[ubuntu/noble-updates] linux-azure-fde-6.17 6.17.0-1010.10~24.04.1 (Accepted)

Andy Whitcroft apw at canonical.com
Mon May 4 12:07:21 UTC 2026


linux-azure-fde-6.17 (6.17.0-1010.10~24.04.1) noble; urgency=medium

  * noble/linux-azure-fde-6.17: 6.17.0-1010.10~24.04.1 -proposed tracker (LP: #2147895)

  [ Ubuntu-azure-fde: 6.17.0-1010.10 ]

  * questing/linux-azure-fde: 6.17.0-1010.10 -proposed tracker (LP: #2147896)
  [ Ubuntu-azure: 6.17.0-1013.13 ]
  * questing/linux-azure: 6.17.0-1013.13 -proposed tracker (LP: #2147900)
  * Backporting critical SMB client fixes to affected Ubuntu distros
    (LP: #2147347)
    - smb: client: fix in-place encryption corruption in SMB2_write()
    - cifs: make default value of retrans as zero
  [ Ubuntu: 6.17.0-23.23 ]
  * questing/linux: 6.17.0-23.23 -proposed tracker (LP: #2147920)
  * CVE-2026-23231
    - netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
  * macvlan: observe an RCU grace period in macvlan_common_newlink() error
    path (LP: #2144380) // CVE-2026-23209
    - macvlan: observe an RCU grace period in macvlan_common_newlink() error
      path
  * Dell Machines cannot boot into OS with 6.17.0-1012-oem (LP: #2144522)
    - drm/amd: Disable MES LR compute W/A
    - drm/amd: Set minimum version for set_hw_resource_1 on gfx11 to 0x52
  * CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

linux-azure-fde-6.17 (6.17.0-1009.9~24.04.1) noble; urgency=medium

  * noble/linux-azure-fde-6.17: 6.17.0-1009.9~24.04.1 -proposed tracker (LP: #2143404)

  [ Ubuntu-azure-fde: 6.17.0-1009.9 ]

