← Back to archive

Daily update · Oct 8–9, 2026

Linux mainline update: WireGuard handshake fix, ASUS Wi-Fi power restored, ext4 data=journal deprecated

A networking-heavy day in mainline: the kernel stops sending uninitialized bytes onto the wire, MediaTek Wi-Fi gets a batch of fixes, Raspberry Pi Ethernet crashes are patched, and Intel SR-IOV bonding sheds a 10-second stall.

In brief

Today's mainline pull is dominated by networking fixes spanning the core stack, tunnels, wireless, and a wide range of NIC drivers. On the security side, the network stack no longer transmits stale buffer memory in ICMP replies and TX bounce buffers, IPv4 now validates checksum metadata before completing checksums, an unterminated net/sched algorithm name can no longer leak kernel stack bytes into module-loading command lines, and Xen netfront drops malformed backend packets instead of crashing. WireGuard received a fix for a handshake race that could resurrect superseded session state, and a bareudp GSO bug that throttled IPv6-over-bareudp from roughly 700 Mbit/s to 10 Mbit/s was corrected. MediaTek Wi-Fi hardware picked up multiple-link stability fixes, restoration of correct TX power on ASUS MT7922/MT7925 laptops, and a fix that lets mt7925 associate to normal networks after leaving a multi-link one. Raspberry Pi hardware benefits from Cadence MACB corruption fixes that could kill a Pi CM5 within seconds under pktgen and a bcmgenet fix that permanently disabled TX after Wake-on-LAN suspend/resume. Intel users get faster SR-IOV bonding setup on i40e/ice, an iavf MAC-change deadlock fix, and an e1000e quirk that eliminated 40% packet loss on an affected system. Azure VMs on MANA regain wire-speed forwarding, and ext4's data=journal mode is now formally deprecated with removal planned for January 2028.

Security and hardening

Network stack no longer transmits stale buffer memory

When skb_copy_and_csum_bits() hit unreadable frags it copied only the linear part and left the rest of the caller's buffer untouched, so uninitialized bytes could go out on the wire in ICMP error messages or driver TX bounce buffers. The unfilled portion is now zeroed.

Why it matters: Prevents uninitialized kernel memory from leaking onto the network via ICMP replies and transmit paths.

ab9414ed70bd

IPv4 validates checksum metadata before completing checksums

A packet with bad checksum metadata entering the IPv4 stack could cause skb_checksum_help to corrupt the network header. The stack now checks checksum_start before completing the checksum, as defence in depth until fuller input validation lands.

Why it matters: Hardens the kernel against packets with crafted checksum metadata, for example injected via tun or packet sockets, that could otherwise corrupt headers.

6785011f8b16

net/sched em_text no longer leaks stack bytes into module loader

em_text_change() passed a 16-byte algo array with no enforced NUL terminator to textsearch_prepare(), which on a TS_AUTOLOAD retry called request_module() with vsnprintf walking past the array into adjacent struct fields, feeding those bytes to the usermode helper command line.

Why it matters: A malicious netlink message could previously leak kernel stack contents into module-loading command lines.

c9728fcf2e7f

Xen netfront hardened against malformed backend packets

Backend-controlled RX slot lengths shorter than an Ethernet header triggered a BUG() or an out-of-bounds read in eth_type_trans(); short packets are now dropped. A related fix frees the skb when a response chain overflows the frags array, which previously leaked the skb and its pages.

Why it matters: Xen guest kernels no longer crash or leak memory when a buggy or malicious backend sends malformed or oversized packet chains.

089e58805c4593ccaf1c26e2

Networking core

IPv4 TCP SYN processing use-after-free fixed

tcp_v4_syn_recv_sock() transferred ireq_opt ownership to the child socket without copying, but a concurrent retransmitted SYN could read the same pointer under RCU only. The fix defers freeing via call_rcu.

Why it matters: High-connection-rate TCP servers could hit use-after-free races during SYN processing.

e3f33b0a1d89

TCP zerocopy receive NULL pointer dereference on net_iov fragments

tcp_zerocopy_receive() could pass a net_iov fragment to can_map_frag(), which dereferenced a NULL page pointer from skb_frag_page(), causing a kernel panic.

Why it matters: TCP zerocopy receive on connections with dmabuf-backed pages could crash the kernel.

8b1f0af1fd5f

Open vSwitch soft lockup and panic during netlink flow dump

ovs_flow_cmd_dump() released stats->lock with spin_unlock_bh() once per CPU, each time running pending softirq backlog. On a busy CPU the backlog refilled as fast as it drained, so the dumping thread never slept and hit a soft lockup.

Why it matters: Dumping OVS flow tables on busy production hosts could lock up and panic the kernel.

aaaaf87ea99b

Bonding XDP program reference leak on replacement or removal

When an XDP program was replaced or removed on a bonding interface, the old BPF program reference was not released, causing leaked programs to accumulate.

Why it matters: Repeatedly changing XDP programs on bond interfaces leaked memory and BPF program references.

184b5ddf82d4

Flow dissector u16 truncation caused bogus transport header offsets

The flow dissector truncated skb->len to u16 when computing the transport header offset, so packets larger than 65535 bytes got bogus small thoff values, pointing transport headers inside Ethernet headers.

