Skip to content

UPDATE: 6.6.157 - #1378

Open
fepitre-bot wants to merge 1 commit into
QubesOS:stable-6.6from
fepitre-bot:update-v6.6.157
Open

fepitre-bot wants to merge 1 commit into
QubesOS:stable-6.6from
fepitre-bot:update-v6.6.157

Conversation

@fepitre-bot

Copy link
Copy Markdown
Contributor

Update to 6.6.157

Details

Changes since previous version:
gregkh/linux@8d08713ec83a PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
gregkh/linux@362726c9c6e5 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
gregkh/linux@10a6b9907969 rndis_host: add overflow check in rndis_rx_fixup()
gregkh/linux@fcaf8ba7e56b NTB: ntb_netdev: Preserve RX queue depth on allocation failure
gregkh/linux@c8c8e895f65f serial: amba-pl011: synchronize DMA teardown
gregkh/linux@c4ab0d688802 perf: Unify perf_event_free_task() / perf_event_exit_task_context()
gregkh/linux@80c6054a4c40 perf/core: Fix group leader use-after-free after sibling detach
gregkh/linux@1606abb7ce8c serial: qcom-geni: fix TX DMA buffer flush
gregkh/linux@969e3867ef67 serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants
gregkh/linux@7047aa394d6c serial: sc16is7xx: convert bitmask definitions to use BIT() macro
gregkh/linux@a289a78f13ab serial: sc16is7xx: rename EFR mutex with generic name
gregkh/linux@811b44be278b serial: sc16is7xx: use guards for simple mutex locks
gregkh/linux@4a8887dd3a8a serial: sc16is7xx: enable THRI before filling TX FIFO
gregkh/linux@4d40d900ffb2 inet: frags: add inet_frag_putn() helper
gregkh/linux@c69b3593aa73 ipv4: frags: remove ipq_put()
gregkh/linux@32fa602b5dd6 inet: frags: change inet_frag_kill() to defer refcount updates
gregkh/linux@bb7488c797d0 inet: frags: save a pair of atomic operations in reassembly
gregkh/linux@d3ffb89b2944 inet: frags: publish queues before arming timer
gregkh/linux@2eca18dd026b xfs: don't use a xfs_log_iovec for ri_buf in log recovery
gregkh/linux@b7528b42813f xfs: bounds-check buffer log item's dirty bitmap
gregkh/linux@b20eb7ecbdaa ALSA: dummy: Check card index validity at probe
gregkh/linux@6a009f1e61b1 ocfs2: fix missing metadata reservation for large xattrs
gregkh/linux@075e52fd6d86 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
gregkh/linux@a2fb8222cde2 kcov: fix data corruption and race conditions on PREEMPT_RT
gregkh/linux@a40c45268f43 ext4: stop retrying saturated xattr cache entries
gregkh/linux@46116f574be3 ext4: clear error before retrying inode xattr space fallback
gregkh/linux@e99120b5944a xfs: validate attr entry pointer before field access
gregkh/linux@b6505a4cea45 gpio: ml-ioh: use raw_spinlock_t for the register lock
gregkh/linux@152fcb74a268 s390/vfio_ccw: Free all memory if cp_init() fails
gregkh/linux@460b977a4e71 s390/vfio_ccw: Ensure first IDAW remains constant
gregkh/linux@f0d189d95eee s390/vfio_ccw: Calculate idal length based on idaw type
gregkh/linux@a3d60ae24183 s390/vfio_ccw: Implement a crw lock
gregkh/linux@3227cd511675 drm/amd/amdgpu: disable ASPM in some situations
gregkh/linux@874d1bdda79b drm/amd/display: Fix BT2020 YCbCr limited/full range input
gregkh/linux@b287812f88a1 drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
gregkh/linux@77693fb8aec3 drm/amdgpu: check ASPM on the dGPU host link
gregkh/linux@d0756a98277e nfc: digital: clamp SENSF_RES length to the destination buffer
gregkh/linux@fc3c2bd5b1ec nfc: fdp: bound the device-reported read length and fix an skb leak
gregkh/linux@18f02354ed22 nfc: microread: validate target discovery payload lengths
gregkh/linux@1964addc8dd5 nfc: llcp: bound the connect_sn TLV walk to the skb
gregkh/linux@a209334ed929 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
gregkh/linux@3793d768b40f nfc: llcp: reject PDUs shorter than the LLCP header
gregkh/linux@4a52ec2457ff nfc: pn533: purge fragmented skbs during cleanup
gregkh/linux@9635507fe829 nfc: st21nfca: validate ATR_REQ length against the received frame
gregkh/linux@24761d3a5f69 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
gregkh/linux@7489f59d1ea2 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
gregkh/linux@790576dc7ccc nfc: nci: free destination parameters when closing a connection
gregkh/linux@3a398e09a6c1 ndisc: ndisc_send_redirect() cleanup
gregkh/linux@28d984a66b9e Input: byd - synchronize timer deletion before freeing private data
gregkh/linux@eab3eeb68bfc libceph: fix OOB read in decode_watchers() via missing bounds check
gregkh/linux@b0ea911453ce ipv4: reject undersized MTUs in ip_do_fragment()
gregkh/linux@087ee0d914aa ipv6: fix use-after-free in ip6_finish_output2()
gregkh/linux@8f6363c8d54d nvmet-auth: zero the AUTH_RECEIVE response buffer
gregkh/linux@d094582cce9c nvmet-fc: fix invalid free in LS IOD error path
gregkh/linux@86cc45002247 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
gregkh/linux@925cb11b60c1 ASoC: sof: pcm: use snd_pcm_direction_name()
gregkh/linux@93c9bee22615 ASoC: SOF: Relocate and rework functionality for PCM stream freeing
gregkh/linux@5f291adb281e ASoC: SOF: pcm: Move period/buffer configuration print after platform open
gregkh/linux@74ec9c120e90 ASoC: SOF: pcm: Add snd_sof_pcm specific wrappers for dev_dbg() and dev_err()
gregkh/linux@4931c09d8387 ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
gregkh/linux@48b76879f5bf ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
gregkh/linux@13aa13ce3d65 mptcp: pm: fix data race in add_addr timer callback
gregkh/linux@514a814c7427 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
gregkh/linux@3d7a7bac4c75 HID: magicmouse: do not keep a stale msc->input if no input is claimed
gregkh/linux@9b3469d162e3 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
gregkh/linux@c1d9c16af51c HID: core: fix OOB read of field->usage in hid_set_field()
gregkh/linux@f0ab9a71167b xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
gregkh/linux@c4cec575a6d6 Bluetooth: hci_sync: Fix advertising data UAFs
gregkh/linux@346f0edba1d4 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
gregkh/linux@a5321b00b98e Input: atkbd - skip deactivate for HONOR ZQC-P
gregkh/linux@bb32e9a6a9a9 mptcp: pm: fix memory leak from alloc-during-teardown race
gregkh/linux@bd397c4123a4 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
gregkh/linux@abec577de5fc HID: core: fix number/pointer type confusion on long items
gregkh/linux@2ce90cfc6646 HID: sensor: custom: Fix use-after-free in enable_sensor
gregkh/linux@334271d3812a HID: hyperv: validate initial device info bounds
gregkh/linux@0628cc9b2fa2 Bluetooth: hci_event: fix LE list UAF on reset
gregkh/linux@26741d178f31 Bluetooth: hci_event: validate LE Set CIG Parameters response
gregkh/linux@e907bf694ed5 net: gro: properly validate BIG TCP aggregation criteria
gregkh/linux@93e0c9521fa8 Linux 6.6.154
gregkh/linux@3edf721bb4b9 inet: frags: strip GSO state from fragments before reassembly
gregkh/linux@a4a971135a2f Linux 6.6.155
gregkh/linux@f5e6580a3a16 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
gregkh/linux@429b6f43b4d8 KVM: x86/mmu: Check write tracking in all address spaces
gregkh/linux@a13f61ba9b2a ext4: don't enable DAX on new encrypted files
gregkh/linux@eb1e94fee5e2 io_uring/io-wq: fix worker accounting when canceling creation callbacks
gregkh/linux@ff3f428df00b Revert "usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal"
gregkh/linux@c1164f14c636 bpf: Ensure reg is PTR_TO_STACK in process_iter_arg
gregkh/linux@ce12e1170c0c perf: Reject exited events as group leaders
gregkh/linux@e217492f6fa2 bpf: Remove tst_run from lwt_seg6local_prog_ops.
