[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2024-12272 -- Oracle kernel-uek_bpftool

ID: oval:org.secpod.oval:def:1507450Date: (C)2024-04-12   (M)2024-04-12
Class: PATCHFamily: unix




[5.15.0-205.149.5.1.el9uek] - KVM: x86: Add BHI_NO [Orabug: 36384802] {CVE-2024-2201} - x86/bhi: Mitigate KVM by default [Orabug: 36384802] {CVE-2024-2201} - x86/bhi: Add BHI mitigation knob [Orabug: 36384802] {CVE-2024-2201} - x86/bhi: Enumerate Branch History Injection bug [Orabug: 36384802] {CVE-2024-2201} - x86/bhi: Define SPEC_CTRL_BHI_DIS_S [Orabug: 36384802] {CVE-2024-2201} - x86/bhi: Add support for clearing branch history at syscall entry [Orabug: 36384802] {CVE-2024-2201} - x86/cpufeature: Add missing leaf enumeration [Orabug: 36384802] {CVE-2024-2201} - KVM: x86: Use a switch statement and macros in __feature_translate [Orabug: 36384802] {CVE-2024-2201} - KVM: x86: Advertise CPUID.:EDX[5:0] to userspace [Orabug: 36384802] {CVE-2024-2201} - KVM: x86: Update KVM-only leaf handling to allow for 100% KVM-only leafs [Orabug: 36384802] {CVE-2024-2201} - x86/bugs: Use sysfs_emit [Orabug: 36384802] {CVE-2024-2201} - x86/cpu: Support AMD Automatic IBRS [Orabug: 36384802] {CVE-2024-2201} - Documentation/hw-vuln: Update spectre doc [Orabug: 36384802] {CVE-2024-2201} - x86/speculation: Reorder SRSO and GDS functions [Orabug: 36384802] {CVE-2024-2201} [5.15.0-205.149.5.el9uek] - uek-rpm: Bluefield 3: enable lockdown mode for secure boot [Orabug: 36318788] - Documentation/x86: Update split lock documentation [Orabug: 36298291] - x86/split_lock: Add sysctl to control the misery mode [Orabug: 36298291] - x86/split-lock: Remove unused TIF_SLD bit [Orabug: 36298291] - x86/split_lock: Make life miserable for split lockers [Orabug: 36298291] [5.15.0-205.149.4.el9uek] - Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST - netfilter: nf_tables: allow NFPROTO_INET in nft__validate - ksmbd: free aux buffer if ksmbd_iov_pin_rsp_read fails - afs: Fix endless loop in directory parsing - PCI: dwc: Fix a 64bit bug in dw_pcie_ep_raise_msix_irq - Revert quot;drm/bridge: lt8912b: Register and attach our DSI device at probequot; - net: usb: dm9601: fix wrong return value in dm9601_mdio_read - usb: dwc3: gadget: Don"t disconnect if not started - platform/x86: intel-vbtn: Stop calling quot;VBDLquot; from notify_handler - Fix null ptr in rds_tcp_recv_path [Orabug: 35587408] - cifs: fix mid leak during reconnection after timeout threshold [Orabug: 36123597] - vfio/mlx5: Activate the chunk mode functionality [Orabug: 36298327] - vfio/mlx5: Add support for READING in chunk mode [Orabug: 36298327] - vfio/mlx5: Add support for SAVING in chunk mode [Orabug: 36298327] - vfio/mlx5: Pre-allocate chunks for the STOP_COPY phase [Orabug: 36298327] - vfio/mlx5: Rename some stuff to match chunk mode [Orabug: 36298327] - vfio/mlx5: Enable querying state size which is gt; 4GB [Orabug: 36298327] - vfio/mlx5: Refactor the SAVE callback to activate a work only upon an error [Orabug: 36298327] - vfio/mlx5: Wake up the reader post of disabling the SAVING migration file [Orabug: 36298327] - net/mlx5: Introduce ifc bits for migration in a chunk mode [Orabug: 36298327] - af_unix: Drop oob_skb ref before purging queue in GC. [Orabug: 36375407] - hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed [Orabug: 36379479] [5.15.0-205.149.3.el9uek] - net/rds: print PPID/COMM of process doing user reset on RDS connection [Orabug: 36248460] - platform/mellanox: mlxbf-pmc: Fix offset calculation for crspace events [Orabug: 36299543] - platform/mellanox: mlxbf-tmfifo: Drop Tx network packet when Tx TmFIFO is full [Orabug: 36299543] - platform/mellanox: mlxbf-tmfifo: Remove unnecessary bool conversion [Orabug: 36299543] - power: reset: pwr-mlxbf: support graceful reboot instead of emergency reset [Orabug: 36299543] - platform/mellanox: tmfifo: fix kernel-doc warnings [Orabug: 36299543] - platform/mellanox: mlxbf-tmfifo: Convert to platform remove callback returning void [Orabug: 36299543] - platform/mellanox: mlxbf-pmc: Add support for BlueField-3 [Orabug: 36299543] - pwr-mlxbf: extend Kconfig to include gpio-mlxbf3 dependency [Orabug: 36299543] - pinctrl: mlxbf3: Remove gpio_disable_free [Orabug: 36299543] - gpio: mlxbf3: use capital quot;ORquot; for multiple licenses in SPDX [Orabug: 36299543] - pinctrl: use capital quot;ORquot; for multiple licenses in SPDX [Orabug: 36299543] - gpio: mlxbf3: Support add_pin_ranges [Orabug: 36299543] - uek: kabi: Add two new exported kABI symbols for ACFS and EDV [Orabug: 36303821] - uek-rpm: Update the aarch64 kABI files for new symbol [Orabug: 36323808] - arm64: Minimize tlb flush due to vttbr writes on AmpereOne [Orabug: 36349790] [5.15.0-205.149.2.el9uek] - LTS version: v5.15.149 - usb: dwc3: gadget: Ignore End Transfer delay on teardown - media: Revert quot;media: rkisp1: Drop IRQF_SHAREDquot; - usb: dwc3: gadget: Execute gadget stop after halting the controller - usb: dwc3: gadget: Don"t delay End Transfer on delayed_status - staging: fbtft: core: set smem_len before fb_deferred_io_init call - smb3: Replace smb2pdu 1-element arrays with flex-arrays - fs/ntfs3: Add null pointer checks - net: bcmgenet: Fix EEE implementation - drm/msm/dsi: Enable runtime PM - PM: runtime: Have devm_pm_runtime_enable handle pm_runtime_dont_use_autosuspend - dm: limit the number of targets and parameter size area - nilfs2: replace WARN_ONs for invalid DAT metadata block requests - nilfs2: fix potential bug in end_buffer_async_write - sched/membarrier: reduce the ability to hammer on sys_membarrier - netfilter: ipset: Missing gc cancellations fixed - net: prevent mss overflow in skb_segment - hrtimer: Ignore slack time for RT tasks in schedule_hrtimeout_range - netfilter: ipset: fix performance regression in swap operation - scripts/decode_stacktrace.sh: optionally use LLVM utilities - scripts: decode_stacktrace: demangle Rust symbols - scripts/decode_stacktrace.sh: support old bash version - fbdev: flush deferred IO before closing - fbdev: Fix incorrect page mapping clearance at fb_deferred_io_release - fbdev: Fix invalid page access after closing deferred I/O devices - fbdev: Rename pagelist to pagereflist for deferred I/O - fbdev: Track deferred-I/O pages in pageref struct - fbdev: defio: fix the pagelist corruption - fbdev: Don"t sort deferred-I/O pages by default - fbdev/defio: Early-out if page is already enlisted - serial: 8250_exar: Set missing rs485_supported flag - serial: 8250_exar: Fill in rs485_supported - usb: dwc3: gadget: Queue PM runtime idle on disconnect event - usb: dwc3: gadget: Handle EP0 request dequeuing properly - usb: dwc3: