[ubuntu/noble-proposed] linux-gcp-6.14 6.14.0-1011.11~24.04.1 (Accepted)

Andy Whitcroft apw at canonical.com
Mon Jul 14 20:35:30 UTC 2025


linux-gcp-6.14 (6.14.0-1011.11~24.04.1) noble; urgency=medium

  * noble/linux-gcp-6.14: 6.14.0-1011.11~24.04.1 -proposed tracker (LP: #2116558)

  * Packaging resync (LP: #1786013)
    - [Packaging] update variants

  [ Ubuntu-gcp: 6.14.0-1011.11 ]

  * plucky/linux-gcp: 6.14.0-1011.11 -proposed tracker (LP: #2116287)
  * Attestation failure due to vTPM device error (LP: #2116545)
    - SAUCE: Revert "x86/mtrr: Rename mtrr_overwrite_state() to
      guest_force_mtrr_state()"
    - SAUCE: Revert "x86/kvm: Override default caching mode for SEV-SNP and
      TDX"

  [ Ubuntu-gcp: 6.14.0-1010.10 ]

  * plucky/linux-gcp: 6.14.0-1010.10 -proposed tracker (LP: #2114487)
  * Add SVSM vTPM support for AMD SEV-SNP confidential VMs (LP: #2111956)
    - tpm: Make chip->{status,cancel,req_canceled} opt
    - x86/sev: Add SVSM vTPM probe/send_command functions
    - svsm: Add header with SVSM_VTPM_CMD helpers
    - tpm: Add SNP SVSM vTPM driver
    - x86/sev: Register tpm-svsm platform device
    - [Config] gcp: Make tpm_svsm built-in
  [ Ubuntu: 6.14.0-24.24 ]
  * plucky/linux: 6.14.0-24.24 -proposed tracker (LP: #2114501)
  * Packaging resync (LP: #1786013)
    - [Packaging] update variants
    - [Packaging] update annotations scripts
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/2025.06.16)
  * Apple spi keyboard/trackpad not working 25.04 (LP: #2107976)
    - iommu/vt-d: Restore context entry setup order for aliased devices
  * Unexpected system reboot at loading GUI session on some AMD platforms
    (LP: #2112462)
    - drm/amdgpu/hdp4: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp5: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp5.2: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp6: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp7: use memcfg register to post the write for HDP flush
  * Fix ARL-U/H suspend issues (LP: #2112469)
    - platform/x86/intel/pmc: Remove duplicate enum
    - platform/x86:intel/pmc: Make tgl_core_generic_init() static
    - platform/x86:intel/pmc: Create generic_core_init() for all platforms
    - platform/x86/intel/pmc: Remove simple init functions
    - platform/x86/intel/pmc: Add Arrow Lake U/H support to intel_pmc_core
      driver
    - platform/x86/intel/pmc: Fix Arrow Lake U/H NPU PCI ID
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174)
    - s390/pci: Remove redundant bus removal and disable from
      zpci_release_device()
    - s390/pci: Prevent self deletion in disable_slot()
    - s390/pci: Allow re-add of a reserved but not yet removed device
    - s390/pci: Serialize device addition and removal
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174) // CVE-2025-37946
    - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has
      child VFs
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174) // CVE-2025-37974
    - s390/pci: Fix missing check for zpci_create_device() error return
  * HW accelerated video playback causes VCN timeout on VCN 4.0.5 (AMD Strix)
    (LP: #2112582)
    - drm/amdgpu: read back register after written for VCN v4.0.5
  * kvmppc_set_passthru_irq_hv: Could not assign IRQ map traces are seen when
    pci device is attached to kvm guest when "xive=off" is set (LP: #2109951)
    - KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries KVM Guest
  * System will restart while resuming with SATA HDD or nvme installed with
    password set (LP: #2110090)
    - PCI: Explicitly put devices into D0 when initializing
  * VM boots slowly with large-BAR GPU Passthrough (Root Cause Fix SRU)
    (LP: #2111861)
    - mm: Provide address mask in struct follow_pfnmap_args
    - vfio/type1: Convert all vaddr_get_pfns() callers to use vfio_batch
    - vfio/type1: Catch zero from pin_user_pages_remote()
    - vfio/type1: Use vfio_batch for vaddr_get_pfns()
    - vfio/type1: Use consistent types for page counts
    - vfio/type1: Use mapping page mask for pfnmaps
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881)
    - Revert "rndis_host: Flag RNDIS modems as WWAN devices"
    - ALSA: hda/realtek - Add more HP laptops which need mute led fixup
    - ALSA: usb-audio: Add retry on -EPROTO from usb_set_interface()
    - ALSA: usb-audio: Add second USB ID for Jabra Evolve 65 headset
    - ASoC: renesas: rz-ssi: Use NOIRQ_SYSTEM_SLEEP_PM_OPS()
    - btrfs: fix COW handling in run_delalloc_nocow()
    - cpufreq: intel_pstate: Unchecked MSR aceess in legacy mode
    - drm/fdinfo: Protect against driver unbind
    - EDAC/altera: Test the correct error reg offset
    - EDAC/altera: Set DDR and SDMMC interrupt mask before registration
    - i2c: imx-lpi2c: Fix clock count when probe defers
    - pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines
    - perf/x86/intel: Only check the group flag for X86 leader
    - amd-xgbe: Fix to ensure dependent features are toggled with RX checksum
      offload
    - mm/memblock: pass size instead of end to memblock_set_node()
    - mm/memblock: repeat setting reserved region nid if array is doubled
    - mmc: renesas_sdhi: Fix error handling in renesas_sdhi_probe
    - spi: tegra114: Don't fail set_cs_timing when delays are zero
    - tracing: Do not take trace_event_sem in print_event_fields()
    - x86/boot/sev: Support memory acceptance in the EFI stub under SVSM
    - dm-integrity: fix a warning on invalid table line
    - dm: always update the array size in realloc_argv on success
    - drm/amdgpu: Fix offset for HDP remap in nbio v7.11