  * questing/linux-azure-fde: 6.17.0-1009.9 -proposed tracker (LP: #2143405)
  [ Ubuntu-azure: 6.17.0-1012.12 ]
  * questing/linux-azure: 6.17.0-1012.12 -proposed tracker (LP: #2143409)
  * [Mana][Backport] net: mana: Implement ndo_tx_timeout and serialize queue
    resets per port (LP: #2141683)
    - net: mana: Implement ndo_tx_timeout and serialize queue resets per port.
  * [Mana_IB][RDMA][Backport] RDMA/mana_ib: Take CQ type from the device type
    (LP: #2140368)
    - RDMA/mana_ib: Take CQ type from the device type
  [ Ubuntu: 6.17.0-22.22 ]
  * questing/linux: 6.17.0-22.22 -proposed tracker (LP: #2143428)
  * Questing preinstalled server fails to boot on QCS8300 based boards
    (LP: #2134400)
    - [Config] move qcom interconnect/pinctrl/gcc as built-in for QCS8300
  * TBT call trace while connecting TBT4 monitor on TBT5 port (LP: #2137613)
    - SAUCE: thunderbolt: log path activation failures without WARN backtraces
  * efi: Fix swapped arguments to bsearch() in efi_status_to_*() SAUCE patch
    (LP: #2141276)
    - SAUCE efi: Fix swapped arguments to bsearch() in efi_status_to_*()
  * [SRU]Fix xe GPU suspend/resume crash on Battlemage (LP: #2141377)
    - drm/xe: make xe_gt_idle_disable_c6() handle the forcewake internally
  * Accumulative updates for Intel PTL-H component enabling PV rev3.0
    (LP: #2137272)
    - drm/i915/display: Optimize panel power-on wait time
    - HID: intel-ish-hid: Use dedicated unbound workqueues to prevent resume
      blocking
    - drm/xe/guc: Recommend GUC v70.49.4 for PTL, BMG
    - HID: Intel-thc-hid: Intel-thc: Use str_true_false() helper
    - HID: intel-thc-hid: intel-quicki2c: support ACPI config for advanced
      features
    - usb: typec: ucsi: Add SET_POWER_LEVEL UCSI command to debugfs
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250)
    - bpf: Fix sleepable context for async callbacks
    - bpf: extract generic helper from process_timer_func()
    - bpf: Fix handling maps with no BTF and non-constant offsets for the
      bpf_wq
    - irqchip: Drop leftover brackets
    - irqchip: Pass platform device to platform drivers
    - arm64: dts: exynos: gs101: fix clock module unit reg sizes
    - ice: move service task start out of ice_init_pf()
    - ice: move ice_init_interrupt_scheme() prior ice_init_pf()
    - ice: ice_init_pf: destroy mutexes and xarrays on memory alloc failure
    - ice: move udp_tunnel_nic and misc IRQ setup into ice_init_pf()
    - ice: move ice_init_pf() out of ice_init_dev()
    - ice: extract ice_init_dev() from ice_init()
    - ice: move ice_deinit_dev() to the end of deinit paths
    - ice: remove duplicate call to ice_deinit_hw() on error paths
    - arm64: dts: qcom: lemans: Add missing quirk for HS only USB controller
    - tools/nolibc: x86: fix section mismatch caused by asm "mem*" functions
    - arm64: dts: ti: k3-j784s4: Fix I2C pinmux pull configuration
    - wifi: ath12k: enforce vdev limit in ath12k_mac_vdev_create()
    - ARM: dts: am33xx: Add missing serial console speed
    - arm64: tegra: Add pinctrl definitions for pcie-ep nodes
    - arm64: mm: Move KPTI helpers to mmu.c
    - arm64/mm: Allow __create_pgd_mapping() to propagate pgtable_alloc()
      errors
    - pwm: Simplify printf to emit chip->npwm in $debugfs/pwm
    - pwm: Use %u to printf unsigned int pwm_chip::npwm and pwm_chip::id
    - soc/tegra: fuse: speedo-tegra210: Update speedo IDs
    - iio: core: add missing mutex_destroy in iio_dev_release()
    - iio: core: Clean up device correctly on iio_device_alloc() failure
    - iommu/vt-d: Set INTEL_IOMMU_FLOPPY_WA depend on BLK_DEV_FD
    - of/fdt: Fix the len check in early_init_dt_check_for_elfcorehdr()
    - of/fdt: Fix the len check in early_init_dt_check_for_usable_mem_range()
    - rtla/tests: Extend action tests to 5s
    - rtla: Fix -a overriding -t argument
    - btrfs: make sure extent and csum paths are always released in
      scrub_raid56_parity_stripe()
    - iomap: allocate s_dio_done_wq for async reads as well
    - RDMA/irdma: Remove doorbell elision logic
    - selftests/landlock: Fix makefile header list
    - io_uring/kbuf: use READ_ONCE() for userspace-mapped memory
    - ALSA: wavefront: Clear substream pointers on close
    - btrfs: do not skip logging new dentries when logging a new name
    - btrfs: fix a potential path leak in print_data_reloc_error()
    - bpf, arm64: Do not audit capability check in do_jit()
    - btrfs: fix memory leak of fs_devices in degraded seed device path
    - iomap: account for unaligned end offsets when truncating read range
    - scripts/faddr2line: Fix "Argument list too long" error
    - sched/fair: Revert max_newidle_lb_cost bump
    - x86/ptrace: Always inline trivial accessors
    - ACPI: property: Use ACPI functions in acpi_graph_get_next_endpoint()
      only
    - cpufreq: dt-platdev: Add JH7110S SOC to the allowlist
    - ACPI: fan: Workaround for 64-bit firmware bug
    - cpufreq: s5pv210: fix refcount leak
    - cpuidle: menu: Use residency threshold in polling state override
      decisions
    - livepatch: Match old_sympos 0 and 1 in klp_find_func()
    - fs/ntfs3: Support timestamps prior to epoch
    - kbuild: Use objtree for module signing key path
    - hfsplus: fix volume corruption issue for generic/070
    - hfsplus: fix volume corruption issue for generic/073
    - fs/ntfs3: check for shutdown in fsync
    - wifi: rtl8xxxu: Fix HT40 channel config for RTL8192CU, RTL8723AU
    - wifi: cfg80211: stop radar detection in cfg80211_leave()
    - wifi: cfg80211: use cfg80211_leave() in iftype change
    - wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING after CLC
      load
    - wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840 tablet
    - btrfs: scrub: always update btrfs_scrub_progress::last_physical
    - gfs2: fix remote evict for read-only filesystems
    - gfs2: Fix "gfs2: Switch to wait_event in gfs2_quotad"
    - smb/server: fix return value of smb2_ioctl()
    - Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV
    - Bluetooth: btusb: MT7922: Add VID/PID 0489/e170
    - Bluetooth: btusb: MT7920: Add VID/PID 0489/e135
    - Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE
    - Bluetooth: btusb: Add new VID/PID 0x0489/0xE12F for RTL8852BE-VT
    - net: fec: ERR007885 Workaround for XDP TX path
    - ipvlan: Ignore PACKET_LOOPBACK in handle_mode_l2()
    - mlxsw: spectrum_router: Fix possible neighbour reference count leak
    - broadcom: b44: prevent uninitialized value usage
    - netfilter: nf_conncount: fix leaked ct in error paths
    - nfc: pn533: Fix error code in pn533_acr122_poweron_rdr()
    - netfilter: nf_nat: remove bogus direction check
    - netfilter: nf_tables: remove redundant chain validation on register
      store
    - selftests: netfilter: packetdrill: avoid failure on HZ=100 kernel
    - iommufd/selftest: Make it clearer to gcc that the access is not out of
      bounds
    - net/mlx5: fw reset, clear reset requested on drain_fw_reset
    - net/mlx5: Drain firmware reset in shutdown callback
    - net/mlx5: fw_tracer, Handle escaped percent properly
    - net/mlx5: Serialize firmware reset with devlink
    - net: enetc: do not transmit redirected XDP frames when the link is down
    - net: hns3: using the num_tqps to check whether tqp_index is out of range
      when vf get ring info from mbx
    - hwmon: (dell-smm) Limit fan multiplier to avoid overflow
    - hwmon: (tmp401) fix overflow caused by default conversion rate value
    - drm/me/gsc: mei interrupt top half should be in irq disabled context
    - drm/xe: Restore engine registers before restarting schedulers after GT
      reset
    - MIPS: Fix a reference leak bug in ip22_check_gio()
    - drm/panel: sony-td4353-jdi: Enable prepare_prev_first
    - x86/xen: Fix sparse warning in enlighten_pv.c
    - arm64: kdump: Fix elfcorehdr overlap caused by reserved memory
      processing reorder
    - spi: cadence-quadspi: Fix clock disable on probe failure path
    - block: rnbd-clt: Fix leaked ID in init_dev()
    - hwmon: (ltc4282): Fix reset_history file permissions
    - HID: input: map HID_GD_Z to ABS_DISTANCE for stylus/pen
    - Input: i8042 - add TUXEDO InfinityBook Max Gen10 AMD to i8042 quirk
      table
    - xfs: don't leak a locked dquot when xfs_dquot_attach_buf fails
    - can: gs_usb: gs_can_open(): fix error handling
    - soc/tegra: fuse: Do not register SoC device on ACPI boot
    - ACPI: PCC: Fix race condition by removing static qualifier
    - ACPI: CPPC: Fix missing PCC check for guaranteed_perf
    - mmc: sdhci-esdhc-imx: add alternate ARCH_S32 dependency to Kconfig
    - mmc: sdhci-of-arasan: Increase CD stable timeout to 2 seconds
    - dt-bindings: mmc: sdhci-of-aspeed: Switch ref to sdhci-common.yaml
    - x86/fpu: Fix FPU state core dump truncation on CPUs with no extended
      xfeatures
    - ALSA: vxpocket: Fix resource leak in vxpocket_probe error path
    - ALSA: pcmcia: Fix resource leak in snd_pdacf_probe error path
    - ASoC: ak4458: remove the reset operation in probe and remove
    - nfsd: fix memory leak in nfsd_create_serv error paths
    - ipmi: Fix the race between __scan_channels() and deliver_response()
    - ipmi: Fix __scan_channels() failing to rescan channels
    - scsi: ufs: host: mediatek: Fix shutdown/suspend race condition
    - firmware: imx: scu-irq: Init workqueue before request mbox channel
    - ti-sysc: allow OMAP2 and OMAP4 timers to be reserved on AM33xx
    - scsi: smartpqi: Add support for Hurray Data new controller PCI device
    - clk: mvebu: cp110 add CLK_IGNORE_UNUSED to pcie_x10, pcie_x11 & pcie_x4
    - powerpc/addnote: Fix overflow on 32-bit builds
    - scsi: qla2xxx: Fix lost interrupts with qlini_mode=disabled
    - scsi: qla2xxx: Fix initiator mode with qlini_mode=exclusive
    - scsi: qla2xxx: Use reinit_completion on mbx_intr_comp
    - fuse: Always flush the page cache before FOPEN_DIRECT_IO write
    - fuse: Invalidate the page cache after FOPEN_DIRECT_IO write
    - reset: fix BIT macro reference
    - exfat: fix remount failure in different process environments
    - exfat: zero out post-EOF page cache on file extension
    - usbip: Fix locking bug in RT-enabled kernels
    - iio: adc: ti_am335x_adc: Limit step_avg to valid range for gcc complains
    - usb: xhci: limit run_graceperiod for only usb 3.0 devices
    - usb: usb-storage: No additional quirks need to be added to the EL-R12
      optical drive.
    - serial: sprd: Return -EPROBE_DEFER when uart clock is not ready
    - libperf cpumap: Fix perf_cpu_map__max for an empty/NULL map
    - clk: qcom: dispcc-sm7150: Fix dispcc_mdss_pclk0_clk_src
    - i2c: designware: Disable SMBus interrupts to prevent storms from mis-
      configured firmware
    - nvme-fc: don't hold rport lock when putting ctrl
    - nvme-fabrics: add ENOKEY to no retry criteria for authentication
      failures
    - scsi: scsi_debug: Fix atomic write enable module param description
    - block: rnbd-clt: Fix signedness bug in init_dev()
    - vhost/vsock: improve RCU read sections around vhost_vsock_get()
    - x86/mce: Do not clear bank's poll bit in mce_poll_banks on AMD SMCA
      systems
    - mmc: sdhci-msm: Avoid early clock doubling during HS400 transition
    - perf: arm_cspmu: fix error handling in arm_cspmu_impl_unregister()
    - lib/crypto: x86/blake2s: Fix 32-bit arg treated as 64-bit
    - s390/dasd: Fix gendisk parent after copy pair swap
    - wifi: mt76: Fix DTS power-limits on little endian systems
    - block: rate-limit capacity change info log
    - floppy: fix for PAGE_SIZE != 4KB
    - kallsyms: Fix wrong "big" kernel symbol type read from procfs
    - fs/ntfs3: fix mount failure for sparse runs in run_unpack()
    - ktest.pl: Fix uninitialized var in config-bisect.pl
    - ext4: clear i_state_flags when alloc inode
    - ext4: fix incorrect group number assertion in mb_check_buddy
    - ext4: align max orphan file size with e2fsprogs limit
    - jbd2: use a per-journal lock_class_key for jbd2_trans_commit_key
    - jbd2: use a weaker annotation in journal handling
    - media: v4l2-mem2mem: Fix outdated documentation
    - selftests: mptcp: pm: ensure unknown flags are ignored
    - mptcp: schedule rtx timer only after pushing data
    - usb: usb-storage: Maintain minimal modifications to the bcdDevice range.
    - media: pvrusb2: Fix incorrect variable used in trace message
    - phy: broadcom: bcm63xx-usbh: fix section mismatches
    - usb: ohci-nxp: fix device leak on probe failure
    - usb: typec: altmodes/displayport: Drop the device reference in
      dp_altmode_probe()
    - USB: lpc32xx_udc: Fix error handling in probe
    - usb: phy: isp1301: fix non-OF device reference imbalance
    - usb: gadget: lpc32xx_udc: fix clock imbalance in error path
    - usb: dwc3: of-simple: fix clock resource leak in dwc3_of_simple_probe
    - usb: dwc3: keep susphy enabled during exit to avoid controller faults
    - usb: renesas_usbhs: Fix a resource leak in usbhs_pipe_malloc()
    - intel_th: Fix error handling in intel_th_output_open
    - mei: gsc: add dependency on Xe driver
    - serial: sh-sci: Check that the DMA cookie is valid
    - cpuidle: governors: teo: Drop misguided target residency check
    - cpufreq: nforce2: fix reference count leak in nforce2
    - NFSD: use correct reservation type in nfsd4_scsi_fence_client
    - scsi: mpi3mr: Read missing IOCFacts flag for reply queue full overflow
    - scsi: ufs: core: Add ufshcd_update_evt_hist() for UFS suspend error
    - f2fs: fix age extent cache insertion skip on counter overflow
    - f2fs: fix uninitialized one_time_gc in victim_sel_policy
    - tools/testing/nvdimm: Use per-DIMM device handle
    - KVM: x86: Don't clear async #PF queue when CR0.PG is disabled (e.g. on
      #SMI)
    - powerpc: Add reloc_offset() to font bitmap pointer used for
      bootx_printf()
    - KVM: x86: WARN if hrtimer callback for periodic APIC timer fires with
      period=0
    - KVM: x86: Explicitly set new periodic hrtimer expiration in
      apic_timer_fn()
    - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE
    - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN
    - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation
    - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN
    - KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-
      Exit
    - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed
      VMRUN)
    - KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested VM-Exits
    - xfs: fix a memory leak in xfs_buf_item_init()
    - xfs: fix stupid compiler warning
    - PM: runtime: Do not clear needs_force_resume with enabled runtime PM
    - r8169: fix RTL8117 Wake-on-Lan in DASH mode
    - net: phy: marvell-88q2xxx: Fix clamped value in mv88q2xxx_hwmon_write
    - NFSD: Clear SECLABEL in the suppattr_exclcreat bitmap
    - nfsd: Mark variable __maybe_unused to avoid W=1 build break
    - svcrdma: return 0 on success from svc_rdma_copy_inline_range
    - s390/ipl: Clear SBP flag when bootprog is set
    - gpio: regmap: Fix memleak in error path in gpio_regmap_register()
    - io_uring: fix min_wait wakeups for SQPOLL
    - drm/amd/display: Use GFP_ATOMIC in dc_create_plane_state()
    - drm/amd/display: Fix scratch registers offsets for DCN35
    - drm/amd/display: Fix scratch registers offsets for DCN351
    - drm/displayid: pass iter to drm_find_displayid_extension()
    - ALSA: wavefront: Use guard() for spin locks
    - pinctrl: renesas: rzg2l: Fix ISEL restore on resume
    - arm64: Revamp HCR_EL2.E2H RES1 detection
    - dt-bindings: PCI: qcom,pcie-sc7280: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sc8280xp: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sm8150: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sm8250: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sm8350: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sm8450: Add missing required power-domains
      and resets
    - dt-bindings: PCI: qcom,pcie-sm8550: Add missing required power-domains
      and resets
    - crypto: caam - Add check for kcalloc() in test_len()
    - amba: tegra-ahb: Fix device leak on SMMU enable
    - virtio: vdpa: Fix reference count leak in octep_sriov_enable()
    - tracing: Fix fixed array of synthetic event
    - soc: samsung: exynos-pmu: fix device leak on regmap lookup
    - soc: qcom: pbs: fix device leak on lookup
    - soc: qcom: ocmem: fix device leak on lookup
    - soc: apple: mailbox: fix device leak on lookup
    - soc: amlogic: canvas: fix device leak on lookup
    - rpmsg: glink: fix rpmsg device leak
    - platform/x86: intel: chtwc_int33fe: don't dereference swnode args
    - i2c: amd-mp2: fix reference leak in MP2 PCI device
    - interconnect: qcom: sdx75: Drop QPIC interconnect and BCM nodes
    - hwmon: (max16065) Use local variable to avoid TOCTOU
    - hwmon: (max6697) fix regmap leak on probe failure
    - hwmon: (w83l786ng) Convert macros to functions to avoid TOCTOU
    - ARM: dts: microchip: sama5d2: fix spi flexcom fifo size to 32
    - x86/msi: Make irq_retrigger() functional for posted MSI
    - wifi: rtw88: limit indirect IO under powered off for RTL8822CS
    - wifi: cfg80211: sme: store capped length in __cfg80211_connect_result()
    - wifi: mac80211: do not use old MBSSID elements
    - i40e: fix scheduling in set_rx_mode
    - i40e: validate ring_len parameter against hardware-specific values
    - idpf: reduce mbx_task schedule delay to 300us
    - net: mdio: aspeed: add dummy read to avoid read-after-write issue
    - net: openvswitch: Avoid needlessly taking the RTNL on vport destroy
    - platform/mellanox: mlxbf-pmc: Remove trailing whitespaces from event
      names
    - platform/x86: msi-laptop: add missing sysfs_remove_group()
    - platform/x86: ibm_rtl: fix EBDA signature search pointer arithmetic
    - net: dsa: fix missing put_device() in dsa_tree_find_first_conduit()
    - amd-xgbe: reset retries and mode on RX adapt failures
    - Revert "UBUNTU: SAUCE: selftests: net: fix "buffer overflow detected"
      for tap.c"
    - selftests: net: fix "buffer overflow detected" for tap.c
    - genalloc.h: fix htmldocs warning
    - firewire: nosy: Fix dma_free_coherent() size
    - net: dsa: b53: skip multicast entries for fdb_dump()
    - kbuild: fix compilation of dtb specified on command-line without make
      rule
    - net: bridge: Describe @tunnel_hash member in net_bridge_vlan_group
      struct
    - vfio/pds: Fix memory leak in pds_vfio_dirty_enable()
    - RDMA/efa: Remove possible negative shift
    - RDMA/core: Fix logic error in ib_get_gids_from_rdma_hdr()
    - RDMA/bnxt_re: Fix incorrect BAR check in bnxt_qplib_map_creq_db()
    - RDMA/bnxt_re: Fix IB_SEND_IP_CSUM handling in post_send
    - RDMA/bnxt_re: Fix to use correct page size for PDE table
    - md: Fix static checker warning in analyze_sbs
    - RDMA/rtrs: Fix clt_path::max_pages_per_mr calculation
    - RDMA/bnxt_re: fix dma_free_coherent() pointer
    - blk-mq: skip CPU offline notify on unmapped hctx
    - selftests/ftrace: traceonoff_triggers: strip off names
    - ntfs: Do not overwrite uptodate pages
    - ASoC: codecs: wcd939x: fix regmap leak on probe failure
    - ASoC: stm32: sai: fix device leak on probe
    - ASoC: stm32: sai: fix clk prepare imbalance on probe failure
    - ASoC: codecs: lpass-tx-macro: fix SM6115 support
    - ASoC: qcom: q6apm-dai: set flags to reflect correct operation of
      appl_ptr
    - ASoC: qcom: q6asm-dai: perform correct state check before closing
    - ASoC: qcom: q6adm: the the copp device only during last instance
    - ASoC: qcom: qdsp6: q6asm-dai: set 10 ms period and buffer alignment.
    - iommu/amd: Fix pci_segment memleak in alloc_pci_segment()
    - iommu/amd: Propagate the error code returned by __modify_irte_ga() in
      modify_irte_ga()
    - iommu/apple-dart: fix device leak on of_xlate()
    - iommu/exynos: fix device leak on of_xlate()
    - iommu/ipmmu-vmsa: fix device leak on of_xlate()
    - iommu/mediatek-v1: fix device leak on probe_device()
    - iommu/mediatek-v1: fix device leaks on probe()
    - iommu/mediatek: fix device leak on of_xlate()
    - iommu/omap: fix device leaks on probe_device()
    - iommu/qcom: fix device leak on of_xlate()
    - iommu/sun50i: fix device leak on of_xlate()
    - iommu/tegra: fix device leak on probe_device()
    - HID: logitech-dj: Remove duplicate error logging
    - fgraph: Initialize ftrace_ops->private for function graph ops
    - fgraph: Check ftrace_pids_enabled on registration for early filtering
    - PCI/PM: Reinstate clearing state_saved in legacy and !PM codepaths
    - arm64: dts: ti: k3-j721e-sk: Fix pinmux for pin Y1 used by power
      regulator
    - powerpc, mm: Fix mprotect on book3s 32-bit
    - leds: leds-cros_ec: Skip LEDs without color components
    - leds: leds-lp50xx: Allow LED 0 to be added to module bank
    - leds: leds-lp50xx: LP5009 supports 3 modules for a total of 9 LEDs
    - leds: leds-lp50xx: Enable chip before any communication
    - block: Clear BLK_ZONE_WPLUG_PLUGGED when aborting plugged BIOs
    - mfd: altera-sysmgr: Fix device leak on sysmgr regmap lookup
    - mfd: max77620: Fix potential IRQ chip conflict when probing two devices
    - media: rc: st_rc: Fix reset control resource leak
    - media: verisilicon: Fix CPU stalls on G2 bus error
    - mtd: mtdpart: ignore error -ENOENT from parsers on subpartitions
    - mtd: spi-nor: winbond: Add support for W25Q01NWxxIQ chips
    - mtd: spi-nor: winbond: Add support for W25Q01NWxxIM chips
    - mtd: spi-nor: winbond: Add support for W25Q02NWxxIM chips
    - mtd: spi-nor: winbond: Add support for W25H512NWxxAM chips
    - mtd: spi-nor: winbond: Add support for W25H01NWxxAM chips
    - mtd: spi-nor: winbond: Add support for W25H02NWxxAM chips
    - parisc: entry.S: fix space adjustment on interruption for 64-bit
      userspace
    - parisc: entry: set W bit for !compat tasks in syscall_restore_rfi()
    - perf/x86/amd/uncore: Fix the return value of amd_uncore_df_event_init()
      on error
    - powerpc/pseries/cmm: call balloon_devinfo_init() also without
      CONFIG_BALLOON_COMPACTION
    - firmware: stratix10-svc: Add mutex in stratix10 memory management
    - dm-ebs: Mark full buffer dirty even on partial write
    - dm-bufio: align write boundary on physical block size
    - fbdev: gbefb: fix to use physical address instead of dma address
    - fbdev: pxafb: Fix multiple clamped values in pxafb_adjust_timing
    - fbdev: tcx.c fix mem_map to correct smem_start offset
    - media: cec: Fix debugfs leak on bus_register() failure
    - media: msp3400: Avoid possible out-of-bounds array accesses in
      msp3400c_thread()
    - media: platform: mtk-mdp3: fix device leaks at probe
    - media: renesas: rcar_drif: fix device node reference leak in
      rcar_drif_bond_enabled
    - media: samsung: exynos4-is: fix potential ABBA deadlock on init
    - media: TDA1997x: Remove redundant cancel_delayed_work in probe
    - media: verisilicon: Protect G2 HEVC decoder against invalid DPB index
    - media: videobuf2: Fix device reference leak in vb2_dc_alloc error path
    - media: vpif_capture: fix section mismatch
    - media: vpif_display: fix section mismatch
    - media: amphion: Cancel message work before releasing the VPU core
    - media: i2c: ADV7604: Remove redundant cancel_delayed_work in probe
    - media: i2c: adv7842: Remove redundant cancel_delayed_work in probe
    - media: mediatek: vcodec: Fix a reference leak in
      mtk_vcodec_fw_vpu_init()
    - LoongArch: Add new PCI ID for pci_fixup_vgadev()
    - LoongArch: Correct the calculation logic of thread_count
    - LoongArch: Fix build errors for CONFIG_RANDSTRUCT
    - LoongArch: Use __pmd()/__pte() for swap entry conversions
    - LoongArch: Use unsigned long for _end and _text
    - mm/damon/tests/sysfs-kunit: handle alloc failures on
      damon_sysfs_test_add_targets()
    - mm/damon/tests/vaddr-kunit: handle alloc failures in
      damon_test_split_evenly_fail()
    - mm/damon/tests/vaddr-kunit: handle alloc failures on
      damon_test_split_evenly_succ()
    - mm/damon/tests/core-kunit: handle alloc failures on
      damon_test_split_at()
    - mm/damon/tests/core-kunit: handle allocation failures in
      damon_test_regions()
    - mm/damon/tests/core-kunit: handle memory failure from
      damon_test_target()
    - mm/damon/tests/core-kunit: handle memory alloc failure from
      damon_test_aggregate()
    - mm/damon/tests/core-kunit: handle alloc failures on
      dasmon_test_merge_regions_of()
    - mm/damon/tests/core-kunit: handle alloc failures on
      damon_test_merge_two()
    - mm/damon/tests/core-kunit: handle alloc failures in
      damon_test_set_regions()
    - mm/damon/tests/core-kunit: handle alloc failures in
      damon_test_update_monitoring_result()
    - mm/damon/tests/core-kunit: handle alloc failures in
      damon_test_ops_registration()
    - mm/damon/tests/core-kunit: handle alloc failure on
      damon_test_set_attrs()
    - pmdomain: imx: Fix reference count leak in imx_gpc_probe()
    - compiler_types.h: add "auto" as a macro for "__auto_type"
    - mm/kasan: fix incorrect unpoisoning in vrealloc for KASAN
    - kasan: refactor pcpu kasan vmalloc unpoison
    - kasan: unpoison vms[area] addresses with a common tag
    - lockd: fix vfs_test_lock() calls
    - idr: fix idr_alloc() returning an ID out of range
    - mm/page_owner: fix memory leak in page_owner_stack_fops->release()
    - tools/mm/page_owner_sort: fix timestamp comparison for stable sorting
    - samples/ftrace: Adjust LoongArch register restore order in direct calls
    - fjes: Add missing iounmap in fjes_hw_init()
    - LoongArch: Refactor register restoration in ftrace_common_return
    - LoongArch: BPF: Zero-extend bpf_tail_call() index
    - nfsd: Drop the client reference in client_states_open()
    - net: usb: sr9700: fix incorrect command used to write single register
    - net: macb: Relocate mog_init_rings() callback from macb_mac_link_up() to
      macb_open()
    - drm/amdgpu/gmc12: add amdgpu_vm_handle_fault() handling
    - drm/amdgpu: add missing lock to amdgpu_ttm_access_memory_sdma
    - drm/amdgpu/gmc11: add amdgpu_vm_handle_fault() handling
    - drm/msm/a6xx: Fix out of bound IO access in a6xx_get_gmu_registers
    - drm/buddy: Optimize free block management with RB tree
    - drm/buddy: Separate clear and dirty free block trees
    - drm/gma500: Remove unused helper psb_fbdev_fb_setcolreg()
    - drm/edid: add DRM_EDID_IDENT_INIT() to initialize struct drm_edid_ident
    - drm/mediatek: Fix device node reference leak in mtk_dp_dt_parse()
