[ubuntu/noble-security] linux-nvidia-tegra 6.8.0-1008.8 (Accepted)
Andy Whitcroft
apw at canonical.com
Mon Jul 21 22:41:07 UTC 2025
linux-nvidia-tegra (6.8.0-1008.8) noble; urgency=medium
* noble/linux-nvidia-tegra: 6.8.0-1008.8 -proposed tracker (LP: #2116964)
- Dropped patches
- NVIDIA: SAUCE: memory: tegra: init ICC once for multiple MC instances
* Packaging resync (LP: #1786013)
- [Packaging] debian.nvidia-tegra/dkms-versions -- update from kernel-
versions (main/d2025.07.14)
linux-nvidia-tegra (6.8.0-1007.7) noble; urgency=medium
* noble/linux-nvidia-tegra: 6.8.0-1007.7 -proposed tracker (LP: #2116292)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
[ Ubuntu-realtime: 6.8.1-1025.26 ]
* noble/linux-realtime: 6.8.1-1025.26 -proposed tracker (LP: #2114664)
[ Ubuntu: 6.8.0-64.67 ]
* noble/linux: 6.8.0-64.67 -proposed tracker (LP: #2114668)
* Unexpected system reboot at loading GUI session on some AMD platforms
(LP: #2112462)
- drm/amdgpu/hdp4: use memcfg register to post the write for HDP flush
- drm/amdgpu/hdp5: use memcfg register to post the write for HDP flush
- drm/amdgpu/hdp5.2: use memcfg register to post the write for HDP flush
- drm/amdgpu/hdp6: use memcfg register to post the write for HDP flush
* [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
(LP: #2114174)
- s390/pci: rename lock member in struct zpci_dev
- s390/pci: introduce lock to synchronize state of zpci_dev's
- s390/pci: remove hotplug slot when releasing the device
- s390/pci: Remove redundant bus removal and disable from
zpci_release_device()
- s390/pci: Prevent self deletion in disable_slot()
- s390/pci: Allow re-add of a reserved but not yet removed device
- s390/pci: Serialize device addition and removal
* [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
(LP: #2114174) // CVE-2025-37946
- s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has
child VFs
* [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
(LP: #2114174) // CVE-2025-37974
- s390/pci: Fix missing check for zpci_create_device() error return
* [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
(LP: #2114174) // CVE-2024-56699
- s390/pci: Fix potential double remove of hotplug slot
* System will restart while resuming with SATA HDD or nvme installed with
password set (LP: #2110090)
- PCI: Explicitly put devices into D0 when initializing
* Noble update: upstream stable patchset 2025-06-12 (LP: #2114239)
- btrfs: fix assertion failure when splitting ordered extent after
transaction abort
- btrfs: fix use-after-free when attempting to join an aborted transaction
- arm64/mm: Ensure adequate HUGE_MAX_HSTATE
- exec: fix up /proc/pid/comm in the execveat(AT_EMPTY_PATH) case
- s390/stackleak: Use exrl instead of ex in __stackleak_poison()
- btrfs: fix data race when accessing the inode's disk_i_size at
btrfs_drop_extents()
- btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error
handling
- sched: Don't try to catch up excess steal time.
- locking/ww_mutex/test: Use swap() macro
- lockdep: Fix upper limit for LOCKDEP_*_BITS configs
- x86/amd_nb: Restrict init function to AMD-based systems
- drm/virtio: New fence for every plane update
- drm: Add panel backlight quirks
- drm: panel-backlight-quirks: Add Framework 13 matte panel
- drm: panel-backlight-quirks: Add Framework 13 glossy and 2.8k panels
- nvkm/gsp: correctly advance the read pointer of GSP message queue
- nvkm: correctly calculate the available space of the GSP cmdq buffer
- drm/amd/display: Populate chroma prefetch parameters, DET buffer fix
- drm/amd/display: Overwriting dualDPP UBF values before usage
- printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
- drm/connector: add mutex to protect ELD from concurrent access
- drm/bridge: anx7625: use eld_mutex to protect access to connector->eld
- drm/bridge: ite-it66121: use eld_mutex to protect access to
connector->eld
- drm/amd/display: use eld_mutex to protect access to connector->eld
- drm/exynos: hdmi: use eld_mutex to protect access to connector->eld
- drm/radeon: use eld_mutex to protect access to connector->eld
- drm/sti: hdmi: use eld_mutex to protect access to connector->eld
- drm/vc4: hdmi: use eld_mutex to protect access to connector->eld
- drm/amd/display: Fix Mode Cutoff in DSC Passthrough to DP2.1 Monitor
- drm/amdgpu: Don't enable sdma 4.4.5 CTXEMPTY interrupt
- drm/amdkfd: Queue interrupt work to different CPU
- drm/bridge: it6505: Change definition MAX_HDCP_DOWN_STREAM_COUNT
- drm/bridge: it6505: fix HDCP Bstatus check
- drm/bridge: it6505: fix HDCP encryption when R0 ready
- drm/bridge: it6505: fix HDCP CTS compare V matching
- drm/bridge: it6505: fix HDCP V match check is not performed correctly
- drm/bridge: it6505: fix HDCP CTS KSV list wait timer
- safesetid: check size of policy writes
- drm/amd/display: Increase sanitizer frame larger than limit when compile
testing with clang
- drm/amd/display: Limit Scaling Ratio on DCN3.01
- wifi: rtw89: add crystal_cap check to avoid setting as overflow value
- tun: fix group permission check
- mmc: core: Respect quirk_max_rate for non-UHS SDIO card
- mmc: sdhci-esdhc-imx: enable 'SDHCI_QUIRK_NO_LED' quirk for S32G
- wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()
- tomoyo: don't emit warning in tomoyo_write_control()
- mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
- wifi: rtw88: add __packed attribute to efuse layout struct
- clk: qcom: Make GCC_8150 depend on QCOM_GDSC
- HID: multitouch: Add quirk for Hantick 5288 touchpad
- HID: Wacom: Add PCI Wacom device support
- net/mlx5: use do_aux_work for PHC overflow checks
- wifi: brcmfmac: Check the return value of
of_property_read_string_index()
- wifi: iwlwifi: pcie: Add support for new device ids
- wifi: iwlwifi: avoid memory leak
- i2c: Force ELAN06FA touchpad I2C bus freq to 100KHz
- APEI: GHES: Have GHES honor the panic= setting
- Bluetooth: btusb: Add new VID/PID 13d3/3610 for MT7922
- Bluetooth: btusb: Add new VID/PID 13d3/3628 for MT7925
- Bluetooth: MGMT: Fix slab-use-after-free Read in
mgmt_remove_adv_monitor_sync
- net: wwan: iosm: Fix hibernation by re-binding the driver around it
- mmc: sdhci-msm: Correctly set the load for the regulator
- octeon_ep: update tx/rx stats locally for persistence
- tipc: re-order conditions in tipc_crypto_key_rcv()
- selftests/net/ipsec: Fix Null pointer dereference in rtattr_pack()
- x86/kexec: Allocate PGD for x86_64 transition page tables separately
- iommu/arm-smmu-qcom: add sdm670 adreno iommu compatible
- iommu/arm-smmu-v3: Clean up more on probe failure
- platform/x86: int3472: Check for adev == NULL
- platform/x86: acer-wmi: Add support for Acer PH14-51
- ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback
- platform/x86: acer-wmi: Add support for Acer Predator PH16-72
- ASoC: amd: Add ACPI dependency to fix build error
- Input: allocate keycode for phone linking
- platform/x86: acer-wmi: add support for Acer Nitro AN515-58
- platform/x86: acer-wmi: Ignore AC events
- xfs: report realtime block quota limits on realtime directories
- xfs: don't over-report free space or inodes in statvfs
- tty: xilinx_uartps: split sysrq handling
- tty: vt: pass proper pointers from tioclinux()
- tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
- tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT
- platform/x86: serdev_helpers: Check for serial_ctrl_uid == NULL
- nvme: handle connectivity loss in nvme_set_queue_count
- firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry
- gpu: drm_dp_cec: fix broken CEC adapter properties check
- ice: put Rx buffers after being done with current frame
- ice: gather page_count()'s of each frag right before XDP prog call
- ice: stop storing XDP verdict within ice_rx_buf
- nvme-fc: use ctrl state getter
- net: bcmgenet: Correct overlaying of PHY and MAC Wake-on-LAN
- vmxnet3: Fix tx queue race condition with XDP
- tg3: Disable tg3 PCIe AER on system reboot
- udp: gso: do not drop small packets when PMTU reduces
- rxrpc: Fix the rxrpc_connection attend queue handling
- gpio: pca953x: Improve interrupt support
- net: atlantic: fix warning during hot unplug
- net: rose: lock the socket in rose_bind()
- ACPI: property: Fix return value for nval == 0 in acpi_data_prop_read()
- tun: revert fix group permission check
- net: sched: Fix truncation of offloaded action statistics
- rxrpc: Fix call state set to not include the SERVER_SECURING state
- cpufreq: s3c64xx: Fix compilation warning
- leds: lp8860: Write full EEPROM, not only half of it
- ALSA: hda/realtek: Enable Mute LED on HP Laptop 14s-fq1xxx
- drm/modeset: Handle tiled displays in pan_display_atomic.
- drm/client: Handle tiled displays better
- smb: client: fix order of arguments of tracepoints
- smb: client: change lease epoch type from unsigned int to __u16
- s390/futex: Fix FUTEX_OP_ANDN implementation
- arm64: Filter out SVE hwcaps when FEAT_SVE isn't implemented
- m68k: vga: Fix I/O defines
- fs/proc: do_task_stat: Fix ESP not readable during coredump
- binfmt_flat: Fix integer overflow bug on 32 bit systems
- accel/ivpu: Fix Qemu crash when running in passthrough
- arm64/kvm: Configure HYP TCR.PS/DS based on host stage1
- arm64/sme: Move storage of reg_smidr to __cpuinfo_store_cpu()
- KVM: arm64: timer: Always evaluate the need for a soft timer
- drm/rockchip: cdn-dp: Use drm_connector_helper_hpd_irq_event()
- arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma
- remoteproc: omap: Handle ARM dma_iommu_mapping
- KVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
- KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
- ksmbd: fix integer overflows on 32 bit systems
- drm/amd/display: Optimize cursor position updates
- drm/amd/pm: Mark MM activity as unsupported
- drm/amdkfd: only flush the validate MES contex
- drm/i915/guc: Debug print LRC state entries only if the context is
pinned
- drm/i915: Fix page cleanup on DMA remap failure
- drm/komeda: Add check for komeda_get_layer_fourcc_list()
- drm/i915/dp: Iterate DSC BPP from high to low on all platforms
- drm/i915: Drop 64bpp YUV formats from ICL+ SDR planes
- drm/amd/display: Fix seamless boot sequence
- Bluetooth: L2CAP: accept zero as a special value for MTU auto-selection
- clk: sunxi-ng: a100: enable MMC clock reparenting
- clk: mmp2: call pm_genpd_init() only after genpd.name is set
- media: i2c: ds90ub960: Fix UB9702 refclk register access
- clk: qcom: clk-alpha-pll: fix alpha mode configuration
- clk: qcom: gcc-sm8550: Do not turn off PCIe GDSCs during gdsc_disable()
- clk: qcom: gcc-sm8650: Do not turn off PCIe GDSCs during gdsc_disable()
- clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
- clk: qcom: dispcc-sm6350: Add missing parent_map for a clock
- clk: qcom: gcc-mdm9607: Fix cmd_rcgr offset for blsp1_uart6 rcg
- clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
- clk: mediatek: mt2701-vdec: fix conversion to mtk_clk_simple_probe
- clk: mediatek: mt2701-aud: fix conversion to mtk_clk_simple_probe
- clk: mediatek: mt2701-bdp: add missing dummy clk
- clk: mediatek: mt2701-img: add missing dummy clk
- clk: mediatek: mt2701-mm: add missing dummy clk
- blk-cgroup: Fix class @block_class's subsystem refcount leakage
- efi: libstub: Use '-std=gnu11' to fix build with GCC 15
- perf bench: Fix undefined behavior in cmpworker()
- scsi: ufs: core: Fix the HIGH/LOW_TEMP Bit Definitions
- of: Correct child specifier used as input of the 2nd nexus node
- of: Fix of_find_node_opts_by_path() handling of alias+path+options
- Input: bbnsm_pwrkey - add remove hook
- HID: hid-sensor-hub: don't use stale platform-data on remove
- ring-buffer: Do not allow events in NMI with generic atomic64 cmpxchg()
- atomic64: Use arch_spin_locks instead of raw_spin_locks
- wifi: rtlwifi: rtl8821ae: Fix media status report
- wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()
- wifi: mt76: mt7921u: Add VID/PID for TP-Link TXE50UH
- wifi: rtw88: sdio: Fix disconnection after beacon loss
- wifi: mt76: mt7915: add module param to select 5 GHz or 6 GHz on MT7916
- usb: gadget: f_tcm: Translate error to sense
- usb: gadget: f_tcm: Decrement command ref count on cleanup
- usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
- usb: gadget: f_tcm: Don't prepare BOT write request twice
- usbnet: ipheth: fix possible overflow in DPE length check
- usbnet: ipheth: use static NDP16 location in URB
- usbnet: ipheth: check that DPE points past NCM header
- usbnet: ipheth: refactor NCM datagram loop
- usbnet: ipheth: break up NCM header size computation
- usbnet: ipheth: fix DPE OoB read
- usbnet: ipheth: document scope of NCM implementation
- ASoC: acp: Support microphone from Lenovo Go S
- soc: qcom: socinfo: Avoid out of bounds read of serial number
- serial: sh-sci: Drop __initdata macro for port_cfg
- serial: sh-sci: Do not probe the serial port if its slot in sci_ports[]
is in use
- MIPS: Loongson64: remove ROM Size unit in boardinfo
- LoongArch: Extend the maximum number of watchpoints
- powerpc/pseries/eeh: Fix get PE state translation
- dm-crypt: don't update io->sector after kcryptd_crypt_write_io_submit()
- dm-crypt: track tag_offset in convert_context
- mips/math-emu: fix emulation of the prefx instruction
- MIPS: pci-legacy: Override pci_address_to_pio
- block: don't revert iter for -EIOCBQUEUED
- firmware: qcom: scm: Fix missing read barrier in qcom_scm_is_available()
- ALSA: hda/realtek: Enable headset mic on Positivo C6400
- ALSA: hda: Fix headset detection failure due to unstable sort
- ALSA: hda/realtek: Fix built-in mic on another ASUS VivoBook model
- ALSA: hda/realtek: Fix built-in mic breakage on ASUS VivoBook X515JA
- arm64: tegra: Fix Tegra234 PCIe interrupt-map
- PCI: endpoint: Finish virtual EP removal in pci_epf_remove_vepf()
- PCI: dwc: ep: Write BAR_MASK before iATU registers in pci_epc_set_bar()
- PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
- scsi: st: Don't set pos_unknown just after device recognition
- scsi: qla2xxx: Move FCE Trace buffer allocation to user control
- scsi: ufs: qcom: Fix crypto key eviction
- scsi: ufs: core: Fix use-after free in init error and remove paths
- scsi: storvsc: Set correct data length for sending SCSI command without
payload
- scsi: core: Do not retry I/Os during depopulation
- kbuild: Move -Wenum-enum-conversion to W=2
- rust: init: use explicit ABI to clean warning in future compilers
- x86/boot: Use '-std=gnu11' to fix build with GCC 15
- ubi: Add a check for ubi_num
- ARM: dts: dra7: Add bus_dma_limit for l4 cfg bus
- ARM: dts: ti/omap: gta04: fix pm issues caused by spi module
- arm64: dts: qcom: sm6115: Fix MPSS memory length
- arm64: dts: qcom: sm6115: Fix CDSP memory length
- arm64: dts: qcom: sm6115: Fix ADSP memory base and length
- arm64: dts: qcom: sm6350: Fix ADSP memory length
- arm64: dts: qcom: sm6350: Fix MPSS memory length
- arm64: dts: qcom: sm6350: Fix uart1 interconnect path
- arm64: dts: qcom: sm6375: Fix ADSP memory length
- arm64: dts: qcom: sm6375: Fix CDSP memory base and length
- arm64: dts: qcom: sm6375: Fix MPSS memory base and length
- arm64: dts: qcom: sm8350: Fix ADSP memory base and length
- arm64: dts: qcom: sm8350: Fix CDSP memory base and length
- arm64: dts: qcom: sm8350: Fix MPSS memory length
- arm64: dts: qcom: sm8450: Fix CDSP memory length
- arm64: dts: qcom: sm8450: Fix MPSS memory length
- arm64: dts: qcom: sm8550: Fix CDSP memory length
- arm64: dts: qcom: sm8550: Fix MPSS memory length
- arm64: dts: qcom: sm8450: add missing qcom,non-secure-domain property
- arm64: dts: qcom: sm8450: Fix ADSP memory base and length
- arm64: dts: qcom: sm8550: add missing qcom,non-secure-domain property
- arm64: dts: qcom: sm8550: Add dma-coherent property
- arm64: dts: qcom: sm8550: Fix ADSP memory base and length
- arm64: dts: qcom: sm8650: Fix CDSP memory length
- arm64: dts: qcom: sm8650: Fix MPSS memory length
- arm64: dts: qcom: sm8550: correct MDSS interconnects
- arm64: dts: qcom: sm8650: correct MDSS interconnects
- crypto: qce - fix priority to be less than ARMv8 CE
- arm64: tegra: Fix typo in Tegra234 dce-fabric compatible
- arm64: tegra: Disable Tegra234 sce-fabric node
- parisc: Temporarily disable jump label support
- pwm: microchip-core: fix incorrect comparison with max period
- xfs: Propagate errors from xfs_reflink_cancel_cow_range in
xfs_dax_write_iomap_end
- xfs: Add error handling for xfs_reflink_cancel_cow_range
- ACPI: PRM: Remove unnecessary strict handler address checks
- tpm: Change to kvalloc() in eventlog/acpi.c
- rv: Reset per-task monitors also for idle tasks
- hrtimers: Force migrate away hrtimers queued after
CPUHP_AP_HRTIMERS_DYING
- kfence: skip __GFP_THISNODE allocations on NUMA systems
- media: ccs: Clean up parsed CCS static data on parse failure
- mm/hugetlb: fix avoid_reserve to allow taking folio from subpool
- iio: light: as73211: fix channel handling in only-color triggered buffer
- soc: mediatek: mtk-devapc: Fix leaking IO map on error paths
- soc: mediatek: mtk-devapc: Fix leaking IO map on driver remove
- soc: qcom: smem_state: fix missing of_node_put in error path
- media: mmp: Bring back registration of the device
- media: mc: fix endpoint iteration
- media: nuvoton: Fix an error check in npcm_video_ece_init()
- media: imx296: Add standby delay during probe
- media: ov5640: fix get_light_freq on auto
- media: stm32: dcmipp: correct dma_set_mask_and_coherent mask value
- media: ccs: Fix CCS static data parsing for large block sizes
- media: ccs: Fix cleanup order in ccs_probe()
- media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()
- media: i2c: ds90ub960: Fix use of non-existing registers on UB9702
- media: i2c: ds90ub960: Fix UB9702 VC map
- media: i2c: ds90ub960: Fix logging SP & EQ status only for UB9702
- media: uvcvideo: Fix crash during unbind if gpio unit is in use
- media: uvcvideo: Fix event flags in uvc_ctrl_send_events
- media: uvcvideo: Support partial control reads
- media: uvcvideo: Remove redundant NULL assignment
- media: uvcvideo: Refactor iterators
- media: uvcvideo: Only save async fh if success
- media: uvcvideo: Remove dangling pointers
- mm: kmemleak: fix upper boundary check for physical address objects
- mm/compaction: fix UBSAN shift-out-of-bounds warning
- ata: libata-sff: Ensure that we cannot write outside the allocated
buffer
- crypto: qce - fix goto jump in error path
- crypto: qce - unregister previously registered algos in error path
- nvmem: qcom-spmi-sdam: Set size in struct nvmem_config
- nvmem: core: improve range check for nvmem_cell_write()
- nvmem: imx-ocotp-ele: simplify read beyond device check
- nvmem: imx-ocotp-ele: fix MAC address byte order
- nvmem: imx-ocotp-ele: fix reading from non zero offset
- nvmem: imx-ocotp-ele: set word length to 1
- io_uring: fix multishots with selected buffers
- io_uring/net: don't retry connect operation on EPOLLERR
- selftests: mptcp: connect: -f: no reconnect
- pnfs/flexfiles: retry getting layout segment for reads
- ocfs2: fix incorrect CPU endianness conversion causing mount failure
- ocfs2: handle a symlink read error correctly
- nilfs2: fix possible int overflows in nilfs_fiemap()
- nfs: Make NFS_FSCACHE select NETFS_SUPPORT instead of depending on it
- NFSD: Encode COMPOUND operation status on page boundaries
- mailbox: tegra-hsp: Clear mailbox before using message
- NFC: nci: Add bounds checking in nci_hci_create_pipe()
- irqchip/apple-aic: Only handle PMC interrupt as FIQ when configured so
- mtd: onenand: Fix uninitialized retlen in do_otp_read()
- misc: misc_minor_alloc to use ida for all dynamic/misc dynamic minors
- char: misc: deallocate static minor in error path
- misc: fastrpc: Deregister device nodes properly in error scenarios
- misc: fastrpc: Fix registered buffer page address
- misc: fastrpc: Fix copy buffer page size
- net/ncsi: wait for the last response to Deselect Package before
configuring channel
- net: phy: c45-tjaxx: add delay between MDIO write and read in soft_reset
- maple_tree: simplify split calculation
- scripts/gdb: fix aarch64 userspace detection in get_current_task
- tracing/osnoise: Fix resetting of tracepoints
- rtla/osnoise: Distinguish missing workload option
- rtla: Add trace_instance_stop
- rtla/timerlat_hist: Stop timerlat tracer on signal
- rtla/timerlat_top: Stop timerlat tracer on signal
- pinctrl: samsung: fix fwnode refcount cleanup if
platform_get_irq_optional() fails
- ptp: Ensure info->enable callback is always set
- RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error
- rtc: zynqmp: Fix optional clock name property
- MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static
- xfs: avoid nested calls to __xfs_trans_commit
- xfs: don't lose solo superblock counter update transactions
- spi: atmel-quadspi: Create `atmel_qspi_ops` to support newer SoC
families
- spi: atmel-qspi: Memory barriers after memory-mapped I/O
- btrfs: avoid monopolizing a core when activating a swap file
- mptcp: prevent excessive coalescing on receive
- Revert "drm/amd/display: Fix green screen issue after suspend"
- statmount: let unset strings be empty
- arm64: dts: rockchip: add reset-names for combphy on rk3568
- ocfs2: check dir i_size in ocfs2_find_entry
- Upstream stable to v6.6.77, v6.12.14
* kvmppc_set_passthru_irq_hv: Could not assign IRQ map traces are seen when
pci device is attached to kvm guest when "xive=off" is set (LP: #2109951)
- KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries KVM Guest
* Latitude 5450 is experiencing packet loss on Ethernet in Ubuntu 22.04
(LP: #2106558)
- e1000e: change k1 configuration on MTP and later platforms
* cpufreq amd-pstate: cpuinfo_max_freq reports incorrect value
(LP: #2109609)
- SAUCE: Revert "Revert "cpufreq: amd-pstate: Fix the inconsistency in max
frequency units""
* Backport pci=config_acs parameter with fix commit (LP: #2100340)
- PCI: Extend ACS configurability
- PCI: Fix pci_enable_acs() support for the ACS quirks
- PCI/ACS: Fix 'pci=config_acs=' parameter
* [UBUNTU 24.04] s390/pci: Fix zpci_bus_is_isolated_vf() for non-VF
(LP: #2111599)
- s390/pci: Fix zpci_bus_is_isolated_vf() for non-VFs
* nvme/tcp hangs IO on arm (LP: #2106381)
- nvmet-tcp: Fix a possible sporadic response drops in weakly ordered arch
* CVE-2025-37750
- smb: client: fix UAF in decryption with multichannel
* CVE-2025-40364
- io_uring: fix io_req_prep_async with provided buffers
* CVE-2024-49887
- f2fs: fix to handle segment allocation failure correctly
- f2fs: fix to don't panic system for no free segment fault injection
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953)
- powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump is active
- dlm: fix srcu_read_lock() return type to int
- afs: Fix EEXIST error returned from afs_rmdir() to be ENOTEMPTY
- afs: Fix directory format encoding struct
- afs: Fix cleanup of immediately failed async calls
- fs: fix proc_handler for sysctl_nr_open
- block: retry call probe after request_module in blk_request_module
- pstore/blk: trivial typo fixes
- nvme: Add error check for xa_store in nvme_get_effects_log
- selftests/powerpc: Fix argument order to timer_sub()
- nvme: Add error path for xa_store in nvme_init_effects
- partitions: ldm: remove the initial kernel-doc notation
- select: Fix unbalanced user_access_end()
- nvme: fix bogus kzalloc() return check in nvme_init_effects_log()
- afs: Fix the fallback handling for the YFS.RemoveFile2 RPC call
- perf/core: Save raw sample data conditionally based on sample type
- sched/fair: Fix value reported by hot tasks pulled in /proc/schedstat
- x86/cpu: Enable SD_ASYM_PACKING for PKG domain on AMD
- x86/topology: Use x86_sched_itmt_flags for PKG domain unconditionally
- drm/msm/dp: set safe_to_exit_level before printing it
- drm/etnaviv: Fix page property being used for non writecombine buffers
- drm/amd/pm: Fix an error handling path in
vega10_enable_se_edc_force_stall_config()
- drm/rockchip: vop2: Fix cluster windows alpha ctrl regsiters offset
- drm/rockchip: vop2: Fix the mixer alpha setup for layer 0
- drm/rockchip: vop2: Fix the windows switch between different layers
- drm/rockchip: vop2: Check linear format for Cluster windows on rk3566/8
- drm/rockchip: vop2: include rockchip_drm_drv.h
- drm/msm/dpu: link DSPP_2/_3 blocks on SM8150
- drm/msm/dpu: link DSPP_2/_3 blocks on SC8180X
- drm/msm/dpu: link DSPP_2/_3 blocks on SM8250
- drm/msm/dpu: link DSPP_2/_3 blocks on SM8350
- drm/msm/dpu: link DSPP_2/_3 blocks on SM8550
- drm/msm: Check return value of of_dma_configure()
- drm/bridge: it6505: Change definition of AUX_FIFO_MAX_SIZE
- drm/amdgpu: tear down ttm range manager for doorbell in
amdgpu_ttm_fini()
- genirq: Make handle_enforce_irqctx() unconditionally available
- wifi: ath11k: Fix unexpected return buffer manager error for
WCN6750/WCN6855
- wifi: rtlwifi: do not complete firmware loading needlessly
- wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last
step
- wifi: rtlwifi: wait for firmware loading before releasing memory
- wifi: rtlwifi: fix init_sw_vars leak when probe fails
- wifi: rtlwifi: usb: fix workqueue leak when probe fails
- net_sched: sch_sfq: annotate data-races around q->perturb_period
- net_sched: sch_sfq: handle bigger packets
- spi: zynq-qspi: Add check for clk_enable()
- dt-bindings: mmc: controller: clarify the address-cells description
- of: remove internal arguments from of_property_for_each_u32()
- clk: fix an OF node reference leak in of_clk_get_parent_name()
- dt-bindings: leds: class-multicolor: Fix path to color definitions
- wifi: rtlwifi: destroy workqueue at rtl_deinit_core
- wifi: rtlwifi: pci: wait for firmware loading before releasing memory
- HID: multitouch: fix support for Goodix PID 0x01e9
- regulator: dt-bindings: mt6315: Drop regulator-compatible property
- wifi: brcmfmac: add missing header include for brcmf_dbg
- ACPI: fan: cleanup resources in the error path of .probe()
- cpupower: fix TSC MHz calculation
- dt-bindings: mfd: bd71815: Fix rsense and typos
- leds: netxbig: Fix an OF node reference leak in
netxbig_leds_get_of_pdata()
- inetpeer: remove create argument of inet_getpeer_v[46]()
- inetpeer: remove create argument of inet_getpeer()
- inetpeer: update inetpeer timestamp in inet_getpeer()
- inetpeer: do not get a refcount in inet_getpeer()
- pwm: stm32-lp: Add check for clk_enable()
- cpufreq: schedutil: Fix superfluous updates caused by need_freq_update
- gpio: pca953x: log an error when failing to get the reset GPIO
- cpufreq: qcom: Fix qcom_cpufreq_hw_recalc_rate() to query LUT if LMh IRQ
is not available
- cpufreq: qcom: Implement clk_ops::determine_rate() for qcom_cpufreq*
clocks
- clk: imx8mp: Fix clkout1/2 support
- dt-bindings: clock: sunxi: Export PLL_VIDEO_2X and PLL_MIPI
- clk: sunxi-ng: a64: drop redundant CLK_PLL_VIDEO0_2X and CLK_PLL_MIPI
- clk: sunxi-ng: a64: stop force-selecting PLL-MIPI as TCON0 parent
- regulator: of: Implement the unwind path of of_regulator_match()
- OPP: OF: Fix an OF node leak in _opp_add_static_v2()
- ipmi: ssif_bmc: Fix new request loss when bmc ready for a response
- wifi: ath12k: fix tx power, max reg power update to firmware
- clk: qcom: gcc-sdm845: Do not use shared clk_ops for QUPs
- HID: fix generic desktop D-Pad controls
- leds: cht-wcove: Use devm_led_classdev_register() to avoid memory leak
- mfd: syscon: Remove extern from function prototypes
- mfd: syscon: Add of_syscon_register_regmap() API
- mfd: syscon: Use scoped variables with memory allocators to simplify
error paths
- mfd: syscon: Fix race in device_node_get_regmap()
- samples/landlock: Fix possible NULL dereference in parse_path()
- wifi: wlcore: fix unbalanced pm_runtime calls
- wifi: mt76: mt7915: Fix mesh scan on MT7916 DBDC
- wifi: mac80211: fix tid removal during mesh forwarding
- wifi: mac80211: Fix common size calculation for ML element
- net/smc: fix data error when recvmsg with MSG_PEEK flag
- wifi: mt76: mt76u_vendor_request: Do not print error messages when
-EPROTO
- wifi: mt76: mt7921: fix using incorrect group cipher after
disconnection.