gadget: Refactor EP0 forced stall/restart into a separate API - usb: dwc3: gadget: Stall and restart EP0 if host is unresponsive - usb: dwc3: gadget: Submit endxfer command if delayed during disconnect - usb: dwc3: gadget: Force sending delayed status during soft disconnect - usb: dwc3: Fix ep0 handling when getting reset while doing control transfer - usb: dwc3: gadget: Delay issuing End Transfer - usb: dwc3: gadget: Only End Transfer for ep0 data phase - usb: dwc3: ep0: Don"t prepare beyond Setup stage - usb: dwc3: gadget: Wait for ep0 xfers to complete during dequeue - crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init - bus: moxtet: Add spi device table - dma-buf: add dma_fence_timestamp helper - af_unix: Fix task hung while purging oob_skb in GC. - tracing: Inform kmemleak of saved_cmdlines allocation - pmdomain: core: Move the unused cleanup to a _sync initcall - can: j1939: Fix UAF in j1939_sk_match_filter during setsockopt - can: j1939: prevent deadlock by changing j1939_socks_lock to rwlock - of: property: fix typo in io-channels - mm: hugetlb pages should not be reserved by shmat if SHM_NORESERVE - ceph: prevent use-after-free in encode_cap_msg - net: ethernet: ti: cpsw_new: enable mac_managed_pm to fix mdio - s390/qeth: Fix potential loss of L3-IP@ in case of network issues - net: ethernet: ti: cpsw: enable mac_managed_pm to fix mdio - irqchip/gic-v3-its: Fix GICv4.1 VPE affinity update - irqchip/irq-brcmstb-l2: Add write memory barrier before exit - wifi: mac80211: reload info pointer in ieee80211_tx_dequeue - nfp: flower: prevent re-adding mac index for bonded port - nfp: use correct macro for LengthSelect in BAR config - crypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked - nilfs2: fix hang in nilfs_lookup_dirty_data_buffers - nilfs2: fix data corruption in dsync block recovery for small block sizes - ALSA: hda/conexant: Add quirk for SWS JS201D - mmc: slot-gpio: Allow non-sleeping GPIO ro - x86/mm/ident_map: Use gbpages only where full GB page should be mapped. - x86/Kconfig: Transmeta Crusoe is CPU family 5, not 6 - powerpc/64: Set task pt_regs-gt;link to the LR value on scv entry - serial: max310x: fail probe if clock crystal is unstable - serial: max310x: improve crystal stable clock detection - serial: max310x: set default value when reading clock ready bit - ring-buffer: Clean ring_buffer_poll_wait error return - hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove - drm/prime: Support page array gt;= 4GB - media: rc: bpf attach/detach requires write permission - iio: accel: bma400: Fix a compilation problem - iio: core: fix memleak in iio_device_register_sysfs - iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC - staging: iio: ad5933: fix type mismatch regression - tracing: Fix wasted memory in saved_cmdlines logic - ext4: fix double-free of blocks due to wrong extents moved_len - misc: fastrpc: Mark all sessions as invalid in cb_remove - binder: signal epoll threads of self-work - ALSA: hda/cs8409: Suppress vmaster control for Dolphin models - ASoC: codecs: wcd938x: handle deferred probe - ALSA: hda/realtek: Enable headset mic on Vaio VJFE-ADL - xen-netback: properly sync TX responses - net: hsr: remove WARN_ONCE in send_hsr_supervision_frame - nfc: nci: free rx_data_reassembly skb on NCI device cleanup - kbuild: Fix changing ELF file type for output of gen_btf for big endian - firewire: core: correct documentation of fw_csr_string kernel API - lsm: fix the logic in security_inode_getsecctx - Revert quot;drm/amd: flush any delayed gfxoff on suspend entryquot; - scsi: Revert quot;scsi: fcoe: Fix potential deadlock on amp;fip-gt;ctlr_lockquot; - mptcp: fix data re-injection from stale subflow - modpost: trim leading spaces when processing source files list - i2c: i801: Fix block process call transactions - i2c: i801: Remove i801_set_block_buffer_mode - powerpc/kasan: Fix addr error caused by page alignment - media: ir_toy: fix a memleak in irtoy_tx - usb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend - usb: f_mass_storage: forbid async queue when shutdown happen - USB: hub: check for alternate port before enabling A_ALT_HNP_SUPPORT - usb: ucsi_acpi: Fix command completion handling - iio: hid-sensor-als: Return 0 for HID_USAGE_SENSOR_TIME_TIMESTAMP - HID: wacom: Do not register input devices until after hid_hw_start - HID: wacom: generic: Avoid reporting a serial of "0" to userspace - HID: i2c-hid-of: fix NULL-deref on failed power up - ALSA: hda/realtek: Enable Mute LED on HP Laptop 14-fq0xxx - ALSA: hda/realtek: Fix the external mic not being recognised for Acer Swift 1 SF114-32 - scsi: storvsc: Fix ring buffer size calculation - mm/writeback: fix possible divide-by-zero in wb_dirty_limits, again - tracing/trigger: Fix to return error if failed to alloc snapshot - scs: add CONFIG_MMU dependency for vfree_atomic - i40e: Fix waiting for queues of all VSIs to be disabled - MIPS: Add "memory" clobber to csum_ipv6_magic inline assembler path for statistics - ASoC: rt5645: Fix deadlock in rt5645_jack_detect_work - spi: ppc4xx: Drop write-only variable - net: openvswitch: limit the number of recursions from action sets - wifi: iwlwifi: Fix some error codes - of: unittest: Fix compile in the non-dynamic case - btrfs: send: return EOPNOTSUPP on unknown flags - btrfs: forbid deleting live subvol qgroup - btrfs: do not ASSERT if the newly created subvolume already got read - btrfs: forbid creating subvol qgroups - netfilter: nft_set_rbtree: skip end interval element from gc - net: stmmac: xgmac: fix a typo of register name in DPP safety handling - net: stmmac: xgmac: use #define for string constants - clocksource: Skip watchdog check for large watchdog intervals - Input: atkbd - skip ATKBD_CMD_SETLEDS when skipping ATKBD_CMD_GETID - Input: i8042 - fix strange behavior of touchpad on Clevo NS70PU - usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK - usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK - USB: serial: cp210x: add ID for IMST iM871A-USB - USB: serial: option: add Fibocom FM101-GL variant - USB: serial: qcserial: add new usb-id for Dell Wireless DW5826e - ALSA: usb-audio: Add a quirk for Yamaha YIT-W12TX transmitter - drivers: lkdtm: fix clang -Wformat warning - blk-iocost: Fix an UBSAN shift-out-of-bounds warning - scsi: core: Move scsi_host_busy out of host lock if it is for per-command - fs/ntfs3: Fix an NULL dereference bug - netfilter: nft_set_pipapo: remove scratch_aligned pointer - netfilter: nft_set_pipapo: add helper to release pcpu scratch area - netfilter: nft_set_pipapo: store index in scratch maps - netfilter: nft_ct: reject