UPDATE: 6.12.110 - #1377
Open
fepitre-bot wants to merge 1 commit into
Open
UPDATE: 6.12.110#1377fepitre-bot wants to merge 1 commit into
fepitre-bot wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update to 6.12.110
Details
Changes since previous version:
gregkh/linux@74456843f18b PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
gregkh/linux@825b95561d7b Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
gregkh/linux@013448eb7b0d ALSA: scarlett2: Use a private URB for the notification endpoint
gregkh/linux@c5398ce6db76 rndis_host: add overflow check in rndis_rx_fixup()
gregkh/linux@84be002b40d3 gpio: ml-ioh: use raw_spinlock_t for the register lock
gregkh/linux@447ddf805994 gve: fix zero-length skb frag with header-split
gregkh/linux@cfb38b036992 hwmon: (ltc4286) Fix symbol namespace of MODULE_IMPORT_NS()
gregkh/linux@d4ae8dba90b8 netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
gregkh/linux@69d27cf39966 inet: frags: add inet_frag_putn() helper
gregkh/linux@872c093deef0 ipv4: frags: remove ipq_put()
gregkh/linux@8a681bcea4c4 inet: frags: change inet_frag_kill() to defer refcount updates
gregkh/linux@da9c1c1a1c0f inet: frags: save a pair of atomic operations in reassembly
gregkh/linux@39c6c4b267b6 inet: frags: publish queues before arming timer
gregkh/linux@c321dc5172c8 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
gregkh/linux@3f2a15f33f86 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
gregkh/linux@9f6989e477f0 serial: amba-pl011: synchronize DMA teardown
gregkh/linux@5ed1be08b353 serial: sc16is7xx: rename EFR mutex with generic name
gregkh/linux@76a91352fbd6 serial: sc16is7xx: use guards for simple mutex locks
gregkh/linux@49bd99360538 serial: sc16is7xx: enable THRI before filling TX FIFO
gregkh/linux@f607b13ad656 xfs: namespace the maximum length/refcount symbols
gregkh/linux@fbfd43c85b1a xfs: don't use a xfs_log_iovec for ri_buf in log recovery
gregkh/linux@7e32d4eebae6 xfs: bounds-check buffer log item's dirty bitmap
gregkh/linux@063dd7a53d4e xfs: hoist per-bucket unlinked list check to helper
gregkh/linux@599453f83458 xfs: don't livelock in scrub on a circular unlinked list
gregkh/linux@c9f10a001c24 ALSA: dummy: Check card index validity at probe
gregkh/linux@b9eb5c9fdd81 ocfs2: fix missing metadata reservation for large xattrs
gregkh/linux@5327827c7dba null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
gregkh/linux@18799e858b40 kcov: fix data corruption and race conditions on PREEMPT_RT
gregkh/linux@889ec86464d2 ext4: stop retrying saturated xattr cache entries
gregkh/linux@e0aeee3b3d3c ext4: clear error before retrying inode xattr space fallback
gregkh/linux@40b741de4a82 ext4: propagate errors from fast commit range replay
gregkh/linux@98a42bb9d60d xfs: validate attr entry pointer before field access
gregkh/linux@c59219a6b62d libceph: fix OOB read in decode_watchers() via missing bounds check
gregkh/linux@af4c0606f743 nfc: digital: clamp SENSF_RES length to the destination buffer
gregkh/linux@0d723090645b nfc: fdp: bound the device-reported read length and fix an skb leak
gregkh/linux@e6397fe7b8b5 nfc: microread: validate target discovery payload lengths
gregkh/linux@389986fd79e4 nfc: llcp: bound the connect_sn TLV walk to the skb
gregkh/linux@382eaa770335 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
gregkh/linux@eab47618e282 nfc: llcp: reject PDUs shorter than the LLCP header
gregkh/linux@e16927728137 nfc: pn533: purge fragmented skbs during cleanup
gregkh/linux@0f344944c506 nfc: st21nfca: validate ATR_REQ length against the received frame
gregkh/linux@50e87e1c0e18 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
gregkh/linux@7086dab72b3e nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
gregkh/linux@022969dee274 nfc: nci: free destination parameters when closing a connection
gregkh/linux@4bfce749ef19 ndisc: ndisc_send_redirect() cleanup
gregkh/linux@ee944a706a18 Input: byd - synchronize timer deletion before freeing private data
gregkh/linux@36e0741833bd ipv4: reject undersized MTUs in ip_do_fragment()
gregkh/linux@3c770ac4e6f0 ipv6: fix use-after-free in ip6_finish_output2()
gregkh/linux@dfcf013f7770 nvmet-auth: zero the AUTH_RECEIVE response buffer
gregkh/linux@371fb1bf902a nvmet-fc: fix invalid free in LS IOD error path
gregkh/linux@d2acc96c528d nvmet-tcp: bound SGL data length before allocating command buffers
gregkh/linux@c509f20be1ca nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
gregkh/linux@d4a241723234 mptcp: pm: fix data race in add_addr timer callback
gregkh/linux@2ed3601e9db0 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
gregkh/linux@491c499295fb drm/xe: Fix DPT allocation paths.
gregkh/linux@d863aa31bd04 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
gregkh/linux@448260a3ec95 HID: magicmouse: re-enable multitouch after reset-resume
gregkh/linux@9bdf8c7bfd79 HID: magicmouse: do not keep a stale msc->input if no input is claimed
gregkh/linux@ba6af07e700b HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
gregkh/linux@a38212687519 HID: core: fix OOB read of field->usage in hid_set_field()
gregkh/linux@881a805a8029 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
gregkh/linux@8dd8929b71c4 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
gregkh/linux@684efb2c86c8 ipv4: start using dst_dev_rcu()
gregkh/linux@b2a0b55bf613 mptcp: pm: fix memory leak from alloc-during-teardown race
gregkh/linux@40e812ced723 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
gregkh/linux@b9a651311fd4 Input: atkbd - skip deactivate for HONOR ZQC-P
gregkh/linux@addca61f9a23 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
gregkh/linux@3288bec1a21d HID: nintendo: register input device after capabilities are set
gregkh/linux@03a84f9f88b4 HID: nintendo: stop device IO before hid_hw_stop on probe failure
gregkh/linux@dd8035dec26e HID: core: fix number/pointer type confusion on long items
gregkh/linux@244a1cb63837 HID: sensor: custom: Fix use-after-free in enable_sensor
gregkh/linux@f84d777574b7 HID: hyperv: validate initial device info bounds
gregkh/linux@d57702d4c556 Bluetooth: hci_event: fix LE list UAF on reset
gregkh/linux@a34df5c4a439 Bluetooth: hci_event: validate LE Set CIG Parameters response
gregkh/linux@8715ffd60872 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
gregkh/linux@7733b01ed136 Bluetooth: hci_aml: validate firmware segment lengths
gregkh/linux@03cb8cc2961f net: gro: properly validate BIG TCP aggregation criteria
gregkh/linux@8b74a2fbba5a Linux 6.12.106
gregkh/linux@dec2edb7aaf1 inet: frags: strip GSO state from fragments before reassembly
gregkh/linux@f717995cb7dc Linux 6.12.107
gregkh/linux@0136b528b753 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
gregkh/linux@bc6e94379451 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
gregkh/linux@d8636c8f9f95 KVM: x86/mmu: Check write tracking in all address spaces
gregkh/linux@ed1cd834da65 ext4: don't enable DAX on new encrypted files
gregkh/linux@2acc77e88670 io_uring/io-wq: fix worker accounting when canceling creation callbacks
gregkh/linux@d19f98c79f1b nvme-tcp: fix usage of page_frag_cache
gregkh/linux@569eff012480 HID: uhid: convert to hid_safe_input_report()
gregkh/linux@dd0e4d0441a0 selinux: use known type instead of void pointer
gregkh/linux@778fdda45307 selinux: avoid unnecessary indirection in struct level_datum
gregkh/linux@8e14b420188c selinux: make more use of str_read() when loading the policy
gregkh/linux@47f287839263 selinux: use u16 for security classes
gregkh/linux@8c07940b6cc8 selinux: more strict policy parsing
gregkh/linux@6c2ab7c4549f selinux: reject a permission value exceeding the class permission count
gregkh/linux@42a2949e0155 selinux: require a class's permission values to cover its permission count
gregkh/linux@e593031ff19a perf: Reject exited events as group leaders
gregkh/linux@77038187890e jfs: add check read-only before truncation in jfs_truncate_nolock()
gregkh/linux@939dba7a6404 jfs: add check read-only before txBeginAnon() call
gregkh/linux@005fee039dd8 ibmvnic: Use kernel helpers for hex dumps
gregkh/linux@233340626cf1 jfs: Fix null-ptr-deref in jfs_ioc_trim
gregkh/linux@29abaf93357f exfat: fix double free in delayed_free
gregkh/linux@2fbe83fe23f5 media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
gregkh/linux@544ffd62ddd0 mISDN: hfcpci: Fix warning when deleting uninitialized timer
gregkh/linux@4e154cb5e768 can: j1939: implement NETDEV_UNREGISTER notification handler
gregkh/linux@90265bd35d89 can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
gregkh/linux@02871132d8b0 can: j1939: make j1939_sk_bind() fail if device is no longer registered
gregkh/linux@08aca586482e smc: Fix use-after-free in __pnet_find_base_ndev().