    - drm: Select DRM_KMS_HELPER from DRM_DEBUG_DP_MST_TOPOLOGY_REFS
    - iommu/arm-smmu-v3: Fix iommu_device_probe bug due to duplicated stream
      ids
    - iommu/arm-smmu-v3: Fix pgsize_bit for sva domains
    - iommu/vt-d: Apply quirk_iommu_igfx for 8086:0044 (QM57/QS57)
    - platform/x86/amd: pmc: Require at least 2.5 seconds between HW sleep
      cycles
    - platform/x86/intel-uncore-freq: Fix missing uncore sysfs during CPU
      hotplug
    - smb: client: fix zero length for mkdir POSIX create context
    - cpufreq: Avoid using inconsistent policy->min and policy->max
    - cpufreq: Fix setting policy limits when frequency tables are used
    - bcachefs: Remove incorrect __counted_by annotation
    - drm/amd/display: Default IPS to RCG_IN_ACTIVE_IPS2_IN_OFF
    - ASoC: soc-core: Stop using of_property_read_bool() for non-boolean
      properties
    - ASoC: cs-amp-lib-test: Don't select SND_SOC_CS_AMP_LIB
    - firmware: cs_dsp: tests: Depend on FW_CS_DSP rather then enabling it
    - ASoC: soc-pcm: Fix hw_params() and DAPM widget sequence
    - Revert "UBUNTU: SAUCE: powerpc64/ftrace: fix module loading without
      patchable function entries"
    - pinctrl: imx: Return NULL if no group is matched and found
    - powerpc/boot: Check for ld-option support
    - ASoC: Intel: sof_sdw: Add NULL check in asoc_sdw_rt_dmic_rtd_init()
    - iommu/arm-smmu-v3: Add missing S2FWB feature detection
    - ALSA: hda/realtek - Enable speaker for HP platform
    - drm/i915/pxp: fix undefined reference to
      `intel_pxp_gsccs_is_ready_for_sessions'
    - wifi: iwlwifi: back off on continuous errors
    - wifi: iwlwifi: don't warn if the NIC is gone in resume
    - wifi: iwlwifi: fix the check for the SCRATCH register upon resume
    - powerpc/boot: Fix dash warning
    - xsk: Fix offset calculation in unaligned mode
    - net/mlx5e: Use custom tunnel header for vxlan gbp
    - net/mlx5: E-Switch, Initialize MAC Address for Default GID
    - net/mlx5e: TC, Continue the attr process even if encap entry is invalid
    - net/mlx5e: Fix lock order in mlx5e_tx_reporter_ptpsq_unhealthy_recover
    - net/mlx5: E-switch, Fix error handling for enabling roce
    - accel/ivpu: Correct DCT interrupt handling
    - cpufreq: Introduce policy->boost_supported flag
    - cpufreq: acpi: Set policy->boost_supported
    - cpufreq: ACPI: Re-sync CPU boost state on system resume
    - Bluetooth: hci_conn: Fix not setting conn_timeout for Broadcast Receiver
    - Bluetooth: hci_conn: Fix not setting timeout for BIG Create Sync
    - Bluetooth: btintel_pcie: Avoid redundant buffer allocation
    - Bluetooth: btintel_pcie: Add additional to checks to clear TX/RX paths
    - Bluetooth: L2CAP: copy RX timestamp to new fragments
    - net: mscc: ocelot: delete PVID VLAN when readding it as non-PVID
    - octeon_ep_vf: Resolve netdevice usage count issue
    - bnxt_en: improve TX timestamping FIFO configuration
    - rtase: Modify the condition used to detect overflow in
      rtase_calc_time_mitigation
    - net: ethernet: mtk-star-emac: rearm interrupts in rx_poll only when
      advised
    - net: ethernet: mtk_eth_soc: sync mtk_clks_source_name array
    - pds_core: make pdsc_auxbus_dev_del() void
    - pds_core: specify auxiliary_device to be created
    - ice: Don't check device type when checking GNSS presence
    - ice: Remove unnecessary ice_is_e8xx() functions
    - ice: fix Get Tx Topology AQ command error on E830
    - idpf: fix offloads support for encapsulated packets
    - scsi: ufs: core: Remove redundant query_complete trace
    - drm/xe/guc: Fix capture of steering registers
    - pinctrl: qcom: Fix PINGROUP definition for sm8750
    - nvme-pci: fix queue unquiesce check on slot_reset
    - drm/tests: shmem: Fix memleak
    - drm/mipi-dbi: Fix blanking for non-16 bit formats
    - net: dlink: Correct endianness handling of led_mode
    - net: mdio: mux-meson-gxl: set reversed bit when using internal phy
    - idpf: fix potential memory leak on kcalloc() failure
    - idpf: protect shutdown from reset
    - igc: fix lock order in igc_ptp_reset
    - net: dsa: felix: fix broken taprio gate states after clock jump
    - net: ipv6: fix UDPv6 GSO segmentation with NAT
    - ALSA: hda/realtek: Fix built-mic regression on other ASUS models
    - bnxt_en: Fix ethtool selftest output in one of the failure cases
    - bnxt_en: Add missing skb_mark_for_recycle() in bnxt_rx_vlan()
    - bnxt_en: call pci_alloc_irq_vectors() after bnxt_reserve_rings()
    - bnxt_en: Fix coredump logic to free allocated buffer
    - bnxt_en: Fix ethtool -d byte order for 32-bit values
    - nvme-tcp: fix premature queue removal and I/O failover
    - nvme-tcp: select CONFIG_TLS from CONFIG_NVME_TCP_TLS
    - nvmet-tcp: select CONFIG_TLS from CONFIG_NVME_TARGET_TCP_TLS
    - ASoC: stm32: sai: skip useless iterations on kernel rate loop
    - ASoC: stm32: sai: add a check on minimal kernel frequency
    - bnxt_en: fix module unload sequence
    - net: fec: ERR007885 Workaround for conventional TX
    - net: hns3: store rx VLAN tag offload state for VF
    - net: hns3: fix an interrupt residual problem
    - net: hns3: fixed debugfs tm_qset size
    - net: hns3: defer calling ptp_clock_register()
    - net: vertexcom: mse102x: Fix possible stuck of SPI interrupt
    - net: vertexcom: mse102x: Fix LEN_MASK
    - net: vertexcom: mse102x: Add range check for CMD_RTS
    - net: vertexcom: mse102x: Fix RX error handling
    - accel/ivpu: Abort all jobs after command queue unregister
    - accel/ivpu: Add handling of VPU_JSM_STATUS_MVNCI_CONTEXT_VIOLATION_HW