    - drm/mediatek: Fix probe resource leaks
    - drm/mediatek: Fix probe memory leak
    - drm/mediatek: Fix probe device leaks
    - drm/amdkfd: Trap handler support for expert scheduling mode
    - drm/i915: Fix format string truncation warning
    - drm/mgag200: Fix big-endian support
    - drm/xe/bo: Don't include the CCS metadata in the dma-buf sg-table
    - drm/xe/oa: Disallow 0 OA property values
    - drm/xe: Adjust long-running workload timeslices to reasonable values
    - drm/xe: Use usleep_range for accurate long-running workload timeslicing
    - drm/xe: Drop preempt-fences when destroying imported dma-bufs.
    - drm/nouveau/dispnv50: Don't call drm_atomic_get_crtc_state() in
      prepare_fb
    - drm/imagination: Disallow exporting of PM/FW protected objects
    - lib/crypto: riscv/chacha: Avoid s0/fp register
    - gfs2: fix freeze error handling
    - btrfs: don't rewrite ret from inode_permission
    - sched/eevdf: Fix min_vruntime vs avg_vruntime
    - erofs: fix unexpected EIO under memory pressure
    - sched_ext: Fix incorrect sched_class settings for per-cpu migration
      tasks
    - jbd2: fix the inconsistency between checksum and data in memory for
      journal sb
    - xhci: dbgtty: fix device unregister: fixup
    - f2fs: fix to detect recoverable inode during dryrun of
      find_fsync_dnodes()
    - serial: core: Restore sysfs fwnode information
    - mptcp: pm: ignore unknown endpoint flags
    - mm/ksm: fix exec/fork inheritance support for prctl
    - ARM: dts: microchip: sama7g5: fix uart fifo size to 32
    - tpm2-sessions: Fix out of range indexing in name_size
    - tpm2-sessions: Fix tpm2_read_public range checks
    - sched_ext: Factor out local_dsq_post_enq() from dispatch_enqueue()
    - sched_ext: Fix missing post-enqueue handling in
      move_local_task_to_local_dsq()
    - drm/displayid: add quirk to ignore DisplayID checksum errors
    - serial: xilinx_uartps: fix rs485 delay_rts_after_send
    - f2fs: add timeout in f2fs_enable_checkpoint()
    - f2fs: dump more information for f2fs_{enable,disable}_checkpoint()
    - f2fs: fix to propagate error from f2fs_enable_checkpoint()
    - gpiolib: acpi: Add quirk for Dell Precision 7780
    - serial: core: Fix serial device initialization
    - media: i2c: imx219: Fix 1920x1080 mode to use 1:1 pixel aspect ratio
    - ASoC: renesas: rz-ssi: Fix channel swap issue in full duplex mode
    - block: handle zone management operations completions
    - ASoC: qcom: sdw: fix memory leak for sdw_stream_runtime
    - ASoC: renesas: rz-ssi: Fix rz_ssi_priv::hw_params_cache::sample_width
    - PCI: brcmstb: Fix disabling L0s capability
    - powerpc/pseries/cmm: adjust BALLOON_MIGRATE when migrating pages
    - media: amphion: Make some vpu_v4l2 functions static
    - media: amphion: Remove vpu_vb_is_codecconfig
    - vfio/pci: Disable qword access to the PCI ROM bar
    - mm/damon/tests/core-kunit: handle alloc failures on
      damon_test_split_regions_of()
    - mm/damon/tests/core-kunit: handle alloc failres in
      damon_test_new_filter()
    - mm/damon/tests/vaddr-kunit: handle alloc failures on
      damon_do_test_apply_three_regions()
    - block: fix NULL pointer dereference in blk_zone_reset_all_bio_endio()
    - bpf: Fix truncated dmabuf iterator reads
    - bpf: Fix verifier assumptions of bpf_d_path's output buffer
    - btrfs: fix changeset leak on mmap write after failure to reserve
      metadata
    - scripts: kdoc_parser.py: warn about Python version only once
    - crypto: ccp - Add support for PCI device 0x115A
    - hfsplus: fix volume corruption issue for generic/101
    - Bluetooth: btusb: add new custom firmwares
    - net/mlx5: make enable_mpesw idempotent
    - net: phy: realtek: eliminate priv->phycr2 variable
    - net: phy: realtek: eliminate has_phycr2 variable
    - net: phy: realtek: allow CLKOUT to be disabled on RTL8211F(D)(I)-VD-CG
    - net: phy: realtek: eliminate priv->phycr1 variable
    - net: phy: realtek: create rtl8211f_config_phy_eee() helper
    - net: phy: RTL8211FVD: Restore disabling of PHY-mode EEE
    - net: ti: icssg-prueth: add PTP_1588_CLOCK_OPTIONAL dependency
    - selftests: net: Fix build warnings
    - selftests: net: tfo: Fix build warning
    - inet: frags: avoid theoretical race in ip_frag_reinit()
    - inet: frags: add inet_frag_queue_flush()
    - selftests: netfilter: prefer xfail in case race wasn't triggered
    - can: j1939: make j1939_sk_bind() fail if device is no longer registered
    - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC
      init
    - net/mlx5e: Trigger neighbor resolution for unresolved destinations
    - drm/tests: hdmi: Handle drm_kunit_helper_enable_crtc_connector()
      returning EDEADLK
    - drm/tests: Handle EDEADLK in drm_test_check_valid_clones()
    - drm/tests: Handle EDEADLK in set_up_atomic_state()
    - selftests: ublk: fix overflow in ublk_queue_auto_zc_fallback()
    - block: unify elevator tags and type xarrays into struct elv_change_ctx
    - block: move elevator tags into struct elevator_resources
    - block: introduce alloc_sched_data and free_sched_data elevator methods
    - block: use {alloc|free}_sched data methods
    - spi: microchip: rename driver file and internal identifiers
    - [Config] Remove CONFIG_SPI_MICROCHIP_CORE
    - spi: mpfs: Fix an error handling path in mpfs_spi_probe()
    - drm/xe: Fix freq kobject leak on sysfs_create_files failure
    - drm/xe: Apply Wa_14020316580 in xe_gt_idle_enable_pg()
    - drm/xe: Increase TDF timeout
    - io_uring: fix nr_segs calculation in io_import_kbuf
    - ublk: add parameter `struct io_uring_cmd *` to ublk_prep_auto_buf_reg()
    - ublk: add `union ublk_io_buf` with improved naming
    - ublk: refactor auto buffer register in ublk_dispatch_req()
    - drm/xe/oa: Always set OAG_OAGLBCTXCTRL_COUNTER_RESUME
    - amd/iommu: Preserve domain ids inside the kdump kernel
    - arm64: dts: mediatek: Apply mt8395-radxa DT overlay at build time
    - Input: apple_z2 - fix reading incorrect reports after exiting sleep
    - Input: xpad - add support for CRKD Guitars
    - platform/x86: intel_pmc_ipc: fix ACPI buffer memory leak
    - x86/mm/tlb/trace: Export the TLB_REMOTE_WRONG_CPU enum in
      <trace/events/tlb.h>
    - ASoC: fsl_sai: Constrain sample rates from audio PLLs only in master
      mode
    - ASoC: SDCA: support Q7.8 volume format
    - ASoC: ops: fix snd_soc_get_volsw for sx controls
    - scsi: lpfc: Fix reusing an ndlp that is marked NLP_DROPPED during FLOGI
    - usb: xhci: Don't unchain link TRBs on quirky HCs
    - platform/x86: wmi-gamezone: Add Legion Go 2 Quirks
    - hwmon: (emc2305) fix device node refcount leak in error path
    - hwmon: (emc2305) fix double put in emc2305_probe_childs_from_dt
    - ublk: add helpers to check ublk_device flags
    - rust/drm/gem: Fix missing header in `Object` rustdoc
    - rust: dma: add helpers for architectures without CONFIG_HAS_DMA
    - samples: rust: fix endianness issue in rust_driver_pci
    - rust: io: define ResourceSize as resource_size_t
    - rust: io: move ResourceSize to top-level io module
    - rust: io: add typedef for phys_addr_t
    - clk: keystone: syscon-clk: fix regmap leak on probe failure
    - printk: Avoid scheduling irq_work on suspend
    - sched_ext: Fix the memleak for sch->helper objects
    - sched_ext: Fix bypass depth leak on scx_enable() failure
    - dt-bindings: clock: mmcc-sdm660: Add missing MDSS reset
    - phy: exynos5-usbdrd: fix clock prepare imbalance
    - efi: Add missing static initializer for efi_mm::cpus_allowed_lock
    - crypto: scatterwalk - Fix memcpy_sglist() to always succeed
    - printk: Allow printk_trigger_flush() to flush all types
    - printk: Avoid irq_work for printk_deferred() on suspend
    - mm/huge_memory: add pmd folio to ds_queue in do_huge_zero_wp_pmd()
    - crash: let architecture decide crash memory export to iomem_resource
    - usb: typec: ucsi: huawei-gaokin: add DRM dependency
    - f2fs: clean up w/ get_left_section_blocks()
    - f2fs: fix to not account invalid blocks in get_left_section_blocks()
    - KVM: selftests: Forcefully override ARCH from x86_64 to x86
    - KVM: Fix last_boosted_vcpu index assignment bug
    - KVM: TDX: Explicitly set user-return MSRs that *may* be clobbered by the
      TDX-Module
    - KVM: x86: Apply runtime updates to current CPUID during
      KVM_SET_CPUID{,2}
    - KVM: selftests: Add missing "break" in rseq_test's param parsing
    - xfs: fix the zoned RT growfs check for zone alignment
    - xfs: validate that zoned RT devices are zone aligned
    - arm64/gcs: Flush the GCS locking state on exec
    - ALSA: hda/realtek: Add Asus quirk for TAS amplifiers
    - NFSD: Clear TIME_DELEG in the suppattr_exclcreat bitmap
    - cgroup: rstat: use LOCK CMPXCHG in css_rstat_updated
    - gpio: loongson: Switch 2K2000/3000 GPIO to BYTE_CTRL_MODE
    - crypto: arm64/ghash - Fix incorrect output from ghash-neon
    - zloop: fail zone append operations that are targeting full zones
    - zloop: make the write pointer of full zones invalid
    - vfio: Fix ksize arg while copying user struct in
      vfio_df_ioctl_bind_iommufd()
    - rtla/timerlat_bpf: Stop tracing on user latency
    - pwm: rzg2l-gpt: Allow checking period_tick cache value only if sibling
      channel is enabled
    - lib/crypto: riscv: Depend on RISCV_EFFICIENT_VECTOR_UNALIGNED_ACCESS
    - [Config] Disable accelerated crypto for riscv64 by default
    - io_uring/rsrc: fix lost entries after cloned range
    - ARM: dts: microchip: sama7d65: fix uart fifo size to 32
    - ice: add missing ice_deinit_hw() in devlink reinit path
    - arp: do not assume dev_hard_header() does not change skb->head
    - firmware: imx: scu-irq: Set mu_resource_id before get handle
    - tpm: Compare HMAC values in constant time
    - keys/trusted_keys: fix handle passed to tpm_buf_append_name during
      unseal
    - intel_th: fix device leak on output open()
    - Upstream stable to v6.18.2, v6.12.64, v6.18.3
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68791
    - fuse: missing copy_finish in fuse-over-io-uring argument copies
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68805
    - fuse: fix io-uring list corruption for terminated non-committed requests
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68812
    - media: iris: Add sanity check for stop streaming
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71117
    - block: Remove queue freezing from several sysfs store callbacks
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71070
    - ublk: clean up user copy references on ublk server exit
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71124
    - drm/msm/a6xx: move preempt_prepare_postamble after error check
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71115
    - um: init cpu_tasks[] earlier
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68823
    - ublk: fix deadlock when reading partition table
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68793
    - drm/amdgpu: fix a job->pasid access race in gpu recovery
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68807
    - block: fix race between wbt_enable_default and IO submission
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68768
    - inet: frags: flush pending skbs in fqdir_pre_exit()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71140
    - media: mediatek: vcodec: Use spinlock for context list protection lock
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71156
    - gve: defer interrupt enabling until NAPI registration
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2024-36347
    - x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix Halo
    - x86/microcode/AMD: Select which microcode patch to load
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71068
    - svcrdma: bound check rq_pages index in inline path
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68772
    - f2fs: fix to avoid updating compression context during writeback
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71105
    - f2fs: use global inline_xattr_slab instead of per-sb slab cache
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71130
    - drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71138
    - drm/msm/dpu: Add missing NULL pointer check for pingpong interface
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71083
    - drm/ttm: Avoid NULL pointer deref for evicted BOs
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71099
    - drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71079
    - net: nfc: fix deadlock between nfc_unregister_device and
      rfkill_fop_write
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71129
    - LoongArch: BPF: Sign extend kfunc call arguments
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71093
    - e1000: fix OOB in e1000_tbi_should_accept()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71084
    - RDMA/cm: Fix leaking the multicast GID table reference
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71096
    - RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71136
    - media: adv7842: Avoid possible out-of-bounds array accesses in
      adv7842_cp_log_status()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71143
    - clk: samsung: exynos-clkout: Assign .num before accessing .hws
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71078
    - powerpc/64s/slb: Fix SLB multihit issue during SLB preload
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71089
    - iommu: disable SVA when CONFIG_X86 is set
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71081
    - ASoC: stm32: sai: fix OF node leak on probe
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71153
    - ksmbd: Fix memory leak in get_file_all_info()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71135
    - md/raid5: fix possible null-pointer dereferences in
      raid5_store_group_thread_cnt()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71157
    - RDMA/core: always drop device refcount in ib_del_sub_device_and_put()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71133
    - RDMA/irdma: avoid invalid read in irdma_net_event
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71080
    - ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71086
    - net: rose: fix invalid array index in rose_kill_by_device()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71097
    - ipv4: Fix reference count leak when using error routes with nexthop
      objects
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71085
    - ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71095
    - net: stmmac: fix the crash issue for zero copy XDP_TX action
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71137
    - octeontx2-pf: fix "UBSAN: shift-out-of-bounds error"
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71101
    - platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package
      parsing
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71094
    - net: usb: asix: validate PHY address before use
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71132
    - smc91x: fix broken irq-context in PREEMPT_RT
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71154
    - net: usb: rtl8150: fix memory leak on usb_submit_urb() failure
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71091
    - team: fix check for port enabled in
      team_queue_override_port_prio_changed()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71098
    - ip6_gre: make ip6gre_header() robust
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71082
    - Bluetooth: btusb: revert use of devm_kzalloc in btusb
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71131
    - crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71087
    - iavf: fix off-by-one issues in iavf_config_rss_reg()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71100
    - wifi: rtlwifi: 8192cu: fix tid out of range in rtl92cu_tx_fill_desc()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68821
    - fuse: fix readahead reclaim deadlock
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71071
    - iommu/mediatek: fix use-after-free on probe deferral
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71111
    - hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71113
    - crypto: af_alg - zero initialize memory allocated via sock_kmalloc
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71149
    - io_uring/poll: correctly handle io_poll_add() return value on update
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68778
    - btrfs: don't log conflicting inode if it's a dir moved in the current
      transaction
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71119
    - powerpc/kexec: Enable SMT before waking offline CPUs
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71120
    - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in
      gss_read_proxy_verf
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68811
    - svcrdma: use rc_pageoff for memcpy byte offset
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68803
    - NFSD: NFSv4 file creation neglects setting ACL
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71148
    - net/handshake: restore destructor on submit failure
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68788
    - fsnotify: do not generate ACCESS/MODIFY events on child for special
      files
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71125
    - tracing: Do not register unsupported perf events
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68784
    - xfs: fix a UAF problem in xattr repair
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71104
    - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV
      timer
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71116
    - libceph: make decode_pool() more resilient against corrupted osdmaps
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71121
    - parisc: Do not reprogram affinitiy on ASP chip
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71102
    - scs: fix a wrong parameter in __scs_magic
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68804
    - platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68771
    - ocfs2: fix kernel BUG in ocfs2_find_victim_chain
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68808
    - media: vidtv: initialize local pointers upon transfer of memory
      ownership
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68810
    - KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68769
    - f2fs: fix return value of f2fs_recover_fsync_data()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71069
    - f2fs: invalidate dentry cache on failed whiteout creation
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68796
    - f2fs: fix to avoid updating zero-sized extent in extent cache
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71065
    - f2fs: fix to avoid potential deadlock
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71107
    - f2fs: ensure node page reads complete before f2fs_put_super() finishes
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68782
    - scsi: target: Reset t_task_cdb pointer in error case
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71075
    - scsi: aic94xx: fix use-after-free in device removal path
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68818
    - scsi: Revert "scsi: qla2xxx: Perform lockless command completion in
      abort path"
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68797
    - char: applicom: fix NULL pointer dereference in ac_ioctl
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68781
    - usb: phy: fsl-usb: Fix use-after-free in delayed work during device
      removal
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68819
    - media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71126
    - mptcp: avoid deadlock on fallback while reinjecting
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68820
    - ext4: xattr: fix null pointer deref in ext4_raw_inode()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71123
    - ext4: fix string copying in parse_apply_sb_mount_options()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71077
    - tpm: Cap the number of PCR banks
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68814
    - io_uring: fix filename leak in __io_openat_prep()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71147
    - KEYS: trusted: Fix a memory leak in tpm2_load_cmd
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71151
    - cifs: Fix memory and information leak in smb3_reconfigure()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71109
    - MIPS: ftrace: Fix memory corruption when kernel is located beyond 32
      bits
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71108
    - usb: typec: ucsi: Handle incorrect num_connectors capability
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71114
    - via_wdt: fix critical boot hang due to unnamed resource allocation
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68783
    - ALSA: usb-mixer: us16x08: validate meter packet indices
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68776
    - net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68773
    - spi: fsl-cpm: Check length parity before switching to 16 bit mode
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68822
    - Input: alps - fix use-after-free bugs caused by dev3_register_work
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71073
    - Input: lkkbd - disable pending work before freeing device
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68777
    - Input: ti_am335x_tsc - fix off-by-one error in wire_order validation
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68806
    - ksmbd: fix buffer validation by including null terminator size in EA
      length
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71150
    - ksmbd: Fix refcount leak when invalid session is found on session lookup
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68786
    - ksmbd: skip lock-range check on equal size to avoid size==0 underflow
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71076
    - drm/xe/oa: Limit num_syncs to prevent oversized allocations
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68802
    - drm/xe: Limit num_syncs to prevent oversized allocations
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68789
    - hwmon: (ibmpex) fix use-after-free in high/low store
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71112
    - net: hns3: add VLAN id validation before using
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71064
    - net: hns3: using the num_tqps in the vf driver to apply for resources
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68775
    - net/handshake: duplicate handshake cancellations leak socket
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68816
    - net/mlx5: fw_tracer, Validate format string parameters
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68795
    - ethtool: Avoid overflowing userspace buffer on stats query
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71122
    - iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68815
    - net/sched: ets: Remove drr class from the active list if it changes to
      strict
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68799
    - caif: fix integer underflow in cffrml_receive()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68813
    - ipvs: fix ipv4 null-ptr-deref in route error path
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68785
    - net: openvswitch: fix middle attribute validation in push_nsh() action
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68770
    - bnxt_en: Fix XDP_TX path
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68800
    - mlxsw: spectrum_mr: Fix use-after-free when updating multicast route
      stats
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68801
    - mlxsw: spectrum_router: Fix neighbour use-after-free
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71066
    - net/sched: ets: Always remove class from active list before deleting in
      ets_qdisc_change
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68787
    - netrom: Fix memory leak in nr_sendmsg()
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68809
    - ksmbd: vfs: fix race on m_flags in vfs_cache
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68817
    - ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68767
    - hfsplus: Verify inode mode when loading from disk
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68774
    - hfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71067
    - ntfs: set dummy blocksize to read boot_block when mounting
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71118
    - ACPICA: Avoid walking the Namespace if start_node is NULL
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68780
    - sched/deadline: only set free_cpus for online runqueues
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68798
    - perf/x86/amd: Check event before enable to avoid GPF
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68794
    - iomap: adjust read range correctly for non-block-aligned positions
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-71072
    - shmem: fix recovery on rename failures
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68351
    - exfat: fix refcount leak in exfat_find
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68736
    - landlock: Fix handling of disconnected directories
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68353
    - net: vxlan: prevent NULL deref in vxlan_xmit_one
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68745
    - scsi: qla2xxx: Clear cmds after chip reset
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68365
    - fs/ntfs3: Initialize allocated memory before use
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68368
    - md: init bioset in mddev_init
  * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250) //
    CVE-2025-68725
    - bpf: Do not let BPF test infra emit invalid GSO types to stack
  * CVE-2026-23111
    - netfilter: nf_tables: fix inverted genmask check in
      nft_map_catchall_activate()
  * CVE-2026-23209
    - macvlan: fix error recovery in macvlan_common_newlink()
  * CVE-2026-23074
    - net/sched: Enforce that teql can only be used as root qdisc
  * CVE-2026-23060
    - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN
      spec