- wifi: mt76: mt7915: fix overflows seen when writing limit attributes
- wifi: mt76: mt7996: fix rx filter setting for bfee functionality
- wifi: mt76: mt7915: firmware restart on devices with a second pcie link
- wifi: mt76: connac: move mt7615_mcu_del_wtbl_all to connac
- wifi: mt76: mt7915: improve hardware restart reliability
- wifi: mt76: mt7915: fix omac index assignment after hardware reset
- wifi: mt76: mt7915: fix register mapping
- wifi: mt76: mt7996: fix register mapping
- wifi: mt76: mt7996: add max mpdu len capability
- wifi: mt76: mt7996: fix the capability of reception of EHT MU PPDU
- wifi: mt76: mt7996: fix HE Phy capability
- wifi: mt76: mt7996: fix incorrect indexing of MIB FW event
- wifi: mt76: mt7996: fix ldpc setting
- cpufreq: ACPI: Fix max-frequency computation
- selftests: timers: clocksource-switch: Adapt progress to kselftest
framework
- selftests: harness: fix printing of mismatch values in __EXPECT()
- wifi: cfg80211: adjust allocation of colocated AP data
- inet: ipmr: fix data-races
- clk: analogbits: Fix incorrect calculation of vco rate delta
- pwm: stm32: Add check for clk_enable()
- selftests/landlock: Fix error message
- net/mlxfw: Drop hard coded max FW flash image size
- octeon_ep: remove firmware stats fetch in ndo_get_stats64
- netfilter: nf_tables: fix set size with rbtree backend
- netfilter: nft_flow_offload: update tcp state flags under lock
- tcp_cubic: fix incorrect HyStart round start detection
- libbpf: don't adjust USDT semaphore address if .stapsdt.base addr is
missing
- tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind
- libbpf: Fix segfault due to libelf functions not setting errno
- ASoC: sun4i-spdif: Add clock multiplier settings
- selftests/bpf: Fix fill_link_info selftest on powerpc
- crypto: caam - use JobR's space to access page 0 regs
- perf header: Fix one memory leakage in process_bpf_btf()
- perf header: Fix one memory leakage in process_bpf_prog_info()
- perf bpf: Fix two memory leakages when calling
perf_env__insert_bpf_prog_info()
- ASoC: renesas: rz-ssi: Use only the proper amount of dividers
- perf expr: Initialize is_test value in expr__ctx_new()
- ktest.pl: Remove unused declarations in run_bisect_test function
- crypto: hisilicon/sec2 - fix for aead icv error
- crypto: hisilicon/sec2 - fix for aead invalid authsize
- crypto: ixp4xx - fix OF node reference leaks in init_ixp_crypto()
- ALSA: seq: remove redundant 'tristate' for SND_SEQ_UMP_CLIENT
- ALSA: seq: Make dependency on UMP clearer
- padata: fix sysfs store callback check
- perf top: Don't complain about lack of vmlinux when not resolving some
kernel samples
- perf machine: Don't ignore _etext when not a text symbol
- perf namespaces: Introduce nsinfo__set_in_pidns()
- perf namespaces: Fixup the nsinfo__in_pidns() return type, its bool
- ASoC: Intel: avs: Prefix SKL/APL-specific members
- ASoC: Intel: avs: Abstract IPC handling
- ASoC: Intel: avs: Do not readq() u32 registers
- ASoC: Intel: avs: Fix theoretical infinite loop
- perf report: Fix misleading help message about --demangle
- pinctrl: stm32: Add check for clk_enable()
- pinctrl: amd: Take suspend type into consideration which pins are non-
wake
- bpf: tcp: Mark bpf_load_hdr_opt() arg2 as read-write
- ALSA: hda/realtek - Fixed headphone distorted sound on Acer Aspire
A115-31 laptop
- perf lock: Fix parse_lock_type which only retrieve one lock flag
- padata: add pd get/put refcnt helper
- cifs: Use cifs_autodisable_serverino() for disabling
CIFS_MOUNT_SERVER_INUM in readdir.c
- soc: atmel: fix device_node release in atmel_soc_device_init()
- ARM: at91: pm: change BU Power Switch to automatic mode
- arm64: dts: mediatek: mt8186: Move wakeup to MTU3 to get working suspend
- arm64: dts: mt8183: set DMIC one-wire mode on Damu
- arm64: dts: mediatek: mt8516: fix GICv2 range
- arm64: dts: mediatek: mt8516: fix wdt irq type
- arm64: dts: mediatek: mt8516: add i2c clock-div property
- arm64: dts: mediatek: mt8516: reserve 192 KiB for TF-A
- ARM: dts: stm32: Fix IPCC EXTI declaration on stm32mp151
- RDMA/mlx4: Avoid false error about access to uninitialized gids array
- arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property
- arm64: dts: mediatek: mt8173-elm: Drop regulator-compatible property
- arm64: dts: mediatek: mt8192-asurada: Drop regulator-compatible property
- arm64: dts: mediatek: mt8195-cherry: Drop regulator-compatible property
- arm64: dts: mediatek: mt8195-demo: Drop regulator-compatible property
- arm64: dts: mediatek: mt8173-elm: Fix MT6397 PMIC sub-node names
- arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names
- ARM: dts: aspeed: yosemite4: correct the compatible string of adm1272
- ARM: dts: aspeed: yosemite4: Add required properties for IOE on fan
boards
- ARM: dts: aspeed: yosemite4: correct the compatible string for max31790
- arm: dts: socfpga: use reset-name "stmmaceth-ocp" instead of "ahb"
- RDMA/rxe: Improve newline in printing messages
- RDMA/rxe: Fix mismatched max_msg_sz
- arm64: dts: mediatek: mt8183: kenzo: Support second source touchscreen
- arm64: dts: mediatek: mt8183: willow: Support second source touchscreen
- RDMA/srp: Fix error handling in srp_add_port
- arm64: dts: mediatek: mt8195: Remove suspend-breaking reset from pcie1
- ARM: dts: stm32: Deduplicate serial aliases and chosen node for
STM32MP15xx DHCOM SoM
- ARM: dts: stm32: Swap USART3 and UART8 alias on STM32MP15xx DHCOM SoM
- arm64: dts: mediatek: mt8183-kukui-jacuzzi: Drop pp3300_panel voltage
settings
- arm64: dts: qcom: msm8996-xiaomi-gemini: Fix LP5562 LED1 reg property
- arm64: dts: qcom: move common parts for sa8775p-ride variants into a
.dtsi
- arm64: dts: qcom: sa8775p: Update sleep_clk frequency
- arm64: dts: qcom: msm8996: Fix up USB3 interrupts
- arm64: dts: qcom: msm8994: Describe USB interrupts
- arm64: dts: qcom: sm7225-fairphone-fp4: Drop extra qcom,msm-id value
- arm64: dts: qcom: msm8916: correct sleep clock frequency
- arm64: dts: qcom: msm8939: correct sleep clock frequency
- arm64: dts: qcom: msm8994: correct sleep clock frequency
- arm64: dts: qcom: qcs404: correct sleep clock frequency
- arm64: dts: qcom: q[dr]u1000: correct sleep clock frequency
- arm64: dts: qcom: qrb4210-rb2: correct sleep clock frequency
- arm64: dts: qcom: sc7280: correct sleep clock frequency
- arm64: dts: qcom: sdx75: correct sleep clock frequency
- arm64: dts: qcom: sm4450: correct sleep clock frequency
- arm64: dts: qcom: sm6125: correct sleep clock frequency
- arm64: dts: qcom: sm6375: correct sleep clock frequency
- arm64: dts: qcom: sm8250: correct sleep clock frequency
- arm64: dts: qcom: sm8350: correct sleep clock frequency
- arm64: dts: qcom: sm8450: correct sleep clock frequency
- ARM: dts: microchip: sama5d27_wlsom1_ek: Add no-1-8-v property to sdmmc0
node
- arm64: dts: ti: k3-am62: Remove duplicate GICR reg
- arm64: dts: ti: k3-am62a: Remove duplicate GICR reg
- arm64: dts: allwinner: a64: explicitly assign clock parent for TCON0
- RDMA/bnxt_re: Fix to drop reference to the mmap entry in case of error
- ARM: omap1: Fix up the Retu IRQ on Nokia 770
- arm64: dts: qcom: sdm845-db845c-navigation-mezzanine: Convert mezzanine
riser to dtso
- arm64: dts: qcom: sdm845-db845c-navigation-mezzanine: remove disabled
ov7251 camera
- arm64: dts: qcom: sc7180-trogdor-quackingstick: add missing avee-supply
- arm64: dts: qcom: sc7180-*: Remove thermal zone polling delays
- arm64: dts: qcom: sc7180-trogdor-pompom: rename 5v-choke thermal zone
- arm64: dts: qcom: sc7180: change labels to lower-case
- arm64: dts: qcom: sc7180: fix psci power domain node names
- arm64: dts: qcom: sm8150-microsoft-surface-duo: fix typos in da7280
properties
- arm64: dts: qcom: sc8280xp: Fix up remoteproc register space sizes
- dts: arm64: mediatek: mt8195: Remove MT8183 compatible for OVL
- arm64: dts: mediatek: add per-SoC compatibles for keypad nodes
- arm64: dts: qcom: sdm845: Fix interrupt types of camss interrupts
- arm64: dts: qcom: sm8250: Fix interrupt types of camss interrupts
- ARM: dts: mediatek: mt7623: fix IR nodename
- fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()
- arm64: tegra: Fix DMA ID for SPI2
- i3c: dw: Add hot-join support.
- RDMA/mlx5: Fix indirect mkey ODP page count
- of: reserved-memory: Do not make kmemleak ignore freed address
- efi: sysfb_efi: fix W=1 warnings when EFI is not set
- spi: omap2-mcspi: Correctly handle devm_clk_get_optional() errors
- media: rc: iguanair: handle timeouts
- media: lmedm04: Handle errors for lme2510_int_read
- PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
- media: marvell: Add check for clk_enable()
- media: i2c: imx290: Register 0x3011 varies between imx327 and imx290
- media: i2c: imx412: Add missing newline to prints
- media: i2c: ov9282: Correct the exposure offset
- media: mipi-csis: Add check for clk_enable()
- media: camif-core: Add check for clk_enable()
- media: uvcvideo: Propagate buf->error to userspace
- mtd: rawnand: brcmnand: fix status read of brcmnand_waitfunc
- mtd: hyperbus: hbmc-am654: fix an OF node reference leak
- media: nxp: imx8-isi: fix v4l2-compliance test errors
- watchdog: rti_wdt: Fix an OF node leak in rti_wdt_probe()
- staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()
- media: dvb-usb-v2: af9035: fix ISO C90 compilation error on
af9035_i2c_master_xfer
- PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL on error
- PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
- scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
- scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
- ocfs2: mark dquot as inactive if failed to start trans while releasing
dquot
- module: Extend the preempt disabled section in
dereference_symbol_descriptor().
- serial: 8250: Adjust the timeout for FIFO mode
- NFSv4.2: fix COPY_NOTIFY xdr buf size calculation
- NFSv4.2: mark OFFLOAD_CANCEL MOVEABLE
- tools/bootconfig: Fix the wrong format specifier
- xfrm: replay: Fix the update of replay_esn->oseq_hi for GSO
- dmaengine: ti: edma: fix OF node reference leaks in edma_driver
- rtc: loongson: clear TOY_MATCH0_REG in loongson_rtc_isr()
- regulator: core: Add missing newline character
- gpio: mxc: remove dead code after switch to DT-only
- net: fec: implement TSO descriptor cleanup
- PM: hibernate: Add error handling for syscore_suspend()
- iavf: allow changing VLAN state without calling PF
- net: netdevsim: try to close UDP port harness races
- ptp: Properly handle compat ioctls
- net: stmmac: Limit the number of MTL queues to hardware capability
- net: stmmac: Limit FIFO size by hardware capability
- perf trace: Fix runtime error of index out of bounds
- Bluetooth: btnxpuart: Fix glitches seen in dual A2DP streaming
- vsock: Allow retrying on connect() failure
- bgmac: reduce max frame size to support just MTU 1500
- net: sh_eth: Fix missing rtnl lock in suspend/resume path
- genksyms: fix memory leak when the same symbol is added from source
- genksyms: fix memory leak when the same symbol is read from *.symref
file
- RISC-V: Mark riscv_v_init() as __init
- ASoC: rockchip: i2s_tdm: Re-add the set_sysclk callback
- io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock()
- cifs: Fix getting and setting SACLs over SMB1
- kconfig: fix file name in warnings when loading KCONFIG_DEFCONFIG_LIST
- kconfig: fix memory leak in sym_warn_unmet_dep()
- hexagon: fix using plain integer as NULL pointer warning in cmpxchg
- hexagon: Fix unbalanced spinlock in die()
- f2fs: Introduce linear search for dentries
- Revert "SUNRPC: Reduce thread wake-up rate when receiving large RPC
messages"
- kbuild: switch from lz4c to lz4 for compression
- selftests/rseq: Fix handling of glibc without rseq support
- ktest.pl: Check kernelrelease return in get_version
- ALSA: usb-audio: Add delay quirk for iBasso DC07 Pro
- usb: gadget: f_tcm: Fix Get/SetInterface return value
- usb: dwc3-am62: Fix an OF node leak in phy_syscon_pll_refclk()
- usb: dwc3: core: Defer the probe until USB power supply ready
- usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to
PD_T_SENDER_RESPONSE
- usb: typec: tcpci: Prevent Sink disconnection before vPpsShutdown in SPR
PPS
- btrfs: output the reason for open_ctree() failure
- s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
- LoongArch: Change 8 to 14 for LOONGARCH_MAX_{BRP,WRP}
- block: copy back bounce buffer to user-space correctly in case of split
- nvme-tcp: Fix I/O queue cpu spreading for multiple controllers
- sched/fair: Untangle NEXT_BUDDY and pick_next_task()
- sched: Fix race between yield_to() and try_to_wake_up()
- drm/v3d: Fix performance counter source settings on V3D 7.x
- drm/rockchip: vop2: fix rk3588 dp+dsi maxclk verification
- drm/rockchip: vop2: Set AXI id for rk3588
- drm/rockchip: vop2: Setup delay cycle for Esmart2/3
- drm/rockchip: vop2: Add check for 32 bpp format for rk3588
- drm/msm/dpu: provide DSPP and correct LM config for SDM670
- drm/msm/dpu: link DSPP_2/_3 blocks on SM8650
- drm/msm: don't clean up priv->kms prematurely
- drm/msm/mdp4: correct LCDC regulator name
- wifi: rtlwifi: rtl8821ae: phy: restore removed code to fix infinite loop
- selftests/bpf: Actuate tx_metadata_len in xdp_hw_metadata
- selftests: ktap_helpers: Fix uninitialized variable
- inet: constify inet_sk_bound_dev_eq() net parameter
- inet: constify 'struct net' parameter of various lookup helpers
- udp: constify 'struct net' parameter of socket lookups
- inet6: constify 'struct net' parameter of various lookup helpers
- ipv6: udp: constify 'struct net' parameter of socket lookups
- dt-bindings: clock: imx93: Drop IMX93_CLK_END macro definition
- dt-bindings: clock: Add i.MX91 clock support
- dt-bindings: clock: imx93: Add SPDIF IPG clk
- clk: imx93: Move IMX93_CLK_END macro to clk driver
- clk: imx: add i.MX91 clk
- clk: imx93: Add IMX93_CLK_SPDIF_IPG clock
- arm64: dts: imx93: Use IMX93_CLK_SPDIF_IPG as SPDIF IPG clock
- clk: imx: Apply some clks only for i.MX93
- wifi: rtw89: mcc: consider time limits not divisible by 1024
- wifi: iwlwifi: cleanup uefi variables loading
- wifi: iwlwifi: fw: read STEP table from correct UEFI var
- wifi: mt76: mt7996: fix overflows seen when writing limit attributes
- wifi: mt76: mt7996: fix definition of tx descriptor
- Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name()
- platform/mellanox: mlxbf-pmc: incorrect type in assignment
- platform/x86: x86-android-tablets: make platform data be static
- crypto: api - Fix boot-up self-test race
- pinctrl: nomadik: Add check for clk_enable()
- rhashtable: Fix potential deadlock by moving schedule_work outside lock
- crypto: iaa - Fix IAA disabling that occurs when sync_mode is set to
'async'
- perf maps: Fix display of kernel symbols
- perf MANIFEST: Add arch/*/include/uapi/asm/bpf_perf_event.h to the perf
tarball
- ALSA: hda: Fix compilation of snd_hdac_adsp_xxx() helpers
- tools: Sync if_xdp.h uapi tooling header
- rhashtable: Fix rhashtable_try_insert test
- ARM: dts: imx7-tqma7: add missing vs-supply for LM75A (rev. 01xxx)
- arm64: dts: renesas: rzg3s-smarc: Fix the debug serial alias
- arm64: dts: mediatek: mt8395-genio-1200-evk: Drop regulator-compatible
property
- arm64: dts: qcom: sm8550: correct sleep clock frequency
- arm64: dts: qcom: sm8650: correct sleep clock frequency
- arm64: dts: qcom: x1e80100: correct sleep clock frequency
- ARM: dts: microchip: sama5d29_curiosity: Add no-1-8-v property to sdmmc0
node
- RDMA/hns: Clean up the legacy CONFIG_INFINIBAND_HNS
- [Config] updateconfigs for INFINIBAND_HNS
- RDMA/cxgb4: Notify rdma stack for IB_EVENT_QP_LAST_WQE_REACHED event
- iommu: iommufd: fix WARNING in iommufd_device_unbind
- remoteproc: mtk_scp: Only populate devices for SCP cores
- PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
- PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
- PCI: microchip: Add support for using either Root Port 1 or 2
- PCI: microchip: Set inbound address translation for coherent or non-
coherent mode
- erofs: get rid of erofs_{find,insert}_workgroup
- erofs: move erofs_workgroup operations into zdata.c
- erofs: sunset `struct erofs_workgroup`
- erofs: fix potential return value overflow of z_erofs_shrink_scan()
- tty: mips_ejtag_fdc: fix one more u8 warning
- xfrm: Add support for per cpu xfrm state handling.
- xfrm: Cache used outbound xfrm states at the policy.
- xfrm: Add an inbound percpu state cache.
- xfrm: Don't disable preemption while looking up cache state.
- idpf: add read memory barrier when checking descriptor done bit
- net/ncsi: use dev_set_mac_address() for Get MC MAC Address handling
- tools: ynl: c: correct reverse decode of empty attrs
- selftests: mptcp: extend CFLAGS to keep options from environment
- selftests: net/{lib,openvswitch}: extend CFLAGS to keep options from
environment
- net: ethtool: only allow set_rxnfc with rss + ring_cookie if driver opts
in
- ethtool: Fix set RXNFC command with symmetric RSS hash
- tools/power turbostat: Fix forked child affinity regression
- md: add a new callback pers->bitmap_sector()
- md/raid5: implement pers->bitmap_sector()
- xfs: check for dead buffers in xfs_buf_find_insert
- xfs: don't shut down the filesystem for media failures beyond end of log
- usb: dwc3: Skip resume if pm_runtime_set_active() fails
- clk: qcom: gcc-x1e80100: Do not turn off usb_2 controller GDSC
- xfrm: Add error handling when nla_put_u32() returns an error
- xfrm: Fix acquire state insertion.
- ethtool: Fix access to uninitialized fields in set RXNFC command
- ASoC: da7213: Initialize the mutex
- drm/amd/display: Add hubp cache reset when powergating
- KVM: x86: Plumb in the vCPU to kvm_x86_ops.hwapic_isr_update()
- ethtool: ntuple: fix rss + ring_cookie check
- Upstream stable to v6.6.76, v6.12.13
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57975
- btrfs: do proper folio cleanup when run_delalloc_nocow() failed
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21714
- RDMA/mlx5: Fix implicit ODP use after free
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21801
- net: ravb: Fix missing rtnl lock in suspend/resume path
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21809
- rxrpc, afs: Fix peer hash locking vs RCU callback
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58057
- idpf: convert workqueues to unbound
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57953
- rtc: tps6594: Fix integer overflow on 32bit systems
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57982
- xfrm: state: fix out-of-bounds read during lookup
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21721
- nilfs2: handle errors that nilfs_prepare_chunk() may return
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21722
- nilfs2: do not force clear folio if buffer is referenced
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21798
- firewire: test: Fix potential null dereference in firewire kunit test
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21723
- scsi: mpi3mr: Fix possible crash when setting up bsg fails
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21724
- iommufd/iova_bitmap: Fix shift-out-of-bounds in
iova_bitmap_offset_to_index()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21825
- bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57990
- wifi: mt76: mt7925: fix off by one in mt7925_load_clc()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57974
- udp: Deal with race between UDP socket address change and rehash
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57994
- ptr_ring: do not block hard interrupts in ptr_ring_resize_multiple()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57999
- powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58054
- staging: media: max96712: fix kernel oops when removing module
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58055
- usb: gadget: f_tcm: Don't free command immediately
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57979
- pps: Fix a use-after-free
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57980
- media: uvcvideo: Fix double free in error path
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58056
- remoteproc: core: Fix ida_free call while not allocated
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21705
- mptcp: handle fastopen disconnect correctly
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21707
- mptcp: consolidate suboption status
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57981
- usb: xhci: Fix NULL pointer dereference on certain command aborts
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21708
- net: usb: rtl8150: enable basic endpoint checking
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21826
- netfilter: nf_tables: reject mismatching sum of field_len with set key
length
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21808
- net: xdp: Disallow attaching device-bound programs in generic mode
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21710
- tcp: correct handling of extreme memory squeeze
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21715
- net: davicom: fix UAF in dm9000_drv_remove
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21716
- vxlan: Fix uninit-value in vxlan_vnifilter_dump()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21718
- net: rose: fix timer races against user threads
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21719
- ipmr: do not call mr_mfc_uses_dev() for unres entries
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21802
- net: hns3: fix oops when unload drivers paralleling
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58058
- ubifs: skip dumping tnc tree when zroot is null
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58069
- rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21720
- xfrm: delete intermediate secpath entry in packet offload mode
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21803
- LoongArch: Fix warnings during S3 suspend
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21810
- driver core: class: Fix wild pointer dereferences in API
class_dev_iter_next()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21811
- nilfs2: protect access to buffers with no active references
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21804
- PCI: rcar-ep: Fix incorrect variable used when calling
devm_request_mem_region()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21829
- RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]"
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57984
- i3c: dw: Fix use-after-free in dw_i3c_master driver due to race
condition
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58034
- memory: tegra20-emc: fix an OF node reference bug in
tegra_emc_find_node_by_ram_code()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57973
- rdma/cxgb4: Prevent potential integer overflow on 32bit
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21725
- smb: client: fix oops due to unset link speed
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21726
- padata: avoid UAF for reorder_work
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21727
- padata: fix UAF in padata_reorder
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21728
- bpf: Send signals asynchronously if !preemptible
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58070
- bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21711
- net/rose: prevent integer overflows in rose_setsockopt()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21799
- net: ethernet: ti: am65-cpsw: fix freeing IRQ in
am65_cpsw_nuss_remove_tx_chns()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21806
- net: let net.core.dev_weight always be non-zero
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21830
- landlock: Handle weird files
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21828
- wifi: mac80211: don't flush non-uploaded STAs
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58061
- wifi: mac80211: prohibit deactivating all links
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57993
- HID: hid-thrustmaster: Fix warning in thrustmaster_probe by adding
endpoint check
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21812
- ax25: rcu protect dev->ax25_ptr
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58071
- team: prevent adding a device which is already a team device lower
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58063
- wifi: rtlwifi: fix memory leaks and invalid access at probe error path
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58072
- wifi: rtlwifi: remove unused check_buddy_priv
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58053
- rxrpc: Fix handling of received connection abort
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57996
- net_sched: sch_sfq: don't allow 1 packet limit
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57997
- wifi: wcn36xx: fix channel survey memory allocation size
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58051
- ipmi: ipmb: Add check devm_kasprintf() returned value
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58068
- OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57998
- OPP: add index check to assert to avoid buffer overflow in _read_freq()
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-58052
- drm/amdgpu: Fix potential NULL pointer dereference in
atomctrl_get_smc_sclk_range_table
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2024-57986
- HID: core: Fix assumption that Resolution Multipliers must be in Logical
Collections
* Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
CVE-2025-21731
- nbd: don't allow reconnect after disconnect
* CVE-2025-37798
- sch_htb: make htb_qlen_notify() idempotent
- sch_htb: make htb_deactivate() idempotent
- sch_drr: make drr_qlen_notify() idempotent
- sch_hfsc: make hfsc_qlen_notify() idempotent
- sch_qfq: make qfq_qlen_notify() idempotent
- sch_ets: make est_qlen_notify() idempotent
- codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
* CVE-2025-37997
- netfilter: ipset: fix region locking in hash types
* CVE-2025-22088
- RDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
* CVE-2025-37890
- net_sched: hfsc: Fix a UAF vulnerability in class with netem as child
qdisc
- sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
- net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
* raid1: Fix NULL pointer dereference in process_checks() (LP: #2112519)
- md/raid1: Add check for missing source disk in process_checks()
* Packaging resync (LP: #1786013)
- [Packaging] update variants
- [Packaging] update annotations scripts
[ Ubuntu-realtime: 6.8.1-1024.25 ]
* noble/linux-realtime: 6.8.1-1024.25 -proposed tracker (LP: #2114337)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
[ Ubuntu: 6.8.0-63.66 ]
* noble/linux: 6.8.0-63.66 -proposed tracker (LP: #2114341)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
- [Packaging] update annotations scripts
* CVE-2025-37798
- sch_htb: make htb_qlen_notify() idempotent
- sch_htb: make htb_deactivate() idempotent
- sch_drr: make drr_qlen_notify() idempotent
- sch_hfsc: make hfsc_qlen_notify() idempotent
- sch_qfq: make qfq_qlen_notify() idempotent
- sch_ets: make est_qlen_notify() idempotent
- codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
* CVE-2025-37997
- netfilter: ipset: fix region locking in hash types
* CVE-2025-22088
- RDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
* CVE-2025-37890
- net_sched: hfsc: Fix a UAF vulnerability in class with netem as child
qdisc
- sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
- net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
* raid1: Fix NULL pointer dereference in process_checks() (LP: #2112519)
- md/raid1: Add check for missing source disk in process_checks()
linux-nvidia-tegra (6.8.0-1006.6) noble; urgency=medium
* noble/linux-nvidia-tegra: 6.8.0-1006.6 -proposed tracker (LP: #2113896)
linux-nvidia-tegra (6.8.0-1005.5) noble; urgency=medium
* noble/linux-nvidia-tegra: 6.8.0-1005.5 -proposed tracker (LP: #2111512)
* Packaging resync (LP: #1786013)
- [Packaging] debian.nvidia-tegra/dkms-versions -- update from kernel-versions
(main/d2025.05.22)
* NVIDIA OOTM fails to compile due to small CONFIG_FRAME_WARN (LP: #2109728)
- [Config] Match default upstream value CONFIG_FRAME_WARN=2048
[ Ubuntu: 6.8.1-1023.24 ]
* noble/linux-realtime: 6.8.1-1023.24 -proposed tracker (LP: #2110731)
[ Ubuntu: 6.8.0-62.65 ]
* noble/linux: 6.8.0-62.65 -proposed tracker (LP: #2110737)
* Rotate the Canonical Livepatch key (LP: #2111244)
- [Config] Prepare for Canonical Livepatch key rotation
* KVM bug causes Firecracker crash when it runs the vCPU for the first time
(LP: #2109859)
- vhost: return task creation error instead of NULL
- kvm: retry nx_huge_page_recovery_thread creation
* CVE-2025-2312 cifs.upcall could access incorrect kerberos credentials cache
(LP: #2099914) // CVE-2025-2312
- CIFS: New mount option for cifs.upcall namespace resolution
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640)
- ASoC: wm8994: Add depends on MFD core
- ASoC: samsung: Add missing selects for MFD_WM8994
- seccomp: Stub for !CONFIG_SECCOMP
- scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request
- of/unittest: Add test that of_address_to_resource() fails on non-
translatable address
- irqchip/sunxi-nmi: Add missing SKIP_WAKE flag
- hwmon: (drivetemp) Set scsi command timeout to 10s
- ASoC: samsung: Add missing depends on I2C
- ata: libata-core: Set ATA_QCFLAG_RTF_FILLED in fill_result_tf()
- Revert "libfs: fix infinite directory reads for offset dir"
- libfs: Replace simple_offset end-of-directory detection
- Revert "HID: multitouch: Add support for lenovo Y9000P Touchpad"
- ALSA: usb-audio: Add delay quirk for USB Audio Device
- Input: xpad - add support for Nacon Pro Compact
- Input: atkbd - map F23 key to support default copilot shortcut
- Input: xpad - add unofficial Xbox 360 wireless receiver clone
- Input: xpad - add QH Electronics VID/PID
- Input: xpad - improve name of 8BitDo controller 2dc8:3106
- Input: xpad - add support for Nacon Evol-X Xbox One Controller
- Input: xpad - add support for wooting two he (arm)
- ASoC: codecs: es8316: Fix HW rate calculation for 48Mhz MCLK
- ASoC: cs42l43: Add codec force suspend/resume ops
- ALSA: hda/realtek: Fix volume adjustment issue on Lenovo ThinkBook 16P Gen5
- libfs: Return ENOSPC when the directory offset range is exhausted
- Revert "libfs: Add simple_offset_empty()"
- libfs: Use d_children list to iterate simple_offset directories
- wifi: rtl8xxxu: add more missing rtl8192cu USB IDs
- HID: wacom: Initialize brightness of LED trigger
- Upstream stable to v6.6.75, v6.12.12
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2025-21689
- USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2025-21690
- scsi: storvsc: Ratelimit warning logs to prevent VM denial of service
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2025-21691
- cachestat: fix page cache statistics permission checking
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2025-21692
- net: sched: fix ets qdisc OOB Indexing
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2025-21699
- gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
* Noble update: upstream stable patchset 2025-04-29 (LP: #2109640) //
CVE-2024-50157
- RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop
* rtw89: Support hardware rfkill (LP: #2077384)
- wifi: rtw89: add support for hardware rfkill
* Introduce configfs-based interface for gpio-aggregator (LP: #2103496)
- gpio: introduce utilities for synchronous fake device creation
- bitmap: Define a cleanup function for bitmaps
- gpio: aggregator: simplify aggr_parse() with scoped bitmap
- gpio: aggregator: protect driver attr handlers against module unload
- gpio: aggregator: reorder functions to prepare for configfs introduction
- gpio: aggregator: unify function naming
- gpio: aggregator: add gpio_aggregator_{alloc, free}()
- gpio: aggregator: introduce basic configfs interface
- [Config] Enable DEV_SYNC_PROBE as module
- SAUCE: gpio: aggregator: Fix error code in gpio_aggregator_activate()
- gpio: aggregator: rename 'name' to 'key' in gpio_aggregator_parse()
- gpio: aggregator: expose aggregator created via legacy sysfs to configfs
- SAUCE: gpio: aggregator: fix "_sysfs" prefix check in
gpio_aggregator_make_group()
- SAUCE: gpio: aggregator: Fix gpio_aggregator_line_alloc() checking
- SAUCE: gpio: aggregator: Return an error if there are no GPIOs in
gpio_aggregator_parse()
- SAUCE: gpio: aggregator: Fix leak in gpio_aggregator_parse()
- gpio: aggregator: cancel deferred probe for devices created via configfs
- Documentation: gpio: document configfs interface for gpio-aggregator
- selftests: gpio: add test cases for gpio-aggregator
- SAUCE: selftests: gpio: gpio-aggregator: add a test case for _sysfs prefix
reservation
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449)
- net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field()
- net: add exit_batch_rtnl() method
- gtp: use exit_batch_rtnl() method
- gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp().
- gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
- nfp: bpf: prevent integer overflow in nfp_bpf_event_output()
- net: xilinx: axienet: Fix IRQ coalescing packet count overflow
- net/mlx5: Fix RDMA TX steering prio
- net/mlx5e: Rely on reqid in IPsec tunnel mode
- net/mlx5e: Always start IPsec sequence number from 1
- drm/vmwgfx: Add new keep_resv BO param
- drm/v3d: Assign job pointer to NULL before signaling the fence
- soc: ti: pruss: Fix pruss APIs
- hwmon: (tmp513) Fix division of negative numbers
- i2c: mux: demux-pinctrl: check initial mux selection, too
- i2c: rcar: fix NACK handling when being a target
- hfs: Sanity check the root record
- fs: fix missing declaration of init_files
- kheaders: Ignore silly-rename files
- cachefiles: Parse the "secctx" immediately
- scsi: ufs: core: Honor runtime/system PM levels if set by host controller
drivers
- selftests: tc-testing: reduce rshift value
- ACPI: resource: acpi_dev_irq_override(): Check DMI match last
- poll_wait: add mb() to fix theoretical race between waitqueue_active() and
.poll()
- RDMA/bnxt_re: Fix to export port num to ib_query_qp
- nvmet: propagate npwg topology
- ALSA: hda/realtek: Add support for Ayaneo System using CS35L41 HDA
- i2c: atr: Fix client detach
- mptcp: be sure to send ack when mptcp-level window re-opens
- mptcp: fix spurious wake-up on under memory pressure
- selftests: mptcp: avoid spurious errors on disconnect
- net: ethernet: xgbe: re-add aneg to supported features in PHY quirks
- vsock/virtio: cancel close work in the destructor
- vsock: reset socket state when de-assigning the transport
- nouveau/fence: handle cross device fences properly
- irqchip: Plug a OF node reference leak in platform_irqchip_probe()
- irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly
- drm/i915/fb: Relax clear color alignment to 64 bytes
- drm/amdgpu: always sync the GFX pipe on ctx switch
- ocfs2: fix deadlock in ocfs2_get_system_file_inode
- nfsd: add list_head nf_gc to struct nfsd_file
- x86/xen: fix SLS mitigation in xen_hypercall_iret()
- efi/zboot: Limit compression options to GZIP and ZSTD
- [Config] updateconfigs for HAVE_KERNEL_(LZ4|LZMA|LZO|XZ)
- net: ravb: Fix max TX frame size for RZ/V2M
- net/mlx5: SF, Fix add port error handling
- drm/vmwgfx: Unreserve BO on error
- i2c: testunit: on errors, repeat NACK until STOP
- hwmon: (ltc2991) Fix mixed signed/unsigned in DIV_ROUND_CLOSEST
- fs/qnx6: Fix building with GCC 15
- gpio: sim: lock up configfs that an instantiated device depends on
- gpio: sim: lock hog configfs items if present
- platform/x86: ISST: Add Clearwater Forest to support list
- drm/nouveau/disp: Fix missing backlight control on Macbook 5,1
- net/ncsi: fix locking in Get MAC Address handling
- drm/amd/display: Do not elevate mem_type change to full update
- drm/xe: Mark ComputeCS read mode as UC on iGPU
- drm/amdgpu/smu13: update powersave optimizations
- drm/amdgpu: fix fw attestation for MP0_14_0_{2/3}
- drm/amdgpu: disable gfxoff with the compute workload on gfx12
- drm/amd/display: Fix PSR-SU not support but still call the
amdgpu_dm_psr_enable
- Upstream stable to v6.6.73, v6.6.74, v6.12.11
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21672
- afs: Fix merge preference rule failure condition
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21682
- eth: bnxt: always recalculate features after XDP clearing, fix null-deref
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2024-53124
- net: fix data-races around sk->sk_forward_alloc
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2024-57924
- fs: relax assertions on failure to encode file handles
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2024-57951
- hrtimers: Handle CPU state correctly on hotplug
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2024-57949
- irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity()
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21668
- pmdomain: imx8mp-blk-ctrl: add missing loop break condition
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21684
- gpio: xilinx: Convert gpio_lock to raw spinlock
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21694
- fs/proc: fix softlockup in __read_vmcore (part 2)
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21665
- filemap: avoid truncating 64-bit offset to 32 bits
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21666
- vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21669
- vsock/virtio: discard packets if the transport changes
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21670
- vsock/bpf: return early if transport is not assigned
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21667
- iomap: avoid avoid truncating 64-bit offset to 32 bits
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2024-57948
- mac802154: check local interfaces before deleting sdata list
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21673
- smb: client: fix double free of TCP_Server_Info::hostname
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21697
- drm/v3d: Ensure job pointer is set to NULL after job completion
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21674
- net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21675
- net/mlx5: Clear port select structure when fail to create
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21676
- net: fec: handle page_pool_dev_alloc_pages error
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21678
- gtp: Destroy device along with udp socket's netns dismantle.
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21680
- pktgen: Avoid out-of-bounds access in get_imix_entries
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21681
- openvswitch: fix lockup on tx to unregistering netdev with carrier
* Noble update: upstream stable patchset 2025-04-16 (LP: #2107449) //
CVE-2025-21683
- bpf: Fix bpf_sk_select_reuseport() memory leak
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
[ Ubuntu: 6.8.1-1022.23 ]
* noble/linux-realtime: 6.8.1-1022.23 -proposed tracker (LP: #2107133)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
[ Ubuntu: 6.8.0-60.63 ]
* noble/linux: 6.8.0-60.63 -proposed tracker (LP: #2107138)
* Packaging resync (LP: #1786013)
- [Packaging] debian.master/dkms-versions -- update from kernel-versions
(main/2025.04.14)
* Missing upstream commits for LP: #2102181 (LP: #2107336)
- libperf cpumap: Add any, empty and min helpers
- libperf cpumap: Ensure empty cpumap is NULL from alloc
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770)
- memblock: use numa_valid_node() helper to check for invalid node ID
- jbd2: increase IO priority for writing revoke records
- jbd2: flush filesystem device before updating tail sequence
- dm array: fix unreleased btree blocks on closing a faulty array cursor
- dm array: fix cursor index when skipping across block boundaries
- exfat: fix the infinite loop in __exfat_free_cluster()
- erofs: fix PSI memstall accounting
- ASoC: rt722: add delay time to wait for the calibration procedure
- ASoC: mediatek: disable buffer pre-allocation
- selftests/alsa: Fix circular dependency involving global-timer
- ieee802154: ca8210: Add missing check for kfifo_alloc() in ca8210_probe()
- net: 802: LLC+SNAP OID:PID lookup on start of skb data
- tcp/dccp: complete lockless accesses to sk->sk_max_ack_backlog
- tcp/dccp: allow a connection when sk_max_ack_backlog is zero
- net: libwx: fix firmware mailbox abnormal return
- pds_core: limit loop over fw name list
- bnxt_en: Fix possible memory leak when hwrm_req_replace fails
- cxgb4: Avoid removal of uninserted tid
- ice: fix incorrect PHY settings for 100 GB/s
- igc: return early when failing to read EECD register
- tls: Fix tls_sw_sendmsg error handling
- eth: gve: use appropriate helper to set xdp_features
- Bluetooth: hci_sync: Fix not setting Random Address when required
- Bluetooth: MGMT: Fix Add Device to responding before completing
- Bluetooth: btnxpuart: Fix driver sending truncated data
- tcp: Annotate data-race around sk->sk_mark in tcp_v4_send_reset
- riscv: Fix early ftrace nop patching
- memblock tests: fix implicit declaration of function 'numa_valid_node'
- iio: imu: inv_icm42600: fix timestamps after suspend if sensor is on
- netfilter: nf_tables: imbalance in flowtable binding
- drm/mediatek: stop selecting foreign drivers
- [Config] updateconfigs for MTK_SMI
- drm/mediatek: Fix YCbCr422 color format issue for DP
- drm/mediatek: Fix mode valid issue for dp
- drm/mediatek: Add return value check when reading DPCD
- cpuidle: riscv-sbi: fix device node release in early exit of
for_each_possible_cpu
- scsi: ufs: qcom: Power off the PHY if it was already powered on in
ufs_qcom_power_up_sequence()
- dm-ebs: don't set the flag DM_TARGET_PASSES_INTEGRITY
- ksmbd: Implement new SMB3 POSIX type
- thermal: of: fix OF node leak in of_thermal_zone_find()
- smb: client: sync the root session and superblock context passwords before
automounting
- ACPI: resource: Add TongFang GM5HG0A to irq1_edge_low_force_override[]
- ACPI: resource: Add Asus Vivobook X1504VAP to irq1_level_low_skip_override[]
- drm/amd/display: increase MAX_SURFACES to the value supported by hw
- io_uring/timeout: fix multishot updates
- dm-verity FEC: Fix RS FEC repair for roots unaligned to block size (take 2)
- USB: serial: option: add MeiG Smart SRM815
- USB: serial: option: add Neoway N723-EA support
- staging: iio: ad9834: Correct phase range check
- staging: iio: ad9832: Correct phase range check
- usb-storage: Add max sectors quirk for Nokia 208
- USB: serial: cp210x: add Phoenix Contact UPS Device
- usb: dwc3: gadget: fix writing NYET threshold
- misc: microchip: pci1xxxx: Resolve return code mismatch during GPIO set
config
- tty: serial: 8250: Fix another runtime PM usage counter underflow
- usb: dwc3-am62: Disable autosuspend during remove
- USB: usblp: return error when setting unsupported protocol
- USB: core: Disable LPM only for non-suspended ports
- usb: fix reference leak in usb_new_device()
- usb: gadget: midi2: Reverse-select at the right place
- usb: chipidea: ci_hdrc_imx: decrement device's refcount in .remove() and in
the error path of .probe()
- usb: gadget: f_uac2: Fix incorrect setting of bNumEndpoints
- usb: typec: tcpm/tcpci_maxim: fix error code in
max_contaminant_read_resistance_kohm()
- usb: gadget: configfs: Ignore trailing LF for user strings to cdev
- iio: gyro: fxas21002c: Fix missing data update in trigger handler
- iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()
- iio: inkern: call iio_device_put() only on mapped devices
- iio: adc: ad7124: Disable all channels at probe time
- riscv: kprobes: Fix incorrect address calculation
- ARM: dts: imxrt1050: Fix clocks for mmc
- arm64: dts: rockchip: add hevc power domain clock to rk3328
- pmdomain: imx: gpcv2: Simplify with scoped for each OF child loop
- pmdomain: imx: gpcv2: fix an OF node reference leak in imx_gpcv2_probe()
- workqueue: Add rcu lock check at the end of work item execution
- workqueue: Update lock debugging code
- mm/hugetlb: enforce that PMD PT sharing has split PMD PT locks
- riscv: Fix text patching when IPI are used
- drm/mediatek: Only touch DISP_REG_OVL_PITCH_MSB if AFBC is supported
- ovl: pass realinode to ovl_encode_real_fh() instead of realdentry
- net: don't dump Tx and uninitialized NAPIs
- ice: fix max values for dpll pin phase adjust
- net: hns3: fixed reset failure issues caused by the incorrect reset type
- net: hns3: fix missing features due to dev->features configuration too early
- net: hns3: Resolved the issue that the debugfs query result is inconsistent.
- net: hns3: initialize reset_timer before hclgevf_misc_irq_init()
- mctp i3c: fix MCTP I3C driver multi-thread issue
- drm/mediatek: Move mtk_crtc_finish_page_flip() to ddp_cmdq_cb()
- drm/mediatek: Add support for 180-degree rotation in the display driver
- drm/mediatek: mtk_dsi: Add registers to pdata to fix MT8186/MT8188
- platform/x86: intel/pmc: Fix ioremap() of bad address
- riscv: module: remove relocation_head rel_entry member allocation
- cgroup/cpuset: Prevent leakage of isolated CPUs into sched domains
- fs: kill MNT_ONRB
- gpio: loongson: Fix Loongson-2K2000 ACPI GPIO register offset
- drm/amd/pm: fix BUG: scheduling while atomic
- drm/amdkfd: wq_release signals dma_fence only when available
- drm/amd/display: fix divide error in DM plane scale calcs
- drm/amd/display: fix page fault due to max surface definition mismatch
- serial: stm32: use port lock wrappers for break control
- usb: host: xhci-plat: set skip_phy_initialization if software node has
XHCI_SKIP_PHY_INIT property
- iio: imu: inv_icm42600: add register caching in the regmap
- iio: imu: inv_icm42600: fix spi burst write not supported
- Upstream stable to v6.6.71, v6.6.72, v6.12.10
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21659
- netdev: prevent accessing NAPI instances from another namespace
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21634
- cgroup/cpuset: remove kernfs active break
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21635
- rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21643
- netfs: Fix kernel async DIO
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21649
- net: hns3: fix kernel crash when 1588 is sent on HIP08 devices
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21650
- net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21651
- net: hns3: don't auto enable misc vector
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21654
- ovl: support encoding fid from inode with no alias
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57883
- mm: hugetlb: independent PMD page table shared count
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57888
- workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from
!WQ_MEM_RECLAIM worker
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21631
- block, bfq: fix waker_bfqq UAF after bfq_split_bfqq()
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21656
- hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21655
- io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57904
- iio: adc: at91: call input_free_device() on allocated iio_dev
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57906
- iio: adc: ti-ads8688: fix information leak in triggered buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57907
- iio: adc: rockchip_saradc: fix information leak in triggered buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57908
- iio: imu: kmx61: fix information leak in triggered buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57910
- iio: light: vcnl4035: fix information leak in triggered buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57911
- iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered
buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57912
- iio: pressure: zpa2326: fix information leak in triggered buffer
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57913
- usb: gadget: f_fs: Remove WARN_ON in functionfs_bind
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21632
- x86/fpu: Ensure shadow stack is active before "getting" registers
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57916
- misc: microchip: pci1xxxx: Resolve kernel panic during GPIO IRQ handling
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57917
- topology: Keep the cpumask unchanged when printing cpumap
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57939
- riscv: Fix sleeping in invalid context in die()
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21636
- sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21637
- sctp: sysctl: udp_port: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21638
- sctp: sysctl: auth_enable: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21639
- sctp: sysctl: rto_min/max: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21640
- sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21642
- mptcp: sysctl: sched: avoid using current->nsproxy
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21664
- dm thin: make get_first_thin use rcu-safe list first function
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57945
- riscv: mm: Fix the out of bound issue of vmemmap address
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21660
- ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21645
- platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled
it
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21646
- afs: Fix the maximum cell name length
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57925
- ksmbd: fix a missing return value check bug
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57926
- drm/mediatek: Set private->all_drm_private[i]->drm to NULL if mtk_drm_bind
returns err
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21662
- net/mlx5: Fix variable not being completed when function returns
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21663
- net: stmmac: dwmac-tegra: Read iommu stream id from device tree
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21647
- sched: sch_cake: add bounds checks to host bulk flow fairness counts
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21648
- netfilter: conntrack: clamp maximum hashtable size to INT_MAX
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21652
- ipvlan: Fix use-after-free in ipvlan_get_iflink().
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21658
- btrfs: avoid NULL pointer dereference if no valid extent tree
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2025-21653
- net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-47736
- erofs: handle overlapped pclusters out of crafted images properly
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57940
- exfat: fix the infinite loop in exfat_readdir()
* Noble update: upstream stable patchset 2025-04-10 (LP: #2106770) //
CVE-2024-57929
- dm array: fix releasing a faulty array block twice in dm_array_cursor_end
* intel_idle: add Granite Rapids Xeon (D) support (LP: #2106638)
- intel_idle: add Granite Rapids Xeon support
- intel_idle: add Granite Rapids Xeon D support
* [SRU] Enable speaker/mic mute LEDs on Lenovo ideapad and thinkbook
(LP: #2106449)
- ALSA: hda: Support for Ideapad hotkey mute LEDs
- platform/x86:lenovo-wmi-hotkey-utilities.c: Support for mic and audio mute
LEDs
- [Config] Enable Lenovo wmi hotkey driver
* Backport "PCI: Wait for device readiness with Configuration RRS" to N/O
(LP: #2106251)
- PCI: Wait for device readiness with Configuration RRS
- PCI: Avoid FLR for Mediatek MT7922 WiFi
* Enable OOB P-state control for Intel Sierra Forest/Granite Rapids
(LP: #2106275)
- cpufreq: intel_pstate: Support Granite Rapids and Sierra Forest OOB mode
* mptcp BUG 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addr
(LP: #2101120)
- mptcp: fix 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addr
* CVE-2025-21971
- net_sched: Prevent creation of classes with TC_H_ROOT
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632)
- smb/client: rename cifs_ntsd to smb_ntsd
- smb/client: rename cifs_sid to smb_sid
- smb/client: rename cifs_acl to smb_acl
- smb/client: rename cifs_ace to smb_ace
- fs/smb/client: implement chmod() for SMB3 POSIX Extensions
- smb: client: stop flooding dmesg in smb2_calc_signature()
- media: uvcvideo: Force UVC version to 1.0a for 0408:4033
- Bluetooth: btusb: Add new VID/PID 13d3/3602 for MT7925
- watchdog: rzg2l_wdt: Remove reset de-assert from probe
- watchdog: rzg2l_wdt: Rely on the reset driver for doing proper reset
- watchdog: rzg2l_wdt: Power on the watchdog domain in the restart handler
- ALSA: ump: Use guard() for locking
- ALSA: ump: Don't open legacy substream for an inactive group
- scsi: mpi3mr: Use ida to manage mrioc ID
- scsi: mpi3mr: Start controller indexing from 0
- ACPI/IORT: Add PMCG platform information for HiSilicon HIP10/11
- ACPI/IORT: Add PMCG platform information for HiSilicon HIP09A
- x86/ptrace: Cleanup the definition of the pt_regs structure
- x86/ptrace: Add FRED additional information to the pt_regs structure
- Bluetooth: btusb: add callback function in btusb suspend/resume
- Bluetooth: btusb: mediatek: add callback function in btusb_disconnect
- platform/x86: mlx-platform: call pci_dev_put() to balance the refcount
- mmc: sdhci-msm: fix crypto key eviction
- tracing: Handle old buffer mappings for event strings and functions
- tracing: Fix trace_check_vprintf() when tp_printk is used
- tracing: Check "%s" dereference via the field and not the TP_printk format
- RDMA/bnxt_re: Allow MSN table capability check
- RDMA/bnxt_re: Remove always true dattr validity check
- RDMA/mlx5: Enforce same type port association for multiport RoCE
- RDMA/bnxt_re: Avoid initializing the software queue for user queues
- RDMA/bnxt_re: Avoid sending the modify QP workaround for latest adapters
- nvme-pci: 512 byte aligned dma pool segment quirk
- RDMA/bnxt_re: Fix the check for 9060 condition
- RDMA/bnxt_re: Add check for path mtu in modify_qp
- RDMA/bnxt_re: Fix reporting hw_ver in query_device
- RDMA/bnxt_re: Fix max_qp_wrs reported
- RDMA/bnxt_re: Add support for Variable WQE in Genp7 adapters
- RDMA/bnxt_re: Disable use of reserved wqes
- RDMA/bnxt_re: Add send queue size check for variable wqe
- RDMA/bnxt_re: Fix MSN table size for variable wqe mode
- drm/bridge: adv7511_audio: Update Audio InfoFrame properly
- net: dsa: microchip: Fix KSZ9477 set_ageing_time function
- net: dsa: microchip: Fix LAN937X set_ageing_time function
- RDMA/hns: Refactor mtr find
- RDMA/hns: Remove unused parameters and variables
- RDMA/hns: Fix mapping error of zero-hop WQE buffer
- RDMA/hns: Fix warning storm caused by invalid input in IO path
- RDMA/hns: Fix missing flush CQE for DWQE
- ip_tunnel: annotate data-races around t->parms.link
- ipv4: ip_tunnel: Unmask upper DSCP bits in ip_tunnel_bind_dev()
- ipv4: ip_tunnel: Unmask upper DSCP bits in ip_md_tunnel_xmit()
- ipv4: ip_tunnel: Unmask upper DSCP bits in ip_tunnel_xmit()
- net: Fix netns for ip_tunnel_init_flow()
- net/mlx5: DR, select MSIX vector 0 for completion queue creation
- net/mlx5e: macsec: Maintain TX SA from encoding_sa
- drm/i915/dg1: Fix power gate sequence.
- net: llc: reset skb->transport_header
- ALSA: usb-audio: US16x08: Initialize array before use
- eth: bcmsysport: fix call balance of priv->clk handling routines
- net: mv643xx_eth: fix an OF node reference leak
- net: sfc: Correct key_len for efx_tc_ct_zone_ht_params
- net: wwan: iosm: Properly check for valid exec stage in ipc_mmio_init()
- net: ti: icssg-prueth: Fix clearing of IEP_CMP_CFG registers during iep_init
- wifi: mac80211: wake the queues in case of failure in resume
- ALSA: hda/ca0132: Use standard HD-audio quirk matching helpers
- ALSA: hda/realtek: Add new alc2xx-fixup-headset-mic model
- sound: usb: enable DSD output for ddHiFi TC44C
- sound: usb: format: don't warn that raw DSD is unsupported
- bpf: fix potential error return
- ksmbd: retry iterate_dir in smb2_query_dir
- smb: client: destroy cfid_put_wq on module exit
- net: usb: qmi_wwan: add Telit FE910C04 compositions
- irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base
- ARC: build: Try to guess GCC variant of cross compiler
- RDMA/bnxt_re: Fix the max WQE size for static WQE support
- modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host
- modpost: fix the missed iteration for the max bit in do_input()
- ALSA: seq: Check UMP support for midi_version change
- ALSA hda/realtek: Add quirk for Framework F111:000C
- kcov: mark in_softirq_really() as __always_inline
- scripts/sorttable: fix orc_sort_cmp() to maintain symmetry and transitivity
- sky2: Add device ID 11ab:4373 for Marvell 88E8075
- drm: adv7511: Drop dsi single lane support
- dt-bindings: display: adi,adv7533: Drop single lane support
- fs/proc/task_mmu: fix pagemap flags with PMD THP entries on 32bit
- mm/readahead: fix large folio support in async readahead
- mptcp: fix recvbuffer adjust on sleeping rcvmsg
- mptcp: don't always assume copied data in mptcp_cleanup_rbuf()
- RDMA/bnxt_re: Fix max SGEs for the Work Request
- scsi: hisi_sas: Remove redundant checks for automatic debugfs dump
- platform/x86: hp-wmi: Add thermal profile support for 8BAD boards
- platform/x86: hp-wmi: Fix platform profile option switch bug on Omen and
Victus laptops
- platform/x86: hp-wmi: Fix implementation of the platform_profile_omen_get
function
- platform/x86: hp-wmi: mark 8A15 board for timed OMEN thermal profile
- RDMA/core: Fix ENODEV error for iWARP test over vlan
- net: phy: micrel: Dynamically control external clock of KSZ PHY
- netdev-genl: avoid empty messages in napi get
- net: stmmac: restructure the error path of stmmac_probe_config_dt()
- net/mlx5e: Fix netif state handling
- net/mlx5e: Keep netdev when leave switchdev for devlink set legacy only
- drm/i915/cx0_phy: Fix C10 pll programming sequence
- RDMA/bnxt_re: Fix error recovery sequence
- btrfs: allow swap activation to be interruptible
- perf/x86/intel: Add Arrow Lake U support
- ALSA: hda: cs35l56: Remove calls to
cs35l56_force_sync_asp1_registers_from_cache()
- ALSA: hda/realtek - Add support for ASUS Zen AIO 27 Z272SD_A272SD audio
- spi: spi-cadence-qspi: Disable STIG mode for Altera SoCFPGA.
- ARC: build: disallow invalid PAE40 + 4K page config
- bpf: refactor bpf_helper_changes_pkt_data to use helper number
- bpf: consider that tail calls invalidate packet pointers
- maple_tree: reload mas before the second call for mas_empty_area
- io_uring/rw: fix downgraded mshot read
- wifi: iwlwifi: mvm: Fix __counted_by usage in cfg80211_wowlan_nd_*
- net: ethernet: ti: am65-cpsw: default to round-robin for host port receive
- gve: process XSK TX descriptors as part of RX NAPI
- gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup
- mm: reinstate ability to map write-sealed memfd mappings read-only
- Upstream stable to v6.6.70, v6.12.9
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57898
- wifi: cfg80211: clear link ID from bitmap during link delete after clean up
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57882
- mptcp: fix TCP options overflow.