    - drm/xe: Invalidate L3 read-only cachelines for geometry streams too
    - platform/x86: alienware-wmi-wmax: Add support for Alienware m15 R7
    - ublk: add helper of ublk_need_map_io()
    - ublk: properly serialize all FETCH_REQs
    - ublk: move device reset into ublk_ch_release()
    - ublk: improve detection and handling of ublk server exit
    - ublk: remove __ublk_quiesce_dev()
    - ublk: simplify aborting ublk request
    - firmware: arm_ffa: Skip Rx buffer ownership release if not acquired
    - arm64: dts: imx95: Correct the range of PCIe app-reg region
    - ARM: dts: opos6ul: add ksz8081 phy properties
    - arm64: dts: st: Adjust interrupt-controller for stm32mp25 SoCs
    - arm64: dts: st: Use 128kB size for aliased GIC400 register access on
      stm32mp25 SoCs
    - block: introduce zone capacity helper
    - btrfs: zoned: skip reporting zone for new block group
    - kernel: param: rename locate_module_kobject
    - kernel: globalize lookup_or_create_module_kobject()
    - drivers: base: handle module_kobject creation
    - btrfs: expose per-inode stable writes flag
    - btrfs: pass struct btrfs_inode to btrfs_read_locked_inode()
    - btrfs: pass struct btrfs_inode to btrfs_iget_locked()
    - drm/amd/display: Add scoped mutexes for amdgpu_dm_dhcp
    - bcachefs: Change btree_insert_node() assertion to error
    - dm: fix copying after src array boundaries
    - Linux 6.14.6
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37903
    - drm/amd/display: Fix slab-use-after-free in hdcp
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37904
    - btrfs: fix the inode leak in btrfs_iget()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37905
    - firmware: arm_scmi: Balance device refcount when destroying devices
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37906
    - ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37907
    - accel/ivpu: Fix locking order in ivpu_job_submit
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37908
    - mm, slab: clean up slab->obj_exts always
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37933
    - octeon_ep: Fix host hang issue during device reboot
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37909
    - net: lan743x: Fix memleak issue when GSO enabled
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37910
    - ptp: ocp: Fix NULL dereference in Adva board SMA sysfs operations
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37894
    - net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37934
    - ASoC: simple-card-utils: Fix pointer check in
      graph_util_parse_link_direction
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37911
    - bnxt_en: Fix out-of-bound memcpy() during ethtool -w
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37895
    - bnxt_en: Fix error handling path in bnxt_init_chip()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37935
    - net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37891
    - ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37912
    - ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37913
    - net_sched: qfq: Fix double list add in class with netem as child qdisc
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37914
    - net_sched: ets: Fix double list add in class with netem as child qdisc
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37915
    - net_sched: drr: Fix double list add in class with netem as child qdisc
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37916
    - pds_core: remove write-after-free of client_id
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37917
    - net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx
      poll
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37918
    - Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37919
    - ASoC: amd: acp: Fix NULL pointer deref in acp_i2s_set_tdm_slot
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37896
    - spi: spi-mem: Add fix to avoid divide error
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37920
    - xsk: Fix race condition in AF_XDP generic RX path
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37921
    - vxlan: vnifilter: Fix unlocked deletion of default FDB entry
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37897
    - wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37898
    - powerpc64/ftrace: fix module loading without patchable function entries
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37922
    - book3s64/radix : Align section vmemmap start address to PAGE_SIZE
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37923
    - tracing: Fix oob write in trace_seq_to_buffer()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37899
    - ksmbd: fix use-after-free in session logoff
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37924
    - ksmbd: fix use-after-free in kerberos authentication
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37926
    - ksmbd: fix use-after-free in ksmbd_session_rpc_open
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37900
    - iommu: Fix two issues in iommu_copy_struct_from_user()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37927
    - iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37928
    - dm-bufio: don't schedule in atomic context
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37990
    - wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37901
    - irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37936
    - perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's
      value.