linux-azure-fde-6.17 (6.17.0-1008.8~24.04.1) noble; urgency=medium

  * noble/linux-azure-fde-6.17: 6.17.0-1008.8~24.04.1 -proposed tracker (LP: #2144272)

  [ Ubuntu-azure-fde: 6.17.0-1008.8 ]

  * questing/linux-azure-fde: 6.17.0-1008.8 -proposed tracker (LP: #2144273)
  [ Ubuntu-azure: 6.17.0-1011.11 ]
  * questing/linux-azure: 6.17.0-1011.11 -proposed tracker (LP: #2144277)
  [ Ubuntu: 6.17.0-20.20 ]
  * questing/linux: 6.17.0-20.20 -proposed tracker (LP: #2144297)
  * CVE-2026-23074
    - net/sched: Enforce that teql can only be used as root qdisc
  * CVE-2026-23060
    - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN
      spec
  * CVE-2026-23111
    - netfilter: nf_tables: fix inverted genmask check in
      nft_map_catchall_activate()

linux-azure-fde-6.17 (6.17.0-1007.7~24.04.1) noble; urgency=medium

  [ Ubuntu-azure-fde: 6.17.0-1007.7 ]

  [ Ubuntu-azure: 6.17.0-1010.10 ]
  [ Ubuntu: 6.17.0-19.19 ]
  * Questing: Failed to query NVIDIA devices (LP: #2143480)
    - [Config] disable NOVA_CORE
  * Miscellaneous upstream changes
    - apparmor: validate DFA start states are in bounds in unpack_pdb
    - apparmor: fix memory leak in verify_header
    - apparmor: replace recursive profile removal with iterative approach
    - apparmor: fix: limit the number of levels of policy namespaces
    - apparmor: fix side-effect bug in match_char() macro usage
    - apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
    - apparmor: Fix double free of ns_name in aa_replace_profiles()
    - apparmor: fix unprivileged local user can do privileged policy
      management
    - apparmor: fix differential encoding verification
    - apparmor: fix race on rawdata dereference
    - apparmor: fix race between freeing data and fs accessing it

linux-azure-fde-6.17 (6.17.0-1006.6~24.04.1) noble; urgency=medium

  * noble/linux-azure-fde-6.17: 6.17.0-1006.6~24.04.1 -proposed tracker (LP: #2141124)

  [ Ubuntu-azure-fde: 6.17.0-1006.6 ]