gregkh/linux@41da1715cd24 jfs: add check read-only before truncation in jfs_truncate_nolock()
gregkh/linux@47a99881ecc5 jfs: add check read-only before txBeginAnon() call
gregkh/linux@9bc078818ec7 ibmvnic: Use kernel helpers for hex dumps
gregkh/linux@a39f811a9f5e jfs: Fix null-ptr-deref in jfs_ioc_trim
gregkh/linux@ac65f76db9b2 exfat: fix double free in delayed_free
gregkh/linux@71209954f1e8 media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
gregkh/linux@75194165e650 mISDN: hfcpci: Fix warning when deleting uninitialized timer
gregkh/linux@76957b618ce7 can: j1939: implement NETDEV_UNREGISTER notification handler
gregkh/linux@fd8c807f8d5f can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
gregkh/linux@53ca5b78b69d can: j1939: make j1939_sk_bind() fail if device is no longer registered
gregkh/linux@302dbed4760b smc: Fix use-after-free in __pnet_find_base_ndev().
gregkh/linux@7b854e68365a KVM: arm64: Prevent access to vCPU events before init
gregkh/linux@80d1fd39f4e3 smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
gregkh/linux@4f5f52a58429 smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
gregkh/linux@36fb28fa033f ASoC: nau8821: Cancel delayed work on component remove
gregkh/linux@5662dac41a34 bpf: Fix use-after-free in offloaded map/prog info fill
gregkh/linux@66dedb6028c3 riscv: Fix register corruption from uninitialized cregs on error
gregkh/linux@b671ba32c563 Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
gregkh/linux@a698d43ce95b ASoC: nau8821: Cancel pending work before suspend
gregkh/linux@9a4d8e559c3c smc: Use _sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
gregkh/linux@4f15e7704c33 selinux: switch two allocations to use kzalloc_objs()
gregkh/linux@524323f52cbf net/sched: Fix mirred deadlock on device recursion
gregkh/linux@2df9641e4b62 net/sched: initialize noop_qdisc owner
gregkh/linux@b300312562fd powerpc/hv-gpci: fix preempt count leak in sysfs show paths
gregkh/linux@bfd861dadd3a crypto: starfive - Do not free stack buffer
gregkh/linux@4241e3b406c8 ksmbd: harden file lifetime during session teardown
gregkh/linux@e971a37c68cb ext4: make state in ext4_mb_mark_bb to be bool
gregkh/linux@0b34ea0dc2bb ext4: make some fast commit functions reuse extents path
gregkh/linux@267a15c4f994 ext4: propagate errors from fast commit range replay
gregkh/linux@df75b4d1656b nilfs2: correct return value kernel-doc descriptions for ioctl functions
gregkh/linux@a5e776e29375 nilfs2: reject invalid block index in GC ioctl
gregkh/linux@e25b44bd8b8c nfc: nci: add data_len bound checks to activation parameter extractors
gregkh/linux@250cea475827 HID: magicmouse: re-enable multitouch after reset-resume
gregkh/linux@d16df755b449 HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
gregkh/linux@59d4c2352e82 nvme: rename nvme_sc_to_pr_err to nvme_status_to_pr_err
gregkh/linux@cb8b78b34593 nvme: fix status magic numbers
gregkh/linux@e4f43b3d8588 nvme: rename CDR/MORE/DNR to NVME_STATUS
*
gregkh/linux@25ad03d5c0e8 nvmet-tcp: bound SGL data length before allocating command buffers
gregkh/linux@c023443f0e6c HID: nintendo: stop device IO before hid_hw_stop on probe failure
gregkh/linux@3a32b93cff2a HID: ft260: validate i2c input report length
gregkh/linux@460514d46e88 HID: ft260: fix stack-use-after-return write in I2C read race
gregkh/linux@9d77ac82e57e HID: uclogic: fix use-after-free of inrange_timer on remove
gregkh/linux@1acff0590a44 HID: pidff: Support device error response from PID_BLOCK_LOAD
gregkh/linux@e9f2ce45b311 HID: pidff: clang-format pass
gregkh/linux@2e0471bf3ab2 HID: pidff: fix OOB write when hid->inputs is empty
gregkh/linux@b95bc136fe54 Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync()
gregkh/linux@b5181516a9f5 Bluetooth: hci_sync: Fix accept list UAF during suspend
gregkh/linux@95f90c6029ca xfs: remove file_path tracepoint data
gregkh/linux@ba537c32de31 fpga: dfl: fme: add error handling
gregkh/linux@daba8d1cd995 accessibility: speakup: unregister tty ldisc on later init failures
gregkh/linux@d27599347b69 usb: xhci: Handle USB3 port events when there is one roothub
gregkh/linux@eaca2814f32b xhci: dbgtty: Fix unregister on tty_register_driver() failure
gregkh/linux@c36e7e4eb83e xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
gregkh/linux@92588d187ba4 fuse: fix invalidate lock leak on setattr writeback failure
gregkh/linux@dcf30a56624c fuse: fix invalidate lock leak on open O_TRUNC DAX failure
gregkh/linux@f95e57b66195 usb: usbtest: disable dynamic ID support
gregkh/linux@ad6f0375d2e9 usb: gadget: f_tcm: keep port count until LUN teardown completes
gregkh/linux@a832d7cb09da tls: device: fix out-of-bounds write in tls_append_frag()
gregkh/linux@5953e7a89966 x86/CPU/AMD: Add X86_FEATURE_ZEN5
gregkh/linux@ed9cf952fdec x86/CPU/AMD: Add more models to X86_FEATURE_ZEN5
gregkh/linux@fa05e559102e x86/CPU/AMD: Add models 0x10-0x1f to the Zen5 range
gregkh/linux@7287cc121131 x86/CPU/AMD: Add models 0x60-0x6f to the Zen5 range
gregkh/linux@a62216735102 x86/CPU/AMD: Carve out a Zen5 models range
gregkh/linux@ff8dd7a932f3 xfrm: espintcp: fix UAF during close
gregkh/linux@2dd1609cadff xfrm: drop ESP-in-TCP packets with no ingress device
gregkh/linux@f00df8500e5a xfrm: ah6: validate routing header segments_left
gregkh/linux@c8837bbe7922 xfrm: fix xfrm_state_construct() auth-trunc leak
gregkh/linux@7c54fd8cfbcf net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
gregkh/linux@f52f1e75716d ipv6: seg6: clear IPv4 control block on IPIP decapsulation
gregkh/linux@da45847766b5 mm/swap: reject swapon() on filesystem-level encrypted files
gregkh/linux@4d35a92dd3da crypto: atmel-tdes - use scatterlist length before DMA mapping
gregkh/linux@cc56d2b0d77c crypto: qce - fix CCM AAD buffer underallocation
gregkh/linux@1537bd55b4f8 crypto: mxs-dcp - fix source scatterlist length access
gregkh/linux@fb8110b748b2 crypto: qce - Remove unsafe/deprecated algorithms
gregkh/linux@087c19cc60a8 KVM: s390: vsie: zero stale crypto bits
gregkh/linux@04ab26040797 usb: core: Add lock to usb_wakeup_notification()
gregkh/linux@656bd0ccb900 usb: core: Strengthen error handling in hub_hub_status()
gregkh/linux@94e4562fcc81 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
gregkh/linux@f1c05c41d07b ALSA: usb-audio: Complete cleanup after system-resume errors
gregkh/linux@030e3a73d3c3 USB: serial: option: fix slab OOB read in interrupt URB callback
gregkh/linux@8e987c4daf4f USB: serial: spcp8x5: drop broken carrier detect support
gregkh/linux@62cd519ab74c USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
gregkh/linux@65879e0a452c usb: usbfs: fix use-after-free of usb_device in usbdev_release()
gregkh/linux@8b73de7da85f Linux 6.6.156
gregkh/linux@73b7a1181483 Revert "arm64: mm: Don't remap pgtables for allocate vs populate"
gregkh/linux@19ccd78a4e7c net: dst: add four helpers to annotate data-races around dst->dev
gregkh/linux@49b02a9d11c7 ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu]
gregkh/linux@40acb0537963 net: dst: introduce dst->dev_rcu
gregkh/linux@e150f273cd8e ipv4: start using dst_dev_rcu()
gregkh/linux@0e6245b2424d ALSA: aloop: Fix racy access at PCM trigger
gregkh/linux@d258cdce50ff ALSA: aloop: Fix peer runtime UAF during format-change stop
gregkh/linux@184870af0e73 perf/x86/intel/uncore: Fix die ID init and look up bugs
gregkh/linux@e5038d7f3603 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
gregkh/linux@7b5771d0bf17 alpha: don't leak hardware-fabricated FP exception bits to user space
gregkh/linux@ebba4d0aeba0 clocksource/drivers/timer-sun4i: Advertise a real minimum delta
gregkh/linux@da268a44d773 powerpc/pseries/iommu: switch to Default DMA window during kdump
gregkh/linux@bdfda99c5763 timers/itimer: Zero-init old itimerval before copy to userspace
gregkh/linux@f93f15541f22 include/linux/list.h: mark list_add and __list_add as __always_inline
gregkh/linux@4757542649af mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