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37991
    - parisc: Fix double SIGFPE crash
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37929
    - arm64: errata: Add missing sentinels to Spectre-BHB MIDR arrays
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37930
    - drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill()
  * Plucky update: v6.14.6 upstream stable release (LP: #2113881) //
    CVE-2025-37931
    - btrfs: adjust subpage bit start based on sectorsize
  * Support Sony IMX471 camera sensor for Intel IPU7 platforms (LP: #2107320)
    - SAUCE: media: ipu-bridge: Support imx471 sensor
  * deadlock on cpu_hotplug_lock in __accept_page() (LP: #2109543)
    - mm/page_alloc: fix deadlock on cpu_hotplug_lock in __accept_page()
  * Plucky fails to boot on (older) Macs (LP: #2105402)
    - SAUCE: hack: efi/libstub: enable t14s boot failure hack only on arm64
  * CVE-2025-37798
    - sch_htb: make htb_qlen_notify() idempotent
    - sch_htb: make htb_deactivate() idempotent
    - sch_drr: make drr_qlen_notify() idempotent
    - sch_hfsc: make hfsc_qlen_notify() idempotent
    - sch_qfq: make qfq_qlen_notify() idempotent
    - sch_ets: make est_qlen_notify() idempotent
    - selftests/tc-testing: Add a test case for FQ_CODEL with HTB parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with QFQ parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with HFSC parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with DRR parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with ETS parent
  * CVE-2025-37997
    - netfilter: ipset: fix region locking in hash types
  * CVE-2025-37890
    - net_sched: hfsc: Fix a UAF vulnerability in class with netem as child
      qdisc
    - sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
    - net_sched: hfsc: Address reentrant enqueue adding class to eltree twice

  [ Ubuntu-gcp: 6.14.0-1009.9 ]

  * plucky/linux-gcp: 6.14.0-1009.9 -proposed tracker (LP: #2114268)
  * Packaging resync (LP: #1786013)
    - [Packaging] update variants
  [ Ubuntu: 6.14.0-23.23 ]
  * plucky/linux: 6.14.0-23.23 -proposed tracker (LP: #2114279)
  * Packaging resync (LP: #1786013)
    - [Packaging] update variants
    - [Packaging] update annotations scripts
  * CVE-2025-37798
    - sch_htb: make htb_qlen_notify() idempotent
    - sch_htb: make htb_deactivate() idempotent
    - sch_drr: make drr_qlen_notify() idempotent
    - sch_hfsc: make hfsc_qlen_notify() idempotent
    - sch_qfq: make qfq_qlen_notify() idempotent
    - sch_ets: make est_qlen_notify() idempotent
    - selftests/tc-testing: Add a test case for FQ_CODEL with HTB parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with QFQ parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with HFSC parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with DRR parent
    - selftests/tc-testing: Add a test case for FQ_CODEL with ETS parent
  * CVE-2025-37997
    - netfilter: ipset: fix region locking in hash types
  * CVE-2025-37890
    - net_sched: hfsc: Fix a UAF vulnerability in class with netem as child
      qdisc
    - sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
    - net_sched: hfsc: Address reentrant enqueue adding class to eltree twice

  [ Ubuntu-gcp: 6.14.0-1008.8 ]

  * plucky/linux-gcp: 6.14.0-1008.8 -proposed tracker (LP: #2110643)
  [ Ubuntu: 6.14.0-22.22 ]
  * plucky/linux: 6.14.0-22.22 -proposed tracker (LP: #2111404)
  * snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes
    (LP: #2110289)
    - fs/eventpoll: fix endless busy loop after timeout has expired
  [ Ubuntu: 6.14.0-20.20 ]
  * plucky/linux: 6.14.0-20.20 -proposed tracker (LP: #2110652)
  * Rotate the Canonical Livepatch key (LP: #2111244)
    - [Config] Prepare for Canonical Livepatch key rotation
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268)
    - soc: qcom: ice: introduce devm_of_qcom_ice_get
    - mmc: sdhci-msm: fix dev reference leaked through of_qcom_ice_get
    - PM: EM: use kfree_rcu() to simplify the code
    - PM: EM: Address RCU-related sparse warnings
    - media: i2c: imx214: Use subdev active state
    - media: i2c: imx214: Simplify with dev_err_probe()
    - media: i2c: imx214: Convert to CCI register access helpers
    - media: i2c: imx214: Replace register addresses with macros
    - media: i2c: imx214: Check number of lanes from device tree
    - media: i2c: imx214: Fix link frequency validation
    - media: ov08x40: Move ov08x40_identify_module() function up
    - media: ov08x40: Add missing ov08x40_identify_module() call on stream-start
    - iio: adc: ad7768-1: Move setting of val a bit later to avoid unnecessary
      return value check
    - iio: adc: ad7768-1: Fix conversion result sign
    - of: resolver: Simplify of_resolve_phandles() using __free()
    - of: resolver: Fix device node refcount leakage in of_resolve_phandles()
    - scsi: ufs: qcom: fix dev reference leaked through of_qcom_ice_get
    - PCI/MSI: Convert pci_msi_ignore_mask to per MSI domain flag
    - PCI/MSI: Handle the NOMASK flag correctly for all PCI/MSI backends
    - PCI/MSI: Add an option to write MSIX ENTRY_DATA before any reads
