211a65465dd9 Linux 6.18.50-xanmod1 e8b3291361f1 Merge tag 'v6.18.50' into 6.18 7cfc41f8e80f Linux 6.18.50 8e30f5427f34 mm/rmap: use huge_ptep_get() in try_to_unmap_one() 381a0a524e96 mm: avoid unnecessary use of is_swap_pmd() 6a259dd31304 platform/chrome: sensorhub: Fix dropped timestamp events and log spam e91d66e5ff66 selftests/mm: fix on-fault-limit false failure under sudo-rs 2d6150e5e6aa udf: Fix i_lenExtents truncation on 32-bit kernels b7eff3f621ef timer: Keep debugobjects state consistent in migrate_timer_list() fecf1e377752 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() 6067c39c2cec taskstats: fix cpumask parsing cutting off the last character ed64aa505875 smack: fix cred UAF in smack_file_send_sigiotask() a246da20c8e4 signal: avoid shared siginfo namespace rewrites 236c8ecaafc6 sticon/parisc: Detect default STI graphics card for console output e8527de7fea1 sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cde2d927c29e tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout c3c7e87c76b4 zloop: truncate finished zones to zone capacity f49e55b1c8fe xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() ae0c79a85270 w1: ds28e17: reject an oversize length on an I2C block read 165a330a68b5 vsock/virtio: flush works in dependency order 03b81f015dbb wifi: mt76: mt7996: validate default EEPROM firmware size 01f2e0da8548 wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames 304470333b7f wifi: mt76: mt7925: cancel mlo_pm_work on stop 5fdaf7016d76 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy 4506e229b2e4 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex 34a505071d1f wifi: rtw88: pci: fix resource leak on failed NAPI setup 7364713f0931 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() dc8b0be0ec4d wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() 0c0b374e12d5 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids 97a1af5ac131 wifi: rtl818x: initialize eeprom_93cx6 struct to zero b1bbeb8970ee wifi: mwifiex: Detach sync cmd buffer on interrupted wait 7c257a295e05 crypto: sun8i-ss - Remove crypto_rng interface 8e4f9110aba3 crypto: sun8i-ce - Remove crypto_rng interface 620acb1e8037 wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop 84ba017a1e1e wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() 261d7c7610b4 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() 7ef23317f997 i3c: renesas: Reconfigure the DATBAS register on re-attach 9382fcf3a8c4 i3c: renesas: Clean DATBAS register on detach 0093f9fc102b i3c: renesas: Check that the transfer is valid before accessing it 5697d779577e i3c: master: svc: bound IBI payload to the requested max_payload_len 94fb9786d67a i3c: master: Fix info leak and UAF in device unregister path a15a1b95de98 i3c: master: adi: initialize the lock before enabling interrupts 1894fc7a3bab dm-pcache: fix use-after-free and invalid seg operations in kset_replay() 10acf740c3ad dm-pcache: fix implicit u8 truncation of gc_percent in message handler 83e3116283ed dm-pcache: only hand out initialized cache segments 663ee2f3824a dm-pcache: detect a cycle in the last-kset chain during replay 2cd9776fe3f2 dm-pcache: clamp the tail kset read to the segment data region ffd9a214a94f dm-pcache: bound the persisted tail-position offset 91b93fe5cf4d dm-pcache: validate on-media seg_num against the cache device size d8caf96040a0 dm-pcache: validate kset key_num and intra-segment bounds ab5dcde6fa96 dm-pcache: validate geometry fields from on-disk cache_info 296efdc110b1 dm-switch: use WRITE_ONCE() in switch_region_table_write() 74210fa07296 dm-stats: fix a crash if allocation of per-cpu data fails c860cd3f4038 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map() edf30d65e3ac net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry 44dc702be9a9 rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22 b5fe67111e63 ovpn: run deferred work on a module-owned workqueue 50f4a793c4ff ring-buffer: Fix subbuf resize race with ring buffer readers 22fe01a2e2f7 ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering 37c3210c491a ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG 8acb66d0513d ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx 40ee4224e2fe ALSA: virmidi: Check card index validity at probe 7555e83d7738 ALSA: serial-u16550: Check card index validity at probe d7ef7890e3e3 ALSA: portman2x4: Check card index validity at probe 7ef9ad82d95d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ a4e774eeb61a ALSA: mts64: Check card index validity at probe cc4215cc2a4b ALSA: mpu401: Check card index validity at probe 13d61a920435 ALSA: hda/ext: preserve PPLCCTL bits when clearing reset 7df3194bdb74 ALSA: bcd2000: clear the URB pointers on disconnect 7b3f98558493 ALSA: aloop: Check card index validity at probe 2a6f6fba3bd3 ALSA: 6fire: bound the MIDI event length