gregkh/linux@029c9408049f mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
gregkh/linux@8bf21ad36573 mm: memcg: stop reclaim when a limit update is superseded
gregkh/linux@f668affa147a tools/compiler: match glibc 2.42 definition of attribute_const
gregkh/linux@220011fe95fc x86/tdx: Fix off-by-one in port I/O handling
gregkh/linux@f3ed36a608d8 x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
gregkh/linux@3eaf78e6571d hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
gregkh/linux@33ce55b368b6 tracing/user_events: Clear copied tracing state before fork duplication
gregkh/linux@ceb1707aef58 tracing: Fix crash passing ERR_PTR to kthread_stop()
gregkh/linux@3a8534664426 tracing: Fix use-after-free with same-name named triggers
gregkh/linux@f4ae79b5f001 device property: fix infinite loop in fwnode_for_each_child_node()
gregkh/linux@261c958b6acb powerpc/powermac: fix OF node refcount
gregkh/linux@bd8881c24a95 rapidio: mport_cdev: fix use-after-free in dma_req_free()
gregkh/linux@2ac009a65d23 Revert "media: v4l2-dev: fix error handling in __video_register_device()"
gregkh/linux@c881f5b175fd staging: greybus: hid: fix SET_REPORT return value
gregkh/linux@f09b3f48ff65 usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
gregkh/linux@d82cfb853c5d USB: phy: fsl-usb: fix missing static keywords
gregkh/linux@891a8d11f4d5 usb: gadget: u_audio: Fix use-after-free on sound card disconnect
gregkh/linux@95cf1b50ba6b usb: gadget: snps_udc_plat: clean up PHY on probe deferral
gregkh/linux@79dbedf40ad9 usb: gadget: midi2: remove default configfs groups on teardown
gregkh/linux@eef3e62f90d8 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
gregkh/linux@bec7708eb3b5 usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
gregkh/linux@b0a6bfac0c3c usb: gadget: f_fs: Prevent deadlock during ep0 read loop
gregkh/linux@8f3365ed2a5d fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
gregkh/linux@c5c60260a07e HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
gregkh/linux@60c74f42f5ab lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
gregkh/linux@1b4fdefd788d media: cec: stm32: prevent out-of-bounds write on RX overflow
gregkh/linux@e21cccc29b84 media: vicodec: fix out-of-bounds write in FWHT encoder
gregkh/linux@b313edfbc0c2 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
gregkh/linux@da7a80ddc610 of: fix out-of-bounds read in of_alias_scan() stem parser
gregkh/linux@37a9d25a563f ubifs: fix out-of-bounds read in signature length check
gregkh/linux@07615c1eb1d0 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
gregkh/linux@bfd1004ab123 NFSD: Fix off-by-one in DRC bucket pruning limit
gregkh/linux@60680ae7243b NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
gregkh/linux@2ef131323999 NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
gregkh/linux@a080bb69d30f NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
gregkh/linux@085cfde7c218 nfsd: release path refs on follow_down() error
gregkh/linux@6b13d26cc21b nfsd: Reset write verifier when async COPY writeback fails
gregkh/linux@f8914ba102d7 nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
gregkh/linux@322422d66d1a nfsd: sample writeback error cursor before async COPY loop
gregkh/linux@3ef5e7a01a4d nfsd: validate symlink target length in NFSv4 CREATE
gregkh/linux@d823bf9285cd nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
gregkh/linux@9e8924bef5b5 nfsd: add filehandle match check to nfsd4_delegreturn()
gregkh/linux@977e6f006a7a nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
gregkh/linux@75268f6cfe26 nfsd: check client ownership when cancelling a copy-notify stateid
gregkh/linux@bfeac42d9074 nfsd: fix cpntf publish race in nfs4_init_cp_state
gregkh/linux@59416992d1f5 nfsd: fix version mismatch loops in nfsd_acl_init_request()
gregkh/linux@bee826c00ac9 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
gregkh/linux@88bce7e326c3 nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
gregkh/linux@8e4422b05f41 nfsd: gate nfs2 setacl by argp->mask
gregkh/linux@3be1d8611dae nfsd: gate nfs3 setacl by argp->mask
gregkh/linux@9caad13b7cfe nfsd: initialize copy-notify stateid before publishing it
gregkh/linux@1db456ffc22e nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
gregkh/linux@70290db6c980 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
gregkh/linux@caddbeffab1e nfsd: revoke copy-notify stateids before dropping their reference
gregkh/linux@1ce74d1b7770 NFSD: Prevent lock owner use-after-free during client teardown
gregkh/linux@94ae5145c520 libceph: validate OSD extent maps before cursor advance
gregkh/linux@6e5c6ce252b1 libceph: reject buckets with mismatched CRUSH ids
gregkh/linux@19f16f04c2b0 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
gregkh/linux@c4addccd05ba ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
gregkh/linux@a294064e0e0f ceph: bound copied dentry name length in NFS export get_name
gregkh/linux@eb3e1a1cb163 ceph: bound num_export_targets array for mds info v2/v3
gregkh/linux@61f085cb8976 ceph: bound xattr value length in __build_xattrs()
gregkh/linux@01b0ec8c397b audit: avoid dropping live tree ref on fsnotify rule autoremove
gregkh/linux@7f62817fe049 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
gregkh/linux@3ff9462bb7a0 smb: client: clear ce->tgthint in free_tgts()
gregkh/linux@b89d678f9eaf smb: client: fix ALIGN() overflow in symlink_data() error context loop
gregkh/linux@735abe493235 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
gregkh/linux@6cb7f9fed8f4 smb: client: harden DFS cache against invalid target hints
gregkh/linux@4daf432c94a4 HID: picolcd: clamp eeprom debugfs read to bytes actually received
gregkh/linux@4cb3ff31d237 HID: roccat: free buffered reports when destroying device
gregkh/linux@2409779f3096 HID: sensor: custom: Fix field sysfs group cleanup on failure
gregkh/linux@85d963499f1f HID: mcp2221: stop device IO before hid_hw_stop
gregkh/linux@c1c508e89239 HID: mcp2221: validate report size in mcp2221_raw_event()
gregkh/linux@069729282fbe eventfs: Initialize ei->children and ei->list in init_ei()
gregkh/linux@d23155634a4b fs/ntfs3: validate dirty page table on log replay
gregkh/linux@77d8efd04745 fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
gregkh/linux@61ca8cbbf68f fs/ntfs3: bound page_lcns[] index by the log record
gregkh/linux@70fa0cf82e43 eCryptfs: bound the packet-length peek to the user buffer
gregkh/linux@7abf2992c61e ecryptfs: fix tag 11 packet exact-fit size check
gregkh/linux@ec1627bcb5b5 ecryptfs: hold msg ctx list lock when cleaning daemon queue
gregkh/linux@749fa08d8f1b ecryptfs: pass packet set buffer size to parser
gregkh/linux@33e050cac841 ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
gregkh/linux@414a0f04feb0 ecryptfs: reject too-small tag 70 packets
gregkh/linux@30845ed22747 ecryptfs: release message context on send failure
gregkh/linux@a980ac04ada5 ecryptfs: show filename encryption options
gregkh/linux@3cd611c9f1db efivarfs: Rate limit statfs() handler
gregkh/linux@35b333480010 fat: restore original value when fat_ent_write failed
gregkh/linux@302d19fbc7dc fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
gregkh/linux@74de052b4399 fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
gregkh/linux@237924f5b9af fbdev: ssd1307fb: defer I2C transfers from damage callbacks
gregkh/linux@9eb7b3cbe99c fbdev: uvesafb: unregister connector callback on init failure
gregkh/linux@c4d595358246 forcedeth: fix off-by-one when saving/restoring non-PCI config space
gregkh/linux@827ded884dbd fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
gregkh/linux@9963a65be2be hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
gregkh/linux@c5a31b4e7e37 ACPI: pfr_update: fix stack buffer overflow in query_capability()
gregkh/linux@a12408ff9a94 alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
gregkh/linux@748d3e1dcecf alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