    - irqchip/renesas-rzv2h: Simplify rzv2h_icu_init()
    - irqchip/renesas-rzv2h: Add struct rzv2h_hw_info with t_offs variable
    - irqchip/renesas-rzv2h: Prevent TINT spurious interrupt
    - drm/xe/ptl: Apply Wa_14023061436
    - drm/xe/xe3lpg: Add Wa_13012615864
    - drm/xe: Add performance tunings to debugfs
    - drm/xe/rtp: Drop sentinels from arg to xe_rtp_process_to_sr()
    - drm/xe: Ensure fixed_slice_mode gets set after ccs_mode change
    - lib/Kconfig.ubsan: Remove 'default UBSAN' from UBSAN_INTEGER_WRAP
    - ceph: Fix incorrect flush end position calculation
    - dma/contiguous: avoid warning about unused size_bytes
    - virtio_pci: Use self group type for cap commands
    - cpufreq: cppc: Fix invalid return value in .get() callback
    - cpufreq: Do not enable by default during compile testing
    - cpufreq: fix compile-test defaults
    - btrfs: avoid page_lockend underflow in btrfs_punch_hole_lock_range()
    - cgroup/cpuset-v1: Add missing support for cpuset_v2_mode
    - vhost-scsi: Add better resource allocation failure handling
    - vhost-scsi: Fix vhost_scsi_send_bad_target()
    - vhost-scsi: Fix vhost_scsi_send_status()
    - net/mlx5: Move ttc allocation after switch case to prevent leaks
    - scsi: core: Clear flags for scsi_cmnd that did not complete
    - net: enetc: register XDP RX queues with frag_size
    - net: enetc: refactor bulk flipping of RX buffers to separate function
    - net: enetc: fix frame corruption on bpf_xdp_adjust_head/tail() and XDP_PASS
    - net: lwtunnel: disable BHs when required
    - net: phylink: force link down on major_config failure
    - net: phylink: fix suspend/resume with WoL enabled and link down
    - net: phy: leds: fix memory leak
    - virtio-net: Refactor napi_enable paths
    - virtio-net: Refactor napi_disable paths
    - virtio-net: disable delayed refill when pausing rx
    - net: ethernet: mtk_eth_soc: net: revise NETSYSv3 hardware configuration
    - fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount()
    - net: dsa: mt7530: sync driver-specific behavior of MT7531 variants
    - pds_core: Prevent possible adminq overflow/stuck condition
    - pds_core: Remove unnecessary check in pds_client_adminq_cmd()
    - net: phy: Add helper for getting tx amplitude gain
    - net: phy: dp83822: Add support for changing the transmit amplitude voltage
    - net: dp83822: Fix OF_MDIO config check
    - net: stmmac: fix dwmac1000 ptp timestamp status offset
    - net: stmmac: fix multiplication overflow when reading timestamp
    - block: never reduce ra_pages in blk_apply_bdi_limits
    - bdev: use bdev_io_min() for statx block size
    - block: move blkdev_{get,put} _no_open prototypes out of blkdev.h
    - block: remove the backing_inode variable in bdev_statx
    - block: don't autoload drivers on stat
    - iommu/amd: Return an error if vCPU affinity is set for non-vCPU IRTE
    - riscv: Replace function-like macro by static inline function
    - ublk: remove io_cmds list in ublk_queue
    - ublk: comment on ubq->canceling handling in ublk_queue_rq()
    - ublk: implement ->queue_rqs()
    - ublk: remove unused cmd argument to ublk_dispatch_req()
    - ublk: call ublk_dispatch_req() for handling UBLK_U_IO_NEED_GET_DATA
    - splice: remove duplicate noinline from pipe_clear_nowait
    - fs/xattr: Fix handling of AT_FDCWD in setxattrat(2) and getxattrat(2)
    - bpf: Add namespace to BPF internal symbols
    - Revert "drm/meson: vclk: fix calculation of 59.94 fractional rates"
    - drm/meson: use unsigned long long / Hz for frequency types
    - perf/x86: Fix non-sampling (counting) events on certain x86 platforms
    - LoongArch: Select ARCH_USE_MEMTEST
    - LoongArch: Make regs_irqs_disabled() more clear
    - LoongArch: Make do_xyz() exception handlers more robust
    - net: stmmac: simplify phylink_suspend() and phylink_resume() calls
    - net: phylink: add phylink_prepare_resume()
    - net: stmmac: address non-LPI resume failures properly
    - net: stmmac: socfpga: remove phy_resume() call
    - net: phylink: add functions to block/unblock rx clock stop
    - net: stmmac: block PHY RXC clock-stop
    - netfilter: fib: avoid lookup if socket is available
    - virtio_console: fix missing byte order handling for cols and rows
    - sched_ext: Use kvzalloc for large exit_dump allocation
    - crypto: atmel-sha204a - Set hwrng quality to lowest possible
    - net: selftests: initialize TCP header and skb payload with zero
    - net: phy: microchip: force IRQ polling mode for lan88xx
    - mptcp: pm: Defer freeing of MPTCP userspace path manager entries
    - scsi: mpi3mr: Fix pending I/O counter
    - rust: firmware: Use `ffi::c_char` type in `FwFunc`
    - drm: panel: jd9365da: fix reset signal polarity in unprepare
    - drm/amd/display: Fix gpu reset in multidisplay config
    - drm/amd/display: Force full update in gpu reset
    - drm/amd/display: Fix ACPI edid parsing on some Lenovo systems
    - x86/insn: Fix CTEST instruction decoding
    - x86/mm: Fix _pgd_alloc() for Xen PV mode
    - selftests/pcie_bwctrl: Fix test progs list