direction for ct id - drm/amd/display: Implement bounds check for stream encoder creation in DCN301 - drm/amd/display: Fix multiple memory leaks reported by coverity - netfilter: nft_compat: restrict match/target protocol to u16 - netfilter: nft_compat: reject unused compat flag - ppp_async: limit MRU to 64K - af_unix: Call kfree_skb for dead unix_-gt;oob_skb in GC. - tipc: Check the bearer type before calling tipc_udp_nl_bearer_add - rxrpc: Fix response to PING RESPONSE ACKs to a dead call - inet: read sk-gt;sk_family once in inet_recv_error - hwmon: Fix bogus core_id to attr name mapping - hwmon: Fix out-of-bounds memory access - hwmon: mutex for tach reading - octeontx2-pf: Fix a memleak otx2_sq_init - atm: idt77252: fix a memleak in open_card_ubr0 - tunnels: fix out of bounds access when building IPv6 PMTU error - selftests: net: avoid just another constant wait - selftests: net: cut more slack for gro fwd tests. - net: stmmac: xgmac: fix handling of DPP safety error for DMA channels - drm/msm/dp: return correct Colorimetry for DP_TEST_DYNAMIC_RANGE_CEA case - phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP - dmaengine: fix is_slave_direction return false when DMA_DEV_TO_DEV - phy: renesas: rcar-gen3-usb2: Fix returning wrong error code - dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA - dmaengine: fsl-qdma: Fix a memory leak related to the status queue DMA - dmaengine: ti: k3-udma: Report short packet errors - dmaengine: fsl-dpaa2-qdma: Fix the size of dma pools - ASoC: codecs: lpass-wsa-macro: fix compander volume hack - bonding: remove print in bond_verify_device_path - HID: apple: Add 2021 magic keyboard FN key mapping - HID: apple: Add support for the 2021 Magic Keyboard - gve: Fix use-after-free vulnerability - arm64: irq: set the correct node for shadow call stack path - selftests: net: fix available tunnels detection - af_unix: fix lockdep positive in sk_diag_dump_icons - net: ipv4: fix a memleak in ip_setup_cork - netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger - netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV - bridge: mcast: fix disabled snooping after long uptime - llc: call sock_orphan at release time - ipv6: Ensure natural alignment of const ipv6 loopback and router addresses - ixgbe: Fix an error handling path in ixgbe_read_iosf_sb_reg_x550 - ixgbe: Refactor overtemp event handling - ixgbe: Refactor returning internal error codes - ixgbe: Remove non-inclusive language - tcp: add sanity checks to rx zerocopy - ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv - ip6_tunnel: use dev_sw_netstats_rx_add - selftests: net: give more time for GRO aggregation - scsi: core: Move scsi_host_busy out of host lock for waking up EH handler - scsi: isci: Fix an error code problem in isci_io_request_build - drm: using mul_u32_u32 requires linux/math64.h - wifi: cfg80211: fix RCU dereference in __cfg80211_bss_update - perf: Fix the nr_addr_filters fix - drm/amdkfd: Fix "node" NULL check in "svm_range_get_range_boundaries" - drm/amdgpu: Release "adev-gt;pm.fw" before return in "amdgpu_device_need_post" - drm/amd/powerplay: Fix kzalloc parameter "ATOM_Tonga_PPM_Table" in "get_platform_power_management_table" - ceph: fix deadlock or deadcode of misusing dget - blk-mq: fix IO hang from sbitmap wakeup race - virtio_net: Fix quot;#8216;%d#8217; directive writing between 1 and 11 bytes into a region of size 10quot; warnings - drm/amdkfd: Fix lock dependency warning - libsubcmd: Fix memory leak in uniq - PCI/AER: Decode Requester ID when no error info found - PCI: Fix 64GT/s effective data rate calculation - fs/kernfs/dir: obey S_ISGID - tty: allow TIOCSLCKTRMIOS with CAP_CHECKPOINT_RESTORE - selftests/sgx: Fix linker script asserts - usb: hub: Replace hardcoded quirk value with BIT macro - perf cs-etm: Bump minimum OpenCSD version to ensure a bugfix is present - PCI: switchtec: Fix stdev_release crash after surprise hot remove - PCI: Only override AMD USB controller if required - mailbox: arm_mhuv2: Fix a bug for mhuv2_sender_interrupt - mfd: ti_am335x_tscadc: Fix TI SoC dependencies - xen/gntdev: Fix the abuse of underlying struct page in DMA-buf import - i3c: master: cdns: Update maximum prescaler value for i2c clock - um: time-travel: fix time corruption - um: net: Fix return type of uml_net_start_xmit - um: Don"t use vfprintf for os_info - um: Fix naming clash between UML and scheduler - leds: trigger: panic: Don"t register panic notifier if creating the trigger failed - ALSA: hda/conexant: Fix headset auto detect fail in cx8070 and SN6140 - drm/amdgpu: Drop "fence" check in "to_amdgpu_amdkfd_fence" - drm/amdgpu: Let KFD sync with VM fences - clk: imx: clk-imx8qxp: fix LVDS bypass, pixel and phy clocks - clk: imx: scu: Fix memory leak in __imx_clk_gpr_scu - watchdog: it87_wdt: Keep WDTCTRL bit 3 unmodified for IT8784/IT8786 - clk: mmp: pxa168: Fix memory leak in pxa168_clk_init - clk: hi3620: Fix memory leak in hi3620_mmc_clk_init - drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap - drm/msm/dpu: Ratelimit framedone timeout msgs - media: i2c: imx335: Fix hblank min/max values - media: ddbridge: fix an error code problem in ddb_probe - IB/ipoib: Fix mcast list locking - drm/exynos: Call drm_atomic_helper_shutdown at shutdown/unbind time - f2fs: fix to tag gcing flag on page during block migration - media: rkisp1: Drop IRQF_SHARED - ALSA: hda: intel-dspcfg: add filters for ARL-S and ARL - ALSA: hda: Intel: add HDA_ARL PCI ID support - PCI: add INTEL_HDA_ARL to pci_ids.h - media: rockchip: rga: fix swizzling for RGB formats - media: stk1160: Fixed high volume of stk1160_dbg messages - drm/mipi-dsi: Fix detach call without attach - drm/framebuffer: Fix use of uninitialized variable - drm/drm_file: fix use of uninitialized variable - f2fs: fix write pointers on zoned device after roll forward - drm/amd/display: Fix tiled display misalignment - RDMA/IPoIB: Fix error code return in ipoib_mcast_join - fast_dput: handle underflows gracefully - ASoC: doc: Fix undefined SND_SOC_DAPM_NOPM argument - ALSA: hda: Refer to correct stream index at loops - f2fs: fix to check return value of f2fs_reserve_new_block - octeontx2-af: Fix max NPC MCAM entry check while validating ref_entry - i40e: Fix VF disable behavior to block all traffic - bridge: cfm: fix enum typo in br_cc_ccm_tx_parse - Bluetooth: L2CAP: Fix possible multiple reject send - Bluetooth: qca: Set both WIDEBAND_SPEECH and LE_STATES quirks for QCA2066 - wifi: cfg80211: free beacon_ies when overridden from hidden BSS - wifi: rtlwifi: rtl8723{be,ae}: using calculate_bit_shift - ALSA: usb-audio: Add delay quirk for MOTU