gregkh/linux@1712e99ddeb1 alpha: marvel: Fix lock ordering in init_io7_irqs()
gregkh/linux@3a6f8d3adbd6 ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
gregkh/linux@977554ed91b5 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
gregkh/linux@6eaed64a32e5 auxdisplay: charlcd: cancel backlight work on registration failure
gregkh/linux@958cfdc655f7 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
gregkh/linux@1b5fb9c40e30 Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
gregkh/linux@0725f93b395f Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
gregkh/linux@1a28aae7f1fc Bluetooth: eir: Fix OOB read in eir_get_service_data()
gregkh/linux@ac280f6872e7 bnx2x: fix double free in bnx2x_init_firmware() error path
gregkh/linux@80551bf8912c bpf: Harden bloom filter sizing and indexing on 32-bit kernels
gregkh/linux@dc731d7fddfd dm-era: fix shadowed superblock leak on take-snap failure
gregkh/linux@01a0276706c7 dm raid1: reserve space for NUL-terminator in build_constructor_string()
gregkh/linux@522fa26da24c dm array: reject an array block whose value size is not the caller's
gregkh/linux@aa436b021e50 cpufreq: schedutil: Fix rate limit overflow
gregkh/linux@1353679268b3 cxl/pmem: Format the nvdimm serial number as unsigned decimal
gregkh/linux@1c4b02a81032 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@1a7196c4fffb Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
gregkh/linux@d47b8f8c02a3 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
gregkh/linux@82425b14f0fb Bluetooth: RFCOMM: serialize security confirmation handling
gregkh/linux@ff76a63e9524 Bluetooth: hci_conn: re-enable advertising only for peripheral role
gregkh/linux@d5eef0747071 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
gregkh/linux@6ebb6d175682 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
gregkh/linux@7df825df95cf Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@faf331d3f214 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@d90a166ac55c Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
gregkh/linux@7cd164f0e1ba kasan: fix cache shrink race with CPU hotplug
gregkh/linux@c4dc23de4cc7 ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
gregkh/linux@defa0adeff13 ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
gregkh/linux@c3457a5aae5f ip6_gre: fix hardware header length for NBMA tunnels
gregkh/linux@3665abc3d2ae ipv6: use RCU iterator to dump route exceptions
gregkh/linux@93967bfb17da libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
gregkh/linux@792515b2b77c mailbox: qcom-ipcc: fix duplicate channel allocation across holes
gregkh/linux@0a03f9541c06 md: do overflow check for sb->bblog_shift in super_1_load()
gregkh/linux@d9640239827d mpls: reload header after pskb_may_pull()
gregkh/linux@9df36a484637 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
gregkh/linux@e05c28bd6043 nouveau/gem: reserve the bo in the info ioctl around the vma lookup
gregkh/linux@4bf59cb0ea5b SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
gregkh/linux@56b29d62017c SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
gregkh/linux@0ea5b0c7f212 SUNRPC: svcauth_gss: enforce krb5 token minimum length
gregkh/linux@edb20e8c03ae sunrpc: route to a populated pool in svc_pool_for_cpu()
gregkh/linux@6d74ecc2be12 SUNRPC: always drain cache_cleaner before destroying a cache_detail
gregkh/linux@57ac7d899409 SUNRPC: Check svc pool percpu counter allocation
gregkh/linux@ef948257d121 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
gregkh/linux@f2591660e0eb SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
gregkh/linux@81fd7654a842 SUNRPC: harden gss_unwrap_resp_priv length checks
gregkh/linux@89c8e0733e8c sunrpc: init gssp_lock before publishing proc entry
gregkh/linux@4abb44a29bb5 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
gregkh/linux@fb43997407bc SUNRPC: wait for in-flight client TLS handshake callback
gregkh/linux@cba8543c18cf svcrdma: Fix offset arithmetic in read_chunk_range
gregkh/linux@06d0390c37fa svcrdma: Fix pcl_for_each_segment for empty chunks
gregkh/linux@b77b83f5529a udf: reject VAT indexes equal to the entry count
gregkh/linux@6deb4d7a0c3d wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
gregkh/linux@a3783800c947 staging: media: tegra-video: fix of_node_put() on VIP parse errors
gregkh/linux@46101fb96aff staging: media: tegra-video: vi: fix probe failure on skipped last port
gregkh/linux@28cf91db44ce rpmsg: glink: smem: order FIFO read after availability check
gregkh/linux@bfc3e5fe778c arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
gregkh/linux@a2e0e01a7fbf arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
gregkh/linux@6ca338cf2d38 remoteproc: scp: Fix device reference leak on failed lookup
gregkh/linux@a5e1fdc126ab qede: Fix NULL pointer dereference in TPA fragment processing
gregkh/linux@3265d558dfaf RDMA/cxgb4: Cancel reg_work before freeing device on remove
gregkh/linux@71dc206f2e2a RDMA/ucma: Lock the handler in ucma_set_ib_path()
gregkh/linux@eda08b6bd64f regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
gregkh/linux@c99889009106 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
gregkh/linux@c4c338dcd38b regulator: qcom-refgen: correct the regulator type to CURRENT
gregkh/linux@9c9eacc47c61 orangefs: fix double-free of trailer_buf on readdir copy failure
gregkh/linux@ce748ae1181d orangefs: skip leading spaces before parsing client debug masks
gregkh/linux@a4adaa722977 ocfs2: always run deallocs on copy-on-write completion
gregkh/linux@24989909d341 ocfs2: bound namelen in dlm_migrate_request_handler
gregkh/linux@77686fa5bba1 ocfs2: validate lengths in dlm_mig_lockres_handler
gregkh/linux@97584e93fc49 ocfs2: validate rl_used against rl_count in refcount block validator
gregkh/linux@c9be4de77f97 ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
gregkh/linux@da279037473a ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
gregkh/linux@1507c5586ebd ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
gregkh/linux@f9dd5cad8d09 ocfs2: fix readdir position truncation on 32-bit kernels
gregkh/linux@574ae2ac2b31 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
gregkh/linux@4d5c460ef875 openvswitch: only skb_tx_error() a packet we are about to drop
gregkh/linux@8a2ec0eb2c5b ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
gregkh/linux@9df45b83d6f6 arm64: compat: Fix decrementing LDM/STM alignment emulation
gregkh/linux@213a32146337 ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
gregkh/linux@7d69a2747441 hwmon: (max6621) fix negative temperature offset and crit readings
gregkh/linux@697d946853e7 hwmon: (max6621) fix temperature clamp range
gregkh/linux@350087f231c1 lockd: pin next file across nlm_inspect_file lock-drop
gregkh/linux@da7555248e9b nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
gregkh/linux@66b5af23b6f9 nvme: zero the discard fallback page
gregkh/linux@313b05de246a nvme-pci: disable controller on admin queue IRQ setup failure
gregkh/linux@b96e1ff75e5c nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
gregkh/linux@bc4013c7cce5 nvme-tcp: fix host memory disclosure on R2T for a read command
gregkh/linux@fca3ebb63e5c nvme-tcp: reject a read that transferred too few bytes
gregkh/linux@5c0b2dbbdafc sctp: stop processing a packet once its association is deleted
gregkh/linux@928fd7920ba3 sctp: drop a chunk if its transport was removed
gregkh/linux@b2d6d873b4df sctp: fix NULL deref on untransmitted RECONF completion
gregkh/linux@b55c2561d3fe sctp: distinguish sequence zero from wildcard in reconf lookup
gregkh/linux@092acd3c55a4 sctp: fix stream->outcnt underflow on duplicate RECONF responses
gregkh/linux@6d2eb93975c0 power: supply: bq24257: fix use-after-free on remove
gregkh/linux@2cfb59dc9df8 power: supply: bq256xx: drain usb_work before freeing the charger
gregkh/linux@976c10d883a0 power: supply: bq25890: Fix power_supply reference leak