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57884
- mm: vmscan: account for free pages to prevent infinite Loop in
throttle_direct_reclaim()
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57885
- mm/kmemleak: fix sleeping function called from invalid context at print
message
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57932
- gve: guard XDP xmit NDO on existence of xdp queues
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57933
- gve: guard XSK operations on the existence of queues
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57887
- drm: adv7511: Fix use-after-free in adv7533_attach_dsi()
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57938
- net/sctp: Prevent autoclose integer overflow in sctp_association_init()
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57889
- pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57890
- RDMA/uverbs: Prevent integer overflow issue
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57892
- ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57893
- ALSA: seq: oss: Fix races at processing SysEx messages
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57895
- ksmbd: set ATTR_CTIME flags when setting mtime
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57896
- btrfs: flush delalloc workers queue before stopping cleaner kthread during
unmount
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57897
- drm/amdkfd: Correct the migration DMA map direction
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57899
- wifi: mac80211: fix mbss changed flags corruption on 32 bit systems
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57900
- ila: serialize calls to nf_register_net_hooks()
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57901
- af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57902
- af_packet: fix vlan_get_tci() vs MSG_PEEK
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57903
- net: restrict SO_REUSEPORT to inet sockets
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-36476
- RDMA/rtrs: Ensure 'ib_sge list' is accessible
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-39282
- net: wwan: t7xx: Fix FSM command timeout issue
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57801
- net/mlx5e: Skip restore TC rules for vport rep without loaded flag
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57802
- netrom: check buffer length before accessing it
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57841
- net: fix memory leak in tcp_conn_request()
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-57931
- selinux: ignore unknown extended permissions
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-56761
- x86/fred: Clear WFE in missing-ENDBRANCH #CPs
* Noble update: upstream stable patchset 2025-04-09 (LP: #2106632) //
CVE-2024-53179
- smb: client: fix use-after-free of signing key
* uprobe-related panics during profiling (LP: #2104210)
- uprobes: Fix race in uprobe_free_utask
* ubuntu_bpf failed to build on Noble / Oracular (LP: #2069407)
- selftests/bpf: Fix compilation failure when CONFIG_NET_FOU!=y
* nfsd hangs and never recovers after NFS4ERR_DELAY and a connection loss
(LP: #2103564)
- NFSD: Reset cb_seq_status after NFS4ERR_DELAY
* thermal: Fix temperature readings on intel hardware (LP: #2103427)
- thermal: intel: intel_tcc: Add model checks for temperature registers
- thermal: intel: intel_tcc_cooling: Use a model-specific bitmask for TCC
offset
- hwmon: (coretemp) Extend the bitmask to read temperature to 0xff
* [SRU] Fix Lenovo M70/90 gen6 micmute key and led (LP: #2101811)
- ALSA: hda/realtek - add supported Mic Mute LED for Lenovo platform
- ALSA: hda: realtek: fix incorrect IS_REACHABLE() usage
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869)
- ceph: allocate sparse_ext map only for sparse reads
- mm/vmstat: fix a W=1 clang compiler warning
- tcp_bpf: Charge receive socket buffer in bpf_tcp_ingress()
- tcp_bpf: Add sk_rmem_alloc related logic for tcp_bpf ingress redirection
- bpf: Check negative offsets in __bpf_skb_min_len()
- mtd: diskonchip: Cast an operand to prevent potential overflow
- mtd: rawnand: arasan: Fix double assertion of chip-select
- mtd: rawnand: arasan: Fix missing de-registration of NAND
- phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP
- phy: core: Fix an OF node refcount leakage in _of_phy_get()
- phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()
- phy: core: Fix that API devm_phy_put() fails to release the phy
- phy: core: Fix that API devm_of_phy_provider_unregister() fails to
unregister the phy provider
- phy: core: Fix that API devm_phy_destroy() fails to destroy the phy
- phy: usb: Toggle the PHY power during init
- phy: rockchip: naneng-combphy: fix phy reset
- dmaengine: mv_xor: fix child node refcount handling in early exit
- dmaengine: dw: Select only supported masters for ACPI devices
- dmaengine: tegra: Return correct DMA status when paused
- dmaengine: fsl-edma: implement the cleanup path of fsl_edma3_attach_pd()
- dmaengine: apple-admac: Avoid accessing registers in probe
- stddef: make __struct_group() UAPI C++-friendly
- tracing/kprobe: Make trace_kprobe's module callback called after jump_label
update
- watchdog: it87_wdt: add PWRGD enable quirk for Qotom QCML04
- watchdog: mediatek: Add support for MT6735 TOPRGU/WDT
- scsi: qla1280: Fix hw revision numbering for ISP1020/1040
- udf: Skip parent dir link count update if corrupted
- ALSA: hda/conexant: fix Z60MR100 startup pop issue
- ALSA: sh: Use standard helper for buffer accesses
- smb: server: Fix building with GCC 15
- regmap: Use correct format specifier for logging range errors
- LoongArch: Fix reserving screen info memory for above-4G firmware
- LoongArch: BPF: Adjust the parameter of emit_jirl()
- platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
- spi: intel: Add Panther Lake SPI controller support
- scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver load
time
- scsi: storvsc: Do not flag MAINTENANCE_IN return of SRB_STATUS_DATA_OVERRUN
as an error
- spi: omap2-mcspi: Fix the IS_ERR() bug for devm_clk_get_optional_enabled()
- blk-mq: register cpuhp callback after hctx is added to xarray table
- blk-mq: move cpuhp callback registering out of q->sysfs_lock
- MIPS: Probe toolchain support of -msym32
- MIPS: mipsregs: Set proper ISA level for virt extensions
- freezer, sched: Report frozen tasks as 'D' instead of 'R'
- tracing: Constify string literal data member in struct trace_event_call
- io_uring/sqpoll: fix sqpoll error handling races
- i2c: microchip-core: actually use repeated sends
- i2c: imx: add imx7d compatible string for applying erratum ERR007805
- i2c: microchip-core: fix "ghost" detections
- btrfs: sysfs: fix direct super block member reads
- ALSA: sh: Fix wrong argument order for copy_from_iter()
- block: avoid to reuse `hctx` not removed from cpuhp callback list
- fork: avoid inappropriate uprobe access to invalid mm
- ASoC: SOF: Intel: hda-dai: Do not release the link DMA on STOP
- power: supply: bq24190: Fix BQ24296 Vbus regulator support
- udf: Verify inode link counts before performing rename
- ALSA: ump: Indicate the inactive group in legacy substream names
- ALSA: ump: Update legacy substream names upon FB info update
- scsi: mpi3mr: Synchronize access to ioctl data buffer
- scsi: mpi3mr: Handling of fault code for insufficient power
- objtool: Add bch2_trans_unlocked_error() to bcachefs noreturns
- dmaengine: loongson2-apb: Change GENMASK to GENMASK_ULL
- perf/x86/intel/ds: Add PEBS format 6
- btrfs: add and use helper to verify the calling task has locked the inode
- btrfs: fix race with memory mapped writes when activating swap file
- btrfs: fix swap file activation failure due to extents that used to be
shared
- ALSA: ump: Shut up truncated string warning
- Upstream stable to v6.6.69, v6.12.8
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56758
- btrfs: check folio mapping after unlock in relocate_one_folio()
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56759
- btrfs: fix use-after-free when COWing tree bock and tracing is enabled
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57806
- btrfs: fix transaction atomicity bug when enabling simple quotas
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57793
- virt: tdx-guest: Just leak decrypted memory on unrecoverable errors
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56764
- ublk: detach gendisk from ublk device if add_disk() fails
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57804
- scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57792
- power: supply: gpio-charger: Fix set charge current limits
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56760
- PCI/MSI: Handle lack of irqdomain gracefully
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56763
- tracing: Prevent bad count for tracing_cpumask_write
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57946
- virtio-blk: don't keep queue frozen during system suspend
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-57807
- scsi: megaraid_sas: Fix for a potential deadlock
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56767
- dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
* Noble update: upstream stable patchset 2025-03-22 (LP: #2103869) //
CVE-2024-56769
- media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266)
- usb: dwc2: gadget: Don't write invalid mapped sg entries into dma_desc with
iommu enabled
- PCI: vmd: Create domain symlink before pci_bus_add_devices()
- PCI: Add ACS quirk for Broadcom BCM5760X NIC
- usb: cdns3-ti: Add workaround for Errata i2409
- MIPS: Loongson64: DTS: Fix msi node for ls7a
- ASoC: Intel: sof_sdw: fix jack detection on ADL-N variant RVP
- ASoC: Intel: sof_sdw: add quirk for Dell SKU 0B8C
- usb: cdns3: Add quirk flag to enable suspend residency
- platform/x86: p2sb: Make p2sb_get_devfn() return void
- p2sb: Factor out p2sb_read_from_cache()
- p2sb: Introduce the global flag p2sb_hidden_by_bios
- p2sb: Move P2SB hide and unhide code to p2sb_scan_and_cache()
- p2sb: Do not scan and remove the P2SB device when it is unhidden
- i2c: pnx: Fix timeout in wait functions
- xfs: fix the contact address for the sysfs ABI documentation
- xfs: verify buffer, inode, and dquot items every tx commit
- xfs: use consistent uid/gid when grabbing dquots for inodes
- xfs: declare xfs_file.c symbols in xfs_file.h
- xfs: create a new helper to return a file's allocation unit
- xfs: Fix xfs_flush_unmap_range() range for RT
- xfs: Fix xfs_prepare_shift() range for RT
- xfs: convert comma to semicolon
- xfs: fix file_path handling in tracepoints
- xfs: remove unused parameter in macro XFS_DQUOT_LOGRES
- xfs: attr forks require attr, not attr2
- xfs: conditionally allow FS_XFLAG_REALTIME changes if S_DAX is set
- xfs: Fix the owner setting issue for rmap query in xfs fsmap
- xfs: use XFS_BUF_DADDR_NULL for daddrs in getfsmap code
- xfs: take m_growlock when running growfsrt
- xfs: reset rootdir extent size hint after growfsrt
- tools: hv: change permissions of NetworkManager configuration file
- cxl/pci: Fix potential bogus return value upon successful probing
- cxl/region: Fix region creation for greater than x2 switches
- net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
- ionic: use ee->offset when returning sprom data
- net: renesas: rswitch: rework ts tags management
- net: hinic: Fix cleanup in create_rxqs/txqs()
- net: ethernet: bgmac-platform: fix an OF node reference leak
- ipvs: Fix clamp() of ip_vs_conn_tab on small memory systems
- netfilter: ipset: Fix for recursive locking warning
- selftests: openvswitch: fix tcpdump execution
- net: mdiobus: fix an OF node reference leak
- mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk
- mmc: mtk-sd: disable wakeup in .remove() and in the error path of .probe()
- EDAC/amd64: Simplify ECC check on unified memory controllers
- chelsio/chtls: prevent potential integer overflow on 32bit
- i2c: riic: Always round-up when calculating bus period
- efivarfs: Fix error on non-existent file
- hexagon: Disable constant extender optimization for LLVM prior to 19.1.0
- USB: serial: option: add TCL IK512 MBIM & ECM
- USB: serial: option: add MeiG Smart SLM770A
- USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
- USB: serial: option: add MediaTek T7XX compositions
- USB: serial: option: add Telit FE910C04 rmnet compositions
- thunderbolt: Improve redrive mode handling
- drm/panel: novatek-nt35950: fix return value check in nt35950_probe()
- i915/guc: Reset engine utilization buffer before registration
- i915/guc: Ensure busyness counter increases motonically
- i915/guc: Accumulate active runtime on gt reset
- hwmon: (tmp513) Fix interpretation of values of Shunt Voltage and Limit
Registers
- hwmon: (tmp513) Fix Current Register value interpretation
- hwmon: (tmp513) Fix interpretation of values of Temperature Result and Limit
Registers
- zram: refuse to use zero sized block device as backing device
- zram: fix uninitialized ZRAM not releasing backing device
- zram: fix potential UAF of zram table
- vmalloc: fix accounting with i915
- btrfs: tree-checker: reject inline extent items with 0 ref count
- smb: client: fix TCP timers deadlock after rmmod
- tracing: Fix test_event_printk() to process entire print argument
- tracing: Add missing helper functions in event pointer dereference check
- tracing: Add "%s" check in test_event_printk()
- tracing: Have process_string() also allow arrays
- selftests/memfd: run sysctl tests when PID namespace support is enabled
- selftests/bpf: Use asm constraint "m" for LoongArch
- io_uring: Fix registered ring file refcount leak
- NFS/pnfs: Fix a live lock between recalled layouts and layoutget
- of/irq: Fix interrupt-map cell length check in of_irq_parse_imap_parent()
- of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one()
- nilfs2: fix buffer head leaks in calls to truncate_inode_pages()
- udmabuf: also check for F_SEAL_FUTURE_WRITE
- of: Fix error path in of_parse_phandle_with_args_map()
- of: Fix refcount leakage for OF node returned by __of_get_dma_parent()
- ceph: validate snapdirname option length when mounting
- ceph: improve error handling and short/overflow-read logic in
__ceph_sync_read()
- ceph: fix memory leaks in __ceph_sync_read()
- epoll: Add synchronous wakeup support for ep_poll_callback
- io_uring/rw: avoid punting to io-wq directly
- drm/amdgpu: Handle NULL bo->tbo.resource (again) in amdgpu_vm_bo_update
- xfs: sb_spino_align is not verified
- xfs: fix sparse inode limits on runt AG
- xfs: fix sb_spino_align checks for large fsblock sizes
- xfs: fix zero byte checking in the superblock scrubber
- netdev: fix repeated netlink messages in queue dump
- team: Fix feature exposure when no ports are present
- can: m_can: fix missed interrupts with m_can_pci
- netdev-genl: avoid empty messages in queue dump
- KVM: arm64: Do not allow ID_AA64MMFR0_EL1.ASIDbits to be overridden
- KVM: arm64: Fix set_id_regs selftest for ASIDBITS becoming unwritable
- net: mctp: handle skb cleanup on sock_queue failures
- xhci: retry Stop Endpoint on buggy NEC controllers
- usb: xhci: Limit Stop Endpoint retries
- usb: xhci: Avoid queuing redundant Stop Endpoint commands
- xhci: Turn NEC specific quirk for handling Stop Endpoint errors generic
- thunderbolt: Add support for Intel Panther Lake-M/P
- thunderbolt: Don't display nvm_version unless upgrade supported
- drm/panel: st7701: Add prepare_prev_first flag to drm_panel
- drm/panel: synaptics-r63353: Fix regulator unbalance
- drm/amdgpu/nbio7.11: fix IP version check
- drm/amdgpu/nbio7.7: fix IP version check
- fgraph: Still initialize idle shadow stacks when starting
- x86/hyperv: Fix hv tsc page based sched_clock for hibernation
- ocfs2: fix the space leak in LA when releasing LA
- of: property: fw_devlink: Do not use interrupt-parent directly
- of: address: Preserve the flags portion on 1:1 dma-ranges mapping
- Upstream stable to v6.6.68, v6.12.7
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56710
- ceph: fix memory leak in ceph_direct_read_write()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-53685
- ceph: give up on paths longer than PATH_MAX
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-54193
- accel/ivpu: Fix WARN in ivpu_ipc_send_receive_internal()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-54455
- accel/ivpu: Fix general protection fault in ivpu_bo_list()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-53690
- nilfs2: prevent use of deleted inode
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56709
- io_uring: check if iowq is killed before queuing
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-55881
- KVM: x86: Play nice with protected guests in complete_hypercall_exit()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-55916
- Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56369
- drm/modes: Avoid divide by zero harder in drm_mode_vrefresh()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56372
- net: tun: fix tun_napi_alloc_frags()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56715
- ionic: Fix netdev notifier unregister on failure
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56716
- netdevsim: prevent bad user input in nsim_dev_health_break_write()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56717
- net: mscc: ocelot: fix incorrect IFH SRC_PORT field in
ocelot_ifh_set_basic()
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-57791
- net/smc: check return value of sock_recvmsg when draining clc data
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-47408
- net/smc: check smcd_v2_ext_offset when receiving proposal msg
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-49568
- net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-49571
- net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal
msg
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-56718
- net/smc: protect link down work from execute after lgr freed
* Noble update: upstream stable patchset 2025-03-14 (LP: #2102266) //
CVE-2024-41013
- xfs: don't walk off the end of a directory data block
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181)
- perf/x86/intel/ds: Unconditionally drain PEBS DS when changing PEBS_DATA_CFG
- ksmbd: fix racy issue from session lookup and expire
- splice: do not checksum AF_UNIX sockets
- tcp: check space before adding MPTCP SYN options
- ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5
- usb: host: max3421-hcd: Correctly abort a USB request.
- ata: sata_highbank: fix OF node reference leak in highbank_initialize_phys()
- usb: dwc2: Fix HCD resume
- usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature
- usb: dwc2: Fix HCD port connection race
- scsi: ufs: core: Update compl_time_stamp_local_clock after completing a cqe
- usb: gadget: midi2: Fix interpretation of is_midi1 bits
- usb: ehci-hcd: fix call balance of clocks handling routines
- usb: typec: anx7411: fix fwnode_handle reference leak
- usb: typec: anx7411: fix OF node reference leaks in
anx7411_typec_switch_probe()
- usb: dwc3: xilinx: make sure pipe clock is deselected in usb2 only mode
- drm/i915: Fix memory leak by correcting cache object name in error handler
- xfs: update btree keys correctly when _insrec splits an inode root block
- xfs: don't drop errno values when we fail to ficlone the entire range
- xfs: return from xfs_symlink_verify early on V4 filesystems
- xfs: fix scrub tracepoints when inode-rooted btrees are involved
- xfs: only run precommits once per transaction object
- bpf: Check size for BTF-based ctx access of pointer members
- bpf: Fix theoretical prog_array UAF in __uprobe_perf_func()
- bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog
- bpf, sockmap: Fix update element with same
- wifi: mac80211: init cnt before accessing elem in
ieee80211_copy_mbssid_beacon
- wifi: mac80211: clean up 'ret' in sta_link_apply_parameters()
- wifi: mac80211: fix station NSS capability initialization order
- batman-adv: Do not send uninitialized TT changes
- batman-adv: Remove uninitialized data in full table TT response
- batman-adv: Do not let TT changes list grows indefinitely
- wifi: cfg80211: sme: init n_channels before channels[] access
- selftests: mlxsw: sharedbuffer: Remove h1 ingress test case
- selftests: mlxsw: sharedbuffer: Remove duplicate test cases
- selftests: mlxsw: sharedbuffer: Ensure no extra packets are counted
- ptp: kvm: x86: Return EOPNOTSUPP instead of ENODEV from kvm_arch_ptp_init()
- net: mscc: ocelot: fix memory leak on ocelot_port_add_txtstamp_skb()
- net: mscc: ocelot: improve handling of TX timestamp for unknown skb
- net: mscc: ocelot: ocelot->ts_id_lock and ocelot_port->tx_skbs.lock are IRQ-
safe
- net: mscc: ocelot: be resilient to loss of PTP packets during transmission
- net: mscc: ocelot: perform error cleanup in ocelot_hwstamp_set()
- spi: aspeed: Fix an error handling path in aspeed_spi_[read|write]_user()
- net: sparx5: fix FDMA performance issue
- net: sparx5: fix the maximum frame length register
- ACPI: resource: Fix memory resource type union access
- cxgb4: use port number to set mac addr
- qca_spi: Fix clock speed for multiple QCA7000
- qca_spi: Make driver probing reliable
- ASoC: amd: yc: Fix the wrong return value
- Documentation: PM: Clarify pm_runtime_resume_and_get() return value
- net: renesas: rswitch: fix race window between tx start and complete
- net: renesas: rswitch: fix leaked pointer on error path
- net: renesas: rswitch: handle stop vs interrupt race
- net: dsa: felix: fix stuck CPU-injected packets with short taprio windows
- netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
- bonding: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL
- team: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL
- ACPICA: events/evxfregn: don't release the ContextMutex that was never
acquired
- Bluetooth: iso: Fix recursive locking warning
- Bluetooth: SCO: Add support for 16 bits transparent voice setting
- net: renesas: rswitch: fix initial MPIC register setting
- net: dsa: microchip: KSZ9896 register regmap alignment to 32 bit boundaries
- blk-iocost: Avoid using clamp() on inuse in __propagate_weights()
- kselftest/arm64: abi: fix SVCR detection
- KVM: arm64: Disable MPAM visibility by default and ignore VMM writes
- selftests/bpf: remove use of __xlated()
- xen/netfront: fix crash when removing device
- x86: make get_cpu_vendor() accessible from Xen code
- objtool/x86: allow syscall instruction
- x86/static-call: provide a way to do very early static-call updates
- x86/xen: don't do PV iret hypercall through hypercall page
- x86/xen: add central hypercall functions
- x86/xen: fix xen_hypercall_hvm() to not clobber %rbx
- x86/xen: add FRAME_END to xen_hypercall_hvm()
- x86/xen: use new hypercall functions instead of hypercall page
- x86/xen: remove hypercall page
- x86/static-call: fix 32-bit build
- x86/asm: Make serialize() always_inline
- x86/static-call: Remove early_boot_irqs_disabled check to fix Xen PVH dom0
- serial: sh-sci: Check if TX data was written to device in .tx_empty()
- gpio: ljca: Initialize num before accessing item in ljca_gpio_config
- ALSA: hda/realtek: Fix headset mic on Acer Nitro 5
- drm/amdkfd: Use device based logging for errors
- drm/amdkfd: pause autosuspend when creating pdd
- drm/amdkfd: fixed page fault when enable MES shader debugger
- drm/i915/color: Stop using non-posted DSB writes for legacy LUT
- drm/amd/pm: Set SMU v13.0.7 default workload type
- xfs: return a 64-bit block count from xfs_btree_count_blocks
- perf machine: Initialize machine->env to address a segfault
- bnxt_en: Fix GSO type for HW GRO packets on 5750X chips
- net: renesas: rswitch: fix possible early skb release
- Bluetooth: Improve setsockopt() handling of malformed user input
- libperf: evlist: Fix --cpu argument on hybrid platform
- selftests: netfilter: Stabilize rpath.sh
- net, team, bonding: Add netdev_base_features helper
- bonding: Fix initial {vlan,mpls}_feature set in bond_compute_features
- team: Fix initial vlan_feature set in __team_compute_features
- drm/xe: fix the ERR_PTR() returned on failure to allocate tiny pt
- Upstream stable to v6.6.67, v6.12.6
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56652
- drm/xe/reg_sr: Remove register pool
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-54460
- Bluetooth: iso: Fix circular lock in iso_listen_bis
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-57879
- Bluetooth: iso: Always release hdev at the end of iso_listen_bis
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56656
- bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-53125
- bpf: sync_linked_regs() must preserve subreg_def
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56654
- Bluetooth: hci_event: Fix using rcu_read_(un)lock while iterating
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56770
- net/sched: netem: account for backlog updates from child qdisc
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-54683
- netfilter: IDLETIMER: Fix for possible ABBA deadlock
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-55639
- net: renesas: rswitch: avoid use-after-put for a device tree node
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56657
- ALSA: control: Avoid WARN() for symlink errors
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56659
- net: lapb: increase LAPB_HEADER_LEN
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56660
- net/mlx5: DR, prevent potential error pointer dereference
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56662
- acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56664
- bpf, sockmap: Fix race between element replace and close()
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56667
- drm/i915: Fix NULL pointer dereference in capture_engine
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56670
- usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to
accessing null pointer
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-53687
- riscv: Fix IPIs usage in kfence_protect_page()
* Noble update: upstream stable patchset 2025-03-13 (LP: #2102181) //
CVE-2024-56675
- bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors
* Noble update: upstream stable patchset 2025-02-04 (LP: #2097393)
- selftests: net: Remove executable bits from library scripts
* CVE-2024-56653
- Bluetooth: btmtk: avoid UAF in btmtk_process_coredump
[ Ubuntu: 6.8.1-1021.22 ]
* noble/linux-realtime: 6.8.1-1021.22 -proposed tracker (LP: #2107071)
[ Ubuntu: 6.8.0-59.61 ]
* noble/linux: 6.8.0-59.61 -proposed tracker (LP: #2107076)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
* CVE-2024-56653
- Bluetooth: btmtk: avoid UAF in btmtk_process_coredump
[ Ubuntu: 6.8.1-1020.21 ]
* noble/linux-realtime: 6.8.1-1020.21 -proposed tracker (LP: #2102524)
* Packaging resync (LP: #1786013)
- [Packaging] debian.realtime/dkms-versions -- update from kernel-versions
(main/2025.03.17)
* Noble real-time patchset update: Merge changes from 6.6-rt LTS
(LP: #2102249)
- prinkt/nbcon: Add a scheduling point to nbcon_kthread_func().
- printk: nbcon: Fix illegal RCU usage on thread wakeup
- netfilter: nft_counter: Use u64_stats_t for statistic.
- Realtime patchset v6.8-rt11+2
[ Ubuntu: 6.8.0-58.60 ]
* noble/linux: 6.8.0-58.60 -proposed tracker (LP: #2102529)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
- [Packaging] debian.master/dkms-versions -- update from kernel-versions
(main/2025.03.17)
* wdat_wdt.ko should be pulled in by linux-image-virtual (LP: #2098554)
- [Packaging]: wdat_wdt.ko is moved from "linux-modules-extra-*-generic" to
"linux-modules-*-generic"
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118)
- openrisc: Use asm-generic's version of fix_to_virt() & virt_to_fix()
- iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
- watchdog: xilinx_wwdt: Calculate max_hw_heartbeat_ms using clock frequency
- watchdog: apple: Actually flush writes after requesting watchdog restart
- watchdog: mediatek: Make sure system reset gets asserted in
mtk_wdt_restart()
- can: gs_usb: add VID/PID for Xylanta SAINT3 product family
- can: gs_usb: add usb endpoint address detection at driver probe step
- can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL
- can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors statistics
- can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors statistics
- can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics
- can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics
- can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
- can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics
- can: f81604: f81604_handle_can_bus_errors(): fix {rx,tx}_errors statistics
- ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init()
- selftests: hid: fix typo and exit code
- ptp: Add error handling for adjfine callback in ptp_clock_adjtime
- net/sched: tbf: correct backlog statistic for GSO packets
- net: hsr: fix fill_frame_info() regression vs VLAN packets
- platform/x86: asus-wmi: add support for vivobook fan profiles
- platform/x86: asus-wmi: Fix inconsistent use of thermal policies
- platform/x86: asus-wmi: Ignore return value when writing thermal policy
- net/smc: mark optional smcd_ops and check for support when called
- net/smc: add operations to merge sndbuf with peer DMB
- net/smc: {at|de}tach sndbuf to peer DMB if supported
- net/smc: refactoring initialization of smc sock
- net/qed: allow old cards not supporting "num_images" to work
- ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5
- ixgbe: downgrade logging of unsupported VF API version to debug
- net: sched: fix erspan_opt settings in cls_flower
- netfilter: nft_set_hash: skip duplicated elements pending gc run
- netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext
- ethtool: Fix wrong mod state in case of verbose and no_mask bitset
- mlxsw: spectrum_acl_flex_keys: Constify struct mlxsw_afk_element_inst
- mlxsw: spectrum_acl_flex_keys: Use correct key block on Spectrum-4
- net/mlx5e: Remove workaround to avoid syndrome for internal port
- xhci: Allow RPM on the USB controller (1022:43f7) by default
- gpio: grgpio: use a helper variable to store the address of ofdev->dev
- usb: dwc3: gadget: Rewrite endpoint allocation flow
- usb: dwc3: ep0: Don't reset resource alloc flag (including ep0)
- usb: dwc3: ep0: Don't clear ep0 DWC3_EP_TRANSFER_STARTED
- mmc: mtk-sd: use devm_mmc_alloc_host
- mmc: mtk-sd: Fix error handle of probe function
- mmc: mtk-sd: fix devm_clk_get_optional usage
- mmc: mtk-sd: Fix MMC_CAP2_CRYPTO flag setting
- zram: do not mark idle slots that cannot be idle
- zram: clear IDLE flag in mark_idle()
- powerpc/vdso: Refactor CFLAGS for CVDSO build
- powerpc/vdso: Drop -mstack-protector-guard flags in 32-bit files with clang
- ntp: Remove invalid cast in time offset math
- driver core: Add FWLINK_FLAG_IGNORE to completely ignore a fwnode link
- driver core: fw_devlink: Stop trying to optimize cycle detection logic
- drivers: core: fix device leak in __fw_devlink_relax_cycles()
- i3c: master: support to adjust first broadcast address speed
- i3c: master: svc: use slow speed for first broadcast address
- i3c: master: svc: Modify enabled_events bit 7:0 to act as IBI enable counter
- i3c: master: Replace hard code 2 with macro I3C_ADDR_SLOT_STATUS_BITS
- i3c: master: Extend address status bit to 4 and add
I3C_ADDR_SLOT_EXT_DESIRED
- i3c: master: Fix dynamic address leak when 'assigned-address' is present
- i3c: master: Fix missing 'ret' assignment in set_speed()
- drm/bridge: it6505: update usleep_range for RC circuit charge time
- drm/bridge: it6505: Fix inverted reset polarity
- scsi: ufs: core: Always initialize the UIC done completion
- scsi: ufs: core: Add ufshcd_send_bsg_uic_cmd() for UFS BSG
- bpf, vsock: Fix poll() missing a queue
- bpf, vsock: Invoke proto::close on close()
- xsk: always clear DMA mapping information when unmapping the pool
- bpftool: fix potential NULL pointer dereferencing in prog_dump()
- drm/sti: Add __iomem for mixer_dbg_mxn's parameter
- ALSA: seq: ump: Use automatic cleanup of kfree()
- ALSA: ump: Update substream name from assigned FB names
- ALSA: seq: ump: Fix seq port updates per FB info notify
- ALSA: usb-audio: Notify xrun for low-latency mode
- tools: Override makefile ARCH variable if defined, but empty
- ASoC: SOF: ipc3-topology: Convert the topology pin index to ALH dai index
- ASoC: SOF: ipc3-topology: fix resource leaks in
sof_ipc3_widget_setup_comp_dai()
- bpf: Fix narrow scalar spill onto 64-bit spilled scalar slots
- scsi: scsi_debug: Fix hrtimer support for ndelay
- ASoC: mediatek: mt8188-mt6359: Remove hardcoded dmic codec
- drm/v3d: Enable Performance Counters before clearing them
- scatterlist: fix incorrect func name in kernel-doc
- iio: magnetometer: yas530: use signed integer type for clamp limits
- bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie
- bpf: Remove unnecessary kfree(im_node) in lpm_trie_update_elem
- bpf: Handle in-place update for full LPM trie correctly
- bpf: Fix exact match conditions in trie_get_next_key()
- x86/CPU/AMD: WARN when setting EFER.AUTOIBRS if and only if the WRMSR fails
- watchdog: rti: of: honor timeout-sec property
- can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum DS80000789E 6.
