyro: mpu3050-i2c: fix pm_runtime error handling (Antoniu Miclaus) - iio: gyro: mpu3050-core: fix pm_runtime error handling (Antoniu Miclaus) [Orabug: 39343731] {CVE-2026-43357} - iio: buffer: Fix wait_queue not being removed (Nuno Sa) - iio: chemical: bme680: Fix measurement wait duration calculation (Chris Spencer) - iio: potentiometer: mcp4131: fix double application of wiper shift (Lukas Schmid) - iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() (Antoniu Miclaus) - iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas() (Antoniu Miclaus) - iio: frequency: adf4377: Fix duplicated soft reset mask (Seungju Cheon) - iio: dac: ds4424: reject -128 RAW value (Oleksij Rempel) - btrfs: abort transaction on failure to update root in the received subvol ioctl (Filipe Manana) - btrfs: fix transaction abort on set received ioctl due to item overflow (Filipe Manana) [Orabug: 39343736] {CVE-2026-43359} - btrfs: fix transaction abort on file creation due to name hash collision (Filipe Manana) [Orabug: 39343740] {CVE-2026-43360} - smb: client: fix iface port assignment in parse_server_interfaces (Henrique Carvalho) - smb: client: fix in-place encryption corruption in SMB2_write() (Bharath Sm) [Orabug: 39343749] {CVE-2026-43362} - smb: client: fix atomic open with O_DIRECT & O_SYNC (Paulo Alcantara) - lib/bootconfig: check bounds before writing in __xbc_open_brace() (Josh Law) - lib/bootconfig: fix snprintf truncation check in xbc_node_compose_key_after() (Josh Law) - x86/apic: Disable x2apic on resume if the kernel expects so(Shashank Balaji) [Orabug: 39343755] {CVE-2026-43363} - lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error (Josh Law) - s390/dasd: Copy detected format information to secondary device (Stefan Haberland) - s390/dasd: Move quiesce state with pprc swap (Stefan Haberland) - xfs: ensure dquot item is deleted from AIL only after log shutdown (Long Li) - xfs: fix undersized l_iclog_roundoff values (Darrick J. Wong) [Orabug: 39343760] {CVE-2026-43365} - xfs: fix returned valued from xfs_defer_can_append (Carlos Maiolino) - cifs: make default value of retrans as zero (Shyam Prasad N) - tracing: Fix trace_buf_size= cmdline parameter with sizes > = 2G (Calvin Owens) - tracing: Fix enabling multiple events on the kernel command line and bootconfig (Andrei-Alexandru Tachici) - drm/msm: Fix dma_free_attrs() buffer size (Thomas Fourier) - drm/i915: Fix potential overflow of shmem scatterlist length (Janusz Krzysztofik) [Orabug: 39343766] {CVE-2026-43368} - drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding (Luca Ceresoli) - drm/amd: Set num IP blocks to 0 if discovery fails (Mario Limonciello) - drm/amdgpu: Fix use-after-free race in VM acquire (Alysa Liu) [Orabug: 39343769] {CVE-2026-43370} - drm/amd/pm: remove invalid gpu_metrics.energy_accumulator on smu v13.0.x (Yang Wang) - net: dsa: microchip: Fix error path in PTP IRQ setup (Bastien Curutchet) - net: ethernet: arc: emac: quiesce interrupts before requesting IRQ (Fan Wu) - net: ncsi: fix skb leak in error paths (Jian Zhang) - net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (Mehul Rao) [Orabug: 39343780] {CVE-2026-43374} - ksmbd: fix use-after-free by using call_rcu() for oplock_info (Namjae Jeon) - smb: server: fix use-after-free in smb2_open() (Marios Makassikis) - ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() (Namjae Jeon) - drm/amd/display: Fallback to boot snapshot for dispclk (Dillon Varone) - ata: libata-core: Disable LPM on ST1000DM010-2EP102 (Maximilian Pezzullo) [Orabug: 39386866] {CVE-2026-43487} -pmdomain: bcm: bcm2835-power: Fix broken reset status read (Maíra Canal) - parisc: Check kernel mapping earlier at bootup (Helge Deller) - parisc: Fix initial page table creation for boot (Helge Deller) - hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read (Sanman Pradhan) - arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation (Catalin Marinas) - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep (Dave Airlie) [Orabug: 39343796] {CVE-2026-43381} - parisc: Increase initial mapping to 64 MB with KALLSYMS (Helge Deller) - batman-adv: Avoid double-rtnl_lock ELP metric worker (Sven Eckelmann) [Orabug: 39343801] {CVE-2026-43382} - net/tcp-ao: Fix MAC comparison to be constant-time (Eric Biggers) - tracing: Fix syscall events activation by ensuring refcount hits zero (Huiwen He) - ice: fix retry for AQ command 0x06EE (Jakub Staniszewski) - net: mana: Ring doorbell at 4 CQ wraparounds (Long Li) - media: dvb-net: fix OOB access in ULE extension header tables (Ariel Silver) [Orabug: 39171441] {CVE-2026-31405} - staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (Luka Gejak) - staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() (Greg Kroah-Hartman) - ixgbevf: fix link setup issue (Jedrzej Jagielski) - ice: reintroduce retry mechanism for indirect AQ (Jakub Staniszewski) - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (Mark Harmstone) [Orabug: 39343826] {CVE-2026-43393} - irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS supports (Marc Zyngier) - device property: Allow secondary lookup in fwnode_get_next_child_node() (Andy Shevchenko) - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit(). (Kuniyuki Iwashima) [Orabug: 39343828] {CVE-2026-43394} - s390/pfault: Fix virtual vs physical address confusion (Alexander Gordeev) - drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used (Franz Schnyder) - drm/bridge: samsung-dsim: Fix memory leak in error path (Osama Abdelkader) [Orabug:39343833] {CVE-2026-43397} - drm/amd: Disable MES LR compute W/A (Mario Limonciello) - Revert "tcpm: allow looking for role_sw device in the main node" (Xu Yang) - Fix CC_HAS_ASM_GOTO_OUTPUT on non-x86 architectures (Linus Torvalds) - kbuild: Disable CC_HAS_ASM_GOTO_OUTPUT on clang < 17 (Thomas Gleixner) - scsi: hisi_sas: Fix NULL pointer exception during user_scan() (Xingui Yang) [Orabug: 39343866] {CVE-2026-43413} - scsi: hisi_sas: Use macro instead of magic number (Yihang Li) - scsi: hisi_sas: Add time interval between two H2D FIS following soft reset spec (Xingui Yang) - scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (Wangshuaiwei) [Orabug: 39343873] {CVE-2026-43415} - i3c: dw-i3c-master: Set SIR_REJECT in DAT on device attach and reattach (Adrian Ng Ho Yin) - time/jiffies: Mark jiffies_64_to_clock_t() notrace (Steven Rostedt) - ceph: fix memory leaks in ceph_mdsc_build_path() (Max Kellermann) [Orabug: 39343881] {CVE-2026-43419} - ceph: fix i_nlink underrun during async unlink (Max Kellermann) [Orabug: 39343883] {CVE-2026-43420} - libceph: admit message frames only in CEPH_CON_S_OPEN state (Ilya Dryomov) - libceph: Use u32 for non-negative values in ceph_monmap_decode() (Raphael Zimmer) [Orabug: 39343843] {CVE-2026-43405} - libceph: prevent potential out-of-bounds reads in process_message_header() (Ilya Dryomov) [Orabug: 39343846] {CVE-2026-43406} - libceph: reject preamble if control segment is empty (Ilya Dryomov) - libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39343849] {CVE-2026-43407} - ceph: add a bunch of missing ceph_path_info initializers (Max Kellermann) [Orabug: 39343853] {CVE-2026-43408} - kprobes: avoid crash when rmmod/insmod after ftrace killed (Masami Hiramatsu) [Orabug: 39343855] {CVE-2026-43409} - tipc: fix divide-by-zero in tipc_sk_filter_connect() (Mehul Rao) [Orabug: 39343860] {CVE-2026-43411} - ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start (Ravi Hothi) - mmc: core: Avoid bitfield RMW forclaim/retune flags (Penghe Geng) [Orabug: 39386858] {CVE-2026-43484} - mm/kfence: disable KFENCE upon KASAN HW tags enablement (Alexander Potapenko) - mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index() (Felix Gu) - mm/tracing: rss_stat: ensure curr is false from kthread context (Kalesh Singh) - rust: kbuild: allow unused_features (Miguel Ojeda) - usb: image: mdc800: kill download URB on timeout (Ziyi Guo) [Orabug: 39343896] {CVE-2026-43425} - usb: mdc800: handle signal and read racing (Oliver Neukum) - usb: renesas_usbhs: fix use-after-free in ISR during device removal (Fan Wu) - usb: class: cdc-wdm: fix reordering issue in read code path (Oliver Neukum) [Orabug: 39343905] {CVE-2026-43427} - USB: core: Limit the length of unkillable synchronous timeouts (Alan Stern) [Orabug: 39343910] {CVE-2026-43428} - USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts (Alan Stern) [Orabug: 39343916] {CVE-2026-43429} - USB: usbcore: Introduce usb_bulk_msg_killable() (Alan Stern) - usb: typec: altmode/displayport: set displayport signaling rate in configure message (Rd Babiera) - usb: roles: get usb role switch from parent only for usb-b-connector (Xu Yang) - usb: cdc-acm: Restore CAP_BRK functionnality to CH343 (Marc Zyngier) - usb: core: don't power off roothub PHYs if phy_set_mode() fails (Gabor Juhos) - usb: misc: uss720: properly clean up reference in uss720_probe() (Greg Kroah-Hartman) - usb: dwc3: pci: add support for the Intel Nova Lake -H (Krogerus Heikki) - usb: yurex: fix race in probe (Oliver Neukum) [Orabug: 39343920] {CVE-2026-43430} - usb: xhci: Prevent interrupt storm on host controller error (HCE) (Dayu Jiang) [Orabug: 39386868] {CVE-2026-43488} - usb: xhci: Fix memory leak in xhci_disable_slot() (Zilin Guan) [Orabug: 39343929] {CVE-2026-43432} - USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb speed (Vyacheslav Vahnenko) - usb/core/quirks: Add Huawei ME906S-device to wakeup quirk (Christoffer Sandberg) - USB: add QUIRK_NO_BOS for video capture several devices(A1Rm4X) - KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (Sean Christopherson) - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA (Zhang Heng) - ata: libata-core: Add BRIDGE_OK quirk for QEMU drives (Pedro Falcato) - net: usb: lan78xx: skip LTM configuration for LAN7850 (Oleksij Rempel) - net: usb: lan78xx: fix TX byte statistics for small packets (Oleksij Rempel) - net: usb: lan78xx: fix silent drop of packets with checksum errors (Oleksij Rempel) - ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces (Takashi Iwai) [Orabug: 39343938] {CVE-2026-43436} - ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (Mehul Rao) [Orabug: 39343941] {CVE-2026-43437} - cgroup: fix race between task migration and iteration (Qingye Zhao) [Orabug: 39343947] {CVE-2026-43439} - usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() (Seungjin Bae) - iio: imu: inv-mpu9150: fix irq ack preventing irq storms (Andreas Kemnade) - net: prevent NULL deref in ip[6]tunnel_xmit() (Eric Dumazet) - octeontx2-af: devlink: fix NIX RAS reporter to use RAS interrupt status (Alok Tiwari) - octeontx2-af: devlink: fix NIX RAS reporter recovery condition (Alok Tiwari) - net: dsa: realtek: Fix LED group port bit for non-zero LED group (Marek Behún) - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (Ricardo B. Marlière) [Orabug: 39343952] {CVE-2026-43441} - drm/amdkfd: Unreserve bo if queue update failed (Philip Yang) [Orabug: 39343958] {CVE-2026-43444} - ASoC: detect empty DMI strings (Casey Connolly) - ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition (Chen Ni) - ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address() (Ben Dooks) - net: bcmgenet: fix broken EEE by converting to phylib-managed state (Nicolai Buchwitz) - e1000/e1000e: Fix leak in DMA error cleanup (Matt Vollrath) [Orabug: 39343960] {CVE-2026-43445} - i40e: fix src IP mask checks and memcpy argumentnames in cloud filter (Alok Tiwari) - nvme-pci: Fix race bug in nvme_poll_irqdisable() (Sungwoo Kim) [Orabug: 39343966] {CVE-2026-43448} - nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (Sungwoo Kim) [Orabug: 39343971] {CVE-2026-43449} - perf ftrace: Fix hashmap__new() error checking (Chen Ni) - regulator: pca9450: Correct interrupt type (Peng Fan) - perf annotate: Fix hashmap__new() error checking (Chen Ni) - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (Yuan Tan) [Orabug: 39110655] {CVE-2026-23274} - netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (Hyunwoo Kim) [Orabug: 39343975] {CVE-2026-43450} - netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (Hyunwoo Kim) [Orabug: 39343979] {CVE-2026-43451} - netfilter: x_tables: guard option walkers against 1-byte tail reads (David Dull) [Orabug: 39343983] {CVE-2026-43452} - netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() (Jenny Guanni Qu) [Orabug: 39343987] {CVE-2026-43453} - net: add xmit recursion limit to tunnel xmit functions (Weiming Shi) [Orabug: 39110659] {CVE-2026-23276} - xdp: register system page pool as an XDP memory model (Toke Høiland-Jørgensen) - xdp: allow attaching already registered memory model to xdp_rxq_info (Alexander Lobakin) - amd-xgbe: prevent CRC errors during RX adaptation with AN disabled (Raju Rangoju) - amd-xgbe: fix link status handling in xgbe_rx_adaptation (Raju Rangoju) - mctp: route: hold key-> lock in mctp_flow_prepare_output() (Chengfeng Ye) - bonding: fix type confusion in bond_setup_by_slave() (Jiayuan Chen) [Orabug: 39343993] {CVE-2026-43456} - bonding: use common function to compute the features (Hangbin Liu) - net: add a common function to compute features for upper devices (Hangbin Liu) - bonding: Correctly support GSO ESP offload (Cosmin Ratiu) - bonding: add ESP offload features when slaves support (Jianbo Liu) - can: hi311x: hi3110_open(): add check for hi3110_power_enable() return value (Wenyuan Li) - mctp: i2c: fix skb memoryleak in receive path (Haiyue Wang) - bnxt_en: Fix RSS table size check when changing ethtool channels (Pavan Chebbi) - serial: caif: hold tty-> link reference in ldisc_open and ser_release (Shuangpeng Bai) - net: sfp: improve Huawei MA5671a fixup (Álvaro Fernández Rojas) - ASoC: simple-card-utils: fix graph_util_is_ports0() for DT overlays (Sen Wang) - ASoC: simple-card-utils: use __free(device_node) for device node (Kuninori Morimoto) - ASoC: soc-core: flush delayed work before removing DAIs and widgets (Matteo Cotifava) [Orabug: 39344003] {CVE-2026-43459} - ASoC: soc-core: drop delayed_work_pending() check before flush (Matteo Cotifava) - drm/sitronix/st7586: fix bad pixel data due to byte swap (David Lechner) - net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit (Weiming Shi) [Orabug: 39110665] {CVE-2026-23277} - net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (Gal Pressman) [Orabug: 39344016] {CVE-2026-43466} - net/mlx5: Fix deadlock between devlink lock and esw-> wq (Cosmin Ratiu) [Orabug: 39344022] {CVE-2026-43468} - net/mlx5: Query to see if host PF is disabled (Daniel Jurgens) - net/mlx5: IFC updates for disabled host PF (Daniel Jurgens) - bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states (Hangbin Liu) - drm/amd/pm: add missing od setting PP_OD_FEATURE_ZERO_FAN_BIT for smu v14 (Yang Wang) - drm/msm/dsi: fix pclk rate calculation for bonded dsi (Pengyu Luo) - net: dsa: realtek: rtl8365mb: remove ifOutDiscards from rx_packets (Mieczyslaw Nalewaj) - perf disasm: Fix off-by-one bug in outside check (Peter Collingbourne) - workqueue: Use POOL_BH instead of WQ_BH when checking pool flags (Breno Leitao) - btrfs: hold space_info-> lock when clearing periodic reclaim ready (Sun Yangkai) - xprtrdma: Decrement re_receiving on the early exit paths (Eric Badger) [Orabug: 39344025] {CVE-2026-43469} - drm/msm/dsi: fix hdisplay calculation when programming dsi registers (Pengyu Luo) - nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (Roberto BergantinosCorpas) [Orabug: 39344029] {CVE-2026-43470} - smb/server: Fix another refcount leak in smb2_open() (Guenter Roeck) - powerpc: 83xx: km83xx: Fix keymile vendor prefix (Jonathan Neuschäfer) - remoteproc: sysmon: Correct subsys_name_len type in QMI request (Bjorn Andersson) - powerpc/crash: adjust the elfcorehdr size (Sourabh Jain) - powerpc/kexec/core: use big-endian types for crash variables (Sourabh Jain) - kexec: Include kernel-end even without crashkernel (Ben Collins) - kexec: Consolidate machine_kexec_mask_interrupts() implementation (Eliav Farber) - powerpc/uaccess: Fix inline assembly for clang build on PPC32 (Christophe Leroy) - ALSA: usb-audio: Check max frame size for implicit feedback mode, too (Takashi Iwai) - drm/amdgpu/vcn5: Add SMU dpm interface type (Sguttula) - ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0 (Takashi Iwai) - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (Wangshuaiwei) - scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (Peter Wang) [Orabug: 39344031] {CVE-2026-43471} - ASoC: cs42l43: Report insert for exotic peripherals (Charles Keepax) - ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table (Azamat Almazbek Uulu) - scsi: ses: Fix devices attaching to different hosts (Tomas Henzl) - ACPI: OSI: Add DMI quirk for Acer Aspire One D255 (Sofia Schneider) - wifi: mac80211: set default WMM parameters on all links (Ramanathan Choodamani) - unshare: fix unshare_fs() handling (Al Viro) [Orabug: 39344033] {CVE-2026-43472} - ALSA: hda/realtek: Fix speaker pop on Star Labs StarFighter (Sean Rhodes) - scsi: mpi3mr: Add NULL checks when resetting request and reply queues (Ranjan Kumar) [Orabug: 39344037] {CVE-2026-43473} - ACPI: PM: Save NVS memory on Lenovo G70-35 (Piotr Mazek) - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (Jan Kiszka) [Orabug: 39344042] {CVE-2026-43475} - LTS version: v6.12.77 (Sherry Yang) - ata: libata-eh: Fix detection of deferred qc timeouts (Guenter Roeck) - ata: libata: cancel pendingwork after clearing deferred_qc (Niklas Cassel) - ata: libata-eh: correctly handle deferred qc timeouts (Damien Le Moal) - ata: libata-core: fix cancellation of a port deferred qc work (Damien Le Moal) - ext4: fix potential null deref in ext4_mb_init() (Baokun Li) - apparmor: fix race between freeing data and fs accessing it (John Johansen) - apparmor: fix race on rawdata dereference (John Johansen) - apparmor: fix differential encoding verification (John Johansen) - apparmor: fix unprivileged local user can do privileged policy management (John Johansen) - apparmor: Fix double free of ns_name in aa_replace_profiles() (John Johansen) - apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (Massimiliano Pellizzer) - apparmor: fix side-effect bug in match_char() macro usage (Massimiliano Pellizzer) - apparmor: fix: limit the number of levels of policy namespaces (John Johansen) - apparmor: replace recursive profile removal with iterative approach (Massimiliano Pellizzer) - apparmor: fix memory leak in verify_header (Massimiliano Pellizzer) - apparmor: validate DFA start states are in bounds in unpack_pdb (Massimiliano Pellizzer) - selftest/arm64: Fix sve2p1_sigill() to hwcap test (Yifan Wu) - xdp: produce a warning when calculated tailroom is negative (Larysa Zaremba) [Orabug: 39130928] {CVE-2026-23343} - i40e: use xdp.frame_sz as XDP RxQ info frag_size (Larysa Zaremba) - i40e: fix registering XDP RxQ info (Larysa Zaremba) - xsk: introduce helper to determine rxq-> frag_size (Larysa Zaremba) - xdp: use modulo operation to calculate XDP frag tailroom (Larysa Zaremba) - net/sched: act_ife: Fix metalist update behavior (Jamal Hadi Salim) - net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (Jiayuan Chen) [Orabug: 39130788] {CVE-2026-23300} - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (Fernando Fernandez Mancera) [Orabug: 39130766] {CVE-2026-23293} - selftests/harness: order TEST_F and XFAIL_ADD constructors (Sun Jian) - kselftest/harness: Use helper to avoidzero-size memset warning (Wake Liu) - net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup() (Lorenzo Bianconi) - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal) [Orabug: 39130948] {CVE-2026-23351} - net: stmmac: Fix error handling in VLAN add and delete paths (Ovidiu Panait) - nfc: rawsock: cancel tx_work before socket teardown (Jakub Kicinski) - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback (Jakub Kicinski) - nfc: nci: free skb on nci_transceive early error paths (Jakub Kicinski) - net_sched: sch_fq: clear q-> band_pkt_count[] in fq_reset() (Eric Dumazet) - net: nfc: nci: Fix zero-length proprietary notifications (Ian Ray) - net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (Koichiro Den) [Orabug: 39130922] {CVE-2026-23340} - hwmon: (max6639) fix inverted polarity (Olivier Sobrie) - hwmon: (max6639) : Configure based on DT property (Naresh Solanki) - nvme: fix memory allocation in nvme_pr_read_keys() (Sungwoo Kim) [Orabug: 39103115] {CVE-2026-23244} - nvme: reject invalid pr_read_keys() num_keys values (Stefan Hajnoczi) - drm/xe/reg_sr: Fix leak on xa_store failure (Shuicheng Lin) - i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus lock" (Charles Haithcock) [Orabug: 39131012] {CVE-2026-23369} - drm/sched: Fix kernel-doc warning for drm_sched_job_done() (Kernel Test Robot) - amd-xgbe: fix sleep while atomic on suspend/resume (Raju Rangoju) - net: ipv4: fix ARM64 alignment fault in multipath hash seed (Yung Chih Su) [Orabug: 39130846] {CVE-2026-23316} - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() (Jakub Kicinski) [Orabug: 39130806] {CVE-2026-23304} - smb/client: fix buffer size for smb311_posix_qinfo in SMB311_posix_query_info() (Zhangguodong) - smb/client: fix buffer size for smb311_posix_qinfo in smb2_compound_op() (Zhangguodong) - bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim (Lang Xu) [Orabug: 39130859] {CVE-2026-23319} - iavf: fix netdev-> max_mtu torespect actual hardware limit (Kohei Enju) - xen/acpi-processor: fix _CST detection using undersized evaluation buffer (David Thomson) - indirect_call_wrapper: do not reevaluate function pointer (Eric Dumazet) - wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() (Lorenzo Bianconi) [Orabug: 39130843] {CVE-2026-23315} - wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() (Lorenzo Bianconi) - wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() (Lorenzo Bianconi) - wifi: wlcore: Fix a locking bug (Bart Van Assche) [Orabug: 39167424] {CVE-2026-23420} - wifi: cw1200: Fix locking in error paths (Bart Van Assche) - octeon_ep_vf: avoid compiler and IQ/OQ reordering (Vimlesh Kumar) - octeon_ep_vf: Relocate counter updates before NAPI (Vimlesh Kumar) - octeon_ep: avoid compiler and IQ/OQ reordering (Vimlesh Kumar) - octeon_ep: Relocate counter updates before NAPI (Vimlesh Kumar) - bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded (Jiayuan Chen) [Orabug: 39130827] {CVE-2026-23310} - net: dsa: realtek: rtl8365mb: fix rtl8365mb_phy_ocp_write return value (Mieczyslaw Nalewaj) - kunit: tool: copy caller args in run_kernel to prevent mutation (Shuvam Pandey) - rust: kunit: fix warning when !CONFIG_PRINTK (Alexandre Courbot) - drm/xe: Do not preempt fence signaling CS instructions (Matthew Brost) - wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config (Sebastian Krzyszkowiak) {CVE-2026-23373} - can: mcp251x: fix deadlock in error path of mcp251x_open (Alban Bedel) [Orabug: 39130970] {CVE-2026-23357} - can: bcm: fix locking for bcm_op runtime updates (Oliver Hartkopp) [Orabug: 39131186] {CVE-2026-23362} - amd-xgbe: fix MAC_TCR_SS register width for 2.5G and 10M speeds (Raju Rangoju) - net: ti: icssg-prueth: Fix ping failure after offload mode setup when link speed is not 1G (Md Danish Anwar) - atm: lec: fix null-ptr-deref in lec_arp_clear_vccs (Jiayuan Chen) [Orabug: 39130725] {CVE-2026-23286} - xsk: Fix zero-copy AF_XDPfragment drop (Nikhil P. Rao) - xsk: Fix fragment node deletion to prevent buffer leak (Nikhil P. Rao) - xsk: s/free_list_node/list_node/ (Maciej Fijalkowski) - xsk: Get rid of xdp_buff_xsk::xskb_list_node (Maciej Fijalkowski) - net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling in ALE table (Chintan Vankar) - drm/solomon: Fix page start when updating rectangle in page addressing mode (Francesco Lavra) - e1000e: clear DPG_EN after reset to avoid autonomous power-gating (Vitaly Lifshits) - i40e: Fix preempt count leak in napi poll tracepoint (Thomas Gleixner) [Orabug: 39130838] {CVE-2026-23313} - idpf: change IRQ naming to match netdev and ethtool queue numbering (Brian Vazquez) - hwmon: (it87) Check the it87_lock() return value (Bart Van Assche) - pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() (Felix Gu) - HID: multitouch: new class MT_CLS_EGALAX_P80H84 (Ian Ray) - HID: multitouch: add quirks for Lenovo Yoga Book 9i (Brian Howard) - platform/x86: thinkpad_acpi: Fix errors reading battery thresholds (Jonathan Teh) - pinctrl: equilibrium: fix warning trace on load (Florian Eckert) - pinctrl: equilibrium: rename irq_chip function callbacks (Florian Eckert) - hwmon: (aht10) Fix initialization commands for AHT20 (Hao Yu) - hwmon: (aht10) Add support for dht20 (Akhilesh Patil) - nvme: fix admin queue leak on controller reset (Ming Lei) [Orabug: 39131191] {CVE-2026-23360} - ACPI: APEI: GHES: Disable KASAN instrumentation when compile testing with clang < 18 (Nathan Chancellor) - btrfs: always fallback to buffered write if the inode requires checksum (Qu Wenruo) - net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz (Huacai Chen) - ARM: clean up the memset64() C wrapper (Thomas Weißschuh) - xattr: switch to CLASS(fd) (Al Viro) [Orabug: 39073878] {CVE-2024-14027} - selftests: mptcp: join: check removing signal+subflow endp (Matthieu Baerts) - selftests: mptcp: more stable simult_flows tests (Paolo Abeni) - smb: client: Don't log plaintext credentials in cifs_set_cifscreds(Thorsten Blum) {CVE-2026-23303} - smb: client: fix broken multichannel with krb5+signing (Paulo Alcantara) - smb: client: fix cifs_pick_channel when channels are equally loaded (Henrique Carvalho) - drbd: fix null-pointer dereference on local read error (Christoph Böhmwalder) [Orabug: 39130720] {CVE-2026-23285} - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() (Lars Ellenberg) [Orabug: 39130964] {CVE-2026-23356} - Squashfs: check metadata block offset is within range (Phillip Lougher) [Orabug: 39131078] {CVE-2026-23388} - scsi: target: Fix recursive locking in __configfs_open_file() (Prithvi Tambewagh) [Orabug: 39130762] {CVE-2026-23292} - tracing: Fix WARN_ON in tracing_buffers_mmap_close (Qing Wang) [Orabug: 39131052] {CVE-2026-23380} - nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit(). (Kuniyuki Iwashima) [Orabug: 39130777] {CVE-2026-23297} - net/sched: ets: fix divide by zero in the offload path (Davide Caratti) [Orabug: 39131048] {CVE-2026-23379} - RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (Jason Gunthorpe) [Orabug: 39130901] {CVE-2026-23335} - IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() (Jason Gunthorpe) [Orabug: 39130741] {CVE-2026-23289} - wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (Vahagn Vardanian) [Orabug: 39130699] {CVE-2026-23279} - wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration (Ariel Silver) [Orabug: 39103120] {CVE-2026-23246} - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() (Daniil Dulov) [Orabug: 39130904] {CVE-2026-23336} - wifi: radiotap: reject radiotap with unknown bits (Johannes Berg) [Orabug: 39131004] {CVE-2026-23367} - ALSA: usb-audio: Use correct version for UAC3 header validation (Jun Seo) [Orabug: 39130853] {CVE-2026-23318} - platform/x86: dell-wmi: Add audio/mic mute key codes (Kurt Borja) - platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data (Thorsten Blum) {CVE-2026-23370} - x86/efi: defer freeing of boot services memory (Mike Rapoport) [Orabug:39130952] {CVE-2026-23352} - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them (Greg Kroah-Hartman) [Orabug: 39131060] {CVE-2026-23382} - can: usb: f81604: handle bulk write errors properly (Greg Kroah-Hartman) - can: usb: f81604: handle short interrupt urb messages properly (Greg Kroah-Hartman) - can: usb: etas_es58x: correctly anchor the urb in the read bulk callback (Greg Kroah-Hartman) - can: ucan: Fix infinite loop from zero-length messages (Greg Kroah-Hartman) - can: usb: f81604: correctly anchor the urb in the read bulk callback (Greg Kroah-Hartman) - can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message (Greg Kroah-Hartman) [Orabug: 39130814] {CVE-2026-23307} - net: usb: pegasus: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130748] {CVE-2026-23290} - net: usb: kalmia: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130996] {CVE-2026-23365} - net: usb: kaweth: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130831] {CVE-2026-23312} - nfc: pn533: properly drop the usb interface reference on disconnect (Greg Kroah-Hartman) - media: dvb-core: fix wrong reinitialization of ringbuffer on reopen (Jens Axboe) [Orabug: 39103137] {CVE-2026-23253} - namespace: fix proc mount iteration (Christian Brauner) - eventpoll: Fix integer overflow in ep_loop_check_proc() (Jann Horn) - net: arcnet: com20020-pci: fix support for 2.5Mbit cards (Ethan Nelson-Moore) - ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314 (Takashi Iwai) - ALSA: hda/realtek: Add quirk for Samsung Galaxy Book3 Pro 360 (NP965QFG) (Lewis Mason) - ALSA: hda/realtek: Add quirk for Gigabyte G5 KF5 (2023) (Eric Naim) - LoongArch: Remove some extern variables in source files (Tiezhu Yang) - LoongArch: Handle percpu handler address for ORC unwinder (Tiezhu Yang) - LoongArch: Remove unnecessary checks for ORC unwinder (Tiezhu Yang) - LoongArch/orc: Use RCU in all users of __module_address(). (Sebastian Andrzej Siewior) - ksmbd: add chann_lock to protect ksmbd_chann_listxarray (Namjae Jeon) - ksmbd: check return value of xa_store() in krb5_authenticate (Namjae Jeon) - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (Gui-Dong Han) - ALSA: hda/conexant: Add quirk for HP ZBook Studio G4 (Takashi Iwai) - drm/amd: Fix hang on amdgpu unload by using pci_dev_is_disconnected() (Mario Limonciello) - usb: cdns3: fix role switching during resume (Thomas Richard) - usb: cdns3: call cdns_power_is_lost() only once in cdns_resume() (Théo Lebrun) - usb: cdns3: remove redundant if branch (Hongyu Xie) - btrfs: zoned: fixup last alloc pointer after extent removal for RAID0/10 (Naohiro Aota) - btrfs: define the AUTO_KFREE/AUTO_KVFREE helper macros (Miquel Sabaté Solà) - btrfs: zoned: fix stripe width calculation (Naohiro Aota) - btrfs: zoned: fixup last alloc pointer after extent removal for DUP (Naohiro Aota) - btrfs: zoned: fixup last alloc pointer after extent removal for RAID1 (Naohiro Aota) - btrfs: zoned: fix alloc_offset calculation for partly conventional block groups (Johannes Thumshirn) - btrfs: fix periodic reclaim condition (Sun Yangkai) - btrfs: fix reclaimed bytes accounting after automatic block group reclaim (Filipe Manana) - btrfs: get used bytes while holding lock at btrfs_reclaim_bgs_work() (Filipe Manana) - btrfs: drop unused parameter fs_info from do_reclaim_sweep() (David Sterba) - uprobes: Fix incorrect lockdep condition in filter_chain() (Breno Leitao) - uprobes: switch to RCU Tasks Trace flavor for better performance (Andrii Nakryiko) - drm/exynos: vidi: use ctx-> lock to protect struct vidi_context member variables related to memory alloc/free (Jeongjun Park) - drm/exynos/vidi: Remove redundant error handling in vidi_get_modes() (Xu Wang) - drm/exynos: vidi: fix to avoid directly dereferencing user pointer (Jeongjun Park) - ima: kexec: define functions to copy IMA log at soft boot (Steven Chen) - kexec: define functions to map and unmap segments (Steven Chen) - ima: define and call ima_alloc_kexec_file_buf() (Steven Chen) - ima: renamevariable the seq_file "file" to "ima_kexec_file" (Steven Chen) - ima: kexec: silence RCU list traversal warning (Breno Leitao) - clk: tegra: tegra124-emc: fix device leak on set_rate() (Johan Hovold) - arm64: dts: rockchip: Fix rk3588 PCIe range mappings (Shawn Lin) - arm64: dts: rockchip: Fix rk356x PCIe range mappings (Shawn Lin) - iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (Jinhui Guo) [Orabug: 39331474] {CVE-2026-43161} - Input: synaptics_i2c - guard polling restart in resume (Minseong Kim) - Input: synaptics_i2c - replace use of system_wq with system_dfl_wq (Marco Crivellari) - workqueue: Add system_percpu_wq and system_dfl_wq (Marco Crivellari) - ext4: always allocate blocks only from groups inode can use (Jan Kara) - ext4: implement linear-like traversal across order xarrays (Baokun Li) - ext4: refactor choose group to scan group (Baokun Li) - ext4: convert free groups order lists to xarrays (Baokun Li) - ext4: factor out ext4_mb_scan_group() (Baokun Li) - ext4: factor out ext4_mb_might_prefetch() (Baokun Li) - ext4: factor out __ext4_mb_scan_group() (Baokun Li) - ext4: add ext4_try_lock_group() to skip busy groups (Baokun Li) - mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (Joonwon Kang) [Orabug: 39331965] {CVE-2026-43281} - mailbox: Allow controller specific mapping using fwnode (Anup Patel) - mailbox: Use guard/scoped_guard for con_mutex (Peng Fan) - mailbox: Use dev_err when there is error (Peng Fan) - mailbox: remove unused header files (Tudor Ambarus) - mailbox: sort headers alphabetically (Tudor Ambarus) - mailbox: don't protect of_parse_phandle_with_args with con_mutex (Tudor Ambarus) - ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (Zhang Yi) [Orabug: 39452050] {CVE-2026-45985} - ext4: correct the comments place for EXT4_EXT_MAY_ZEROOUT (Yangerkun) - drm/tegra: dsi: fix device leak on probe (Johan Hovold) - ata: libata-scsi: avoid Non-NCQ command starvation (Damien Le Moal) [Orabug: 39451561]{CVE-2026-45855} - ata: libata: Introduce ata_port_eh_scheduled() (Damien Le Moal) - ata: libata: Remove ATA_DFLAG_ZAC device flag (Damien Le Moal) - ata: libata-scsi: Remove struct ata_scsi_args (Damien Le Moal) - ata: libata-scsi: Document all VPD page inquiry actors (Damien Le Moal) - ata: libata-scsi: Refactor ata_scsiop_maint_in() (Damien Le Moal) - ata: libata-scsi: Refactor ata_scsiop_read_cap() (Damien Le Moal) - ata: libata-scsi: Refactor ata_scsi_simulate() (Damien Le Moal) - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (Sean Christopherson) [Orabug: 39331893] {CVE-2026-43265} - media: dw9714: Fix powerup sequence (Ricardo Ribalda) - media: dw9714: add support for powerdown pin (Matthias Fend) - media: dw9714: move power sequences to dedicated functions (Matthias Fend) - media: tegra-video: Fix memory leak in __tegra_channel_try_format() (Zilin Guan) - PCI: Use resource_set_range() that correctly sets -> end (Ilpo Järvinen) - resource: Add resource set range and size helpers (Ilpo Järvinen) - Revert "PCI: qcom: Don't wait for link if we can detect Link Up" (Niklas Cassel) - PCI: qcom: Don't wait for link if we can detect Link Up (Krishna Chaitanya Chundru) - Revert "PCI: dw-rockchip: Don't wait for link since we can detect Link Up" (Niklas Cassel) - PCI: dw-rockchip: Don't wait for link since we can detect Link Up (Niklas Cassel) - memory: mtk-smi: fix device leak on larb probe (Johan Hovold) - memory: mtk-smi: fix device leaks on common probe (Johan Hovold) - x86/acpi/boot: Correct acpi_is_processor_usable() check again (Yazen Ghannam) - PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value (Bjorn Helgaas) - bpf: Fix stack-out-of-bounds write in devmap (Kohei Enju) [Orabug: 39130977] {CVE-2026-23359} - bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing (Fuad Tabba) [Orabug: 39131066] {CVE-2026-23383} - btrfs: fix compat mask in error messages in btrfs_check_features() (Mark Harmstone) - btrfs: print correct subvol num if active swapfile prevents deletion(Mark Harmstone) - btrfs: fix warning in scrub_verify_one_metadata() (Mark Harmstone) - btrfs: fix objectid value in error message in check_extent_data_ref() (Mark Harmstone) - btrfs: fix incorrect key offset in error message in check_dev_extent_item() (Mark Harmstone) - ALSA: hda: cs35l56: Fix signedness error in cs35l56_hda_posture_put() (Richard Fitzgerald) - ALSA: pci: hda: use snd_kcontrol_chip() (Kuninori Morimoto) - drm/amdgpu: Fix locking bugs in error paths (Bart Van Assche) - drm/amdgpu: Replace kzalloc + copy_from_user with memdup_user (Thorsten Blum) - drm/amdgpu: Unlock a mutex before destroying it (Bart Van Assche) - PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry (Niklas Cassel) - PCI: dwc: ep: Use align addr function for dw_pcie_ep_raise_{msi,msix}_irq() (Niklas Cassel) - PCI: dwc: endpoint: Implement the pci_epc_ops::align_addr() operation (Damien Le Moal) - PCI: endpoint: Introduce pci_epc_mem_map()/unmap() (Damien Le Moal) - PCI: endpoint: Introduce pci_epc_function_is_valid() (Damien Le Moal) - s390/vtime: Fix virtual timer forwarding (Heiko Carstens) - s390/idle: Fix cpu idle exit cpu time accounting (Heiko Carstens) - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (Peter Zijlstra) [Orabug: 39110643] {CVE-2026-23271} - ALSA: usb-audio: Use inclusive terms (Takashi Iwai) - ALSA: usb-audio: Cap the packet size pre-calculations (Takashi Iwai) - scsi: ufs: core: Move link recovery for hibern8 exit failure to wl_resume (Peter Wang) - cgroup/cpuset: Fix incorrect use of cpuset_update_tasks_cpumask() in update_cpumasks_hier() (Waiman Long) - rseq: Clarify rseq registration rseq_size bound check comment (Mathieu Desnoyers) - x86/fred: Correct speculative safety in fred_extint() (Andrew Cooper) [Orabug: 39130960] {CVE-2026-23354} - ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite devices (Geoffrey D. Bennett) - ALSA: scarlett2: Fix DSP filter control array handling (Geoffrey D. Bennett) - ALSA: scarlett2: Fix redeclaration of loop variable (Geoffrey D.Bennett) - scsi: pm8001: Fix use-after-free in pm8001_queue_command() (Salomon Dushimirimana) [Orabug: 39130811] {CVE-2026-23306} - scsi: lpfc: Properly set WC for DPP mapping (Mathias Krause) - irqchip/sifive-plic: Fix frozen interrupt due to affinity setting (Nam Cao) - KVM: arm64: Hide S1POE from guests when not supported by the host (Fuad Tabba) - drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse() (Felix Gu) - drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (Ian Forbes) [Orabug: 39130850] {CVE-2026-23317} - drm/vmwgfx: Fix invalid kref_put callback in vmw_bo_dirty_release (Brad Spengler) [6.12.0-204.76.1] - uek-rpm: BF3: Enable CONFIG_DMI (Jeremy Tang) [Orabug: 39360834] - kabi: update FIPS kABI files (Saeed Mirzamohammadi) [Orabug: 39334603] - KEYS: Reserve key usage values (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: keep FIPS MPI helpers private (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: keep FIPS compression helpers private (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: keep FIPS helper library symbols private (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: tcrypt - clamp num_mb to avoid divide-by-zero (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: tcrypt - stop ahash speed tests when setkey fails (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: add x86 GHASH CLMUL to FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: add fixed-time AES to FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - fips: add scatterwalk to FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: avoid auto-load for arch specific impls (Saeed Mirzamohammadi) [Orabug: 39334603] - arm64/crypto: wire up FIPS aliases and helpers (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: share alg registry between FIPS and base kernel (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: keep crypto_user out of the FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: tcrypt - skip retest in FIPS mode (Saeed Mirzamohammadi) [Orabug:39334603] - crypto: skip redundant FIPS self-module signature check (Saeed Mirzamohammadi) [Orabug: 39334603] - scripts: fail cleanly on arm64 boot image formats (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto/hkdf: Skip tests with keys too short in FIPS mode (Saeed Mirzamohammadi) [Orabug: 39334603] - uek-rpm: build module symvers before fips140.ko (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: add crc64_rocksoft_generic to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: add keywrap to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: add cts to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto: convert kdf_sp800108 to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 39334603] - fips: drop ansi_cprng and revert ansi_cprng FIPS hooks (Saeed Mirzamohammadi) [Orabug: 39334603] - crypto/testmgr: mark xxhash64 as fips disallowed (Saeed Mirzamohammadi) [Orabug: 39334603] - Revert "fips: add xxhash64-generic to FIPS module" (Saeed Mirzamohammadi) [Orabug: 39334603] - asm-generic/vmlinux.lds.h: remove unreachable FIPS140 branch (Saeed Mirzamohammadi) [Orabug: 39334603] - btrfs: switch to library APIs for checksums (Eric Biggers) [Orabug: 39334603] - lib/crypto: blake2b: Add BLAKE2b library functions (Eric Biggers) [Orabug: 39334603] - byteorder: Add le64_to_cpu_array() and cpu_to_le64_array() (Eric Biggers) [Orabug: 39334603] - iommu/amd: reduce GA Log overflow printk noise (Alejandro Jimenez) [Orabug: 39209026] - iommu/amd: add reschedule points to GA Log draining (Alejandro Jimenez) [Orabug: 39209026] - iommu/amd: Rework GAInt handling in overflow case (Joao Martins) [Orabug: 39209026] - iommu/amd: Use GA Log-aware handler for legacy MSI interrupts (Joao Martins) [Orabug: 39209026] - iommu/amd: Disable GAInt while GA Log is processed (Joao Martins) [Orabug: 39209026] - iommu/amd: Add GA Log-aware primary IRQ handler (Joao Martins) [Orabug: 39209026] - iommu/amd: Allow x2APIC interrupt setup to use primary IRQ handlers (Alejandro Jimenez) [Orabug: 39209026] -iommu/amd: Increase GA Log buffer size to 8192 entries (Joao Martins) [Orabug: 39209026] - iommu/amd: Use core's primary handler and set IRQF_ONESHOT (Sebastian Andrzej Siewior) [Orabug: 39209026] [6.12.0-203.76.5] - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384273,39391434,39407652] {CVE-2026-46333} [6.12.0-203.76.4] - x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218893] {CVE-2025-54518} - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Hyunwoo Kim) [Orabug: 39334587,39356061] {CVE-2026-43500} - rxrpc: Fix conn-level packet handling to unshare RESPONSE packets (David Howells) [Orabug: 39334587,39452112] {CVE-2026-46000} - rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39263367,39334587] {CVE-2026-31676} - rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets (David Howells) [Orabug: 39334587] - rxrpc: Fix potential UAF after skb_unshare() failure (David Howells) [Orabug: 39334587,39452107] {CVE-2026-45998} - rxrpc: Fix re-decryption of RESPONSE packets (David Howells) [Orabug: 39334587,39452067] {CVE-2026-45988} - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334587,39367145] {CVE-2026-43284} - bcm-hsdk-gpl: Fix build issues for HSDK 6.5.34 (Vijay Kumar) [Orabug: 39342234] - bcm-hsdk-gpl: Update BCM HSDK GPL driver to 6.5.34 (Vijay Kumar) [Orabug: 39342234] - minke-fan-cpld: Avoid logging 'unknown fan id' when no fan is present (Arista-Hpandya) [Orabug: 39335238] - exadata: tools: perf: update column to comm_nodigit (Stephen Brennan) [Orabug: 39327035] - perf report: Add comm_nodigit sort key (Stephen Brennan) [Orabug: 39327035] - Revert "tools: perf: add comm_ignore_digit column" (Stephen Brennan) [Orabug: 39327035] - octeontx2-af: cn20k: Fix RVU AF interrupt handler (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Move QMEM allocations from GFP_KERNEL to ATOMIC (Sunil Kovvuri Goutham) [Orabug: 39318904] - bphy-pf: CNF20Ka: poll MHABs based on cpri_maskinstead of fixed count (Viswajith Murali) [Orabug: 39318904] - octeontx2-af: Add devlink param for NIX RQ caching (Nishok A) [Orabug: 39318904] - octeontx2-af: cn20k: Fix the RVUAF-> PF mbox address (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Add devlink and debugfs support for NPA DWRR registers. (Anshumali Gaur) [Orabug: 39318904] - cn20k-af: psw: Fix build warning (Srujana Challa) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix AI review comments. (Ratheesh Kannoth) [Orabug: 39318904] - cn20k-af: psw: add mailbox to write to PSW MSIX registers (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add debugfs support for psw (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: introduce a mailbox to program PSW mbox msix vector (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add PSW AF API Notification queue support (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add FLR handler for PSW (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: setup PSW timed polling structure tables (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add mailbox for PSW PCIe configuration (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add mailbox for PSW LF mapping (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add new mailbox for PSW doorbell configuration (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: setups PSW FID resources (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: setup PSW GID resources (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: add mailbox to get PSW capabilities (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: register PSW AF interrupts (Srujana Challa) [Orabug: 39318904] - cn20k-af: psw: introduce PSW block (Srujana Challa) [Orabug: 39318904] - octeontx2-af: limit max periodic timers for cn20k (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Make default entries as x4. (Ratheesh Kannoth) [Orabug: 39318904] - octeonxt2-af: npc: Fix bugs (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: cn20ka: fix call trace in otx2_unregister_dl() afterkernel reboot. (Anshumali Gaur) [Orabug: 39318904] - octeontx2-pf: cn20ka: fix call trace in otx2vf_remove after kernel reboot. (Anshumali Gaur) [Orabug: 39318904] - octeontx2-af: cn20k: Configure default CPT_AF_UCC_CTL for IPsec error codes (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: CN20k: add support for RFOE4 on half MP (Sai Krishna) [Orabug: 39318904] - octeontx2-pf: Fix kernel crash during eswitch creation (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Use ZERO_OR_NULL_PTR for cgxchan2link_map (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: cn20K: mcs: Add parser configuration for VLAN extraction (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Add support for single SBTAG parsing (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Fix SDP channel base (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20K: mcs: Add MCS DSA tag parsing configuration support (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Avoid any false positives for Altaf (Linu Cherian) [Orabug: 39318904] - octeontx2-af: npc: Fix broadcast MCAM entry type on CN10K (Rakesh Kudurumalla) [Orabug: 39318904] - octeontx2-af: cn20k: Add platform check. (Anshumali Gaur) [Orabug: 39318904] - octeontx2-bphy-netdev: add get_link_ksettings to fix SIOCETHTOOL error (Sai Krishna) [Orabug: 39318904] - octeontx2-af: npc: cn20k: dont free default mcam indexes (Ratheesh Kannoth) [Orabug: 39318904] - bphy-pf: CNF20ka: Replace deprecated MSI-X API in CPRI netdev driver (Viswajith Murali) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix kernel warn. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Mismatch stats. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Dont free PF default mcam indexes. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: FIx invalid access (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: dstats (Ratheesh Kannoth) [Orabug: 39318904] - octeonxt2-af: npc: cn20k: show enable/disable status. (Ratheesh Kannoth) [Orabug: 39318904] -octeontx2-af: npc: cn20k: debugfs for virtual indexes (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix AI reviews (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Alloc default indexes during nix lf alloc (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix default mcam idx free (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: Remove SoC specific local variables. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: mcs: Fix SC resource cleanup loop (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: mcs: Add SC CAM bypass entry (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Modify the pcifunc VF mask (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: cn20k: update the AFPFX_TRIGX reg offset (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20K: Fix rvu mbox registers offset (Geetha Sowjanya) [Orabug: 39318904] - octeontx2: sdp: Display backpressure status in debugfs (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Fix aura BPID assignment when CONFIG_DCB is enabled (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: add bounds check in nix_bp_enable (Rakesh Kudurumalla) [Orabug: 39318904] - octeontx2-af: cn20k: Set a default value for res_meta_offset (Tanmay Jagdale) [Orabug: 39318904] - octeontx2-af: Support mapping of individual slots to RVU block LFs (Subbaraya Sundeep) [Orabug: 39318904] - cn20k-af: ml: improve AF register access control (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: fetch list of LF IDs attached (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: fix using uninitialized partition ID (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: enable mapping LF to partition ID (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: enable mapping LF with partitions (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: support ML lf alloc and free (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: support fetching msix offset for ML (Srikanth Yalavarthi) [Orabug: 39318904] -cn20k-af: ml: support attach and detach of ML LFs (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: add support to fetch ML capabilities (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: implement ML mbox message handler (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: register ML interrupt handlers (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: implement hw resource setup and free (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: enable ML block probe and remove (Srikanth Yalavarthi) [Orabug: 39318904] - cn20k-af: ml: add skeleton code for ML EB driver (Prince Takkar) [Orabug: 39318904] - octeontx2-pf: cn20k: Add CN20K TX SecY policy bit support (Subrat Pandey) [Orabug: 39318904] - octeontx2-af: cn20k: mcs: Set default mcs Id to 0. (Subrat Pandey) [Orabug: 39318904] - octeontx2-af: cn20k: Fix memleak in npc_install flow (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix flags for HWWQE period timers (Mikko Suni) [Orabug: 39318904] - octeontx2-af: cn20k: Use physical address for AF-> PF mbox (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: update fields of CPT_AF_LFX_CTL (Rahul Bhansali) [Orabug: 39318904] - octeontx2-af: cn20k: configure RX inline replay (Shashank Gupta) [Orabug: 39318904] - Octeontx2-af: cn20k: configure inline RQ mask (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: Don't initialize ipsec queues for representor PF. (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-bphy-pf: CNF20ka: BPHY NIC PF driver for chiplet based BPHY NIX bypass mode (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: fix npc mbox structure defination (Mohit Kumar Parjapat) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Avoid SoC specific structures (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix get number of kw (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: cancel work before destroying wq. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx: switch: Fix compiler warnings. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf:selftest: Use unique mbox ids (Linu Cherian) [Orabug: 39318904] - octeontx: pan: Disable WQ after unregister notifier (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Define new flag (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Fix bugs. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Update mcam_idx for reply flow (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Support ovs offloading (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Support mask as well for flow. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Pass tuple mask as well to flow. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Retrieve VLAN infor for L3 routing (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Add vlan tag as part of message (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Dont process events if switchdev is not up (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: make functions static (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Fix graceful shutdown. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Notify switchdev on NF table callback (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Support SNAT/DNAT routing (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Reject acceleration for invalid bridge (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switch: Fix buffer overflow (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switch: Fix below kernel splat (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switchdev: Register for Route events. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switchdev: Forward route notifications. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: switchdev: Add driver support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: switchdev: L2 offload support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: Remove devlink support for SDP VF NIC driver (Anshumali Gaur) [Orabug: 39318904] -octeontx2-af: Handle pool context address update in Aura context write (Ashwin Sekhar T K) [Orabug: 39318904] - octeontx2-af: CN20k: fix unused-function warning (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-pf: Move representor event handling into common file (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Fix Rep link state sync up with PF/VFs (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: npa: cn20k: Fix DPC config mbox (Ashwin Sekhar T K) [Orabug: 39318904] - Octeontx2-pf: Fix transceiver details corruption (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: change GEN PF device ID (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20K: Fetch LBK supported channels (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix limiting SRIOV VF count logic (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-af: Fix KASAN slab-out-of-bounds error (Anshumali Gaur) [Orabug: 39318904] - octeontx2-af: Update irq affinity for mbox and flr (Linu Cherian) [Orabug: 39318904] - octeontx2-af: cn20k: Add FLR/ME support (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Fix possible memleak while mbox init (Sai Krishna) [Orabug: 39318904] - octeontx2-af: Map alternative AF NIX_AF_GINT only for CN10K (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Add support to forward error interrupts to alt AF (Anil Kumar Reddy) [Orabug: 39318904] - octeontx2-af: Add support to forward flr to alternative AF (Anil Kumar Reddy) [Orabug: 39318904] - octeontx2-af: Update Alternative AF status (Linu Cherian) [Orabug: 39318904] - octeontx2-af: cn20k: Cleanup AF interrupt vector (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Do not hardcode AF bus number in debugfs (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Fix rsrc_alloc debugfs file (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Add devlink option to reset MAC stats for debugging (Viswajith Murali) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Add devlink for defrag initiation (Ratheesh Kannoth) [Orabug: 39318904] - net: octeontx2: Fix coding styleissues (Subrat Pandey) [Orabug: 39318904] - octeontx2-af: Fix mcs string buffer size (Stefan Wiehler) [Orabug: 39318904] - octeontx2-af: Skip TM tree print for disabled SQs (Anshumali Gaur) [Orabug: 39318904] - octeontx2-af: debugfs: Add cn20k sdp rings info (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Fix kernel crash during NIX TM register dump (Anshumali Gaur) [Orabug: 39318904] - octeontx2-af: cpt: Add debug support for more than 64 engines. (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: cpt: Update engine offset calculation (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: Add support to display "Autoneg" (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-vf: Set tc filter flag on vf netdev (Suman Ghosh) [Orabug: 39318904] - Octeontx2-pf: Update link mode mapping (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-pf: Fix ethtool eeprom read logic (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: ethtool: Display physical connector type (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: restart interface when link settings are changed by user (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-sdpvf: Fix PTP options for SDP interfaces (Roy Franz) [Orabug: 39318904] - octeontx2-vf: Add partial ethtool support for SDP VFs (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: Add page pool stats to ethtool (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: Add missing changes in otx2_ethtool.c (Suman Ghosh) [Orabug: 39318904] - Octeontx2-pf: tc: fix egress ratelimiting (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: Support to enable EDSA/Higig2 pkts parsing (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: Using compound/head page ref count (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Fix NDC sync operation errors (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: cn20k: fix target address (Juan Garcia) [Orabug: 39318904] - octeontx2-pf: Check address for Null before free (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: mcs: Add soft reset sequence inmcs_global_cfg() (Viswajith Murali) [Orabug: 39318904] - octeontx2-pf: mcs: Don't account field alignment when installing TX SecY policy (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Fix start and end bit for scan config (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2: npc: cn20k: Remove function (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2: npc: cn20k: refactor code (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: cgx: misc changes (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: reset TL1 SW_XOFF before returning from link mode change (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: Remove MAC address validation check (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Show count of dropped packets by DMAC filters (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Update mbox version (Sunil Kovvuri Goutham) [Orabug: 39318904] - cn10k-ipsec: Fix compilation with XFRM_OFFLOAD enabled (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-vf: Register dummy netdev for host PF VFs (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: cn20k: Configure SQ default channel based on UP message (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Dereference only a valid pointer (Suman Ghosh) [Orabug: 39318904] - octeontx2-vf: Fix VF mbox up message error on PTP RX enable (Sai Krishna) [Orabug: 39318904] - octeontx2-pf: Add support for creating netdev interfaces for SDP VFs (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Add more debug messages (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Send UP messages to VF only when VF is up. (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Avoid null pointer dereference (Subbaraya Sundeep) [Orabug: 39318904] - cn10k-ipsec: fix uninitialized send queue during ESP offload (Shashank Gupta) [Orabug: 39318904] - cn10k-ipsec: Initialize ipsec queues on enabling IPsec (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: cn10k/cn20k: Update count_eot in NPA_LF_AURA_BATCH_FREE0 (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: persistnetdev stats across routine operations (Anshumali Gaur) [Orabug: 39318904] - octeontx2-pf: Add self test (Linu Cherian) [Orabug: 39318904] - octeontx2-pf: Add ethtool -m option support (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Skip dma map and unmap when IOMMU is bypassed (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-pf: Add NIXLF error/poison interrupt handlers (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-pf: Validation for TL1 Round robin priority (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: devlink param support to modify physical interface links. (Rakesh Babu Saladi) [Orabug: 39318904] - octeontx2-pf: Add devlink param to vary rbuf size (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Add devlink param to vary cqe size (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: CN20k: add multi chiplet support to NIX path (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k: Enable TX PTP timestamping on BPHY NIX link (Sai Krishna) [Orabug: 39318904] - octeontx2-af: cn10k: Fix accessing invalid CSRs (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k: fix fwdata NULL pointer dereference when RPM probe fails (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k: Map BPHY chiplet RPMs followed by compute chiplet RPMs (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k: Add chiplet RPM AF mbox support for port ready, get channel info messages. (Sai Krishna) [Orabug: 39318904] - octeontx2-af: cnf20k: account for XCB RPM links in CGX link calculation (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: Add support for chiplet based BPHY RPM driver as AF RVU extension block module (Sai Krishna) [Orabug: 39318904] - octeontx2-af: Add BPHY chiplet, RPM, LMAC data to fwdata (Sai Krishna) [Orabug: 39318904] - bphy-pf: CNF20ka: Register driver with PCI subsys ID (Anshumali Gaur) [Orabug: 39318904] - bphy-pf: CNF20ka: Fix MSI-X init failure by setting both DMA masks (Viswajith Murali) [Orabug: 39318904] - bphy-pf: CNF20K: Add build and config support for CPRI PF driver toavoid module conflicts (Viswajith Murali) [Orabug: 39318904] - bphy-pf: CNF20ka: Fix CPRI MSI-X initialization failure (Viswajith Murali) [Orabug: 39318904] - bphy-pf: CNF20ka: Add workaround for gpint issue for CPRI pkt path (Viswajith Murali) [Orabug: 39318904] - bphy-pf: CNF20ka: Add cpri netdev driver support (Viswajith Murali) [Orabug: 39318904] - octeontx-bphy-netdev: Fix unexpected packet in netdev by ensuring proper PSW hardware write handling (Viswajith Murali) [Orabug: 39318904] - octeontx2-bphy-netdev: allow forcing ts steps cnt (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: fix fec counters reporting (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: fix ecpri pkt stats update (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: fix ecpri type5 handling (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: fix a deadlock in cpri (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: Fix race condition for timestamp packets (Sai Krishna) [Orabug: 39318904] - octeontx2-bphy-netdev: Fix kernel crash by using proper max PSM queue count (Sai Krishna) [Orabug: 39318904] - octeontx2-bphy-netdev: protect psm queue access (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: fix debugfs memleak (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: Detect DL circular buffer full (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-bphy-netdev: fix rsfec stats reading (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: Support for eCPRI MsgType5 timestamping (Sai Krishna) [Orabug: 39318904] - octeontx2-bphy-netdev: Use correct netdev priv structure for debugging (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: disable CPRI RX on cleanup (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: ignore mcs untagged error (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: disable rx on RFOEs on exit (Baha Mesleh) [Orabug: 39318904] - octeontx2-bphy-netdev: Fix crash issue during initialization of cpri, rfoe interfaces on set MAC address (Sai Krishna)[Orabug: 39318904] - octeontx2-bphy-netdev: OcteonTX2 Base PHY RFOE netdev driver (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k DPI AF driver msix, interrupt handling (Sai Krishna) [Orabug: 39318904] - octeontx2-af: Move DPI block reset handling to AF extension block driver (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k DPI AF driver channel table mbox support (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k DPI AF driver mbox support (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k DPI AF driver initial support (Sai Krishna) [Orabug: 39318904] - octeontx2-af: cn20k: Don't reset the PF_DISC register (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: CN20K: update RPM links (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: cn20k: Add block discovery register (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Fix PTP RX enable mbox fail issue over NIC VF (Sai Krishna) [Orabug: 39318904] - octeontx2-af: Modify NIX register offset value for CN20K (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Validate NIX maximum LFs correctly (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Fix incorrect BPID initialization for CPT channels (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: Allow CPT PF access to CPT_AF_GRPX_THR (Shashank Gupta) [Orabug: 39318904] - octeontx2-af: cn20k: support packet data buffer (pdb) configuration (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Set LBK channels (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: cn20k: Fix config parameter check when disable inline queue (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Enable CPT parse and Frag info header byte swap (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: Add an MCAM entry to count CPT 2nd pass miss packets (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: support overriding aura to zero for second pass (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-af: cn20k: cpt: Use proper mask to get max CPT LF's (Amit Singh Tomar) [Orabug: 39318904] -octeontx2-af: allow mbox access from CPT VFs for backward compatibility (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: Drop CPT PF/VF check for relevant mboxes (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: Change CPT channels configuration (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Allow CPT PF access to CPTX_AF_CTX_PSP_TIMER_CTL (Shashank Gupta) [Orabug: 39318904] - octeontx2-af: cn20k: change CPT register address as per latest csr (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Allow access to CPT_AF_UCCX_CTL (Tanmay Jagdale) [Orabug: 39318904] - octeontx2-af: CN20K channel configuration (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-af: cn20k: Enable RXC on inline inbound cptlf (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Fix RXC flush and cleanup sequence (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Add CPT CTX flush support (Tanmay Jagdale) [Orabug: 39318904] - octeontx2-af: fix CPT ctx flush (Srujana Challa) [Orabug: 39318904] - octeontx2-af: cn20k: Setup CPT reassembly Queue Configuration Register (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: Move RXC specific functions (Tanmay Jagdale) [Orabug: 39318904] - octeontx2-af: cn20k: handle multi-queue reassembly teardown (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: add mbox for NIX RX inline configuration (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: add mbox for CPT RX inline configuration (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: add mbox for CPT RX queue allocation (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: Add mbox to configure rx inline nixlf (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Add mbox to configure rx inline profile (Bharat Bhushan) [Orabug: 39318904] - crypto: octeontx2: Add new mailbox to set queue priority (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: cn20k: Add rxc teardown support (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Add queue id torxc time config mbox (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: Add cpt stats mailbox support (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: add FLT interrupts (Amit Singh Tomar) [Orabug: 39318904] - octeontx2-af: Unify HW interrupt APIs (Amit Singh Tomar) [Orabug: 39318904] - octeontx-af: cpt: Get CPT PF number using PF Device ID (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: cpt: Update max engine calculation (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: Add TC rules support for CN20K (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh) [Orabug: 39318904] - octeontx2: Fix klockwork issues. (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Free queue memory allocated sq timestamp (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: Check for DMAC extraction support before setting DMAC based hardware filter for a VF (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Move REP devlink APIs to separate file (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Fix representor up notification events (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Use ews_rules value to update REP tcam rules (Geetha Sowjanya) [Orabug: 39318904] - Octeontx2-af: Change args for rvu_get_pf (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Add validation before accessing fwdata (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: map management port always to first PF (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: replace generic error codes (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: link mode mapping (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Assign CGX id from PCI revision id (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Remove MAC address validation check (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: lmac validation with is_lmac_valid (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix compilation warning/klockwork issues (Hariprasad Kelam) [Orabug: 39318904] -octeontx2-af: configure 802.3 pause frames in SGMII/QSGMII mode (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Add new CGX_CMDs to set and get PHY modulation type (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Do not allow VFs to overwrite PKIND config (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Put CGX LMAC also in Higig2 mode (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-sdp: Add FLR interrupts for Host PFs (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-sdp: Refactor SDP interrupts code (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-sdp: Fix SDP channel numbers in NPC rules (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-sdp: Check whether SDP block is present before access (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: sdp: Fix address range assignment logic (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: sdp: Maintain host to RVU GEN PF mapping (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-sdp: misc SDP fixes (Hariprasad Kelam) [Orabug: 39318904] - octeontx-af: cn20k: Manage rings allocation and freeing (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: CN20K: SDP mbox framework (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: CN20K: SDP extension driver (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-pf: enable AF_XDP zero copy support (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix clearing TL3_TL2X_LINKX_CFG[ENA] during SMQ flush to drop packets (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: Fix ROCEV2 RSS hashing QP ID length (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Allow to set CPT result address offset (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: cn20k: add mbox for NIX flow vector configuration (Satheesh Paul A) [Orabug: 39318904] - octeontx2-af: add ROCEv2 header for RSS hashing (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Update lbk maximum frame size as per CN20K (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: fix TX scheduler count (Satha Rao) [Orabug: 39318904] - octeontx2-af:Fix the issue of infinite loop in nix_aq_reset (Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: Misc changes in NIX block (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Dump hw register state on error (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: Add new mailbox to configure LSO alt flags (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: cn20k: Extend SPI to SA index translation (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: notify VF about ptp event (Harman Kalra) [Orabug: 39318904] - octeontx2-af: Sending tsc value to the userspace (Harman Kalra) [Orabug: 39318904] - octeontx2-af: Support for PTP notification to PF (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: npa: fix DPC permit register access (Ashwin Sekhar T K) [Orabug: 39318904] - octeontx2-af: npa: cn20k: Add DPC support (Linu Cherian) [Orabug: 39318904] - octeontx2-af: npa: cn20k: Add debugfs support for Halo (Linu Cherian) [Orabug: 39318904] - octeontx2-af: npa: cn20k: Add NPA Halo support (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Fix number of entries in the kpu3 cam (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix subbank count (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Fix number of entries in the kpu2 cam (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: add mbox to read default rule (Satheesh Paul A) [Orabug: 39318904] - octeontx2-af: kpu: Input validation check. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: kpu: Fix lodable profile issue (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Convert to C99 flexible array (Anshumali Gaur) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Restore stats in defrag (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Flow delete and free mbox (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Add traces in NPC mailboxes (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix KPU9 state variable for ROCEV2 (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: add support for ROCEv2 header parsing (Kiran Kumar K) [Orabug:39318904] - octeontx2-af: add more VLAN tag parsing in case of E-tag (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: add changes to fragment flags for cn20k (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Avoid updating cn10k registers during cn20k reboot (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Do not access match stats for cn20k (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: cn20k: Update NPC CSRs (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix out of bound access in entry2counter array (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Fix initialization of mcam's entry2target_pffunc field (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: add changes to fragment flag extraction in parse nibble (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Fix CPT CGX channel mask for cn20k (Sai Krishna) [Orabug: 39318904] - octeontx2-af: add changes to fragment flag in KPU profile for CN20K (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: fix mcam hit counter (Satheesh Paul A) [Orabug: 39318904] - Revert "octeontx2-af: npc: cn20k: Get base steer rule index." (Rahul Bhansali) [Orabug: 39318904] - octeontx2-af: npc: cn20k: fix rule type for LBK VF (Rahul Bhansali) [Orabug: 39318904] - octeontx2-af: Fix failed to load custom pfl warning (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: add changes to update CPT pad length offset in KPU (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix search order (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: Use dev_dbg() (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Fix compilation warnings (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2: cn20k: npc: Set action2 for x2 entries. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: cn20k: Enable action2 programming in npc (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Set default profile DYNAMIC (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix csr register field offset. (Satheesh Paul A) [Orabug: 39318904] - octeontx2-af:npc: cn20k: Reject request for x4 entries in x2 profile. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Alloc mcam entry for install flow (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Disable fw load faiure warning (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Load custom kpu profile from filesystem. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix install flow priority (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: cn20k: Add support for custom mkex profiles (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Get base steer rule index. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Stats support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: cn20k: Reject mcam alloc mbox with invalid keytype (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-pf: cn20k: Reserve x4 key mcam entries for ntuple (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Get kex related info from PF. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Fix parse result nibble mask reading. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: Set correct nibble bits for cn20k (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix parse nibble mask (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: cn20k: Avoid accessing cn10k registers (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: cn20k: Add new mailboxes for CN20K silicon (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix npc_mcam_get_hit_status mbox for cn10k (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Convert vidx to mcam_idx in mbox handler (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Add an mbox interface to defrag (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: defragmentation support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Introduce virtual mcam index (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Validate mcam index before enable/disable (Ratheesh Kannoth)[Orabug: 39318904] - octeontx2-af: npc: cn20k: Add new mailboxes to get kex config and free counts (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Use common APIs to read/write/copy/enable mcam entry (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Add a new mbox to read/write MCAM hit status (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: npc: cn20k: debugfs support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Use common APIs to alloc/free/get mcam index. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Allocate default mcam indexes. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Modify alloc entry mailbox (Suman Ghosh) [Orabug: 39318904] - ocetontx2-af: npc: cn20k: MKEX profile support (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: npc: cn20k: KPM profile changes (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: npc: cn20k: Index management. (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2: Fix klockwork issues. (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: Fix Support of FDSA tag (George Cherian) [Orabug: 39318904] - octeontx2-af: Support for FDSA tag (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Adding changes to parse stacked VLANs (Kiran Kumar K) [Orabug: 39318904] - Octeontx2-af: Skip overlap check for SPI field (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix issue with GRE parsing (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Add support to parse more VLAN headers (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Fix issue with IPV6 GRE and multi VLAN (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Add KPU changes to parse fabric path header (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Add few missing changes (Suman Ghosh) [Orabug: 39318904] - octeontx2-af: allow second pass pkts via default ucast entry (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-af: suppress kpu profile loading warning (Harman Kalra) [Orabug: 39318904] - octeontx2-af: use cpt channel mask in flow install path (NithinDabilpuram) [Orabug: 39318904] - octeontx2-af: Add NPC support to filter GTP-U and GTP-C packets based on TEID (Suman Ghosh) [Orabug: 39318904] - octeontx2: cn20k: Assign unique MCS IDs based on PCI enumeration (Subrat Pandey) [Orabug: 39318904] - octeontx2-pf: Choose macsec encryption offload per packet (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: mcs: Use new SCI CAM in hardware (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: mcs: Add devlink parameter to toggle MCS bypass mode (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: mcs: Display port mapped stats for cn20k (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: cn20k: Add MCS LMAC channel and count configuration (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: mcs set mcs id and silicon check (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: Fix mcs tx_sa_map API (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: Add mcs PN threshold support (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: MCS add port configure APIs (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20K: Add MCS parser configuration (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: mcs: Fix mcs register offsets (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: mcs: Fix unsupported secy stats read (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: cn20k: Add MCS support (Linu Cherian) [Orabug: 39318904] - octeontx2-af: mcs: Remove SA stats support (Ratheesh Kannoth) [Orabug: 39318904] - octeontx2-af: cnf10k-b: mcs: Fix stats reg address (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: rvu: enable mcs fips mailboxes (Ankur Dwivedi) [Orabug: 39318904] - octeontx2-af: mcs: add mailboxes for fips (Ankur Dwivedi) [Orabug: 39318904] - octeontx2-af: sso: clear all the sets on init (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: tim: add ring priority support (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af:update TIM interval support (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: moderate SSO AF error interrupts (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: lower TIM bucket skip IRQ log level (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: cn20k: remove GTI clock adjustment (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: cn20k: update xaq aura offset (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: cn20k: cleanup SSO EVA on LF reset (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add SSO HW info mbox (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add SSO AGGR config and stats mbox (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add SSO EVA error interrupts (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: update masks for CN20K resources (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: Fixed compilation warnings (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-af: fix interval flag check (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add TIM hardware info mbox (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add TIM HWWQE mbox support (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: add mbox to capture counters (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: reveal only TIM params that are available (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: add TIM error af interrupt handlers (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: clear state on TIM ring disable (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: disable preemption when enabling TIM (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: account for cycle wraparound (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: prevent TIM register read reorder (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: fix arguments passed to XAQ aura deinit (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: debugfs: fix undefined SSO register access (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: update TIM adjust GTI errata silicons (Shijith Thotton) [Orabug: 39318904] -octeontx2-af: update TIM adjust GTI errata silicons (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: add TIM adjust GTI errata workaround (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: cn10k: devlink params to configure TIM (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: TIM: Set conditional clock always on (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Apply relevant HW issue workarounds for 96xx B0 silicon (Sunil Kovvuri Goutham) [Orabug: 39318904] - octeontx2-af: Add SSO and TIM units support to the AF driver (Pavan Nikhilesh) [Orabug: 39318904] - octeontx2-af: enable rxc with lookaside cpt lf (Vidya Sagar Velumuri) [Orabug: 39318904] - octeontx2-af: fix issue with spitosa table teardown (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-af: fix cflags include paths (Wladislav Wiebe) [Orabug: 39318904] - octeontx2-af: Move out REE mbox messages (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Add generic mbox handler for Eblock (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Use AF extension block interface (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Add RVU AF extension block interface (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Introducing REE block for 98xx (Smadar Fuks) [Orabug: 39318904] - octeontx2-af: fix VF bringup affecting PF promiscous state (Harman Kalra) [Orabug: 39318904] - octeontx2-af: consider mode when using cpt base channel for bp (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-af: Update minimum receive frame size (Sathesh Edara) [Orabug: 39318904] - octeontx2-af: set default min and max rx len for CPT link (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-af: add NIX mbox message to get HW info (Shijith Thotton) [Orabug: 39318904] - octeontx2-af: fix inline inbound IPsec configuration (Srujana Challa) [Orabug: 39318904] - octeontx2-af: support for custom L2 header (Satheesh Paul A) [Orabug: 39318904] - octeontx2-af: fix to get different rq mask (Rakesh Kudurumalla) [Orabug: 39318904] - octeontx2-af: poll for tx link credits before link mode change(Naveen Mamindlapalli) [Orabug: 39318904] - octeontx2-af: Handle physical link state change requests (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Add mbox to alloc/free BPIDs (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Dynamically allocate bpids for CPT and LBK (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Add support for SPI to SA index translation (Kiran Kumar K) [Orabug: 39318904] - octeontx2-af: Update HW workarounds for 96xx C0, 98xx and F95xx B0 chips (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add devlink support to configure TL1 RR_PRIO (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: add support for CPT second pass (Rakesh Kudurumalla) [Orabug: 39318904] - octeontx2-af: add new mbox to support sync cycle on rx path (Satha Rao) [Orabug: 39318904] - octeontx2-af: add support for changing vlan tpid (Nithin Dabilpuram) [Orabug: 39318904] - octeontx2-pf: Fix devm_kcalloc() error checking (Dan Carpenter) [Orabug: 39318904] - octeontx2-pf: Use new bandwidth profiles in receive queue (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Display new bandwidth profiles too in debugfs (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Accommodate more bandwidth profiles for cn20k (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Initialize new NIX SQ context for cn20k (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Initialize cn20k specific aura and pool contexts (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Skip NDC operations for cn20k (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Extend debugfs support for cn20k NPA (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Add cn20k NPA block contexts (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Extend debugfs support for cn20k NIX (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Add cn20k NIX block contexts (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Simplify context writing and reading to hardware (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2: convert to ndo_hwtstamp API (VadimFedorenko) [Orabug: 39318904] - Octeontx2-af: Fix pci_alloc_irq_vectors() return value check (Harshit Mogalapalli) [Orabug: 39318904] - Octeontx2-af: Fix missing error code in cgx_probe() (Harshit Mogalapalli) [Orabug: 39318904] - octeontx2-pf: fix bitmap leak (Bo Sun) [Orabug: 39318904] - octeontx2-vf: fix bitmap leak (Bo Sun) [Orabug: 39318904] - octeontx2-af: Remove unused declarations (Yue Haibing) [Orabug: 39318904] - Octeontx2-af: Fix NIX X2P calibration failures (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-vf: Fix max packet length errors (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-af: Broadcast XON on all channels (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: use unsigned int as iterator for unsigned values (Simon Horman) [Orabug: 39318904] - net: Fix typos (Bjorn Helgaas) [Orabug: 39318904] - Octeontx2-af: Debugfs support for firmware data (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-af: RPM: Update DMA mask (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-af: Disable stale DMAC filters (Subbaraya Sundeep) [Orabug: 39318904] - Octeontx2-af: Add programmed macaddr to RVU pfvf (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix error code in rvu_mbox_init() (Dan Carpenter) [Orabug: 39318904] - Octeontx2-pf: ethtool: support multi advertise mode (Hariprasad Kelam) [Orabug: 39318904] - Octeontx2-af: Introduce mode group index (Hariprasad Kelam) [Orabug: 39318904] - Octeontx-pf: Update SGMII mode mapping (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Fix rvu_mbox_init return path (Subbaraya Sundeep) [Orabug: 39318904] - Octeontx2-pf: Fix Backpresure configuration (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: CN20K mbox implementation between PF-VF (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20K mbox implementation for AF's VF (Sai Krishna) [Orabug: 39318904] - octeontx2-pf: CN20K mbox REQ/ACK implementation for NIC PF (Sai Krishna) [Orabug: 39318904] - octeontx2-af: CN20k mbox to support AF REQ/ACK functionality (Sai Krishna) [Orabug: 39318904] -octeontx2-af: CN20k basic mbox operations and structures (Sai Krishna) [Orabug: 39318904] - octeontx2: Set appropriate PF, VF masks and shifts based on silicon (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Avoid typecasts by simplifying otx2_atomic64_add macro (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: macsec: Get MACSEC capability flag from AF (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Add MACSEC capability flag (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Send Link events one by one (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: NPC: Clear Unicast rule on nixlf detach (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-pf: Avoid adding dcbnl_ops for LBK and SDP vf (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Add tracepoint for NIX_PARSE_S (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2: Add new tracepoint otx2_msg_status (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2: Add pcifunc also to mailbox tracepoints (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: Display names for CPT and UP messages (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-af: convert dev_dbg to tracepoint in mbox (Subbaraya Sundeep) [Orabug: 39318904] - octeontx2-pf: Fix ethtool support for SDP representors (Hariprasad Kelam) [Orabug: 39318904] - net: octeontx2: Use pure PCI devres API (Philipp Stanner) [Orabug: 39318904] - octeontx2-pf: AF_XDP: code clean up (Hariprasad Kelam) [Orabug: 39318904] - octeontx2-af: Remove unused rvu_npc_enable_bcast_entry (Dr. David Alan Gilbert) [Orabug: 39318904] - xfrm: Add explicit dev to .xdo_dev_state_{add,delete,free} (Cosmin Ratiu) [Orabug: 39318904] - octeontx2-pf: handle otx2_mbox_get_rsp errors (Chenyuan Yang) [Orabug: 39318904] - net: octeontx2: Handle XDP_ABORTED and XDP invalid as XDP_DROP (Lorenzo Bianconi) [Orabug: 39318904] - octeontx2-af: mcs: Remove redundant 'flush_workqueue()' calls (Chen Ni) [Orabug: 39318904] - net: octeontx2: Addmetadata support for xdp mode (Lorenzo Bianconi) [Orabug: 39318904] - xfrm: provide common xdo_dev_offload_ok callback implementation (Leon Romanovsky) [Orabug: 39318904] - octeontx2: hide unused label (Arnd Bergmann) [Orabug: 39318904] - octeontx2-pf: AF_XDP zero copy transmit support (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Prepare for AF_XDP (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: Reconfigure RSS table after enabling AF_XDP zerocopy on rx queue (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: AF_XDP zero copy receive support (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: use xdp_return_frame() to free xdp buffers (Suman Ghosh) [Orabug: 39318904] - octeontx2-pf: mcs: Remove dead code and semi-colon from rsrc_name() (Nihar Chaithanya) [Orabug: 39318904] - octeontx2-pf: fix error handling of devlink port in rvu_rep_create() (Harshit Mogalapalli) [Orabug: 39318904] - octeontx2-pf: fix netdev memory leak in rvu_rep_create() (Harshit Mogalapalli) [Orabug: 39318904] - octeontx2-af: fix build regression without CONFIG_DCB (Arnd Bergmann) [Orabug: 39318904] - cn10k-ipsec: Fix compilation error when CONFIG_XFRM_OFFLOAD disabled (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: Fix installation of PF multicast rule (Geetha Sowjanya) [Orabug: 39318904] - cn10k-ipsec: Enable outbound ipsec crypto offload (Bharat Bhushan) [Orabug: 39318904] - cn10k-ipsec: Allow ipsec crypto offload for skb with SA (Bharat Bhushan) [Orabug: 39318904] - cn10k-ipsec: Process outbound ipsec crypto offload (Bharat Bhushan) [Orabug: 39318904] - cn10k-ipsec: Add SA add/del support for outb ipsec crypto offload (Bharat Bhushan) [Orabug: 39318904] - cn10k-ipsec: Init hardware for outbound ipsec crypto offload (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af: Disable backpressure between CPT and NIX (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: Move skb fragment map/unmap to common code (Bharat Bhushan) [Orabug: 39318904] - octeontx2-pf: map skb data as device writeable (Bharat Bhushan) [Orabug: 39318904] - octeontx2-af:Fix SDP MAC link credits configuration (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Fix spelling mistake "reprentator" -> "representor" (Colin Ian King) [Orabug: 39318904] - octeontx2-pf: Adds TC offload support (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Implement offload stats ndo for representors (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add devlink port support (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add representors for sdp MAC (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Configure VF mtu via representor (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add support to sync link state between representor and VFs (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Get VF stats via representor (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Add packet path between representor and VF (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add basic net_device_ops (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Create representor netdev (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: RVU representor driver (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-af: Knobs for NPC default rule counters (Linu Cherian) [Orabug: 39318904] - octeontx2-af: Refactor few NPC mcam APIs (Linu Cherian) [Orabug: 39318904] - octeontx2-pf: Move shared APIs to header file (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Reuse PF max mtu value (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Add new APIs for queue memory alloc/free. (Geetha Sowjanya) [Orabug: 39318904] - octeontx2-pf: Define common API for HW resources configuration (Geetha Sowjanya) [Orabug: 39318904] - net: marvell: use ethtool string helpers (Rosen Penev) [Orabug: 39318904] - uek: kabi: update kABI files for new symbols (Saeed Mirzamohammadi) [Orabug: 39268116] - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167615,39361444] {CVE-2026-31402} - netfilter: nf_tables: always walk all pending catchall elements (Florian Westphal) [Orabug: 39110670,39361449]{CVE-2026-23278} - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira) [Orabug: 39103229,39361451] {CVE-2026-23270} [6.12.0-203.76.3] - sched/deadline: Use revised wakeup rule for dl_server (Peter Zijlstra) - netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [Orabug: 39339273] {CVE-2026-43084} - netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation (Scott Mitchell) - Revert "drm/xe: Switch MMIO interface to take xe_mmio instead of xe_gt" (Sasha Levin) - Revert "drm/xe/mmio: Avoid double-adjust in 64-bit reads" (Sasha Levin) - iommu/amd: Fix ivrs_base memleak in early_amd_iommu_init() (Zhen Ni) [Orabug: 39145066] - iommu/amd: Fix header file (Vasant Hegde) [Orabug: 39145066] - iommu/amd: Preserve default DTE fields when updating Host Page Table Root (Alejandro Jimenez) [Orabug: 39145066] - iommu/amd: Enable support for up to 2K interrupts per function (Kishon Vijay Abraham I) [Orabug: 39145066] - iommu/amd: Rename DTE_INTTABLEN* and MAX_IRQS_PER_TABLE macro (Sairaj Kodilkar) [Orabug: 39145066] - iommu/amd: Replace slab cache allocator with page allocator (Sairaj Kodilkar) [Orabug: 39145066] - iommu/amd: Introduce generic function to set multibit feature value (Sairaj Kodilkar) [Orabug: 39145066] - iommu/amd: Remove amd_iommu_apply_erratum_63() (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Lock DTE before updating the entry with WRITE_ONCE() (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Modify clear_dte_entry() to avoid in-place update (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Introduce helper function get_dte256() (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Modify set_dte_entry() to use 256-bit DTE helpers (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Introduce helper function to update 256-bit DTE (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Introduce struct ivhd_dte_flags to store persistent DTE flags (Suravee Suthikulpanit) [Orabug:39145066] - iommu/amd: Disable AMD IOMMU if CMPXCHG16B feature is not supported (Suravee Suthikulpanit) [Orabug: 39145066] - iommu/amd: Misc ACPI IVRS debug info clean up (Suravee Suthikulpanit) [Orabug: 39145066] - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250685,39331108] {CVE-2026-43078} - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250685] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250685,39300909] {CVE-2026-43033} - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250685] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250685,39452215] {CVE-2026-46028} - crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39250685,39283866,39291972,39292190] {CVE-2026-31431} - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250685] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250685] - iommu/arm-smmu-v3: Handle zeroed A4-2C HTTU override settings (Joao Martins) [Orabug: 39260974] [6.12.0-203.76.2] - Revert "rds: Drop rds conn in connect worker if not in down state." (Vijayendra Suman) [Orabug: 39276980] - uek-rpm/config-aarch64: Enable NVIDIA-recommended Vera-Rubin configs (Vijay Kumar) [Orabug: 39157707] - kselftest/arm64: Add HWCAP test for FEAT_LS64 (Yicong Yang) [Orabug: 39157707] - arm64: Provide basic EL2 setup for FEAT_{LS64, LS64_V} usage at EL0/1 (Yicong Yang) [Orabug: 39157707] - perf: arm_spe: Relax period restriction (Leo Yan) [Orabug: 39157707] - perf/arm_cspmu: Add PMEVFILT2R support (Robin Murphy) [Orabug: 39157707] - ACPI: CPPC: Add IS_OPTIONAL_CPC_REG macro to judge if a cpc_reg is optional (Lifeng Zheng) [Orabug: 39157707] - dt-bindings: gpio: Add Tegra256 support (Prathamesh Shete) [Orabug: 39157707] - perf/arm_cspmu: nvidia: Add revision id matching (BesarWicaksono) [Orabug: 39157707] - arm64: Handle BRBE booting requirements (Anshuman Khandual) [Orabug: 39157707] - arm64: el2_setup.h: Make __init_el2_fgt labels consistent, again (Rob Herring) [Orabug: 39157707] - arm64/gcs: Provide basic EL2 setup to allow GCS usage at EL0 and EL1 (Mark Brown) [Orabug: 39157707] - tools headers arm64: Add NVIDIA Olympus part (Besar Wicaksono) [Orabug: 39157707] - perf arm-spe: Add NVIDIA Olympus to neoverse list (Besar Wicaksono) [Orabug: 39157707] - perf arm_spe: Add CPU variants supporting common data source packet (Leo Yan) [Orabug: 39157707] - arch_topology: Provide a stub topology_core_has_smt() for !CONFIG_GENERIC_ARCH_TOPOLOGY (Yicong Yang) [Orabug: 39157707] - perf: arm_pmuv3: Don't use PMCCNTR_EL0 on SMT cores (Yicong Yang) [Orabug: 39157707] - perf: arm_pmuv3: Factor out PMCCNTR_EL0 use conditions (Yicong Yang) [Orabug: 39157707] - perf/arm_cspmu: nvidia: Add pmevfiltr2 support (Besar Wicaksono) [Orabug: 39157707] - perf/arm_cspmu: Add pmpidr support (Besar Wicaksono) [Orabug: 39157707] - perf/arm_cspmu: Move register definitons to header (Robin Murphy) [Orabug: 39157707] - perf/arm_cspmu: Add callback to reset filter config (Besar Wicaksono) [Orabug: 39157707] - perf/arm_cspmu: Generalise event filtering (Robin Murphy) [Orabug: 39157707] - perf: arm_pmuv3: Add support for the Branch Record Buffer Extension (BRBE) (Rob Herring) [Orabug: 39157707] - arm64/sysreg: Add BRBE registers and fields (Anshuman Khandual) [Orabug: 39157707] - perf: arm_pmu: Move PMUv3-specific data (Mark Rutland) [Orabug: 39157707] - perf: apple_m1: Don't disable counter in m1_pmu_enable_event() (Rob Herring) [Orabug: 39157707] - perf: arm_v7_pmu: Don't disable counter in (armv7|krait_|scorpion_)pmu_enable_event() (Rob Herring) [Orabug: 39157707] - perf: arm_v7_pmu: Drop obvious comments for enabling/disabling counters and interrupts (Rob Herring) [Orabug: 39157707] - perf: arm_pmuv3: Don't disable counter in armv8pmu_enable_event() (Mark Rutland) [Orabug: 39157707] - ACPI: CPPC: Rename EPPconstants for clarity (Sumit Gupta) [Orabug: 39157707] - ACPI: CPPC: Add three functions related to autonomous selection (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Modify cppc_get_auto_sel_caps() to cppc_get_auto_sel() (Lifeng Zheng) [Orabug: 39157707] - cpufreq/amd-pstate: Store the boost numerator as highest perf again (Mario Limonciello) [Orabug: 39157707] - ACPI: CPPC: Refactor register value get and set ABIs (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Add cppc_set_reg_val() (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Extract cppc_get_reg_val_in_pcc() (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Rename cppc_get_perf() to cppc_get_reg_val() (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Optimize cppc_get_perf() (Lifeng Zheng) [Orabug: 39157707] - ACPI: CPPC: Factor out and export per-cpu cppc_perf_ctrs_in_pcc_cpu() (Jie Zhan) [Orabug: 39157707] - ACPI: CPPC: Clean up cppc_perf_caps and cppc_perf_ctrls structs (Sumit Gupta) [Orabug: 39157707] - cpufreq: CPPC: Add generic helpers for sysfs show/store (Sumit Gupta) [Orabug: 39157707] - cpufreq: CPPC: Add support for autonomous selection (Lifeng Zheng) [Orabug: 39157707] - PCI: Add PCI_BRIDGE_NO_ALIAS quirk for ASPEED AST1150 (Nirmoy Das) [Orabug: 39157707] - PCI: Add ASPEED vendor ID to pci_ids.h (Nirmoy Das) [Orabug: 39157707] - i2c: tegra: Add support for SW mutex register (Kartik) [Orabug: 39157707] - i2c: tegra: Use internal reset when reset property is not available (Akhil R) [Orabug: 39157707] - i2c: tegra: Add HS mode support (Akhil R) [Orabug: 39157707] - i2c: tegra: Update Tegra256 timing parameters (Akhil R) [Orabug: 39157707] - i2c: tegra: Use separate variables for fast and fastplus (Akhil R) [Orabug: 39157707] - i2c: tegra: Add Tegra264 support (Akhil R) [Orabug: 39157707] - i2c: tegra: Add Tegra256 support (Akhil R) [Orabug: 39157707] - i2c: tegra: Do not configure DMA if not supported (Kartik) [Orabug: 39157707] - gpio: tegra186: Fix GPIO name collisions for Tegra410 (Kartik) [Orabug: 39157707] - gpio: tegra186: Use generic macrofor port definitions (Kartik) [Orabug: 39157707] - gpio: tegra186: Add support for Tegra410 (Prathamesh Shete) [Orabug: 39157707] - gpio: tegra186: Add support for Tegra256 (Prathamesh Shete) [Orabug: 39157707] - arm64: acpi: Enable ACPI CCEL support (Suzuki K Poulose) [Orabug: 39157707] - arm64: Enable EFI secret area Securityfs support (Suzuki K Poulose) [Orabug: 39157707] - arm64: realm: ioremap: Allow mapping memory as encrypted (Suzuki K Poulose) [Orabug: 39157707] - arm64: Document Arm Confidential Compute (Steven Price) [Orabug: 39157707] - virt: arm-cca-guest: TSM_REPORT support for realms (Sami Mujawar) [Orabug: 39157707] - arm64: Enable memory encrypt for Realms (Suzuki K Poulose) [Orabug: 39157707] - arm64: mm: Avoid TLBI when marking pages as valid (Steven Price) [Orabug: 39157707] - arm64: Enforce bounce buffers for realm DMA (Steven Price) [Orabug: 39157707] - efi: arm64: Map Device with Prot Shared (Suzuki K Poulose) [Orabug: 39157707] - arm64: rsi: Map unprotected MMIO as decrypted (Suzuki K Poulose) [Orabug: 39157707] - arm64: rsi: Add support for checking whether an MMIO is protected (Suzuki K Poulose) [Orabug: 39157707] - arm64: realm: Query IPA size from the RMM (Steven Price) [Orabug: 39157707] - arm64: Detect if in a realm and set RIPAS RAM (Suzuki K Poulose) [Orabug: 39157707] - arm64: rsi: Add RSI definitions (Suzuki K Poulose) [Orabug: 39157707] - PCI/TPH: Add TPH documentation (Wei Huang) [Orabug: 39157707] - PCI/TPH: Add Steering Tag support (Wei Huang) [Orabug: 39157707] - PCI: Add TLP Processing Hints (TPH) support (Wei Huang) [Orabug: 39157707] - sched: Update rq-> avg_idle when a task is moved to an idle CPU (Shubhang Kaushik) [Orabug: 39214522] - arm64: mte: Set TCMA1 whenever MTE is present in the kernel (Carl Worth) [Orabug: 39214522] - x86/CPU: Fix FPDSS on Zen1 (Borislav Petkov) [Orabug: 39241227,39273721] {CVE-2026-31628} - uek-rpm: Enable FWCTL modules for aarch64 (Dave Kleikamp) [Orabug: 39252919] - uek-rpm: CONFIG_INTEL_IOMMU_SCALABLE_MODE_DEFAULT_ON should be set (DaveKleikamp) [Orabug: 39259550] _______________________________________________ El-errata mailing list
An update that solves five vulnerabilities and has one fix can now be installed.. # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22487-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilitiesand has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-477=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-5-1.1 * kernel-livepatch-6_4_0-41-rt-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 . An important update is available for SUSE Linux Kernel RT addressing five security issues vital for system stability.. SUSE Linux, Kernel Security, Important Update, System Patch, Live Patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50294 http://linux.oracle.com/errata/ELSA-2026-50294.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: aarch64: bpftool-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-container-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-container-debug-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-core-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-debug-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-debug-core-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-devel-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-doc-5.15.0-321.202.5.el9uek.noarch.rpm kernel-uek-modules-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek64k-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek64k-core-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek64k-devel-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek64k-modules-5.15.0-321.202.5.el9uek.aarch64.rpm kernel-uek64k-modules-extra-5.15.0-321.202.5.el9uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-5.15.0-321.202.5.el9uek.src.rpm Related CVEs: CVE-2025-38085 CVE-2025-54518 CVE-2026-23270 CVE-2026-31402 CVE-2026-43284 CVE-2026-46300 CVE-2026-46333 Description of changes: [5.15.0-321.202.5] - Revert "ip6_tunnel: Fix usage of skb_vlan_inet_prepare()" (Harshit Mogalapalli) [Orabug: 39476647] - smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463672] [5.15.0-321.202.4] - tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429143] - tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429143] - tun:free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429143] [5.15.0-321.202.3] - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368827] {CVE-2026-46300} - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368827] - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384274] {CVE-2026-46333} - mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD tables using mmu_gather (David Hildenbrand (Red Hat)) [Orabug: 38474901] - Revert "mm/hugetlb: add option to allows disabling CVE-2025-38085 mitigation" (Samasth Norway Ananda) [Orabug: 38474901] - mm/rmap: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat)) [Orabug: 38474901] - mm/hugetlb: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat)) [Orabug: 38474901] - mm/hugetlb: fix hugetlb_pmd_shared() (David Hildenbrand (Red Hat)) [Orabug: 38474901] [5.15.0-321.202.2] - dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler (Guenter Roeck) - Revert "arm64: dts: qcom: sdm845-oneplus: Mark l14a regulator as boot-on" (Sasha Levin) - ip6_tunnel: Fix usage of skb_vlan_inet_prepare() (Ben Hutchings) - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (Gui-Dong Han) - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom (Guenter Roeck) - sched: idle: Make skipping governor callbacks more consistent (Rafael J. Wysocki) - nvmet-tcp: fix use-before-check of sg in bounds validation (Cengiz Can) - remoteproc: mediatek: Unprepare SCP clock during system suspend (Tzung-Bi Shih) - net: openvswitch: Avoid releasing netdev before teardown completes (Toke Høiland-Jørgensen) - ACPI: processor: Fix previous acpi_processor_errata_piix4() fix (Rafael J. Wysocki) - net: hsr: fix VLAN add unwind on slave errors (Luka Gejak) - x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39327141] {CVE-2025-54518} - xfrm: esp: ipv4: fix up flags setting (Greg Kroah-Hartman) [Orabug: 39342679] {CVE-2026-43284} - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39342679] {CVE-2026-43284} - KVM: x86: disable preemption around the call to kvm_arch_vcpu_{un|}blocking (Maxim Levitsky) [Orabug: 39334996] - KVM: Don't block+unblock when halt-polling is successful (Sean Christopherson) [Orabug: 39334996] - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167616] {CVE-2026-31402} - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira) [Orabug: 39103230] {CVE-2026-23270} - exadata: tools: perf: update column to comm_nodigit (Stephen Brennan) [Orabug: 39327019] - perf report: Add comm_nodigit sort key (Stephen Brennan) [Orabug: 39327019] - Revert "tools: perf: add comm_ignore_digit column" (Stephen Brennan) [Orabug: 39327019] [5.15.0-321.202.1] - virtio-net: add cond_resched() to the command waiting loop (Jason Wang) [Orabug: 39291988] - virtio-net: convert rx mode setting to use workqueue (Jason Wang) [Orabug: 39291988] - x86: KVM: Add common feature flag for AMD's PSFD (Sean Christopherson) [Orabug: 35586248] - KVM: x86: Insert "AMD" in KVM_X86_FEATURE_PSFD (Jim Mattson) [Orabug: 35586248] - KVM: x86: Expose Predictive Store Forwarding Disable (Babu Moger) [Orabug: 35586248] - i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174661] [5.15.0-320.202.8] - iommu/arm-smmu-v3: Handle zeroed A4-2C HTTU override settings (Joao Martins) [Orabug: 39186453] - iommu: Move IOMMU_DIRTY_NO_CLEAR define (Shameer Kolothum) [Orabug: 39186453] - iommu/arm-smmu-v3: Enable HTTU for stage1 with io-pgtable mapping (Kunkun Jiang) [Orabug: 39186453] - iommu/arm-smmu-v3: Add support for dirty tracking in domain alloc (Joao Martins) [Orabug: 39186453] - iommu/io-pgtable-arm: Add read_and_clear_dirty() support (Shameer Kolothum) [Orabug: 39186453] - iommu/arm-smmu-v3: Addfeature detection for HTTU (Jean-Philippe Brucker) [Orabug: 39186453] [5.15.0-320.202.7] - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39250686,39331104] {CVE-2026-43077} - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250686,39331109] {CVE-2026-43078} - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250686] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250686,39300910] {CVE-2026-43033} - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250686] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250686] - crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39250686,39283867,39291961] {CVE-2026-31431} - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250686] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250686] - uek-rpm: Enable FWCTL for aarch64 (Dave Kleikamp) [Orabug: 39252913] [5.15.0-320.202.6] - Revert "rds: Drop rds conn in connect worker if not in down state." (Vijayendra Suman) [Orabug: 39277795] - uek-rpm: CONFIG_INTEL_IOMMU_SCALABLE_MODE_DEFAULT_ON should be set (Dave Kleikamp) [Orabug: 39109819] - iommu/vt-d: Disallow dirty tracking if incoherent page walk (Lu Baolu) [Orabug: 39109819] - iommu/vt-d: Set variable intel_dirty_ops to static (Kunwu Chan) [Orabug: 39109819] - iommu/vt-d: Access/Dirty bit support for SS domains (Joao Martins) [Orabug: 39109819] - iommu/amd: reduce GA Log overflow printk noise (Alejandro Jimenez) [Orabug: 39209012] - iommu/amd: add reschedule points to GA Log draining (Alejandro Jimenez) [Orabug: 39209012] - iommu/amd: Rework GAInt handling in overflow case (Joao Martins) [Orabug: 39209012] - iommu/amd: Disable GAInt while GA Log is processed (Joao Martins) [Orabug: 39209012] - iommu/amd: Move helpers to updateIOMMU features to amd_iommu.h (Alejandro Jimenez) [Orabug: 39209012] - iommu/amd: Increase GA Log buffer size to 8192 entries (Joao Martins) [Orabug: 39209012] - x86/CPU: Fix FPDSS on Zen1 (Borislav Petkov) [Orabug: 39241228,39273722] {CVE-2026-31628} [5.15.0-320.202.5] - Revert "PCI: Enable ACS after configuring IOMMU for OF platforms" (Manivannan Sadhasivam) [Orabug: 39187371] - net/handshake: duplicate handshake cancellations leak socket (Scott Mayhew) [Orabug: 38847720] {CVE-2025-68775} - ext4: show 'shutdown' hint when ext4 is forced to shutdown (Baokun Li) [Orabug: 39002346] - ext4: show 'emergency_ro' when EXT4_FLAGS_EMERGENCY_RO is set (Baokun Li) [Orabug: 39002346] - ext4: correct behavior under errors=remount-ro mode (Baokun Li) [Orabug: 39002346] - ext4: add more ext4_emergency_state() checks around sb_rdonly() (Baokun Li) [Orabug: 39002346] - ext4: add ext4_emergency_state() helper function (Baokun Li) [Orabug: 39002346] - ext4: add EXT4_FLAGS_EMERGENCY_RO bit (Baokun Li) [Orabug: 39002346] - ext4: convert EXT4_FLAGS_* defines to enum (Baokun Li) [Orabug: 39002346] - ext4: make ext4_forced_shutdown() take struct super_block (Jan Kara) [Orabug: 39002346] - ipv6: use RCU in ip6_xmit() (Eric Dumazet) [Orabug: 38649062] {CVE-2025-40135} - memfd: move MFD_MF_KEEP_UE_MAPPED flag to higher bit (William Roche) [Orabug: 39109773] - scsi: qla2xxx: Sanitize payload size to prevent member overflow (Jiasheng Jiang) [Orabug: 38930868] {CVE-2026-23059} - bpf: Fix reference count leak in bpf_prog_test_run_xdp() (Tetsuo Handa) [Orabug: 38887702] {CVE-2026-22994} - nfsd: check that server is running in unlock_filesystem (Olga Kornievskaia) [Orabug: 38887682] {CVE-2026-22989} - net/mlx5e: TC, delete flows only for existing peers (Mark Bloch) [Orabug: 38970398] {CVE-2026-23173} - net/handshake: restore destructor on submit failure (Caoping) [Orabug: 38887601] {CVE-2025-71148} - scsi: qla2xxx: Fix improper freeing of purex item (Zilin Guan) [Orabug: 38798929] {CVE-2025-68741} - bnxt_en: Fix XDP_TX path (Michael Chan)[Orabug: 38847684] {CVE-2025-68770} - perf/x86/amd: Check event before enable to avoid GPF (George Kennedy) [Orabug: 38847849] {CVE-2025-68798} - scsi: smartpqi: Fix device resources accessed after device removal (Mike Mcgowen) [Orabug: 38798848] {CVE-2025-68371} - KVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced (Omar Sandoval) [Orabug: 38773579] {CVE-2025-68259} - x86/fpu: Ensure XFD state on signal delivery (Chang S. Bae) [Orabug: 38773165] {CVE-2025-68171} - virtio-net: fix received length check in big packets (Bui Quang Minh) [Orabug: 38737152] {CVE-2025-40292} - ACPI: CPPC: Fix NULL pointer dereference when nosmp is used (Yunhui Cui) [Orabug: 38641284] {CVE-2025-38113} - EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller (Qiuxu Zhuo) [Orabug: 38649173] {CVE-2025-40157} - sunrpc: fix null pointer dereference on zero-length checksum (Lei Lu) [Orabug: 38649042] {CVE-2025-40129} - cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost() (Jinjie Ruan) [Orabug: 38641275] {CVE-2024-53230} - cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw() (Jinjie Ruan) [Orabug: 38641272] {CVE-2024-53231} - vhost: vringh: Fix copy_to_iter return value check (Michael S. Tsirkin) [Orabug: 38592117] {CVE-2025-40056} - crypto: qat - flush misc workqueue during device shutdown (Giovanni Cabiddu) [Orabug: 38401717] {CVE-2025-39721} - vhost: vringh: Modify the return value check (Zhang Jiao) [Orabug: 38592085] {CVE-2025-40051} - virtio-net: fix recursived rtnl_lock() during probe() (Zigit Zo) [Orabug: 38324330] {CVE-2025-38551} - gve: prevent ethtool ops after shutdown (Jordan Rhee) [Orabug: 38401492] {CVE-2025-38735} - KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight (Sean Christopherson) [Orabug: 38254140] {CVE-2025-38455} - net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect (Oleksij Rempel) [Orabug: 38253871] {CVE-2025-38385} - net/mlx5e: Disable MACsec offload for uplink representor profile (Carolina Jubran) [Orabug:38094809] {CVE-2025-38020} - dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (Shuai Xue) [Orabug: 38094794] {CVE-2025-38015} - net/mlx5: Fix ECVF vports unload on shutdown flow (Amir Tzin) [Orabug: 38152903] {CVE-2025-38109} - bnxt: properly flush XDP redirect lists (Yan Zhai) [Orabug: 38175054] {CVE-2025-38246} - eth: bnxt: fix missing ring index trim on error path (Jakub Kicinski) [Orabug: 37937451] {CVE-2025-37873} - net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() (Henry Martin) [Orabug: 37938078] {CVE-2025-37888} - nfsd: fix possible badness in FREE_STATEID (Olga Kornievskaia) [Orabug: 37989102] {CVE-2024-50043} - devlink: fix xa_alloc_cyclic() error handling (Michal Swiatkowski) [Orabug: 37828271] {CVE-2025-22017} [5.15.0-320.202.4] - xsk: fix an integer overflow in xp_create_and_assign_umem() (Gavrilov Ilia) [Orabug: 37828202] {CVE-2025-21997} - RDMA/mlx5: Fix the recovery flow of the UMR QP (Yishai Hadas) [Orabug: 37766306] {CVE-2025-21892} - misc: misc_minor_alloc to use ida for all dynamic/misc dynamic minors (Vimal Agrawal) [Orabug: 37678552] {CVE-2024-58078} - net/sched: cls_api: fix error handling causing NULL dereference (Pierre Riteau) [Orabug: 37702083] {CVE-2025-21857} - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() (Shigeru Yoshida) [Orabug: 37766220] {CVE-2025-21867} - net: xdp: Disallow attaching device-bound programs in generic mode (Toke Høiland-Jørgensen) [Orabug: 37650238] {CVE-2025-21808} - iommufd/iova_bitmap: Fix shift-out-of-bounds in iova_bitmap_offset_to_index() (Qasim Ijaz) [Orabug: 37649891] {CVE-2025-21724} - xfrm: delete intermediate secpath entry in packet offload mode (Alexandre Cassen) [Orabug: 37649866] {CVE-2025-21720} - gpiolib: Fix crash on error in gpiochip_get_ngpios() (Andy Shevchenko) [Orabug: 37650154] {CVE-2025-21783} - scsi: mpi3mr: Fix possible crash when setting up bsg fails (Guixin Liu) [Orabug: 37649886] {CVE-2025-21723} - uek-rpm: Enable CONFIG_NET_VRF in container kernel (Boris Ostrovsky) [Orabug:38932706] - Documentation: add documentation for MFD_MF_KEEP_UE_MAPPED (William Roche) [Orabug: 38768951] - selftests/mm: test userspace MFR for HugeTLB hugepage (William Roche) [Orabug: 38768951] - mm: memfd/hugetlb: introduce memfd-based userspace MFR policy (William Roche) [Orabug: 38768951] _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # perl-CryptX-0.89.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10773-1 Rating: moderate Cross-References: * CVE-2026-41564 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the perl-CryptX-0.89.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * perl-CryptX 0.89.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41564.html . An update for openSUSE addresses a moderate risk in perl-CryptX to enhance security and patch issues.. openSUSE Tumbleweed perl-CryptX security update moderate. . LinuxSecurity.com Team
MGASA-2026-0078 - Updated freeipmi packages fix security vulnerability. MGASA-2026-0078 - Updated freeipmi packages fix security vulnerability Publication date: 31 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0078.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-33554 Description: ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. (CVE-2026-33554) References: - https://bugs.mageia.org/show_bug.cgi?id=35293 - https://lists.opensuse.org/archives/list/
An update that solves 155 vulnerabilities, contains one feature and has 35 security fixes can now be installed.. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:1081-1 Release Date: 2026-03-26T13:23:57Z Rating: important References: * bsc#1241345 * bsc#1243055 * bsc#1245728 * bsc#1247180 * bsc#1249587 * bsc#1249998 * bsc#1251135 * bsc#1251186 * bsc#1251966 * bsc#1251971 * bsc#1252008 * bsc#1252266 * bsc#1252911 * bsc#1252924 * bsc#1253049 * bsc#1253129 * bsc#1253455 * bsc#1253644 * bsc#1253691 * bsc#1254214 * bsc#1254306 * bsc#1254992 * bsc#1255084 * bsc#1255129 * bsc#1255265 * bsc#1255379 * bsc#1255530 * bsc#1255698 * bsc#1255811 * bsc#1256564 * bsc#1256640 * bsc#1256645 * bsc#1256679 * bsc#1256683 * bsc#1256708 * bsc#1256716 * bsc#1256755 * bsc#1256784 * bsc#1256802 * bsc#1256863 * bsc#1257159 * bsc#1257179 * bsc#1257209 * bsc#1257228 * bsc#1257231 * bsc#1257246 * bsc#1257279 * bsc#1257332 * bsc#1257466 * bsc#1257472 * bsc#1257473 * bsc#1257552 * bsc#1257553 * bsc#1257554 * bsc#1257556 * bsc#1257557 * bsc#1257559 * bsc#1257560 * bsc#1257562 * bsc#1257570 * bsc#1257573 * bsc#1257576 * bsc#1257579 * bsc#1257580 * bsc#1257586 * bsc#1257635 * bsc#1257679 * bsc#1257687 * bsc#1257704 * bsc#1257706 * bsc#1257707 * bsc#1257709 * bsc#1257714 * bsc#1257715 * bsc#1257716 * bsc#1257718 * bsc#1257722 * bsc#1257723 * bsc#1257729 * bsc#1257732 * bsc#1257734 * bsc#1257735 * bsc#1257739 * bsc#1257740 * bsc#1257741 * bsc#1257742 * bsc#1257743 * bsc#1257745 * bsc#1257749 * bsc#1257750 * bsc#1257755 * bsc#1257757 * bsc#1257758 * bsc#1257759 * bsc#1257761 * bsc#1257762 * bsc#1257763 * bsc#1257765 * bsc#1257768 * bsc#1257770 * bsc#1257772 * bsc#1257775 * bsc#1257776 * bsc#1257788 * bsc#1257789 * bsc#1257790 * bsc#1257805 * bsc#1257808 * bsc#1257809 * bsc#1257811 * bsc#1257813 *bsc#1257814 * bsc#1257816 * bsc#1257830 * bsc#1257891 * bsc#1257942 * bsc#1257952 * bsc#1258037 * bsc#1258153 * bsc#1258176 * bsc#1258181 * bsc#1258184 * bsc#1258222 * bsc#1258226 * bsc#1258234 * bsc#1258237 * bsc#1258245 * bsc#1258249 * bsc#1258252 * bsc#1258256 * bsc#1258259 * bsc#1258272 * bsc#1258273 * bsc#1258277 * bsc#1258278 * bsc#1258279 * bsc#1258286 * bsc#1258293 * bsc#1258297 * bsc#1258298 * bsc#1258299 * bsc#1258304 * bsc#1258309 * bsc#1258313 * bsc#1258317 * bsc#1258321 * bsc#1258326 * bsc#1258338 * bsc#1258340 * bsc#1258349 * bsc#1258354 * bsc#1258358 * bsc#1258374 * bsc#1258376 * bsc#1258377 * bsc#1258379 * bsc#1258389 * bsc#1258394 * bsc#1258395 * bsc#1258397 * bsc#1258411 * bsc#1258415 * bsc#1258419 * bsc#1258422 * bsc#1258424 * bsc#1258429 * bsc#1258442 * bsc#1258464 * bsc#1258465 * bsc#1258468 * bsc#1258469 * bsc#1258484 * bsc#1258517 * bsc#1258518 * bsc#1258519 * bsc#1258520 * bsc#1258524 * bsc#1258544 * bsc#1258660 * bsc#1258824 * bsc#1258832 * bsc#1258849 * bsc#1258850 * bsc#1258860 * bsc#1258928 * bsc#1259070 * bsc#1259130 * bsc#1259558 * bsc#1259580 * bsc#1259857 * jsc#PED-15553 Cross-References: * CVE-2023-53817 * CVE-2025-37861 * CVE-2025-39748 * CVE-2025-39817 * CVE-2025-39964 * CVE-2025-40099 * CVE-2025-40103 * CVE-2025-40201 * CVE-2025-40253 * CVE-2025-68283 * CVE-2025-68295 * CVE-2025-68374 * CVE-2025-68735 * CVE-2025-68736 * CVE-2025-68778 * CVE-2025-68785 * CVE-2025-68810 * CVE-2025-71066 * CVE-2025-71071 * CVE-2025-71104 * CVE-2025-71113 * CVE-2025-71125 * CVE-2025-71126 * CVE-2025-71148 * CVE-2025-71182 * CVE-2025-71184 * CVE-2025-71185 * CVE-2025-71188 * CVE-2025-71189 * CVE-2025-71190 * CVE-2025-71191 * CVE-2025-71192 * CVE-2025-71194 * CVE-2025-71195 * CVE-2025-71196 * CVE-2025-71197 * CVE-2025-71198 * CVE-2025-71199 * CVE-2025-71200 *CVE-2025-71222 * CVE-2025-71224 * CVE-2025-71225 * CVE-2025-71229 * CVE-2025-71231 * CVE-2025-71232 * CVE-2025-71234 * CVE-2025-71235 * CVE-2025-71236 * CVE-2026-22979 * CVE-2026-22982 * CVE-2026-22989 * CVE-2026-22998 * CVE-2026-23003 * CVE-2026-23004 * CVE-2026-23010 * CVE-2026-23017 * CVE-2026-23021 * CVE-2026-23023 * CVE-2026-23026 * CVE-2026-23033 * CVE-2026-23035 * CVE-2026-23037 * CVE-2026-23038 * CVE-2026-23049 * CVE-2026-23053 * CVE-2026-23054 * CVE-2026-23056 * CVE-2026-23057 * CVE-2026-23058 * CVE-2026-23060 * CVE-2026-23061 * CVE-2026-23062 * CVE-2026-23063 * CVE-2026-23064 * CVE-2026-23065 * CVE-2026-23068 * CVE-2026-23069 * CVE-2026-23070 * CVE-2026-23071 * CVE-2026-23073 * CVE-2026-23074 * CVE-2026-23076 * CVE-2026-23078 * CVE-2026-23080 * CVE-2026-23082 * CVE-2026-23083 * CVE-2026-23084 * CVE-2026-23085 * CVE-2026-23086 * CVE-2026-23088 * CVE-2026-23089 * CVE-2026-23090 * CVE-2026-23091 * CVE-2026-23094 * CVE-2026-23095 * CVE-2026-23096 * CVE-2026-23099 * CVE-2026-23101 * CVE-2026-23102 * CVE-2026-23104 * CVE-2026-23105 * CVE-2026-23107 * CVE-2026-23108 * CVE-2026-23110 * CVE-2026-23111 * CVE-2026-23112 * CVE-2026-23113 * CVE-2026-23116 * CVE-2026-23119 * CVE-2026-23121 * CVE-2026-23125 * CVE-2026-23128 * CVE-2026-23129 * CVE-2026-23131 * CVE-2026-23133 * CVE-2026-23135 * CVE-2026-23139 * CVE-2026-23141 * CVE-2026-23145 * CVE-2026-23146 * CVE-2026-23150 * CVE-2026-23151 * CVE-2026-23152 * CVE-2026-23154 * CVE-2026-23155 * CVE-2026-23156 * CVE-2026-23157 * CVE-2026-23163 * CVE-2026-23166 * CVE-2026-23167 * CVE-2026-23169 * CVE-2026-23170 * CVE-2026-23171 * CVE-2026-23172 * CVE-2026-23173 * CVE-2026-23176 * CVE-2026-23178 * CVE-2026-23179 * CVE-2026-23182 * CVE-2026-23190 * CVE-2026-23191 * CVE-2026-23198 * CVE-2026-23202 * CVE-2026-23204 * CVE-2026-23207 * CVE-2026-23208 *CVE-2026-23209 * CVE-2026-23210 * CVE-2026-23213 * CVE-2026-23214 * CVE-2026-23221 * CVE-2026-23222 * CVE-2026-23229 * CVE-2026-23268 * CVE-2026-23269 CVSS scores: * CVE-2023-53817 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2023-53817 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-37861 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-37861 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-37861 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39748 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-39748 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39748 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39817 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39817 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40099 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40099 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-40103 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-40103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40201 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40201 