gregkh/linux@2746d502b12b power: supply: cros_usbpd-charger: bound the EC-reported port count
gregkh/linux@3262977a05b2 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
gregkh/linux@6f0ce09d60a0 power: supply: lp8727: fix use-after-free in lp8727_release_irq()
gregkh/linux@c06028db6208 power: supply: qcom_battmgr: terminate the strings from firmware
gregkh/linux@442c60c08ec2 power: supply: rt9455: quiesce delayed work before teardown
gregkh/linux@c46c205bab0d power: supply: twl4030_charger: cancel workers via devm
gregkh/linux@2ec4d203ecb0 power: supply: ucs1002: fix use-after-free on remove
gregkh/linux@f46465aefa91 power: supply: max17040: drop incorrect I2C functionality check
gregkh/linux@23783db5642a power: supply: max17040: synchronize work cancellation on suspend
gregkh/linux@991be92489bc s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
gregkh/linux@55f4df40178c s390/dasd: Do not complete a failed ESE read as successful
gregkh/linux@57db27ccc162 s390/dasd: Guard sysfs discipline callbacks against unallocated private data
gregkh/linux@f735b9710f0c s390/dasd: Propagate partial completion length across ERP recovery
gregkh/linux@dcaf13f2f468 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
gregkh/linux@5a072fc80a75 PCI: meson: Fix GPIO state while requesting PERST#
gregkh/linux@838e146ae4cd PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
gregkh/linux@131900a24613 PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@d0631a0ab18a PCI/MSI: Enable memory decoding before restoring MSI-X messages
gregkh/linux@d6895710703e PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@e7730acd6a01 PCI/proc: Use file_ns_capable() when checking config space read access
gregkh/linux@a6a4cee09b15 PCI/proc: Warn on writes to kernel-exclusive config space regions
gregkh/linux@d5db80b68ee5 iommu/vt-d: Fix no_iommu to disable platform opt-in
gregkh/linux@579eb867d3da iommu/vt-d: Force requesting ACS when tboot is enabled
gregkh/linux@44ec7f111330 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
gregkh/linux@beb22ebf76c0 platform/x86: ISST: Validate level in perf mask ioctls
gregkh/linux@c847ea4851ec platform/x86: ISST: Validate socket ID in clos_assoc ioctl
gregkh/linux@dde5b9c91e9f mmc: via-sdmmc: stop card-detect handling on probe failure
gregkh/linux@649024043d23 platform/x86: ISST: Just allow 2 bits for SST feature enable
gregkh/linux@0d601126c7af platform/x86: ISST: Validate logical CPU id and clos id
gregkh/linux@f2a9289a65d3 platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
gregkh/linux@d1b4add68dab platform/chrome: sensorhub: Bound the EC-reported sensor number
gregkh/linux@d8690d44f1b0 platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
gregkh/linux@27a93d0fe239 platform/x86: hp-bioscfg: advance elem past consumed array elements
gregkh/linux@1bf0a07a2ea4 platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
gregkh/linux@81db79fed115 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
gregkh/linux@21243c15e1d3 platform/x86: hp-bioscfg: fix heap OOB read on empty password write
gregkh/linux@62f6f04abc64 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
gregkh/linux@8f5aa1506cdd platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
gregkh/linux@fe837a99e4e3 platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
gregkh/linux@467e53f231f7 platform/x86: hp-bioscfg: pass validated element count to package parsers
gregkh/linux@dfdee7ceff6a platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
gregkh/linux@fedea72e8f31 interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
gregkh/linux@7d66d54b974c ipmi: ipmb: validate write message length
gregkh/linux@d377bf743f29 ipmi: si: Fix NULL pointer dereference after failed registration
gregkh/linux@0a5af67e7184 net/iucv: filter frames in afiucv_hs_rcv() by ingress device
gregkh/linux@6de17275b3cc xdp: fix zero-copy frame layout
gregkh/linux@70e20456bcbf slip: fix use-after-free in sl_sync()
gregkh/linux@98610769784d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
gregkh/linux@010eee265d6b net: tun: bound receive headroom
gregkh/linux@64051fe200c7 net: openvswitch: fix flow mask use-after-free on flow deletion
gregkh/linux@06323666c4e2 net: openvswitch: fix nf_connlabels leak in ovs_ct_init
gregkh/linux@bf3308416a2b net: ravb: avoid dereferencing an invalid PTP clock
gregkh/linux@47981eb66461 net: thunderbolt: Release the Rx HopID that was handed out on mismatch
gregkh/linux@e0d4a17afde5 net: thunderbolt: Mark the connection down when bringing it up fails
gregkh/linux@81fbd4021ca9 NTB: ntb_transport: Recycle TX entries before client callbacks
gregkh/linux@e6cc541fab01 NTB: ntb_transport: Fail TX enqueue when the QP link is down
gregkh/linux@b6db88cde0fb NTB: ntb_transport: Reject oversized TX buffers
gregkh/linux@965c4452bfe3 net: ntb_netdev: Avoid double-accounting netif_rx() drops
gregkh/linux@746681f9e877 net: ntb_netdev: Count packets dropped on RX refill failure
gregkh/linux@ab26e12dd5d2 net/smc: do not dereference an unset send buffer on the SMC-D teardown path
gregkh/linux@09d7a9e162ee net/smc: fix socket refcount leak in smc_switch_conns()
gregkh/linux@df441f3efbb5 net/smc: fix use-after-free in smc_rx_pipe_buf_release()
gregkh/linux@b6b6ac713ee8 net/smc: unregister the connection before draining the rx tasklet
gregkh/linux@84783961cb8b net: cap advertised IP tunnel headroom
gregkh/linux@bfb1c9e6297b net: fix spurious TX timeout after dev_activate()
gregkh/linux@6ec22afc82a3 net: skbuff: don't touch shared zerocopy state in skb_tx_error()
gregkh/linux@96c74420ac92 seg6: reset IP6CB after IPv6 decapsulation
gregkh/linux@00e84a9ff2d4 ALSA: 6fire: bound the MIDI event length from the device
gregkh/linux@6fe7d13608a9 ALSA: aloop: Check card index validity at probe
gregkh/linux@6c07aad8a7c9 ALSA: bcd2000: clear the URB pointers on disconnect
gregkh/linux@26a25fb4ef4b ALSA: mpu401: Check card index validity at probe
gregkh/linux@9cd7c59a106e ALSA: mts64: Check card index validity at probe
gregkh/linux@ede25b7fea0d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
gregkh/linux@64898e9bd8b7 ALSA: portman2x4: Check card index validity at probe
gregkh/linux@487ede9b648f ALSA: serial-u16550: Check card index validity at probe
gregkh/linux@368c521503e3 ALSA: virmidi: Check card index validity at probe
gregkh/linux@342d8d63f653 cgroup/cpuset: Fix misplaced DL migration reset
gregkh/linux@0444f2803b96 PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
gregkh/linux@d18bbf826251 x86/tdx: Fix zero-extension for 32-bit port I/O
gregkh/linux@d1361d4a42bb arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
gregkh/linux@389a50d094e1 dm-stats: fix a crash if allocation of per-cpu data fails
gregkh/linux@42ea423a50ae dm-switch: use WRITE_ONCE() in switch_region_table_write()
gregkh/linux@ef72ff6650c4 i3c: master: Fix info leak and UAF in device unregister path
gregkh/linux@35aa6730b8c5 i3c: master: svc: bound IBI payload to the requested max_payload_len
gregkh/linux@7704f6ba2a8c wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
gregkh/linux@f2134d6ff30c wifi: mwifiex: Detach sync cmd buffer on interrupted wait
gregkh/linux@2610885f7086 wifi: rtl818x: initialize eeprom_93cx6 struct to zero
gregkh/linux@c86199357a93 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
gregkh/linux@ef2ec8b537c3 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
gregkh/linux@b9cb4e8ba71c vsock/virtio: flush works in dependency order
gregkh/linux@0f6496b34cc2 w1: ds28e17: reject an oversize length on an I2C block read
gregkh/linux@6c1a8685be6a xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
gregkh/linux@b0dc3f18af01 tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
gregkh/linux@262b80521915 sticon/parisc: Detect default STI graphics card for console output
gregkh/linux@6b1de022304e signal: avoid shared siginfo namespace rewrites
gregkh/linux@f9c7b1f2b9d8 smack: fix cred UAF in smack_file_send_sigiotask()