    - binder: fix offset calculation in debug log
    - LoongArch: Handle fp, lsx, lasx and lbt assembly symbols
    - LoongArch: Remove a bogus reference to ZONE_DMA
    - LoongArch: KVM: Fix multiple typos of KVM code
    - LoongArch: KVM: Fully clear some CSRs when VM reboot
    - LoongArch: KVM: Fix PMU pass-through issue if VM exits to host finally
    - io_uring: fix 'sync' handling of io_fallback_tw()
    - KVM: SVM: Allocate IR data using atomic allocation
    - cxl/core/regs.c: Skip Memory Space Enable check for RCD and RCH Ports
    - ata: libata-scsi: Improve CDL control
    - ata: libata-scsi: Fix ata_mselect_control_ata_feature() return type
    - ata: libata-scsi: Fix ata_msense_control_ata_feature()
    - USB: storage: quirk for ADATA Portable HDD CH94
    - scsi: Improve CDL control
    - mei: me: add panther lake H DID
    - KVM: x86: Explicitly treat routing entry type changes as changes
    - KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer
    - char: misc: register chrdev region with all possible minors
    - misc: microchip: pci1xxxx: Fix incorrect IRQ status handling during ack
    - firmware: stratix10-svc: Add of_platform_default_populate()
    - serial: msm: Configure correct working mode before starting earlycon
    - serial: sifive: lock port in startup()/shutdown() callbacks
    - USB: serial: ftdi_sio: add support for Abacus Electrics Optical Probe
    - USB: serial: option: add Sierra Wireless EM9291
    - USB: serial: simple: add OWON HDS200 series oscilloscope support
    - xhci: Limit time spent with xHC interrupts disabled during bus resume
    - usb: chipidea: ci_hdrc_imx: fix call balance of regulator routines
    - usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error handling
    - USB: OHCI: Add quirk for LS7A OHCI controller (rev 0x02)
    - usb: dwc3: xilinx: Prevent spike in reset signal
    - usb: quirks: add DELAY_INIT quirk for Silicon Motion Flash Drive
    - usb: quirks: Add delay init quirk for SanDisk 3.2Gen1 Flash Drive
    - USB: VLI disk crashes if LPM is used
    - usb: typec: class: Invalidate USB device pointers on partner unregistration
    - usb: typec: class: Unlocked on error in typec_register_partner()
    - USB: wdm: handle IO errors in wdm_wwan_port_start
    - USB: wdm: close race between wdm_open and wdm_wwan_port_stop
    - USB: wdm: wdm_wwan_port_tx_complete mutex in atomic context
    - USB: wdm: add annotation
    - crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP()
    - selftests/bpf: Fix stdout race condition in traffic monitor
    - pinctrl: renesas: rza2: Fix potential NULL pointer dereference
    - pinctrl: mcp23s08: Get rid of spurious level interrupts
    - MIPS: cm: Detect CM quirks from device tree
    - crypto: ccp - Add support for PCI device 0x1134
    - crypto: lib/Kconfig - Fix lib built-in failure when arch is modular
    - clk: check for disabled clock-provider in of_clk_get_hw_from_clkspec()
    - parisc: PDT: Fix missing prototype warning
    - s390/tty: Fix a potential memory leak bug
    - clk: renesas: rzv2h: Adjust for CPG_BUS_m_MSTOP starting from m = 1
    - selftests/bpf: Fix cap_enable_effective() return code
    - bpf: bpftool: Setting error code in do_loader()
    - bpf: Only fails the busy counter check in bpf_cgrp_storage_get if it creates
      storage
    - bpf: Reject attaching fexit/fmod_ret to __noreturn functions
    - mailbox: pcc: Fix the possible race in updation of chan_in_use flag
    - mailbox: pcc: Always clear the platform ack interrupt first
    - staging: gpib: Use min for calculating transfer length
    - usb: host: max3421-hcd: Add missing spi_device_id table
    - usb: typec: ucsi: return CCI and message from sync_control callback
    - usb: typec: ucsi: ccg: move command quirks to ucsi_ccg_sync_control()
    - iio: adc: ad4695: make ad4695_exit_conversion_mode() more robust
    - fs/ntfs3: Fix WARNING in ntfs_extend_initialized_size
    - usb: dwc3: gadget: Refactor loop to avoid NULL endpoints
    - usb: dwc3: gadget: Avoid using reserved endpoints on Intel Merrifield
    - dmaengine: bcm2835-dma: fix warning when CONFIG_PM=n
    - usb: xhci: Complete 'error mid TD' transfers when handling Missed Service
    - xhci: Handle spurious events on Etron host isoc enpoints
    - i3c: master: svc: Add support for Nuvoton npcm845 i3c
    - dmaengine: dmatest: Fix dmatest waiting less when interrupted
    - usb: xhci: Avoid Stop Endpoint retry loop if the endpoint seems Running
    - phy: rockchip: usbdp: Avoid call hpd_event_trigger in dp_phy_init
    - usb: host: xhci-plat: mvebu: use ->quirks instead of ->init_quirk() func
    - thunderbolt: Scan retimers after device router has been enumerated
    - iommu/arm-smmu-v3: Set MEV bit in nested STE for DoS mitigations
    - objtool: Silence more KCOV warnings
    - objtool, panic: Disable SMAP in __stack_chk_fail()
    - objtool, ASoC: codecs: wcd934x: Remove potential undefined behavior in
      wcd934x_slim_irq_handler()
    - objtool, regulator: rk808: Remove potential undefined behavior in
      rk806_set_mode_dcdc()
    - objtool, lkdtm: Obfuscate the do_nothing() pointer