gregkh/linux@c0fcd72e7eb5 KVM: arm64: Prevent access to vCPU events before init
gregkh/linux@956c57daba55 smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
gregkh/linux@326e5cf301d0 smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
gregkh/linux@9210ae708dde ASoC: nau8821: Cancel delayed work on component remove
gregkh/linux@1a2dc103e164 bpf: Fix use-after-free in offloaded map/prog info fill
gregkh/linux@2a7d1daf2674 riscv: Fix register corruption from uninitialized cregs on error
gregkh/linux@bea242c21187 Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
gregkh/linux@a6cd64ead3b4 ASoC: nau8821: Cancel pending work before suspend
gregkh/linux@2c10b145972f smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
gregkh/linux@0e7899950308 selinux: switch two allocations to use kzalloc_objs()
gregkh/linux@2b3a3c5d72da ring buffer: Propagate __rb_map_vma return value to caller
gregkh/linux@ef05dae9abb6 veth: fix OOB txq access in veth_poll() with asymmetric queue counts
gregkh/linux@45afabe7f99c powerpc/hv-gpci: fix preempt count leak in sysfs show paths
gregkh/linux@b708aa5cb142 ksmbd: harden file lifetime during session teardown
gregkh/linux@44b379a89076 nilfs2: correct return value kernel-doc descriptions for ioctl functions
gregkh/linux@68aa9ab6f8f2 nilfs2: reject invalid block index in GC ioctl
gregkh/linux@9b01f5af0dc5 nfc: nci: add data_len bound checks to activation parameter extractors
gregkh/linux@f49fbb6c1353 HID: pidff: Rework pidff_set_time() to fix warnings
gregkh/linux@dc6a6f604dce HID: pidff: Use ARRAY_SIZE macro instead of sizeof
gregkh/linux@c6cd31a5e280 HID: pidff: clang-format pass
gregkh/linux@ad9330f7e74a HID: pidff: fix OOB write when hid->inputs is empty
gregkh/linux@ab7bd22eeca0 HID: asus: simplify RGB init sequence
gregkh/linux@bdb2e0a2a359 HID: asus: fix missing hid_is_usb() check
gregkh/linux@e951ee73e423 HID: ft260: validate i2c input report length
gregkh/linux@5aa5a1b7cc4b HID: ft260: fix stack-use-after-return write in I2C read race
gregkh/linux@e750cdb6de00 HID: uclogic: fix use-after-free of inrange_timer on remove
gregkh/linux@1cd4bea9cb46 Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync()
gregkh/linux@87ad116ac3ab Bluetooth: hci_sync: Fix accept list UAF during suspend
gregkh/linux@bec338b07beb HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
gregkh/linux@198590bcd2ee fpga: dfl: fme: add error handling
gregkh/linux@a4bb1242c858 accessibility: speakup: unregister tty ldisc on later init failures
gregkh/linux@65b2f6f79753 usb: xhci: Handle USB3 port events when there is one roothub
gregkh/linux@943f976c93e7 xhci: dbgtty: Fix unregister on tty_register_driver() failure
gregkh/linux@3c281882d0c4 xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
gregkh/linux@ea9fea370b8d fuse: fix invalidate lock leak on setattr writeback failure
gregkh/linux@7288c279ddbd fuse: fix invalidate lock leak on open O_TRUNC DAX failure
gregkh/linux@48a4e549b8df usb: usbtest: disable dynamic ID support
gregkh/linux@2efbfd42441d usb: gadget: f_tcm: keep port count until LUN teardown completes
gregkh/linux@b7f10d4ff987 tls: device: fix out-of-bounds write in tls_append_frag()
gregkh/linux@5f77ddb27563 gtp: serialize PDP context updates
gregkh/linux@efb867f04917 x86/CPU/AMD: Carve out a Zen5 models range
gregkh/linux@e477275951de net/tcp: fix TCP-AO key deletion in VRFs
gregkh/linux@594ba77210a1 tcp: fix AO info use-after-free in tcp_ao_connect_init()
gregkh/linux@84a93b4e0125 net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
gregkh/linux@4b31a875693c xfrm: espintcp: fix UAF during close
gregkh/linux@c296d25efbc8 xfrm: drop ESP-in-TCP packets with no ingress device
gregkh/linux@ea0921046231 xfrm: avoid lock inversion in nat keepalive work
gregkh/linux@1516e31ac458 xfrm: ah6: validate routing header segments_left
gregkh/linux@71d42da01740 xfrm: fix xfrm_state_construct() auth-trunc leak
gregkh/linux@71cdc4bb7aa7 xfrm: bound nat keepalive state collection
gregkh/linux@3a0ad4fcdfa0 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
gregkh/linux@0e3f01fe2e70 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
gregkh/linux@da1f5aa7ec93 batman-adv: reject unrepresentable multicast TVLV offsets
gregkh/linux@2a7c2f008432 vxlan: keep the last remote linked during FDB flush
gregkh/linux@df86c0e84025 netfilter: nf_tables: don't queue packet path object notifications
gregkh/linux@45fec72da424 mm/swap: reject swapon() on filesystem-level encrypted files
gregkh/linux@34455bbab8db crypto: qcom-rng - Enable clock in hwrng case
gregkh/linux@813e6718a199 crypto: qcom-rng - Allow zero as a random number
gregkh/linux@bb474dcd9d02 crypto: qcom-rng - Remove crypto_rng interface
gregkh/linux@1f7b304b5577 crypto: atmel-tdes - use scatterlist length before DMA mapping
gregkh/linux@002f1f99aef7 crypto: qce - fix CCM AAD buffer underallocation
gregkh/linux@da14fae5203b crypto: mxs-dcp - fix source scatterlist length access
gregkh/linux@ca1a361e9e82 crypto: qce - Remove unsafe/deprecated algorithms
gregkh/linux@7d23489f5110 KVM: s390: vsie: zero stale crypto bits
gregkh/linux@bf2288583b4e usb: core: Add lock to usb_wakeup_notification()
gregkh/linux@b810896d6018 usb: core: Strengthen error handling in hub_hub_status()
gregkh/linux@7639ec9755d3 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
gregkh/linux@5a625fc2284e ALSA: usb-audio: Complete cleanup after system-resume errors
gregkh/linux@060db7d48af1 USB: serial: option: fix slab OOB read in interrupt URB callback
gregkh/linux@75894aa664f3 USB: serial: spcp8x5: drop broken carrier detect support
gregkh/linux@ff172092cba7 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
gregkh/linux@9a72b180f057 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
gregkh/linux@b3cde26a66b0 usb: usbfs: fix use-after-free of usb_device in usbdev_release()
gregkh/linux@064531c7e30c Linux 6.12.108
gregkh/linux@9ee185e0f155 bnxt_en: Mask the bd_cnt field in the TX BD properly
gregkh/linux@d713e105a613 md: make rdev_addable usable for rcu mode
gregkh/linux@7cd460bd9e7c f2fs: fix potential deadloop in prepare_compress_overwrite()
gregkh/linux@a09280c39ea5 block: mark GFP_NOIO around sysfs ->store()
gregkh/linux@03a3dbca3b8e drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1
gregkh/linux@bdb35811ff41 perf/x86/intel/uncore: Fix die ID init and look up bugs
gregkh/linux@7de35b995030 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
gregkh/linux@9478aa5b39e9 wifi: ath11k: fix memory leaks in beacon template setup
gregkh/linux@a71fdbd6e828 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
gregkh/linux@e67968dd19b3 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
gregkh/linux@b06a595370aa alpha: don't leak hardware-fabricated FP exception bits to user space
gregkh/linux@151eb52f8712 clocksource/drivers/timer-sun4i: Advertise a real minimum delta
gregkh/linux@88c927a63dc7 fs: fix user path of nested backing files
gregkh/linux@2d829b5dcd8a powerpc/pseries/iommu: switch to Default DMA window during kdump
gregkh/linux@4c66719dd1e4 timers/itimer: Zero-init old itimerval before copy to userspace
gregkh/linux@361488984d66 apparmor: fix cred UAF caused by begin_current_label_crit_section()
gregkh/linux@9124e078ea22 apparmor: fix out-of-bounds write when null terminating a label vec
gregkh/linux@956f8cbf946d include/linux/list.h: mark list_add and __list_add as __always_inline
gregkh/linux@9a1b12c06c19 mm/kmemleak: avoid soft lockup when scanning task stacks
gregkh/linux@4996a7bc01ef mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
gregkh/linux@b5391676c61d mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
gregkh/linux@2617f089521c mm/zswap: fix global shrinker when memory cgroup is disabled