  * questing/linux-azure-fde: 6.17.0-1006.6 -proposed tracker (LP: #2141125)
  [ Ubuntu-azure: 6.17.0-1009.9 ]
  * questing/linux-azure: 6.17.0-1009.9 -proposed tracker (LP: #2141129)
  * [Mana Direct][Backport] Patch: net: mana: Support HW link state events
    (LP: #2139695)
    - net: mana: Support HW link state events
  * [storvsc][Backport] Backport storvsc patch for handling MODE_SENSE_10
    (LP: #2139232)
    - scsi: storvsc: Process unsupported MODE_SENSE_10
  [ Ubuntu: 6.17.0-16.16 ]
  * questing/linux: 6.17.0-16.16 -proposed tracker (LP: #2141148)
  * Packaging resync (LP: #1786013)
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/2026.02.09)
  * Support Intel Scorpius Peak, Whale Peak WiFi/Bluetooth for Intel Panther
    Lake platforms (LP: #2116169)
    - Bluetooth: btintel_pcie: Add Bluetooth core/platform as comments
    - Bluetooth: btintel_pcie: Add id of Scorpious, Panther Lake-H484
  * Boot up hang with ucsi call trace while plug power cord or device on tbt5
    port (LP: #2127764)
    - SAUCE: usb: typec: ucsi: Fix workqueue destruction race during connector
      cleanup
  * net:rtnetlink.sh in ubuntu_kernel_selftests failed with FAIL: address
    proto IPv4 / IPv6 (LP: #2031531)
    - selftests: rtnetlink: skip tests if tools or feats are missing
  * TBT call trace while connecting TBT4 monitor on TBT5 port (LP: #2137613)
    - drm/i915/psr: Do not unnecessarily remove underrun on idle PSR WA
  * No output on external monitor when connecting to dell dock (LP: #2131066)
    - drm/i915/dsc: Add helper to enable the DSC configuration for a CRTC
    - drm/i915/dp: Ensure the FEC state stays disabled for UHBR links
    - drm/i915/dp: Export helper to determine if FEC on non-UHBR links is
      required
    - drm/i915/dp_mst: Reuse the DP-SST helper function to compute FEC config
    - drm/i915/dp_mst: Track DSC enabled status on the MST link
    - drm/i915/dp_mst: Recompute all MST link CRTCs if DSC gets enabled on the
      link
    - drm/i915/psr: Underrun on idle PSR wa only when pkgc latency > delayed
      vblank
    - drm/i915/display: Remove unused declarations of intel_io_*
    - drm/i915/dp: Fix panel replay when DSC is enabled
  * [questing] kernel BUG at lib/string_helpers.c:1043! (LP: #2129580)
    - erspan: Initialize options_len before referencing options.
  * Hotplug dock with monitor leads to call trace (LP: #2130998)
    - drm/i915/psr: Check pause counter before continuing to PSR activation
    - drm/i915/psr: Check PSR pause counter in __psr_wait_for_idle_locked
  * [SRU] Fix the error during suspend on cs42l43 (LP: #2138423)
    - mfd: cs42l43: Remove IRQ masking in suspend
    - ASoC: cs42l43: Rename system suspend callback and fix debug print
    - ASoC: cs42l43: Store IRQ domain in codec private data
    - ASoC: cs42l43: Disable IRQs in system suspend
    - ASoC: cs42l43: Shutdown jack detection on suspend
  * noble/plucky: ubuntu_kselftests_ftrace fails 7 ftrace:test.d tests for
    riscv64 on openstack:riscv64.vm (LP: #2124276)
    - riscv: Enable ARCH_HAVE_NMI_SAFE_CMPXCHG
    - [Config] Enable ARCH_HAVE_NMI_SAFE_CMPXCHG for riscv64
  * Got call trace when plug in device/AC in type-c port(both TBT5/TBT4)
    (LP: #2138192)
    - usb: typec: ucsi: Add support for READ_POWER_LEVEL command
    - usb: typec: ucsi: Add check for UCSI version
  * Export CWSR size to userspace (LP: #2134491)
    - drm/amdkfd: bump minimum vgpr size for gfx1151
    - drm/amdkfd: Export the cwsr_size and ctl_stack_size to userspace
  * [SRU] add pmc c6 support of Arrow Lake (LP: #2137615)
    - platform/x86:intel/pmc: Update Arrow Lake telemetry GUID
    - platform/x86:intel/pmc: Add support for multiple DMU GUIDs
    - platform/x86:intel/pmc: Add DMU GUID to Arrow Lake U/H
  * net:tap in ubuntu_kselftests_net fails on Noble (buffer overflow detected)
    (LP: #2067642)
    - SAUCE: selftests: net: fix "buffer overflow detected" for tap.c
  * MT7925 wifi is hard blocked on HP's machine (LP: #2127044)
    - SAUCE: wifi: mt76: mt7925: add DMI quirk for HP Z2 Mini G1a Workstation
  * No on-screen keyboard on dell tablets (LP: #2122398)
    - platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to VGBS DMI
      quirks
  * Enable RTL ASPM for more new Dell platforms (LP: #2133144)
    - SAUCE: r8169: Add more Dell platforms to enable ASPM
  * Enable RTL ASPM for new Dell platforms (LP: #2121200)
    - SAUCE: r8169: enable ASPM on all new Dell platforms
  * Questing update: v6.17.13 upstream stable release (LP: #2139960)
    - smack: deduplicate "does access rule request transmutation"
    - smack: fix bug: SMACK64TRANSMUTE set on non-directory
    - smack: deduplicate xattr setting in smack_inode_init_security()
    - smack: always "instantiate" inode in smack_inode_init_security()
    - smack: fix bug: invalid label of unix socket file
    - smack: fix bug: setting task label silently ignores input garbage
    - accel/ivpu: Ensure rpm_runtime_put in case of engine reset/resume fail
    - drm/panel: visionox-rm69299: Fix clock frequency for SHIFT6mq
    - drm/panel: visionox-rm69299: Don't clear all mode flags
    - accel/ivpu: Rework bind/unbind of imported buffers
    - accel/ivpu: Make function parameter names consistent
    - accel/ivpu: Fix DCT active percent format
    - bpf: Cleanup unused func args in rqspinlock implementation
    - tools/nolibc: handle NULL wstatus argument to waitpid()
    - USB: Fix descriptor count when handling invalid MBIM extended descriptor
    - perf bpf_counter: Fix opening of "any"(-1) CPU events
    - ima: Attach CREDS_CHECK IMA hook to bprm_creds_from_file LSM hook
    - pinctrl: renesas: rzg2l: Fix PMC restore
    - clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle callback
    - clk: renesas: cpg-mssr: Read back reset registers to assure values
      latched
    - drm: atmel-hlcdc: fix atmel_xlcdc_plane_setup_scaler()
    - HID: logitech-hidpp: Do not assume FAP in hidpp_send_message_sync()
    - remoteproc: imx_rproc: Fix runtime PM cleanup and improve remove path
    - objtool: Fix standalone --hacks=jump_label
    - objtool: Fix weak symbol detection
    - accel/ivpu: Fix race condition when mapping dmabuf
    - perf parse-events: Fix legacy cache events if event is duplicated in a
      PMU
    - wifi: ath10k: move recovery check logic into a new work
    - wifi: ath11k: restore register window after global reset
    - wifi: ath12k: fix VHT MCS assignment
    - wifi: ath12k: fix TX and RX MCS rate configurations in HE mode
    - sched/fair: Forfeit vruntime on yield
    - irqchip/bcm2712-mip: Fix OF node reference imbalance
    - irqchip/bcm2712-mip: Fix section mismatch
    - irqchip/irq-bcm7038-l1: Fix section mismatch
    - irqchip/irq-bcm7120-l2: Fix section mismatch
    - irqchip/irq-brcmstb-l2: Fix section mismatch
    - irqchip/imx-mu-msi: Fix section mismatch
    - irqchip/renesas-rzg2l: Fix section mismatch
    - irqchip/starfive-jh8100: Fix section mismatch
    - irqchip/qcom-irq-combiner: Fix section mismatch
    - crypto: authenc - Correctly pass EINPROGRESS back up to the caller
    - dt-bindings: clock: qcom,x1e80100-gcc: Add missing USB4 clocks/resets
    - clk: qcom: gcc-x1e80100: Add missing USB4 clocks/resets
    - rculist: Add hlist_nulls_replace_rcu() and
      hlist_nulls_replace_init_rcu()
    - inet: Avoid ehash lookup race in inet_ehash_insert()
    - inet: Avoid ehash lookup race in inet_twsk_hashdance_schedule()
    - iio: imu: st_lsm6dsx: Fix measurement unit for odr struct member
    - firmware: qcom: tzmem: fix qcom_tzmem_policy kernel-doc
    - block/mq-deadline: Introduce dd_start_request()
    - block/mq-deadline: Switch back to a single dispatch list
    - arm64: dts: freescale: imx8mp-venice-gw7905-2x: remove duplicate usdhc1
      props
    - arm64: dts: imx8mm-venice-gw72xx: remove unused sdhc1 pinctrl
    - arm64: dts: imx8mp-venice-gw702x: remove off-board uart
    - arm64: dts: imx8mp-venice-gw702x: remove off-board sdhc1
    - arm64: dts: imx95-15x15-evk: add fan-supply property for pwm-fan
    - perf annotate: Check return value of evsel__get_arch() properly
    - arm64: dts: exynos: gs101: fix sysreg_apm reg property
    - PCI: rcar-gen2: Drop ARM dependency from PCI_RCAR_GEN2
    - uio: uio_fsl_elbc_gpcm:: Add null pointer check to
      uio_fsl_elbc_gpcm_probe
    - tty: introduce tty_port_tty guard()
    - tty: serial: imx: Only configure the wake register when device is set as
      wakeup source
    - clk: qcom: camcc-sm8550: Specify Titan GDSC power domain as a parent to
      other
    - clk: qcom: camcc-sm6350: Specify Titan GDSC power domain as a parent to
      other
    - clk: qcom: gcc-sm8750: Add a new frequency for sdcc2 clock
    - clk: qcom: gcc-ipq5424: Correct the icc_first_node_id
    - clk: qcom: camcc-sm6350: Fix PLL config of PLL2
    - clk: qcom: camcc-sm7150: Fix PLL config of PLL2
    - soc: qcom: gsbi: fix double disable caused by devm
    - crypto: hisilicon/qm - restore original qos values
    - wifi: ath11k: fix VHT MCS assignment
    - s390/smp: Fix fallback CPU detection
    - scsi: ufs: core: Move the ufshcd_enable_intr() declaration
    - s390/ap: Don't leak debug feature files if AP instructions are not
      available
    - tools/power turbostat: Regression fix Uncore MHz printed in hex
    - wifi: ath12k: restore register window after global reset
    - leds: upboard: Fix module alias
    - PCI: endpoint: pci-epf-test: Fix sleeping function being called from
      atomic context
    - arm64: dts: ti: k3-am62p: Fix memory ranges for GPU
    - firmware: imx: scu-irq: fix OF node leak in
    - arm64: dts: qcom: x1e80100: Fix compile warnings for USB HS controller
    - arm64: dts: qcom: x1e80100: Add missing quirk for HS only USB controller
    - arm64: dts: qcom: sdm845-starqltechn: remove (address|size)-cells
    - arm64: dts: qcom: starqltechn: remove extra empty line
    - arm64: dts: qcom: sdm845-starqltechn: fix max77705 interrupts
    - arm64: dts: qcom: sdm845-oneplus: Correct gpio used for slider
    - arm64: dts: qcom: qcm6490-fairphone-fp5: Add supplies to simple-fb node
    - arm64: dts: qcom: sm8650: set ufs as dma coherent
    - arm64: dts: qcom: qcm6490-shift-otter: Add missing reserved-memory
    - arm64: dts: qcom: sdm845-starqltechn: Fix i2c-gpio node name
    - perf hwmon_pmu: Fix uninitialized variable warning
    - phy: mscc: Fix PTP for VSC8574 and VSC8572
    - sctp: Defer SCTP_DBG_OBJCNT_DEC() to sctp_destroy_sock().
    - arm64: dts: qcom: qcm2290: Add CCI node
    - arm64: dts: qcom: qcm2290: Fix camss register prop ordering
    - ARM: dts: renesas: gose: Remove superfluous port property
    - ARM: dts: renesas: r9a06g032-rzn1d400-db: Drop invalid #cells properties
    - drm/amdgpu: add userq object va track helpers
    - drm/amdgpu/userq: fix SDMA and compute validation
    - wifi: iwlwifi: mld: add null check for kzalloc() in
      iwl_mld_send_proto_offload()
    - Revert "mtd: rawnand: marvell: fix layouts"
    - mtd: nand: relax ECC parameter validation check
    - mtd: rawnand: lpc32xx_slc: fix GPIO descriptor leak on probe error and
      remove
    - perf: Remove get_perf_callchain() init_nr argument
    - bpf: Refactor stack map trace depth calculation into helper function
    - perf/x86/intel/cstate: Remove PC3 support from LunarLake
    - task_work: Fix NMI race condition
    - x86/dumpstack: Prevent KASAN false positive warnings in __show_regs()
    - accel/ivpu: Remove skip of dma unmap for imported buffers
    - tools/nolibc/stdio: let perror work when NOLIBC_IGNORE_ERRNO is set
    - tools/nolibc/dirent: avoid errno in readdir_r
    - clk: qcom: gcc-qcs615: Update the SDCC clock to use shared_floor_ops
    - soc: qcom: smem: fix hwspinlock resource leak in probe error paths
    - pinctrl: stm32: fix hwspinlock resource leak in probe function
    - drm: nova: select NOVA_CORE
    - [Config] select NOVA_CORE
    - gpu: nova-core: select RUST_FW_LOADER_ABSTRACTIONS
    - pidfs: add missing PIDFD_INFO_SIZE_VER1
    - pidfs: add missing BUILD_BUG_ON() assert on struct pidfd_info
    - i3c: fix refcount inconsistency in i3c_master_register
    - i3c: master: svc: Prevent incomplete IBI transaction
    - random: use offstack cpumask when necessary
    - wifi: ath12k: fix potential memory leak in ath12k_wow_arp_ns_offload()
    - wifi: ath12k: fix reusing m3 memory
    - wifi: ath12k: fix error handling in creating hardware group
    - wifi: ath12k: unassign arvif on scan vdev create failure
    - interconnect: qcom: msm8996: add missing link to SLAVE_USB_HS
    - arm64: dts: qcom: msm8996: add interconnect paths to USB2 controller
    - accel/amdxdna: Fix incorrect command state for timed out job
    - interconnect: debugfs: Fix incorrect error handling for NULL path
    - arm64: dts: renesas: sparrow-hawk: Fix full-size DP connector node name
      and labels
    - drm/imagination: Fix reference to
      devm_platform_get_and_ioremap_resource()
    - perf lock contention: Load kernel map before lookup
    - perf record: skip synthesize event when open evsel failed
    - timers/migration: Convert "while" loops to use "for"
    - timers/migration: Remove locking on group connection
    - timers/migration: Fix imbalanced NUMA trees
    - power: supply: rt5033_charger: Fix device node reference leaks
    - power: supply: cw2015: Check devm_delayed_work_autocancel() return code
    - power: supply: max17040: Check iio_read_channel_processed() return code
    - power: supply: rt9467: Return error on failure in
      rt9467_set_value_from_ranges()
    - power: supply: rt9467: Prevent using uninitialized local variable in
      rt9467_set_value_from_ranges()
    - power: supply: wm831x: Check wm831x_set_bits() return value
    - power: supply: apm_power: only unset own apm_get_power_status
    - scsi: target: Do not write NUL characters into ASCII configfs output
    - scsi: target: Fix LUN/device R/W and total command stats
    - fs/9p: Don't open remote file with APPEND mode when writeback cache is
      used
    - drm/panthor: Handle errors returned by drm_sched_entity_init()
    - drm/panthor: Fix group_free_queue() for partially initialized queues
    - drm/panthor: Fix race with suspend during unplug
    - firmware: ti_sci: Set IO Isolation only if the firmware is capable
    - cleanup: fix scoped_class()
    - libbpf: Fix parsing of multi-split BTF
    - ARM: dts: am335x-netcom-plus-2xx: add missing GPIO labels
    - ARM: dts: omap3: beagle-xm: Correct obsolete TWL4030 power compatible
    - ARM: dts: omap3: n900: Correct obsolete TWL4030 power compatible
    - entry,unwind/deferred: Fix unwind_reset_info() placement
    - x86/boot: Fix page table access in 5-level to 4-level paging transition
    - efi/libstub: Fix page table access in 5-level to 4-level paging
      transition
    - locktorture: Fix memory leak in param_set_cpumask()
    - wifi: rtw89: usb: use common error path for skbs in
      rtw89_usb_rx_handler()
    - wifi: rtw89: usb: fix leak in rtw89_usb_write_port()
    - mfd: da9055: Fix missing regmap_del_irq_chip() in error path
    - wifi: ath12k: Fix timeout error during beacon stats retrieval
    - ext4: correct the checking of quota files before moving extents
    - accel/amdxdna: Fix dma_fence leak when job is canceled
    - io_uring: use WRITE_ONCE for user shared memory
    - perf/x86/intel: Correct large PEBS flag check
    - regulator: core: disable supply if enabling main regulator fails
    - md: delete mddev kobj before deleting gendisk kobj
    - scsi: stex: Fix reboot_notifier leak in probe error path
    - [Config] remove most i2c driver
    - iio: imu: bmi270: fix dev_err_probe error msg
    - dt-bindings: PCI: amlogic: Fix the register name of the DBI region
    - RDMA/rtrs: server: Fix error handling in get_or_create_srv
    - ARM: dts: stm32: stm32mp157c-phycore: Fix STMPE811 touchscreen node
      properties
    - drm/panthor: Fix potential memleak of vma structure
    - scsi: ufs: core: fix incorrect buffer duplication in
      ufshcd_read_string_desc()
    - md: delete md_redundancy_group when array is becoming inactive
    - cpufreq/amd-pstate: Call cppc_set_auto_sel() only for online CPUs
    - powerpc/kdump: Fix size calculation for hot-removed memory ranges
    - powerpc/32: Fix unpaired stwcx. on interrupt exit
    - wifi: cw1200: Fix potential memory leak in cw1200_bh_rx_helper()
    - coresight: Change device mode to atomic type
    - coresight: etm4x: Always set tracer's device mode on target CPU
    - coresight: etm3x: Always set tracer's device mode on target CPU
    - coresight: etm4x: Correct polling IDLE bit
    - coresight: etm4x: Add context synchronization before enabling trace
    - coresight: etm4x: Properly control filter in CPU idle with FEAT_TRF
    - perf tools: Fix missing feature check for inherit + SAMPLE_READ
    - drm/tidss: Remove max_pclk_khz and min_pclk_khz from tidss display
      features
    - drm/tidss: Move OLDI mode validation to OLDI bridge mode_valid hook
    - clk: renesas: r9a09g077: Propagate rate changes to parent clocks
    - clk: renesas: r9a06g032: Fix memory leak in error path
    - lib/vsprintf: Check pointer before dereferencing in time_and_date()
    - ocfs2: use correct endian in ocfs2_dinode_has_extents
    - ACPI: property: Fix fwnode refcount leak in
      acpi_fwnode_graph_parse_endpoint()
    - scsi: sim710: Fix resource leak by adding missing ioport_unmap() calls
    - leds: netxbig: Fix GPIO descriptor leak in error paths
    - accel/amdxdna: Clear mailbox interrupt register during channel creation
    - accel/amdxdna: Fix deadlock between context destroy and job timeout