    - qibfs: fix _another_ leak
    - riscv: tracing: Fix __write_overflow_field in ftrace_partial_regs()
    - ntb: reduce stack usage in idt_scan_mws
    - ntb_hw_amd: Add NTB PCI ID for new gen CPU
    - 9p/trans_fd: mark concurrent read and writes to p9_conn->err
    - rtc: pcf85063: do a SW reset if POR failed
    - tracing: Enforce the persistent ring buffer to be page aligned
    - kbuild, rust: use -fremap-path-prefix to make paths relative
    - kbuild: add dependency from vmlinux to sorttable
    - sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP
    - KVM: s390: Don't use %pK through tracepoints
    - KVM: s390: Don't use %pK through debug printing
    - cgroup/cpuset: Don't allow creation of local partition over a remote one
    - selftests: ublk: fix test_stripe_04
    - xen: Change xen-acpi-processor dom0 dependency
    - pwm: Let pwm_set_waveform() succeed even if lowlevel driver rounded up
    - pwm: axi-pwmgen: Let .round_waveform_tohw() signal when request was rounded
      up
    - nvme: requeue namespace scan on missed AENs
    - ACPI: EC: Set ec_no_wakeup for Lenovo Go S
    - ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls
    - drm/amdkfd: sriov doesn't support per queue reset
    - drm/amdgpu: Increase KIQ invalidate_tlbs timeout
    - drm/xe/xe3lpg: Apply Wa_14022293748, Wa_22019794406
    - nvme: re-read ANA log page after ns scan completes
    - nvme: multipath: fix return value of nvme_available_path
    - objtool: Stop UNRET validation on UD2
    - gpiolib: of: Move Atmel HSMCI quirk up out of the regulator comment
    - x86/xen: disable CPU idle and frequency drivers for PVH dom0
    - selftests/mincore: Allow read-ahead pages to reach the end of the file
    - x86/bugs: Use SBPB in write_ibpb() if applicable
    - x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline
    - x86/bugs: Don't fill RSB on context switch with eIBRS
    - nvmet-fc: take tgtport reference only once
    - nvmet-fc: put ref when assoc->del_work is already scheduled
    - cifs: Fix encoding of SMB1 Session Setup Kerberos Request in non-UNICODE
      mode
    - timekeeping: Add a lockdep override in tick_freeze()
    - cifs: Fix querying of WSL CHR and BLK reparse points over SMB1
    - ext4: make block validity check resistent to sb bh corruption
    - scsi: hisi_sas: Fix I/O errors caused by hardware port ID changes
    - scsi: ufs: exynos: Ensure pre_link() executes before exynos_ufs_phy_init()
    - scsi: ufs: exynos: Enable PRDT pre-fetching with UFSHCD_CAP_CRYPTO
    - scsi: ufs: exynos: Move phy calls to .exit() callback
    - scsi: ufs: exynos: gs101: Put UFS device in reset on .suspend()
    - scsi: pm80xx: Set phy_attached to zero when device is gone
    - ASoC: fsl_asrc_dma: get codec or cpu dai from backend
    - ASoC: codecs: Add of_match_table for aw888081 driver
    - x86/i8253: Call clockevent_i8253_disable() with interrupts disabled
    - platform/x86: x86-android-tablets: Add "9v" to Vexia EDU ATLA 10 tablet
      symbols
    - platform/x86: x86-android-tablets: Add Vexia Edu Atla 10 tablet 5V data
    - iomap: skip unnecessary ifs_block_is_uptodate check
    - riscv: Provide all alternative macros all the time
    - spi: tegra210-quad: use WARN_ON_ONCE instead of WARN_ON for timeouts
    - spi: tegra210-quad: add rate limiting and simplify timeout error message
    - ubsan: Fix panic from test_ubsan_out_of_bounds
    - nvmet: pci-epf: cleanup link state management
    - x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove cores
    - md/raid1: Add check for missing source disk in process_checks()
    - drm/amdgpu: use a dummy owner for sysfs triggered cleaner shaders v4
    - drm/amd: Forbid suspending into non-default suspend states
    - drm/amdgpu: Use the right function for hdp flush
    - ublk: add ublk_force_abort_dev()
    - ublk: rely on ->canceling for dealing with ublk_nosrv_dev_should_queue_io
    - Revert "drivers: core: synchronize really_probe() and dev_uevent()"
    - driver core: introduce device_set_driver() helper
    - comedi: jr3_pci: Fix synchronous deletion of timer
    - crypto: lib/Kconfig - Hide arch options from user
    - [Config] updateconfigs for crypto libs
    - media: i2c: imx214: Fix uninitialized variable in imx214_set_ctrl()
    - MIPS: cm: Fix warning if MIPS_CM is disabled
    - net: phy: dp83822: fix transmit amplitude if CONFIG_OF_MDIO not defined
    - rust: kbuild: skip `--remap-path-prefix` for `rustdoc`
    - ublk: don't fail request for recovery & reissue in case of ubq->canceling
    - nvme: fixup scan failure for non-ANA multipath controllers
    - usb: xhci: Fix Short Packet handling rework ignoring errors
    - objtool: Ignore end-of-section jumps for KCOV/GCOV
    - objtool: Silence more KCOV warnings, part 2
    - crypto: Kconfig - Select LIB generic option
    - Linux 6.14.5
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37799
    - vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37800
    - driver core: fix potential NULL pointer dereference in dev_uevent()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37801