gregkh/linux@39ec1e4183a7 mm: memcg: stop reclaim when a limit update is superseded
gregkh/linux@c81698178e9c mm: mempolicy: fix automatic numa balancing for shmem
gregkh/linux@25786749efbc tools/compiler: match glibc 2.42 definition of attribute_const
gregkh/linux@222b7005e451 x86/tdx: Fix off-by-one in port I/O handling
gregkh/linux@c1171d11c5cc x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
gregkh/linux@686456795227 x86/tdx: Fix zero-extension for 32-bit port I/O
gregkh/linux@707382e295a6 hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
gregkh/linux@63b39e49a4c9 tracing/user_events: Clear copied tracing state before fork duplication
gregkh/linux@12a499f741fc tracing: Fix crash passing ERR_PTR to kthread_stop()
gregkh/linux@9b5e544ee0a0 tracing: Fix logged instance name on creation failure
gregkh/linux@05ebe1e1d7d3 tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
gregkh/linux@477d762be4b0 tracing: Fix use-after-free with same-name named triggers
gregkh/linux@88f4cd42a04b cdx: Fix double free when sysfs file creation fails
gregkh/linux@20ed517e416d device property: fix infinite loop in fwnode_for_each_child_node()
gregkh/linux@339f19b9a617 misc: nsm: bound the device-reported response length
gregkh/linux@4b3a5504c013 powerpc/powermac: fix OF node refcount
gregkh/linux@9a9929ec875f rapidio: mport_cdev: fix use-after-free in dma_req_free()
gregkh/linux@712ca1cf756d Revert "media: v4l2-dev: fix error handling in __video_register_device()"
gregkh/linux@681696ae9e4a serial: imx: serialize imx_uart_ports[] lifetime
gregkh/linux@c23656711719 staging: greybus: hid: fix SET_REPORT return value
gregkh/linux@2c6c6d666d82 usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
gregkh/linux@a2a602cb1e28 usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
gregkh/linux@323629d797a4 USB: phy: fsl-usb: fix missing static keywords
gregkh/linux@ed6998475bdf usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
gregkh/linux@827cfd75ee3f usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
gregkh/linux@c74ff0b1a0fc usb: gadget: u_audio: Fix use-after-free on sound card disconnect
gregkh/linux@e6cb97c028df usb: gadget: snps_udc_plat: clean up PHY on probe deferral
gregkh/linux@4beda67ee72e usb: gadget: midi2: remove default configfs groups on teardown
gregkh/linux@f81a2da137b0 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
gregkh/linux@8e88ed8a374d usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
gregkh/linux@fd20cc68bbdb usb: gadget: f_fs: Prevent deadlock during ep0 read loop
gregkh/linux@b138bc665e21 fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
gregkh/linux@fa95b14198b6 HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
gregkh/linux@709eb41adaf7 lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
gregkh/linux@c3edd7fb8e36 media: cec: stm32: prevent out-of-bounds write on RX overflow
gregkh/linux@84cfebf7f422 media: vicodec: fix out-of-bounds write in FWHT encoder
gregkh/linux@5d3783c451a5 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
gregkh/linux@96a9c984dd7c of: fix out-of-bounds read in of_alias_scan() stem parser
gregkh/linux@f76b79d6e42a ubifs: fix out-of-bounds read in signature length check
gregkh/linux@343603228768 zsmalloc: account for handle size in class lookup
gregkh/linux@3afa17d93ba8 NFSD: check truncate permission under inode lock
gregkh/linux@7504777c617c NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
gregkh/linux@d10cc42dbd4e NFSD: Fix off-by-one in DRC bucket pruning limit
gregkh/linux@77de363d9a1c NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
gregkh/linux@b55b4d880bb0 NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
gregkh/linux@f4776c1c4b38 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
gregkh/linux@7c5b0e813efd NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
gregkh/linux@2ef79f5aa107 pNFS: Fix EBUSY check in pnfs_layout_need_return
gregkh/linux@194316df8126 nfsd: release path refs on follow_down() error
gregkh/linux@31d4d0a62ec4 nfsd: Reset write verifier when async COPY writeback fails
gregkh/linux@3ba1cc742b0e nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
gregkh/linux@52b2db7a72e1 nfsd: sample writeback error cursor before async COPY loop
gregkh/linux@d832a0587528 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
gregkh/linux@95d064f9828a nfsd: size fh_verify server sockaddr slot by xpt_locallen
gregkh/linux@b24843ea3de1 nfsd: validate symlink target length in NFSv4 CREATE
gregkh/linux@15ca3b64a69c nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
gregkh/linux@468dfe369aae nfsd: add filehandle match check to nfsd4_delegreturn()
gregkh/linux@f501f2f4ec1d nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
gregkh/linux@35f248bd40b4 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
gregkh/linux@b1eca0730359 nfsd: check client ownership when cancelling a copy-notify stateid
gregkh/linux@58bcdfb2b2e4 nfsd: clear opcnt on compound arg release to prevent OOB read
gregkh/linux@48f72aff24f7 nfsd: defer vfree of compound ops to fix rpc_status UAF
gregkh/linux@69ed78b6b947 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
gregkh/linux@c517f2749875 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
gregkh/linux@21d6c5957f5c nfsd: fix cpntf publish race in nfs4_init_cp_state
gregkh/linux@d493cf57f4c4 nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
gregkh/linux@1a6a41b84845 nfsd: fix nfsd_file leak on inter-server COPY setup failure
gregkh/linux@6f761ff71483 nfsd: fix reply size estimate for GET_DIR_DELEGATION
gregkh/linux@9a5e0b5e6ecd nfsd: fix version mismatch loops in nfsd_acl_init_request()
gregkh/linux@e7d9d23ecd91 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
gregkh/linux@74015b7be806 nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
gregkh/linux@e41d173d9dc7 nfsd: gate nfs2 setacl by argp->mask
gregkh/linux@68a80b26efdf nfsd: gate nfs3 setacl by argp->mask
gregkh/linux@e08a3dcaca05 nfsd: initialize copy-notify stateid before publishing it
gregkh/linux@f060f43a6763 nfsd: initialize DRC hash table before registering shrinker
gregkh/linux@55341d8a5a0f nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
gregkh/linux@a937dd1aa2d9 nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
gregkh/linux@a97d9466acba nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
gregkh/linux@6b8149448cdc nfsd: revoke copy-notify stateids before dropping their reference
gregkh/linux@a6ead6fff3a7 NFSD: Prevent lock owner use-after-free during client teardown
gregkh/linux@0ae0d2b5c5a1 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
gregkh/linux@058ffa81f944 libceph: validate OSD extent maps before cursor advance
gregkh/linux@3516a4131c4e libceph: reject buckets with mismatched CRUSH ids
gregkh/linux@2701431aa3cc ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
gregkh/linux@736adee11af3 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
gregkh/linux@61d9f27b191b ceph: bound copied dentry name length in NFS export get_name
gregkh/linux@dc5c7dffda92 ceph: bound MDSCapAuth path and fs_name decode in handle_session()
gregkh/linux@3bf7dba8dba9 ceph: bound num_export_targets array for mds info v2/v3
gregkh/linux@38be2f3c41ec ceph: bound xattr value length in __build_xattrs()
gregkh/linux@5a541eb401ac ceph: do not repeat ceph_trim_dentries() if no progress possible
gregkh/linux@2256d6dc5b88 btrfs: drop recovered reloc root refs on recovery failure
gregkh/linux@cf37b61b5420 audit: avoid dropping live tree ref on fsnotify rule autoremove
gregkh/linux@b098f5e58587 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
gregkh/linux@7507bd188564 smb: client: clear ce->tgthint in free_tgts()
gregkh/linux@657372ba6ea5 smb: client: fix ALIGN() overflow in symlink_data() error context loop