- tracing: Fix cmp_entries_dup() to respect sort() comparison rules
- arm64: Ensure bits ASID[15:8] are masked out when the kernel uses 8-bit
ASIDs
- ALSA: usb-audio: add mixer mapping for Corsair HS80
- ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook 430 G8
- ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360 (NP730QFG)
- scsi: qla2xxx: Fix abort in bsg timeout
- scsi: qla2xxx: Fix NVMe and NPIV connect issue
- scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
- scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt
- scsi: ufs: core: Add missing post notify for power mode change
- fs/smb/client: cifs_prime_dcache() for SMB3 POSIX reparse points
- drm/dp_mst: Verify request type in the corresponding down message reply
- drm/amdgpu/hdp5.2: do a posting read when flushing HDP
- modpost: Add .irqentry.text to OTHER_SECTIONS
- x86/kexec: Restore GDT on return from ::preserve_context kexec
- dma-buf: fix dma_fence_array_signaled v4
- dma-fence: Fix reference leak on fence merge failure path
- dma-fence: Use kernel's sort for merging fences
- regmap: detach regmap from dev on regmap_exit
- mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia Edu Atla 10
tablet
- mmc: core: Further prevent card detect during shutdown
- ocfs2: update seq_file index in ocfs2_dlm_seq_next
- lib: stackinit: hide never-taken branch from compiler
- kasan: make report_lock a raw spinlock
- x86/mm: Add _PAGE_NOPTISHADOW bit to avoid updating userspace page tables
- epoll: annotate racy check
- kselftest/arm64: Log fp-stress child startup errors to stdout
- btrfs: avoid unnecessary device path update for the same device
- btrfs: do not clear read-only when adding sprout device
- kselftest/arm64: Don't leak pipe fds in pac.exec_sign_all()
- hwmon: (nct6775) Add 665-ACE/600M-CL to ASUS WMI monitoring list
- ACPI: x86: Make UART skip quirks work on PCI UARTs without an UID
- perf/x86/amd: Warn only on new bits set
- spi: spi-fsl-lpspi: Adjust type of scldiv
- HID: add per device quirk to force bind to hid-generic
- media: uvcvideo: RealSense D421 Depth module metadata
- media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera
- media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108
- mmc: core: Add SD card quirk for broken poweroff notification
- mmc: sdhci-esdhc-imx: enable quirks SDHCI_QUIRK_NO_LED
- regmap: maple: Provide lockdep (sub)class for maple tree's internal lock
- selftests/resctrl: Protect against array overflow when reading strings
- drm/vc4: hdmi: Avoid log spam for audio start failure
- drm/vc4: hvs: Set AXI panic modes for the HVS
- drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
- drm: panel-orientation-quirks: Add quirk for AYA NEO Founder edition
- drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK
- drm/bridge: it6505: Enable module autoloading
- drm/mcde: Enable module autoloading
- drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check()
- drm/display: Fix building with GCC 15
- ALSA: hda: Use own quirk lookup helper
- ALSA: hda/conexant: Use the new codec SSID matching
- r8169: don't apply UDP padding quirk on RTL8126A
- samples/bpf: Fix a resource leak
- net: fec_mpc52xx_phy: Use %pa to format resource_size_t
- net: ethernet: fs_enet: Use %pa to format resource_size_t
- net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
- Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
- wifi: ath5k: add PCI ID for SX76X
- wifi: ath5k: add PCI ID for Arcadyan devices
- fanotify: allow reporting errors on failure to open fd
- drm/panel: simple: Add Microchip AC69T88A LVDS Display panel
- net: sfp: change quirks for Alcatel Lucent G-010S-P
- net: stmmac: Programming sequence for VLAN packets with split header
- drm/sched: memset() 'job' in drm_sched_job_init()
- amdgpu/uvd: get ring reference from rq scheduler
- drm/amdgpu: don't access invalid sched
- drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih
- drm/amdgpu: Dereference the ATCS ACPI buffer
- netlink: specs: Add missing bitset attrs to ethtool spec
- drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr
- fsl/fman: Validate cell-index value obtained from Device Tree
- drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov
- ALSA: usb-audio: Make mic volume workarounds globally applicable
- wifi: ipw2x00: libipw_rx_any(): fix bad alignment
- dsa: qca8k: Use nested lock to avoid splat
- Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables
- Bluetooth: Add new quirks for ATS2851
- Bluetooth: Support new quirks for ATS2851
- Bluetooth: Set quirks for ATS2851
- ASoC: hdmi-codec: reorder channel allocation list
- rocker: fix link status detection in rocker_carrier_init()
- net/neighbor: clear error in case strict check is not set
- netpoll: Use rcu_access_pointer() in __netpoll_setup
- pinctrl: freescale: fix COMPILE_TEST error with PINCTRL_IMX_SCU
- tracing/ftrace: disable preemption in syscall probe
- tracing: Use atomic64_inc_return() in trace_clock_counter()
- tools/rtla: fix collision with glibc sched_attr/sched_set_attr
- rtla/timerlat: Make timerlat_top_cpu->*_count unsigned long long
- scsi: ufs: core: Make DMA mask configuration more flexible
- scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod paths
- clk: qcom: rcg2: add clk_rcg2_shared_floor_ops
- clk: qcom: rpmh: add support for SAR2130P
- clk: qcom: tcsrcc-sm8550: add SAR2130P support
- scsi: st: Don't modify unknown block number in MTIOCGET
- scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset
- pinctrl: qcom-pmic-gpio: add support for PM8937
- pinctrl: qcom: spmi-mpp: Add PM8937 compatible
- thermal/drivers/qcom/tsens-v1: Add support for MSM8937 tsens
- nvdimm: rectify the illogical code within nd_dax_probe()
- smb: client: memcpy() with surrounding object base address
- verification/dot2: Improve dot parser robustness
- KMSAN: uninit-value in inode_go_dump (5)
- PCI: qcom: Add support for IPQ9574
- PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs
- PCI: vmd: Set devices to D0 before enabling PM L1 Substates
- PCI: Detect and trust built-in Thunderbolt chips
- PCI: Add 'reset_subordinate' to reset hierarchy below bridge
- PCI: Add ACS quirk for Wangxun FF5xxx NICs
- f2fs: print message if fscorrupted was found in f2fs_new_node_page()
- ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 8 A1-840
- ACPI: x86: Clean up Asus entries in acpi_quirk_skip_dmi_ids[]
- fs/ntfs3: Fix case when unmarked clusters intersect with zone
- usb: chipidea: udc: handle USB Error Interrupt if IOC not set
- iio: light: ltr501: Add LTER0303 to the supported devices
- ASoC: amd: yc: fix internal mic on Redmi G 2022
- drm/amdgpu/vcn: reset fw_shared when VCPU buffers corrupted on vcn v4.0.3
- drm/amdgpu/vcn: reset fw_shared under SRIOV
- ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad T14s Gen 6
21M1CTO1WW
- misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
- rtc: cmos: avoid taking rtc_lock for extended period of time
- serial: 8250_dw: Add Sophgo SG2044 quirk
- smb: client: don't try following DFS links in cifs_tree_connect()
- setlocalversion: work around "git describe" performance
- sched/core: Remove the unnecessary need_resched() check in nohz_csd_func()
- sched/fair: Check idle_cpu() before need_resched() to detect ilb CPU turning
busy
- sched/core: Prevent wakeup of ksoftirqd during idle load balance
- btrfs: fix missing snapshot drew unlock when root is dead during swap
activation
- clk: en7523: Initialize num before accessing hws in en7523_register_clocks()
- tracing/eprobe: Fix to release eprobe when failed to add dyn_event
- x86: Fix build regression with CONFIG_KEXEC_JUMP enabled
- Revert "unicode: Don't special case ignorable code points"
- vfio/mlx5: Align the page tracking max message size with the device
capability
- selftests/ftrace: adjust offset for kprobe syntax error test
- KVM: x86/mmu: Ensure that kvm_release_pfn_clean() takes exact pfn from
kvm_faultin_pfn()
- jffs2: Fix rtime decompressor
- mm/damon/vaddr: fix issue in damon_va_evenly_split_region()
- iio: invensense: fix multiple odr switch when FIFO is off
- ocfs2: Revert "ocfs2: fix the la space leak when unmounting an ocfs2 volume"
- ALSA: hda: Fix build error without CONFIG_SND_DEBUG
- usb: dwc3: ep0: Don't reset resource alloc flag
- ALSA: usb-audio: Update UMP group attributes for GTB blocks, too
- platform/x86: asus-wmi: Fix thermal profile initialization
- i3c: master: svc: fix possible assignment of the same address to two devices
- btrfs: drop unused parameter file_offset from
btrfs_encoded_read_regular_fill_pages()
- md/raid5: Wait sync io to finish before changing group cnt
- media: platform: rga: fix 32-bit DMA limitation
- net: phy: dp83869: fix status reporting for 1000base-x autonegotiation
- remoteproc: qcom_q6v5_pas: disable auto boot for wpss
- mtd: spinand: winbond: Fix 512GW and 02JW OOB layout
- PCI: Pass domain number to pci_bus_release_domain_nr() explicitly
- dt-bindings: net: fec: add pps channel property
- net: fec: refactor PPS channel configuration
- net: fec: make PPS channel configurable
- drm/xe/xe_guc_ads: save/restore OA registers and allowlist regs
- drm/xe/migrate: use XE_BO_FLAG_PAGETABLE
- drm/amd: Add some missing straps from NBIO 7.11.0
- drm/amd: Fix initialization mistake for NBIO 7.11 devices
- drm/amdgpu/pm: Don't use OD table on Arcturus
- drm/amd/pm: Remove arcturus min power limit
- drm/amd/display: update pipe selection policy to check head pipe
- drm/amd/display: Remove PIPE_DTO_SRC_SEL programming from set_dtbclk_dto
- Revert "drm/xe/xe_guc_ads: save/restore OA registers and allowlist regs"
- ipv6: avoid possible NULL deref in modify_prefix_route()
- net: phy: microchip: Reset LAN88xx PHY to ensure clean link state on
LAN7800/7850
- ice: fix PHY Clock Recovery availability check
- vsock/test: fix failures due to wrong SO_RCVLOWAT parameter
- vsock/test: fix parameter types in SO_VM_SOCKETS_* calls
- mmc: core Convert UNSTUFF_BITS macro to inline function
- mmc: sd: SDUC Support Recognition
- mmc: core: Adjust ACMD22 to SDUC
- mmc: core: Use GFP_NOIO in ACMD22
- f2fs: clean up w/ F2FS_{BLK_TO_BYTES,BTYES_TO_BLK}
- f2fs: fix to adjust appropriate length for fiemap
- f2fs: fix to requery extent which cross boundary of inquiry
- drm/amd/display: calculate final viewport before TAP optimization
- drm/amd/display: Ignore scalar validation failure if pipe is phantom
- pmdomain: core: Add missing put_device()
- pmdomain: core: Fix error path in pm_genpd_init() when ida alloc fails
- pmdomain: core: add dummy release function to genpd device
- bpf: Ensure reg is PTR_TO_STACK in process_iter_arg
- bpf: Don't mark STACK_INVALID as STACK_MISC in mark_stack_slot_misc
- LoongArch: KVM: Protect kvm_check_requests() with SRCU
- net :mana :Request a V2 response version for MANA_QUERY_GF_STAT
- ALSA: usb-audio: Add extra PID for RME Digiface USB
- ALSA: hda/realtek: fix micmute LEDs don't work on HP Laptops
- scsi: ufs: pltfrm: Disable runtime PM during removal of glue drivers
- io_uring/cmd: document some uring_cmd related helpers
- io_uring: Change res2 parameter type in io_uring_cmd_done
- selftests/damon: add _damon_sysfs.py to TEST_FILES
- drm/amd/display: Correct prefetch calculation
- drm/amd/amdgpu: allow use kiq to do hdp flush under sriov
- drm/amdgpu/hdp6.0: do a posting read when flushing HDP
- drm/amdgpu/hdp4.0: do a posting read when flushing HDP
- drm/amdgpu/hdp5.0: do a posting read when flushing HDP
- x86/cpu/intel: Switch to new Intel CPU model defines
- x86/cpu/intel: Drop stray FAM6 check with new Intel CPU model defines
- x86/cpu: Add Lunar Lake to list of CPUs with a broken MONITOR implementation
- mm/damon: fix order of arguments in damos_before_apply tracepoint
- mm: respect mmap hint address when aligning for THP
- scsi: ufs: pltfrm: Drop PM runtime reference count after ufshcd_remove()
- memblock: allow zero threshold in validate_numa_converage()
- s390/pci: Sort PCI functions prior to creating virtual busses
- s390/pci: Use topology ID for multi-function devices
- s390/pci: Ignore RID for isolated VFs
- s390/pci: Fix SR-IOV for PFs initially in standby
- s390/pci: Pull search for parent PF out of zpci_iov_setup_virtfn()
- s390/pci: Fix handling of isolated VFs
- ext4: partial zero eof block on unaligned inode size extension
- crypto: ecdsa - Convert byte arrays with key coordinates to digits
- crypto: ecc - Prevent ecc_digits_from_bytes from reading too many bytes
- crypto: ecdsa - Rename keylen to bufsize where necessary
- crypto: ecdsa - Use ecc_digits_from_bytes to convert signature
- crypto: ecdsa - Avoid signed integer overflow on signature decoding
- ACPI: video: force native for Apple MacbookPro11,2 and Air7,2
- cleanup: Adjust scoped_guard() macros to avoid potential warning
- gpio: free irqs that are still requested when the chip is being removed
- media: uvcvideo: Force UVC version to 1.0a for 0408:4035
- media: uvcvideo: Force UVC version to 1.0a for 0408:4033
- wifi: mac80211: export ieee80211_purge_tx_queue() for drivers
- drm/amd/display: skip disable CRTC in seemless bootup case
- drm/amd/display: disable SG displays on cyan skillfish
- wifi: mac80211: Add non-atomic station iterator
- accel/qaic: Add AIC080 support
- mptcp: annotate data-races around subflow->fully_established
- net/tcp: Add missing lockdep annotations for TCP-AO hlist traversals
- drm/amd/display: Prune Invalid Modes For HDMI Output
- i2c: i801: Add support for Intel Arrow Lake-H
- i2c: i801: Add support for Intel Panther Lake
- Bluetooth: hci_conn: Reduce hci_conn_drop() calls in two functions
- Bluetooth: btusb: Add new VID/PID 13d3/3602 for MT7925
- Bluetooth: btusb: Add USB HW IDs for MT7921/MT7922/MT7925
- Bluetooth: btusb: Add new VID/PID 0489/e111 for MT7925
- Bluetooth: btusb: Add new VID/PID 0489/e124 for MT7925
- Bluetooth: btusb: Add 3 HWIDs for MT7925
- rtla/timerlat: Make timerlat_hist_cpu->*_count unsigned long long
- ring-buffer: Correct stale comments related to non-consuming readers
- ring-buffer: Limit time with disabled interrupts in rb_check_pages()
- scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting follow up
FDMI
- scsi: lpfc: Prevent NDLP reference count underflow in dev_loss_tmo callback
- clk: qcom: clk-alpha-pll: Add support for zonda ole pll configure
- clk: qcom: clk-alpha-pll: Add NSS HUAYRA ALPHA PLL support for ipq9574
- mailbox: pcc: Check before sending MCTP PCC response ACK
- remoteproc: qcom: pas: Add support for SA8775p ADSP, CDSP and GPDSP
- remoteproc: qcom: pas: enable SAR2130P audio DSP support
- fs/ntfs3: Implement fallocate for compressed files
- fs/ntfs3: Fix warning in ni_fiemap
- regulator: qcom-rpmh: Update ranges for FTSMPS525
- usb: chipidea: add CI_HDRC_HAS_SHORT_PKT_LIMIT flag
- usb: chipidea: udc: limit usb request length to max 16KB
- usb: chipidea: udc: create bounce buffer for problem sglist entries if
possible
- iio: adc: ad7192: Convert from of specific to fwnode property handling
- iio: adc: ad7192: properly check spi_get_device_match_data()
- usb: typec: ucsi: add callback for connector status updates
- usb: typec: ucsi: glink: move GPIO reading into connector_status callback
- usb: typec: ucsi: add update_connector callback
- usb: typec: ucsi: glink: set orientation aware if supported
- usb: typec: ucsi: glink: be more precise on orientation-aware ports
- usb: typec: ucsi: glink: fix off-by-one in connector_status
- usb: typec: ucsi: Set orientation as none when connector is unplugged
- nvme: use helper nvme_ctrl_state in nvme_keep_alive_finish function
- Revert "nvme: make keep-alive synchronous operation"
- irqchip/gic-v3-its: Avoid explicit cpumask allocation on stack
- irqchip/gicv3-its: Add workaround for hip09 ITS erratum 162100801
- [Config] updateconfigs for HISILICON_ERRATUM_162100801
- drm/amd/display: Add option to retrieve detile buffer size
- btrfs: drop unused parameter options from open_ctree()
- btrfs: drop unused parameter data from btrfs_fill_super()
- btrfs: fix mount failure due to remount races
- net/mlx5: unique names for per device caches
- s390/pci: Fix leak of struct zpci_dev when zpci_add_device() fails
- ALSA: hda/realtek: Fix spelling mistake "Firelfy" -> "Firefly"
- softirq: Allow raising SCHED_SOFTIRQ from SMP-call-function on RT kernel
- Upstream stable to v6.6.65, v6.6.66, v6.12.4, v6.12.5
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-41932
- sched: fix warning in sched_setaffinity
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57872
- scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56588
- scsi: hisi_sas: Create all dump files during debugfs initialization
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-47794
- bpf: Prevent tailcall infinite loop caused by freplace
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56599
- wifi: ath10k: avoid NULL pointer error during sdio remove
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56607
- wifi: ath12k: fix atomic calls in ath12k_mac_op_set_bitrate_mask()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56608
- drm/amd/display: Fix out-of-bounds access in 'dcn21_link_encoder_create'
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56609
- wifi: rtw88: use ieee80211_purge_tx_queue() to purge TX skb
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56782
- ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-48876
- stackdepot: fix stack_depot_save_flags() in NMI context
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56620
- scsi: ufs: qcom: Only free platform MSIs when ESI is enabled
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56621
- scsi: ufs: core: Cancel RTC work during ufshcd_remove()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-49569
- nvme-rdma: unquiesce admin_q before destroy it
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56632
- nvme-tcp: fix the memleak while create new ctrl failed
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56647
- net: Fix icmp host relookup triggering ip_rt_bug
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56775
- drm/amd/display: Fix handling of plane refcount
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56561
- PCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56550
- s390/stacktrace: Use break instead of return statement
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56771
- mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC information
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56568
- iommu/arm-smmu: Defer probe of clients after smmu device bound
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56772
- kunit: string-stream: Fix a UAF bug in kunit_init_suite()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56773
- kunit: Fix potential null dereference in kunit_device_driver_test()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56580
- media: qcom: camss: fix error path on configuration of power domains
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57850
- jffs2: Prevent rtime decompress memory corruption
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56583
- sched/deadline: Fix warning in migrate_enable for boosted tasks
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56611
- mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a
MM
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56613
- sched/numa: fix memory leak due to the overwritten vma->numab_state
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56584
- io_uring/tctx: work around xa_store() allocation error issue
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56781
- powerpc/prom_init: Fixup missing powermac #size-cells
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56785
- MIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56585
- LoongArch: Fix sleeping in atomic context for PREEMPT_RT
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-41935
- f2fs: fix to shrink read extent node in batches
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-43098
- i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to
avoid deadlock
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-45828
- i3c: mipi-i3c-hci: Mask ring interrupts before ring stop request
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56586
- f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56587
- leds: class: Protect brightness_show() with led_cdev->led_access mutex
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56786
- bpf: put bpf_link's program when link is safe to be deallocated
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-47141
- pinmux: Use sequential access to access desc->pinmux data
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56589
- scsi: hisi_sas: Add cond_resched() for no forced preemption model
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56590
- Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56592
- bpf: Call free_htab_elem() after htab_unlock_bucket()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56593
- wifi: brcmfmac: Fix oops due to NULL pointer dereference in
brcmf_sdiod_sglist_rw()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56594
- drm/amdgpu: set the right AMDGPU sg segment limitation
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57843
- virtio-net: fix overflow inside virtnet_rq_alloc
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56596
- jfs: fix array-index-out-of-bounds in jfs_readdir
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56597
- jfs: fix shift-out-of-bounds in dbSplit
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-47143
- dma-debug: fix a possible deadlock on radix_lock
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56601
- net: inet: do not leave a dangling sk pointer in inet_create()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56602
- net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56603
- net: af_can: do not leave a dangling sk pointer in can_create()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56604
- Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56605
- Bluetooth: L2CAP: do not leave dangling sk pointer on error in
l2cap_sock_create()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56606
- af_packet: avoid erroring out after sock_init_data() in packet_create()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-47809
- dlm: fix possible lkb_resource null dereference
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-48873
- wifi: rtw89: check return value of ieee80211_probereq_get() for RNR
* Missing support for USB-C Apple Magic Trackpad (LP: #2098063) // Noble
update: upstream stable patchset 2025-03-12 (LP: #2102118)
- HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56787
- soc: imx8m: Probe the SoC driver as platform driver
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56610
- kcsan: Turn report_filterlist_lock into a raw_spinlock
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-48875
- btrfs: don't take dev_replace rwsem on task already holding it
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57849
- s390/cpum_sf: Handle CPU hotplug remove during sampling
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57876
- drm/dp_mst: Fix resetting msg rx state after topology removal
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56616
- drm/dp_mst: Fix MST sideband message body length check
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-48881
- bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56619
- nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56622
- scsi: ufs: core: sysfs: Prevent div by zero
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56623
- scsi: qla2xxx: Fix use after free on unload
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-57874
- arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56625
- can: dev: can_set_termination(): allow sleeping GPIOs
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56626
- ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56628
- LoongArch: Add architecture specific huge_pte_clear()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56629
- HID: wacom: fix when get product name maybe null pointer
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56630
- ocfs2: free inode when ocfs2_get_init_inode() fails
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56631
- scsi: sg: Fix slab-use-after-free read in sg_release()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-50051
- spi: mpc52xx: Add cancel_work_sync before module remove
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56633
- tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56565
- f2fs: fix to drop all discards after creating snapshot on lvm device
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56634
- gpio: grgpio: Add NULL check in grgpio_probe
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56635
- net: avoid potential UAF in default_operstate()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56636
- geneve: do not assume mac header is set in geneve_xmit_skb()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56637
- netfilter: ipset: Hold module reference while requesting a module
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56638
- netfilter: nft_inner: incorrect percpu area handling under softirq
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-52332
- igb: Fix potential invalid memory access in igb_init_module()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56640
- net/smc: fix LGR and link use-after-free issue
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56641
- net/smc: initialize close_work early to avoid warning
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56643
- dccp: Fix memory leak in dccp_feat_change_recv
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56644
- net/ipv6: release expired exception dst cached in socket
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56645
- can: j1939: j1939_session_new(): fix skb reference counting
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56648
- net: hsr: avoid potential out-of-bound access in fill_frame_info()
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56649
- net: enetc: Do not configure preemptible TCs if SIs do not support
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56783
- netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level
* Noble update: upstream stable patchset 2025-03-12 (LP: #2102118) //
CVE-2024-56650
- netfilter: x_tables: fix LED ID check in led_tg_check()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915)
- wifi: radiotap: Avoid -Wflex-array-member-not-at-end warnings
- ASoC: codecs: rt5640: Always disable IRQs from rt5640_cancel_work()
- ASoC: Intel: bytcr_rt5640: Add support for non ACPI instantiated codec
- ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet
- ASoC: Intel: sst: Support LPE0F28 ACPI HID
- wifi: iwlwifi: mvm: Use the sync timepoint API in suspend
- mac80211: fix user-power when emulating chanctx
- usb: add support for new USB device ID 0x17EF:0x3098 for the r8152 driver
- selftests/watchdog-test: Fix system accidentally reset after watchdog-test
- ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
- x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB
- bpf: fix filed access without lock
- net: usb: qmi_wwan: add Quectel RG650V
- soc: qcom: Add check devm_kasprintf() returned value
- firmware: arm_scmi: Reject clear channel request on A2P
- regulator: rk808: Add apply_bit for BUCK3 on RK809
- platform/x86: dell-smbios-base: Extends support to Alienware products
- platform/x86: dell-wmi-base: Handle META key Lock/Unlock events
- ASoC: tas2781: Add new driver version for tas2563 & tas2781 qfn chip
- tools/lib/thermal: Remove the thermal.h soft link when doing make clean
- can: j1939: fix error in J1939 documentation.