    - spi: spi-imx: Add check for spi_imx_setupxfer()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37802
    - ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37876
    - netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37877
    - iommu: Clear iommu-dma ops on cleanup
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37878
    - perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37803
    - udmabuf: fix a buf size overflow issue during udmabuf creation
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37804
    - io_uring: always do atomic put from iowq
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37879
    - 9p/net: fix improper handling of bogus negative read/write replies
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37880
    - um: work around sched_yield not yielding in time-travel mode
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37881
    - usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37882
    - usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37805
    - sound/virtio: Fix cancel_sync warnings on uninitialized work_structs
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37806
    - fs/ntfs3: Keep write operations atomic
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37883
    - s390/sclp: Add check for get_zeroed_page()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37884
    - bpf: Fix deadlock between rcu_tasks_trace and event_mutex.
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37807
    - bpf: Fix kmemleak warning for percpu hashmap
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37808
    - crypto: null - Use spin lock instead of mutex
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37809
    - usb: typec: class: Fix NULL pointer access
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37810
    - usb: dwc3: gadget: check that event count does not exceed event buffer
      length
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37811
    - usb: chipidea: ci_hdrc_imx: fix usbmisc handling
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37812
    - usb: cdns3: Fix deadlock when using NCM gadget
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37813
    - usb: xhci: Fix invalid pointer dereference in Etron workaround
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37814
    - tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37815
    - misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37885
    - KVM: x86: Reset IRTE to host control if *new* route isn't postable
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37816
    - mei: vsc: Fix fortify-panic caused by invalid counted_by() use
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37817
    - mcb: fix a double free bug in chameleon_parse_gdd()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37818
    - LoongArch: Return NULL from huge_pte_offset() for invalid PMD
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37819
    - irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37820
    - xen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37821
    - sched/eevdf: Fix se->slice being set to U64_MAX and resulting crash
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37822
    - riscv: uprobes: Add missing fence.i after building the XOL buffer
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37886
    - pds_core: make wait_context part of q_info
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37887
    - pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37823
    - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37797
    - net_sched: hfsc: Fix a UAF vulnerability in class handling
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37824
    - tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37825
    - nvmet: fix out-of-bounds access in nvmet_enable_port
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37826
    - scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37888
    - net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37827
    - btrfs: zoned: return EIO on RAID1 block group write pointer mismatch
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37828
    - scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37829
    - cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37830
    - cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37831
    - cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37832
    - cpufreq: sun50i: prevent out-of-bounds access
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37833
    - net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads
  * Plucky update: v6.14.5 upstream stable release (LP: #2111268) //
    CVE-2025-37834
    - mm/vmscan: don't try to reclaim hwpoison folio
  * Packaging resync (LP: #1786013)
    - [Packaging] resync git-ubuntu-log
    - [Packaging] update annotations scripts

Date: 2025-07-11 01:09:13.674914+00:00
Changed-By: Tim Whisonant <tim.whisonant at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-gcp-6.14/6.14.0-1011.11~24.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list