gregkh/linux@bf5126f6c519 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
gregkh/linux@66dbcdbb0cad smb: client: harden DFS cache against invalid target hints
gregkh/linux@a3e6e8d7198a HID: picolcd: clamp eeprom debugfs read to bytes actually received
gregkh/linux@943b8dc2c604 HID: roccat: free buffered reports when destroying device
gregkh/linux@79154fad98ee HID: sensor: custom: Fix field sysfs group cleanup on failure
gregkh/linux@0ae90a19e6b5 HID: mcp2221: stop device IO before hid_hw_stop
gregkh/linux@bdc6a3af0dd7 HID: mcp2221: validate report size in mcp2221_raw_event()
gregkh/linux@c480f8af173d eventfs: Initialize ei->children and ei->list in init_ei()
gregkh/linux@1200c2779c43 fs/ntfs3: validate dirty page table on log replay
gregkh/linux@0f699ddb290a fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
gregkh/linux@f4c1bc6d7331 fs/ntfs3: bound page_lcns[] index by the log record
gregkh/linux@b11a78646c10 eCryptfs: bound the packet-length peek to the user buffer
gregkh/linux@ac1728f9ae2a ecryptfs: fix tag 11 packet exact-fit size check
gregkh/linux@7e48afafe7ab ecryptfs: hold msg ctx list lock when cleaning daemon queue
gregkh/linux@329de8b9e988 ecryptfs: pass packet set buffer size to parser
gregkh/linux@ccd13eff0e73 ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
gregkh/linux@9d88391bbed7 ecryptfs: reject too-small tag 70 packets
gregkh/linux@47ce611cb13f ecryptfs: release message context on send failure
gregkh/linux@3c3ac341443b ecryptfs: show filename encryption options
gregkh/linux@8953bdd1b9c0 efivarfs: Rate limit statfs() handler
gregkh/linux@7b6e602f4fc3 fat: restore original value when fat_ent_write failed
gregkh/linux@2c3f8c9c995d fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
gregkh/linux@3d90ab423f04 fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
gregkh/linux@b64f3497a0cd fbdev: ssd1307fb: defer I2C transfers from damage callbacks
gregkh/linux@9f8a822b44c4 fbdev: uvesafb: unregister connector callback on init failure
gregkh/linux@9379f8527ca6 forcedeth: fix off-by-one when saving/restoring non-PCI config space
gregkh/linux@71a7ac491a86 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
gregkh/linux@e8d47e309c70 hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
gregkh/linux@af147ef9f8df ACPI: APEI: Fix ERST timeout unit conversion
gregkh/linux@5ff385e9403e ACPI: APEI: GHES: fix ARM section length accounting after header
gregkh/linux@a2151624b550 ACPI: pfr_update: fix stack buffer overflow in query_capability()
gregkh/linux@63f256bddf5f alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
gregkh/linux@d0ae2e0d8a83 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
gregkh/linux@5ad52dd9b1bb alpha: marvel: Fix lock ordering in init_io7_irqs()
gregkh/linux@2ae970ad5adc ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
gregkh/linux@04e2befe2579 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
gregkh/linux@fe7ba73dde94 auxdisplay: charlcd: cancel backlight work on registration failure
gregkh/linux@48ca2b8c8a6b block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
gregkh/linux@f05baf6e0680 Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
gregkh/linux@32412aff8d11 Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
gregkh/linux@815fc98c227a Bluetooth: eir: Fix OOB read in eir_get_service_data()
gregkh/linux@dc98e727b9cf bnx2x: fix double free in bnx2x_init_firmware() error path
gregkh/linux@638bc3aada8e bpf, x86: Fix per-CPU address resolution into an extended register
gregkh/linux@8c5ba022f208 bpf: Disable preemption in __bpf_get_stack
gregkh/linux@3b7a13eccfcf bpf: Harden bloom filter sizing and indexing on 32-bit kernels
gregkh/linux@d66ceeefb87d dm-era: fix shadowed superblock leak on take-snap failure
gregkh/linux@0a3657ebd6b5 dm raid1: reserve space for NUL-terminator in build_constructor_string()
gregkh/linux@67adda7ed5da dm array: validate array block headers on read
gregkh/linux@7bf4b5cb42a4 dm array: reject an array block whose value size is not the caller's
gregkh/linux@48b4c396e528 coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
gregkh/linux@6937d853e1fe cpufreq: schedutil: Fix rate limit overflow
gregkh/linux@64744b53b752 cxl/pmem: Format the nvdimm serial number as unsigned decimal
gregkh/linux@e2862cd4639f Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
gregkh/linux@1778aad971a6 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@f14c0d9264fb Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
gregkh/linux@2387cd06a2c0 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
gregkh/linux@1b7841ffad08 Bluetooth: RFCOMM: serialize security confirmation handling
gregkh/linux@f4fde735a813 Bluetooth: hci_conn: re-enable advertising only for peripheral role
gregkh/linux@d7723320db4c Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
gregkh/linux@858c69659e9b Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
gregkh/linux@8d1e0bec6081 Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@0aa499eaaa37 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@5dfd5483256c Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
gregkh/linux@709c3646545e kasan: fix cache shrink race with CPU hotplug
gregkh/linux@edf5fcd0469b jbd2: bound shrinker scans by examined checkpoint buffers
gregkh/linux@f83c23286e54 jbd2: check need_resched() when skipping busy checkpoint buffers
gregkh/linux@6d8c5b266d00 ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
gregkh/linux@37df5bc6b5cc ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
gregkh/linux@8bfe746afee3 ip6_gre: fix hardware header length for NBMA tunnels
gregkh/linux@eda56ee17713 ipv6: use RCU iterator to dump route exceptions
gregkh/linux@e057efcc9c71 libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
gregkh/linux@60e85f81f05d mailbox: qcom-ipcc: fix duplicate channel allocation across holes
gregkh/linux@9bb8da6ecb33 md/raid10: fix still_degraded being inverted in raid10_sync_request()
gregkh/linux@75d15738fd33 md: do overflow check for sb->bblog_shift in super_1_load()
gregkh/linux@fed638a24811 mpls: reload header after pskb_may_pull()
gregkh/linux@64f2c5dd49b9 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
gregkh/linux@208867763843 nouveau/gem: reserve the bo in the info ioctl around the vma lookup
gregkh/linux@614f873268c5 params: fix charp corruption on allocation failure
gregkh/linux@e6267cccd7b0 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
gregkh/linux@0e18641708ea SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
gregkh/linux@dd6afc6cab8c SUNRPC: svcauth_gss: enforce krb5 token minimum length
gregkh/linux@011479cf9a76 sunrpc: route to a populated pool in svc_pool_for_cpu()
gregkh/linux@9d44836f60c8 SUNRPC: always drain cache_cleaner before destroying a cache_detail
gregkh/linux@3a2b7649de76 SUNRPC: Check svc pool percpu counter allocation
gregkh/linux@611b30a437a1 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
gregkh/linux@dddcb0f4b7e2 SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
gregkh/linux@89a15a50f84d SUNRPC: harden gss_unwrap_resp_priv length checks
gregkh/linux@f15b87521168 sunrpc: init gssp_lock before publishing proc entry
gregkh/linux@f615b884310b SUNRPC: reject duplicate CREDS_VALUE options
gregkh/linux@dfcd81ab4561 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
gregkh/linux@15431820f448 SUNRPC: wait for in-flight client TLS handshake callback
gregkh/linux@6ee4dc7476b3 svcrdma: Fix offset arithmetic in read_chunk_range
gregkh/linux@9c5a03c3dc50 svcrdma: Fix pcl_for_each_segment for empty chunks
gregkh/linux@0335800071a6 svcrdma: Fix unmatched rn_unregister on failed accept
gregkh/linux@6e21754bbf75 svcrdma: Reject connection when transport allocation fails