    - PCI: keystone: Exit ks_pcie_probe() for invalid mode
    - arm64: dts: rockchip: Move the EEPROM to correct I2C bus on Radxa ROCK
      5A
    - arm64: dts: rockchip: Add eeprom vcc-supply for Radxa ROCK 5A
    - arm64: dts: rockchip: Add eeprom vcc-supply for Radxa ROCK 3C
    - crypto: iaa - Fix incorrect return value in save_iaa_wq()
    - arm64: dts: qcom: qrb2210-rb1: Fix UART3 wakeup IRQ storm
    - drm/msm/dpu: drop dpu_hw_dsc_destroy() prototype
    - ps3disk: use memcpy_{from,to}_bvec index
    - PCI: Prevent resource tree corruption when BAR resize fails
    - bpf: Prevent nesting overflow in bpf_try_get_buffers
    - bpf: Handle return value of ftrace_set_filter_ip in register_fentry
    - selftests/bpf: Fix failure paths in send_signal test
    - mshv: Fix deposit memory in MSHV_ROOT_HVCALL
    - watchdog: wdat_wdt: Fix ACPI table leak in probe function
    - watchdog: starfive: Fix resource leak in probe error path
    - fuse_ctl_add_conn(): fix nlink breakage in case of early failure
    - tracefs: fix a leak in eventfs_create_events_dir()
    - NFSD/blocklayout: Fix minlength check in proc_layoutget
    - arm64: dts: imx95-tqma9596sa: fix TPM5 pinctrl node name
    - arm64: dts: imx95-tqma9596sa: reduce maximum FlexSPI frequency to 66MHz
    - block/blk-throttle: Fix throttle slice time for SSDs
    - drm/msm: Fix NULL pointer dereference in crashstate_get_vm_logs()
    - drm/msm: fix missing NULL check after kcalloc in crashstate_get_bos()
    - drm/msm/a2xx: stop over-complaining about the legacy firmware
    - net: phy: Add helper for fixing RGMII PHY mode based on internal mac
      delay
    - net: stmmac: dwmac-sophgo: Add phy interface filter
    - powerpc/64s/hash: Restrict stress_hpt_struct memblock region to within
      RMA limit
    - powerpc/64s/ptdump: Fix kernel_hash_pagetable dump for ISA v3.00 HPTE
      format
    - net: stmmac: Fix VLAN 0 deletion in vlan_del_hw_rx_fltr()
    - fs/ntfs3: out1 also needs to put mi
    - fs/ntfs3: Prevent memory leaks in add sub record
    - drm/mediatek: Fix CCORR mtk_ctm_s31_32_to_s1_n function issue
    - drm/msm/a6xx: Flush LRZ cache before PT switch
    - drm/msm/a6xx: Fix the gemnoc workaround
    - drm/msm/a6xx: Improve MX rail fallback in RPMH vote init
    - spi: sophgo: Fix incorrect use of bus width value macros
    - ipv6: clear RA flags when adding a static route
    - perf arm_spe: Fix memset subclass in operation
    - pwm: bcm2835: Make sure the channel is enabled after pwm_request()
    - scsi: ufs: rockchip: Reset controller on PRE_CHANGE of hce enable notify
    - net: phy: realtek: create rtl8211f_config_rgmii_delay()
    - iommu/vt-d: Fix unused invalidation hint in qi_desc_iotlb
    - wifi: mac80211: fix CMAC functions not handling errors
    - mfd: mt6397-irq: Fix missing irq_domain_remove() in error path
    - mfd: mt6358-irq: Fix missing irq_domain_remove() in error path
    - of/fdt: Consolidate duplicate code into helper functions
    - of/fdt: Fix incorrect use of dt_root_addr_cells in
      early_init_dt_check_kho()
    - leds: rgb: leds-qcom-lpg: Don't enable TRILED when configuring PWM
    - phy: renesas: rcar-gen3-usb2: Fix an error handling path in
      rcar_gen3_phy_usb2_probe()
    - phy: rockchip: naneng-combphy: Add SoC prefix to register definitions
    - phy: rockchip: naneng-combphy: Fix PCIe L1ss support RK3562
    - phy: freescale: Initialize priv->lock
    - phy: rockchip: samsung-hdptx: Fix reported clock rate in high bpc mode
    - phy: rockchip: samsung-hdptx: Reduce ROPLL loop bandwidth
    - phy: rockchip: samsung-hdptx: Prevent Inter-Pair Skew from exceeding the
      limits
    - ASoC: SDCA: Fix missing dash in HIDE DisCo property
    - selftests/bpf: Use ASSERT_STRNEQ to factor in long slab cache names
    - net: phy: adin1100: Fix software power-down ready condition
    - cpuset: Treat cpusets in attaching as populated
    - clk: spacemit: Set clk_hw_onecell_data::num before using flex array
    - RAS: Report all ARM processor CPER information to userspace
    - usb: chaoskey: fix locking for O_NONBLOCK
    - usb: dwc2: fix hang during shutdown if set as peripheral
    - usb: dwc2: fix hang during suspend if set as peripheral
    - usb: raw-gadget: cap raw_io transfer length to KMALLOC_MAX_SIZE
    - regulator: pca9450: Fix error code in probe()
    - selftests/bpf: skip test_perf_branches_hw() on unsupported platforms
    - selftests/bpf: Improve reliability of test_perf_branches_no_hw()
    - crypto: ccree - Correctly handle return of sg_nents_for_len
    - RISC-V: KVM: Fix guest page fault within HLV* instructions
    - erofs: correct FSDAX detection
    - RDMA/bnxt_re: Fix the inline size for GenP7 devices
    - RDMA/bnxt_re: Pass correct flag for dma mr creation
    - crypto: ahash - Fix crypto_ahash_import with partial block data
    - crypto: ahash - Zero positive err value in ahash_update_finish
    - ASoC: tas2781: correct the wrong period
    - wifi: mt76: mt7921: add MBSSID support
    - Revert "wifi: mt76: mt792x: improve monitor interface handling"
    - wifi: mt76: mt7996: fix max nss value when getting rx chainmask
    - wifi: mt76: mt7996: fix implicit beamforming support for mt7992
    - wifi: mt76: mt7996: fix several fields in mt7996_mcu_bss_basic_tlv()
    - wifi: mt76: mt7996: fix teardown command for an MLD peer
    - wifi: mt76: mt7996: set link_valid field when initializing wcid
    - wifi: mt76: mt7996: fix MLD group index assignment
    - wifi: mt76: mt7996: fix using wrong phy to start in mt7996_mac_restart()
    - wifi: mt76: mt7996: grab mt76 mutex in mt7996_mac_sta_event()
    - wifi: mt76: mt7996: skip deflink accounting for offchannel links
    - wifi: mt76: mt7996: Add missing locking in mt7996_mac_sta_rc_work()
    - firmware: stratix10-svc: fix make htmldocs warning for stratix10_svc
    - staging: fbtft: core: fix potential memory leak in fbtft_probe_common()
    - iommu/arm-smmu-v3: Fix error check in arm_smmu_alloc_cd_tables
    - btrfs: fix leaf leak in an error path in btrfs_del_items()
    - PCI: dwc: Fix wrong PORT_LOGIC_LTSSM_STATE_MASK definition
    - drm/nouveau: restrict the flush page to a 32-bit address
    - um: Don't rename vmap to kernel_vmap
    - iomap: always run error completions in user context
    - wifi: ieee80211: correct FILS status codes
    - backlight: lp855x: Fix lp855x.h kernel-doc warnings
    - iommu/arm-smmu-qcom: Enable use of all SMR groups when running bare-
      metal
    - RDMA/irdma: Fix data race in irdma_sc_ccq_arm
    - RDMA/irdma: Fix data race in irdma_free_pble
    - RDMA/irdma: Do not directly rely on IB_PD_UNSAFE_GLOBAL_RKEY
    - drm/panthor: Avoid adding of kernel BOs to extobj list
    - clocksource/drivers/ralink: Fix resource leaks in init error path
    - clocksource/drivers/stm: Fix double deregistration on probe failure
    - clocksource/drivers/nxp-stm: Fix section mismatches
    - clocksource/drivers/nxp-stm: Prevent driver unbind
    - ASoC: nau8325: use simple i2c probe function
    - ASoC: nau8325: add missing build config
    - [Config] enable NAU8325 codec
    - ASoC: fsl_xcvr: clear the channel status control memory
    - firmware_loader: make RUST_FW_LOADER_ABSTRACTIONS select FW_LOADER
    - [Config] enable RUST_FW_LOADER_ABSTRACTIONS
    - [Config] enable AMCC QT2025 PHY driver
    - greybus: gb-beagleplay: Fix timeout handling in bootloader functions
    - misc: rp1: Fix an error handling path in rp1_probe()
    - drm/amd/display: Fix logical vs bitwise bug in
      get_embedded_panel_info_v2_1()
    - hwmon: sy7636a: Fix regulator_enable resource leak on error path
    - ACPI: processor_core: fix map_x2apic_id for amd-pstate on am4
    - ublk: prevent invalid access with DEBUG
    - ext4: improve integrity checking in __mb_check_buddy by enhancing
      order-0 validation
    - selftests/net: packetdrill: pass send_omit_free to MSG_ZEROCOPY tests
    - of: Skip devicetree kunit tests when RISCV+ACPI doesn't populate root
      node
    - virtio_vdpa: fix misleading return in void function
    - virtio: fix typo in virtio_device_ready() comment
    - virtio: fix whitespace in virtio_config_ops
    - virtio: fix grammar in virtio_queue_info docs
    - virtio: fix virtqueue_set_affinity() docs
    - vdpa/mlx5: Fix incorrect error code reporting in query_virtqueues
    - vhost: Fix kthread worker cgroup failure handling
    - vdpa/pds: use %pe for ERR_PTR() in event handler registration
    - virtio: clean up features qword/dword terms
    - ASoC: Intel: catpt: Fix error path in hw_params()
    - spi: airoha-snfi: en7523: workaround flash damaging if UART_TXD was
      short to GND
    - ARM: dts: samsung: universal_c210: turn off SDIO WLAN chip during system
      suspend
    - ARM: dts: samsung: exynos4210-i9100: turn off SDIO WLAN chip during
      system suspend
    - ARM: dts: samsung: exynos4210-trats: turn off SDIO WLAN chip during
      system suspend
    - ARM: dts: samsung: exynos4412-midas: turn off SDIO WLAN chip during
      system suspend
    - Reinstate "resource: avoid unnecessary lookups in find_next_iomem_res()"
    - netfilter: flowtable: check for maximum number of encapsulations in
      bridge vlan
    - netfilter: nf_conncount: rework API to use sk_buff directly
    - netfilter: nft_connlimit: update the count if add was skipped
    - net: stmmac: fix rx limit check in stmmac_rx_zc()
    - mtd: rawnand: renesas: Handle devm_pm_runtime_enable() errors
    - vfio/pci: Use RCU for error/request triggers to avoid circular locking
    - net: phy: aquantia: check for NVMEM deferral
    - selftests: bonding: add delay before each xvlan_over_bond connectivity
      check
    - mtd: lpddr_cmds: fix signed shifts in lpddr_cmds
    - rqspinlock: Enclose lock/unlock within lock entry acquisitions
    - rqspinlock: Use trylock fallback when per-CPU rqnode is busy
    - remoteproc: qcom_q6v5_wcss: fix parsing of qcom,halt-regs
    - md/raid5: fix IO hang when array is broken with IO inflight
    - clk: keystone: fix compile testing
    - net: dsa: b53: fix VLAN_ID_IDX write size for BCM5325/65
    - net: dsa: b53: fix extracting VID from entry for BCM5325/65
    - net: dsa: b53: b53_arl_read{,25}(): use the entry for comparision
    - net: dsa: b53: move reading ARL entries into their own function
    - net: dsa: b53: move writing ARL entries into their own functions
    - net: dsa: b53: provide accessors for accessing ARL_SRCH_CTL
    - net: dsa: b53: split reading search entry into their own functions
    - net: dsa: b53: move ARL entry functions into ops struct
    - net: dsa: b53: add support for 5389/5397/5398 ARL entry format
    - net: dsa: b53: use same ARL search result offset for BCM5325/65
    - net: dsa: b53: fix CPU port unicast ARL entries for BCM5325/65
    - net: dsa: b53: add support for bcm63xx ARL entry format
    - net: dsa: b53: fix BCM5325/65 ARL entry multicast port masks
    - net: dsa: b53: fix BCM5325/65 ARL entry VIDs
    - net: hsr: create an API to get hsr port type
    - net: dsa: xrs700x: reject unsupported HSR configurations
    - perf jitdump: Add sym/str-tables to build-ID generation
    - perf tools: Mark split kallsyms DSOs as loaded
    - perf tools: Fix split kallsyms DSO counting
    - perf hist: In init, ensure mem_info is put on error paths
    - pinctrl: single: Fix incorrect type for error return variable
    - fbdev: ssd1307fb: fix potential page leak in ssd1307fb_probe()
    - 9p: fix cache/debug options printing in v9fs_show_options
    - sched/fair: Fix unfairness caused by stalled tg_load_avg_contrib when
      the last task migrates out
    - sched/core: Fix psi_dequeue() for Proxy Execution
    - f2fs: maintain one time GC mode is enabled during whole zoned GC cycle
    - kbuild: install-extmod-build: Fix when given dir outside the build dir
    - kbuild: install-extmod-build: Properly fix CC expansion when ccache is
      used
    - NFS: Avoid changing nlink when file removes and attribute updates race
    - fs/nls: Fix utf16 to utf8 conversion
    - NFS: Initialise verifiers for visible dentries in readdir and lookup
    - NFS: Initialise verifiers for visible dentries in nfs_atomic_open()
    - NFS: Initialise verifiers for visible dentries in
      _nfs4_open_and_get_state
    - panthor: save task pid and comm in panthor_group
    - Revert "nfs: ignore SB_RDONLY when remounting nfs"
    - Revert "nfs: clear SB_RDONLY before getting superblock"
    - Revert "nfs: ignore SB_RDONLY when mounting nfs"
    - NFS: Fix inheritance of the block sizes when automounting
    - fs/nls: Fix inconsistency between utf8_to_utf32() and utf32_to_utf8()
    - platform/x86: asus-wmi: use brightness_set_blocking() for kbd led
    - ASoC: bcm: bcm63xx-pcm-whistler: Check return value of
      of_dma_configure()
    - ASoC: amd: acp: Audio is not resuming after s0ix
    - ASoC: ak4458: Disable regulator when error happens
    - ASoC: ak5558: Disable regulator when error happens
    - f2fs: revert summary entry count from 2048 to 512 in 16kb block support
    - blk-mq: Abort suspend when wakeup events are pending
    - block: fix comment for op_is_zone_mgmt() to include RESET_ALL
    - nvme-auth: use kvfree() for memory allocated with kvcalloc()
    - drm/plane: Fix IS_ERR() vs NULL check in
      drm_plane_create_hotspot_properties()
    - regulator: fixed: Rely on the core freeing the enable GPIO
    - drm/nouveau: refactor deprecated strcpy
    - drm/nouveau: fix circular dep oops from vendored i2c encoder
    - cifs: Fix handling of a beyond-EOF DIO/unbuffered read over SMB1
    - cifs: Fix handling of a beyond-EOF DIO/unbuffered read over SMB2
    - docs: hwmon: fix link to g762 devicetree binding
    - i2c: spacemit: fix detect issue
    - dma/pool: eliminate alloc_pages warning in atomic_pool_expand
    - ALSA: uapi: Fix typo in asound.h comment
    - drm/amdkfd: Use huge page size to check split svm range alignment
    - rtc: gamecube: Check the return value of ioremap()
    - rtc: max31335: Fix ignored return value in set_alarm
    - ARM: 9464/1: fix input-only operand modification in
      load_unaligned_zeropad()
    - drm/xe/fbdev: use the same 64-byte stride alignment as i915
    - drm/i915/fbdev: make intel_framebuffer_create() error return handling
      explicit
    - drm/{i915, xe}/fbdev: pass struct drm_device to intel_fbdev_fb_alloc()
    - drm/{i915, xe}/fbdev: deduplicate struct drm_mode_fb_cmd2 init
    - drm/i915/fbdev: Hold runtime PM ref during fbdev BO creation
    - ASoC: amd: acp: update tdm channels for specific DAI
    - dm-raid: fix possible NULL dereference with undefined raid type
    - dm log-writes: Add missing set_freezable() for freezable kthread
    - efi/cper: Add a new helper function to print bitmasks
    - efi/cper: Adjust infopfx size to accept an extra space
    - efi/cper: align ARM CPER type with UEFI 2.9A/2.10 specs
    - perf/core: Fix missing read event generation on task exit
    - cpu: Make atomic hotplug callbacks run with interrupts disabled on UP
    - ocfs2: fix memory leak in ocfs2_merge_rec_left()
    - perf/x86/intel: Fix NULL event dereference crash in handle_pmi_common()
    - usb: gadget: tegra-xudc: Always reinitialize data toggle when clear halt
    - usb: typec: ucsi: fix probe failure in gaokun_ucsi_probe()
    - usb: phy: Initialize struct usb_phy list_head
    - usb: dwc3: dwc3_power_off_all_roothub_ports: Use ioremap_np when
      required
    - ALSA: hda/realtek: Add match for ASUS Xbox Ally projects
    - ALSA: hda/tas2781: fix speaker id retrieval for multiple probes
    - ASoC: codecs: nau8325: Silence uninitialized variables warnings
    - Linux 6.17.13
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68344
    - ALSA: wavefront: Fix integer overflow in sample size validation
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68345
    - ALSA: hda: cs35l41: Fix NULL pointer dereference in
      cs35l41_hda_read_acpi()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68346
    - ALSA: dice: fix buffer overflow in detect_stream_formats()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68323
    - usb: typec: ucsi: fix use-after-free caused by uec->work
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68766
    - irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68324
    - scsi: imm: Fix use-after-free bug caused by unfinished delayed work
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68756
    - block: Use RCU in blk_mq_[un]quiesce_tagset() instead of
      set->tag_list_lock
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68753
    - ALSA: firewire-motu: add bounds check in put_user loop for DSP events
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68347
    - ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68348
    - block: fix memory leak in __blkdev_issue_zero_pages
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68764
    - NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68735
    - drm/panthor: Prevent potential UAF in group creation
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68349
    - NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in
      pnfs_mark_layout_stateid_invalid
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68754
    - rtc: amlogic-a4: fix double free caused by devm
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68325
    - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68762
    - net: netpoll: initialize work queue before error checks
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68352
    - spi: ch341: fix out-of-bounds memory access in ch341_transfer_one