gregkh/linux@2252f8ccc308 taskstats: fix cpumask parsing cutting off the last character
gregkh/linux@51e368f723aa timer: Keep debugobjects state consistent in migrate_timer_list()
gregkh/linux@8395cff0b286 udf: Fix i_lenExtents truncation on 32-bit kernels
gregkh/linux@e34ff3f88229 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
gregkh/linux@8069643ae64d net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
gregkh/linux@d7c2b66bc552 net: openvswitch: fix kernel-doc warnings in internal headers
gregkh/linux@680f20d5937f openvswitch: Fix CT limit teardown use-after-free
gregkh/linux@dfb10d989056 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
gregkh/linux@b4bf67cc0871 wifi: mt76: mt7996: validate default EEPROM firmware size
gregkh/linux@343ae18e960f fsnotify: Fix stale object mask after concurrent mark updates
gregkh/linux@cd644e6dc72e tcp: fix potential race in tcp_v6_syn_recv_sock()
gregkh/linux@23001ee5d863 entry: Fix seccomp bypass after ptrace with TSYNC
gregkh/linux@7ab40f7577d8 net: ntb_netdev: Fix TX busy and drop handling
gregkh/linux@517ed2f9ea7d tracing/mmiotrace: Remove reference to unused per CPU data pointer
gregkh/linux@2df964d14127 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
gregkh/linux@28ed5343666f scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
gregkh/linux@4c5b61b9df6a drm/amd/display: fix division by zero in get_estimated_bw()
gregkh/linux@553c375e86a4 usb: image: mdc800: change kmalloc() to kzalloc()
gregkh/linux@1d4add2b832b ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
gregkh/linux@d91993f4c763 clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
gregkh/linux@67374e3a0081 media: usbtv: keep device alive while ALSA card exists
gregkh/linux@9481bc04a8c3 usb-storage: ene_ub6250: fix race between scan work and probe
gregkh/linux@dbbb3bb0bf2f usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
gregkh/linux@0b69b166852d usb: typec: qcom-pmic: cancel reset_work on stop
gregkh/linux@58e0ee293ec5 usb: typec: ucsi: displayport: Fix OOB altmode array index
gregkh/linux@51ddc55c7508 usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
gregkh/linux@f9bdf4c4f641 usb: gadget: f_midi2: fix use-after-free in string attribute show path
gregkh/linux@162178ca83c3 USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
gregkh/linux@7a4f4ca7ff32 usb: gadget: fix null pointer dereference in usb_put_function_instance()
gregkh/linux@fd5e24ea8373 staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
gregkh/linux@0b7f64c7bb96 staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
gregkh/linux@03ff03e5c95a thermal/drivers/imx: Disable clock on runtime resume failure
gregkh/linux@d3018aaa5e3b thermal/drivers/qoriq: Disable clock on resume failure
gregkh/linux@be41733c24be ublk: clear VM_MAYWRITE on read-only ublk char device mmap
gregkh/linux@5597b4ffd0be spi: bcm63xx-hsspi: disable clocks on resume failure
gregkh/linux@d45f27903f94 spi: bcm63xx: disable clock on resume failure
gregkh/linux@635b2bddea56 spi: bcmbca-hsspi: disable clocks on resume failure
gregkh/linux@6b589ef9d5f6 scsi: target: iscsi: Reserve a terminator byte for the login payload
gregkh/linux@2853ce9c88e0 scsi: pm8001: Use rollback index when freeing MSI-X vectors
gregkh/linux@b33f9b018415 mm/damon/sysfs-schemes: kobject_del() scheme dirs
gregkh/linux@0e4aa31ab32a mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
gregkh/linux@ffab414fc5e0 mm/damon/sysfs-schemes: kobject_del() scheme region dirs
gregkh/linux@c97ded32334d mm/damon/sysfs: kobject_del() region and target (error) dirs
gregkh/linux@2bf705699fd7 mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
gregkh/linux@81aadbd09bf1 futex: Prevent rcuwait use-after-free during requeue PI
gregkh/linux@a8be8bbf0952 HID: rmi: fix OOB access with undersized RMI reports
gregkh/linux@96dd0af7597a HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
gregkh/linux@0ea6e5ad4a58 dm: fix race when loading and unloading a table
gregkh/linux@94f3d399c1dd dm: fix resume-vs-remove race
gregkh/linux@718ee263a60d dmaengine: dw-edma: Fix HDMA channel status register access
gregkh/linux@8bc87a50fd0e dmaengine: dw-edma: Complete descriptors before pausing
gregkh/linux@17ef63843c0f dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
gregkh/linux@a38caa9ed0d5 cpuidle: dt_idle_genpd: kfree() the original name allocation
gregkh/linux@642b76f92bc4 block: flag zoned disks with GENHD_FL_NO_PART
gregkh/linux@23a969a2df8d ata: ahci: work around lost interrupts on Marvell 88SE61xx
gregkh/linux@30b5c0e17dca ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
gregkh/linux@630ed8734a02 kprobes: Protect kprobe_blacklist with RCU
gregkh/linux@a098e2cecd9d Input: aiptek - validate raw macro indices before updating state
gregkh/linux@5548f41e2f8d rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
gregkh/linux@341ec28243f1 rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
gregkh/linux@ca19a175e89b perf/x86/intel: Fix kernel address leakages in LBR stack
gregkh/linux@f9094ace03e0 i2c: core: fix debugfs UAF on adapter removal
gregkh/linux@0927153f2abf i2c: mux: Fix channel node leak on adapter add failure
gregkh/linux@08d931a0a850 arm64: mm: Fix the lockless page-table walk in show_pte()
gregkh/linux@7dc239edb6d5 ALSA: harmony: initialize locks before requesting IRQ
gregkh/linux@ad29779736cf ALSA: pcm: Fix race between non-atomic ops and trigger-start
gregkh/linux@0673a2affe45 nvme-tcp: check the data direction of a C2HData PDU
gregkh/linux@cf5f39d2b58f nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
gregkh/linux@9fb527103e53 nvmet-tcp: reject unsolicited H2CData PDUs
gregkh/linux@0fb7c549357c Revert "irqchip/mbigen: Fix mbigen node address layout"
gregkh/linux@6eddedb1a300 mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
gregkh/linux@f9bf05c63b77 nvdimm/btt: reject an arena whose nfree is below the lane count
gregkh/linux@62d88e93ef5e parisc: eisa: Fix infinite loop when parsing invalid IRQ value
gregkh/linux@f5e9bea0d7c1 parisc: Fix alignment of asm statements in head.S
gregkh/linux@b96be860673f powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
gregkh/linux@b0cf5aceafb4 powerpc/pseries: Handle and log pseries-wdt registration failures
gregkh/linux@9c8e0e526b76 powerpc/pseries: Move H_WATCHDOG definitions to a common header
gregkh/linux@114b6ce2cf86 powerpc/crash: stop watchdogs before booting kdump kernel
gregkh/linux@eb6cc898501a s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()
gregkh/linux@1f54efd80032 s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove
gregkh/linux@02e72909453d s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
gregkh/linux@5e932abfcce6 s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
gregkh/linux@3a9b049bbdc4 s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed
gregkh/linux@31fa0a8a3c33 s390/vfio-ap: Fix NULL deref in status_show() during queue probe
gregkh/linux@4ba8a08f5f26 s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
gregkh/linux@58f6f9125e74 s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object
gregkh/linux@da740539e8f3 mtd: afs: validate v2 image info bounds
gregkh/linux@f25c804947e0 mtd: mtdoops: free page bitmap when the backing MTD is removed
gregkh/linux@ddb6ddf5be74 mtd: rawnand: validate ONFI extended parameter page sections
gregkh/linux@6df64825f8b1 batman-adv: fix stale receive device on merged fragments
gregkh/linux@c74a4acf41d1 batman-adv: dat: avoid unaligned fault in IP extraction
gregkh/linux@76aedcde5a24 batman-adv: bla: fix freeing of claims on meshif deletion
gregkh/linux@b89701e1fae1 batman-adv: bla: prevent CRC corruptions after claim flush
gregkh/linux@a2c156d22c3d clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@ce6f40f8dc66 clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@1e2465ee57a3 clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src
gregkh/linux@0944e2cd198f clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