gregkh/linux@fcd91b995746 svcrdma: Reject inline replies that overflow the pull-up buffer
gregkh/linux@5ab3f6d882fe svcrdma: Validate Read chunk positions before reconstruction
gregkh/linux@9193368408d7 udf: reject VAT indexes equal to the entry count
gregkh/linux@e3619bed5da1 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
gregkh/linux@1295ba29ac59 staging: media: tegra-video: fix of_node_put() on VIP parse errors
gregkh/linux@86b4afb19b59 staging: media: tegra-video: vi: fix probe failure on skipped last port
gregkh/linux@a4353ec7742b scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
gregkh/linux@a7533dc3c2aa rpmsg: glink: smem: order FIFO read after availability check
gregkh/linux@549bf4887a86 arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
gregkh/linux@721a38f71d02 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
gregkh/linux@1d3d0941de91 arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
gregkh/linux@e8f4e692d2bd riscv: acpi: Handle LPI architectural context loss flags
gregkh/linux@f794c930d823 remoteproc: scp: Fix device reference leak on failed lookup
gregkh/linux@7f911e208b3c qede: Fix NULL pointer dereference in TPA fragment processing
gregkh/linux@fe9c591026c5 RDMA/cxgb4: Cancel reg_work before freeing device on remove
gregkh/linux@764586f8f618 RDMA/ucma: Lock the handler in ucma_set_ib_path()
gregkh/linux@d3c1316d84e0 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
gregkh/linux@3a41d6b79d17 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
gregkh/linux@ff73301b1ac3 regulator: qcom-refgen: correct the regulator type to CURRENT
gregkh/linux@77275ccea06e ring-buffer: Free cpu_buffer::free_page with subbuf_order
gregkh/linux@8a496aaa3da6 ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
gregkh/linux@2f5454a25127 orangefs: fix double-free of trailer_buf on readdir copy failure
gregkh/linux@15d79c806231 orangefs: skip leading spaces before parsing client debug masks
gregkh/linux@123c050eb96a ocfs2: always run deallocs on copy-on-write completion
gregkh/linux@f8658ee3327f ocfs2: bound namelen in dlm_migrate_request_handler
gregkh/linux@f33041906885 ocfs2: validate lengths in dlm_mig_lockres_handler
gregkh/linux@af56e90cb546 ocfs2: validate rl_used against rl_count in refcount block validator
gregkh/linux@49002acc520c ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
gregkh/linux@4d9f789bb3f7 ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
gregkh/linux@9f13aa8116be ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
gregkh/linux@1001fb3b69a1 ocfs2: fix readdir position truncation on 32-bit kernels
gregkh/linux@a520e8cac54f openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
gregkh/linux@6767d70cf46f openvswitch: only skb_tx_error() a packet we are about to drop
gregkh/linux@a8fad8cdb444 ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
gregkh/linux@4ea3c2f54dfe arm64: compat: Fix decrementing LDM/STM alignment emulation
gregkh/linux@aacaae0b9487 ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
gregkh/linux@e219dfdb10b5 hwmon: (max6621) fix negative temperature offset and crit readings
gregkh/linux@129c54abd0a3 hwmon: (max6621) fix temperature clamp range
gregkh/linux@c24bdb7df2f3 lockd: pin next file across nlm_inspect_file lock-drop
gregkh/linux@07adfbb3de75 lockd: fix NULL dereference on lockowner allocation failure
gregkh/linux@1a220b566d47 nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
gregkh/linux@dc4d4b70a863 nvme: zero the discard fallback page
gregkh/linux@328af1c06c5d nvme-pci: disable controller on admin queue IRQ setup failure
gregkh/linux@b36161701cb3 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
gregkh/linux@a4c3c7310156 nvme-tcp: fix host memory disclosure on R2T for a read command
gregkh/linux@99066cf9bba1 nvme-tcp: reject a read that transferred too few bytes
gregkh/linux@ee3f04cf566f sctp: stop processing a packet once its association is deleted
gregkh/linux@c6c86a5e62a4 sctp: drop a chunk if its transport was removed
gregkh/linux@77ea60f2d240 sctp: fix NULL deref on untransmitted RECONF completion
gregkh/linux@4b7bcb04b18c sctp: distinguish sequence zero from wildcard in reconf lookup
gregkh/linux@2d867663c563 sctp: fix stream->outcnt underflow on duplicate RECONF responses
gregkh/linux@861ec73ce86e power: supply: bq24257: fix use-after-free on remove
gregkh/linux@9a467bd1e681 power: supply: bq256xx: drain usb_work before freeing the charger
gregkh/linux@81b558afda93 power: supply: bq25890: Fix power_supply reference leak
gregkh/linux@af3ce383ba0d power: supply: charger-manager: register regulators before exposing sysfs
gregkh/linux@fd29d08ee487 power: supply: cros_usbpd-charger: bound the EC-reported port count
gregkh/linux@fd5f289cca04 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
gregkh/linux@80d4e40a85ba power: supply: lp8727: fix use-after-free in lp8727_release_irq()
gregkh/linux@88d8eadfad5d power: supply: lp8788-charger: fix use-after-free on remove
gregkh/linux@0e70a9b0d16a power: supply: qcom_battmgr: terminate the strings from firmware
gregkh/linux@df67c7a2fff8 power: supply: rt9455: quiesce delayed work before teardown
gregkh/linux@72a2d6cd049f power: supply: twl4030_charger: cancel workers via devm
gregkh/linux@4ca2a4678202 power: supply: ucs1002: fix use-after-free on remove
gregkh/linux@2943a0edd486 power: supply: max17040: propagate register read errors
gregkh/linux@1ea611fbbd8d power: supply: max17040: drop incorrect I2C functionality check
gregkh/linux@5a863417fb9a power: supply: max17040: synchronize work cancellation on suspend
gregkh/linux@777d040c2f91 s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
gregkh/linux@c9adf8399732 s390/dasd: Do not complete a failed ESE read as successful
gregkh/linux@536407b27240 s390/dasd: Guard sysfs discipline callbacks against unallocated private data
gregkh/linux@d6b8778b1b82 s390/dasd: Propagate partial completion length across ERP recovery
gregkh/linux@553c141ac7d8 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
gregkh/linux@3d2faf945768 PCI: meson: Fix GPIO state while requesting PERST#
gregkh/linux@1d0159e13926 PCI: plda: Fix use-after-free of event IRQs during teardown
gregkh/linux@01b05cebe1e8 PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
gregkh/linux@8e6a82467426 PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
gregkh/linux@fed747d2a15a PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@1872805e9704 PCI/MSI: Enable memory decoding before restoring MSI-X messages
gregkh/linux@0ca85dd5ea19 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@77272b7fd0e4 PCI/proc: Use file_ns_capable() when checking config space read access
gregkh/linux@d9dc007eb70d PCI/proc: Warn on writes to kernel-exclusive config space regions
gregkh/linux@1de4443f85e4 iommu/amd: Put PCI device after handling PPR faults
gregkh/linux@bcffb1c75da8 iommu/sva: Set handle->dev before the SVA handle is visible
gregkh/linux@981686f41377 iommu/arm-smmu-v3: Manage teardown with devm
gregkh/linux@07e20b9e6ef9 iommu/vt-d: Fix no_iommu to disable platform opt-in
gregkh/linux@aaeb81241e80 iommu/vt-d: Force requesting ACS when tboot is enabled
gregkh/linux@ceeee18c9279 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
gregkh/linux@1a8bab5ceee1 platform/x86: ISST: Validate level in perf mask ioctls
gregkh/linux@0d90ab5f80e1 platform/x86: ISST: Validate socket ID in clos_assoc ioctl
gregkh/linux@efe7f25dd27e mmc: via-sdmmc: stop card-detect handling on probe failure
gregkh/linux@49a95fe1f64f platform/x86: ISST: Add a NULL check for sst_inst[]
gregkh/linux@eeb04f2899a4 platform/x86: ISST: Just allow 2 bits for SST feature enable
gregkh/linux@da29ce3b3d12 platform/x86: ISST: Use PP level enable mask
gregkh/linux@c9ee2770eb95 platform/x86: ISST: Validate logical CPU id and clos id