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68752
    - iavf: Implement settime64 with -EOPNOTSUPP
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68354
    - regulator: core: Protect regulator_supply_alias_list with
      regulator_list_mutex
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68356
    - gfs2: Prevent recursive memory reclaim
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68758
    - backlight: led-bl: Add devlink to supplier LEDs
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68358
    - btrfs: fix racy bitfield write in btrfs_clear_space_info_full()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68359
    - btrfs: fix double free of qgroup record after failure to add delayed ref
      head
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68765
    - mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68360
    - wifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68738
    - wifi: mt76: mt7996: fix null pointer deref in mt7996_conf_tx()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68361
    - erofs: limit the level of fs stacking for file-backed mounts
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68739
    - PM / devfreq: hisi: Fix potential UAF in OPP handling
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68763
    - crypto: starfive - Correctly handle return of sg_nents_for_len
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68740
    - ima: Handle error code returned by ima_filter_rule_match()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68362
    - wifi: rtl818x: rtl8187: Fix potential buffer underflow in
      rtl8187_rx_cb()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68741
    - scsi: qla2xxx: Fix improper freeing of purex item
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68742
    - bpf: Fix invalid prog->stats access when update_effective_progs fails
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68759
    - wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68743
    - mshv: Fix create memory region overlap check
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68363
    - bpf: Check skb->transport_header is set in bpf_skb_check_mtu
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68751
    - s390/fpu: Fix false-positive kmsan report in fpu_vstl()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68744
    - bpf: Free special fields when update [lru_,]percpu_hash maps
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68364
    - ocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68366
    - nbd: defer config unlock in nbd_genl_connect
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68367
    - macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68369
    - ntfs3: init run lock for extend inode
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68370
    - coresight: tmc: add the handle of the event to the path
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68755
    - staging: most: remove broken i2c driver
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68371
    - scsi: smartpqi: Fix device resources accessed after device removal
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68372
    - nbd: defer config put in recv_work
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68373
    - md: avoid repeated calls to del_gendisk
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68374
    - md: fix rcu protection in md_wakeup_thread
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68375
    - perf/x86: Fix NULL event access and potential PEBS record loss
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68376
    - coresight: ETR: Fix ETR buffer use-after-free issue
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68746
    - spi: tegra210-quad: Fix timeout handling
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68760
    - iommu/amd: Fix potential out-of-bounds read in iommu_mmio_show
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68747
    - drm/panthor: Fix UAF on kernel BO VA nodes
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68748
    - drm/panthor: Fix UAF race between device unplug and FW event processing
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68749
    - accel/ivpu: Fix race condition when unbinding BOs
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68378
    - bpf: Fix stackmap overflow check in __bpf_get_stackid()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68379
    - RDMA/rxe: Fix null deref on srq->rq.queue after resize failure
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68380
    - wifi: ath11k: fix peer HE MCS assignment
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68724
    - crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68726
    - crypto: aead - Fix reqsize handling
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68727
    - ntfs3: Fix uninit buffer allocated by __getname()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68728
    - ntfs3: fix uninit memory after failed mi_read in mi_format_new
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68729
    - wifi: ath12k: Fix MSDU buffer types handling in RX error path
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68757
    - drm/vgem-fence: Fix potential deadlock on release
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68730
    - accel/ivpu: Fix page fault in ivpu_bo_unbind_all_bos_from_context()
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68732
    - gpu: host1x: Fix race in syncpt alloc/free
  * Questing update: v6.17.13 upstream stable release (LP: #2139960) //
    CVE-2025-68733
    - smack: fix bug: unprivileged task can create labels
  * Questing update: v6.17.12 upstream stable release (LP: #2139373)
    - Documentation: process: Also mention Sasha Levin as stable tree
      maintainer
    - jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system
      corrupted
    - ext4: refresh inline data size before write operations
    - ksmbd: ipc: fix use-after-free in ipc_msg_send_request
    - locking/spinlock/debug: Fix data-race in do_raw_write_lock
    - crypto: zstd - fix double-free in per-CPU stream cleanup
    - ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
    - comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
    - KVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced
    - USB: serial: option: add Foxconn T99W760
    - USB: serial: option: add Telit Cinterion FE910C04 new compositions
    - USB: serial: option: move Telit 0x10c7 composition in the right place
    - USB: serial: ftdi_sio: match on interface number for jtag
    - serial: add support of CPCI cards
    - dt-bindings: serial: rsci: Drop "uart-has-rtscts: false"
    - serial: sh-sci: Fix deadlock during RSCI FIFO overrun error
    - USB: serial: belkin_sa: fix TIOCMBIS and TIOCMBIC
    - USB: serial: kobil_sct: fix TIOCMBIS and TIOCMBIC
    - ftrace: bpf: Fix IPMODIFY + DIRECT in modify_ftrace_direct()
    - spi: xilinx: increase number of retries before declaring stall
    - spi: imx: keep dma request disabled before dma transfer setup
    - ACPI: MRRM: Fix memory leaks and improve error handling
    - drm/vmwgfx: Use kref in vmw_bo_dirty
    - arm64: Reject modules with internal alternative callbacks
    - ALSA: hda/tas2781: Add new quirk for HP new projects
    - Bluetooth: btrtl: Avoid loading the config file on security chips
    - ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list
    - smb: fix invalid username check in smb3_fs_context_parse_param()
    - drm/amdkfd: Fix GPU mappings for APU after prefetch
    - ALSA: usb-audio: Add native DSD quirks for PureAudio DAC series
    - HID: lenovo: fixup Lenovo Yoga Slim 7x Keyboard rdesc
    - bfs: Reconstruct file type when loading from disk
    - HID: hid-input: Extend Elan ignore battery quirk to USB
    - platform/x86/amd/pmc: Add support for Van Gogh SoC
    - platform/x86: hp-wmi: mark Victus 16-r0 and 16-s0 for victus_s fan and
      thermal profile support
    - nvme: fix admin request_queue lifetime
    - pinctrl: qcom: msm: Fix deadlock in pinmux configuration
    - platform/x86: acer-wmi: Ignore backlight event
    - HID: apple: Add SONiX AK870 PRO to non_apple_keyboards quirk list
    - platform/x86: huawei-wmi: add keys for HONOR models
    - platform/x86: intel-uncore-freq: Add additional client processors
    - platform/x86/amd: pmc: Add Lenovo Legion Go 2 to pmc quirk list
    - platform/x86/amd/pmc: Add spurious_8042 to Xbox Ally
    - sched_ext: Fix possible deadlock in the deferred_irq_workfn()
    - platform/x86/intel/hid: Add Nova Lake support
    - HID: elecom: Add support for ELECOM M-XT3URBK (018F)
    - sched_ext: Use IRQ_WORK_INIT_HARD() to initialize
      rq->scx.kick_cpus_irq_work
    - LoongArch: Mask all interrupts during kexec/kdump
    - samples: work around glibc redefining some of our defines wrong
    - platform/x86: hp-wmi: Add Omen 16-wf1xxx fan support
    - platform/x86: hp-wmi: Add Omen MAX 16-ah0xx fan support and thermal
      profile
    - wifi: rtl8xxxu: Add USB ID 2001:3328 for D-Link AN3U rev. A1
    - wifi: rtw88: Add USB ID 2001:3329 for D-Link AC13U rev. A1
    - iio: adc: ad4080: fix chip identification
    - comedi: c6xdigio: Fix invalid PNP driver unregistration
    - comedi: multiq3: sanitize config options in multiq3_attach()
    - comedi: check device's attached status in compat ioctls
    - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
    - staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
    - staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
    - Linux 6.17.12
  * Questing update: v6.17.11 upstream stable release (LP: #2138824)
    - Bluetooth: hci_core: Fix triggering cmd_timer for HCI_OP_NOP
    - Bluetooth: SMP: Fix not generating mackey and ltk when repairing
    - drm/bridge: sii902x: Fix HDMI detection with
      DRM_BRIDGE_ATTACH_NO_CONNECTOR
    - net: phy: mxl-gpy: fix bogus error on USXGMII and integrated PHY
    - net: aquantia: Add missing descriptor cache invalidation on ATL2
    - net: phy: mxl-gpy: fix link properties on USXGMII and internal PHYs
    - net: lan966x: Fix the initialization of taprio
    - drm/xe: Fix conversion from clock ticks to milliseconds
    - net/mlx5e: Fix validation logic in rate limiting
    - xsk: avoid overwriting skb fields for multi-buffer traffic
    - drm/amdgpu: fix cyan_skillfish2 gpu info fw handling
    - dma-direct: Fix missing sg_dma_len assignment in P2PDMA bus mappings
    - net: wwan: mhi: Keep modem name match with Foxconn T99W640
    - net: dsa: sja1105: fix SGMII linking at 10M or 100M but not passing
      traffic
    - eth: fbnic: Fix counter roll-over issue
    - net: mctp: unconditionally set skb->dev on dst output
    - net: fec: cancel perout_timer when PEROUT is disabled
    - net: fec: do not update PEROUT if it is enabled
    - net: fec: do not allow enabling PPS and PEROUT simultaneously
    - net: fec: do not register PPS event for PEROUT
    - iio: st_lsm6dsx: Fixed calibrated timestamp calculation
    - usb: gadget: renesas_usbf: Handle devm_pm_runtime_enable() errors
    - mailbox: mailbox-test: Fix debugfs_create_dir error checking
    - mailbox: mtk-cmdq: Refine DMA address handling for the command buffer
    - mailbox: pcc: don't zero error register
    - spi: spi-cadence-quadspi: Remove duplicate pm_runtime_put_autosuspend()
      call
    - spi: spi-cadence-quadspi: Enable pm runtime earlier to avoid imbalance
    - ovl: fail ovl_lock_rename_workdir() if either target is unhashed
    - riscv: dts: allwinner: d1: fix vlenb property
    - spi: tegra114: remove Kconfig dependency on TEGRA20_APB_DMA
    - spi: amlogic-spifc-a1: Handle devm_pm_runtime_enable() errors
    - spi: spi-nxp-fspi: Add OCT-DTR mode support
    - spi: nxp-fspi: Propagate fwnode in ACPI case as well
    - spi: bcm63xx: fix premature CS deassertion on RX-only transactions
    - afs: Fix uninit var in afs_alloc_anon_key()
    - timekeeping: Fix error code in tk_aux_sysfs_init()
    - Revert "perf/x86: Always store regs->ip in perf_callchain_kernel()"
    - iio: buffer-dma: support getting the DMA channel
    - iio: buffer-dmaengine: enable .get_dma_dev()
    - iio: buffer: support getting dma channel from the buffer
    - iio: humditiy: hdc3020: fix units for temperature and humidity
      measurement
    - iio: humditiy: hdc3020: fix units for thresholds and hysteresis
    - iio: imu: st_lsm6dsx: fix array size for st_lsm6dsx_settings fields
    - iio: pressure: bmp280: correct meas_time_us calculation
    - iio:common:ssp_sensors: Fix an error handling path ssp_probe()
    - iio: adc: stm32-dfsdm: fix st,adc-alt-channel property handling
    - iio: accel: fix ADXL355 startup race condition
    - iio: adc: ad4030: Fix _scale value for common-mode channels
    - iio: adc: ad7124: fix temperature channel
    - iio: adc: ad7280a: fix ad7280_store_balance_timer()
    - iio: adc: ad7380: fix SPI offload trigger rate
    - iio: adc: rtq6056: Correct the sign bit index
    - MIPS: mm: Prevent a TLB shutdown on initial uniquification
    - MIPS: mm: kmalloc tlb_vpn array to avoid stack overflow
    - virtio-net: avoid unnecessary checksum calculation on guest RX
    - vhost: rewind next_avail_head while discarding descriptors
    - ALSA: hda/cirrus fix cs420x MacPro 6,1 inverted jack detection
    - ALSA: usb-audio: Add DSD quirk for LEAK Stereo 230
    - arm64: dts: imx8dxl-ss-conn: swap interrupts number of eqos
    - arm64: dts: imx8dxl: Correct pcie-ep interrupt number
    - arm64: dts: imx8qm-mek: fix mux-controller select/enable-gpios polarity
    - ARM: dts: nxp: imx6ul: correct SAI3 interrupt line
    - can: rcar_canfd: Fix CAN-FD mode as default
    - can: sja1000: fix max irq loop handling
    - can: sun4i_can: sun4i_can_interrupt(): fix max irq loop handling
    - counter: microchip-tcb-capture: Allow shared IRQ for multi-channel TCBs
    - dm-verity: fix unreliable memory allocation
    - drivers/usb/dwc3: fix PCI parent check
    - thunderbolt: Add support for Intel Wildcat Lake
    - slimbus: ngd: Fix reference count leak in qcom_slim_ngd_notify_slaves
    - nvmem: layouts: fix nvmem_layout_bus_uevent
    - pmdomain: tegra: Add GENPD_FLAG_NO_STAY_ON flag
    - r8169: fix RTL8127 hang on suspend/shutdown
    - regulator: rtq2208: Correct buck group2 phase mapping logic
    - regulator: rtq2208: Correct LDO2 logic judgment bits
    - iommufd/driver: Fix counter initialization for counted_by annotation
    - mmc: sdhci-of-dwcmshc: Promote the th1520 reset handling to ip level
    - mptcp: clear scheduled subflows on retransmit
    - mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in
      mptcp_do_fastclose().
    - serial: 8250: Fix 8250_rsa symbol loop
    - serial: amba-pl011: prefer dma_mapping_error() over explicit address
      checking
    - usb: cdns3: Fix double resource release in cdns3_pci_probe
    - USB: storage: Remove subclass and protocol overrides from Novatek quirk
    - usb: typec: ucsi: psy: Set max current to zero when disconnected
    - usb: dwc3: pci: add support for the Intel Nova Lake -S
    - usb: dwc3: pci: Sort out the Intel device IDs
    - xhci: fix stale flag preventig URBs after link state error is cleared
    - xhci: dbgtty: Fix data corruption when transmitting data form DbC to
      host
    - xhci: dbgtty: fix device unregister
    - USB: serial: ftdi_sio: add support for u-blox EVK-M101
    - USB: serial: option: add support for Rolling RW101R-GL
    - drm: sti: fix device leaks at component probe
    - drm/i915/psr: Reject async flips when selective fetch is enabled
    - drm/amdgpu: attach tlb fence to the PTs update
    - drm/amd/amdgpu: reserve vm invalidation engine for uni_mes
    - drm/amd/display: Don't change brightness for disabled connectors
    - drm/amd/display: Increase EDID read retries
    - net: dsa: microchip: common: Fix checks on irq_find_mapping()
    - net: dsa: microchip: ptp: Fix checks on irq_find_mapping()
    - net: dsa: microchip: Free previously initialized ports on init failures
    - net: dsa: microchip: Fix symetry in ksz_ptp_msg_irq_{setup/free}()
    - mm: swap: remove duplicate nr_swap_pages decrement in
      get_swap_page_of_type()
    - usb: udc: Add trace event for usb_gadget_set_state
    - Revert "ACPI: Suppress misleading SPCR console message when SPCR table
      is absent"
    - spi: cadence-quadspi: Fix cqspi_probe() error handling for runtime pm
    - Linux 6.17.11
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68282
    - usb: gadget: udc: fix use-after-free in usb_gadget_state_work
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68283
    - libceph: replace BUG_ON with bounds check for map->max_osd
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68284
    - libceph: prevent potential out-of-bounds writes in
      handle_auth_session_key()
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68285
    - libceph: fix potential use-after-free in have_mon_and_osd_map()
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68338
    - net: dsa: microchip: Don't free uninitialized ksz_irq
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68286
    - drm/amd/display: Check NULL before accessing
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68326
    - drm/xe/guc: Fix stack_depot usage
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68287
    - usb: dwc3: Fix race condition between concurrent dwc3_remove_requests()
      call paths
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68331
    - usb: uas: fix urb unmapping issue when the uas device is remove during