gregkh/linux@0c0609c1da0d clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
gregkh/linux@c93a8c7064b3 clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
gregkh/linux@ad3436ad31b8 clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
gregkh/linux@0c4c642b4d03 clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
gregkh/linux@52f7ce8896d6 i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
gregkh/linux@614c2616ea67 ASoC: cs35l33: drain threaded IRQ before runtime suspend
gregkh/linux@f4bfd755c52d ASoC: cs35l34: drain threaded IRQ before runtime suspend
gregkh/linux@6150b04ce847 ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
gregkh/linux@4dc91d0dadfe AsoC: intel: sst: fix PCI device reference leak on probe failure
gregkh/linux@ed43e34f431d ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get
gregkh/linux@72daa7eb7fc6 iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
gregkh/linux@f64b437641b5 iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF
gregkh/linux@3462c13bb0f5 iio: chemical: sgp30: Handle IAQ thread creation failure
gregkh/linux@f5acb824277a iio: dac: m62332: Fix regulator reference count imbalance
gregkh/linux@7dfbbb2f219f iio: gyro: mpu3050: fix sign of raw angular velocity readings
gregkh/linux@82c27dabc391 iio: light: cm32181: return zero after writing calibscale
gregkh/linux@da41c3e0e67a iio: light: gp2ap002: Disable regulators on resume failure
gregkh/linux@a32a39da18e0 iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
gregkh/linux@d97f4e012ba3 iio: pressure: mpl115: Fix runtime PM cleanup
gregkh/linux@e44b2af0c14e iio: srf04: fix pm_runtime handling on probe error path
gregkh/linux@9b75d89fd1e3 iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register()
gregkh/linux@170904917dc8 iio: light: opt4001: Fix power down clearing bits of the wrong register
gregkh/linux@0f9f6d0ee5a5 iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem()
gregkh/linux@7a1be6e7a857 iio: light: opt4001: Reject integration times with a non-zero seconds part
gregkh/linux@ee2d20a38666 iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask
gregkh/linux@62604376c313 KVM: nVMX: Always flush vpid02 on first use
gregkh/linux@312cdb6d8940 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
gregkh/linux@8e19ded84336 KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
gregkh/linux@fec89d327d9b KVM: s390: Fix length check __import_wp_info()
gregkh/linux@5940418e4232 KVM: s390: Fix memory leak in guest debug handling
gregkh/linux@5fbf31913773 KVM: s390: Fix old_data leak in guest debug error path
gregkh/linux@544a5a665019 KVM: s390: Free guest debug data on vcpu destroy
gregkh/linux@f8e3a9997d5e KVM: s390: Take srcu when importing watchpoint data
gregkh/linux@934b7b2b76d3 KVM: s390: Zero initialize irq in reinject_machine_check
gregkh/linux@191449955646 KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
gregkh/linux@9c55a7d4e521 KVM: s390: Restore sigset on error path
gregkh/linux@a03b5e7483ad LoongArch: Do not save/restore percpu base register in rethook trampoline
gregkh/linux@ff40e597d5d9 LoongArch: Avoid preempt count underflow without probe
gregkh/linux@6e4ea90fdc66 media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref
gregkh/linux@954ee95a03b4 media: cec: core: Fix kmemleak due to missed rc_free_device() call
gregkh/linux@cf3bf86f3237 media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash
gregkh/linux@271e57a936dc media: cec: Serialize exclusive follower delivery
gregkh/linux@22441be29ec2 media: cedrus: fix memory leak in cedrus_init_ctrls()
gregkh/linux@42e00371f83c media: cobalt: Avoid freeing ALSA private data twice
gregkh/linux@54ac6df8b8d9 media: cx231xx: reject geometry changes while the VBI queue is busy
gregkh/linux@ec82b0cf7f75 media: cx23885: cancel NetUP CI work before teardown
gregkh/linux@4e11c45dfdc7 media: em28xx: defer audio-only extension registration
gregkh/linux@20aacd87550b media: em28xx: fix use-after-free of dev_next->devlist on disconnect
gregkh/linux@1c9fdd946521 media: go7007: defer the ALSA v4l2 put until card release
gregkh/linux@4c2988bf1ad2 media: i2c: ov02a10: fix endpoint parsing use-after-free
gregkh/linux@7512838a19af media: i2c: ov7740: fix use-after-destroy in remove
gregkh/linux@680a89683197 media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
gregkh/linux@94666ec4ae77 media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing
gregkh/linux@e9fe8e3f758f media: nxp: imx8-isi: Correct color map between V4L2 and ISI
gregkh/linux@c817f2441062 media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks
gregkh/linux@826763adbd8b media: rc: sunxi-cir: Unregister rc device on probe failure
gregkh/linux@053581d4657c media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak
gregkh/linux@c91e8ae2b39c media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
gregkh/linux@79f58f900dd2 media: s2255: bound JPEG frame size before copying into the buffer
gregkh/linux@5626785b0e46 media: s2255: check firmware size before reading trailing marker
gregkh/linux@77f216f8de62 media: saa7164: fix cleanup on resource allocation failure
gregkh/linux@593b1172e5d5 media: tda18250: fix possible integer overflow
gregkh/linux@d273571e5314 media: v4l2-async: avoid deleting unlinked ASC entry on link error
gregkh/linux@ea5a921d4d27 media: v4l2-ctrls: Allow unknown HDR10 white point and luminance
gregkh/linux@ef609b3ce456 media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
gregkh/linux@fdf1eb47a60d media: venus: fix payload size returned by parse_caps() and parse_alloc_mode()
gregkh/linux@7c0212041fab media: venus: fix payload size calculation in parse_raw_formats()
gregkh/linux@3d1b10d81fe5 media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
gregkh/linux@ca87a19381ae media: vimc: fix pixel format lookup in enum_framesizes
gregkh/linux@c4acac8cdc00 media: zoran: Avoid freeing a registered video_device twice
gregkh/linux@84bde5ce4038 scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
gregkh/linux@9a756f277eb8 scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
gregkh/linux@de0c8ef3b900 scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
gregkh/linux@55f8698a6caf scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters
gregkh/linux@f8d2eb510c06 scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
gregkh/linux@b403700ac62f scsi: qla2xxx: Initialize NVMe abort_work once at submission
gregkh/linux@5b8ed910c392 scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()
gregkh/linux@047f1f7ee6f8 scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
gregkh/linux@7eb618877503 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
gregkh/linux@e80adfeac61b scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
gregkh/linux@9cef42a073a0 scsi: qla2xxx: Serialize flash version read in reset handler
gregkh/linux@ae09260be745 scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
gregkh/linux@6003e79148ec scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
gregkh/linux@2f847f06bb22 scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
gregkh/linux@5762d992ddda scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
gregkh/linux@b6a30baa2969 scsi: qla2xxx: Don't query firmware state while chip is down
gregkh/linux@8f0e31e7a413 scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
gregkh/linux@6e3f129538c3 scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()
gregkh/linux@7ac5be2a8609 scsi: qla2xxx: Quiesce response IRQ before freeing request queue
gregkh/linux@6e217a9482ea scsi: qla2xxx: Avoid double completion in async IOCB timeout
gregkh/linux@be75ab791c9b scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
gregkh/linux@d79376fbd2a0 scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
gregkh/linux@af8650037eec scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort
gregkh/linux@e72c9eb93c5f scsi: qla2xxx: Drop vport reference under lock in report ID acquisition