gregkh/linux@52f1e6dca7ea platform/x86: ISST: Validate parameter for core power state
gregkh/linux@860f41a846b8 platform/x86: ISST: Validate parameter for frequency and priority
gregkh/linux@24dbee1405f7 platform/x86: ISST: Return error during profile addition
gregkh/linux@46d33021bbc8 platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
gregkh/linux@3d2636dce0a8 platform/chrome: sensorhub: Bound the EC-reported sensor number
gregkh/linux@6eb84e4ac152 platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
gregkh/linux@2818a22347b3 platform/x86: hp-bioscfg: advance elem past consumed array elements
gregkh/linux@2573377d114b platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
gregkh/linux@4c6374dcb270 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
gregkh/linux@cecb8154bd5f platform/x86: hp-bioscfg: fix heap OOB read on empty password write
gregkh/linux@6a1697b7ea20 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
gregkh/linux@3cc772d01547 platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
gregkh/linux@cf9fe8a45666 platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
gregkh/linux@436017808c7c platform/x86: hp-bioscfg: pass validated element count to package parsers
gregkh/linux@157cd545b449 platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
gregkh/linux@a4e9aa7907ad interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
gregkh/linux@60939bcda6f3 ipmi: ipmb: validate write message length
gregkh/linux@d4be659a3e56 ipmi: si: Fix NULL pointer dereference after failed registration
gregkh/linux@dfac2936b83b net/iucv: filter frames in afiucv_hs_rcv() by ingress device
gregkh/linux@444216dacdbe xdp: fix zero-copy frame layout
gregkh/linux@a235b20972bb slip: fix use-after-free in sl_sync()
gregkh/linux@2bd9fcafc4c4 net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
gregkh/linux@379d85c7f25f net: tun: bound receive headroom
gregkh/linux@c32cf5292a0d net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
gregkh/linux@30d5226bac52 net: ipa: fix stalled modem TX queue after runtime resume
gregkh/linux@0fe037d5eaad net: l2tp: do not propagate multicast notification errors
gregkh/linux@0ba5cbc2f049 net: openvswitch: fix flow mask use-after-free on flow deletion
gregkh/linux@bb912cac6ffa net: openvswitch: fix nf_connlabels leak in ovs_ct_init
gregkh/linux@fc710f89a644 net: ravb: avoid dereferencing an invalid PTP clock
gregkh/linux@695acb5534a9 net: ravb: serialize PTP clock teardown
gregkh/linux@9eac1817bfc5 net: thunderbolt: Release the Rx HopID that was handed out on mismatch
gregkh/linux@ed1d6e3d735e net: thunderbolt: Mark the connection down when bringing it up fails
gregkh/linux@4b8fc255e2c1 NTB: ntb_transport: Recycle TX entries before client callbacks
gregkh/linux@5eca0d899a3b NTB: ntb_transport: Fail TX enqueue when the QP link is down
gregkh/linux@a7f22105a7df NTB: ntb_transport: Reject oversized TX buffers
gregkh/linux@69c676d7b090 net: ntb_netdev: Avoid double-accounting netif_rx() drops
gregkh/linux@b4b41c08ebc2 net: ntb_netdev: Count packets dropped on RX refill failure
gregkh/linux@e3fcff8d22a6 net/smc: do not dereference an unset send buffer on the SMC-D teardown path
gregkh/linux@84dea0585f6b net/smc: fix socket refcount leak in smc_switch_conns()
gregkh/linux@6a644a7340df net/smc: fix use-after-free in smc_rx_pipe_buf_release()
gregkh/linux@b4d540ac95cd net/smc: unregister the connection before draining the rx tasklet
gregkh/linux@bc4e05ae66c9 net: cap advertised IP tunnel headroom
gregkh/linux@8670d954ec12 net: fix spurious TX timeout after dev_activate()
gregkh/linux@15aa81b390d4 net: skbuff: don't touch shared zerocopy state in skb_tx_error()
gregkh/linux@2b154e96fcb3 seg6: reset IP6CB after IPv6 decapsulation
gregkh/linux@fcc6c3b11d73 mfd: sm501: Fix potential memory leaks during remove
gregkh/linux@466e911bbbbb ALSA: 6fire: bound the MIDI event length from the device
gregkh/linux@c589aeaadfde ALSA: aloop: Check card index validity at probe
gregkh/linux@eb482a06791d ALSA: bcd2000: clear the URB pointers on disconnect
gregkh/linux@76b6bc38d0f3 ALSA: mpu401: Check card index validity at probe
gregkh/linux@036e7aa79337 ALSA: mts64: Check card index validity at probe
gregkh/linux@c069b3cfd753 ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
gregkh/linux@0ce391090809 ALSA: portman2x4: Check card index validity at probe
gregkh/linux@fbf3fb097e66 ALSA: serial-u16550: Check card index validity at probe
gregkh/linux@43f161c53279 ALSA: virmidi: Check card index validity at probe
gregkh/linux@6d666f0b8b36 ring-buffer: Fix subbuf resize race with ring buffer readers
gregkh/linux@17eea3c2041d iommu/amd: remove return value of amd_iommu_detect
gregkh/linux@40f9bb1c5faf x86/sev: Fix broken SNP support with KVM module built-in
gregkh/linux@27fe9054679b rust: rust_is_available: warn for
bindgen< 0.72.1 && libclang >= 22gregkh/linux@8c9fdfbb7be4 KVM: selftests: Remove duplicate LAUNCH_UPDATE_VMSA call in SEV-ES migrate test
gregkh/linux@09abf299e08a PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
gregkh/linux@120de0ac581b arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
gregkh/linux@c3f211b7a277 dm-stats: fix a crash if allocation of per-cpu data fails
gregkh/linux@24a952786a5f dm-switch: use WRITE_ONCE() in switch_region_table_write()
gregkh/linux@c16b6f25e0cc i3c: master: Fix info leak and UAF in device unregister path
gregkh/linux@f296a0d5907b i3c: master: svc: bound IBI payload to the requested max_payload_len
gregkh/linux@fdb880a7d575 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
gregkh/linux@800d2b490a9a wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
gregkh/linux@7bb9e6060710 crypto: sun8i-ce - Remove crypto_rng interface
gregkh/linux@d29ccf9eeb67 crypto: sun8i-ss - Remove crypto_rng interface
gregkh/linux@20ee9c03f261 wifi: mwifiex: Detach sync cmd buffer on interrupted wait
gregkh/linux@e839bb2f611b wifi: rtl818x: initialize eeprom_93cx6 struct to zero
gregkh/linux@6e327f14e1c4 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
gregkh/linux@3a5b23e7dbeb wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
gregkh/linux@6e95852f904e wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
gregkh/linux@481fff9bda01 wifi: rtw88: pci: fix resource leak on failed NAPI setup
gregkh/linux@3114d479f2a1 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
gregkh/linux@2187a56f2fd1 vsock/virtio: flush works in dependency order
gregkh/linux@cb55c5da9828 w1: ds28e17: reject an oversize length on an I2C block read
gregkh/linux@ad812805fea7 xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
gregkh/linux@73e89faee1f9 tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
gregkh/linux@71f7da08709f sticon/parisc: Detect default STI graphics card for console output
gregkh/linux@03c8761e75d1 signal: avoid shared siginfo namespace rewrites
gregkh/linux@b5bcf3adfa27 smack: fix cred UAF in smack_file_send_sigiotask()
gregkh/linux@4ba9cfffb9bb taskstats: fix cpumask parsing cutting off the last character
gregkh/linux@f1a2f57598b5 timer: Keep debugobjects state consistent in migrate_timer_list()
gregkh/linux@77ca2edeabb3 udf: Fix i_lenExtents truncation on 32-bit kernels
gregkh/linux@247500297ed5 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
gregkh/linux@0a120646831a mm: avoid unnecessary use of is_swap_pmd()
gregkh/linux@d1bb71ec3a51 mm/rmap: use huge_ptep_get() in try_to_unmap_one()
gregkh/linux@39a867754a8a Linux 6.12.109
gregkh/linux@04dd250a78e2 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
gregkh/linux@d2c447e31e90 net: openvswitch: fix kernel-doc warnings in internal headers
gregkh/linux@bf4aaa7ea257 openvswitch: Fix CT limit teardown use-after-free
gregkh/linux@efb4f24fc2b9 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