      ongoing data transfer
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-40345
    - usb: storage: sddr55: Reject out-of-bound new_pba
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68288
    - usb: storage: Fix memory leak in USB bulk transport
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68327
    - usb: renesas_usbhs: Fix synchronous external abort on unbind
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68289
    - usb: gadget: f_eem: Fix memory leak in eem_unwrap
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68290
    - most: usb: fix double free on late probe failure
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68292
    - mm/memfd: fix information leak in hugetlb folios
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68293
    - mm/huge_memory: fix NULL pointer deference when splitting folio
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68328
    - firmware: stratix10-svc: fix bug in saving controller data
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68294
    - io_uring/net: ensure vectored buffer node import is tied to notification
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68295
    - smb: client: fix memory leak in cifs_construct_tcon()
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68296
    - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68297
    - ceph: fix crash in process_v2_sparse_read() for encrypted directories
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68298
    - Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68339
    - atm/fore200e: Fix possible data race in fore200e_open()
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68329
    - tracing: Fix WARN_ON in tracing_buffers_mmap_close for split VMAs
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68330
    - iio: accel: bmc150: Fix irq assumption regression
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68299
    - afs: Fix delayed allocation of a cell's anonymous key
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68300
    - fs/namespace: fix reference leak in grab_requested_mnt_ns
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68301
    - net: atlantic: fix fragment overflow handling in RX path
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-40290
    - xsk: avoid data corruption on cq descriptor number
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68302
    - net: sxgbe: fix potential NULL dereference in sxgbe_rx()
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68340
    - team: Move team device type change at the end of team_port_add
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68303
    - platform/x86: intel: punit_ipc: fix memory corruption
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68341
    - veth: reduce XDP no_direct return section to fix race
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68304
    - Bluetooth: hci_core: lookup hci_conn on RX path on protocol side
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68305
    - Bluetooth: hci_sock: Prevent race in socket write iter and sock bind
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68306
    - Bluetooth: btusb: mediatek: Fix kernel crash when releasing mtk iso
      interface
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68342
    - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before
      accessing data
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68343
    - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before
      accessing header
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68307
    - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted
      URBs
  * Questing update: v6.17.11 upstream stable release (LP: #2138824) //
    CVE-2025-68308
    - can: kvaser_usb: leaf: Fix potential infinite loop in command parsers
  * Questing update: v6.17.10 upstream stable release (LP: #2137723)
    - arm64: dts: rockchip: Remove non-functioning CPU OPPs from RK3576
    - HID: amd_sfh: Stop sensor before starting
    - HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
    - arm64: dts: rockchip: Fix vccio4-supply on rk3566-pinetab2
    - arm64: dts: rockchip: fix PCIe 3.3V regulator voltage on orangepi-5
    - reset: imx8mp-audiomix: Fix bad mask values
    - arm64: dts: rockchip: include rk3399-base instead of rk3399 in
      rk3399-op1
    - arm64: dts: rockchip: disable HS400 on RK3588 Tiger
    - KVM: SVM: Fix redundant updates of LBR MSR intercepts
    - xfs: check the return value of sb_min_blocksize() in xfs_fs_fill_super
    - isofs: check the return value of sb_min_blocksize() in isofs_fill_super
    - shmem: fix tmpfs reconfiguration (remount) when noswap is set
    - exfat: check return value of sb_min_blocksize in exfat_read_boot_sector
    - mptcp: Disallow MPTCP subflows from sockmap
    - s390/mm: Fix __ptep_rdp() inline assembly
    - ACPI: APEI: EINJ: Fix EINJV2 initialization and injection
    - ata: libata-scsi: Fix system suspend for a security locked drive
    - selinux: rename task_security_struct to cred_security_struct
    - selinux: move avdcache to per-task security struct
    - smb: client: introduce close_cached_dir_locked()
    - wifi: rtw89: hw_scan: Don't let the operating channel be last
    - ata: libata-scsi: Add missing scsi_device_put() in ata_scsi_dev_rescan()
    - net: dsa: microchip: lan937x: Fix RGMII delay tuning
    - Revert "drm/tegra: dsi: Clear enable register if powered by bootloader"
    - Input: goodix - add support for ACPI ID GDIX1003
    - nvme: nvme-fc: move tagset removal to nvme_fc_delete_ctrl()
    - PM: sleep: core: Fix runtime PM enabling in device_resume_early()
    - MIPS: Malta: Fix !EVA SOC-it PCI MMIO
    - dt-bindings: pinctrl: toshiba,visconti: Fix number of items in groups
    - LoongArch: Don't panic if no valid cache info for PCI
    - LoongArch: Fix NUMA node parsing with numa_memblks
    - platform/x86: alienware-wmi-wmax: Fix "Alienware m16 R1 AMD" quirk order
    - platform/x86: alienware-wmi-wmax: Add support for the whole "M" family
    - platform/x86: alienware-wmi-wmax: Add support for the whole "X" family
    - platform/x86: alienware-wmi-wmax: Add support for the whole "G" family
    - platform/x86: alienware-wmi-wmax: Add AWCC support to Alienware 16
      Aurora
    - mptcp: fix ack generation for fallback msk
    - mptcp: fix duplicate reset on fastclose
    - mptcp: fix premature close in case of fallback
    - selftests: mptcp: join: endpoints: longer timeout
    - selftests: mptcp: join: userspace: longer timeout
    - mptcp: avoid unneeded subflow-level drops
    - mptcp: decouple mptcp fastclose from tcp close
    - mptcp: do not fallback when OoO is present
    - drm/tegra: dc: Fix reference leak in tegra_dc_couple()
    - drm/amdgpu: Skip emit de meta data on gfx11 with rs64 enabled
    - drm/amd/display: Increase DPCD read retries
    - drm/amd/display: Move sleep into each retry for retrieve_link_cap()
    - drm/amd/display: Clear the CUR_ENABLE register on DCN20 on DPP5
    - mm/truncate: unmap large folio on split failure
    - pinctrl: mediatek: mt8196: align register base names to dt-bindings ones
    - pinctrl: mediatek: mt8189: align register base names to dt-bindings ones
    - xfrm: drop SA reference in xfrm_state_update if dir doesn't match
    - xfrm: call xfrm_dev_state_delete when xfrm_state_migrate fails to add
      the state
    - xfrm: set err and extack on failure to create pcpu SA
    - clk: sunxi-ng: Mark A523 bus-r-cpucfg clock as critical
    - clk: sunxi-ng: sun55i-a523-r-ccu: Mark bus-r-dma as critical
    - clk: sunxi-ng: sun55i-a523-ccu: Lower audio0 pll minimum rate
    - pinctrl: realtek: Select REGMAP_MMIO for RTD driver
    - xfrm: Check inner packet family directly from skb_dst
    - xfrm: Determine inner GSO type from packet inner protocol
    - xfrm: Prevent locally generated packets from direct output in tunnel
      mode
    - pinctrl: cirrus: Fix fwnode leak in cs42l43_pin_probe()
    - platform/x86: msi-wmi-platform: Only load on MSI devices
    - platform/x86: msi-wmi-platform: Fix typo in WMI GUID
    - mips: dts: econet: fix EN751221 core type
    - mlxsw: spectrum: Fix memory leak in mlxsw_sp_flower_stats()
    - net: dsa: hellcreek: fix missing error handling in LED registration
    - net: mlxsw: linecards: fix missing error check in
      mlxsw_linecard_devlink_info_get()
    - tools: riscv: Fixed misalignment of CSR related definitions
    - nvmet-auth: update sc_c in target host hash calculation
    - drm/i915/xe3lpd: Load DMC for Xe3_LPD version 30.02
    - selftests: net: lib: Do not overwrite error messages
    - net: airoha: Add wlan flowtable TX offload
    - net: airoha: Do not loopback traffic to GDM2 if it is available on the
      device
    - platform/x86/intel/speed_select_if: Convert PCIBIOS_* return codes to
      errnos
    - platform/x86: intel-uncore-freq: fix all header kernel-doc warnings
    - drm/pcids: Split PTL pciids group to make wcl subplatform
    - drm/i915/display: Add definition for wcl as subplatform
    - drm/i915/xe3: Restrict PTL intel_encoder_is_c10phy() to only PHY A
    - drm/xe/kunit: Fix forcewake assertion in mocs test
    - drm/xe/irq: Handle msix vector0 interrupt
    - pinctrl: s32cc: initialize gpio_pin_config::list after kmalloc()
    - af_unix: Read sk_peek_offset() again after sleeping in
      unix_stream_read_generic().
    - net: phylink: add missing supported link modes for the fixed-link
    - tick/sched: Fix bogus condition in report_idle_softirq()
    - LoongArch: Use UAPI types in ptrace UAPI header
    - perf: Fix 0 count issue of cpu-clock
    - timekeeping: Fix resource leak in tk_aux_sysfs_init() error paths
    - MIPS: kernel: Fix random segmentation faults
    - ALSA: hda/realtek: Add quirk for Lenovo Yoga 7 2-in-1 14AKP10
    - sched_ext: Allocate scx_kick_cpus_pnt_seqs lazily using kvzalloc()
    - bcma: don't register devices disabled in OF
    - sched_ext: defer queue_balance_callback() until after ops.dispatch
    - ASoC: rt721: fix prepare clock stop failed
    - cifs: fix typo in enable_gcm_256 module parameter
    - scsi: core: Fix a regression triggered by scsi_host_busy()
    - ALSA: hda/realtek: Fix mute led for HP Victus 15-fa1xxx (MB 8C2D)
    - perf/x86/intel/uncore: Add uncore PMU support for Wildcat Lake
    - x86/microcode/AMD: Limit Entrysign signature checking to known
      generations
    - selftests: cachestat: Fix warning on declaration under label
    - smb: client: handle lack of IPC in dfs_cache_refresh()
    - net: tls: Change async resync helpers argument
    - blk-crypto: use BLK_STS_INVAL for alignment errors
    - net: tls: Cancel RX async resync request on rcd_delta overflow
    - x86/CPU/AMD: Extend Zen6 model range
    - kconfig/mconf: Initialize the default locale at startup
    - kconfig/nconf: Initialize the default locale at startup
    - drm/xe: Prevent BIT() overflow when handling invalid prefetch region
    - ALSA: usb-audio: fix uac2 clock source at terminal parser
    - tracing/tools: Fix incorrcet short option in usage text for --threads
    - btrfs: set inode flag BTRFS_INODE_COPY_EVERYTHING when logging new name
    - smb: client: fix incomplete backport in cfids_invalidation_worker()
    - drm/amdgpu/jpeg: Move parse_cs to amdgpu_jpeg.c
    - drm/amdgpu/jpeg: Add parse_cs for JPEG5_0_1
    - xfs: Replace strncpy with memcpy
    - drm/amd/display: Insert dccg log for easy debug
    - drm/amd/display: Prevent Gating DTBCLK before It Is Properly Latched
    - tty/vt: fix up incorrect backport to stable releases
    - Revert "drm/i915/dp: Reject HBR3 when sink doesn't support TPS4"
    - drm/i915/dp: Add device specific quirk to limit eDP rate to HBR2
    - sched_ext: Fix scx_kick_pseqs corruption on concurrent scheduler loads
    - sched_ext: fix flag check for deferred callbacks
    - Linux 6.17.10
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68221
    - mptcp: fix address removal logic in mptcp_pm_nl_rm_addr
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40246
    - xfs: fix out of bounds memory read error in symlink repair
  * Intel,External monitor flickers or no output when connected to WD25 dock
    (LP: #2136979) // Questing update: v6.17.10 upstream stable release
    (LP: #2137723)
    - drm/i915/psr: Check drm_dp_dpcd_read return value on PSR dpcd init
    - drm/i915/dp_mst: Disable Panel Replay
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68230
    - drm/amdgpu: fix gpu page fault after hibernation on PF passthrough
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68220
    - net: ethernet: ti: netcp: Standardize knav_dma_open_channel to return
      NULL on error
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68236
    - scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40247
    - drm/msm: Fix pgtable prealloc error path
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40248
    - vsock: Ignore signal/timeout on connect() if already established
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68219
    - cifs: fix memory leak in smb3_fs_context_parse_param error path
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40249
    - gpio: cdev: make sure the cdev fd is still active before emitting events
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40250
    - net/mlx5: Clean up only new IRQ glue on request_irq() failure
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40251
    - devlink: rate: Unset parent pointer in devl_rate_nodes_destroy
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68222
    - pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68215
    - ice: fix PTP cleanup on driver removal in error path
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68213
    - idpf: fix possible vport_config NULL pointer deref in remove
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40252
    - net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont()
      and qede_tpa_end()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40253
    - s390/ctcm: Fix double-kfree
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68218
    - nvme-multipath: fix lockdep WARN due to partition scan work
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68232
    - veth: more robust handing of race to avoid txq getting stuck
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40254
    - net: openvswitch: remove never-working support for setting nsh fields
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68233
    - drm/tegra: Add call to put_pid()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40255
    - net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68228
    - drm/plane: Fix create_in_format_blob() return value
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68223
    - drm/radeon: delete radeon_fence_process in is_signaled, no deadlock
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40257
    - mptcp: fix a race in mptcp_pm_del_add_timer()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40258
    - mptcp: fix race condition in mptcp_schedule_work()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68216
    - LoongArch: BPF: Disable trampoline for kernel module function trace
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68229
    - scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40259
    - scsi: sg: Do not sleep in atomic context
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40260
    - sched_ext: Fix scx_enable() crash on helper kthread creation failure
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40261
    - nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68235
    - nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68231
    - mm/mempool: fix poisoning order>0 pages with HIGHMEM
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68217
    - Input: pegasus-notetaker - fix potential out-of-bounds access
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40262
    - Input: imx_sc_key - fix memory corruption on unload
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40263
    - Input: cros_ec_keyb - fix an invalid memory access
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68234
    - io_uring/cmd_net: fix wrong argument types for skb_queue_splice()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40264
    - be2net: pass wrb_params in case of OS2BMC
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68225
    - lib/test_kho: check if KHO is enabled
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68227
    - mptcp: Fix proto fallback detection with BPF
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68237
    - mtdchar: fix integer overflow in read/write ioctls
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68212
    - fs: Fix uninitialized 'offp' in statmount_string()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68238
    - mtd: rawnand: cadence: fix DMA device NULL pointer dereference
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40265
    - vfat: fix missing sb_min_blocksize() return value checks
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-68214
    - timers: Fix NULL function pointer race in timer_shutdown_sync()
  * Questing update: v6.17.10 upstream stable release (LP: #2137723) //
    CVE-2025-40266
    - KVM: arm64: Check the untrusted offset in FF-A memory share

Date: 2026-04-15 16:20:10.987769+00:00
Changed-By: John Cabaj <john-cabaj at ubuntu.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-azure-fde-6.17/6.17.0-1010.10~24.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list