gregkh/linux@e8f1b0cb9782 scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition
gregkh/linux@9c00b8916040 scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics
gregkh/linux@947c6bfcf7f5 scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
gregkh/linux@2935b730211c scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
gregkh/linux@4aa12ba10cbf f2fs: return symlink writeback errors
gregkh/linux@ca1a602d4f73 f2fs: reject overlapping move range after len expansion
gregkh/linux@4c0c610b480c f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
gregkh/linux@694565c0c14c f2fs: return writeback error from collapse range
gregkh/linux@e601926015e0 f2fs: fix i_size when pinned fallocate partially fails
gregkh/linux@d7a07c9ac1e7 f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()
gregkh/linux@6882d458d2e4 f2fs: fix to zero post-EOF data when extending file size
gregkh/linux@c0cbdb43e0c6 drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure
gregkh/linux@8d9e6dffaea9 drm/panel-edp: fix i2c adapter leak on probe failure
gregkh/linux@a0a7e2e177f2 drm: fix race between partial drm_dev_register() failure and ioctl
gregkh/linux@4a0236fe9773 drm/i915: Guard against NULL driver_data in i915_pci_probe()
gregkh/linux@5296c567cbac drm/sun4i: fix refcount leak in sun4i_backend_init_sat()
gregkh/linux@1f0b71afd81d drm/hibmc: Fix list of formats on the primary plane
gregkh/linux@6fa33b32783e drm/hibmc: Use drm_atomic_helper_check_plane_state()
gregkh/linux@4d5ee095a584 drm/amd/display: avoid divide-by-zero in __is_lut_linear()
gregkh/linux@6dceaeceaa7c drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
gregkh/linux@89210cb5ff8f drm/gud: NUL-terminate TV mode names read from the device
gregkh/linux@082e37888654 drm/gud: validate TV mode names before creating enum property
gregkh/linux@4f966558c188 drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value
gregkh/linux@e2f27b5ed908 drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
gregkh/linux@84a8012601b9 drm/amdgpu: check thunderbolt before switcheroo registration
gregkh/linux@5d501f727945 drm/amdgpu: fix autosuspend cleanup during removal
gregkh/linux@b4c90c78f420 drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT
gregkh/linux@0f47c47b4573 drm/amdkfd: Reject zero-sized AQL queue allocations after size halving
gregkh/linux@f02aefbc43bd drm/nouveau: Use write-combined maps for coherent
gregkh/linux@ba42d8a1c2c7 drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
gregkh/linux@a129b2b875c1 drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
gregkh/linux@43239fc6dfb6 xhci: fix lost bounce buffers on TDs spanning several ring segments
gregkh/linux@9fffa6465851 tcp: clear sock_ops cb flags before force-closing a child socket
gregkh/linux@f3d8c2fd591b net/mlx5e: xsk: Fix unlocked writing to ICOSQ
gregkh/linux@c3c126a6142a nvmet-auth: Synchronize timeout work during SQ teardown
gregkh/linux@94c4828bee3d mm/damon/core-kunit: check region count before testing in split_at()
gregkh/linux@2b48a84d31dc mm/damon/vaddr: drop last same folio access check optimization
gregkh/linux@072d538e9d8c mm/damon/paddr: drop last same folio access check reuse optimization
gregkh/linux@9b7cf02158d9 mm/damon/vaddr-kunit: check region count in three_regions test
gregkh/linux@1acb6d1ece3b mm/damon/core-kunit: handle region split failure in filter_out()
gregkh/linux@2b844d952e23 mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()
gregkh/linux@7f1fe43907a6 net: hns3: don't auto enable misc vector
gregkh/linux@9d213ca0cb49 net: hns3: fix kernel crash when 1588 is sent on HIP08 devices
gregkh/linux@7493b9baf0e5 wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path
gregkh/linux@5eaf57fdfa37 md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb
gregkh/linux@9c6c85ae77ef net: libwx: fix Tx L4 checksum
gregkh/linux@73f074fb5e13 ksmbd: fix overflow in dacloffset bounds check
gregkh/linux@97aabdbf7ba8 ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"
gregkh/linux@0afd48b173be net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads
gregkh/linux@4b9aee707c45 parse_longname(): strrchr() expects NUL-terminated string
gregkh/linux@c9a129c82ddf ceph: fix oops due to invalid pointer for kfree() in parse_longname()
gregkh/linux@e2e9599f3503 bpf: Reject narrower access to pointer ctx fields
gregkh/linux@de6601f1374f netfilter: nft_counter: serialize reset with spinlock
gregkh/linux@2120bd8546cd bridge: mrp: reject zero test interval to avoid OOM panic
gregkh/linux@64eaf4ecda00 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
gregkh/linux@f0ff7f12398e ksmbd: fix use-after-free in smb2_open during durable reconnect
gregkh/linux@5e641e4ee0bc ksmbd: fix durable reconnect error path file lifetime
gregkh/linux@d161c4456672 ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
gregkh/linux@1674855a5b6e batman-adv: dat: atomically update mac addresses
gregkh/linux@a3e07db74f22 batman-adv: bla: avoid CRC corruption due to parallel claim add
gregkh/linux@29639f00bfa4 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
gregkh/linux@404079d124d7 clk: meson: align gxbb_32k_clk_sel number of parents with actual count
gregkh/linux@a886ad5f6348 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
gregkh/linux@6d79a939e284 mm/damon/core: skip aging from repeated aggressive merging
gregkh/linux@9ed9a94c1a41 drm: Remove unused header in drm_dumb_buffers.c
gregkh/linux@8504b0e1acef drm: lcdif: Wait for vblank before disabling DMA
gregkh/linux@a008506e55e3 drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format
gregkh/linux@139460b7723c drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure
gregkh/linux@ec47f4177046 smack: fix incorrect task context in smack_msg_queue_msgrcv
gregkh/linux@6d4addf839b9 smack: simplify write handlers of sysfs entries
gregkh/linux@c7bb74fa9c38 smack: deduplicate smackfs/{direct,mapped} file_operations
gregkh/linux@02e095247f0a smack: restrict smackfs/{direct,mapped} values to 0-255
gregkh/linux@c0e090bd6708 x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE()
gregkh/linux@4e37371cb4e3 platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
gregkh/linux@92cca302a4ea HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
gregkh/linux@e45631bf607f HID: nintendo: Fix imu_timestamp_us double increment per report
gregkh/linux@4b29be4b23bc HID: roccat: bound device-supplied profile index
gregkh/linux@111f1311bbdb soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap()
gregkh/linux@b37e82a046e7 media: cec-pin: Fix event FIFO ordering
gregkh/linux@909f1b54d5a0 clk: versaclock7: Fix APLL clock leak on probe failure
gregkh/linux@6956464d233a clk: moxart: remove unused variables, fix refcount leak
gregkh/linux@828a90dadda6 clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation
gregkh/linux@418401f2a872 clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc
gregkh/linux@25f46d253633 clk: nuvoton: ma35d1-pll: convert from round_rate() to determine_rate()
gregkh/linux@b550b77f34f1 clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic
gregkh/linux@1bb23c9d6831 ASoC: rt700-sdw: always drain jack work on remove
gregkh/linux@d3d51e874f7c clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller
gregkh/linux@01a854226f5d ARM: imx: fix device_node refcount leak in imx_src_init()
gregkh/linux@3f0ebe8f8ae3 ARM: imx: fix device_node refcount leaks in imx7_src_init()
gregkh/linux@0c90fe8d8039 clk: imx: scu: drop redundant init.ops variable assignment
gregkh/linux@788917ba77f5 drm/lima: call drm_mm_init() with a valid allocation range
gregkh/linux@f5ec164e733b mm/mm_init: fix incorrect node_spanned_pages
gregkh/linux@69fafae4eb2c sched/fair: Fix overflow in update_tg_cfs_runnable()
gregkh/linux@ff48a41a242f perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails
gregkh/linux@3b978fd0a309 pinctrl: bcm2835: Don't remove an unregistered GPIO chip
greg...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant