SUSE-SU-2026:23241-1

Advisory lineage Upstream: 648 Downstream: 0
Published: 18 Aug 2026, 20:43
Last modified:27 Aug 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Aug 2026, 20:43
Published
Vulnerability first disclosed
27 Aug 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2025-68741: scsi: qla2xxx: Fix improper freeing of purex item (bsc#1255703). - CVE-2025-68818: scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" (bsc#1256675). - CVE-2026-23097: migrate: correct lock ordering for hugetlb file folios (bsc#1257815). - CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). - CVE-2026-43114: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (bsc#1264601). - CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). - CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). - CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537). - CVE-2026-43170: usb: dwc3: gadget: Move vbus draw to workqueue context (bsc#1264452). - CVE-2026-43172: wifi: iwlwifi: fix 22000 series SMEM parsing (bsc#1264543). - CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319). - CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539). - CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). - CVE-2026-43262: gfs2: fiemap page fault fix (bsc#1264422). - CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418). - CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534). - CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712). - CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827). - CVE-2026-43328: cpufreq: governor: Free dbs_data directly when gov->init() fails (bsc#1264832). - CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). - CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141). - CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009). - CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). - CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). - CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710). - CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets (bsc#1266715). - CVE-2026-45877: HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients (bsc#1266468). - CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685). - CVE-2026-45913: net: bridge: mcast: always update mdb_n_entries for vlan contexts (bsc#1266891). - CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896). - CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900). - CVE-2026-45944: iommu/vt-d: Clear Present bit before tearing down context entry (bsc#1267203). - CVE-2026-45973: RDMA/mlx5: Fix UMR hang in LAG error state unload (bsc#1267025). - CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). - CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). - CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes (bsc#1267210). - CVE-2026-46015: tcp: call sk_data_ready() after listener migration (bsc#1267439). - CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). - CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups (bsc#1266876). - CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). - CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye() (bsc#1266695). - CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). - CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). - CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). - CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). - CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). - CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). - CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). - CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race (bsc#1267570). - CVE-2026-46147: KVM: arm64: Factor out pKVM hyp vcpu creation to separate function (bsc#1267689). - CVE-2026-46158: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (bsc#1266880). - CVE-2026-46168: mptcp: sockopt: set timestamp flags on subflow socket, not msk (bsc#1266869). - CVE-2026-46170: mptcp: pm: reuse ID 0 after delete and re-add (bsc#1267714). - CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (bsc#1266813). - CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918). - CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). - CVE-2026-46234: vsock: fix buffer size clamping order (bsc#1266904). - CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678). - CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). - CVE-2026-46265: RDMA/hns: Fix WQ_MEM_RECLAIM warning (bsc#1267662). - CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd (bsc#1267943). - CVE-2026-46294: dm: fix a buffer overflow in ioctl processing (bsc#1267939). - CVE-2026-46306: flow_dissector: do not dissect PPPoE PFC frames (bsc#1267986). - CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). - CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995). - CVE-2026-52910: pf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). - CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). - CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end (bsc#1269024). - CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027). - CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003). - CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR (bsc#1268983). - CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint (bsc#1268966). - CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967). - CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (bsc#1269115). - CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval (bsc#1269229). - CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX setup failure (bsc#1269233). - CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). - CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-52988: rculist: add list_splice_rcu() for private lists (bsc#1269362). - CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134). - CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). - CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118). - CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (bsc#1269119). - CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops (bsc#1269117). - CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112). - CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). - CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). - CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104). - CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). - CVE-2026-53011: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (bsc#1269094). - CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop (bsc#1269154). - CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). - CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs (bsc#1269138). - CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658). - CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659). - CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132). - CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (bsc#1269186). - CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (bsc#1269688). - CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear() (bsc#1269964). - CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (bsc#1269185). - CVE-2026-53106: bpf: Do not allow deleting local storage in NMI (bsc#1269990). - CVE-2026-53107: wifi: libertas: use USB anchors for tracking in-flight URBs (bsc#1269991). - CVE-2026-53123: md: wake raid456 reshape waiters before suspend (bsc#1269643). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue (bsc#1269290). - CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819). - CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (bsc#1269714). - CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink (bsc#1269376). - CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict (bsc#1269689). - CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial() (bsc#1269660). - CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). - CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put() (bsc#1269797). - CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy (bsc#1269672). - CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). - CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (bsc#1269318). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). - CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). - CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (bsc#1269270). - CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994). - CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808). - CVE-2026-53252: adaption to srcu change of hci_dev in hci_sysfs (bsc#1269307). - CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). - CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240). - CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810). - CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs() (bsc#1269694). - CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697). - CVE-2026-53345: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (bsc#1270132). - CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs" (bsc#1270230). - CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). - CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826). - CVE-2026-53393: nfsd: Don't reset the write verifier on a commit EAGAIN (bsc#1271858). - CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869). - CVE-2026-53398: NFSD: Fix SECINFO_NO_NAME decode error cleanup (bsc#1271870). - CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63795: 9p: avoid putting oldfid in p9_client_walk() error path (bsc#1271955). - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63809: bpf: NUL-terminate replaced sysctl value (bsc#1272296). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468). - CVE-2026-63962: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (bsc#1272482). - CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (bsc#1273117). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64187: xfs: fail recovery on a committed log item with no regions (bsc#1272204). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1271912 bsc#1273004). - CVE-2026-64561: kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - accel/qaic: use sizeof(*trans_hdr) for transaction length check (git-fixes). - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (git-fixes). - ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). - ALSA: hda: cs35l41: validate and free ACPI mute object (git-fixes). - ALSA: hda: Fix cached processing coefficient verbs (git-fixes). - ALSA: lx6464es: fix period byte count for 16-bit streams (git-fixes). - ALSA: pcm: wake linked drain waiters on unlink (git-fixes). - ALSA: seq: close a re-opened queue timer in the destructor (git-fixes). - ALSA: ump: fix double free of out_cvts on rawmidi error (git-fixes). - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (git-fixes). - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (git-fixes). - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (git-fixes). - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes). - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (git-fixes). - ASoC: cs35l56: Fix potential probe() deadlock (git-fixes). - ASoC: cs35l56: Use complete_all() to signal init_completion (git-fixes). - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (stable-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (stable-fixes). - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). - ASoC: tas2562: fix broken entries in the volume lookup table (git-fixes). - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). - ASoC: tas2562: fix DVC coefficient write order (git-fixes). - ASoC: tas2781: bound firmware description string parsing (git-fixes). - assoc_array: trim the final shortcut word using the current chunk end (git-fixes). - batman-adv: dat: fix tie-break for candidate selection (git-fixes). - batman-adv: fix VLAN priority offset (git-fixes). - batman-adv: frag: fix primary_if leak on failed linearization (git-fixes). - batman-adv: frag: free unfragmentable packet (git-fixes). - batman-adv: tt: avoid request storms during pending request (git-fixes). - batman-adv: tt: prevent TVLV OOB check overflow (git-fixes). - bitops: make BYTES_TO_BITS() treewide-available (stable-fixes). - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (stable-fixes). - Bluetooth: btintel: Validate length before parsing diagnostics TLV (git-fixes). - Bluetooth: btrtl: validate firmware