gregkh/linux@eb778aed8a9b xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
gregkh/linux@090a8aa1894b netfs: Fix netfs_read_folio() to wait on writeback
gregkh/linux@16beba5cd49e mm/page_vma_mapped: use huge_ptep_get() for hugetlb
gregkh/linux@127a291f4c80 wifi: mt76: mt7996: validate default EEPROM firmware size
gregkh/linux@b0b1b9ca80b7 hugetlb: only adjust reservation during unmapping if mapcount is 0
gregkh/linux@92289e66639f fsnotify: Fix stale object mask after concurrent mark updates
gregkh/linux@9ed654e340f4 tcp: fix potential race in tcp_v6_syn_recv_sock()
gregkh/linux@09e8880ce540 entry: Fix seccomp bypass after ptrace with TSYNC
gregkh/linux@7efd017b0186 objtool/rust: add one more
noreturnRust functiongregkh/linux@975ee6c8dd55 fsnotify: inotify: pass mark connector to fsnotify_recalc_mask()
gregkh/linux@cfa58ae66a8c net: ntb_netdev: Fix TX busy and drop handling
gregkh/linux@ac2ab58a79bf drm/amd/display: fix division by zero in get_estimated_bw()
gregkh/linux@8c38049879f2 usb: image: mdc800: change kmalloc() to kzalloc()
gregkh/linux@de6d252f115b ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
gregkh/linux@4fee456a8964 clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
gregkh/linux@239d1683e08b media: usbtv: keep device alive while ALSA card exists
gregkh/linux@5082546702c3 usb-storage: ene_ub6250: fix race between scan work and probe
gregkh/linux@6271b83fa428 usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
gregkh/linux@4359b5f95c93 usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
gregkh/linux@c58e9058bffe usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails
gregkh/linux@b9a7eed472ed usb: typec: qcom-pmic: cancel reset_work on stop
gregkh/linux@ac9f878c4680 usb: typec: ucsi: displayport: Fix OOB altmode array index
gregkh/linux@5b92f6a0c7c0 usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
gregkh/linux@d11f3300b39e usb: gadget: f_midi2: fix use-after-free in string attribute show path
gregkh/linux@3d8b11255e63 usb: gadget: f_midi: initialize work in f_midi_alloc()
gregkh/linux@ebd916fdfefa USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
gregkh/linux@6ea3a073ca97 usb: gadget: fix null pointer dereference in usb_put_function_instance()
gregkh/linux@a53d1ac9ce63 staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
gregkh/linux@136f9a3ab87d staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
gregkh/linux@64a87806bcb4 thermal/drivers/imx: Disable clock on runtime resume failure
gregkh/linux@2bef922769a3 thermal/drivers/qoriq: Disable clock on resume failure
gregkh/linux@5befd06a7221 ublk: clear VM_MAYWRITE on read-only ublk char device mmap
gregkh/linux@08020c64a11a spi: bcm63xx-hsspi: disable clocks on resume failure
gregkh/linux@0396252f3d87 spi: bcm63xx: disable clock on resume failure
gregkh/linux@f35753b3558a spi: bcmbca-hsspi: disable clocks on resume failure
gregkh/linux@cc8354213ad6 spi: Fix DMA mapping ownership on partial map failure
gregkh/linux@eb9dadf4d552 scsi: target: iscsi: Reserve a terminator byte for the login payload
gregkh/linux@fb22a8d2f3ac scsi: pm8001: Use rollback index when freeing MSI-X vectors
gregkh/linux@9a290965cdab mm/damon/sysfs-schemes: kobject_del() scheme dirs
gregkh/linux@3fbdafefe675 mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
gregkh/linux@a1f6bbb973ad mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
gregkh/linux@2fca67da5d51 mm/damon/sysfs-schemes: kobject_del() scheme region dirs
gregkh/linux@5947f2aa75f7 mm/damon/sysfs: kobject_del() region and target (error) dirs
gregkh/linux@18b888935e6b mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
gregkh/linux@5a1960dc0d2a mm/damon/core-kunit: check region count before testing in split_at()
gregkh/linux@244f301759fd futex: Prevent rcuwait use-after-free during requeue PI
gregkh/linux@7b75dd9a3dcd ftrace: Synchronize the initialization of ftrace_ops
gregkh/linux@401359684620 HID: bpf: serialize device reference release in struct_ops destroy path
gregkh/linux@ab2958e0c94e HID: rmi: fix OOB access with undersized RMI reports
gregkh/linux@114af803e409 HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
gregkh/linux@a1af1884c960 dm: fix race when loading and unloading a table
gregkh/linux@3b59530b14fd dm: fix resume-vs-remove race
gregkh/linux@c3fdb94da43f dma-direct: return struct page from dma_direct_alloc_from_pool()
gregkh/linux@ef02cd3807f3 dmaengine: fsl-edma: tracing: no ptr dereference during log output
gregkh/linux@87f94d3178ab dmaengine: dw-edma: Fix HDMA channel status register access
gregkh/linux@35797a7730be dmaengine: dw-edma: Complete descriptors before pausing
gregkh/linux@d232bc6cf456 dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
gregkh/linux@09d002c8fb02 cpuidle: dt_idle_genpd: kfree() the original name allocation
gregkh/linux@446bfe1b45c2 block: flag zoned disks with GENHD_FL_NO_PART
gregkh/linux@729c1ff670ec ceph: lock mutex in ceph_mds_check_access()
gregkh/linux@017619791965 ata: ahci: work around lost interrupts on Marvell 88SE61xx
gregkh/linux@9e69d683ebd7 ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
gregkh/linux@cfcf7ac1318e irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
gregkh/linux@518d9b5568bb kprobes: Protect kprobe_blacklist with RCU
gregkh/linux@bcb3d0c867ee mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
gregkh/linux@fe23d56e9266 tcp: clear sock_ops cb flags before force-closing a child socket
gregkh/linux@d11b18b11604 Input: aiptek - validate raw macro indices before updating state
gregkh/linux@72fb67f6e0e5 memcg: make the v1 soft limit knob inert
gregkh/linux@ba3e6cd6e0eb rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
gregkh/linux@855ba4f3a800 rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
gregkh/linux@6ac26161db27 perf/x86/intel: Fix kernel address leakages in LBR stack
gregkh/linux@7c6f72bcbbbb perf trace: Factor out BPF loop body
gregkh/linux@be264b7bd1c9 perf trace: Refactor augmented_raw_syscalls using bpf_for
gregkh/linux@643fb872aa04 i2c: core: fix debugfs UAF on adapter removal
gregkh/linux@b580f062b24c i2c: mux: Fix channel node leak on adapter add failure
gregkh/linux@b28fe65a36b8 arm64: mm: Fix the lockless page-table walk in show_pte()
gregkh/linux@6acaeea70d8d ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
gregkh/linux@9347588bbd6a ALSA: harmony: initialize locks before requesting IRQ
gregkh/linux@5abeb4f9f202 ALSA: pcm: Fix race between non-atomic ops and trigger-start
gregkh/linux@702c1ae0d31b nvme-fabrics: fix DHCHAP secret leak on parse failure
gregkh/linux@8bd14aa06511 nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
gregkh/linux@80d56202fbdf nvme-tcp: check the data direction of a C2HData PDU
gregkh/linux@3a385e0c39ef nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
gregkh/linux@2b71f9193e3d nvmet-tcp: reject unsolicited H2CData PDUs
gregkh/linux@7475d3ea26aa Revert "irqchip/mbigen: Fix mbigen node address layout"
gregkh/linux@8e3755b5eaab mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
gregkh/linux@6f79d1a5f261 nvdimm/btt: reject an arena whose nfree is below the lane count
gregkh/linux@bb10d54b7484 parisc: eisa: Fix infinite loop when parsing invalid IRQ value
gregkh/linux@9de52c4b7b10 parisc: Fix alignment of asm statements in head.S
gregkh/linux@11ef1c2a5dbe powerpc/kexec_file: Fix null-ptr-def in extra size calculation
gregkh/linux@9ef63622e6ce powerpc/kexec_file: Prevent kexec range truncation
gregkh/linux@e163c7184acf powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
gregkh/linux@2d80ffb61e7b powerpc/pseries: Handle and log pseries-wdt registration failures
gregkh/linux@6e988bbe74e4 powerpc/pseries: Move H_WATCHDOG definitions to a common header