from the device 94ca4f040ba4 mfd: sm501: Fix potential memory leaks during remove 5e7fe9c6c8c3 mfd: cgbc: Fix teardown ordering in cgbc_remove() efe0ed4c0f4e hwrng: stm32 - Fix runtime PM cleanup on registration failure cfa186a0857a seg6: reset IP6CB after IPv6 decapsulation 288f99706708 net: skbuff: don't touch shared zerocopy state in skb_tx_error() 34ab62c959f5 net: fix spurious TX timeout after dev_activate() af0ee8f04bea net: cap advertised IP tunnel headroom 5bd8b764a610 net/smc: unregister the connection before draining the rx tasklet 313f79149eb3 net/smc: stop killed, freed and out_of_sync sharing a byte c52a998a223e net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() 0761e49aa78c net/smc: fix use-after-free in smc_rx_pipe_buf_release() d89dc1bd8845 net/smc: fix socket refcount leak in smc_switch_conns() f950e1b1f0aa net/smc: do not dereference an unset send buffer on the SMC-D teardown path 486c699a8cde net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages b893152a886b net: ntb_netdev: Count packets dropped on RX refill failure 4fac86e97697 net: ntb_netdev: Avoid double-accounting netif_rx() drops dfab7171cd39 net: ntb_netdev: Fix TX busy and drop handling 6b6bbc6c878d NTB: ntb_transport: Reject oversized TX buffers 894e136b432d NTB: ntb_transport: Fail TX enqueue when the QP link is down 0c4aabc90449 NTB: ntb_transport: Recycle TX entries before client callbacks f01e6a35c440 net: thunderbolt: Mark the connection down when bringing it up fails 61ff3c353e5d net: thunderbolt: Release the Rx HopID that was handed out on mismatch 67a82e6f886b net: ravb: serialize PTP clock teardown 8d4d06d6e2b5 net: ravb: avoid dereferencing an invalid PTP clock b6b533f83461 net: phylink: correctly validate returned PCS in phylink_inband_caps 0860af127aa7 net: openvswitch: fix nf_connlabels leak in ovs_ct_init ac73e3af571d net: openvswitch: fix flow mask use-after-free on flow deletion 9c340473f482 net: l2tp: do not propagate multicast notification errors 62da38b4b3a0 net: ipa: fix stalled modem TX queue after runtime resume 42a33e679ea0 net: ibm: emac: mal: fix NAPI locking f71087e7c63a net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO e098d9cc8859 net: tun: bound receive headroom 32785d75e60d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition 486577db8078 slip: fix use-after-free in sl_sync() 15d1f3c0dbe7 xdp: fix zero-copy frame layout 8e3763f1ccac net/iucv: filter frames in afiucv_hs_rcv() by ingress device 99692252b348 ipmi:msghandler: Cancel work cleanly on an error 53af3a8bae0a ipmi: si: Fix NULL pointer dereference after failed registration d46c97eddcbc ipmi: Remove all sysfs files on registration failure 5719431ca2b5 ipmi: ipmb: validate write message length db8147c5d5ad interconnect: Fix use after free in icc_get() and of_icc_get_by_index() 417e02f7b605 io_uring/query: cap user size passed to copy_struct_to_user 0c12a798078b platform/x86: hp-bioscfg: warn on element type mismatch instead of failing a38127df99ae platform/x86: hp-bioscfg: pass validated element count to package parsers 95d2f9b5189d platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed b15b334fbc3c platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() e3c1c5d1c923 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password 0f9aad084248 platform/x86: hp-bioscfg: fix heap OOB read on empty password write 7cd8fe01aba3 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() dea1a41160e7 platform/x86: hp-bioscfg: bound ordered-list parsing by the package count 0cd1530f84e1 platform/x86: hp-bioscfg: advance elem past consumed array elements 0a14d35ef529 platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS bc9aa5fe21c3 platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails 8178f59d7657 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address 98d91d5b6a98 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths 5eaf7faa9957 platform/chrome: sensorhub: Bound the EC-reported sensor number 56dc46094973 platform/x86: think-lmi: Fix current password length check 9c28adde051f platform/x86: think-lmi: Free system certificate signatures 89a076948ed6 platform/x86: think-lmi: Fix certificate thumbprint sysfs output d7cd3e4d7603 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response e1b3f89673bd platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path e07a42bb9c90 platform/x86: ISST: Return error during profile addition 62840acc3044 platform/x86: ISST: Validate parameter for frequency and priority 93268bc3cd84 platform/x86: ISST: Validate parameter for core power state 5b032e1dda48 platform/x86: ISST: Validate logical CPU id and clos id b14db79d02bd platform/x86: ISST: Use PP level enable mask 92c5fffa63ad platform/x86: ISST: Just allow 2 bits for SST feature enable c280fcd53b93 platform/x86: ISST: Add a NULL check for sst_inst[] 2550f89589ca mmc: via-sdmmc: stop card-detect handling on probe failure f7ff3027ef00 mmc: via-sdmmc: cancel card-detect work on remove 82e707eff9e3 platform/x86: ISST: Validate socket ID in clos_assoc ioctl 1889a9156553 platform/x86: ISST: Validate level in perf mask ioctls 22222f92b0a5 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer cab289572951 iommufd: Fix UAF in selftest IOPF reporting 4c33d00ad9a9 iommufd: Release current IOAS on xa_store() failure 436189ee4bb2 iommufd: Avoid locking internal accesses during unmap 45705a6bfdb2 iommu/vt-d: Force requesting ACS when tboot is enabled 364279b5623f iommu/vt-d: Fix no_iommu to disable platform opt-in f80f3acb6916 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add 2235eafda9b3 iommu/arm-smmu-v3: Manage teardown with devm d903d99ffd22 iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field 968e9a1f7114 iommu/sva: Set handle->dev before the SVA handle is visible f532401be931 iommu/msm: Unwind probe state on registration failure cfc5c1b2caa1 iommu/amd: Put PCI device after handling PPR faults 238e1f7a1463 PCI/proc: Warn on writes to kernel-exclusive config space regions c2d4174f4924 PCI/proc: Use file_ns_capable() when checking config space read access 301288f85679 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses b30713111325 PCI/MSI: Enable memory decoding before restoring MSI-X messages 0e59a232aaa0 PCI/ASPM: Avoid L0s for Realtek RTS525A 39c4dc79d77f PCI/AER: Fix mapping of errors to agent & layer 4f887d8ed75f PCI/AER: Emit TLP Log only for unmasked errors 6beadccc432c PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses 7f4db64f0ba7 PCI/sysfs: Fix read byte order in pci_read_legacy_io() 43cf455dd5a9 PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] 4b575052ea65 PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() 01c2f0c66bd1 PCI: plda: Fix use-after-free of event IRQs during teardown 5d4bc470330a PCI: meson: Fix GPIO state while requesting PERST# 1ad699485385 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk 6053d6eacbfd PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip ceafb262475a s390/dasd: Propagate partial completion length across ERP recovery 6452c13646af s390/dasd: Guard sysfs discipline callbacks against unallocated private data 52b331c99baa s390/dasd: Do not complete a failed ESE read as successful dcce7a06ea69 s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks aad7247bd35a power: supply: max17040: synchronize work cancellation on suspend 17d43f64b17e power: supply: max17040: drop incorrect I2C functionality check 13fb0477da9b power: supply: max17040: propagate register read errors 39b60d615dfa power: supply: ucs1002: fix use-after-free on remove a4460e89d408 power: supply: twl4030_charger: cancel workers via devm 1b9978433c61 power: supply: rt9455: quiesce delayed work before teardown ee053561e21c power: supply: qcom_battmgr: terminate the strings from firmware 06618447029c power: supply: qcom_battmgr: fix use-after-free b3aa1e9509e1 power: supply: lp8788-charger: fix use-after-free on remove ab6b1ad710be power: supply: lp8727: fix use-after-free in lp8727_release_irq() 4b1f2be1e1b7 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS 78be8b7403ff power: supply: cros_usbpd-charger: bound the EC-reported port count 86e4fa65368f power: supply: charger-manager: register regulators before exposing sysfs 238320ad029a power: supply: bq25890: Fix power_supply reference leak 9e1aba34df9a power: supply: bq256xx: drain usb_work before freeing the charger f495808cdd6d power: supply: bq24257: fix use-after-free on remove d02a5794c3de sctp: fix stream->outcnt underflow on duplicate RECONF responses 7ad8933bca97 sctp: distinguish sequence zero from wildcard in reconf lookup 25419f516ea8 sctp: fix NULL deref on untransmitted RECONF completion 1035bdef1efb sctp: drop a chunk if its transport was removed fa306a40e716 sctp: stop processing a packet once its association is deleted 8a02ad98798f nvme-tcp: reject a read that transferred too few bytes 3b3d27670c0c nvme-tcp: fix host memory disclosure on R2T for a read command 6a01b5826310 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone 0d4f317b07d6 nvme-pci: disable controller on admin queue IRQ setup failure 67551d8430df nvme: zero the discard fallback page 1e456cc2744e nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path d662f7fc04fd lockd: fix NULL dereference on lockowner allocation failure 41f0a6d31615 lockd: pin next file across nlm_inspect_file lock-drop 3088e41292fe ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() 6aeff1636b39 i2c: mxs: fix DMA channel leak on probe error 8d2c120d2d5b hwmon: (max6621) fix temperature clamp range 9b38d9a2e46a hwmon: (max6621) fix negative temperature offset and crit readings 68c59343ad1a ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC f2a1a83487c6 arm64: proton-pack: Restore the nospectre_bhb command-line option e7c9b1d433b0 arm64: compat: Fix decrementing LDM/STM alignment emulation 15d1feeae07d ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion e41a59fc056f openvswitch: only skb_tx_error() a packet we are about to drop d64a75369cd0 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall c0c165487a2e ocfs2: fix readdir position truncation on 32-bit kernels 0608018a71f2 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure 251e38f5af7b ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item ce035f208d68 ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() 0761d2c94944 ocfs2: validate rl_used against rl_count in refcount block validator 50c4cc9183e1 ocfs2: validate lengths in dlm_mig_lockres_handler de10cd3b062a ocfs2: bound namelen in dlm_migrate_request_handler 71f07b7f90b3 ocfs2: always run deallocs on copy-on-write completion 116d14f29a05 orangefs: skip leading spaces before parsing client debug masks f796f38a324e orangefs: fix double-free of trailer_buf on readdir copy failure bc6fdd425fde PM: sleep: Unblock runtime PM when device prepare fails 6fcb0b745a0b ring-buffer: Hold cpu_buffer::lock when resizing a subbuf 8c1ecdcdea73 ring-buffer: Free cpu_buffer::free_page with subbuf_order 2dc510957fe8 ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() 1c3036a81800 regulator: qcom-refgen: correct the regulator type to CURRENT 20e5fbb8c1a4 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata 95342d26f9c6 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer 71d5c41ac583 RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR 4f8bb11dd2ff RDMA/ucma: Lock the handler in ucma_write_cm_event() 28ac2dd41648 RDMA/ucma: Lock the handler in ucma_set_ib_path() a38cd610b24f RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget 85f438382a86 RDMA/cxgb4: Cancel reg_work before freeing device on remove 2a952fb1b20d qede: Fix NULL pointer dereference in TPA fragment processing 3f5677d2f817 ptp: vmclock: prevent read-only mappings from becoming writable c7e32814a6bf remoteproc: scp: Fix device reference leak on failed lookup 37797d5013c9 riscv: unaligned: stop using kthread for check_vector_unaligned_access() 8f392916a354 riscv: acpi: Handle LPI architectural context loss flags 5343399ed724 arm64: dts: rockchip: Fix rk3588s-roc-pc audio description 8fc4bafabc06 arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio 650d2d5c0df7 arm64: dts: rockchip: fix emmc reset polarity on px30-cobra 5512c2323120 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck fe455c13bf01 arm64: dts: rockchip: fix eMMC reset polarity on PP-1516 b6b3e4d5973b arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on 6bb9469c34ff arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags ff23eb4823d8 Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro" eb57632f9418 rpmsg: glink: smem: order FIFO read after availability check e7143c3f4e5c scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() 2a8dd9fd12f3 media: staging/ipu7: fix async notifier UAF on probe error path 7f6956b6dcd6 staging: media: tegra-video: vi: fix probe failure on skipped last port 656d047dc0c2 staging: media: tegra-video: fix of_node_put() on VIP parse errors 5be6d02837d4 wifi: mt76: mt7925: cancel pending mlo_pm_work e1330d719c04 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets b95c33a4e743 udf: reject VAT indexes equal to the entry count f84ec84d8d4b svcrdma: Validate Read chunk positions before reconstruction a798714b5804 svcrdma: Reject Write/Reply chunks with segcount 0 1949dd1576f7 svcrdma: Reject inline replies that overflow the pull-up buffer 3cf372cec7ab svcrdma: Reject connection when transport allocation fails 5aabe070c00e svcrdma: Fix unmatched rn_unregister on failed accept a1c954ca4977 svcrdma: Fix pcl_for_each_segment for empty chunks a46b35f213c2 svcrdma: Fix offset arithmetic in read_chunk_range 1de391e8b94e SUNRPC: wait for in-flight client TLS handshake callback 1f9856af065b SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field 7a1d0501cbb9 SUNRPC: reject duplicate CREDS_VALUE options edeefb111d61 sunrpc: init gssp_lock before publishing proc entry ebcbd2523a85 SUNRPC: harden gss_unwrap_resp_priv length checks 806584a4b67a SUNRPC: harden gss_krb5_unwrap_v2 against short tokens fa46b6aa7a69 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat e769fcde3cc7 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir 08bc49e05412 sunrpc: defer rq_argp and rq_resp free until after RCU grace period bd1ef2cfb44d SUNRPC: Check svc pool percpu counter allocation 2e861ce2aaa4 SUNRPC: always drain cache_cleaner before destroying a cache_detail 39981133df21 SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode 9d04d64ad192 sunrpc: route to a