M Series 2nd revision - libbpf: Fix NULL pointer dereference in bpf_object__collect_prog_relos - wifi: rtl8xxxu: Add additional USB IDs for RTL8192EU devices - arm64: dts: qcom: msm8998: Fix "out-ports" is a required property - arm64: dts: qcom: msm8996: Fix "in-ports" is a required property - md: Whenassemble the array, consult the superblock of the freshest device - block: prevent an integer overflow in bvec_try_merge_hw_page - net: dsa: mv88e6xxx: Fix mv88e6352_serdes_get_stats error path - ARM: dts: imx23/28: Fix the DMA controller node name - ARM: dts: imx23-sansa: Use preferred i2c-gpios properties - ARM: dts: imx27-apf27dev: Fix LED name - ARM: dts: imx25/27: Pass timing0 - ARM: dts: imx25: Fix the iim compatible string - block/rnbd-srv: Check for unlikely string overflow - ionic: pass opcode to devcmd_wait - ARM: dts: imx1: Fix sram node - ARM: dts: imx27: Fix sram node - ARM: dts: imx: Use flash at 0 ,0 pattern - ARM: dts: imx25/27-eukrea: Fix RTC node name - ARM: dts: rockchip: fix rk3036 hdmi ports node - bpf: Set uattr-gt;batch.count as zero before batched update or deletion - scsi: libfc: Fix up timeout error in fc_fcp_rec_error - scsi: libfc: Don"t schedule abort twice - bpf: Add map and need_defer parameters to .map_fd_put_ptr - wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus - ARM: dts: imx7s: Fix nand-controller #size-cells - ARM: dts: imx7s: Fix lcdif compatible - ARM: dts: imx7d: Fix coresight funnel ports - scsi: arcmsr: Support new PCI device IDs 1883 and 1886 - bonding: return -ENOMEM instead of BUG in alb_upper_dev_walk - PCI: Add no PM reset quirk for NVIDIA Spectrum devices - scsi: lpfc: Fix possible file string name overflow when updating firmware - selftests/bpf: Fix issues in setup_classid_environment - selftests/bpf: Fix pyperf180 compilation failure with clang18 - selftests/bpf: satisfy compiler by having explicit return in btf test - wifi: rt2x00: restart beacon queue when hardware reset - ext4: avoid online resizing failures due to oversized flex bg - ext4: remove unnecessary check from alloc_flex_gd - ext4: unify the type of flexbg_size to unsigned int - ext4: fix inconsistent between segment fstrim and full fstrim - ecryptfs: Reject casefold directory inodes - SUNRPC: Fix a suspicious RCU usage warning - KVM: s390: fix setting of fpc register - s390/ptrace: handle setting of fpc register correctly - arch: consolidate arch_irq_work_raise prototypes - jfs: fix array-index-out-of-bounds in diNewExt - rxrpc_find_service_conn_rcu: fix the usage of read_seqbegin_or_lock - afs: fix the usage of read_seqbegin_or_lock in afs_find_server* - afs: fix the usage of read_seqbegin_or_lock in afs_lookup_volume_rcu - crypto: stm32/crc32 - fix parsing list of devices - crypto: octeontx2 - Fix cptvf driver cleanup - pstore/ram: Fix crash when setting number of cpus to an odd number - jfs: fix uaf in jfs_evict_inode - jfs: fix array-index-out-of-bounds in dbAdjTree - jfs: fix slab-out-of-bounds Read in dtSearch - UBSAN: array-index-out-of-bounds in dtSplitRoot - FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree - ACPI: APEI: set memory failure flags as MF_ACTION_REQUIRED on synchronous events - PM / devfreq: Synchronize devfreq_monitor_[start/stop] - ACPI: extlog: fix NULL pointer dereference check - PNP: ACPI: fix fortify warning - ACPI: video: Add quirk for the Colorful X15 AT 23 Laptop - audit: Send netlink ACK before setting connection in auditd_set - regulator: core: Only increment use_count when enable_count changes - debugobjects: Stop accessing objects after releasing hash bucket lock - perf/core: Fix narrow startup race when creating the perf nr_addr_filters sysfs file - x86/mce: Mark fatal MCE"s page as poison to avoid panic in the kdump kernel - powerpc/lib: Validate size for vector operations - powerpc: pmd_move_must_withdraw is only needed for CONFIG_TRANSPARENT_HUGEPAGE - x86/boot: Ignore NMIs during very early boot - powerpc/64s: Fix CONFIG_NUMA=n build due to create_section_mapping - powerpc/mm: Fix build failures due to arch_reserved_kernel_pages - powerpc: Fix build error due to is_valid_bugaddr - drivers/perf: pmuv3: don"t expose SW_INCR event in sysfs - arm64: irq: set the correct node for VMAP stack - powerpc/mm: Fix null-pointer dereference in pgtable_cache_add - x86/entry/ia32: Ensure s32 is sign extended to s64 - tick/sched: Preserve number of idle sleeps across CPU hotplug events - mips: Call lose_fpu before initializing fcr31 in mips_set_personality_nan - mtd: cfi: allow building spi-intel standalone - spi: bcm-qspi: fix SFDP BFPT read by usig mspi read - block: Move checking GENHD_FL_NO_PART to bdev_add_partition - gpio: eic-sprd: Clear interrupt after set the interrupt type - drm/exynos: gsc: minor fix for loop iteration in gsc_runtime_resume - drm/exynos: fix accidental on-stack copy of exynos_drm_plane - drm: panel-simple: add missing bus flags for Tianma tm070jvhg[30/33] - cpufreq: intel_pstate: Refine computation of P-state for given frequency - cpufreq: intel_pstate: Drop redundant intel_pstate_get_hwp_cap call - ksmbd: fix global oob in ksmbd_nl_policy - btrfs: add definition for EXTENT_TREE_V2 - PM / devfreq: Fix buffer overflow in trans_stat_show - mm/sparsemem: fix race in accessing memory_section-gt;usage - mm: use __pfn_to_section instead of open coding it - media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run - ARM: dts: qcom: sdx55: fix USB SS wakeup - ARM: dts: qcom: sdx55: fix USB DP/DM HS PHY interrupts - ARM: dts: qcom: sdx55: fix pdc "#interrupt-cells" - ARM: dts: samsung: exynos4210-i9100: Unconditionally enable LDO12 - ARM: dts: qcom: sdx55: fix USB wakeup interrupt types - pipe: wakeup wr_wait after setting max_usage - fs/pipe: move check to pipe_has_watch_queue - bus: mhi: host: Add alignment check for event ring read pointer - bus: mhi: host: Rename quot;struct mhi_trequot; to quot;struct mhi_ring_elementquot; - PM: sleep: Fix possible deadlocks in core system-wide PM code - PM: core: Remove unnecessary conversions - drm/bridge: nxp-ptn3460: simplify some error checking - drm/tidss: Fix atomic_flush check - drm/bridge: nxp-ptn3460: fix i2c_master_send error checking - drm: Don"t unref the same fb many times by mistake due to deadlock handling - gpiolib: acpi: Ignore touchpad wakeup on GPD G1619-04 - xfs: read only mounts with fsopen mount API are busted - firmware: arm_scmi: Check mailbox/SMT channel for consistency - netfilter: nf_tables: reject QUEUE/DROP verdict parameters - netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain - hv_netvsc: Calculate correct ring size when PAGE_SIZE is not 4 Kbytes - wifi: iwlwifi: fix a memory corruption - exec: Fix error handling in begin_new_exec - rbd: don"t move requests to the running list on errors - btrfs: don"t abort filesystem when attempting to snapshot deleted subvolume - btrfs: defrag: reject unknown flags of btrfs_ioctl_defrag_range_args - btrfs: don"t warn if discard range is not aligned to sector - btrfs: tree-checker: fix inline ref size in error messages - btrfs: ref-verify: free ref cache before clearing mount opt - btrfs: avoid copying BTRFS_ROOT_SUBVOL_DEAD flag to snapshot of subvolume being deleted - btrfs: fix race between reading a directory and adding entries to it - btrfs: refresh dir last index during a rewinddir call - btrfs: set last dir index to the current last index when opening dir - btrfs: fix infinite directory reads - net: fec: fix the unhandled context fault from smmu - fjes: fix memleaks in fjes_hw_setup - selftests: netdevsim: fix the udp_tunnel_nic test - net: mvpp2: clear BM pool before initialization - net: stmmac: Wait a bit for the reset to take effect - netfilter: nf_tables: validate NFPROTO_* family - netfilter: nf_tables: restrict anonymous set and map names to 16 bytes - netfilter: nft_limit: reject configurations that cause integer overflow - overflow: Allow mixed type arguments - net/mlx5e: fix a potential double-free in fs_any_create_groups - net/mlx5e: fix a double-free in arfs_create_groups - net/mlx5: DR, Can"t go to uplink vport on RX rule - net/mlx5: DR, Use the right GVMI number for drop action - ipv6: init the accept_queue"s spinlocks in inet6_create - netlink: fix potential sleeping issue in mqueue_flush_file - tcp: Add memory barrier to tcp_push - afs: Hide silly-rename files from userspace - tracing: Ensure visibility when inserting an element into tracing_map - net/rds: Fix UBSAN: array-index-out-of-bounds in rds_cmsg_recv - llc: Drop support for ETH_P_TR_802_2. - llc: make llc_ui_sendmsg more robust against bonding changes - vlan: skip nested type that is not IFLA_VLAN_QOS_MAPPING - bnxt_en: Wait for FLR to complete during probe - tcp: make sure init the accept_queue"s spinlocks once - net/smc: fix illegal rmb_desc access in SMC-D connection dump - ksmbd: Add missing set_freezable for freezable kthread - ksmbd: send lease break notification on FILE_RENAME_INFORMATION - ksmbd: don"t increment epoch if current state and request state are same - ksmbd: fix potential circular locking issue in smb2_set_ea - ksmbd: set v2 lease version on lease upgrade - rename: fix the locking of subdirectories - ubifs: ubifs_symlink: Fix memleak of inode-gt;i_link in error path - nouveau/vmm: don"t set addr on the fail path to avoid warning - rtc: Adjust failure return code for cmos_set_alarm - mmc: mmc_spi: remove custom DMA mapped buffers - mmc: core: Use mrq.sbc in close-ended ffu - scripts/get_abi: fix source path leak - lsm: new security_file_ioctl_compat hook - arm64: dts: qcom: sdm845: fix USB DP/DM HS PHY interrupts - arm64: dts: qcom: sm8150: fix USB wakeup interrupt types - arm64: dts: qcom: sdm845: fix USB wakeup interrupt types - arm64: dts: qcom: sc7180: fix USB wakeup interrupt types - async: Introduce async_schedule_dev_nocall - async: Split async_schedule_node_domain - parisc/firmware: Fix F-extend for PDC addresses - bus: mhi: host: Add spinlock to protect WP access when queueing TREs - bus: mhi: host: Drop chan lock before queuing buffers - mips: Fix max_mapnr being uninitialized on early stages - media: ov9734: Enable runtime PM before registering async sub-device - rpmsg: virtio: Free driver_override when rpmsg_remove - media: imx355: Enable runtime PM before registering async sub-device - crypto: s390/aes - Fix buffer overread in CTR mode - hwrng: core - Fix page fault dead lock on mmap-ed hwrng - PM: hibernate: Enforce ordering during image compression/decompression - crypto: api - Disallow identical driver names - btrfs: sysfs: validate scrub_speed_max value - ext4: allow for the last group to be marked as trimmed - iio:adc:ad7091r: Move exports into IIO_AD7091R namespace. - scsi: ufs: core: Remove the ufshcd_hba_exit call from ufshcd_async_scan - scsi: ufs: core: Simplify power management during async scan - dmaengine: fix NULL pointer in channel unregistration function - iio: adc: ad7091r: Enable internal vref if external vref is not supplied - iio: adc: ad7091r: Allow users to configure device events - iio: adc: ad7091r: Set alert bit in config register - ksmbd: only v2 leases handle the directory - ksmbd: fix UAF issue in ksmbd_tcp_new_connection - ksmbd: validate mech token in session setup - ksmbd: don"t allow O_TRUNC open on read-only share - ksmbd: free ppace array on error in parse_dacl - LTS version: v5.15.148 - Revert quot;Revert quot;md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5dquot;quot; - arm64: dts: armada-3720-turris-mox: set irq type for RTC - netfilter: nft_quota: copy content when cloning expression - netfilter: nft_last: copy content when cloning expression - netfilter: nft_limit: Clone packet limits" cost value - netfilter: nft_limit: fix stateful object memory leak - netfilter: nft_connlimit: memleak if nf_ct_netns_get fails - netfilter: nf_tables: typo NULL check in _clone function - block: Remove special-casing of compound pages - i2c: s3c24xx: fix transferring more than one message in polling mode - i2c: s3c24xx: fix read transfers in polling mode - ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work - selftests: mlxsw: qos_pfc: Adjust the test to support 8 lanes - mlxsw: spectrum_acl_tcam: Fix stack corruption - mlxsw: spectrum_acl_erp: Fix error flow of pool allocation failure - ethtool: netlink: Add missing ethnl_ops_begin/complete - kdb: Fix a potential buffer overflow in kdb_local - ipvs: avoid stat macros calls from preemptible context - netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description - netfilter: nf_tables: skip dead set elements in netlink dump - netfilter: nf_tables: do not allow mismatch field size and set key length - netfilter: nft_limit: do not ignore unsupported flags - netfilter: nf_tables: memcg accounting for dynamically allocated objects - netfilter: nft_limit: move stateful fields out of expression data - netfilter: nft_limit: rename stateful structure - netfilter: nft_quota: move stateful fields out of expression data - netfilter: nft_last: move stateful fields out of expression data - netfilter: nft_connlimit: move stateful fields out of expression data - netfilter: nf_tables: reject invalid set policy - net: dsa: vsc73xx: Add null pointer check to vsc73xx_gpio_probe - bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS - net: stmmac: ethtool: Fixed calltrace caused by unbalanced disable_irq_wake calls - net: ravb: Fix dma_addr_t truncation in error case - mptcp: use OPTION_MPTCP_MPJ_SYN in subflow_check_req - mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect - mptcp: strict validation before using mp_opt-gt;hmac - mptcp: drop unused sk in mptcp_get_options - mptcp: mptcp_parse_option fix for MPTCPOPT_MP_JOIN - net: phy: micrel: populate .soft_reset for KSZ9131 - net: ethernet: ti: am65-cpsw: Fix max mtu to fit ethernet frames - net: qualcomm: rmnet: fix global oob in rmnet_policy - s390/pci: fix max size calculation in zpci_memcpy_toio - PCI: keystone: Fix race condition when initializing PHYs - nvmet-tcp: Fix the H2C expected PDU len calculation - nvmet: re-fix tracing strncpy warning - serial: imx: Correct clock error message in function probe - usb: xhci-mtk: fix a short packet issue of gen1 isoc-in transfer - apparmor: avoid crash when parsed profile name is empty - perf env: Avoid recursively taking env-gt;bpf_progs.lock - nvmet-tcp: fix a crash in nvmet_req_complete - nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length - usb: cdc-acm: return correct error code on unsupported break - tty: use "if" in send_break instead of "goto" - tty: don"t check for signal_pending in send_break - tty: early return from send_break on TTY_DRIVER_HARDWARE_BREAK - tty: change tty_write_lock"s ndelay parameter to bool - perf genelf: Set ELF program header addresses properly - iio: adc: ad9467: fix scale setting - iio: adc: ad9467: don"t ignore error codes - iio: adc: ad9467: fix reset gpio handling - iio: adc: ad9467: Benefit from devm_clk_get_enabled to simplify - selftests/sgx: Skip non X86_64 platform - selftests/sgx: Fix uninitialized pointer dereference in error path - serial: imx: fix tx statemachine deadlock - software node: Let args be NULL in software_node_get_reference_args - libapi: Add missing linux/types.h header to get the __u64 type on io.h - serial: 8250: omap: Don"t skip resource freeing if pm_runtime_resume_and_get failed - power: supply: bq256xx: fix some problem in bq256xx_hw_init - power: supply: cw2015: correct time_to_empty units in sysfs - MIPS: Alchemy: Fix an out-of-bound access in db1550_dev_setup - MIPS: Alchemy: Fix an out-of-bound access in db1200_dev_setup - riscv: Fix module_alloc that did not reset the linear mapping permissions - riscv: Check if the code to patch lies in the exit section - mips: Fix incorrect max_low_pfn adjustment - mips: dmi: Fix early remap on MIPS32 - mfd: intel-lpss: Fix the fractional clock divider flags - leds: aw2013: Select missing dependency REGMAP_I2C - mfd: syscon: Fix null pointer dereference in of_syscon_register - ARM: 9330/1: davinci: also select PINCTRL - iommu/dma: Trace bounce buffer usage when mapping buffers - serial: sc16is7xx: set safe default SPI clock frequency - serial: sc16is7xx: add check for unsupported SPI modes during probe - HID: wacom: Correct behavior when processing some confidence == false touches - iio: adc: ad7091r: Pass iio_dev to event handler - KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache - KVM: arm64: vgic-v4: Restore pending state on host userspace write - x86/kvm: Do not try to disable kvmclock if it was not enabled - PCI: mediatek: Clear interrupt status before dispatching handler - PCI: dwc: endpoint: Fix dw_pcie_ep_raise_msix_irq alignment support - wifi: mwifiex: configure BSSID consistently when starting AP - wifi: rtlwifi: Convert LNKCTL change to PCIe cap RMW accessors - wifi: rtlwifi: Remove bogus and dangerous ASPM disable/enable code - wifi: mt76: fix broken precal loading from MTD for mt7915 - iommu/arm-smmu-qcom: Add missing GMU entry to match table - bpf: Fix re-attachment branch in bpf_tracing_prog_attach - Bluetooth: Fix atomicity violation in {min,max}_key_size_set - rootfs: Fix support for rootfstype= when root= is given - io_uring/rw: ensure io-gt;bytes_done is always initialized - pwm: jz4740: Don"t use dev_err_probe in .request - block: add check that partition length needs to be aligned with block size - scsi: mpi3mr: Refresh sdev queue depth after controller reset - fbdev: flush deferred work in fb_deferred_io_fsync - ALSA: hda/relatek: Enable Mute LED on HP Laptop 15s-fq2xxx - ALSA: oxygen: Fix right channel of capture volume mixer - serial: imx: Ensure that imx_uart_rs485_config is called with enabled clock - usb: mon: Fix atomicity violation in mon_bin_vma_fault - usb: typec: class: fix typec_altmode_put_partner to put plugs - Revert quot;usb: typec: class: fix typec_altmode_put_partner to put plugsquot; - usb: cdns3: Fix uvc fail when DMA cross 4k boundery since sg enabled - usb: cdns3: fix iso transfer error when mult is not zero - usb: cdns3: fix uvc failure work since sg support enabled - usb: chipidea: wait controller resume finished for wakeup irq - Revert quot;usb: dwc3: don"t reset device side if dwc3 was configured as host-onlyquot; - Revert quot;usb: dwc3: Soft reset phy on probe for hostquot; - usb: dwc: ep0: Update request status in dwc3_ep0_stall_restart - usb: phy: mxs: remove CONFIG_USB_OTG condition for mxs_phy_is_otg_host - tick-sched: Fix idle and iowait sleeptime accounting vs CPU hotplug - binder: fix race between mmput and do_exit - xen-netback: don"t produce zero-size SKB frags - virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session - dma-mapping: Fix build error unused-value - Input: atkbd - use ab83 as id when skipping the getid command - binder: fix unused alloc-gt;free_async_space - binder: fix async space check for 0-sized buffers - selftests/bpf: Add assert for user stacks in test_task_stack - of: unittest: Fix of_count_phandle_with_args expected value message - of: Fix double free in of_parse_phandle_with_args_map - ksmbd: validate the zero field of packet header - drm/amd/pm/smu7: fix a memleak in smu7_hwmgr_backend_init - IB/iser: Prevent invalidating wrong MR - mmc: sdhci_omap: Fix TI SoC dependencies - mmc: sdhci_am654: Fix TI SoC dependencies - ALSA: scarlett2: Add clamp in scarlett2_mixer_ctl_put - ALSA: scarlett2: Add missing error checks to *_ctl_get - ALSA: scarlett2: Allow passing any output to line_out_remap - ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config - ALSA: scarlett2: Add missing error check to scarlett2_config_save - ASoC: rt5645: Drop double EF20 entry from dmi_platform_data[] - pwm: stm32: Fix enable count for clk in .probe - pwm: stm32: Use hweight32 in stm32_pwm_detect_channels - pwm: stm32: Use regmap_clear_bits and regmap_set_bits where applicable - clk: fixed-rate: fix clk_hw_register_fixed_rate_with_accuracy_parent_hw - clk: fixed-rate: add devm_clk_hw_register_fixed_rate - clk: asm9260: use parent index to link the reference clock - clk: si5341: fix an error code problem in si5341_output_clk_set_rate - watchdog: rti_wdt: Drop runtime pm reference count when watchdog is unused - watchdog: bcm2835_wdt: Fix WDIOC_SETTIMEOUT handling - watchdog/hpwdt: Only claim UNKNOWN NMI if from iLO - watchdog: set cdev owner before adding - drivers: clk: zynqmp: update divider round rate logic - clk: zynqmp: Add a check for NULL pointer - clk: zynqmp: make bestdiv unsigned - drivers: clk: zynqmp: calculate closest mux rate - clk: qcom: videocc-sm8150: Add missing PLL config property - clk: qcom: videocc-sm8150: Update the videocc resets - dt-bindings: clock: Update the videocc resets for sm8150 - gpu/drm/radeon: fix two memleaks in radeon_vm_init - drivers/amd/pm: fix a use-after-free in kv_parse_power_table - drm/amd/pm: fix a double-free in si_dpm_init - drm/amdgpu/debugfs: fix error code when smc register accessors are NULL - media: dvb-frontends: m88ds3103: Fix a memory leak in an error handling path of m88ds3103_probe - media: dvbdev: drop refcount on error path in dvb_device_open - f2fs: fix the f2fs_file_write_iter tracepoint - f2fs: fix to update iostat correctly in f2fs_filemap_fault - f2fs: fix to check compress file in f2fs_move_file_range - media: rkisp1: Disable runtime PM in probe error path - clk: qcom: gpucc-sm8150: Update the gpu_cc_pll1 config - media: cx231xx: fix a memleak in cx231xx_init_isoc - drm/bridge: tc358767: Fix return value on error case - drm/bridge: cdns-mhdp8546: Fix use of uninitialized variable - drm/radeon/trinity_dpm: fix a memleak in trinity_parse_power_table - drm/radeon/dpm: fix a memleak in sumo_parse_power_table - drm/radeon: check the alloc_workqueue return value in radeon_crtc_init - drm/drv: propagate errors from drm_modeset_register_all - drm/msm/dsi: Use pm_runtime_resume_and_get to prevent refcnt leaks - drm/msm/mdp4: flush vblank event on disable - ASoC: cs35l34: Fix GPIO name and drop legacy include - ASoC: cs35l33: Fix GPIO name and drop legacy include - drm/radeon: check return value of radeon_ring_lock - drm/radeon/r100: Fix integer overflow issues in r100_cs_track_check - drm/radeon/r600_cs: Fix possible int overflows in r600_cs_check_reg - f2fs: fix to avoid dirent corruption - drm/bridge: Fix typo in post_disable description - media: pvrusb2: fix use after free on context disconnection - drm/tilcdc: Fix irq free on unload - drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function - drm/nouveau/fence:: fix warning directly dereferencing a rcu pointer - drm/panel-elida-kd35t133: hold panel in reset for unprepare - RDMA/hns: Fix inappropriate err code for unsupported operations - RDMA/usnic: Silence uninitialized symbol smatch warnings - Revert quot;drm/omapdrm: Annotate dma-fence critical section in commit pathquot; - Revert quot;drm/tidss: Annotate dma-fence critical section in commit pathquot; - ARM: davinci: always select CONFIG_CPU_ARM926T - ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim - mlxbf_gige: Enable the GigE port in mlxbf_gige_open - mlxbf_gige: Fix intermittent no ip issue - net/sched: act_ct: fix skb leak and crash on ooo frags - null_blk: don"t cap max_hw_sectors to BLK_DEF_MAX_SECTORS - block: make BLK_DEF_MAX_SECTORS unsigned - Bluetooth: btmtkuart: fix recv_buf return value - Bluetooth: Fix bogus check for re-auth no supported with non-ssp - netfilter: nf_tables: mark newset as dead on transaction abort - wifi: iwlwifi: mvm: send TX path flush in rfkill - wifi: iwlwifi: mvm: set siso/mimo chains to 1 in FW SMPS request - wifi: rtlwifi: rtl8192se: using calculate_bit_shift - wifi: rtlwifi: rtl8192ee: using calculate_bit_shift - wifi: rtlwifi: rtl8192de: using calculate_bit_shift - wifi: rtlwifi: rtl8192ce: using calculate_bit_shift - wifi: rtlwifi: rtl8192cu: using calculate_bit_shift - wifi: rtlwifi: rtl8192c: using calculate_bit_shift - wifi: rtlwifi: rtl8188ee: phy: using calculate_bit_shift - wifi: rtlwifi: add calculate_bit_shift - arm64: dts: qcom: sc7280: Mark SDHCI hosts as cache-coherent - block: add check of "minors" and "first_minor" in device_add_disk - arm64: dts: qcom: sm8150-hdk: fix SS USB regulators - soc: qcom: llcc: Fix dis_cap_alloc and retain_on_pc configuration - dma-mapping: clear dev-gt;dma_mem to NULL after freeing it - dma-mapping: Add dma_release_coherent_memory to DMA API - virtio/vsock: fix logic which reduces credit update messages - selftests/net: fix grep checking for fib_nexthop_multiprefix - scsi: hisi_sas: Correct the number of global debugfs registers - scsi: hisi_sas: Rollback some operations if FLR failed - scsi: hisi_sas: Replace with standard error code return value - scsi: hisi_sas: Prevent parallel FLR and controller reset - scsi: hisi_sas: Rename HISI_SAS_{RESET -gt; RESETTING}_BIT - block: Set memalloc_noio to false on device_add_disk error path - bpf: Fix verification of indirect var-off stack access - arm64: dts: qcom: sc7280: fix usb_2 wakeup interrupt types - arm64: dts: qcom: sdm845-db845c: correct LED panic indicator - arm64: dts: qcom: qrb5165-rb5: correct LED panic indicator - scsi: fnic: Return error if vmalloc failed - bpf: fix check for attempt to corrupt spilled pointer - arm64: dts: qcom: sm8250: Make watchdog bark interrupt edge triggered - arm64: dts: qcom: sm8150: Make watchdog bark interrupt edge triggered - arm64: dts: qcom: sdm845: Make watchdog bark interrupt edge triggered - arm64: dts: qcom: sc7280: Make watchdog bark interrupt edge triggered - arm64: dts: qcom: sc7180: Make watchdog bark interrupt edge triggered - ARM: dts: qcom: sdx65: correct SPMI node name - bpf: enforce precision of R0 on callback return - arm64: dts: ti: k3-am65-main: Fix DSS irq trigger type - wifi: rtlwifi: rtl8821ae: phy: fix an undefined bitwise shift behavior - firmware: meson_sm: populate platform devices from sm device tree data - firmware: ti_sci: Fix an off-by-one in ti_sci_debugfs_create - net/ncsi: Fix netlink major/minor version numbers - ARM: dts: qcom: apq8064: correct XOADC register address - wifi: libertas: stop selecting wext - wifi: ath11k: Defer on rproc_get failure - bpf: Add crosstask check to __bpf_get_stack - bpf, lpm: Fix check prefixlen before walking trie - wifi: rtw88: fix RX filter in FIF_ALLMULTI flag - NFSv4.1/pnfs: Ensure we handle the error NFS4ERR_RETURNCONFLICT - blocklayoutdriver: Fix reference leak of pnfs_device_node - crypto: scomp - fix req-gt;dst buffer overflow - crypto: sahara - do not resize req-gt;src when doing hash operations - crypto: sahara - fix processing hash requests