patch bounds (git-fixes). - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (stable-fixes). - Bluetooth: btusb: mediatek: remove the unnecessary goto tag (stable-fixes). - Bluetooth: btusb: validate Realtek vendor event length (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks (git-fixes). - Bluetooth: hci_sync: Protect UUID list traversal (git-fixes). - Bluetooth: HIDP: reject frames without a transaction header (git-fixes). - Bluetooth: HIDP: validate numbered report payloads (git-fixes). - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (git-fixes). - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (git-fixes). - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes). - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (git-fixes). - Bluetooth: mgmt: Translate HCI reason in Device Disconnected event (git-fixes). - Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes). - Bluetooth: RFCOMM: Fix session UAF in set_termios (git-fixes). - bus: sunxi-rsb: Always check register address validity (git-fixes). - can: bcm: add missing rcu list annotations and operations (git-fixes). - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (git-fixes). - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (git-fixes). - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (git-fixes). - can: ctucanfd: add missing MODULE_DEVICE_TABLE() (git-fixes). - can: ctucanfd: handle bus error interrupts (git-fixes). - can: ctucanfd: mark error-active controller status valid (git-fixes). - can: ctucanfd: unmap BAR0 using base address (git-fixes). - can: ctucanfd: use self-test mode for PRESUME_ACK (git-fixes). - can: ems_usb: validate CPC message lengths (git-fixes). - can: esd_usb: kill anchored URBs before freeing netdevs (git-fixes). - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (git-fixes). - can: isotp: check register_netdevice_notifier() error in module init (git-fixes). - can: isotp: use unconditional synchronize_rcu() in isotp_release() (git-fixes). - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (git-fixes). - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (git-fixes). - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (git-fixes). - can: peak_usb: add bounds check for USB channel index (git-fixes). - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (git-fixes). - can: peak_usb: validate uCAN receive record lengths (git-fixes). - can: softing: fw_parse(): validate firmware record spans (git-fixes). - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (git-fixes). - comedi: comedi_parport: deal with premature interrupt (git-fixes). - dm cache policy smq: check allocation under invalidate lock (git-fixes). - dm cache: fix missing return in invalidate_committed's error path (git-fixes). - dmaengine: idxd: fix double free of wq, engine, and group structs (git-fixes). - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (git-fixes). - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (git-fixes). - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (git-fixes). - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (git-fixes). - driver core: Guard deferred probe timeout extension with delayed_work_pending() (git-fixes). - driver core: Use mod_delayed_work to prevent lost deferred probe work (git-fixes). - Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes). - drm/amd/display: set new_stream to NULL after release (git-fixes). - drm/amd/display: use proper context for logging (git-fixes). - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (git-fixes). - drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes). - drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes). - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes). - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes). - drm/amdgpu/vce: fix integer overflow in image size (stable-fixes). - drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes). - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes). - drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes). - drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes). - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes). - drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes). - drm/amdkfd: free MQD managers on DQM init failures (git-fixes). - drm/amdkfd: hold event_mutex while checkpointing CRIU events (git-fixes). - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (git-fixes). - drm/i915/gt: use correct selftest config symbol (git-fixes). - drm/i915/selftests: Fix GT PM sort comparators (git-fixes). - drm/mediatek: ovl_adaptor: balance component registrations (git-fixes). - drm/radeon: fix r100_copy_blit for large BOs (stable-fixes). - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (git-fixes). - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (stable-fixes). - drm/vc4: hvs/v3d: Fix null dereference in unbind (git-fixes). - drm/vc4: Prevent shader BO mappings from becoming writable (git-fixes). - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (git-fixes). - drm/vc4: Zero the tile state data array before each BIN job (git-fixes). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (git-fixes). - drm/vmwgfx: bound DMA command body size against suffix pointer (git-fixes). - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (git-fixes). - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (git-fixes). - drm/vmwgfx: reject DX_BIND_QUERY without a DX context (git-fixes). - drm/vmwgfx: use check_add_overflow for shader size+offset bound (git-fixes). - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (git-fixes). - drm/vmwgfx: validate external BO copy bounds for both stride paths (git-fixes). - drm/vmwgfx: Validate vmw_surface_metadata::array_size (git-fixes). - fbcon: fix NULL pointer dereference for a console without vc_data (stable-fixes). - fbdev/efifb: Replace references to global screen_info by local pointer (stable-fixes). - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (git-fixes). - fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). - firewire: net: Fix fragmented datagram reassembly (git-fixes). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (git-fixes). - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes). - firmware_loader: introduce __free() cleanup hanler (stable-fixes). - gpio: eic-sprd: use raw_spinlock_t in the irq startup path (git-fixes). - gpio: mlxbf3: fail probe if gpiochip registration fails (git-fixes). - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (git-fixes). - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes). - HID: add haptics page defines (stable-fixes). - HID: Intel-ish-hid: Ishtp: Fix sensor reads after ACPI S3 suspend (bsc#1266468). - HID: playstation: validate num_touch_reports in DualShock 4 reports (stable-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (git-fixes). - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (git-fixes). - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (git-fixes). - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (git-fixes). - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (git-fixes). - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (git-fixes). - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (git-fixes). - hwmon: (adt7470) Use cached PWM frequency value (git-fixes). - hwmon: (asus-ec-sensors) add missed handle for ENOMEM (git-fixes). - hwmon: (asus-ec-sensors) fix EC read intervals (git-fixes). - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (git-fixes). - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (lm90) Only report alarms if driver is ready (git-fixes). - hwmon: (nct6775-core) Prevent access to unsupported weight registers (git-fixes). - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (git-fixes). - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (git-fixes). - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (git-fixes). - hwmon: (w83627hf) remove VID sysfs files on error and remove (stable-fixes). - hwmon: (w83793) remove vrm sysfs file on probe failure (stable-fixes). - hwmon: occ: validate poll response sensor blocks (git-fixes). - i2c: amd-mp2: Unregister callback on adapter add failure (git-fixes). - i2c: imx: Cancel hrtimer before clearing slave pointer (git-fixes). - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes). - i2c: imx: Fix slave registration race and error handling (git-fixes). - i2c: imx: separate atomic, dma and non-dma use case (stable-fixes). - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (git-fixes). - i2c: mediatek: fix WRRD for SoCs without auto_restart option (git-fixes). - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (git-fixes). - i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes). - i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). - ice: don't check has_ready_bitmap in E810 functions (bsc#1269981). - ice: factor out ice_ptp_rebuild_owner() (bsc#1269981). - ice: fix PTP Call Trace during PTP release (bsc#1269981). - ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981). - ice: introduce PTP state machine (bsc#1269981). - ice: pass reset type to PTP reset functions (bsc#1269981). - ice: rename ice_ptp_tx_cfg_intr (bsc#1269981). - ice: rename verify_cached to has_ready_bitmap (bsc#1269981). - ice: stop destroying and reinitalizing Tx tracker during reset (bsc#1269981). - ieee802154: admin-gate legacy LLSEC dump operations (git-fixes). - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (git-fixes). - ieee802154: ca8210: fix cas_ctl leak on spi_async failure (git-fixes). - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (git-fixes). - ieee802154: fix kernel-infoleak in dgram_recvmsg() (git-fixes). - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (git-fixes). - iio: common: st_sensors: honour channel endianness in read_axis_data (git-fixes). - Input: atkbd - validate scancode in firmware keymap entries (git-fixes). - Input: elan_i2c - prevent division by zero and arithmetic underflow (git-fixes). - Input: goodix - clamp the device-reported contact count (git-fixes). - Input: iforce - bound the device-reported force-feedback effect index (git-fixes). - Input: ims-pcu - add response length checks (git-fixes). - Input: ims-pcu - fix DMA mapping violation in line setup (git-fixes). - Input: ims-pcu - fix firmware leak in async update (git-fixes). - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (git-fixes). - Input: ims-pcu - fix logic error in packet reset (git-fixes). - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (git-fixes). - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix race condition in reset_device sysfs callback (git-fixes). - Input: ims-pcu - fix type confusion in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix use-after-free and double-free in disconnect (git-fixes). - Input: ims-pcu - release data interface on disconnect (git-fixes). - Input: ims-pcu - validate control endpoint type (git-fixes). - Input: maple_keyb - set driver data before registering input device (stable-fixes). - Input: maplecontrol - set driver data before registering input device (stable-fixes). - Input: maplemouse - set driver data before registering input device (stable-fixes). - Input: rmi4 - fix bit count in bitmap_copy() (git-fixes). - Input: rmi4 - fix limit in rmi_register_desc_has_subpacket() (git-fixes). - Input: rmi4 - fix memory leak in rmi_set_attn_data() (git-fixes). - Input: rmi4 - fix num_subpackets overflow in register descriptor (git-fixes). - Input: rmi4 - fix register descriptor address calculation (git-fixes). - Input: rmi4 - fix type overflow in register counts (git-fixes). - Input: rmi4 - initialize attn_fifo properly (stable-fixes). - Input: rmi4 - iterative IRQ handler (git-fixes). - Input: rmi4 - refactor F12 probe function (stable-fixes). - Input: rmi4 - refactor register descriptor parsing (git-fixes). - Input: rmi4 - tolerate short register descriptor structure (git-fixes). - Input: rmi4 - use local presence map in rmi_read_register_desc() (stable-fixes). - Input: serio - define serio_pause_rx guard to pause and resume serio ports (stable-fixes). - Input: synaptics-rmi4 - add support for querying DPM value (F12) (stable-fixes). - Input: synaptics-rmi4 - fix crash when DPM query is not supported (git-fixes). - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (git-fixes). - Input: touchwin - reset the packet index on every complete packet (git-fixes). - intel_th: fix MSC output device reference leak (git-fixes). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (git-fixes). - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (git-fixes). - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes). - KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes). - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes). - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes). - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (git-fixes). - mac802154: hold an interface reference across the scan worker (git-fixes). - mac802154: llsec: reject frames shorter than the authentication tag (git-fixes). - media: airspy: Return queued buffers on start_streaming() failure (git-fixes). - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (git-fixes). - media: cedrus: clean up media device on probe failure (git-fixes). - media: cx231xx: fix devres lifetime (git-fixes). - media: cx23885: add ioremap return check and cleanup (git-fixes). - media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes). - media: msi2500: Return queued buffers on start_streaming() failure (git-fixes). - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes). - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes). - media: nxp: imx8-isi: Convert to platform remove callback returning void (stable-fixes). - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes). - media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes). - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes). - media: nxp: imx8-isi: Fix use-after-free on remove (git-fixes). - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (stable-fixes). - media: pwc: Drain fill_buf on start_streaming() failure (git-fixes). - media: pwc: Return queued buffers on start_streaming() failure (git-fixes). - media: qcom: venus: drop extra padding in NV12 raw size calculation (git-fixes). - media: qcom: venus: relax encoder frame/blur dimension steps on v4 (git-fixes). - media: qcom: venus: relax encoder frame/blur step size on v6 (git-fixes). - media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes). - media: rockchip: rga: fix too small buffer size (git-fixes). - media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes). - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes). - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes). - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (git-fixes). - media: stm32: dcmi: unregister notifier on probe failure (git-fixes). - media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes). - media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes). - media: uvcvideo: Avoid partial metadata buffers (git-fixes). - media: uvcvideo: Fix buffer sequence in frame gaps (git-fixes). - media: uvcvideo: Fix sequence number when no EOF (git-fixes). - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes). - media: vivid: add vivid_update_reduced_fps() (git-fixes). - media: vivid: check for vb2_is_busy() when toggling caps (git-fixes). - mei: bus: access mei_device under device_lock on cleanup (git-fixes). - memstick: ms_block: reject a card that reports too many blocks (git-fixes). - mfd: cros_ec: Delay dev_set_drvdata() until probe success (git-fixes). - mfd: sm501: Fix reference leak on failed device registration (git-fixes). - mfd: tps6586x: Fix OF node refcount (git-fixes). - mkspec-dtb: Skip missing DTBs. - mm: convert pagecache_isize_extended to use a folio (bsc#1272920). - mm: zero range of eof folio exposed by inode size extension (bsc#1272920). - mmc: vub300: defer reset until cmd_mutex is unlocked (git-fixes). - mtd: mchp23k256: use SPI match data for chip caps (git-fixes). - mtd: mtdswap: remove debugfs stats file on teardown (git-fixes). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes). - mtd: onenand: samsung: report DMA completion timeouts (git-fixes). - mtd: rawnand: Add a helper for calculating a page index (stable-fixes). - mtd: rawnand: Ensure all continuous terms are always in sync (git-fixes). - mtd: rawnand: fsl_ifc: return errors for failed page reads (git-fixes). - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (git-fixes). - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (git-fixes). - mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net/x25: fix use-after-free in x25_kill_by_neigh() (git-fixes). - net: mana: Add Interrupt Moderation support (bsc#1271368). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: thunderbolt: Fix frags overflow by bounding frame_count (git-fixes). - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (git-fixes). - net: usb: lan78xx: move functions to avoid forward definitions (stable-fixes). - net: wwan: t7xx: check skb_clone in control TX (git-fixes). - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (git-fixes). - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (git-fixes). - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (git-fixes). - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (git-fixes). - pinctrl-amd: Don't clear S4 wake bits at probe (git-fixes). - pinctrl: bm1880: add missing select GENERIC_PINCONF (git-fixes). - pinctrl: devicetree: don't free uninitialized dev_name on error path (git-fixes). - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (git-fixes). - pkspec-dtb: Fix dtb-al rename. - platform/x86/amd/pmc: Add delay_suspend module parameter (stable-fixes). - platform/x86/amd/pmc: Avoid logging "(null)" for DMI values (git-fixes). - platform/x86/amd/pmc: Check for intermediate wakeup in function (stable-fixes). - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (stable-fixes). - platform/x86/amd/pmc: Don't log during intermediate wakeups (stable-fixes). - platform/x86: dell-smbios: Move request functions for reuse (stable-fixes). - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - power: supply: bq25890: fix the -10 C NTC lookup entry (git-fixes). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (git-fixes). - remoteproc: qcom: Fix leak when custom dump_segments addition fails (git-fixes). - reset: sunxi: fix memory region leak on ioremap failure (git-fixes). - Revert "Input: rmi4 - fix register descriptor address calculation" (stable-fixes). - sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134). - sctp: validate embedded address parameter length (git-fixes). - selftests/alsa: Fix memory leak in find_controls error path (git-fixes). - serial: 8250_mid: Disable DMA for selected platforms (git-fixes). - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (git-fixes). - serial: 8250_mid: Remove 8250_pci usage (stable-fixes). - serial: sc16is7xx: implement gpio get_direction() callback (git-fixes). - slimbus: Convert to platform remove callback returning void (stable-fixes). - slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). - slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). - slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). - slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). - slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). - slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git-fixes). - slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git-fixes). - staging: media: atomisp: reduce load_primary_binaries() stack usage (git-fixes). - staging: rtl8723bs: core: move constants to right side in comparison (stable-fixes). - staging: rtl8723bs: fix inverted HT40 secondary channel offset (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). - usb: cdc_acm: Add quirk for Uniden BC125AT scanner (stable-fixes). - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (git-fixes). - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (stable-fixes). - usb: core: port: Deattach Type-C connector on component unbind (git-fixes). - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (git-fixes). - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (git-fixes). - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (git-fixes). - USB: gadget: fsl-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: function: rndis: add length check for header (stable-fixes). - usb: gadget: function: rndis: add length check to response query (stable-fixes). - usb: gadget: printer: fix infinite loop in printer_read() (git-fixes). - USB: gadget: snps-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (git-fixes). - usb: gadget: udc: Fix use-after-free in gadget_match_driver (stable-fixes). - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (git-fixes). - USB: iowarrior: fix use-after-free on disconnect race (git-fixes). - usb: iowarrior: remove inherent race with minor number (stable-fixes). - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (stable-fixes). - USB: serial: io_edgeport: cap received transmit credits (git-fixes). - USB: serial: io_ti: reject oversized boot-mode firmware (git-fixes). - USB: serial: keyspan_pda: fix data loss on receive throttling (git-fixes). - USB: serial: mxuport: validate firmware header size (git-fixes). - USB: serial: option: add Telit Cinterion FE990D50 compositions (stable-fixes). - wan: wanxl: Only reset hardware after BAR mapping (git-fixes). - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (git-fixes). - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (git-fixes). - wifi: ath6kl: fix OOB access from firmware ADDBA window size (git-fixes). - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (git-fixes). - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (git-fixes). - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (git-fixes). - wifi: ath10k: fix skb leak on incomplete msdu during rx pop (git-fixes). - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (git-fixes). - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (git-fixes). - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (git-fixes). - wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes). - wifi: brcmfmac: make release_scratchbuffers idempotent (git-fixes). - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (git-fixes). - wifi: carl9170: fix buffer overflow in rx_stream failover path (git-fixes). - wifi: carl9170: fix OOB read from off-by-two in TX status handler (git-fixes). - wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes). - wifi: cfg80211: cancel sched scan results work on unregister (git-fixes). - wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes). - wifi: cfg80211: validate PMSR FTM preamble range (git-fixes). - wifi: cfg80211: validate PMSR measurement type data (git-fixes). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes). - wifi: iwlwifi: mvm: fix flushing during quiet CSA (bsc#1272600). - wifi: iwlwifi: mvm: fix read in wake packet notification handler (git-fixes). - wifi: iwlwifi: mvm: validate SAR GEO response payload size (git-fixes). - wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes). - wifi: mac80211: fix memory leak in ieee80211_register_hw() (git-fixes). - wifi: mac80211: free ack status frame on TX header build failure (git-fixes). - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes). - wifi: mac80211: recalculate TIM when a station enters power save (git-fixes). - wifi: mac80211: tear down new links on vif update error path (git-fixes). - wifi: mac80211: validate individual TWT params before driver setup (git-fixes). - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (git-fixes). - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7915: guard HE capability lookups (git-fixes). - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (git-fixes). - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (git-fixes). - wifi: mwifiex: bound uAP association event IEs to the event buffer (git-fixes). - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (git-fixes). - wifi: mwifiex: fix permanently busy scans after multiple roam iterations (git-fixes). - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (git-fixes). - wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes). - wifi: nl80211: validate nested MBSSID IE blobs (git-fixes). - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes). - wifi: rt2x00: avoid full teardown before work setup in probe (git-fixes). - wifi: wilc1000: validate assoc response length before subtracting header (git-fixes).

Affected Systems

  • susekernel-rt&distro=SUSE Linux Micro 6.0

    < 6.4.0-51.1

  • susekernel-source-rt&distro=SUSE Linux Micro 6.0

    < 6.4.0-51.1

References (1312)