populated pool in svc_pool_for_cpu() de942dd8c2c8 SUNRPC: svcauth_gss: enforce krb5 token minimum length e0778464049b SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry ad0cce80d4af SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow f1b7b2c7ffa9 phy: fsl-imx8mq-usb: fix typec switch leak on probe error path 704ecd010d4a params: fix charp corruption on allocation failure ff110e85837d nouveau/gem: reserve the bo in the info ioctl around the vma lookup 04ab51d4e369 module/kallsyms: fix nextval for data symbol lookup 51887ccd8879 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction d82b90a38c2c mpls: reload header after pskb_may_pull() 50d0aa7d25ba module: validate string table section types 3b097416b4cf md: do overflow check for sb->bblog_shift in super_1_load() 0efabe6229dc md/raid10: fix still_degraded being inverted in raid10_sync_request() 121d35014e49 mailbox: qcom-ipcc: fix duplicate channel allocation across holes 09e649117c54 libnvdimm/labels: Prevent integer overflow in __nd_label_validate() 627ce4902df1 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation a602cd128d17 ipv6: use RCU iterator to dump route exceptions 63f50e9f90d0 ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() b8282668d8fa ip6_gre: fix hardware header length for NBMA tunnels b36dfd6e8cff ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() a8af6fbac895 ip: orphan prefetched skbs before multicast forwarding 31e4be21dace ipip: fix skb leak in collect_md mode when metadata_dst allocation fails f9182a85991a jbd2: check need_resched() when skipping busy checkpoint buffers 71c6b872c746 jbd2: bound shrinker scans by examined checkpoint buffers 30e8cb8598aa kasan: fix cache shrink race with CPU hotplug 15deb4e33f47 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request 657054159d83 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative 94d548fc264a Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative 1bad0896cbc0 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection d0b28e9655f4 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb 68e7a31abc88 Bluetooth: hci_conn: re-enable advertising only for peripheral role 946d76db77ee Bluetooth: RFCOMM: serialize security confirmation handling 49fd7116f76b Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready ec3992e38f77 Bluetooth: hci_uart: Fix false success return in hci_uart_setup() 62100186f177 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative 1ed5982c5369 Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 c674c504bfdd cxl/pmem: Format the nvdimm serial number as unsigned decimal 14d52c15d5d9 cxl/features: bound fwctl command payload to the input buffer 2924b2e36514 cpufreq: schedutil: Fix rate limit overflow a807a9ef87ad coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior ac4a5eb8b002 dm array: reject an array block whose value size is not the caller's b33f76d33aae dm array: validate array block headers on read 644140527ae4 dm raid1: reserve space for NUL-terminator in build_constructor_string() 36ff918637e3 dm-era: fix shadowed superblock leak on take-snap failure 49694a363f7e dm-io: report non-retryable errors separatedly 9493ac67623d dm-io: clone the source bio instead of copying its biovec 272fcb4ba6fa bpf: Harden bloom filter sizing and indexing on 32-bit kernels c9189693db47 buffer: avoid tail commit walk for uptodate folios dbfecc8a6631 bpf: Disable preemption in __bpf_get_stack 6886642414f5 bpf, x86: Fix per-CPU address resolution into an extended register 49dcefa83c8a bnxt_en: Write doorbell when linearizing skb fails 4d36e38e4834 bnx2x: fix double free in bnx2x_init_firmware() error path c21fa79301d7 Bluetooth: eir: Fix OOB read in eir_get_service_data() f609eac02d11 Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728 bce588b4ca08 Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU aa7b93fe98ba Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU ce76ca5fb279 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead() 84858671842a auxdisplay: charlcd: cancel backlight work on registration failure c2e3dccd6870 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes fdc0a5e2cbac ARM: 9477/1: Disable broken eBPF JIT on the Risc PC 87d07aa5d38b alpha: marvel: Fix lock ordering in init_io7_irqs() 9e1eefc01912 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number 2fd984c44e3e alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write() 6d4ed2fd022b ACPI: pfr_update: fix stack buffer overflow in query_capability() 452eb28e0301 ACPI: APEI: GHES: fix ARM section length accounting after header b7476b29b696 ACPI: APEI: Fix ERST timeout unit conversion c735dbce7ad0 acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks 9ad8821573a3 accel/rocket: Fix error path handling in rocket_job_run() 304323029665 accel/rocket: initialize job