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68283 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68283 (SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-68295 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68374 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68374 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68735 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68735 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68736 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68736 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68778 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68778 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68785 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68785 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2025-68810 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71066 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71071 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2025-71071 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71113 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-71113 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-71113 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71125 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-71125 ( SUSE ): 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-71125 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71148 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71148 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71148 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-71182 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71182 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71184 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71184 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71188 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71188 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71189 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-71189 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-71189 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71190 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-71190 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-71190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71191 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-71191 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-71191 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71192 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-71192 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-71194 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71194 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71195 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71196 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71197 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2025-71198 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71198 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71199 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71199 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71200 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71200 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71200 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71222 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71224 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71224 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71225 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71225 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2025-71225 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2025-71229 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71231 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71231 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71231 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-71232 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71232 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71232 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71234 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71234 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71234 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71235 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71235 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71235 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71236 ( SUSE ): 5.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-71236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71236 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22979 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22982 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22982 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22989 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22989 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22989 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22998 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22998 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22998 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23003 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23003 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23003 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23010 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23010 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23017 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23017 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23017 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23021 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23021 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23023 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2026-23023 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23023 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23026 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23026 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23033 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23033 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23037 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23037 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23038 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23038 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23049 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23053 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23053 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23054 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23056 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23056 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-23057 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23057 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H *CVE-2026-23058 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23058 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23060 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23060 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23060 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23061 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23061 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23062 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23062 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-23062 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23063 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23063 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23064 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23064 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23065 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23068 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23068 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23069 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23069 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23069 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23070 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23070 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23070 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23071 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23071 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23071 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23073 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23074 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23076 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23076 ( SUSE ): 5.4 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23078 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23078 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23078 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23080 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23082 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23082 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23083 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23084 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23084 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23086 ( SUSE ): 6.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2026-23086 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-23086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23088 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23088 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23088 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23089 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23089 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23090 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23090 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23091 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23091 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23094 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2026-23094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23095 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23095 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23095 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23096 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23096 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23096 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23099 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23099 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23099 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23101 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23101 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23102 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23102 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23104 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23104 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-23104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23105 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23105 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23105 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23107 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23108 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23108 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23108 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23110 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23111 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23111 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23112 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-23112 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23113 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23113 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23113 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23116 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23116 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23119 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23119 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H *CVE-2026-23121 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23121 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23121 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23125 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23128 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23129 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23129 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23129 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23131 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23133 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23133 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-23133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23135 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23135 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-23135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23139 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23139 ( NVD ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23141 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23141 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23141 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23145 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23145 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23146 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23146 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23150 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23150 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23150 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23151 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23151 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23151 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23152 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23152 ( SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23152 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23154 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23155 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23155 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H *CVE-2026-23155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23156 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-23156 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L * CVE-2026-23156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23157 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23157 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23163 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23166 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23167 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23167 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23169 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23169 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-23169 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23170 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23170 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23170 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23171 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23171 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23172 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-23172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-23172 ( NVD): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23173 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23173 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23173 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23176 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23178 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23179 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23182 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23190 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23190 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23191 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23191 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23191 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23198 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23198 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23198 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23202 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23207 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23208 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23208 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23209 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23213 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23213 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23213 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23214 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23214 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23221 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23221 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23222 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-23222 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-23222 ( NVD ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23229 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23269 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 155 vulnerabilities, contains one feature and has 35 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-53817: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() (bsc#1254992). * CVE-2025-37861: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue (bsc#1243055). * CVE-2025-39748: bpf: Forget ranges when refining tnum after JSET (bsc#1249587). * CVE-2025-39817: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (bsc#1249998). * CVE-2025-39964: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (bsc#1251966). * CVE-2025-40099: cifs: parse_dfs_referrals: prevent oob on malformed input (bsc#1252911). * CVE-2025-40103: smb: client:Fix refcount leak for cifs_sb_tlink (bsc#1252924). * CVE-2025-40201: kernel/sys.c: fix the racy usage of task_lock(tsk-> group_leader) in sys_prlimit64() paths (bsc#1253455). * CVE-2025-40253: s390/ctcm: Fix double-kfree (bsc#1255084). * CVE-2025-68283: libceph: replace BUG_ON with bounds check for map-> max_osd (bsc#1255379). * CVE-2025-68295: smb: client: fix memory leak in cifs_construct_tcon() (bsc#1255129). * CVE-2025-68374: md: fix rcu protection in md_wakeup_thread (bsc#1255530). * CVE-2025-68735: drm/panthor: Prevent potential UAF in group creation (bsc#1255811). * CVE-2025-68736: landlock: Fix handling of disconnected directories (bsc#1255698). * CVE-2025-68778: btrfs: don't log conflicting inode if it's a dir moved in the current transaction (bsc#1256683). * CVE-2025-68785: net: openvswitch: fix middle attribute validation in push_nsh() action (bsc#1256640). * CVE-2025-68810: KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot (bsc#1256679). * CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1256645). * CVE-2025-71071: iommu/mediatek: fix use-after-free on probe deferral (bsc#1256802). * CVE-2025-71104: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (bsc#1256708). * CVE-2025-71113: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (bsc#1256716). * CVE-2025-71125: tracing: Do not register unsupported perf events (bsc#1256784). * CVE-2025-71126: mptcp: reset fallback status gracefully at disconnect() time (bsc#1256755). * CVE-2025-71148: net/handshake: restore destructor on submit failure (bsc#1257159). * CVE-2025-71184: btrfs: fix NULL dereference on root when tracing inode eviction (bsc#1257635). * CVE-2025-71194: btrfs: fix deadlock in wait_current_trans() due to ignored transaction type (bsc#1257687). * CVE-2025-71225: md: suspend array while updating raid_disks viasysfs (bsc#1258411). * CVE-2026-22979: net: fix memory leak in skb_segment_list for GRO packets (bsc#1257228). * CVE-2026-22982: net: mscc: ocelot: Fix crash when adding interface under a lag (bsc#1257179). * CVE-2026-22998: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (bsc#1257209). * CVE-2026-23003: geneve: Fix incorrect inner network header offset when innerprotoinherit is set (bsc#1257246). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231). * CVE-2026-23010: ipv6: Fix use-after-free in inet6_addr_del() (bsc#1257332). * CVE-2026-23017: idpf: fix error handling in the init_task on load (bsc#1257552). * CVE-2026-23023: idpf: fix memory leak in idpf_vport_rel() (bsc#1257556). * CVE-2026-23035: net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv (bsc#1257559). * CVE-2026-23053: NFS: Fix a deadlock involving nfs_release_folio() (bsc#1257718). * CVE-2026-23057: vsock/virtio: Coalesce only linear skb (bsc#1257740). * CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen mmio initialization until after multi-tile setup (git- fixes). * drm/xe: Move forcewake to 'gt.pm' substructure (stable-fixes). * drm/xe: Move GSI offset adjustment fields into 'struct xe_mmio' (stable- fixes). * drm/xe: Only toggle scheduling in TDR if GuC is running (stable-fixes). * drm/xe: Populate GT's mmio iomap from tile during init (stable-fixes). * drm/xe: Switch MMIO interface to take xe_mmio instead of xe_gt (stable- fixes). * drm/xe: Switch mmio_ext to use 'struct xe_mmio' (stable-fixes). * drm/xe: Unregister drm device on probe error (git-fixes). * drm: Account property blob allocations to memcg (stable-fixes). * efi: Fix reservation of unaccepted memory table (git-fixes). * efivarfs: fix error propagation in efivar_entry_get() (git-fixes). * ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref (git-fixes). * fbcon: check return value ofcon2fb_acquire_newinfo() (git-fixes). * fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe() (git-fixes). * fbdev: ffb: fix corrupted video output on Sun FFB1 (stable-fixes). * fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (git-fixes). * fbdev: rivafb: fix divide error in nv3_arb() (git-fixes). * fbdev: smscufx: properly copy ioctl memory to kernelspace (stable-fixes). * fbdev: vt8500lcdfb: fix missing dma_free_coherent() (git-fixes). * fpga: dfl: use subsys_initcall to allow built-in drivers to be added (git- fixes). * fpga: of-fpga-region: Fail if any bridge is missing (stable-fixes). * genirq: Set IRQF_COND_ONESHOT in devm_request_irq() (git-fixes). * gpio: aspeed-sgpio: Change the macro to support deferred probe (stable- fixes). * gpio: pca953x: mask interrupts in irq shutdown (stable-fixes). * gpio: sprd: Change sprd_gpio lock to raw_spin_lock (stable-fixes). * gpu/panel-edp: add AUO panel entry for B140HAN06.4 (stable-fixes). * HID: apple: Add "SONiX KN85 Keyboard" to the list of non-apple keyboards (stable-fixes). * HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101) (stable- fixes). * HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK (stable-fixes). * HID: hid-pl: handle probe errors (git-fixes). * HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report() (stable- fixes). * HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients (git- fixes). * HID: intel-ish-hid: Reset enum_devices_done before enumeration (stable- fixes). * HID: intel-ish-hid: Update ishtp bus match to support device ID table (stable-fixes). * HID: logitech-hidpp: Check maxfield in hidpp_get_report_length() (stable- fixes). * HID: magicmouse: Do not crash on missing msc-> input (stable-fixes). * HID: multitouch: add eGalaxTouch EXC3188 support (stable-fixes). * HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL (stable-fixes). * HID: playstation: Add missingcheck for input_ff_create_memless (git-fixes). * HID: playstation: Center initial joystick axes to prevent spurious events (stable-fixes). * HID: prodikeys: Check presence of pm-> input_ep82 (stable-fixes). * HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list (stable- fixes). * hwmon: (f71882fg) Add F81968 support (stable-fixes). * hwmon: (it87) Check the it87_lock() return value (git-fixes). * hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (git-fixes). * hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE (stable-fixes). * hwmon: (occ) Mark occ_init_attribute() as __printf (git-fixes). * hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read (git-fixes). * hyperv: Convert hypercall statuses to linux error codes (git-fixes). * hyperv: Move arch/x86/hyperv/hv_proc.c to drivers/hv (git-fixes). * hyperv: Move hv_current_partition_id to arch-generic code (git-fixes). * i3c: dw: Initialize spinlock to avoid upsetting lockdep (git-fixes). * i3c: master: svc: Initialize 'dev' to NULL in svc_i3c_master_ibi_isr() (stable-fixes). * i3c: master: Update hot-join flag only on success (git-fixes). * i3c: Move device name assignment after i3c_bus_init (git-fixes). * iio: gyro: itg3200: Fix unchecked return value in read_raw (git-fixes). * iio: magnetometer: Remove IRQF_ONESHOT (stable-fixes). * iio: sca3000: Fix a resource leak in sca3000_probe() (git-fixes). * iio: Use IRQF_NO_THREAD (stable-fixes). * Input: stmfts - correct wording for the warning message (git-fixes). * Input: stmfts - make comments correct (git-fixes). * iomap: account for unaligned end offsets when truncating read range (git- fixes). * ipmi: ipmb: initialise event handler read bytes (git-fixes). * ktls, sockmap: Fix missing uncharge operation (bsc#1252008). * KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested VM-Exits (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN)(git-fixes). * KVM: x86: Don't clear async #PF queue when CR0.PG is disabled (e.g. on #SMI) (git-fixes). * KVM: x86: Explicitly set new periodic hrtimer expiration in apic_timer_fn() (git-fixes). * KVM: x86: WARN if hrtimer callback for periodic APIC timer fires with period=0 (git-fixes). * landlock: Optimize file path walks and prepare for audit support (bsc#1255698). * leds: qcom-lpg: Check the return value of regmap_bulk_write() (git-fixes). * media: adv7180: fix frame interval in progressive mode (stable-fixes). * media: amphion: Clear last_buffer_dequeued flag for DEC_CMD_START (stable- fixes). * media: amphion: Drop min_queued_buffers assignment (git-fixes). * media: ccs: Accommodate C-PHY into the calculation (git-fixes). * media: ccs: Avoid possible division by zero (git-fixes). * media: ccs: Fix setting initial sub-device state (git-fixes). * media: chips-media: wave5: Fix memory leak on codec_info allocation failure (git-fixes). * media: cx88: Add missing unmap in snd_cx88_hw_params() (git-fixes). * media: cx23885: Add missing unmap in snd_cx23885_hw_params() (git-fixes). * media: cx25821: Add missing unmap in snd_cx25821_hw_params() (git-fixes). * media: cx25821: Fix a resource leak in cx25821_dev_setup() (stable-fixes). * media: dvb-core: dmxdevfilter must always flush bufs (stable-fixes). * media: dvb-core: fix wrong reinitialization of ringbuffer on reopen (git- fixes). * media: dvb-net: fix OOB access in ULE extension header tables (git-fixes). * media: i2c/tw9903: Fix potential memory leak in tw9903_probe() (git-fixes). * media: i2c/tw9906: Fix potential memory leak in tw9906_probe() (git-fixes). * media: i2c: ov5647: Correct minimum VBLANK value (git-fixes). * media: i2c: ov5647: Correct pixel array offset (git-fixes). * media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode (git-fixes). * media: i2c: ov5647: Initialize subdev before controls (git-fixes). * media: i2c: ov5647: Sensor should report RAW color space(git-fixes). * media: i2c: ov5647: use our own mutex for the ctrl lock (git-fixes). * media: ipu6: Fix RPM reference leak in probe error paths (git-fixes). * media: ipu6: Fix typo and wrong constant in ipu6-mmu.c (git-fixes). * media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove() (git-fixes). * media: mtk-mdp: Fix error handling in probe function (git-fixes). * media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes (stable-fixes). * media: omap3isp: isppreview: always clamp in preview_try_format() (stable- fixes). * media: omap3isp: set initial format (stable-fixes). * media: pvrusb2: fix URB leak in pvr2_send_request_ex (stable-fixes). * media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update() (git-fixes). * media: radio-keene: fix memory leak in error path (git-fixes). * media: rkisp1: Fix filter mode register configuration (stable-fixes). * media: solo6x10: Check for out of bounds chip_id (stable-fixes). * media: tegra-video: Fix memory leak in __tegra_channel_try_format() (git- fixes). * media: uvcvideo: Fix allocation for small frame sizes (git-fixes). * media: v4l2-async: Fix error handling on steps after finding a match (stable-fixes). * media: venus: vdec: fix error state assignment for zero bytesused (git- fixes). * media: verisilicon: AV1: Fix enable cdef computation (git-fixes). * media: verisilicon: AV1: Fix tile info buffer size (git-fixes). * media: verisilicon: AV1: Fix tx mode bit setting (git-fixes). * media: verisilicon: AV1: Set IDR flag for intra_only frame type (git-fixes). * mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() failure (git-fixes). * mfd: core: Add locking around 'mfd_of_node_list' (git-fixes). * mfd: tps6105x: Fix kernel-doc warnings relating to the core struct and tps6105x_mode (git-fixes). * mfd: wm8350-core: Use IRQF_ONESHOT (git-fixes). * misc: bcm_vk: Fix possible null-pointer dereferences in bcm_vk_read() (stable-fixes). * misc:eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66 (stable- fixes). * mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index() (git- fixes). * mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms (git-fixes). * mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse() (git- fixes). * mtd: parsers: ofpart: fix OF node refcount leak in parse_fixed_partitions() (git-fixes). * mtd: rawnand: cadence: Fix return type of CDMA send-and-wait helper (git- fixes). * mtd: rawnand: pl353: Fix software ECC support (git-fixes). * mtd: spinand: Fix kernel doc (git-fixes). * myri10ge: avoid uninitialized variable use (stable-fixes). * net: mana: Fix double destroy_workqueue on service rescan PCI path (git- fixes). * net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). * net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). * net: mana: Support HW link state events (bsc#1253049). * net: nfc: nci: Fix parameter validation for packet data (git-fixes). * net: nfc: nci: Fix zero-length proprietary notifications (git-fixes). * net: usb: catc: enable basic endpoint checking (git-fixes). * net: usb: kalmia: validate USB endpoints (git-fixes). * net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode (git- fixes). * net: usb: kaweth: validate USB endpoints (git-fixes). * net: usb: lan78xx: fix silent drop of packets with checksum errors (git- fixes). * net: usb: lan78xx: fix TX byte statistics for small packets (git-fixes). * net: usb: lan78xx: scan all MDIO addresses on LAN7801 (git-fixes). * net: usb: pegasus: enable basic endpoint checking (git-fixes). * net: usb: r8152: fix transmit queue timeout (stable-fixes). * net: usb: sr9700: remove code to drive nonexistent multicast filter (stable- fixes). * net: usb: sr9700: support devices with virtual driver CD (stable-fixes). * net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean() (git- fixes). * net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets (git-fixes). * nfc: hci: shdlc: Stop timers and work before freeing context (git-fixes). * nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback (git- fixes). * nfc: nci: free skb on nci_transceive early error paths (git-fixes). * nfc: nxp-nci: remove interrupt trigger type (stable-fixes). * nfc: pn533: properly drop the usb interface reference on disconnect (git- fixes). * nfc: rawsock: cancel tx_work before socket teardown (git-fixes). * nfsd: check that server is running in unlock_filesystem (bsc#1257279). * nfsd: use correct loop termination in nfsd4_revoke_states() (git-fixes). * nouveau/dpcd: return EBUSY for aux xfer if the device is asleep (git-fixes). * ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access (stable-fixes). * ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut (stable-fixes). * NTB: ntb_transport: Fix too small buffer for debugfs_name (git-fixes). * nvme-fc: don't hold rport lock when putting ctrl (git-fixes). * nvme-fc: release admin tagset if init fails (git-fixes). * nvme-pci: disable secondary temp for Wodposit WPBSNM8 (git-fixes). * PCI/ACPI: Restrict program_hpx_type2() to AER bits (git-fixes). * PCI/IOV: Fix race between SR-IOV enable/disable and hotplug (git-fixes). * PCI/MSI: Unmap MSI-X region on error (git-fixes). * PCI/MSI: Unmap MSI-X region on error (stable-fixes). * PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails (git- fixes). * PCI/PM: Avoid redundant delays on D3hot-> D3cold (git-fixes). * PCI/portdrv: Fix potential resource leak (git-fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404] (git-fixes). * PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (git-fixes). * PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (stable-fixes). * PCI: Add defines for bridge window indexing (stable-fixes). * PCI: Add PCIE_MSG_CODE_ASSERT_INTx message macros (stable-fixes). * PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value (git-fixes). * PCI: Do not attempt to set ExtTag for VFs (git-fixes). * PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port (git-fixes). * PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port (stable-fixes). * PCI: Enable ACS after configuring IOMMU for OF platforms (git-fixes). * PCI: Enable ACS after configuring IOMMU for OF platforms (stable-fixes). * PCI: endpoint: Fix swapped parameters in pci_{primary/secondary}_epc_epf_unlink() functions (git-fixes). * PCI: Fix pci_slot_lock () device locking (git-fixes). * PCI: Fix pci_slot_lock () device locking (stable-fixes). * PCI: Fix pci_slot_trylock() error handling (git-fixes). * PCI: hv: Correct a comment (git-fixes). * PCI: hv: Fix warnings for missing export.h header inclusion (git-fixes). * PCI: hv: Remove unnecessary flex array in struct pci_packet (git-fixes). * PCI: hv: remove unnecessary module_init/exit functions (git-fixes). * PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). * PCI: Initialize RCB from pci_configure_device() (git-fixes). * PCI: Log bridge info when first enumerating bridge (stable-fixes). * PCI: Log bridge windows conditionally (stable-fixes). * PCI: Mark 3ware-9650SA Root Port Extended Tags as broken (git-fixes). * PCI: Mark ASM1164 SATA controller to avoid bus reset (git-fixes). * PCI: Mark ASM1164 SATA controller to avoid bus reset (stable-fixes). * PCI: Mark Nvidia GB10 to avoid bus reset (git-fixes). * PCI: Mark Nvidia GB10 to avoid bus reset (stable-fixes). * PCI: mediatek: Fix IRQ domain leak when MSI allocation fails (git-fixes). * PCI: Move pci_read_bridge_windows() below individual window accessors (stable-fixes). * PCI: Supply bridge device, not secondary bus, to read window details (stable-fixes). * phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature (stable- fixes). * phy: mvebu-cp110-utmi: fix dr_mode property read from dts (stable-fixes). * pinctrl:equilibrium: Fix device node reference leak in pinbank_init() (git- fixes). * pinctrl: meson: mark the GPIO controller as sleeping (git-fixes). * pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition (git- fixes). * pinctrl: single: fix refcount leak in pcs_add_gpio_func() (git-fixes). * platform/chrome: cros_ec_lightbar: Fix response size initialization (git- fixes). * platform/chrome: cros_typec_switch: Don't touch struct fwnode_handle::dev (git-fixes). * platform/x86/amd/pmc: Add quirk for MECHREVO Wujie 15X Pro (stable-fixes). * platform/x86: classmate-laptop: Add missing NULL pointer checks (stable- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data (git- fixes). * platform/x86: hp-bioscfg: Skip empty attribute names (git-fixes). * platform/x86: int0002: Remove IRQF_ONESHOT from request_irq() (git-fixes). * platform/x86: intel_telemetry: Fix PSS event register mask (git-fixes). * platform/x86: intel_telemetry: Fix swapped arrays in PSS output (git-fixes). * platform/x86: ISST: Add missing write block check (git-fixes). * platform/x86: panasonic-laptop: Fix sysfs group leak in error path (stable- fixes). * platform/x86: toshiba_haps: Fix memory leaks in add/remove routines (git- fixes). * PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races (git- fixes). * PM: sleep: wakeirq: Update outdated documentation comments (git-fixes). * PM: wakeup: Handle empty list in wakeup_sources_walk_start() (git-fixes). * pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong adb400 reset (git-fixes). * power: reset: nvmem-reboot-mode: respect cell size for nvmem_cell_write (git-fixes). * power: supply: ab8500: Fix use-after-free in power_supply_changed() (git- fixes). * power: supply: act8945a: Fix use-after-free in power_supply_changed() (git- fixes). * power: supply: bq27xxx: fix wrong errno when bus ops are unsupported (git- fixes). * power: supply: bq256xx: Fixuse-after-free in power_supply_changed() (git- fixes). * power: supply: bq25980: Fix use-after-free in power_supply_changed() (git- fixes). * power: supply: cpcap-battery: Fix use-after-free in power_supply_changed() (git-fixes). * power: supply: goldfish: Fix use-after-free in power_supply_changed() (git- fixes). * power: supply: qcom_battmgr: Recognize "LiP" as lithium-polymer (git-fixes). * power: supply: rt9455: Fix use-after-free in power_supply_changed() (git- fixes). * power: supply: sbs-battery: Fix use-after-free in power_supply_changed() (git-fixes). * power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed() (git-fixes). * powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version check (git- fixes). * qmi_wwan: allow max_mtu above hard_mtu to control rx_urb_size (git-fixes). * rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net() (git- fixes). * RDMA/mana_ib: Add device-memory support (git-fixes). * RDMA/mana_ib: Take CQ type from the device type (git-fixes). * RDMA/rtrs-clt: For conn rejection use actual err number (git-fixes). * regmap: maple: free entry on mas_store_gfp() failure (stable-fixes). * regulator: core: fix locking in regulator_resolve_supply() error path (git- fixes). * regulator: core: move supply check earlier in set_machine_constraints() (git-fixes). * remoteproc: sysmon: Correct subsys_name_len type in QMI request (git-fixes). * Revert "bpf: xfrm: Add bpf_xdp_get_xfrm_state() kfunc (bsc#1258860). * Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem" (git-fixes). * Revert "drm/nouveau/disp: Set drm_mode_config_funcs.atomic_(check|commit)" (git-fixes). * Revert "hwmon: (ibmpex) fix use-after-free in high/low store" (git-fixes). * Revert "mfd: da9052-spi: Change read-mask to write-mask" (stable-fixes). * Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms" (git- fixes). * Revert "PCI/IOV: Add PCI rescan-remove lockingwhen enabling/disabling SR- IOV" (git-fixes). * Revert "selftests/bpf: Add tc helpers (bsc#1258860). * Revert "selftests/bpf: Remove "&> " usage in the selftests (bsc#1258860). * Revert "selftests/bpf: Remove test_tc_tunnel.sh (bsc#1258860). * Revert "selftests/bpf: Support when CONFIG_VXLAN=m (bsc#1258860). * Revert "selftests/bpf: test_tunnel: Add ping helpers (bsc#1258860). * Revert "selftests/bpf: test_tunnel: Remove test_tunnel.sh (bsc#1258860). * Revert "selftests/bpf: Use make_sockaddr in test_sock_addr (bsc#1258860). * rpmsg: core: fix race in driver_override_show() and use core helper (git- fixes). * rtc: interface: Alarm race handling should not discard preceding error (git- fixes). * rtc: zynqmp: correct frequency value (stable-fixes). * s390/cio: Update purge function to unregister the unused subchannels (bsc#1254214). * s390/ipl: Clear SBP flag when bootprog is set (bsc#1258176). * s390/mm: Fix __ptep_rdp() inline assembly (bsc#1253644). * s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP (bsc#1254306). * scsi: mpi3mr: Event processing debug improvement (bsc#1251186 bsc#1258832). * scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (git-fixes). * scsi: storvsc: Remove redundant ternary operators (git-fixes). * selftests/bpf: Add tc helpers (bsc#1258860). * selftests/bpf: add verifier sign extension bound computation tests (git- fixes). * selftests/bpf: Integrate test_tc_tunnel.sh tests into test_progs (bsc#1258860). * selftests/bpf: Make test_tc_tunnel.bpf.c compatible with big endian platforms (bsc#1258860). * selftests/bpf: Remove "&> " usage in the selftests (bsc#1258860). * selftests/bpf: Remove test_tc_tunnel.sh (bsc#1258860). * selftests/bpf: Support when CONFIG_VXLAN=m (bsc#1258860). * selftests/bpf: test_tunnel: Add generic_attach* helpers (bsc#1258860). * selftests/bpf: test_tunnel: Add ping helpers (bsc#1258860). * selftests/bpf: test_tunnel: Move erspan tunnel tests to test_progs (bsc#1258860). *selftests/bpf: test_tunnel: Move geneve tunnel test to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Move gre tunnel test to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Move ip6erspan tunnel test to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Move ip6geneve tunnel test to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Move ip6gre tunnel test to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Move ip6tnl tunnel tests to test_progs (bsc#1258860). * selftests/bpf: test_tunnel: Remove test_tunnel.sh (bsc#1258860). * selftests/bpf: Use connect_to_addr in test_sock_addr (bsc#1258860). * selftests/bpf: Use log_err in open_netns/close_netns (bsc#1258860). * selftests/bpf: Use make_sockaddr in test_sock_addr (bsc#1258860). * selftests/bpf: Use start_server_addr in test_sock_addr (bsc#1258860). * serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done (git-fixes). * serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done (stable-fixes). * serial: 8250_dw: handle clock enable errors in runtime_resume (git-fixes). * serial: 8250_dw: handle clock enable errors in runtime_resume (stable- fixes). * serial: imx: change SERIAL_IMX_CONSOLE to bool (git-fixes). * serial: SH_SCI: improve "DMA support" prompt (git-fixes). * shrink_slab_memcg: clear_bits of skipped shrinkers (bsc#1256564). * soc: mediatek: svs: Fix memory leak in svs_enable_debug_write() (git-fixes). * soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in cmd_db_dev_probe (git-fixes). * soc: qcom: smem: handle ENOMEM error during probe (git-fixes). * soc: ti: k3-socinfo: Fix regmap leak on probe failure (git-fixes). * soc: ti: pruss: Fix double free in pruss_clk_mux_setup() (git-fixes). * soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded of NUC15) (stable-fixes). * soundwire: intel_ace2x: add SND_HDA_CORE dependency (git-fixes). *spi-geni-qcom: initialize mode related registers to 0 (stable-fixes). * spi-geni-qcom: use xfer-> bits_per_word for can_dma() (stable-fixes). * spi: spi-mem: Limit octal DTR constraints to octal DTR situations (git- fixes). * spi: spi-mem: Limit octal DTR constraints to octal DTR situations (stable- fixes). * spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (git- fixes). * spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (stable- fixes). * spi: spidev: fix lock inversion between spi_lock and buf_lock (git-fixes). * spi: stm32: fix Overrun issue at < 8bpw (stable-fixes). * spi: tegra114: Preserve SPI mode bits in def_command1_reg (git-fixes). * spi: tegra210-quad: Move curr_xfer read inside spinlock (bsc#1257952). * spi: tegra210-quad: Move curr_xfer read inside spinlock (git-fixes). * spi: tegra210-quad: Protect curr_xfer assignment in (bsc#1257952). * spi: tegra210-quad: Protect curr_xfer assignment in tegra_qspi_setup_transfer_one (git-fixes). * spi: tegra210-quad: Protect curr_xfer check in IRQ handler (bsc#1257952). * spi: tegra210-quad: Protect curr_xfer check in IRQ handler (git-fixes). * spi: tegra210-quad: Protect curr_xfer clearing in (bsc#1257952). * spi: tegra210-quad: Protect curr_xfer clearing in tegra_qspi_non_combined_seq_xfer (git-fixes). * spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer (bsc#1257952). * spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer (git- fixes). * spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed (bsc#1257952). * spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed transfer (git-fixes). * spi: tegra: Fix a memory leak in tegra_slink_probe() (git-fixes). * spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe() (git-fixes). * spi: wpcm-fiu: Fix uninitialized res (git-fixes). * spi: wpcm-fiu: Simplify with dev_err_probe() (stable-fixes). * spi:wpcm-fiu: Use devm_platform_ioremap_resource_byname() (stable-fixes). * staging: rtl8723bs: fix memory leak on failure path (stable-fixes). * staging: rtl8723bs: fix missing status update on sdio_alloc_irq() failure (stable-fixes). * staging: rtl8723bs: fix null dereference in find_network (git-fixes). * thermal: int340x: Fix sysfs group leak on DLVR registration failure (stable- fixes). * thermal: intel: x86_pkg_temp_thermal: Handle invalid temperature (git- fixes). * tools/hv: fcopy: Fix irregularities with size of ring buffer (git-fixes). * tools/power cpupower: Reset errno before strtoull() (stable-fixes). * tools/power/x86/intel-speed-select: Fix file descriptor leak in isolate_cpus() (git-fixes). * tools: hv: Enable debug logs for hv_kvp_daemon (git-fixes). * tpm: st33zp24: Fix missing cleanup on get_burstcount() error (git-fixes). * tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure (git- fixes). * uio_hv_generic: Align ring size to system page (git-fixes). * uio_hv_generic: Use correct size for interrupt and monitor pages (git- fixes). * Update "drm/mgag200: fix mgag200_bmc_stop_scanout()" bug number (bsc#1258153 bsc#1258226). * Update "drm/mgag200: fix mgag200_bmc_stop_scanout()" bug number (bsc#1258153). * usb: bdc: fix sleep during atomic (git-fixes). * usb: dwc2: fix resume failure if dr_mode is host (git-fixes). * usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN (git-fixes). * USB: serial: option: add Telit FN920C04 RNDIS compositions (stable-fixes). * usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed PDOs (git- fixes). * watchdog: imx7ulp_wdt: handle the nowayout option (stable-fixes). * wifi: ath9k: debug.h: fix kernel-doc bad lines and struct ath_tx_stats (git- fixes). * wifi: ath9k: fix kernel-doc warnings in common-debug.h (git-fixes). * wifi: ath10k: fix lock protection in ath10k_wmi_event_peer_sta_ps_state_chg() (stable-fixes). * wifi: ath10k: sdio: addmissing lock protection in ath10k_sdio_fw_crashed_dump() (git-fixes). * wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1 (stable-fixes). * wifi: ath11k: Fix failure to connect to a 6 GHz AP (stable-fixes). * wifi: ath12k: fix preferred hardware mode calculation (stable-fixes). * wifi: cfg80211: allow only one NAN interface, also in multi radio (stable- fixes). * wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() (git-fixes). * wifi: cfg80211: Fix bitrate calculation overflow for HE rates (stable- fixes). * wifi: cfg80211: Fix use_for flag update on BSS refresh (git-fixes). * wifi: cfg80211: stop NAN and P2P in cfg80211_leave (git-fixes). * wifi: cfg80211: wext: fix IGTK key ID off-by-one (git-fixes). * wifi: cw1200: Fix locking in error paths (git-fixes). * wifi: iwlegacy: add missing mutex protection in il3945_store_measurement() (stable-fixes). * wifi: iwlegacy: add missing mutex protection in il4965_store_tx_power() (stable-fixes). * wifi: iwlwifi: mvm: check the validity of noa_len (stable-fixes). * wifi: iwlwifi: mvm: pause TCM on fast resume (git-fixes). * wifi: libertas: fix WARNING in usb_tx_block (stable-fixes). * wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration (git- fixes). * wifi: mac80211: collect station statistics earlier when disconnect (stable- fixes). * wifi: mac80211: correctly check if CSA is active (stable-fixes). * wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice (stable- fixes). * wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (git- fixes). * wifi: mac80211: ocb: skip rx_no_sta when interface is not joined (stable- fixes). * wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() (git-fixes). * wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() (git-fixes). * wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() (git-fixes). * wifi: radiotap:reject radiotap with unknown bits (git-fixes). * wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config (git-fixes). * wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add (git-fixes). * wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() (stable- fixes). * wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() (git-fixes). * wifi: rtw88: fix DTIM period handling when conf-> dtim_period is zero (stable-fixes). * wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H (stable-fixes). * wifi: rtw89: 8922a: set random mac if efuse contains zeroes (stable-fixes). * wifi: rtw89: mac: correct page number for CSI response (stable-fixes). * wifi: rtw89: pci: restore LDO setting after device resume (stable-fixes). * wifi: rtw89: ser: enable error IMR after recovering from L1 (stable-fixes). * wifi: rtw89: wow: add reason codes for disassociation in WoWLAN mode (stable-fixes). * wifi: wlcore: ensure skb headroom before skb_push (stable-fixes). * wifi: wlcore: Fix a locking bug (git-fixes). * workqueue: mark power efficient workqueue as unbounded if (bsc#1257891). * x86/hyperv: fix an indentation issue in mshyperv.h (git-fixes). * x86/hyperv: Fix usage of cpu_online_mask to get valid cpu (git-fixes). * x86/hyperv: Fix warnings for missing export.h header inclusion (git-fixes). * x86/hyperv: Use named operands in inline asm (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1081=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1081=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-1081=1 * PublicCloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-1081=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-1081=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1081=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-1081=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. ## Package List: * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-devel-6.4.0-150700.53.34.1 * kernel-64kb-debugsource-6.4.0-150700.53.34.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.34.1 * kernel-64kb-debuginfo-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.34.1.150700.17.23.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.34.1 * kernel-default-devel-debuginfo-6.4.0-150700.53.34.1 * kernel-default-debuginfo-6.4.0-150700.53.34.1 * kernel-default-devel-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (noarch) * kernel-devel-6.4.0-150700.53.34.1 * kernel-macros-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.34.