gregkh/linux@e26bca249c36 powerpc/crash: stop watchdogs before booting kdump kernel
gregkh/linux@6a180adafc2a s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()
gregkh/linux@b5fa2598b7f9 s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove
gregkh/linux@4bffadde7fc4 s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
gregkh/linux@334b435b9513 s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
gregkh/linux@753aa3bb1273 s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed
gregkh/linux@e102ce0f4af9 s390/vfio-ap: Fix NULL deref in status_show() during queue probe
gregkh/linux@f73db6325243 s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
gregkh/linux@56f0c446d216 s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object
gregkh/linux@1edea8900ca3 mtd: afs: validate v2 image info bounds
gregkh/linux@8414f0e9f707 mtd: mtdoops: free page bitmap when the backing MTD is removed
gregkh/linux@12a63a0f0d17 mtd: rawnand: validate ONFI extended parameter page sections
gregkh/linux@a2c272da99c2 batman-adv: fix stale receive device on merged fragments
gregkh/linux@a066aff2174d batman-adv: mcast: ensure unshared skb for multicast packets
gregkh/linux@a9603e0a7cb5 batman-adv: mcast: linearize skbuff for packet generation
gregkh/linux@91c99b4e1520 batman-adv: dat: avoid unaligned fault in IP extraction
gregkh/linux@f50edb69082a batman-adv: bla: fix freeing of claims on meshif deletion
gregkh/linux@6939650a8f32 batman-adv: bla: prevent CRC corruptions after claim flush
gregkh/linux@9bb5db84b9ec clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@f860985dbdfb clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@4254ab70deac clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src
gregkh/linux@e4821f1fcabe clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
gregkh/linux@453c54db8b6f clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
gregkh/linux@c00eb63f4a4e clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@d9ee78500877 clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
gregkh/linux@0c50a424960a clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
gregkh/linux@33f873f8a89a i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
gregkh/linux@6ae989182405 ASoC: cs35l33: drain threaded IRQ before runtime suspend
gregkh/linux@4fe8a91a9266 ASoC: cs35l34: drain threaded IRQ before runtime suspend
gregkh/linux@c437b536ce39 ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
gregkh/linux@7eef9ae3b4ef ASoC: hdac_hda: Fix hlink refcount leak on component registration failure
gregkh/linux@d93715d0f757 AsoC: intel: sst: fix PCI device reference leak on probe failure
gregkh/linux@682c123cef45 ASoC: loongson: Fix error handling in ACPI property parsing
gregkh/linux@39ff4dc855e6 ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get
gregkh/linux@28d23892a45d iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig
gregkh/linux@8d3f06d3397f iio: adc: pac1921: fix wrong channel used in trigger handler read
gregkh/linux@ab53077511cd iio: buffer: Fix potential use-after-free in anonymous buffer release
gregkh/linux@311595dc0b56 iio: buffer: Make IIO DMA fence release RCU-safe
gregkh/linux@6865d79fca17 iio: buffer: Tie IIO dma fence lock lifetime to the fence
gregkh/linux@aedf8f068d9d iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
gregkh/linux@91e12b0fbd70 iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF
gregkh/linux@a5aaea17a183 iio: chemical: sgp30: Handle IAQ thread creation failure
gregkh/linux@ae18d2d2ef27 iio: dac: m62332: Fix regulator reference count imbalance
gregkh/linux@e3ef2f7aa4d0 iio: gyro: mpu3050: fix sign of raw angular velocity readings
gregkh/linux@cc2af22bbe19 iio: light: cm32181: return zero after writing calibscale
gregkh/linux@89484bff0523 iio: light: gp2ap002: Disable regulators on resume failure
gregkh/linux@c4f003d8578f iio: light: ltrf216a: fix runtime PM reference leak in error path
gregkh/linux@bc7b09e701b4 iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
gregkh/linux@d3f94a2445c0 iio: pressure: mpl115: Fix runtime PM cleanup
gregkh/linux@021c69781350 iio: srf04: fix pm_runtime handling on probe error path
gregkh/linux@d6bdc5ddc704 iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register()
gregkh/linux@3346619bbc56 iio: light: opt4001: Fix power down clearing bits of the wrong register
gregkh/linux@8812614ce0ec iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem()
gregkh/linux@5cc471d48a26 iio: light: opt4001: Reject integration times with a non-zero seconds part
gregkh/linux@7abc73e55a2e iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask
gregkh/linux@8b98d662ab24 KVM: nVMX: Always flush vpid02 on first use
gregkh/linux@bd4fc3c88167 KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02
gregkh/linux@ae190f2439ca KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
gregkh/linux@f74fccdf4f7f KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
gregkh/linux@d03e721801ac KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
gregkh/linux@ef721d37aea2 KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot()
gregkh/linux@6a8ba9213cce KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
gregkh/linux@cd2976b4a539 KVM: x86: Serialize writes to disabled_quirks using kvm->lock
gregkh/linux@72bae1bb5b04 KVM: x86: Ensure runtime reads of disabled_quirks are resolved once
gregkh/linux@b94ab9caa5d7 KVM: s390: Fix length check __import_wp_info()
gregkh/linux@fc2034c431ad KVM: s390: Fix memory leak in guest debug handling
gregkh/linux@4048d0a25216 KVM: s390: Fix old_data leak in guest debug error path
gregkh/linux@9a32c4c6a6c2 KVM: s390: Free guest debug data on vcpu destroy
gregkh/linux@76f5b4ea9ed0 KVM: s390: Take srcu when importing watchpoint data
gregkh/linux@aef4cbc39738 KVM: s390: Zero initialize irq in reinject_machine_check
gregkh/linux@a87274fca3b7 KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
gregkh/linux@f4db3dc9f662 KVM: s390: Restore sigset on error path
gregkh/linux@4ec4c3517d31 LoongArch: KVM: Fix TOCTOU race on pv_features
gregkh/linux@6bbbd7b71923 LoongArch: KVM: Free init resources if kvm_init() fails
gregkh/linux@7c6df65b5384 LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
gregkh/linux@0195e04b1eec LoongArch: Fix acpi_package_ids[] array overflow
gregkh/linux@3595bd4afb5d LoongArch: Do not select HAVE_RUST when KASAN is enabled
gregkh/linux@8f15e95b438b LoongArch: Do not save/restore percpu base register in rethook trampoline
gregkh/linux@a1cb727fa27c LoongArch: Avoid preempt count underflow without probe
gregkh/linux@a9a8c37ddda9 media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref
gregkh/linux@74bf7b649633 media: amphion: Remove obsolete frame_count check in venc_start_session
gregkh/linux@f28a8e1ba4d6 media: cec: core: Fix kmemleak due to missed rc_free_device() call
gregkh/linux@9a951931d4b4 media: cec: disable delayed work before freeing an interrupted transmit
gregkh/linux@00c13b4ab481 media: cec: extron-da-hd-4k-plus: add sanity check
gregkh/linux@5635e231e247 media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash
gregkh/linux@df941e6851da media: cec: Serialize exclusive follower delivery
gregkh/linux@79fd0b016150 media: cedrus: fix memory leak in cedrus_init_ctrls()
gregkh/linux@6cbc8a73b346 media: cobalt: Avoid freeing ALSA private data twice
gregkh/linux@1d1079db8d18 media: cx231xx: reject geometry changes while the VBI queue is busy
gregkh/linux@5deec890ecfa media: cx23885: cancel NetUP CI work before teardown
gregkh/linux@d06067ee3262 media: em28xx: defer audio-only extension registration
gregkh/linux@20c2c65f3d9f media: em28xx: fix use-after-free of dev_next->devlist on disconnect
gregkh/linux@29fe4d38fb59 media: go7007: defer the ALSA v4l2 put until c...