domain before cleanup paths c1a5bf1b6e1d accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() a3c65af20cce hugetlb: only adjust reservation during unmapping if mapcount is 0 4e019e5e247b hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device 137c61a6cfd9 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration 0c3f4544ff38 forcedeth: fix off-by-one when saving/restoring non-PCI config space 466a8af0dee2 fbdev: uvesafb: unregister connector callback on init failure 3bcab9b21f71 fbdev: ssd1307fb: defer I2C transfers from damage callbacks 3c1b5809615c fbdev: pvr2fb: correct user pointer annotation and sentinel initializer 76818e81cfca fbdev: omapfb: panel-dsi-cm: initialize lock before registering display 2f66f8ceefc2 fat: restore original value when fat_ent_write failed 66aa9a9e6481 fanotify: fix use-after-free of file range info 92895a14329c efivarfs: Rate limit statfs() handler ce568f6e025d ecryptfs: show filename encryption options 9319706316a8 ecryptfs: release message context on send failure b31da1ecf139 ecryptfs: reject too-small tag 70 packets 14cb36a500a5 ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet e5d254e654f2 ecryptfs: pass packet set buffer size to parser 0d9636ecba34 ecryptfs: hold msg ctx list lock when cleaning daemon queue c1bc956a615d ecryptfs: fix tag 11 packet exact-fit size check 98b890563424 eCryptfs: bound the packet-length peek to the user buffer 7ccb94901f38 fs/ntfs3: bound page_lcns[] index by the log record 376ee45659a4 fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() 2d94ffc9d7b5 fs/ntfs3: validate dirty page table on log replay 5333e18e6b42 eventfs: Initialize ei->children and ei->list in init_ei() b2301bdb4b3e HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown 99f3e197920d HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown 72706b44b665 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer 6fcefe71aeb5 HID: intel-thc-hid: intel-quickspi: validate report size before copy 127de5919820 HID: mcp2221: validate report size in mcp2221_raw_event() c99ba6c234d4 HID: mcp2221: stop device IO before hid_hw_stop 01d9874e84d3 HID: universal-pidff: stop the device when force-feedback init fails 114a58640aaf HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind f3f37b937a6e HID: sensor: custom: Fix field sysfs group cleanup on failure da00eac19fee HID: roccat: free buffered reports when destroying device 471f4a939c66 HID: picolcd: clamp eeprom debugfs read to bytes actually received 79465a30050d HID: corsair-void: Check size of status and firmware events before reading them e78973fe3ef5 HID: apple: preserve keyboard backlight across T2 resume 846f0709559b smb: client: harden DFS cache against invalid target hints 17a1922ada87 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV 1f824f61d1df smb: client: fix ALIGN() overflow in symlink_data() error context loop 9ab46a13798a smb: client: clear ce->tgthint in free_tgts() 8b9b10fe5b8b cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC c2a0dcb5a7a1 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 4f18c9e7ee46 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() 636a99bab36b audit: avoid dropping live tree ref on fsnotify rule autoremove 25128202a8df btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag f42efd634c0a btrfs: fix extent map leak in NOCOW direct I/O write 8a64baeb5bbb btrfs: drop recovered reloc root refs on recovery failure ec32015a955c ceph: fix leaked inode reference on writeback abort at umount 37d6edb2f03b ceph: do not repeat ceph_trim_dentries() if no progress possible 1dd356310b16 ceph: bound xattr value length in __build_xattrs() 58c2d3e954c1 ceph: bound num_export_targets array for mds info v2/v3 c37db86d2b5e ceph: bound MDSCapAuth path and fs_name decode in handle_session() 06fb5e623cdc ceph: bound copied dentry name length in NFS export get_name 4d298880f82c ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode fe46746087b5 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock 00562ccd4e88 libceph: reject buckets with mismatched CRUSH ids 2571b3588326 libceph: validate OSD extent maps before cursor advance b413ec5b23e3 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup 4804c58f73a8 NFSD: Prevent lock owner use-after-free during client teardown b56d2c5f01cd nfsd: revoke copy-notify stateids before dropping their reference dbc11a12aa54 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE ad02d095439f nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE 54e02f5e32c5 nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops 4ae5d7490ae6 nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() b57bd8cb739c nfsd: initialize DRC hash table before registering shrinker a4d7fedcaaf3 nfsd: initialize copy-notify stateid before publishing it 763c0bad8723 nfsd: hold rcu across localio