- platform/x86: thinkpad_acpi: Fix for ThinkPad's with ECFW showing incorrect
fan speed
- ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad E14 Gen 6
- ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate()
- ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div()
- drm: panel-orientation-quirks: Make Lenovo Yoga Tab 3 X90F DMI match less
strict
- proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
- ASoC: audio-graph-card2: Purge absent supplies for device tree nodes
- LoongArch: Define a default value for VM_DATA_DEFAULT_FLAGS
- ALSA: usb-audio: Fix Yamaha P-125 Quirk Entry
- ARM: 9420/1: smp: Fix SMP for xip kernels
- ipmr: Fix access to mfc_cache_list without lock held
- mptcp: fix possible integer overflow in mptcp_reset_tout_timer
- arm64: probes: Disable kprobes/uprobes on MOPS instructions
- kselftest/arm64: mte: fix printf type warnings about __u64
- kselftest/arm64: mte: fix printf type warnings about longs
- s390/cio: Do not unregister the subchannel based on DNV
- s390/pageattr: Implement missing kernel_page_present()
- ext4: avoid remount errors with 'abort' mount option
- mips: asm: fix warning when disabling MIPS_FP_SUPPORT
- m68k: mvme147: Fix SCSI controller IRQ numbers
- m68k: mvme147: Reinstate early console
- arm64: fix .data.rel.ro size assertion when CONFIG_LTO_CLANG
- acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()
- cachefiles: Fix missing pos updates in cachefiles_ondemand_fd_write_iter()
- block: fix bio_split_rw_at to take zone_write_granularity into account
- s390/syscalls: Avoid creation of arch/arch/ directory
- ext4: remove calls to to set/clear the folio error flag
- ext4: pipeline buffer reads in mext_page_mkuptodate()
- ext4: remove array of buffer_heads from mext_page_mkuptodate()
- ext4: fix race in buffer_head read fault injection
- nvme-pci: reverse request order in nvme_queue_rqs
- virtio_blk: reverse request order in virtio_queue_rqs
- crypto: qat - remove check after debugfs_create_dir()
- firmware: google: Unregister driver_info on failure
- crypto: qat - remove faulty arbiter config reset
- thermal: core: Initialize thermal zones before registering them
- EDAC/fsl_ddr: Fix bad bit shift operations
- EDAC/skx_common: Differentiate memory error sources
- EDAC/{skx_common,i10nm}: Fix incorrect far-memory error source indicator
- crypto: cavium - Fix the if condition to exit loop after timeout
- amd-pstate: Set min_perf to nominal_perf for active mode performance gov
- crypto: hisilicon/qm - disable same error report before resetting
- crypto: inside-secure - Fix the return value of safexcel_xcbcmac_cra_init()
- doc: rcu: update printed dynticks counter bits
- hwmon: (pmbus_core) Allow to hook PMBUS_SMBALERT_MASK
- hwmon: (pmbus/core) clear faults after setting smbalert mask
- hwmon: (nct6775-core) Fix overflows seen when writing limit attributes
- ACPI: CPPC: Fix _CPC register setting issue
- crypto: caam - add error check to caam_rsa_set_priv_key_form
- crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
- rcuscale: Do a proper cleanup if kfree_scale_init() fails
- tools/lib/thermal: Make more generic the command encoding function
- thermal/lib: Fix memory leak on error in thermal_genl_auto()
- x86/unwind/orc: Fix unwind for newly forked tasks
- time: Partially revert cleanup on msecs_to_jiffies() documentation
- time: Fix references to _msecs_to_jiffies() handling of values
- kcsan, seqlock: Support seqcount_latch_t
- kcsan, seqlock: Fix incorrect assumption in read_seqbegin()
- clocksource/drivers:sp804: Make user selectable
- clocksource/drivers/timer-ti-dm: Fix child node refcount handling
- spi: spi-fsl-lpspi: Use IRQF_NO_AUTOEN flag in request_irq()
- microblaze: Export xmb_manager functions
- arm64: dts: mt8195: Fix dtbs_check error for mutex node
- arm64: dts: mt8195: Fix dtbs_check error for infracfg_ao node
- soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
- arm64: dts: qcom: sm6350: Fix GPU frequencies missing on some speedbins
- ARM: dts: microchip: sam9x60: Add missing property atmel,usart-mode
- mmc: mmc_spi: drop buggy snprintf()
- openrisc: Implement fixmap to fix earlycon
- efi/libstub: fix efi_parse_options() ignoring the default command line
- tpm: fix signed/unsigned bug when checking event logs
- media: i2c: ds90ub960: Fix missing return check on ub960_rxport_read call
- arm64: dts: mt8183: krane: Fix the address of eeprom at i2c4
- arm64: dts: mt8183: kukui: Fix the address of eeprom at i2c4
- arm64: dts: mediatek: mt8173-elm-hana: Add vdd-supply to second source
trackpad
- Revert "cgroup: Fix memory leak caused by missing cgroup_bpf_offline"
- cgroup/bpf: only cgroup v2 can be attached by bpf programs
- regulator: rk808: Restrict DVS GPIOs to the RK808 variant only
- arm64: dts: mt8183: fennel: add i2c2's i2c-scl-internal-delay-ns
- arm64: dts: mt8183: burnet: add i2c2's i2c-scl-internal-delay-ns
- arm64: dts: mt8183: cozmo: add i2c2's i2c-scl-internal-delay-ns
- arm64: dts: mt8183: Damu: add i2c2's i2c-scl-internal-delay-ns
- pwm: imx27: Workaround of the pwm output bug when decrease the duty cycle
- ARM: dts: cubieboard4: Fix DCDC5 regulator constraints
- arm64: dts: ti: k3-j7200: use ti,j7200-padconf compatible
- arm64: dts: ti: k3-j7200: Fix register map for main domain pmx
- arm64: dts: ti: k3-j7200: Fix clock ids for MCSPI instances
- arm64: dts: ti: k3-j721e: Fix clock IDs for MCSPI instances
- arm64: dts: ti: k3-j721s2: Fix clock IDs for MCSPI instances
- um: Unconditionally call unflatten_device_tree()
- x86/of: Unconditionally call unflatten_and_copy_device_tree()
- of/fdt: add dt_phys arg to early_init_dt_scan and early_init_dt_verify
- riscv: Fix wrong usage of __pa() on a fixmap address
- pmdomain: ti-sci: Add missing of_node_put() for args.np
- spi: tegra210-quad: Avoid shift-out-of-bounds
- spi: zynqmp-gqspi: Undo runtime PM changes at driver exit time
- regmap: irq: Set lockdep class for hierarchical IRQ domains
- arm64: dts: renesas: hihope: Drop #sound-dai-cells
- arm64: dts: mediatek: Add ADC node on MT6357, MT6358, MT6359 PMICs
- arm64: dts: mediatek: mt6358: fix dtbs_check error
- arm64: dts: mediatek: mt8183-kukui-jacuzzi: Fix DP bridge supply names
- arm64: dts: mediatek: mt8183-kukui-jacuzzi: Add supplies for fixed
regulators
- selftests/resctrl: Split fill_buf to allow tests finer-grained control
- selftests/resctrl: Refactor fill_buf functions
- selftests/resctrl: Fix memory overflow due to unhandled wraparound
- selftests/resctrl: Protect against array overrun during iMC config parsing
- arm64: dts: rockchip: correct analog audio name on Indiedroid Nova
- platform/x86: panasonic-laptop: Return errno correctly in show callback
- drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
- drm/vc4: hvs: Don't write gamma luts on 2711
- drm/vc4: hvs: Fix dlist debug not resetting the next entry pointer
- drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs function
- drm/vc4: hvs: Correct logic on stopping an HVS channel
- drm/omap: Fix possible NULL dereference
- drm/omap: Fix locking in omap_gem_new_dmabuf()
- wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq()
- wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
- drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq()
- drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
- drm/v3d: Address race-condition in MMU flush
- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss1
- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss2
- dt-bindings: vendor-prefixes: Add NeoFidelity, Inc
- ASoC: fsl_micfil: fix regmap_write_bits usage
- ASoC: dt-bindings: mt6359: Update generic node name and dmic-mode
- drm/bridge: anx7625: Drop EDID cache on bridge power off
- drm/bridge: it6505: Drop EDID cache on bridge power off
- libbpf: Fix expected_attach_type set handling in program load callback
- libbpf: Fix output .symtab byte-order during linking
- bpf: Fix the xdp_adjust_tail sample prog issue
- wifi: ath11k: Fix CE offset address calculation for WCN6750 in SSR
- ice: consistently use q_idx in ice_vc_cfg_qs_msg()
- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_atomic_flush
- libbpf: fix sym_is_subprog() logic for weak global subprogs
- ASoC: rt722-sdca: Remove logically deadcode in rt722-sdca.c
- libbpf: never interpret subprogs in .text as entry programs
- netdevsim: copy addresses for both in and out paths
- drm/bridge: tc358767: Fix link properties discovery
- selftests/bpf: Fix msg_verify_data in test_sockmap
- selftests/bpf: Fix txmsg_redir of test_txmsg_pull in test_sockmap
- drm: fsl-dcu: enable PIXCLK on LS1021A
- drm/msm/dpu: on SDM845 move DSPP_3 to LM_5 block
- drm/msm/dpu: drop LM_3 / LM_4 on SDM845
- drm/msm/dpu: drop LM_3 / LM_4 on MSM8998
- selftests/bpf: fix test_spin_lock_fail.c's global vars usage
- drm/panfrost: Remove unused id_mask from struct panfrost_model
- bpf, arm64: Remove garbage frame for struct_ops trampoline
- drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
- drm/msm/gpu: Check the status of registration to PM QoS
- drm/etnaviv: Request pages from DMA32 zone on addressing_limited
- drm/etnaviv: hold GPU lock across perfmon sampling
- wifi: wfx: Fix error handling in wfx_core_init()
- drm/msm/dpu: cast crtc_clk calculation to u64 in _dpu_core_perf_calc_clk()
- bpf, bpftool: Fix incorrect disasm pc
- drm/vkms: Drop unnecessary call to drm_crtc_cleanup()
- drm: use ATOMIC64_INIT() for atomic64_t
- netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion
- netfilter: nf_tables: must hold rcu read lock while iterating expression
type list
- netfilter: nf_tables: skip transaction if update object is not implemented
- netfilter: nf_tables: must hold rcu read lock while iterating object type
list
- netlink: typographical error in nlmsg_type constants definition
- selftests/bpf: Add txmsg_pass to pull/push/pop in test_sockmap
- selftests/bpf: Fix SENDPAGE data logic in test_sockmap
- selftests/bpf: Fix total_bytes in msg_loop_rx in test_sockmap
- selftests/bpf: Add push/pop checking for msg_verify_data in test_sockmap
- bpf, sockmap: Several fixes to bpf_msg_push_data
- bpf, sockmap: Fix sk_msg_reset_curr
- sock_diag: add module pointer to "struct sock_diag_handler"
- sock_diag: allow concurrent operations
- sock_diag: allow concurrent operation in sock_diag_rcv_msg()
- net: use unrcu_pointer() helper
- selftests: net: really check for bg process completion
- drm/amdkfd: Fix wrong usage of INIT_WORK()
- bpf: Force uprobe bpf program to always return 0
- net: rfkill: gpio: Add check for clk_enable()
- netpoll: Use rcu_access_pointer() in netpoll_poll_lock
- wireguard: selftests: load nf_conntrack if not present
- cppc_cpufreq: Use desired perf if feedback ctrs are 0 or unchanged
- clk: mediatek: drop two dead config options
- [Config] drop COMMON_CLK_MT8195_AUDSYS and COMMON_CLK_MT8195_MSDC
- trace/trace_event_perf: remove duplicate samples on the first tracepoint
event
- pinctrl: zynqmp: drop excess struct member description
- scsi: hisi_sas: Enable all PHYs that are not disabled by user during
controller reset
- mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race
- mfd: da9052-spi: Change read-mask to write-mask
- cpufreq: loongson2: Unregister platform_driver on failure
- powerpc/fadump: Refactor and prepare fadump_cma_init for late init
- mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE
- mtd: rawnand: atmel: Fix possible memory leak
- mtd: rawnand: fix double free in atmel_pmecc_create_user()
- mtd: spi-nor: spansion: Use nor->addr_nbytes in octal DTR mode in
RD_ANY_REG_OP
- RDMA/hns: Fix an AEQE overflow error caused by untimely update of eq_db_ci
- RDMA/hns: Use dev_* printings in hem code instead of ibdev_*
- RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
- clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset
- clk: renesas: rzg2l: Fix FOUTPOSTDIV clk
- RDMA/rxe: Set queue pair cur_qp_state when being queried
- RISC-V: KVM: Fix APLIC in_clrip and clripnum write emulation
- clk: imx: lpcg-scu: SW workaround for errata (e10858)
- clk: imx: fracn-gppll: correct PLL initialization flow
- clk: imx: fracn-gppll: fix pll power up
- clk: imx: clk-scu: fix clk enable state save and restore
- clk: imx: imx8-acm: Fix return value check in
clk_imx_acm_attach_pm_domains()
- iommu/vt-d: Fix checks and print in dmar_fault_dump_ptes()
- iommu/vt-d: Fix checks and print in pgtable_walk()
- checkpatch: check for missing Fixes tags
- checkpatch: always parse orig_commit in fixes tag
- mfd: rt5033: Fix missing regmap_del_irq_chip()
- fs/proc/kcore.c: fix coccinelle reported ERROR instances
- scsi: fusion: Remove unused variable 'rc'
- scsi: sg: Enable runtime power management
- x86/tdx: Introduce wrappers to read and write TD metadata
- x86/tdx: Rename tdx_parse_tdinfo() to tdx_setup()
- x86/tdx: Dynamically disable SEPT violations from causing #VEs
- RDMA/hns: Fix out-of-order issue of requester when setting FENCE
- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost()
- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power()
- dax: delete a stale directory pmem
- KVM: PPC: Book3S HV: Stop using vc->dpdes for nested KVM guests
- KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on pending
doorbells
- powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static
- powerpc/kexec: Fix return of uninitialized variable
- IB/mlx5: Allocate resources just before first QP/SRQ is created
- clk: ralink: mtmips: fix clock plan for Ralink SoC RT3883
- clk: ralink: mtmips: remove duplicated 'xtal' clock for Ralink SoC RT3883
- dt-bindings: clock: axi-clkgen: include AXI clk
- clk: clk-axi-clkgen: make sure to enable the AXI bus clock
- arm64: dts: qcom: sc8180x: Add a SoC-specific compatible to cpufreq-hw
- pinctrl: k210: Undef K210_PC_DEFAULT
- smb: cached directories can be more than root file handle
- mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb()
- perf cs-etm: Don't flush when packet_queue fills up
- gfs2: Get rid of gfs2_glock_queue_put in signal_our_withdraw
- gfs2: Replace gfs2_glock_queue_put with gfs2_glock_put_async
- gfs2: Rename GLF_VERIFY_EVICT to GLF_VERIFY_DELETE
- gfs2: Allow immediate GLF_VERIFY_DELETE work
- gfs2: Fix unlinked inode cleanup
- perf stat: Close cork_fd when create_perf_stat_counter() failed
- perf stat: Fix affinity memory leaks on error path
- perf trace: Keep exited threads for summary
- perf test attr: Add back missing topdown events
- f2fs: compress: fix inconsistent update of i_blocks in
release_compress_blocks and reserve_compress_blocks
- perf probe: Fix libdw memory leak
- perf probe: Correct demangled symbols in C++ program
- rust: macros: fix documentation of the paste! macro
- PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
- PCI: cpqphp: Fix PCIBIOS_* return value confusion
- perf ftrace latency: Fix unit on histogram first entry when using --use-nsec
- f2fs: fix the wrong f2fs_bug_on condition in f2fs_do_replace_block
- f2fs: check curseg->inited before write_sum_page in change_curseg
- f2fs: fix to avoid use GC_AT when setting gc_mode as GC_URGENT_LOW or
GC_URGENT_MID
- PCI: cadence: Extract link setup sequence from cdns_pcie_host_setup()
- PCI: cadence: Set cdns_pcie_host_init() global
- PCI: j721e: Add reset GPIO to struct j721e_pcie
- PCI: j721e: Use T_PERST_CLK_US macro
- PCI: j721e: Add suspend and resume support
- PCI: j721e: Deassert PERST# after a delay of PCIE_T_PVPERL_MS milliseconds
- f2fs: fix to avoid forcing direct write to use buffered IO on inline_data
inode
- perf trace: avoid garbage when not printing a trace event's arguments
- m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x
- m68k: coldfire/device.c: only build FEC when HW macros are defined
- perf list: Fix topic and pmu_name argument order
- perf trace: Fix tracing itself, creating feedback loops
- perf trace: Do not lose last events in a race
- perf trace: Avoid garbage when not printing a syscall's arguments
- remoteproc: qcom: pas: add minidump_id to SM8350 resources
- rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
- remoteproc: qcom_q6v5_mss: Re-order writes to the IMEM region
- nfsd: restore callback functionality for NFSv4.0
- NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
- NFSD: Fix nfsd4_shutdown_copy()
- hwmon: (tps23861) Fix reporting of negative temperatures
- vdpa/mlx5: Fix suboptimal range on iotlb iteration
- selftests/mount_setattr: Fix failures on 64K PAGE_SIZE kernels
- gpio: zevio: Add missed label initialisation
- fs_parser: update mount_api doc to match function signature
- LoongArch: Fix build failure with GCC 15 (-std=gnu23)
- LoongArch: BPF: Sign-extend return values
- power: supply: core: Remove might_sleep() from power_supply_put()
- power: supply: bq27xxx: Fix registers of bq27426
- power: supply: rt9471: Fix wrong WDT function regfield declaration
- power: supply: rt9471: Use IC status regfield to report real charger status
- net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
- tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
- net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL
configuration
- net: microchip: vcap: Add typegroup table terminators in kunit tests
- net/ipv6: delete temporary address if mngtmpaddr is removed or unmanaged
- net: mdio-ipq4019: add missing error check
- marvell: pxa168_eth: fix call balance of pep->clk handling routines
- net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
- octeontx2-af: RPM: Fix mismatch in lmac type
- octeontx2-af: RPM: Fix low network performance
- octeontx2-pf: Reset MAC stats during probe
- octeontx2-af: RPM: fix stale RSFEC counters
- octeontx2-af: RPM: fix stale FCFEC counters
- octeontx2-af: Quiesce traffic before NIX block reset
- spi: atmel-quadspi: Fix register name in verbose logging function
- net: hsr: fix hsr_init_sk() vs network/transport headers.
- bnxt_en: Reserve rings after PCIe AER recovery if NIC interface is down
- bnxt_en: Refactor bnxt_ptp_init()
- bnxt_en: Unregister PTP during PCI shutdown and suspend
- llc: Improve setsockopt() handling of malformed user input
- rxrpc: Improve setsockopt() handling of malformed user input
- tcp: Fix use-after-free of nreq in reqsk_timer_handler().
- ip6mr: fix tables suspicious RCU usage
- ipmr: fix tables suspicious RCU usage
- iio: light: al3010: Fix an error handling path in al3010_probe()
- usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
- usb: yurex: make waiting on yurex_write interruptible
- USB: chaoskey: fail open after removal
- USB: chaoskey: Fix possible deadlock chaoskey_list_lock
- misc: apds990x: Fix missing pm_runtime_disable()
- counter: stm32-timer-cnt: Add check for clk_enable()
- counter: ti-ecap-capture: Add check for clk_enable()
- ALSA: hda/realtek: Update ALC256 depop procedure
- drm/radeon: add helper rdev_to_drm(rdev)
- drm/radeon: change rdev->ddev to rdev_to_drm(rdev)
- drm/radeon: Fix spurious unplug event on radeon HDMI
- apparmor: fix 'Do simple duplicate message elimination'
- ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry
- gfs2: Don't set GLF_LOCK in gfs2_dispose_glock_lru
- gfs2: Remove and replace gfs2_glock_queue_work
- f2fs: fix fiemap failure issue when page size is 16KB
- usb: ehci-spear: fix call balance of sehci clk handling routines
- ALSA: usb-audio: Fix a DMA to stack memory bug
- ASoC: Intel: sst: Fix used of uninitialized ctx to log an error
- soc: qcom: socinfo: fix revision check in qcom_socinfo_probe()
- ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
- ext4: fix FS_IOC_GETFSMAP handling
- jfs: xattr: check invalid xattr size more strictly
- ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad P14s Gen 5
21MES00B00
- ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
- perf/x86/intel/pt: Fix buffer full but size is 0 case
- crypto: x86/aegis128 - access 32-bit arguments as 32-bit
- KVM: x86/mmu: Skip the "try unsync" path iff the old SPTE was a leaf SPTE
- powerpc/pseries: Fix KVM guest detection for disabling hardlockup detector
- KVM: arm64: vgic-v3: Sanitise guest writes to GICR_INVLPIR
- KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status
- KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
- KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
- KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
- fsnotify: fix sending inotify event with unexpected filename
- tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
- locking/lockdep: Avoid creating new name string literals in
lockdep_set_subclass()
- tools/nolibc: s390: include std.h
- pinctrl: qcom: spmi: fix debugfs drive strength
- dt-bindings: iio: dac: ad3552r: fix maximum spi speed
- exfat: fix uninit-value in __exfat_get_dentry_set
- Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
- Compiler Attributes: disable __counted_by for clang < 19.1.3
- usb: xhci: Fix TD invalidation under pending Set TR Dequeue
- ARM: dts: omap36xx: declare 1GHz OPP as turbo again
- wifi: brcmfmac: release 'root' node in all execution paths
- Revert "usb: gadget: composite: fix OS descriptors w_value logic"
- gpio: exar: set value when external pull-up or pull-down is present
- spi: Fix acpi deferred irq probe
- cpufreq: mediatek-hw: Fix wrong return value in mtk_cpufreq_get_cpu_power()
- cifs: support mounting with alternate password to allow password rotation
- parisc/ftrace: Fix function graph tracing disablement
- platform/chrome: cros_ec_typec: fix missing fwnode reference decrement
- ubi: wl: Put source PEB into correct list if trying locking LEB failed
- dt-bindings: serial: rs485: Fix rs485-rts-delay property
- serial: 8250_fintek: Add support for F81216E
- serial: 8250: omap: Move pm_runtime_get_sync
- iio: gts: Fix uninitialized symbol 'ret'
- ublk: fix ublk_ch_mmap() for 64K page size
- arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled
- block: fix missing dispatching request when queue is started or unquiesced
- block: fix ordering between checking QUEUE_FLAG_QUIESCED request adding
- block: fix ordering between checking BLK_MQ_S_STOPPED request adding
- blk-mq: Make blk_mq_quiesce_tagset() hold the tag list mutex less long
- HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
- soc: fsl: rcpm: fix missing of_node_put() in copy_ippdexpcr1_setting()
- media: v4l2-core: v4l2-dv-timings: check cvt/gtf result
- ALSA: ump: Fix evaluation of MIDI 1.0 FB info
- ALSA: hda/realtek: Update ALC225 depop procedure
- ALSA: hda/realtek: Fixup ALC225 depop procedure
- ALSA: hda/realtek: Set PCBeep to default value for ALC274
- ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max
- ALSA: hda/realtek: Apply quirk for Medion E15433
- smb3: request handle caching when caching directories
- smb: client: handle max length for SMB symlinks
- cifs: Add tracing for the cifs_tcon struct refcounting
- usb: dwc3: gadget: Fix checking for number of TRBs left
- ublk: fix error code for unsupported command
- lib: string_helpers: silence snprintf() output truncation warning
- um: Fix the return value of elf_core_copy_task_fpregs
- um: Always dump trace for specified task in show_stack
- rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
- rtc: abx80x: Fix WDT bit position of the status register
- ubi: fastmap: wl: Schedule fm_work if wear-leveling pool is empty
- ubifs: Correct the total block count by deducting journal reservation
- jffs2: fix use of uninitialized variable
- rtc: rzn1: fix BCD to rtc_time conversion errors
- nvme-multipath: prepare for "queue-depth" iopolicy
- nvme-multipath: implement "queue-depth" iopolicy
- nvme-multipath: avoid hang on inaccessible namespaces
- nvme/multipath: Fix RCU list traversal to use SRCU primitive
- block: return unsigned int from bdev_io_min
- 9p/xen: fix init sequence
- perf/arm-smmuv3: Fix lockdep assert in ->event_init()
- perf/arm-cmn: Ensure port and device id bits are set properly
- smb: client: disable directory caching when dir_cache_timeout is zero
- cifs: Fix parsing native symlinks relative to the export
- cifs: Fix parsing reparse point with native symlink in SMB1 non-UNICODE
session
- rtc: ab-eoz9: don't fail temperature reads on undervoltage notification
- init/modpost: conditionally check section mismatch to __meminit*
- Rename .data.unlikely to .data..unlikely
- Rename .data.once to .data..once to fix resetting WARN*_ONCE
- modpost: remove incorrect code in do_eisa_entry()
- cifs: during remount, make sure passwords are in sync
- cifs: unlock on error in smb3_reconfigure()
- nfs: ignore SB_RDONLY when mounting nfs
- SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT
- xfs: remove unknown compat feature check in superblock write validation
- btrfs: don't loop for nowait writes when checking for cross references
- md/md-bitmap: Add missing destroy_work_on_stack()
- arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer
- arm64: dts: freescale: imx8mm-verdin: Fix SD regulator startup delay
- arm64: dts: ti: k3-am62-verdin: Fix SD regulator startup delay
- media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime pm enabled
- arm64: dts: freescale: imx8mp-verdin: Fix SD regulator startup delay
- media: imx-jpeg: Fix potential error pointer dereference in detach_pm()
- media: verisilicon: av1: Fix reference video buffer pointer assignment
- media: platform: exynos4-is: Fix an OF node reference leak in
fimc_md_is_isp_available
- media: amphion: Fix pm_runtime_set_suspended() with runtime pm enabled
- media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled
- media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate()
- media: uvcvideo: Stop stream during unregister
- maple_tree: refine mas_store_root() on storing NULL
- vmstat: call fold_vm_zone_numa_events() before show per zone NUMA event
- zram: clear IDLE flag after recompression
- iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated tables
- leds: lp55xx: Remove redundant test for invalid channel number
- clk: qcom: gcc-qcs404: fix initial rate of GPLL3
- ARM: 9429/1: ioremap: Sync PGDs for VMALLOC shadow
- ARM: 9430/1: entry: Do a dummy read from VMAP shadow
- ARM: 9431/1: mm: Pair atomic_set_release() with _read_acquire()
- ceph: extract entity name from device id
- util_macros.h: fix/rework find_closest() macros
- scsi: ufs: exynos: Fix hibern8 notify callbacks
- i3c: master: svc: Fix pm_runtime_set_suspended() with runtime pm enabled
- PCI: keystone: Set mode as Root Complex for "ti,keystone-pcie" compatible
- PCI: keystone: Add link up check to ks_pcie_other_map_bus()
- PCI: endpoint: Clear secondary (not primary) EPC in pci_epc_remove_epf()
- fs/proc/kcore.c: Clear ret value in read_kcore_iter after successful
iov_iter_zero
- thermal: int3400: Fix reading of current_uuid for active policy
- leds: flash: mt6360: Fix device_for_each_child_node() refcounting in error
paths
- ovl: properly handle large files in ovl_security_fileattr
- dm: Fix typo in error message
- dm thin: Add missing destroy_work_on_stack()
- PCI: of_property: Assign PCI instead of CPU bus address to dynamic PCI nodes
- PCI: rockchip-ep: Fix address translation unit programming
- iio: accel: kx022a: Fix raw read format
- iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name()
- iio: gts: fix infinite loop for gain_to_scaletables()
- powerpc: Fix stack protector Kconfig test for clang
- powerpc: Adjust adding stack protector flags to KBUILD_CLAGS for clang
- udmabuf: use vmf_insert_pfn and VM_PFNMAP for handling mmap
- drm/mediatek: Fix child node refcount handling in early exit
- drm/etnaviv: flush shader L1 cache after user commandstream
- drm: xlnx: zynqmp_dpsub: fix hotplug detection
- drm/amdkfd: Use the correct wptr size
- drm/amd/pm: update current_socclk and current_uclk in gpu_metrics on smu
v13.0.7
- posix-timers: Target group sigqueue to current task only if not exiting
- wifi: cfg80211: Add wiphy_delayed_work_pending()
- wifi: mac80211: Convert color collision detection to wiphy work
- spi: stm32: fix missing device mode capability in stm32mp25
- usb: typec: use cleanup facility for 'altmodes_node'
- platform/x86: ideapad-laptop: add missing Ideapad Pro 5 fn keys
- integrity: Avoid -Wflex-array-member-not-at-end warnings
- integrity: Use static_assert() to check struct sizes
- ASoC: max9768: Fix event generation for playback mute
- ARM: 9434/1: cfi: Fix compilation corner case
- drm/amd/display: Skip Invalid Streams from DSC Policy
- drm/amd/display: Fix DSC-re-computing
- drm/amd/display: Fix incorrect DSC recompute trigger
- s390/facilities: Fix warning about shadow of global variable
- cachefiles: Fix incorrect length return value in
cachefiles_ondemand_fd_write_iter()
- thermal: core: Drop thermal_zone_device_is_enabled()
- thermal: core: Synchronize suspend-prepare and post-suspend actions
- thermal: core: Rearrange PM notification code
- thermal: core: Represent suspend-related thermal zone flags as bits
- thermal: core: Mark thermal zones as initializing to start with
- thermal: core: Fix race between zone registration and system suspend
- crypto: qat - Fix missing destroy_workqueue in adf_init_aer()
- sched/cpufreq: Ensure sd is rebuilt for EAS check
- cleanup: Remove address space of returned pointer
- ARM: dts: renesas: genmai: Fix partition size for QSPI NOR Flash
- arm64: dts: mediatek: mt8395-genio-1200-evk: Fix dtbs_check error for phy
- scripts/kernel-doc: Do not track section counter across processed files
- arm64: dts: qcom: x1e80100: Resize GIC Redistributor register region
- scripts/kernel-doc: add modeline for vim users
- scripts/kernel-doc: simplify function printing
- scripts/kernel-doc: separate out function signature
- scripts/kernel-doc: simplify signature printing
- doc: kerneldoc.py: fix indentation
- kernel-doc: allow object-like macros in ReST output
- arm64: dts: mediatek: mt8188: Fix USB3 PHY port default status
- arm64: dts: rockchip: Remove 'enable-active-low' from two boards
- arm64: dts: qcom: x1e80100: Update C4/C5 residency/exit numbers
- dt-bindings: cache: qcom,llcc: Fix X1E80100 reg entries
- pwm: Assume a disabled PWM to emit a constant inactive output
- drm/imagination: Convert to use time_before macro
- drm/imagination: Use pvr_vm_context_get()
- drm/v3d: Flush the MMU before we supply more memory to the binner
- drm/amdgpu: Fix JPEG v4.0.3 register write
- ASoC: fsl-asoc-card: Add missing handling of {hp,mic}-dt-gpios
- wifi: rtl8xxxu: Perform update_beacon_work when beaconing is enabled
- selftests/bpf: netns_new() and netns_free() helpers.