with req-gt;nbytes lt; sg-gt;length - crypto: sahara - improve error handling in sahara_sha_process - crypto: sahara - fix wait_for_completion_timeout error handling - crypto: sahara - fix ahash reqsize - crypto: sahara - handle zero-length aes requests - crypto: sahara - avoid skcipher fallback code duplication - crypto: virtio - Wait for tasklet to complete on device remove - gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump - fs: indicate request originates from old mount API - pstore: ram_core: fix possible overflow in persistent_ram_init_ecc - crypto: sahara - fix error handling in sahara_hw_descriptor_create - crypto: sahara - fix processing requests with cryptlen lt; sg-gt;length - crypto: sahara - fix ahash selftest failure - crypto: sahara - fix cbc selftest failure - crypto: sahara - remove FLAGS_NEW_KEY logic - crypto: af_alg - Disallow multiple in-flight AIO requests - crypto: ccp - fix memleak in ccp_init_dm_workarea - crypto: sa2ul - Return crypto_aead_setkey to transfer the error - crypto: virtio - Handle dataq logic with tasklet - selinux: Fix error priority for bind with AF_UNSPEC on PF_INET6 socket - mtd: Fix gluebi NULL pointer dereference caused by ftl notifier - kunit: debugfs: Fix unchecked dereference in debugfs_print_results - ACPI: extlog: Clear Extended Error Log status when RAS_CEC handled the error - ACPI: LPSS: Fix the fractional clock divider flags - spi: sh-msiof: Enforce fixed DTDL for R-Car H3 - efivarfs: force RO when remounting if SetVariable is not supported - calipso: fix memory leak in netlbl_calipso_add_pass - cpufreq: scmi: process the result of devm_of_clk_add_hw_provider - cpufreq: Use of_property_present for testing DT property presence - of: Add of_property_present helper - of: property: define of_property_read_u{8,16,32,64}_array unconditionally - ACPI: LPIT: Avoid u32 multiplication overflow - ACPI: video: check for error while searching for backlight device parent - mtd: rawnand: Increment IFC_TIMEOUT_MSECS for nand controller response - spi: spi-zynqmp-gqspi: fix driver kconfig dependencies - powerpc/imc-pmu: Add a null pointer check in update_events_in_group - powerpc/powernv: Add a null pointer check in opal_powercap_init - powerpc/powernv: Add a null pointer check in opal_event_init - powerpc/powernv: Add a null pointer check to scom_debug_init_one - selftests/powerpc: Fix error handling in FPU/VMX preemption tests - powerpc/pseries/memhp: Fix access beyond end of drmem array - powerpc/44x: select I2C for CURRITUCK - powerpc: add crtsavres.o to always-y instead of extra-y - powerpc: remove checks for binutils older than 2.25 - powerpc/toc: Future proof kernel toc - powerpc: Mark .opd section read-only - EDAC/thunderx: Fix possible out-of-bounds string access - x86/lib: Fix overflow when counting digits - coresight: etm4x: Fix width of CCITMIN field - PCI: Add ACS quirk for more Zhaoxin Root Ports - leds: ledtrig-tty: Free allocated ttyname buffer on deactivate - parport: parport_serial: Add Brainboxes device IDs and geometry - parport: parport_serial: Add Brainboxes BAR details - uio: Fix use-after-free in uio_open - binder: fix comment on binder_alloc_new_buf return value - binder: fix trivial typo of binder_free_buf_locked - binder: fix use-after-free in shinker"s callback - binder: use EPOLLERR from eventpoll.h - kprobes: Fix to handle forcibly unoptimized kprobes on freeing_list - bpf: Add --skip_encoding_btf_inconsistent_proto, --btf_gen_optimized to pahole flags for v1.25 - Revert quot;ASoC: atmel: Remove system clock tree configuration for at91sam9g20ekquot; - ACPI: resource: Add another DMI match for the TongFang GMxXGxx - drm/crtc: fix uninitialized variable use - ARM: sun9i: smp: fix return code check of of_property_match_string - net: qrtr: ns: Return 0 if server port is not present - ida: Fix crash in ida_free when the bitmap is empty - i2c: rk3x: fix potential spinlock recursion on poll - ASoC: Intel: bytcr_rt5640: Add quirk for the Medion Lifetab S10346 - Input: xpad - add Razer Wolverine V2 support - wifi: iwlwifi: pcie: avoid a NULL pointer dereference - ARC: fix spare error - s390/scm: fix virtual vs physical address confusion - Input: i8042 - add nomux quirk for Acer P459-G2-M - Input: atkbd - skip ATKBD_CMD_GETID in translated mode - reset: hisilicon: hi6220: fix Wvoid-pointer-to-enum-cast warning - ring-buffer: Do not record in NMI if the arch does not support cmpxchg in NMI - tracing: Fix uaf issue when open the hist or hist_debug file - MIPS: dts: loongson: drop incorrect dwmac fallback compatible - stmmac: dwmac-loongson: drop useless check for compatible fallback - tracing: Add size check when printing trace_marker output - tracing: Have large events show up as "[LINE TOO BIG]" instead of nothing - jbd2: fix soft lockup in journal_finish_inode_data_buffers - platform/x86: intel-vbtn: Fix missing tablet-mode-switch events - neighbour: Don"t let neigh_forced_gc disable preemption for long - drm/crtc: Fix uninit-value bug in drm_mode_setcrtc - jbd2: correct the printing of write_flags in jbd2_write_superblock - clk: rockchip: rk3128: Fix HCLK_OTG gate register - hwmon: Fix probe when built-in - drm/exynos: fix a wrong error checking - drm/exynos: fix a potential error pointer dereference - drm/amdgpu: Add NULL checks for function pointers - nvme: introduce helper function to get ctrl state - ASoC: ops: add correct range check for limiting volume - ASoC: da7219: Support low DC impedance headset - net/tg3: fix race condition in tg3_reset_task - nouveau/tu102: flush all pdbs on vmm flush - ASoC: rt5650: add mutex to avoid the jack detection failure - ASoC: cs43130: Fix incorrect frame delay configuration - ASoC: cs43130: Fix the position of const qualifier - ASoC: Intel: Skylake: mem leak in skl register function - ASoC: nau8822: Fix incorrect type in assignment and cast to restricted __be16 - ASoC: Intel: Skylake: Fix mem leak in few functions - ASoC: wm8974: Correct boost mixer inputs - nvme-core: check for too small lba shift - drm/amdgpu: Fix cat debugfs amdgpu_regs_didt causes kernel null pointer - debugfs: fix automount d_fsdata usage - wifi: cfg80211: lock wiphy mutex for rfkill poll - mptcp: fix uninit-value in mptcp_incoming_options - ALSA: hda - Fix speaker and headset mic pin config for CHUWI CoreBook XPro - pinctrl: lochnagar: Don"t build on MIPS - f2fs: explicitly null-terminate the xattr list [5.15.0-205.147.1.el9uek] - mm: avoid conflict between MADV_DOEXEC and upstream advice values [Orabug: 36334308]

Platform:
Oracle Linux 9
Product:
kernel-uek
bpftool
Reference:
ELSA-2024-12272
CVE-2024-2201

© SecPod Technologies