cmpxchg retry b3bff820d068 nfsd: gate nfs3 setacl by argp->mask f951b22dbeec nfsd: gate nfs2 setacl by argp->mask 41ebca28e17f nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo 0380129b1373 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget 4106d7a6aaf1 nfsd: fix version mismatch loops in nfsd_acl_init_request() 9b4e5e9ba5ae nfsd: fix stale s2s_cp_stateids IDR entry for async COPY 2ebbf4e3e9cf nfsd: fix reply size estimate for GET_DIR_DELEGATION cf081015a0d1 nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure 3c5119b799a7 nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs 424d5c95108a nfsd: fix nfsd_file leak on inter-server COPY setup failure 360e1b9e3f31 nfsd: fix netlink dumpit error handling for rpc_status_get 65c79d9bb371 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types c1ae0f973bcb nfsd: fix dentry ref leak on V4ROOT export filehandle lookup a631a26a8777 nfsd: fix cpntf publish race in nfs4_init_cp_state 607a56fea772 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke 00843074d9b8 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry 72d40b103bb0 nfsd: don't free session slots that are still in use 6703199f4d7e nfsd: defer vfree of compound ops to fix rpc_status UAF 631b7d5dbbba nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper e879148867bd nfsd: clear opcnt on compound arg release to prevent OOB read b137930ee52e nfsd: clear CALLBACK_RUNNING on failed delegation recall queue b42dc26a14b4 nfsd: check client ownership when cancelling a copy-notify stateid 311f7d926630 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref 1aea0482b98e nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry bff024551a71 nfsd: add filehandle match check to nfsd4_delegreturn() 533964d420d3 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() 895a485cd375 nfsd: validate symlink target length in NFSv4 CREATE 2aca70c18c5f nfsd: validate sockaddr length per family in listener_set 7e7b93da7fa2 nfsd: validate nseconds in TIME_DELEG decode paths 7ff8d6363cff nfsd: size fh_verify server sockaddr slot by xpt_locallen 1e4795766719 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations 8277d4a11ae2 nfsd: sample writeback error cursor before async COPY loop fc83f30731dd nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types 591134e059e3 nfsd: Reset write verifier when async COPY writeback fails 467d56fd3ff5 nfsd: release path refs on follow_down() error f164eb52b6f3 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown dc803d46a8b9 pNFS: Fix EBUSY check in pnfs_layout_need_return 36e3f13bf072 NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path 59baf45a0643 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose 7ef182a8fe9c NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check 4ed8d2317aef NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock 75d13317f163 NFSD: Fix off-by-one in DRC bucket pruning limit e547b06234f8 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies d8352da19634 NFSD: check truncate permission under inode lock f3adf1643517 NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails 5215e734bf7c NFS/localio: fix ref leak on nfs_uuid_add_file failure 344ae0e232d4 zsmalloc: account for handle size in class lookup 923578d0f0d0 zram: validate deflate params a1dc246f98bb ubifs: fix out-of-bounds read in signature length check 14afe18655c0 phy: rockchip-samsung-dcphy: fix out-of-range max_register e892f05f1f79 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() 9253cfc5a85b of: fix out-of-bounds read in of_alias_scan() stem parser 448636c745a3 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation 8c14472431e2 media: vicodec: fix out-of-bounds write in FWHT encoder 0c260d3f97e5 media: cec: stm32: prevent out-of-bounds write on RX overflow 7d658da725ea lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() 9f43499ce645 HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature 827ec385458a fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write 34e88f536146 usb: gadget: f_fs: Prevent deadlock during ep0 read loop 9897b7da8c0a usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() dbe2762ae8e5 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() 6bcd9ee6ad69 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() a15c2acd3083 usb: gadget: midi2: remove default configfs groups on teardown 64005cf3e897 usb: gadget: snps_udc_plat: clean up PHY on probe deferral 4e747c864a88 usb: gadget: u_audio: Fix use-after-free on sound card disconnect 14fa29f3be06 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion ebb840d982a6 usb: typec: thunderbolt: Disable work before freeing tbt on remove d793bd8422e7 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() 12414bbd3e3f USB: phy: fsl-usb: fix missing static keywords 51a311eb97e9 usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed 448e95c0f3ea usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition 316abfe39dce usb: dwc2: gadget: Exit partial power down state when changing USB pull-up 78f5c6e6aef9 staging: greybus: hid: fix SET_REPORT return value 28b932202fcd serial: imx: serialize imx_uart_ports[] lifetime aad08b5f67d2 Revert "media: v4l2-dev: fix error handling in __video_register_device()" e6e925cc1f80 rapidio: mport_cdev: fix use-after-free in dma_req_free() c3d4be91c6fc powerpc/powermac: fix OF node refcount 29e634a18957 misc: nsm: bound the device-reported response length ba69d892ff4e device property: fix infinite loop in fwnode_for_each_child_node() 4cd24873ab9f cdx: Fix double free when sysfs file creation fails b1a49c22de01 tracing: Fix use-after-free with same-name named triggers ddbe921ed16a tracing: Fix use-after-free in trace_pipe read on sub-buffer order change cdb6fb6cf1a7 tracing: Fix logged instance name on creation failure adadf4192f70 tracing: Fix crash passing ERR_PTR to kthread_stop() 25a0758cf6bd tracing/user_events: Clear copied tracing state before fork duplication b503a61d5d39 hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() 9b51dcb4f230 x86/tdx: Fix zero-extension for 32-bit port I/O c4a221548708 x86/tdx: Fix off-by-one in port I/O handling b9ae969e6f1e x86/locking: Use sfence for wmb() if SSE is available 08b4cdef3c2e x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg() 968eea465942 tools/compiler: match glibc 2.42 definition of __attribute_const__ d4bf3a74e2ba mm: vmscan: fix node reclaim ignoring swappiness parameter 461d23368f29 mm: page_alloc: fix non-movable reclaim storm in defrag_mode d435ba3c21a0 mm: page_alloc: move capture_control to the page allocator 0df04778ea14 mm: page_alloc: __GFP_FS lockdep annotation for direct compaction b3d4b65085ef mm: mempolicy: fix automatic numa balancing for shmem 5d866086d5f8 mm: memcontrol: update state_local when flushing NMI stats 95d87030cae7 mm: memcg: stop reclaim when a limit update is superseded 680b93894ddf mm: memcg-v1: fix memsw and TCP failcnt accounting d0943afb5ed8 mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings 295f5a61d3ae mm: compaction: support non-movable compaction for pageblock requests ef765a2e4f57 mm/zswap: fix global shrinker when memory cgroup is disabled 3fd502399863 mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() 895cd4ecbb2e mm/pagewalk: fix stale walk->action escaping walk_pmd_range() 45489d4f9580 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn 5dc0daff0341 mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() 3fc8044251de mm/kmemleak: avoid soft lockup when scanning task stacks 2cfa9ae90813 mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios() d423737dca23 mm, swap: ratelimit bad swap entry reports f2c14f4d427d include/linux/list.h: mark list_add and __list_add as __always_inline 28069434aef6 apparmor: fix out-of-bounds write when null terminating a label vec 587a6a92b93e apparmor: fix cred UAF caused by begin_current_label_crit_section() 753c978f2400 KEYS: trusted: Fix TPM teardown ordering 0a10989de610 rust: kernel: list: fix incorrect pop_back example comment 138722d631ac rust: bug: skip arch-specific asm in `testlib` builds 2bf5e8f7c9bf timers/itimer: Zero-init old itimerval before copy to userspace e6da8a0f3976 powerpc/pseries/iommu: switch to Default DMA window during kdump c03114634d34 fs: fix user path of nested backing files bf38be01d43c clocksource/drivers/timer-sun4i: Advertise a real minimum delta d53c29a89a15 clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path 312f85fdd029 alpha: don't leak hardware-fabricated FP exception bits to user space c25b2aa077d5 rust: time: fix as_micros_ceil() rounding near i64::MAX 7d00a3ff6244 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally 4628e40c9ca7 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile 7d860bed1336 drm/amd/display: hide Apple Studio Display secondary tile c6b915f0df31 drm/amd/display: Refactor amdgpu_dm_connector_detect (v2) a1fa3d1197cc drm/amd/display: Skip PHY SSC reduction on some 8K panels d5c9d19b0ff2 netfs: Fix missing locking around retry adding new subreqs ce493f9261cd platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int() 2ab18de5ebb1 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths 24ebaf6676ae nsfs: tighten permission checks for handle opening ea150ffa9fc9 bpf: Fix incorrect pruning due to atomic fetch precision tracking 5d562153b471 ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS a8bbb2a60513 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free 5fc3d921512d wifi: ath11k: fix memory leaks in beacon template setup 8527ac1bce87 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() c79ef3342632 perf/x86/intel/uncore: Fix die ID init and look up bugs