- selftests/bpf: Fix backtrace printing for selftests crashes
- selftests/bpf: add missing header include for htons
- drm/vc4: hdmi: Increase audio MAI fifo dreq threshold
- drm/vc4: Introduce generation number enum
- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_lut_load
- drm/vc4: Correct generation check in vc4_hvs_lut_load
- bpf: Tighten tail call checks for lingering locks, RCU, preempt_disable
- drm/panfrost: Add missing OPP table refcnt decremental
- selftests: netfilter: Fix missing return values in conntrack_dump_flush
- Bluetooth: btintel: Do no pass vendor events to stack
- Bluetooth: btbcm: fix missing of_node_put() in btbcm_get_board_name()
- Bluetooth: ISO: Use kref to track lifetime of iso_conn
- Bluetooth: ISO: Do not emit LE PA Create Sync if previous is pending
- Bluetooth: hci_conn: Use __counted_by() to avoid -Wfamnae warning
- Bluetooth: hci_conn: Use struct_size() in hci_le_big_create_sync()
- Bluetooth: ISO: Do not emit LE BIG Create Sync if previous is pending
- Bluetooth: ISO: Send BIG Create Sync via hci_sync
- Bluetooth: iso: Fix circular lock in iso_conn_big_sync
- net: txgbe: remove GPIO interrupt controller
- net: txgbe: fix null pointer to pcs
- RDMA/core: Provide rdma_user_mmap_disassociate() to disassociate mmap pages
- RDMA/hns: Disassociate mmap pages for all uctx when HW is being reset
- iommu/amd: Remove amd_iommu_domain_update() from page table freeing
- iommu/amd/pgtbl_v2: Take protection domain lock before invalidating TLB
- RDMA/hns: Fix flush cqe error when racing with destroy qp
- RDMA/hns: Modify debugfs name
- leds: max5970: Fix unreleased fwnode_handle in probe function
- kasan: move checks to do_strncpy_from_user
- kunit: skb: use "gfp" variable instead of hardcoding GFP_KERNEL
- RDMA/hns: Fix different dgids mapping to the same dip_idx
- RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
- rust: kernel: add srctree-relative doclinks
- rust: kernel: fix THIS_MODULE header path in ThisModule doc comment
- i3c: master: Remove i3c_dev_disable_ibi_locked(olddev) on device hotjoin
- remoteproc: qcom: pas: Remove subdevs on the error path of adsp_probe()
- remoteproc: qcom: adsp: Remove subdevs on the error path of adsp_probe()
- nfsd: Revert "nfsd: release svc_expkey/svc_export with rcu_work"
- f2fs: clean up val{>>,<<}F2FS_BLKSIZE_BITS
- f2fs: fix to do cast in F2FS_{BLK_TO_BYTES, BTYES_TO_BLK} to avoid overflow
- vfio/mlx5: Fix unwind flows in mlx5vf_pci_save/resume_device_data()
- exfat: fix file being changed by unaligned direct write
- bnxt_en: Set backplane link modes correctly for ethtool
- devres: Fix page faults when tracing devres from unloaded modules
- usb: gadget: uvc: wake pump everytime we update the free list
- drm/xe/ufence: Wake up waiters after setting ufence->signalled
- net_sched: sch_fq: don't follow the fast path if Tx is behind now
- ASoC: da7213: Populate max_register to regmap_config
- KVM: x86: switch hugepage recovery thread to vhost_task
- kvm: defer huge page recovery vhost task to later
- KVM: x86/mmu: Ensure NX huge page recovery thread is alive before waking
- KVM: arm64: Change kvm_handle_mmio_return() return polarity
- dt-bindings: pinctrl: samsung: Fix interrupt constraint for variants with
fallbacks
- xhci: Fix control transfer error on Etron xHCI host
- xhci: Combine two if statements for Etron xHCI host
- xhci: Don't perform Soft Retry for Etron xHCI host
- xhci: Don't issue Reset Device command to Etron xHCI host
- mtd: spi-nor: core: replace dummy buswidth from addr to data
- Revert "mtd: spi-nor: core: replace dummy buswidth from addr to data"
- RISC-V: Scalar unaligned access emulated on hotplug CPUs
- serial: amba-pl011: Fix RX stall when DMA is used
- serial: amba-pl011: fix build regression
- i40e: Fix handling changed priv flags
- netdev-genl: Hold rcu_read_lock in napi_get
- usb: misc: ljca: set small runtime autosuspend delay
- usb: misc: ljca: move usb_autopm_put_interface() after wait for response
- blk-mq: add non_owner variant of start_freeze/unfreeze queue APIs
- block: model freeze & enter queue as lock for supporting lockdep
- block: always verify unfreeze lock on the owner task
- x86/Documentation: Update algo in init_size description of boot protocol
- kbuild: deb-pkg: Don't fail if modules.order is missing
- tools/power turbostat: Fix trailing '\n' parsing
- block: don't verify IO lock for freeze/unfreeze in elevator_init_mq()
- zram: permit only one post-processing operation at a time
- perf jevents: Don't stop at the first matched pmu when searching a events
table
- docs: media: update location of the media patches
- Revert "KVM: VMX: Move LOAD_IA32_PERF_GLOBAL_CTRL errata handling out of
setup_vmcs_config()"
- soc: fsl: cpm1: qmc: Fix blank line and spaces
- soc: fsl: cpm1: qmc: Re-order probe() operations
- soc: fsl: cpm1: qmc: Introduce qmc_init_resource() and its CPM1 version
- soc: fsl: cpm1: qmc: Introduce qmc_{init,exit}_xcc() and their CPM1 version
- soc: fsl: cpm1: qmc: Set the ret error code on platform_get_irq() failure
- x86/mm: Carve out INVLPG inline asm for use by others
- ALSA: hda/realtek: Enable mic on Vaio VJFH52
- ALSA: hda/realtek: Enable speaker pins for Medion E15443 platform
- ALSA: hda/realtek: fix mute/micmute LEDs don't work for EliteBook X G1i
- usb: dwc3: gadget: Add missing check for single port RAM in TxFIFO resizing
logic
- sched: Initialize idle tasks only once
- Upstream stable to v6.6.64, v6.11.11, v6.12.1, v6.12.2, v6.12.3
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53222
- zram: fix NULL pointer in comp_algorithm_show()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53169
- nvme-fabrics: fix kernel crash while shutting down controller
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56721
- x86/CPU/AMD: Terminate the erratum_1386_microcode array
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53187
- io_uring: check for overflows in io_pin_pages
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53147
- exfat: fix out-of-bounds access of directory entries
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53196
- KVM: arm64: Don't retire aborted MMIO instruction
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56685
- ASoC: mediatek: Check num_codecs is not zero to avoid panic during probe
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53201
- drm/amd/display: Fix null check for pipe_ctx->plane_state in
dcn20_program_pipe
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53203
- usb: typec: fix potential array underflow in ucsi_ccg_sync_control()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53209
- bnxt_en: Fix receive ring space parameters when XDP is active
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56742
- vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53216
- nfsd: release svc_expkey/svc_export with rcu_work
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53219
- virtiofs: use pages instead of pointer for kernel direct IO
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53221
- f2fs: fix null-ptr-deref in f2fs_submit_page_bio()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53228
- riscv: kvm: Fix out-of-bounds array access
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53232
- iommu/s390: Implement blocking domain
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53236
- xsk: Free skb when TX metadata options are invalid
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56703
- ipv6: Fix soft lockups in fib6_select_path under high next hop churn
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56540
- accel/ivpu: Prevent recovery invocation during probe and resume
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53163
- crypto: qat/qat_420xx - fix off by one in uof_get_name()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56755
- netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56549
- cachefiles: Fix NULL pointer dereference in object->file
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56551
- drm/amdgpu: fix usage slab after free
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56776
- drm/sti: avoid potential dereference of error pointers
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56777
- drm/sti: avoid potential dereference of error pointers in
sti_gdp_atomic_check
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56778
- drm/sti: avoid potential dereference of error pointers in
sti_hqvdp_atomic_check
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56557
- iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56779
- nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56558
- nfsd: make sure exp active before svc_export_show
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56562
- i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56566
- mm/slub: Avoid list corruption when removing a slab from the full list
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-57838
- s390/entry: Mark IRQ entries to fix stack depot warnings
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56567
- ad7780: fix division by zero in ad7780_write_raw()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56569
- ftrace: Fix regression with module command in stack_trace_filter
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56570
- ovl: Filter invalid inodes with missing lookup function
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56572
- media: platform: allegro-dvt: Fix possible memory leak in
allocate_buffers_internal()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56573
- efi/libstub: Free correct pointer on failure
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56574
- media: ts2020: fix null-ptr-deref in ts2020_probe()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56575
- media: imx-jpeg: Ensure power suppliers be suspended before detach them
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56576
- media: i2c: tc358743: Fix crash in the probe error path when using polling
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56577
- media: mtk-jpeg: Fix null-ptr-deref during unload module
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56578
- media: imx-jpeg: Set video drvdata before register video device
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56579
- media: amphion: Set video drvdata before register video device
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56581
- btrfs: ref-verify: fix use-after-free after invalid ref action
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56774
- btrfs: add a sanity check for btrfs root in btrfs_search_slot()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56780
- quota: flush quota_release_work upon quota writeback
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53168
- sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56688
- sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56729
- smb: Initialize cfid->tcon before performing network ops
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56704
- 9p/xen: fix release of IRQ
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53171
- ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53172
- ubi: fastmap: Fix duplicate slab cache names while attaching
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56739
- rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53173
- NFSv4.0: Fix a use-after-free problem in the asynchronous open()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53145
- um: Fix potential integer overflow during physmem setup
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53174
- SUNRPC: make sure cache entry active before cache_show
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53146
- NFSD: Prevent a potential integer overflow
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53175
- ipc: fix memleak if msg_init_ns failed in create_ipc_ns
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56692
- f2fs: fix to do sanity check on node blkaddr in truncate_node()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56698
- usb: dwc3: gadget: Fix looping of queued SG entries
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56687
- usb: musb: Fix hardware lockup on first Rx endpoint request
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53176
- smb: During unmount, ensure all cached dir instances drop their dentry
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53177
- smb: prevent use-after-free due to open_cached_dir error paths
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53178
- smb: Don't leak cfid when reconnect races with open_cached_dir
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53180
- ALSA: pcm: Add sanity NULL check for the default mmap fault handler
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56700
- media: wl128x: Fix atomicity violation in fmc_send_cmd()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2022-49034
- sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53181
- um: vector: Do not use drvdata in release
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53183
- um: net: Do not use drvdata in release
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53184
- um: ubd: Do not use drvdata in release
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53185
- smb: client: fix NULL ptr deref in crypto_aead_setkey()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53188
- wifi: ath12k: fix crash when unbinding
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53190
- wifi: rtlwifi: Drastically reduce the attempts to read efuse in case of
failures
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53191
- wifi: ath12k: fix warning when unbinding
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56741
- apparmor: test: Fix memory leak for aa_unpack_strdup()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53148
- comedi: Flush partial mappings in error case
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53194
- PCI: Fix use-after-free of slot->bus on hot remove
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53195
- KVM: arm64: Get rid of userspace_irqchip_in_use
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53197
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox
devices
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-42122
- drm/amd/display: Add NULL pointer check for kzalloc
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-49906
- drm/amd/display: Check null pointer before try to access it
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53150
- ALSA: usb-audio: Fix out of bounds reads when finding clock sources
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53198
- xen: Fix the issue of resource not being properly released in
xenbus_dev_probe()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-41014
- xfs: add bounds checking to xlog_recover_process_data
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53200
- drm/amd/display: Fix null check for pipe_ctx->plane_state in hwss_setup_dpp
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53202
- firmware_loader: Fix possible resource leak in fw_log_firmware_info()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53208
- Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53210
- s390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53213
- net: usb: lan78xx: Fix double free issue with interrupt buffer allocation
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53214
- vfio/pci: Properly hide first-in-list PCIe extended capability
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53215
- svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53217
- NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56689
- PCI: endpoint: epf-mhi: Avoid NULL dereference if DT lacks 'mmio'
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53151
- svcrdma: Address an integer overflow
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53218
- f2fs: fix race in concurrent f2fs_stop_gc_thread
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56744
- f2fs: fix to avoid potential deadlock in f2fs_record_stop_reason()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53220
- f2fs: fix to account dirty data in __get_secs_required()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56745
- PCI: Fix reset_method_store() memory leak
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53223
- clk: ralink: mtmips: fix clocks probe order in oldest ralink SoCs
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53154
- clk: clk-apple-nco: Add NULL check in applnco_probe
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53224
- RDMA/mlx5: Move events notifier registration to be after device registration
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56746
- fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53155
- ocfs2: fix uninitialized value in ocfs2_file_read_iter()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53226
- RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56747
- scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56748
- scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53229
- RDMA/rxe: Fix the qp flush warnings in req
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56722
- RDMA/hns: Fix cpu stuck caused by printings during reset
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53230
- cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53231
- cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56701
- powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56678
- powerpc/mm/fault: Fix kfence page fault reporting
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56677
- powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56723
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56724
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56691
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53233
- unicode: Fix utf8_load() error path
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56694
- bpf: fix recursive lock when verdict program return SK_PASS
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53234
- erofs: handle NONHEAD !delta[1] lclusters gracefully
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53239
- ALSA: 6fire: Release resources at card release
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56531
- ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56532
- ALSA: us122l: Use snd_card_free_when_closed() at disconnection
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56533
- ALSA: usx2y: Use snd_card_free_when_closed() at disconnection
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56751
- ipv6: release nexthop on device removal
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56720
- bpf, sockmap: Several fixes to bpf_msg_pop_data
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56538
- drm: zynqmp_kms: Unplug DRM device before removal
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56752
- drm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56725
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56707
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56726
- octeontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56727
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56728
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_ethtool.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56679
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_common.c
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56539
- wifi: mwifiex: Fix memcpy() field-spanning write warning in
mwifiex_config_scan()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56543
- wifi: ath12k: Skip Rx TID cleanup for self peer
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56683
- drm/vc4: hdmi: Avoid hang with debug registers when suspended
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56545
- HID: hyperv: streamline driver probe to avoid devres issues
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56705
- media: atomisp: Add check for rgby_data memory allocation failure
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53157
- firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53158
- soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56546
- drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56681
- crypto: bcm - add error check in the ahash_hmac_init function
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53160
- rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56708
- EDAC/igen6: Avoid segmentation fault on module unload
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56690
- crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return
-EBUSY
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53161
- EDAC/bluefield: Fix potential integer overflow
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53162
- crypto: qat/qat_4xxx - fix off by one in uof_get_name()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56754
- crypto: caam - Fix the pointer passed to caam_qi_shutdown()
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56548
- hfsplus: don't query the device logical block size multiple times
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56756
- nvme-pci: fix freeing of the HMB descriptor table
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-53142
- initramfs: avoid filename buffer overrun
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-56693
- brd: defer automatic disk creation until module initialization succeeds
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-44955
- drm/amd/display: Don't refer to dc_sink in is_dsc_need_re_compute
* Noble update: upstream stable patchset 2025-03-11 (LP: #2101915) //
CVE-2024-49899
- drm/amd/display: Initialize denominators' default to 1
* Noble update: upstream stable patchset 2025-03-06 (LP: #2101042)
- sctp: fix possible UAF in sctp_v6_available()
- net: vertexcom: mse102x: Fix tx_bytes calculation
- drm/rockchip: vop: Fix a dereferenced before check warning
- mptcp: error out earlier on disconnect
- mptcp: cope racing subflow creation in mptcp_rcv_space_adjust
- net/mlx5: fs, lock FTE when checking if active
- net/mlx5e: kTLS, Fix incorrect page refcounting
- net/mlx5e: clear xdp features on non-uplink representors
- net/mlx5e: CT: Fix null-ptr-deref in add rule err flow
- virtio/vsock: Fix accept_queue memory leak
- Bluetooth: btintel: Direct exception event to bluetooth stack
- net: sched: cls_u32: Fix u32's systematic failure to free IDR entries for
hnodes.
- samples: pktgen: correct dev to DEV
- net: stmmac: dwmac-mediatek: Fix inverted handling of mediatek,mac-wol
- net: Make copy_safe_from_sockptr() match documentation
- stmmac: dwmac-intel-plat: fix call balance of tx_clk handling routines
- net: ti: icssg-prueth: Fix 1 PPS sync
- bonding: add ns target multicast address to slave device
- ARM: 9419/1: mm: Fix kernel memory mapping for xip kernels
- x86/mm: Fix a kdump kernel failure on SME system when CONFIG_IMA_KEXEC=y
- mm: fix NULL pointer dereference in alloc_pages_bulk_noprof
- ocfs2: uncache inode which has failed entering the group
- vdpa: solidrun: Fix UB bug with devres
- vdpa/mlx5: Fix PA offset with unaligned starting iotlb map
- vp_vdpa: fix id_table array not null terminated error
- ima: fix buffer overrun in ima_eventdigest_init_common
- KVM: nVMX: Treat vpid01 as current if L2 is active, but with VPID disabled
- KVM: x86: Unconditionally set irr_pending when updating APICv state
- KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind
CONFIG_BROKEN
- nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
- nommu: pass NULL argument to vma_iter_prealloc()
- ALSA: hda/realtek - Fixed Clevo platform headset Mic issue
- ocfs2: fix UBSAN warning in ocfs2_verify_volume()
- nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
- LoongArch: Fix early_numa_add_cpu() usage for FDT systems
- LoongArch: Disable KASAN if PGDIR_SIZE is too large for cpu_vabits
- LoongArch: Make KASAN work with 5-level page-tables
- Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
- mmc: sunxi-mmc: Fix A100 compatible description
- drm/bridge: tc358768: Fix DSI command tx
- pmdomain: imx93-blk-ctrl: correct remove path
- nouveau: fw: sync dma after setup is called.
- drm/amd: Fix initialization mistake for NBIO 7.7.0
- drm/amd/display: Adjust VSDB parser for replay feature
- lib/buildid: Fix build ID parsing logic
- media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set
- mptcp: add userspace_pm_lookup_addr_by_id helper
- mptcp: update local address flags when setting it
- mptcp: hold pm lock when deleting entry
- mptcp: drop lookup_by_id in lookup_addr
- mptcp: pm: use _rcu variant under rcu_read_lock
- mm: avoid unsafe VMA hook invocation when error arises on mmap hook
- mm: unconditionally close VMAs on error
- mm: refactor map_deny_write_exec()
- mm: refactor arch_calc_vm_flag_bits() and arm64 MTE handling
- mm: resolve faulty mmap_region() error path behaviour
- net/mlx5: Fix msix vectors to respect platform limit
- vsock: Fix sk_error_queue memory leak
- virtio/vsock: Improve MSG_ZEROCOPY error handling
- net: phylink: ensure PHY momentary link-fails are handled
- drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle
- ARM: fix cacheflush with PAN
- drm/amd/display: Run idle optimizations at end of vblank handler
- drm/amd/display: Change some variable name of psr
- x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client
- x86/stackprotector: Work around strict Clang TLS symbol requirements
- sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers
- fs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()
- mm/mremap: fix address wraparound in move_page_tables()
- KVM: selftests: Disable strict aliasing
- mm: page_alloc: move mlocked flag clearance into free_pages_prepare()
- LoongArch: Add WriteCombine shadow mapping in KASAN
- drm/xe: handle flat ccs during hibernation on igpu
- pmdomain: arm: Use FLAG_DEV_NAME_FW to ensure unique names
- pmdomain: core: Add GENPD_FLAG_DEV_NAME_FW flag
- nouveau: handle EBUSY and EAGAIN for GSP aux errors.
- nouveau/dp: handle retries for AUX CH transfers with GSP.
- drm/amdgpu: fix check in gmc_v9_0_get_vm_pte()
- drm/amdgpu: Fix video caps for H264 and HEVC encode maximum size
- drm/amd/pm: print pp_dpm_mclk in ascending order on SMU v14.0.0
- drm/amd/display: Handle dml allocation failure to avoid crash
- drm/amd/display: Fix failure to read vram info due to static BP_RESULT
- drm/xe: Restore system memory GGTT mappings
- drm/xe: improve hibernation on igpu
- net: sched: u32: Add test case for systematic hnode IDR leaks
- Upstream stable to v6.6.63, v6.11.10
* Noble update: upstream stable patchset 2025-03-04 (LP: #2100894)
- 9p: v9fs_fid_find: also lookup by inode if not found dentry
- 9p: Avoid creating multiple slab caches with the same name
- selftests/bpf: Verify that sync_linked_regs preserves subreg_def
- irqchip/ocelot: Fix trigger register address
- nvme: tcp: avoid race between queue_lock lock and destroy
- block: Fix elevator_get_default() checking for NULL q->tag_set
- HID: multitouch: Add support for B2402FVA track point
- HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
- iommu/arm-smmu: Clarify MMU-500 CPRE workaround
- nvme: disable CC.CRIME (NVME_CC_CRIME)
- bpf: use kvzmalloc to allocate BPF verifier environment
- crypto: api - Fix liveliness check in crypto_alg_tested
- crypto: marvell/cesa - Disable hash algorithms
- sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
- drm/vmwgfx: Limit display layout ioctl array size to
VMWGFX_NUM_DISPLAY_UNITS
- RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
- nvme-multipath: defer partition scanning
- drm/amdkfd: Accounting pdd vram_usage for svm
- powerpc/powernv: Free name on error in opal_event_init()
- net: phy: mdio-bcm-unimac: Add BCM6846 support
- nvme-loop: flush off pending I/O while shutting down loop controller
- smb: client: Fix use-after-free of network namespace.
- nvme/host: Fix RCU list traversal to use SRCU primitive
- vDPA/ifcvf: Fix pci_read_config_byte() return code handling
- bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx
- bpf: Fix mismatched RCU unlock flavour in bpf_out_neigh_v6
- ASoC: amd: yc: Add quirk for ASUS Vivobook S15 M3502RA
- ASoC: amd: yc: Fix non-functional mic on ASUS E1404FA
- fs: Fix uninitialized value issue in from_kuid and from_kgid
- HID: multitouch: Add quirk for Logitech Bolt receiver w/ Casa touchpad
- HID: lenovo: Add support for Thinkpad X1 Tablet Gen 3 keyboard
- RISCV: KVM: use raw_spinlock for critical section in imsic
- ASoC: rt722-sdca: increase clk_stop_timeout to fix clock stop issue
- LoongArch: Use "Exception return address" to comment ERA
- ASoC: fsl_micfil: Add sample rate constraint
- net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
- bpf: Check validity of link->type in bpf_link_show_fdinfo()
- mm: support order-1 folios in the page cache
- mm: always initialise folio->_deferred_list
- mm: refactor folio_undo_large_rmappable()
- mm/thp: fix deferred split unqueue naming and locking
- 9p: fix slab cache name creation for real
- nvmet-passthru: clear EUID/NGUID/UUID while using loop target
- pinctrl: intel: platform: Add Panther Lake to the list of supported
- s390/ap: Fix CCA crypto card behavior within protected execution environment
- selftests/bpf: Assert link info uprobe_multi count & path_size if unset
- ALSA: hda/tas2781: Add new quirk for Lenovo, ASUS, Dell projects
- drm/xe/query: Increase timestamp width
- nvme: make keep-alive synchronous operation
- samples/landlock: Fix port parsing in sandboxer
- ASoC: Intel: avs: Update stream status in a separate thread
- ASoC: codecs: Fix error handling in aw_dev_get_dsp_status function
- netfs: Downgrade i_rwsem for a buffered write
- afs: Fix lock recursion
- HID: i2c-hid: Delayed i2c resume wakeup for 0x0d42 Goodix touchpad
- LoongArch: KVM: Mark hrtimer to expire in hard interrupt context
- drm/xe: Don't restart parallel queues multiple times on GT reset
- Upstream stable to v6.6.62, v6.11.9
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292)
- arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-eaidk-610
- arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-
excavator
- arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328
- arm64: dts: rockchip: Fix wakeup prop names on PineNote BT node
- arm64: dts: rockchip: Fix reset-gpios property on brcm BT nodes
- arm64: dts: rockchip: fix i2c2 pinctrl-names property on anbernic-rg353p/v
- arm64: dts: rockchip: Fix bluetooth properties on rk3566 box demo
- arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards
- arm64: dts: rockchip: Add DTS for FriendlyARM NanoPi R2S Plus
- arm64: dts: rockchip: Remove undocumented supports-emmc property
- arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion
- arm64: dts: rockchip: Fix LED triggers on rk3308-roc-cc
- arm64: dts: rockchip: remove num-slots property from rk3328-nanopi-r2s-plus
- arm64: dts: imx8-ss-vpu: Fix imx8qm VPU IRQs
- arm64: dts: imx8mp: correct sdhc ipg clk
- arm64: dts: rockchip: remove orphaned pinctrl-names from pinephone pro
- ARM: dts: rockchip: fix rk3036 acodec node
- ARM: dts: rockchip: drop grf reference from rk3036 hdmi
- ARM: dts: rockchip: Fix the spi controller on rk3036
- ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
- arm64: dts: rockchip: Correct GPIO polarity on brcm BT nodes
- sunrpc: handle -ENOTCONN in xs_tcp_setup_socket()
- NFSv3: only use NFS timeout for MOUNT when protocols are compatible
- nfs: avoid i_lock contention in nfs_clear_invalid_mapping
- net: enetc: set MAC address to the VF net_device
- dt-bindings: net: xlnx,axi-ethernet: Correct phy-mode property value
- can: c_can: fix {rx,tx}_errors statistics
- can: c_can: c_can_handle_bus_err(): update statistics if skb allocation
fails
- ice: change q_index variable type to s16 to store -1 value
- e1000e: Remove Meteor Lake SMBUS workarounds
- net: phy: ti: add PHY_RST_AFTER_CLK_EN flag
- net: stmmac: Fix unbalanced IRQ wake disable warning on single irq case
- netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx
- netfilter: nf_tables: wait for rcu grace period on net_device removal
- netfilter: nf_tables: do not defer rule destruction via call_rcu
- net: arc: rockchip: fix emac mdio node support
- drivers: net: ionic: add missed debugfs cleanup to ionic_probe() error path
- Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown"
- media: stb0899_algo: initialize cfr before using it
- media: dvb_frontend: don't play tricks with underflow values
- media: adv7604: prevent underflow condition when reporting colorspace
- scsi: sd_zbc: Use kvzalloc() to allocate REPORT ZONES buffer
- ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
- tools/lib/thermal: Fix sampling handler context ptr
- thermal/of: support thermal zones w/o trips subnode
- ASoC: SOF: sof-client-probes-ipc4: Set param_size extension bits
- media: pulse8-cec: fix data timestamp at pulse8_setup()
- media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl()
- can: m_can: m_can_close(): don't call free_irq() for IRQ-less devices
- can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation
- can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing configuration when
switching CAN modes
- ksmbd: count all requests in req_running counter
- ksmbd: fix broken transfers when exceeding max simultaneous operations
- pwm: imx-tpm: Use correct MODULO value for EPWM mode
- rpmsg: glink: Handle rejected intent request better
- drm/amdgpu: Adjust debugfs eviction and IB access permissions
- drm/amdgpu: Adjust debugfs register access permissions
- drm/amdgpu: Fix DPX valid mode check on GC 9.4.3
- thermal/drivers/qcom/lmh: Remove false lockdep backtrace
- dm cache: correct the number of origin blocks to match the target length
- dm cache: optimize dirty bit checking with find_next_bit when resizing
- dm-unstriped: cast an operand to sector_t to prevent potential uint32_t
overflow
- ALSA: usb-audio: Add quirk for HP 320 FHD Webcam
- net: wwan: t7xx: Fix off-by-one error in t7xx_dpmaif_rx_buf_alloc()
- mptcp: use sock_kfree_s instead of kfree
- arm64: Kconfig: Make SME depend on BROKEN for now
- [Config] updateconfigs for ARM64_SME
- arm64: smccc: Remove broken support for SMCCCv1.3 SVE discard hint
- Revert "wifi: mac80211: fix RCU list iterations"
- i2c: designware: do not hold SCL low when I2C_DYNAMIC_TAR_UPDATE is not set
- fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
- usb: dwc3: fix fault at system suspend if device was already runtime
suspended
- USB: serial: qcserial: add support for Sierra Wireless EM86xx
- USB: serial: option: add Fibocom FG132 0x0112 composition
- USB: serial: option: add Quectel RG650V
- irqchip/gic-v3: Force propagation of the active state with a read-back
- ucounts: fix counter leak in inc_rlimit_get_ucounts()
- ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022
- arm64: dts: rockchip: Designate Turing RK1's system power controller
- EDAC/qcom: Make irq configuration optional
- arm64: dts: rockchip: Drop regulator-init-microvolt from two boards
- net: dpaa_eth: print FD status in CPU endianness in dpaa_eth_fd tracepoint
- virtio_net: Sync rss config to device when virtnet_probe
- drm/xe: Set mask bits for CCS_MODE register
- drm/amd/display: Fix brightness level not retained over reboot
- drm/imagination: Add a per-file PVR context list
- mptcp: no admin perm to list endpoints
- btrfs: fix the length of reserved qgroup to free
- btrfs: fix per-subvolume RO/RW flags with new mount API
- clk: qcom: gcc-x1e80100: Fix USB MP SS1 PHY GDSC pwrsts flags
- clk: qcom: clk-alpha-pll: Fix pll post div mask when width is not set
- objpool: fix to make percpu slot allocation more robust
- mm/damon/core: handle zero {aggregation,ops_update} intervals
- mm/damon/core: handle zero schemes apply interval
- mm/mlock: set the correct prev on failure
- clk: qcom: gcc-x1e80100: Fix halt_check for pipediv2 clocks
- staging: vchiq_arm: Get the rid off struct vchiq_2835_state
- staging: vchiq_arm: Use devm_kzalloc() for vchiq_arm_state allocation
- drm/xe/guc/ct: Flush g2h worker in case of g2h response timeout
- drm/xe: Move LNL scheduling WA to xe_device.h
- drm/xe/ufence: Flush xe ordered_wq in case of ufence timeout
- drm/xe/guc/tlb: Flush g2h worker in case of tlb timeout
- xtensa: Emulate one-byte cmpxchg
- Upstream stable to v6.6.61, v6.11.8
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50270
- mm/damon/core: avoid overflow in damon_feed_loop_next_input()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50274
- idpf: avoid vport access in idpf_get_link_ksettings
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53067
- scsi: ufs: core: Start the RTC update work later
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53084
- drm/imagination: Break an object reference loop
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53085
- tpm: Lock TPM chip in tpm_pm_suspend() first
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53086
- drm/xe: Drop VM dma-resv lock on xe_sync_in_fence_get failure in exec IOCTL
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53087
- drm/xe: Fix possible exec queue leak in exec IOCTL
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50288
- media: vivid: fix buffer overwrite when using > 32 buffers
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50289
- media: av7110: fix a spectre vulnerability
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53062
- media: mgb4: protect driver against spectre
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50291
- media: dvb-core: add missing buffer index check
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50297
- net: xilinx: axienet: Enqueue Tx packets in dql before dmaengine starts
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50267
- USB: serial: io_edgeport: fix use after free in debug printk
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50268
- usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53083
- usb: typec: qcom-pmic: init value of hdr_len/txbuf_len earlier
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50269
- usb: musb: sunxi: Fix accessing an released usb phy
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50271
- signal: restore the override_rlimit logic
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50272
- filemap: Fix bounds checking in filemap_read()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50273
- btrfs: reinitialize delayed ref list after deleting it from the list
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50275
- arm64/sve: Discard stale CPU state when handling SVE traps
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50276
- net: vertexcom: mse102x: Fix possible double free of TX skb
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53066
- nfs: Fix KMSAN warning in decode_getfattr_attrs()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50278
- dm cache: fix potential out-of-bounds access on the first resume
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50279
- dm cache: fix out-of-bounds access to the dirty bitset when resizing
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50280
- dm cache: fix flushing uninitialized delayed_work on cache_ctr error
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53060
- drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50282
- drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50283
- ksmbd: fix slab-use-after-free in smb3_preauth_hash_rsp
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50284
- ksmbd: Fix the missing xa_store error check
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50285
- ksmbd: check outstanding simultaneous SMB operations
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50286
- ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50287
- media: v4l2-tpg: prevent the risk of a division by zero
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50290
- media: cx24116: prevent overflows on SNR calculus
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53061
- media: s5p-jpeg: prevent buffer overflows
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53081
- media: ar0521: don't overflow when checking PLL values
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50292
- ASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50294
- rxrpc: Fix missing locking causing hanging calls
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50295
- net: arc: fix the device for dma_map_single/dma_unmap_single
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53082
- virtio_net: Add hash_key_length check
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50296
- net: hns3: fix kernel crash when uninstalling driver
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53088
- i40e: fix race condition by adding filter's intermediate sync state
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50298
- net: enetc: allocate vf_state during PF probes
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50299
- sctp: properly validate chunk size in sctp_sf_ootb()
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50300
- regulator: rtq2208: Fix uninitialized use of regulator_config
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-50301
- security/keys: fix slab-out-of-bounds in key_task_permission
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53072
- platform/x86/amd/pmc: Detect when STB is not available
* Noble update: upstream stable patchset 2025-02-27 (LP: #2100292) //
CVE-2024-53068
- firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996)
- Input: xpad - sort xpad_device by vendor and product ID
- Input: xpad - add support for 8BitDo Ultimate 2C Wireless Controller
- cgroup: Fix potential overflow issue when checking max_depth
- spi: geni-qcom: Fix boot warning related to pm_runtime and devres
- wifi: iwlegacy: Fix "field-spanning write" warning in il_enqueue_hcmd()
- mac80211: MAC80211_MESSAGE_TRACING should depend on TRACING
- wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
- wifi: ath11k: Fix invalid ring usage in full monitor mode
- wifi: brcm80211: BRCM_TRACING should depend on TRACING
- RDMA/cxgb4: Dump vendor specific QP details
- RDMA/mlx5: Round max_rd_atomic/max_dest_rd_atomic up instead of down
- RDMA/bnxt_re: Fix the usage of control path spin locks
- RDMA/bnxt_re: synchronize the qp-handle table array
- RDMA/bnxt_re: Fix the locking while accessing the QP table
- wifi: iwlwifi: mvm: disconnect station vifs if recovery failed
- wifi: iwlwifi: mvm: don't add default link in fw restart flow
- ASoC: cs42l51: Fix some error handling paths in cs42l51_probe()
- net: stmmac: dwmac4: Fix high address display by updating reg_space[] from
register values
- net: stmmac: fix TSO DMA API usage causing oops
- gtp: allow -1 to be specified as file description from userspace
- bpf: Force checkpoint when jmp history is too long
- net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension
- net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
- mlxsw: spectrum_ptp: Add missing verification before pushing Tx header
- bpf, test_run: Fix LIVE_FRAME frame update after a page has been recycled
- iomap: improve shared block detection in iomap_unshare_iter
- iomap: don't bother unsharing delalloc extents
- iomap: share iomap_unshare_iter predicate code with fsdax
- fsdax: remove zeroing code from dax_unshare_iter
- iomap: turn iomap_want_unshare_iter into an inline function
- kasan: Fix Software Tag-Based KASAN with GCC
- firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()
- afs: Fix missing subdir edit when renamed between parent dirs
- smb: client: set correct device number on nfs reparse points
- cxl/events: Fix Trace DRAM Event Record
- fs/ntfs3: Fix warning possible deadlock in ntfs_set_state
- fs/ntfs3: Stale inode instead of bad
- scsi: scsi_transport_fc: Allow setting rport state to current state
- cifs: Fix creating native symlinks pointing to current or parent directory
- thermal: intel: int340x: processor: Remove MMIO RAPL CPU hotplug support
- thermal: intel: int340x: processor: Add MMIO RAPL PL4 support
- net: amd: mvme147: Fix probe banner message
- NFS: remove revoked delegation from server's delegation list
- misc: sgi-gru: Don't disable preemption in GRU driver
- usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler
- usb: gadget: dummy_hcd: Set transfer interval to 1 microframe
- usb: gadget: dummy_hcd: execute hrtimer callback in softirq context
- USB: gadget: dummy-hcd: Fix "task hung" problem
- ALSA: usb-audio: Add quirks for Dell WD19 dock
- usbip: tools: Fix detach_port() invalid port error path
- usb: phy: Fix API devm_usb_put_phy() can not release the phy
- usb: typec: fix unreleased fwnode_handle in typec_port_register_altmodes()
- usb: typec: qcom-pmic-typec: use fwnode_handle_put() to release fwnodes
- xhci: Fix Link TRB DMA in command ring stopped completion event
- xhci: Use pm_runtime_get to prevent RPM on unsupported systems
- Revert "driver core: Fix uevent_show() vs driver detach race"
- iio: light: veml6030: fix microlux value calculation
- RISC-V: ACPI: fix early_ioremap to early_memremap
- tools/mm: -Werror fixes in page-types/slabinfo
- tools/mm: fix compile error
- thunderbolt: Honor TMU requirements in the domain when setting TMU mode
- mmc: sdhci-pci-gli: GL9767: Fix low power mode on the set clock function
- mmc: sdhci-pci-gli: GL9767: Fix low power mode in the SD Express process
- block: fix sanity checks in blk_rq_map_user_bvec
- cgroup/bpf: use a dedicated workqueue for cgroup bpf destruction
- phy: freescale: imx8m-pcie: Do CMN_RST just before PHY PLL lock check
- riscv: vdso: Prevent the compiler from inserting calls to memset()
- Input: edt-ft5x06 - fix regmap leak when probe fails
- ALSA: hda/realtek: Limit internal Mic boost on Dell platform
- riscv: efi: Set NX compat flag in PE/COFF header
- riscv: Use '%u' to format the output of 'cpu'
- riscv: Remove unused GENERATING_ASM_OFFSETS
- riscv: Remove duplicated GET_RM
- cxl/port: Fix cxl_bus_rescan() vs bus_rescan_devices()
- cxl/acpi: Ensure ports ready at cxl_acpi_probe() return
- mei: use kvmalloc for read buffer
- mm/page_alloc: let GFP_ATOMIC order-0 allocs access highatomic reserves
- x86/traps: Enable UBSAN traps on x86
- x86/traps: move kmsan check after instrumentation_begin
- kasan: remove vmalloc_percpu test
- vmscan,migrate: fix page count imbalance on node stats when demoting pages
- io_uring: always lock __io_cqring_overflow_flush
- mm: huge_memory: add vma_thp_disabled() and thp_disabled_by_hw()
- mm: don't install PMD mappings when THPs are disabled by the hw/process/vma
- perf trace: Fix non-listed archs in the syscalltbl routines
- dpll: add Embedded SYNC feature for a pin
- ice: add callbacks for Embedded SYNC enablement on dpll pins
- bpf: Add bpf_mem_alloc_check_size() helper
- net: ethernet: mtk_wed: fix path of MT7988 WO firmware
- drm/mediatek: ovl: Remove the color format comment for ovl_fmt_convert()
- drm/mediatek: Fix get efuse issue for MT8188 DPTX
- ACPI: resource: Fold Asus Vivobook Pro N6506M* DMI quirks together
- powercap: intel_rapl_msr: Add PL4 support for Arrowlake-U
- usb: typec: qcom-pmic-typec: fix missing fwnode removal in error path
- mm: shrinker: avoid memleak in alloc_shrinker_info
- firmware: microchip: auto-update: fix poll_complete() to not report spurious
timeout errors
- soc: qcom: pmic_glink: Handle GLINK intent allocation rejections
- cxl/port: Fix CXL port initialization order when the subsystem is built-in
- btrfs: merge btrfs_orig_bbio_end_io() into btrfs_bio_end_io()
- posix-cpu-timers: Clear TICK_DEP_BIT_POSIX_TIMER on clone
- mm/ksm: remove redundant code in ksm_fork
- nvme: re-fix error-handling for io_uring nvme-passthrough
- btrfs: fix extent map merging not happening for adjacent extents
- btrfs: fix defrag not merging contiguous extents due to merged extent maps
- mm, mmap: limit THP alignment of anonymous mappings to PMD-aligned sizes
- mm: multi-gen LRU: ignore non-leaf pmd_young for force_scan=true
- mm: multi-gen LRU: remove MM_LEAF_OLD and MM_NONLEAF_TOTAL stats
- mm: shrink skip folio mapped by an exiting process
- mm: multi-gen LRU: use {ptep,pmdp}_clear_young_notify()
- drm/i915: Skip programming FIA link enable bits for MTL+
- drm/i915/display: WA for Re-initialize dispcnlunitt1 xosc clock
- drm/i915/dp: Clear VSC SDP during post ddi disable routine
- drm/i915/pps: Disable DPLS_GATING around pps sequence
- drm/i915: move rawclk from runtime to display runtime info
- drm/xe/display: drop unused rawclk_freq and RUNTIME_INFO()
- drm/xe: Support 'nomodeset' kernel command-line option
- drm/xe/xe2hpg: Introduce performance tuning changes for Xe2_HPG
- drm/amdgpu/swsmu: fix ordering for setting workload_mask
- drm/amdgpu/swsmu: default to fullscreen 3D profile for dGPUs
- drm/amdgpu: handle default profile on on devices without fullscreen 3D
- MIPS: export __cmpxchg_small()
- rcu/kvfree: Add kvfree_rcu_barrier() API
- rcu/kvfree: Refactor kvfree_rcu_queue_batch()
- Upstream stable to v6.6.60, v6.11.7
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53050
- drm/i915/hdcp: Add encoder check in hdcp2_get_capability
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53051
- drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50303
- resource,kexec: walk_system_ram_res_rev must retain resource flags
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50263
- fork: only invoke khugepaged, ksm hooks if no error
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50220
- fork: do not invoke uffd on fork if error occurs
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50221
- drm/amd/pm: Vangogh: Fix kernel memory out of bounds write
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53053
- scsi: ufs: core: Fix another deadlock during RTC update
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50225
- btrfs: fix error propagation of split bios
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50230
- nilfs2: fix kernel bug due to missing clearing of checked flag
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50238
- phy: qcom: qmp-usbc: fix NULL-deref on runtime suspend
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53044
- net/sched: sch_api: fix xa_insert() error path in tcf_block_get_ext()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50304
- ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53048
- ice: fix crash on probe for DPLL enabled E810 LOM
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53045
- ASoC: dapm: fix bounds checker error in dapm_widget_list_create
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53055
- wifi: iwlwifi: mvm: fix 6 GHz scan construction
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53046
- arm64: dts: imx8ulp: correct the flexspi compatible string
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53052
- io_uring/rw: fix missing NOWAIT check for O_DIRECT start write
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50215
- nvmet-auth: assign dh_key to NULL after kfree_sensitive
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50216
- xfs: fix finding a last resort AG in xfs_filestream_pick_ag
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53043
- mctp i2c: handle NULL header address
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50218
- ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53047
- mptcp: init: protect sched with rcu_read_lock
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50222
- iov_iter: fix copy_page_from_iter_atomic() if KMAP_LOCAL_FORCE_MAP
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50223
- sched/numa: Fix the potential null pointer dereference in task_numa_work()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50224
- spi: spi-fsl-dspi: Fix crash when not using GPIO chip select
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50226
- cxl/port: Fix use-after-free, permit out-of-order decoder shutdown
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50231
- iio: gts-helper: Fix memory leaks in iio_gts_build_avail_scale_table()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53076
- iio: gts-helper: Fix memory leaks for the error path of
iio_gts_build_avail_scale_table()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50232
- iio: adc: ad7124: fix division by zero in ad7124_set_channel_odr()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50234
- wifi: iwlegacy: Clear stale interrupts before resuming device
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50235
- wifi: cfg80211: clear wdev->cqm_config pointer on free
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50236
- wifi: ath10k: Fix memory leak in management tx
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50237
- wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50239
- phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50240
- phy: qcom: qmp-usb: fix NULL-deref on runtime suspend
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50242
- fs/ntfs3: Additional check in ntfs_file_release
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50243
- fs/ntfs3: Fix general protection fault in run_is_mapped_full
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50244
- fs/ntfs3: Additional check in ni_clear()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50245
- fs/ntfs3: Fix possible deadlock in mi_read
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50246
- fs/ntfs3: Add rough attr alloc_size check
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50247
- fs/ntfs3: Check if more than chunk-size bytes are written
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50250
- fsdax: dax_unshare_iter needs to copy entire blocks
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50251
- netfilter: nft_payload: sanitize offset and length before calling
skb_checksum()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50252
- mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50255
- Bluetooth: hci: fix null-ptr-deref in hci_read_supported_codecs
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50257
- netfilter: Fix use-after-free in get_info()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50258
- net: fix crash when config small gso_max_size/gso_ipv4_max_size
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50262
- bpf: Fix out-of-bounds write in trie_get_next_key()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50259
- netdevsim: Add trailing zero to terminate the string in
nsim_nexthop_bucket_activity_write()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53042
- ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow()
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53058
- net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-50261
- macsec: Fix use-after-free while sending the offloading packet
* Noble update: upstream stable patchset 2025-02-25 (LP: #2099996) //
CVE-2024-53059
- wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()
* Noble update: upstream stable patchset 2025-02-07 (LP: #2097575)
- irqchip/gic-v3-its: Fix VSYNC referencing an unmapped VPE on GIC v4.1
- xfs: fix error returns from xfs_bmapi_write
- xfs: fix xfs_bmap_add_extent_delay_real for partial conversions
- xfs: remove a racy if_bytes check in xfs_reflink_end_cow_extent
- xfs: require XFS_SB_FEAT_INCOMPAT_LOG_XATTRS for attr log intent item
recovery
- xfs: check opcode and iovec count match in xlog_recover_attri_commit_pass2
- xfs: fix missing check for invalid attr flags
- xfs: check shortform attr entry flags specifically
- xfs: validate recovered name buffers when recovering xattr items
- xfs: enforce one namespace per attribute
- xfs: revert commit 44af6c7e59b12
- xfs: use dontcache for grabbing inodes during scrub
- xfs: match lock mode in xfs_buffered_write_iomap_begin()
- xfs: make the seq argument to xfs_bmapi_convert_delalloc() optional
- xfs: make xfs_bmapi_convert_delalloc() to allocate the target offset
- xfs: convert delayed extents to unwritten when zeroing post eof blocks
- xfs: allow symlinks with short remote targets
- xfs: make sure sb_fdblocks is non-negative
- xfs: fix unlink vs cluster buffer instantiation race
- xfs: fix freeing speculative preallocations for preallocated files
- xfs: allow unlinked symlinks and dirs with zero size
- xfs: restrict when we try to align cow fork delalloc to cowextsz hints
- selftests: mptcp: join: change capture/checksum as bool
- selftests: mptcp: join: test for prohibited MPC to port-based endp
- selftests: mptcp: remove duplicated variables
- iio: accel: bma400: Fix uninitialized variable field_value in tap event
handling.
- bpf: Make sure internal and UAPI bpf_redirect flags don't overlap
- bpf: devmap: provide rxq after redirect
- cpufreq/amd-pstate: Fix amd_pstate mode switch on shared memory systems
- lib/Kconfig.debug: fix grammar in RUST_BUILD_ASSERT_ALLOW
- bpf: Fix memory leak in bpf_core_apply
- RDMA/bnxt_re: Fix a possible memory leak
- RDMA/bnxt_re: Fix incorrect AVID type in WQE structure
- RDMA/bnxt_re: Add a check for memory allocation
- x86/resctrl: Avoid overflow in MB settings in bw_validate()
- ARM: dts: bcm2837-rpi-cm3-io3: Fix HDMI hpd-gpio pin
- bpf: Add cookie to perf_event bpf_link_info records
- bpf: fix unpopulated name_len field in perf_event link info
- selftests/bpf: Add cookies check for perf_event fill_link_info test
- selftests/bpf: fix perf_event link info name_len assertion
- s390/pci: Handle PCI error codes other than 0x3a
- bpf: fix kfunc btf caching for modules
- iio: frequency: {admv4420,adrf6780}: format Kconfig entries
- iio: frequency: admv4420: fix missing select REMAP_SPI in Kconfig
- drm/vmwgfx: Handle possible ENOMEM in vmw_stdu_connector_atomic_check
- selftests/bpf: Fix cross-compiling urandom_read
- task_work: Add TWA_NMI_CURRENT as an additional notify mode.
- sched/core: Disable page allocation in task_tick_mm_cid()
- ALSA: hda/cs8409: Fix possible NULL dereference
- firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup()
- RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP
- RDMA/irdma: Fix misspelling of "accept*"
- RDMA/srpt: Make slab cache names unique
- ipv4: give an IPv4 dev to blackhole_netdev
- RDMA/bnxt_re: Fix the max CQ WQEs for older adapters
- RDMA/bnxt_re: Fix out of bound check
- RDMA/bnxt_re: Return more meaningful error
- RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages
- RDMA/bnxt_re: Fix the GID table length
- accel/qaic: Fix the for loop used to walk SG table
- drm/msm/dpu: make sure phys resources are properly initialized
- drm/msm/dpu: check for overflow in _dpu_crtc_setup_lm_bounds()
- drm/msm/dsi: improve/fix dsc pclk calculation
- drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation
- drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
- drm/msm: Allocate memory for disp snapshot with kvzalloc()
- firmware: arm_scmi: Queue in scmi layer for mailbox implementation
- net/smc: Fix memory leak when using percpu refs
- net: usb: usbnet: fix race in probe failure
- net: stmmac: dwmac-tegra: Fix link bring-up sequence
- octeontx2-af: Fix potential integer overflows on integer shifts
- drm/amd/amdgpu: Fix double unlock in amdgpu_mes_add_ring
- macsec: don't increment counters for an unrelated SA
- netdevsim: use cond_resched() in nsim_dev_trap_report_work()
- net: ethernet: aeroflex: fix potential memory leak in
greth_start_xmit_gbit()
- net/smc: Fix searching in list of known pnetids in smc_pnet_add_pnetid
- net: xilinx: axienet: fix potential memory leak in axienet_start_xmit()
- bpf: Fix truncation bug in coerce_reg_to_size_sx()
- irqchip/renesas-rzg2l: Fix missing put_device
- drm/msm/dpu: don't always program merge_3d block
- net: bcmasp: fix potential memory leak in bcmasp_xmit()
- tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().
- net: dsa: mv88e6xxx: Fix the max_vid definition for the MV88E6361
- genetlink: hold RCU in genlmsg_mcast()
- ravb: Remove setting of RX software timestamp
- net: ravb: Only advertise Rx/Tx timestamps if hardware supports it
- scsi: target: core: Fix null-ptr-deref in target_alloc_device()
- smb: client: fix possible double free in smb2_set_ea()
- smb: client: fix OOBs when building SMB2_IOCTL request
- usb: typec: altmode should keep reference to parent
- s390: Initialize psw mask in perf_arch_fetch_caller_regs()
- bpf: Fix link info netfilter flags to populate defrag flag
- vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
- net/mlx5: Check for invalid vector index on EQ creation
- net/mlx5: Fix command bitmask initialization
- net/mlx5: Unregister notifier on eswitch init failure
- bpf, sockmap: SK_DROP on attempted redirects of unsupported af_vsock
- vsock: Update rx_bytes on read_skb()
- vsock: Update msg_count on read_skb()
- bpf, vsock: Drop static vsock_bpf_prot initialization
- riscv, bpf: Make BPF_CMPXCHG fully ordered
- nvme-pci: fix race condition between reset and nvme_dev_disable()
- bpf: Fix iter/task tid filtering
- cdrom: Avoid barrier_nospec() in cdrom_ioctl_media_changed()
- khugepaged: inline hpage_collapse_alloc_folio()
- khugepaged: convert alloc_charge_hpage to alloc_charge_folio
- khugepaged: remove hpage from collapse_file()
- mm: khugepaged: fix the arguments order in khugepaged_collapse_file trace
point
- iio: adc: ti-lmp92064: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
- xhci: dbgtty: remove kfifo_out() wrapper
- xhci: dbgtty: use kfifo from tty_port struct
- xhci: dbc: honor usb transfer size boundaries.
- usb: gadget: f_uac2: fix non-newline-terminated function name
- usb: gadget: f_uac2: fix return value for UAC2_ATTRIBUTE_STRING store
- XHCI: Separate PORT and CAPs macros into dedicated file
- usb: dwc3: core: Fix system suspend on TI AM62 platforms
- tracing/fprobe-event: cleanup: Fix a wrong comment in fprobe event
- tracing/probes: cleanup: Set trace_probe::nr_args at trace_probe_init
- tracing/probes: Support $argN in return probe (kprobe and fprobe)
- uprobes: encapsulate preparation of uprobe args buffer
- uprobes: prepare uprobe args buffer lazily
- uprobes: prevent mutex_lock() under rcu_read_lock()
- uprobe: avoid out-of-bounds memory access of fetching args
- exec: don't WARN for racy path_noexec check
- ASoC: amd: yc: Add quirk for HP Dragonfly pro one
- ASoC: codecs: lpass-rx-macro: add missing CDC_RX_BCL_VBAT_RF_PROC2 to
default regs values
- ASoC: fsl_sai: Enable 'FIFO continue on error' FCONT bit
- arm64: Force position-independent veneers
- udf: refactor udf_current_aext() to handle error
- udf: refactor udf_next_aext() to handle error
- udf: refactor inode_bmap() to handle error
- udf: fix uninit-value use in udf_get_fileshortad
- ASoC: qcom: sm8250: add qrb4210-rb2-sndcard compatible string
- cifs: Validate content of NFS reparse point buffer
- platform/x86: dell-sysman: add support for alienware products
- LoongArch: Don't crash in stack_top() for tasks without vDSO
- jfs: Fix sanity check in dbMount
- tracing/probes: Fix MAX_TRACE_ARGS limit handling
- tracing: Consider the NULL character when validating the event length
- xfrm: extract dst lookup parameters into a struct
- xfrm: respect ip protocols rules criteria when performing dst lookups
- netfilter: bpf: must hold reference on net namespace
- net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
- net: plip: fix break; causing plip to never transmit
- octeon_ep: Implement helper for iterating packets in Rx queue
- octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx()
- net: dsa: mv88e6xxx: Fix error when setting port policy on mv88e6393x
- fsl/fman: Save device references taken in mac_probe()
- fsl/fman: Fix refcount handling of fman-related devices
- netfilter: xtables: fix typo causing some targets not to load on IPv6
- net: wwan: fix global oob in wwan_rtnl_policy
- net/sched: adjust device watchdog timer to detect stopped queue at right
time
- net: fix races in netdev_tx_sent_queue()/dev_watchdog()
- net: usb: usbnet: fix name regression
- bpf: Add MEM_WRITE attribute
- bpf: Fix overloading of MEM_UNINIT's meaning
- bpf: Remove MEM_UNINIT from skb/xdp MTU helpers
- net/sched: act_api: deny mismatched skip_sw/skip_hw flags for actions
created by classifiers
- net: sched: fix use-after-free in taprio_change()
- net: sched: use RCU read-side critical section in taprio_dump()
- posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
- Bluetooth: SCO: Fix UAF on sco_sock_timeout
- Bluetooth: ISO: Fix UAF on iso_sock_timeout
- bpf,perf: Fix perf_event_detach_bpf_prog error handling
- net: dsa: mv88e6xxx: group cycle counter coefficients
- net: dsa: mv88e6xxx: read cycle counter period from hardware
- net: dsa: mv88e6xxx: support 4000ps cycle counter period
- ASoC: dt-bindings: davinci-mcasp: Fix interrupts property
- ASoC: dt-bindings: davinci-mcasp: Fix interrupt properties
- ASoC: loongson: Fix component check failed on FDT systems
- ASoC: max98388: Fix missing increment of variable slot_found
- ASoC: rsnd: Fix probe failure on HiHope boards due to endpoint parsing
- ASoC: fsl_micfil: Add a flag to distinguish with different volume control
types
- ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()
- powercap: dtpm_devfreq: Fix error check against dev_pm_qos_add_request()
- nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net
- ALSA: hda/realtek: Update default depop procedure
- smb: client: Handle kstrdup failures for passwords
- cpufreq: CPPC: fix perf_to_khz/khz_to_perf conversion exception
- btrfs: fix passing 0 to ERR_PTR in btrfs_search_dir_index_item()
- btrfs: zoned: fix zone unusable accounting for freed reserved extent
- ACPI: resource: Add LG 16T90SP to irq1_level_low_skip_override[]
- ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and context
- ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid
detection issue
- nilfs2: fix kernel bug due to missing clearing of buffer delay flag
- openat2: explicitly return -E2BIG for (usize > PAGE_SIZE)
- KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
- KVM: arm64: Fix shift-out-of-bounds bug
- KVM: arm64: Don't eagerly teardown the vgic on init error
- x86/lam: Disable ADDRESS_MASKING in most cases
- [Config] disable ADDRESS_MASKING
- ALSA: hda/tas2781: select CRC32 instead of CRC32_SARWATE
- ALSA: hda/realtek: Add subwoofer quirk for Acer Predator G9-593
- LoongArch: Get correct cores_per_package for SMT systems
- LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context
- LoongArch: Make KASAN usable for variable cpu_vabits
- xfrm: fix one more kernel-infoleak in algo dumping
- hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event
- drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too
- selinux: improve error checking in sel_write_load()
- net: phy: dp83822: Fix reset pin definitions
- ata: libata: Set DID_TIME_OUT for commands that actually timed out
- ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe()
- platform/x86: dell-wmi: Ignore suspend notifications
- ACPI: PRM: Clean up guid type in struct prm_handler_info
- tracing: probes: Fix to zero initialize a local variable
- task_work: make TWA_NMI_CURRENT handling conditional on IRQ_WORK
- xfrm: validate new SA's prefixlen using SA family when sel.family is unset
- bpf: Use raw_spinlock_t in ringbuf
- reset: starfive: jh71x0: Fix accessing the empty member on JH7110 SoC
- bpf: Fix unpopulated path_size when uprobe_multi fields unset
- RDMA/bnxt_re: Fix incorrect dereference of srq in async event
- RDMA/bnxt_re: Get the toggle bits from SRQ events
- RDMA/bnxt_re: Change the sequence of updating the CQ toggle value
- drm/msm/dpu: move CRTC resource assignment to dpu_encoder_virt_atomic_check
- ring-buffer: Fix reader locking when changing the sub buffer order
- drm/msm/dpu: Don't always set merge_3d pending flush
- drm/msm/a6xx+: Insert a fence wait before SMMU table update
- drm/xe: Take job list lock in xe_sched_add_pending_job
- drm/xe: Use bookkeep slots for external BO's in exec IOCTL
- net: ethernet: mtk_eth_soc: fix memory corruption during fq dma init
- net/mlx5e: Don't call cleanup on profile rollback failure
- bpf: Fix print_reg_state's constant scalar dump
- fsnotify: optimize the case of no parent watcher
- fsnotify: Avoid data race between fsnotify_recalc_mask() and
fsnotify_object_watched()
- drm/xe/mcr: Use Xe2_LPM steering tables for Xe2_HPM
- objpool: fix choosing allocation for percpu slots
- bnxt_en: replace ptp_lock with irqsave variant
- bpf, arm64: Fix address emission with tag-based KASAN enabled
- net: dsa: microchip: disable EEE for KSZ879x/KSZ877x/KSZ876x
- ASoC: topology: Bump minimal topology ABI version
- fbdev: wm8505fb: select CONFIG_FB_IOMEM_FOPS
- btrfs: qgroup: set a more sane default value for subtree drop threshold
- btrfs: clear force-compress on remount when compress mount option is given
- x86/amd_nb: Add new PCI IDs for AMD family 1Ah model 60h-70h
- x86/amd_nb: Add new PCI ID for AMD family 1Ah model 20h
- btrfs: reject ro->rw reconfiguration if there are hard ro requirements
- xfs: don't fail repairs on metadata files with no attr fork
- drm/bridge: Fix assignment of the of_node of the parent to aux bridge
- platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid
addresses
- fgraph: Fix missing unlock in register_ftrace_graph()
- fgraph: Change the name of cpuhp state to "fgraph:online"
- ASoC: SOF: Intel: hda: Always clean up link DMA during stop
- ASoC: dapm: avoid container_of() to get component
- ASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc
- ASoC: qcom: sdm845: add missing soundwire runtime stream alloc
- soundwire: intel_ace2x: Send PDI stream number during prepare
- x86: support user address masking instead of non-speculative conditional
- ASoC: qcom: Select missing common Soundwire module code on SDM845
- SAUCE: Revert "iio: adc: ti-lmp92064: add missing select
IIO_(TRIGGERED_)BUFFER in Kconfig"
- Upstream stable to v6.6.58, v6.6.59, v6.11.6
* CVE-2025-21756
- vsock: Keep the binding until socket destruction
- vsock: Orphan socket after transport release
* Fix NIC name changes for ice (LP: #2100264)
- ice: Remove ndo_get_phys_port_name
* CVE-2024-50256
- netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()
* CVE-2025-21702
- pfifo_tail_enqueue: Drop new packet when sch->limit == 0
* CVE-2024-50167
- be2net: fix potential memory leak in be_xmit()
* Fix line-out playback on some platforms with Cirrus Logic “Dolphin” hardware
(LP: #2099880)
- ALSA: hda/cirrus: Correct the full scale volume set logic
* Enable Large Language Model (LLM) workloads using Intel NPU (LP: #2098972)
- accel/ivpu: Increase DMA address range
* Patchset for TUXEDO devices (LP: #2098104)
- wifi: ath12k: add fallback board name without variant while searching
board-2.bin
- wifi: ath12k: remove unused ATH12K_BD_IE_BOARD_EXT
- wifi: ath12k: add support to search regdb data in board-2.bin for WCN7850
- wifi: ath12k: support default regdb while searching board-2.bin for WCN7850
- ACPI: resource: Use IRQ override on Maibenben X565
- ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
- ALSA: hda/realtek: Fix headset mic on TUXEDO Gemini 17 Gen3
- ALSA: hda/realtek: Fix headset mic on TUXEDO Stellaris 16 Gen6 mb1
- PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1
- nvme-pci: Add TUXEDO InfinityFlex to Samsung sleep quirk
- nvme-pci: Add TUXEDO IBP Gen9 to Samsung sleep quirk
* Introduce and use sendpages_ok() instead of sendpage_ok() in nvme-tcp and
drbd (LP: #2093871)
- net: introduce helper sendpages_ok()
- nvme-tcp: use sendpages_ok() instead of sendpage_ok()
- drbd: use sendpages_ok() instead of sendpage_ok()
* CVE-2024-56765
- powerpc/pseries/vas: Add close() callback in vas_vm_ops struct
* CVE-2025-21700
- net: sched: Disallow replacing of child qdisc from one parent to another
* CVE-2024-56615
- bpf: fix OOB devmap writes when deleting elements
* CVE-2024-56651
- can: hi311x: hi3110_can_ist(): fix potential use-after-free
* CVE-2024-56627
- ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read
* CVE-2024-56600
- net: inet6: do not leave a dangling sk pointer in inet6_create()
* CVE-2024-56661
- tipc: fix NULL deref in cleanup_bearer()
* CVE-2024-56642
- tipc: Fix use-after-free of kernel socket in cleanup_bearer().
* CVE-2024-53227
- scsi: bfa: Fix use-after-free in bfad_im_module_exit()
* CVE-2024-53237
- Bluetooth: fix use-after-free in device_for_each_child()
* CVE-2024-53166
- block, bfq: fix bfqq uaf in bfq_limit_depth()
* CVE-2024-50265
- ocfs2: remove entry once instead of null-ptr-dereference in
ocfs2_xa_remove()
* CVE-2024-50249
- ACPI: CPPC: Make rmw_lock a raw_spin_lock
* iBFT iSCSI out-of-bounds shift UBSAN warning (LP: #2097824)
- iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
* [Ubuntu 24.04] MultiVM - L2 guest(s) running stress-ng getting stuck at
booting after triggering crash (LP: #2077722)
- KVM: PPC: Book3S HV: Mask off LPCR_MER for a vCPU before running it to avoid
spurious interrupts
* btrfs will WARN_ON() in btrfs_remove_qgroup() unnecessarily (LP: #2091719)
- btrfs: improve the warning and error message for btrfs_remove_qgroup()
* CVE-2024-50248
- ntfs3: Add bounds checking to mi_enum_attr()
- fs/ntfs3: Sequential field availability check in mi_enum_attr()
* CVE-2025-21701
- net: avoid race between device unregistration and ethnl ops
* CVE-2024-57798
- drm/dp_mst: Ensure mst_primary pointer is valid in
drm_dp_mst_handle_up_req()
* CVE-2024-56672
- blk-cgroup: Fix UAF in blkcg_unpin_online()
* CVE-2024-56658
- net: defer final 'struct net' free in netns dismantle
* CVE-2024-56598
- jfs: array-index-out-of-bounds fix in dtReadFirst
* CVE-2024-56595
- jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
* CVE-2024-53140
- netlink: terminate outstanding dump on socket close
* CVE-2024-53063
- media: dvbdev: prevent the risk of out of memory access
* CVE-2024-50302
- HID: core: zero-initialize the report buffer
[ Ubuntu: 6.8.1-1019.20 ]
* noble/linux-realtime: 6.8.1-1019.20 -proposed tracker (LP: #2102485)
[ Ubuntu: 6.8.0-57.59 ]
* noble/linux: 6.8.0-57.59 -proposed tracker (LP: #2102490)
* CVE-2024-57798
- drm/dp_mst: Ensure mst_primary pointer is valid in
drm_dp_mst_handle_up_req()
* CVE-2024-56672
- blk-cgroup: Fix UAF in blkcg_unpin_online()
* CVE-2024-56658
- net: defer final 'struct net' free in netns dismantle
* CVE-2024-56598
- jfs: array-index-out-of-bounds fix in dtReadFirst
* CVE-2024-56595
- jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
* CVE-2024-53140
- netlink: terminate outstanding dump on socket close
* CVE-2024-53063
- media: dvbdev: prevent the risk of out of memory access
* CVE-2024-50302
- HID: core: zero-initialize the report buffer
Date: 2025-07-17 20:30:13.265189+00:00
Changed-By: Noah Wager <noah.wager at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia-tegra/6.8.0-1008.8
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list