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debugsource-6.4.0-150700.53.34.1 * kernel-zfcpdump-debuginfo-6.4.0-150700.53.34.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.34.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.34.1 *kernel-obs-build-debugsource-6.4.0-150700.53.34.1 * kernel-syms-6.4.0-150700.53.34.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.34.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.34.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.34.1 * reiserfs-kmp-default-6.4.0-150700.53.34.1 * kernel-default-debuginfo-6.4.0-150700.53.34.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.34.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.34.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-debugsource-6.4.0-150700.53.34.1 * kernel-azure-debuginfo-6.4.0-150700.53.34.1 * kernel-azure-devel-6.4.0-150700.53.34.1 * kernel-azure-devel-debuginfo-6.4.0-150700.53.34.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.34.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.34.1 * cluster-md-kmp-default-6.4.0-150700.53.34.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.34.1 * ocfs2-kmp-default-6.4.0-150700.53.34.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.34.1 * gfs2-kmp-default-6.4.0-150700.53.34.1 * dlm-kmp-default-6.4.0-150700.53.34.1 * kernel-default-debuginfo-6.4.0-150700.53.34.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.34.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.34.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.34.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-debugsource-6.4.0-150700.53.34.1 * kernel-default-extra-debuginfo-6.4.0-150700.53.34.1 * kernel-default-extra-6.4.0-150700.53.34.1 * kernel-default-debuginfo-6.4.0-150700.53.34.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) *kernel-default-6.4.0-150700.53.34.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.34.1 * kernel-default-livepatch-6.4.0-150700.53.34.1 * kernel-livepatch-SLE15-SP7_Update_10-debugsource-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.34.1 * kernel-livepatch-6_4_0-150700_53_34-default-1-150700.15.3.1 * kernel-default-debuginfo-6.4.0-150700.53.34.1 * kernel-livepatch-6_4_0-150700_53_34-default-debuginfo-1-150700.15.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53817.html * https://www.suse.com/security/cve/CVE-2025-37861.html * https://www.suse.com/security/cve/CVE-2025-39748.html * https://www.suse.com/security/cve/CVE-2025-39817.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40099.html * https://www.suse.com/security/cve/CVE-2025-40103.html * https://www.suse.com/security/cve/CVE-2025-40201.html * https://www.suse.com/security/cve/CVE-2025-40253.html * https://www.suse.com/security/cve/CVE-2025-68283.html * https://www.suse.com/security/cve/CVE-2025-68295.html * https://www.suse.com/security/cve/CVE-2025-68374.html * https://www.suse.com/security/cve/CVE-2025-68735.html * https://www.suse.com/security/cve/CVE-2025-68736.html * https://www.suse.com/security/cve/CVE-2025-68778.html * https://www.suse.com/security/cve/CVE-2025-68785.html * https://www.suse.com/security/cve/CVE-2025-68810.html * https://www.suse.com/security/cve/CVE-2025-71066.html * https://www.suse.com/security/cve/CVE-2025-71071.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2025-71113.html * https://www.suse.com/security/cve/CVE-2025-71125.html * https://www.suse.com/security/cve/CVE-2025-71126.html * https://www.suse.com/security/cve/CVE-2025-71148.html * https://www.suse.com/security/cve/CVE-2025-71182.html *https://www.suse.com/security/cve/CVE-2025-71184.html * https://www.suse.com/security/cve/CVE-2025-71185.html * https://www.suse.com/security/cve/CVE-2025-71188.html * https://www.suse.com/security/cve/CVE-2025-71189.html * https://www.suse.com/security/cve/CVE-2025-71190.html * https://www.suse.com/security/cve/CVE-2025-71191.html * https://www.suse.com/security/cve/CVE-2025-71192.html * https://www.suse.com/security/cve/CVE-2025-71194.html * https://www.suse.com/security/cve/CVE-2025-71195.html * https://www.suse.com/security/cve/CVE-2025-71196.html * https://www.suse.com/security/cve/CVE-2025-71197.html * https://www.suse.com/security/cve/CVE-2025-71198.html * https://www.suse.com/security/cve/CVE-2025-71199.html * https://www.suse.com/security/cve/CVE-2025-71200.html * https://www.suse.com/security/cve/CVE-2025-71222.html * https://www.suse.com/security/cve/CVE-2025-71224.html * https://www.suse.com/security/cve/CVE-2025-71225.html * https://www.suse.com/security/cve/CVE-2025-71229.html * https://www.suse.com/security/cve/CVE-2025-71231.html * https://www.suse.com/security/cve/CVE-2025-71232.html * https://www.suse.com/security/cve/CVE-2025-71234.html * https://www.suse.com/security/cve/CVE-2025-71235.html * https://www.suse.com/security/cve/CVE-2025-71236.html * https://www.suse.com/security/cve/CVE-2026-22979.html * https://www.suse.com/security/cve/CVE-2026-22982.html * https://www.suse.com/security/cve/CVE-2026-22989.html * https://www.suse.com/security/cve/CVE-2026-22998.html * https://www.suse.com/security/cve/CVE-2026-23003.html * https://www.suse.com/security/cve/CVE-2026-23004.html * https://www.suse.com/security/cve/CVE-2026-23010.html * https://www.suse.com/security/cve/CVE-2026-23017.html * https://www.suse.com/security/cve/CVE-2026-23021.html * https://www.suse.com/security/cve/CVE-2026-23023.html * https://www.suse.com/security/cve/CVE-2026-23026.html * https://www.suse.com/security/cve/CVE-2026-23033.html *https://www.suse.com/security/cve/CVE-2026-23035.html * https://www.suse.com/security/cve/CVE-2026-23037.html * https://www.suse.com/security/cve/CVE-2026-23038.html * https://www.suse.com/security/cve/CVE-2026-23049.html * https://www.suse.com/security/cve/CVE-2026-23053.html * https://www.suse.com/security/cve/CVE-2026-23054.html * https://www.suse.com/security/cve/CVE-2026-23056.html * https://www.suse.com/security/cve/CVE-2026-23057.html * https://www.suse.com/security/cve/CVE-2026-23058.html * https://www.suse.com/security/cve/CVE-2026-23060.html * https://www.suse.com/security/cve/CVE-2026-23061.html * https://www.suse.com/security/cve/CVE-2026-23062.html * https://www.suse.com/security/cve/CVE-2026-23063.html * https://www.suse.com/security/cve/CVE-2026-23064.html * https://www.suse.com/security/cve/CVE-2026-23065.html * https://www.suse.com/security/cve/CVE-2026-23068.html * https://www.suse.com/security/cve/CVE-2026-23069.html * https://www.suse.com/security/cve/CVE-2026-23070.html * https://www.suse.com/security/cve/CVE-2026-23071.html * https://www.suse.com/security/cve/CVE-2026-23073.html * https://www.suse.com/security/cve/CVE-2026-23074.html * https://www.suse.com/security/cve/CVE-2026-23076.html * https://www.suse.com/security/cve/CVE-2026-23078.html * https://www.suse.com/security/cve/CVE-2026-23080.html * https://www.suse.com/security/cve/CVE-2026-23082.html * https://www.suse.com/security/cve/CVE-2026-23083.html * https://www.suse.com/security/cve/CVE-2026-23084.html * https://www.suse.com/security/cve/CVE-2026-23085.html * https://www.suse.com/security/cve/CVE-2026-23086.html * https://www.suse.com/security/cve/CVE-2026-23088.html * https://www.suse.com/security/cve/CVE-2026-23089.html * https://www.suse.com/security/cve/CVE-2026-23090.html * https://www.suse.com/security/cve/CVE-2026-23091.html * https://www.suse.com/security/cve/CVE-2026-23094.html * https://www.suse.com/security/cve/CVE-2026-23095.html *https://www.suse.com/security/cve/CVE-2026-23096.html * https://www.suse.com/security/cve/CVE-2026-23099.html * https://www.suse.com/security/cve/CVE-2026-23101.html * https://www.suse.com/security/cve/CVE-2026-23102.html * https://www.suse.com/security/cve/CVE-2026-23104.html * https://www.suse.com/security/cve/CVE-2026-23105.html * https://www.suse.com/security/cve/CVE-2026-23107.html * https://www.suse.com/security/cve/CVE-2026-23108.html * https://www.suse.com/security/cve/CVE-2026-23110.html * https://www.suse.com/security/cve/CVE-2026-23111.html * https://www.suse.com/security/cve/CVE-2026-23112.html * https://www.suse.com/security/cve/CVE-2026-23113.html * https://www.suse.com/security/cve/CVE-2026-23116.html * https://www.suse.com/security/cve/CVE-2026-23119.html * https://www.suse.com/security/cve/CVE-2026-23121.html * https://www.suse.com/security/cve/CVE-2026-23125.html * https://www.suse.com/security/cve/CVE-2026-23128.html * https://www.suse.com/security/cve/CVE-2026-23129.html * https://www.suse.com/security/cve/CVE-2026-23131.html * https://www.suse.com/security/cve/CVE-2026-23133.html * https://www.suse.com/security/cve/CVE-2026-23135.html * https://www.suse.com/security/cve/CVE-2026-23139.html * https://www.suse.com/security/cve/CVE-2026-23141.html * https://www.suse.com/security/cve/CVE-2026-23145.html * https://www.suse.com/security/cve/CVE-2026-23146.html * https://www.suse.com/security/cve/CVE-2026-23150.html * https://www.suse.com/security/cve/CVE-2026-23151.html * https://www.suse.com/security/cve/CVE-2026-23152.html * https://www.suse.com/security/cve/CVE-2026-23154.html * https://www.suse.com/security/cve/CVE-2026-23155.html * https://www.suse.com/security/cve/CVE-2026-23156.html * https://www.suse.com/security/cve/CVE-2026-23157.html * https://www.suse.com/security/cve/CVE-2026-23163.html * https://www.suse.com/security/cve/CVE-2026-23166.html * https://www.suse.com/security/cve/CVE-2026-23167.html *https://www.suse.com/security/cve/CVE-2026-23169.html * https://www.suse.com/security/cve/CVE-2026-23170.html * https://www.suse.com/security/cve/CVE-2026-23171.html * https://www.suse.com/security/cve/CVE-2026-23172.html * https://www.suse.com/security/cve/CVE-2026-23173.html * https://www.suse.com/security/cve/CVE-2026-23176.html * https://www.suse.com/security/cve/CVE-2026-23178.html * https://www.suse.com/security/cve/CVE-2026-23179.html * https://www.suse.com/security/cve/CVE-2026-23182.html * https://www.suse.com/security/cve/CVE-2026-23190.html * https://www.suse.com/security/cve/CVE-2026-23191.html * https://www.suse.com/security/cve/CVE-2026-23198.html * https://www.suse.com/security/cve/CVE-2026-23202.html * https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-23207.html * https://www.suse.com/security/cve/CVE-2026-23208.html * https://www.suse.com/security/cve/CVE-2026-23209.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23213.html * https://www.suse.com/security/cve/CVE-2026-23214.html * https://www.suse.com/security/cve/CVE-2026-23221.html * https://www.suse.com/security/cve/CVE-2026-23222.html * https://www.suse.com/security/cve/CVE-2026-23229.html * https://www.suse.com/security/cve/CVE-2026-23268.html * https://www.suse.com/security/cve/CVE-2026-23269.html * https://bugzilla.suse.com/show_bug.cgi?id=1241345 * https://bugzilla.suse.com/show_bug.cgi?id=1243055 * https://bugzilla.suse.com/show_bug.cgi?id=1245728 * https://bugzilla.suse.com/show_bug.cgi?id=1247180 * https://bugzilla.suse.com/show_bug.cgi?id=1249587 * https://bugzilla.suse.com/show_bug.cgi?id=1249998 * https://bugzilla.suse.com/show_bug.cgi?id=1251135 * https://bugzilla.suse.com/show_bug.cgi?id=1251186 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1251971 * https://bugzilla.suse.com/show_bug.cgi?id=1252008 *https://bugzilla.suse.com/show_bug.cgi?id=1252266 * https://bugzilla.suse.com/show_bug.cgi?id=1252911 * https://bugzilla.suse.com/show_bug.cgi?id=1252924 * https://bugzilla.suse.com/show_bug.cgi?id=1253049 * https://bugzilla.suse.com/show_bug.cgi?id=1253129 * https://bugzilla.suse.com/show_bug.cgi?id=1253455 * https://bugzilla.suse.com/show_bug.cgi?id=1253644 * https://bugzilla.suse.com/show_bug.cgi?id=1253691 * https://bugzilla.suse.com/show_bug.cgi?id=1254214 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1254992 * https://bugzilla.suse.com/show_bug.cgi?id=1255084 * https://bugzilla.suse.com/show_bug.cgi?id=1255129 * https://bugzilla.suse.com/show_bug.cgi?id=1255265 * https://bugzilla.suse.com/show_bug.cgi?id=1255379 * https://bugzilla.suse.com/show_bug.cgi?id=1255530 * https://bugzilla.suse.com/show_bug.cgi?id=1255698 * https://bugzilla.suse.com/show_bug.cgi?id=1255811 * https://bugzilla.suse.com/show_bug.cgi?id=1256564 * https://bugzilla.suse.com/show_bug.cgi?id=1256640 * https://bugzilla.suse.com/show_bug.cgi?id=1256645 * https://bugzilla.suse.com/show_bug.cgi?id=1256679 * https://bugzilla.suse.com/show_bug.cgi?id=1256683 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1256716 * https://bugzilla.suse.com/show_bug.cgi?id=1256755 * https://bugzilla.suse.com/show_bug.cgi?id=1256784 * https://bugzilla.suse.com/show_bug.cgi?id=1256802 * https://bugzilla.suse.com/show_bug.cgi?id=1256863 * https://bugzilla.suse.com/show_bug.cgi?id=1257159 * https://bugzilla.suse.com/show_bug.cgi?id=1257179 * https://bugzilla.suse.com/show_bug.cgi?id=1257209 * https://bugzilla.suse.com/show_bug.cgi?id=1257228 * https://bugzilla.suse.com/show_bug.cgi?id=1257231 * https://bugzilla.suse.com/show_bug.cgi?id=1257246 * https://bugzilla.suse.com/show_bug.cgi?id=1257279 * https://bugzilla.suse.com/show_bug.cgi?id=1257332 *https://bugzilla.suse.com/show_bug.cgi?id=1257466 * https://bugzilla.suse.com/show_bug.cgi?id=1257472 * https://bugzilla.suse.com/show_bug.cgi?id=1257473 * https://bugzilla.suse.com/show_bug.cgi?id=1257552 * https://bugzilla.suse.com/show_bug.cgi?id=1257553 * https://bugzilla.suse.com/show_bug.cgi?id=1257554 * https://bugzilla.suse.com/show_bug.cgi?id=1257556 * https://bugzilla.suse.com/show_bug.cgi?id=1257557 * https://bugzilla.suse.com/show_bug.cgi?id=1257559 * https://bugzilla.suse.com/show_bug.cgi?id=1257560 * https://bugzilla.suse.com/show_bug.cgi?id=1257562 * https://bugzilla.suse.com/show_bug.cgi?id=1257570 * https://bugzilla.suse.com/show_bug.cgi?id=1257573 * https://bugzilla.suse.com/show_bug.cgi?id=1257576 * https://bugzilla.suse.com/show_bug.cgi?id=1257579 * https://bugzilla.suse.com/show_bug.cgi?id=1257580 * https://bugzilla.suse.com/show_bug.cgi?id=1257586 * https://bugzilla.suse.com/show_bug.cgi?id=1257635 * https://bugzilla.suse.com/show_bug.cgi?id=1257679 * https://bugzilla.suse.com/show_bug.cgi?id=1257687 * https://bugzilla.suse.com/show_bug.cgi?id=1257704 * https://bugzilla.suse.com/show_bug.cgi?id=1257706 * https://bugzilla.suse.com/show_bug.cgi?id=1257707 * https://bugzilla.suse.com/show_bug.cgi?id=1257709 * https://bugzilla.suse.com/show_bug.cgi?id=1257714 * https://bugzilla.suse.com/show_bug.cgi?id=1257715 * https://bugzilla.suse.com/show_bug.cgi?id=1257716 * https://bugzilla.suse.com/show_bug.cgi?id=1257718 * https://bugzilla.suse.com/show_bug.cgi?id=1257722 * https://bugzilla.suse.com/show_bug.cgi?id=1257723 * https://bugzilla.suse.com/show_bug.cgi?id=1257729 * https://bugzilla.suse.com/show_bug.cgi?id=1257732 * https://bugzilla.suse.com/show_bug.cgi?id=1257734 * https://bugzilla.suse.com/show_bug.cgi?id=1257735 * https://bugzilla.suse.com/show_bug.cgi?id=1257739 * https://bugzilla.suse.com/show_bug.cgi?id=1257740 * https://bugzilla.suse.com/show_bug.cgi?id=1257741 *https://bugzilla.suse.com/show_bug.cgi?id=1257742 * https://bugzilla.suse.com/show_bug.cgi?id=1257743 * https://bugzilla.suse.com/show_bug.cgi?id=1257745 * https://bugzilla.suse.com/show_bug.cgi?id=1257749 * https://bugzilla.suse.com/show_bug.cgi?id=1257750 * https://bugzilla.suse.com/show_bug.cgi?id=1257755 * https://bugzilla.suse.com/show_bug.cgi?id=1257757 * https://bugzilla.suse.com/show_bug.cgi?id=1257758 * https://bugzilla.suse.com/show_bug.cgi?id=1257759 * https://bugzilla.suse.com/show_bug.cgi?id=1257761 * https://bugzilla.suse.com/show_bug.cgi?id=1257762 * https://bugzilla.suse.com/show_bug.cgi?id=1257763 * https://bugzilla.suse.com/show_bug.cgi?id=1257765 * https://bugzilla.suse.com/show_bug.cgi?id=1257768 * https://bugzilla.suse.com/show_bug.cgi?id=1257770 * https://bugzilla.suse.com/show_bug.cgi?id=1257772 * https://bugzilla.suse.com/show_bug.cgi?id=1257775 * https://bugzilla.suse.com/show_bug.cgi?id=1257776 * https://bugzilla.suse.com/show_bug.cgi?id=1257788 * https://bugzilla.suse.com/show_bug.cgi?id=1257789 * https://bugzilla.suse.com/show_bug.cgi?id=1257790 * https://bugzilla.suse.com/show_bug.cgi?id=1257805 * https://bugzilla.suse.com/show_bug.cgi?id=1257808 * https://bugzilla.suse.com/show_bug.cgi?id=1257809 * https://bugzilla.suse.com/show_bug.cgi?id=1257811 * https://bugzilla.suse.com/show_bug.cgi?id=1257813 * https://bugzilla.suse.com/show_bug.cgi?id=1257814 * https://bugzilla.suse.com/show_bug.cgi?id=1257816 * https://bugzilla.suse.com/show_bug.cgi?id=1257830 * https://bugzilla.suse.com/show_bug.cgi?id=1257891 * https://bugzilla.suse.com/show_bug.cgi?id=1257942 * https://bugzilla.suse.com/show_bug.cgi?id=1257952 * https://bugzilla.suse.com/show_bug.cgi?id=1258037 * https://bugzilla.suse.com/show_bug.cgi?id=1258153 * https://bugzilla.suse.com/show_bug.cgi?id=1258176 * https://bugzilla.suse.com/show_bug.cgi?id=1258181 * https://bugzilla.suse.com/show_bug.cgi?id=1258184 *https://bugzilla.suse.com/show_bug.cgi?id=1258222 * https://bugzilla.suse.com/show_bug.cgi?id=1258226 * https://bugzilla.suse.com/show_bug.cgi?id=1258234 * https://bugzilla.suse.com/show_bug.cgi?id=1258237 * https://bugzilla.suse.com/show_bug.cgi?id=1258245 * https://bugzilla.suse.com/show_bug.cgi?id=1258249 * https://bugzilla.suse.com/show_bug.cgi?id=1258252 * https://bugzilla.suse.com/show_bug.cgi?id=1258256 * https://bugzilla.suse.com/show_bug.cgi?id=1258259 * https://bugzilla.suse.com/show_bug.cgi?id=1258272 * https://bugzilla.suse.com/show_bug.cgi?id=1258273 * https://bugzilla.suse.com/show_bug.cgi?id=1258277 * https://bugzilla.suse.com/show_bug.cgi?id=1258278 * https://bugzilla.suse.com/show_bug.cgi?id=1258279 * https://bugzilla.suse.com/show_bug.cgi?id=1258286 * https://bugzilla.suse.com/show_bug.cgi?id=1258293 * https://bugzilla.suse.com/show_bug.cgi?id=1258297 * https://bugzilla.suse.com/show_bug.cgi?id=1258298 * https://bugzilla.suse.com/show_bug.cgi?id=1258299 * https://bugzilla.suse.com/show_bug.cgi?id=1258304 * https://bugzilla.suse.com/show_bug.cgi?id=1258309 * https://bugzilla.suse.com/show_bug.cgi?id=1258313 * https://bugzilla.suse.com/show_bug.cgi?id=1258317 * https://bugzilla.suse.com/show_bug.cgi?id=1258321 * https://bugzilla.suse.com/show_bug.cgi?id=1258326 * https://bugzilla.suse.com/show_bug.cgi?id=1258338 * https://bugzilla.suse.com/show_bug.cgi?id=1258340 * https://bugzilla.suse.com/show_bug.cgi?id=1258349 * https://bugzilla.suse.com/show_bug.cgi?id=1258354 * https://bugzilla.suse.com/show_bug.cgi?id=1258358 * https://bugzilla.suse.com/show_bug.cgi?id=1258374 * https://bugzilla.suse.com/show_bug.cgi?id=1258376 * https://bugzilla.suse.com/show_bug.cgi?id=1258377 * https://bugzilla.suse.com/show_bug.cgi?id=1258379 * https://bugzilla.suse.com/show_bug.cgi?id=1258389 * https://bugzilla.suse.com/show_bug.cgi?id=1258394 * https://bugzilla.suse.com/show_bug.cgi?id=1258395 *https://bugzilla.suse.com/show_bug.cgi?id=1258397 * https://bugzilla.suse.com/show_bug.cgi?id=1258411 * https://bugzilla.suse.com/show_bug.cgi?id=1258415 * https://bugzilla.suse.com/show_bug.cgi?id=1258419 * https://bugzilla.suse.com/show_bug.cgi?id=1258422 * https://bugzilla.suse.com/show_bug.cgi?id=1258424 * https://bugzilla.suse.com/show_bug.cgi?id=1258429 * https://bugzilla.suse.com/show_bug.cgi?id=1258442 * https://bugzilla.suse.com/show_bug.cgi?id=1258464 * https://bugzilla.suse.com/show_bug.cgi?id=1258465 * https://bugzilla.suse.com/show_bug.cgi?id=1258468 * https://bugzilla.suse.com/show_bug.cgi?id=1258469 * https://bugzilla.suse.com/show_bug.cgi?id=1258484 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1258518 * https://bugzilla.suse.com/show_bug.cgi?id=1258519 * https://bugzilla.suse.com/show_bug.cgi?id=1258520 * https://bugzilla.suse.com/show_bug.cgi?id=1258524 * https://bugzilla.suse.com/show_bug.cgi?id=1258544 * https://bugzilla.suse.com/show_bug.cgi?id=1258660 * https://bugzilla.suse.com/show_bug.cgi?id=1258824 * https://bugzilla.suse.com/show_bug.cgi?id=1258832 * https://bugzilla.suse.com/show_bug.cgi?id=1258849 * https://bugzilla.suse.com/show_bug.cgi?id=1258850 * https://bugzilla.suse.com/show_bug.cgi?id=1258860 * https://bugzilla.suse.com/show_bug.cgi?id=1258928 * https://bugzilla.suse.com/show_bug.cgi?id=1259070 * https://bugzilla.suse.com/show_bug.cgi?id=1259130 * https://bugzilla.suse.com/show_bug.cgi?id=1259558 * https://bugzilla.suse.com/show_bug.cgi?id=1259580 * https://bugzilla.suse.com/show_bug.cgi?id=1259857 * https://jira.suse.com/browse/PED-15553 . SUSE kernel update addresses 155 issues with 35 fixes, significantly enhancing security for various modules.. SUSE kernel security update important vulnerabilities fixes. . Severity: Important. LinuxSecurity.com Team
Rebuilt with updated dr_wav to fix CVE-2026-29022. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-63c5e7d076 2026-03-13 01:17:50.866526+00:00 -------------------------------------------------------------------------------- Name : easyrpg-player Product : Fedora 43 Version : 0.8.1.1 Release : 4.fc43 URL : https://easyrpg.org Summary : Game interpreter for RPG Maker 2000/2003 and EasyRPG games Description : EasyRPG Player is a game interpreter for RPG Maker 2000/2003 and EasyRPG games. To play a game, run the "easyrpg-player" executable inside a RPG Maker 2000/2003 game project folder (same place as RPG_RT.exe). -------------------------------------------------------------------------------- Update Information: Rebuilt with updated dr_wav to fix CVE-2026-29022 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 4 2026 Benjamin A. Beasley - 0.8.1.1-4 - Rebuilt with updated dr_wav to fix CVE-2026-29022 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-63c5e7d076' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:0688-1 Release Date: 2026-02-27T15:09:04Z Rating: important References: * bsc#1193731 * bsc#1245986 Cross-References: * CVE-2021-0920 * CVE-2025-38177 CVSS scores: * CVE-2021-0920 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-0920 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2021-0920 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38177 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38177 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves two vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2021-0920: net: split out functions related to registering inflight socket files (bsc#1193731). * CVE-2025-38177: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1245986). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-688=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-688=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (nosrc x86_64) * kernel-default-3.0.101-108.201.1 *kernel-trace-3.0.101-108.201.1 * kernel-ec2-3.0.101-108.201.1 * kernel-xen-3.0.101-108.201.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * kernel-default-debuginfo-3.0.101-108.201.1 * kernel-default-devel-debuginfo-3.0.101-108.201.1 * kernel-xen-debugsource-3.0.101-108.201.1 * kernel-xen-devel-3.0.101-108.201.1 * kernel-trace-debuginfo-3.0.101-108.201.1 * kernel-ec2-base-3.0.101-108.201.1 * kernel-ec2-debugsource-3.0.101-108.201.1 * kernel-trace-devel-debuginfo-3.0.101-108.201.1 * kernel-xen-base-3.0.101-108.201.1 * kernel-default-devel-3.0.101-108.201.1 * kernel-trace-base-3.0.101-108.201.1 * kernel-source-3.0.101-108.201.1 * kernel-syms-3.0.101-108.201.1 * kernel-ec2-debuginfo-3.0.101-108.201.1 * kernel-default-debugsource-3.0.101-108.201.1 * kernel-default-base-3.0.101-108.201.1 * kernel-trace-debugsource-3.0.101-108.201.1 * kernel-trace-devel-3.0.101-108.201.1 * kernel-ec2-devel-debuginfo-3.0.101-108.201.1 * kernel-ec2-devel-3.0.101-108.201.1 * kernel-xen-debuginfo-3.0.101-108.201.1 * kernel-xen-devel-debuginfo-3.0.101-108.201.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch nosrc) * kernel-docs-3.0.101-108.201.1 * SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64) * kernel-default-3.0.101-108.201.1 * kernel-trace-3.0.101-108.201.1 * kernel-ec2-3.0.101-108.201.1 * kernel-xen-3.0.101-108.201.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * kernel-default-debuginfo-3.0.101-108.201.1 * kernel-default-devel-debuginfo-3.0.101-108.201.1 * kernel-xen-debugsource-3.0.101-108.201.1 * kernel-xen-devel-3.0.101-108.201.1 * kernel-trace-debuginfo-3.0.101-108.201.1 * kernel-ec2-base-3.0.101-108.201.1 * kernel-ec2-debugsource-3.0.101-108.201.1 * kernel-trace-devel-debuginfo-3.0.101-108.201.1 * kernel-xen-base-3.0.101-108.201.1 * kernel-default-devel-3.0.101-108.201.1 * kernel-trace-base-3.0.101-108.201.1 *kernel-source-3.0.101-108.201.1 * kernel-syms-3.0.101-108.201.1 * kernel-ec2-debuginfo-3.0.101-108.201.1 * kernel-default-debugsource-3.0.101-108.201.1 * kernel-default-base-3.0.101-108.201.1 * kernel-trace-debugsource-3.0.101-108.201.1 * kernel-trace-devel-3.0.101-108.201.1 * kernel-ec2-devel-debuginfo-3.0.101-108.201.1 * kernel-ec2-devel-3.0.101-108.201.1 * kernel-xen-debuginfo-3.0.101-108.201.1 * kernel-xen-devel-debuginfo-3.0.101-108.201.1 * SUSE Linux Enterprise Server 11 SP4 (noarch nosrc) * kernel-docs-3.0.101-108.201.1 ## References: * https://www.suse.com/security/cve/CVE-2021-0920.html * https://www.suse.com/security/cve/CVE-2025-38177.html * https://bugzilla.suse.com/show_bug.cgi?id=1193731 * https://bugzilla.suse.com/show_bug.cgi?id=1245986 . SUSE kernel update fixes two important issues; installation steps included to mitigate risks and enhance system security.. kernel security SUSE important update vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.