Why it matters: Large packets, such as AF_PACKET with VNET_HDR and TSO frames, could be misclassified or mishandled by traffic classification, GSO validation, and other flow-dissection users.

99bda1ecbd56f202578efc73

IPv4 NULL derefs in PMTU and FIB dump under nexthop group replacement

Multiple IPv4 code paths independently loaded nh->nh_grp without ensuring consistency, so if a nexthop group was replaced with fewer paths between loads, fib_info_nhc() returned NULL and was dereferenced.

Why it matters: Concurrent nexthop group replacement operations could crash the kernel during PMTU updates, FIB dumps, or route notification sizing.

6619e01855e64f4afc07dcb2d3daa33c7af9

Tunnels and VPN

WireGuard handshake race fixed

Two threads processing a duplicate handshake response, interleaved with a subsequently queued initiation, could copy superseded handshake state back to the peer and start a new session from it. Response consumption after an intermediate initiation is now rejected.

Why it matters: WireGuard tunnel setup is now reliable under retransmitted or concurrently processed handshake messages.

d0305f8d9002

bareudp GSO segmentation failure throttled IPv6 tunneling

bareudp did not correctly set the inner protocol for GSO segmentation, causing software segmentation to fail and drop packets, degrading IPv6-over-bareudp throughput from roughly 700 Mbit/s to about 10 Mbit/s.

Why it matters: Users tunneling traffic over bareudp, especially IPv6, saw dramatic throughput loss and thousands of retransmissions.

c57b2e60d4bf

ip6_gre ERSPAN PMTU path crashable by unprivileged users

A legacy PMTU update in ip6erspan_tunnel_xmit() treated a metadata dst from tc tunnel_key as a route; since it had no output device, dst_dev(dst)->mtu dereferenced NULL and panicked the kernel.

Why it matters: A crash could be triggered from an unprivileged user in a network namespace using tc tunnel_key and mirred to redirect to an ip6erspan device.

8bc60db48e8c

Wi-Fi

mt76 multi-link (MLO) stability fixes for MediaTek hardware

mt7996 did not set the CONNECTION_MONITOR flag, so mac80211's legacy beacon monitor ran alongside the driver's own and removed associations still carrying traffic. Separately, for MLO peers, hardware completions arriving on a different link than the queuing link let the non-AQL packet counter drift upward until it blocked the station entirely.

Why it matters: Multi-link Wi-Fi on MediaTek hardware no longer randomly drops associations while traffic flows on other links, and MLO stations no longer eventually stop transmitting.

0ec14f8c8c5d752770d7a58c

ASUS firmware SAR tables no longer clamp MediaTek TX power to minimum

Some ASUS firmware carries 0xff in ACPI SAR power slots, which the driver narrowed to s8 (-1), letting it win the min() against regulatory limits and cap every TX rate. SAR tables were also parsed with a version byte from a different ACPI table, dropping 6 GHz limits.

Why it matters: ASUS laptops with MT7922/MT7925 Wi-Fi, such as the Zenbook 14 and Vivobook S 14, suffered severely reduced TX power and throughput.

45f53d98cbaaaf97bf5a7e72

mt7925 legacy association failure after MLO teardown

Removing the last link of an MLD interface left stale firmware BSS/DEV entries with per-link MAC addresses, causing every subsequent legacy association to fail authentication until the interface was removed or the module reloaded.

Why it matters: MediaTek mt7925 users who disconnect from a multi-link network could not connect to any normal non-MLO network without reloading the driver.

8f9e5807671e

brcmfmac P2P device double-removal crash on driver detach

When the driver was removed while wpa_supplicant was still exiting, the P2P device interface was removed twice, causing a kernel crash due to a race between brcmf_detach() and the userspace DEL_INTERFACE path.

Why it matters: Broadcom brcmfmac Wi-Fi users could hit kernel crashes when removing the driver while wpa_supplicant was still running.

08a3f02fea63

Bluetooth

SCO connection use-after-free on receive path

sco_recv_scodata() could obtain a reference to an sco_conn that was concurrently freed, because the back-pointer was cleared without holding the device lock. This triggered KASAN slab-use-after-free reports.

Why it matters: Bluetooth SCO audio connections could crash the kernel under connection teardown races.

816fb1590a4c

RFCOMM fixes: skb leak, deadlock, and NULL dereference

Three RFCOMM bugs were fixed: an skb leak when a DLC has no owner, a circular lock dependency between rfcomm_mutex and hdev->lock during connect, and a NULL tty_dev dereference in rfcomm_dev_shutdown when tty registration fails.

Why it matters: Bluetooth serial (RFCOMM) connections are more stable and no longer leak memory, deadlock, or crash under edge cases.

9d1afbf60ed5ac022970e9fb08e90633377f

HCI socket race crash on controller unregistration

Rebinding an HCI socket after its controller was unregistered could race with monitor control replay, causing a NULL pointer dereference or use-after-free in create_monitor_ctrl_open().

Why it matters: Hot-removing Bluetooth controllers while sockets are active no longer crashes the kernel.

381a0925c556

CAN bus

CAN RX skb header regression caused kernel panic via SOCK_PACKET

A regression left CAN RX skbs with an uninitialized mac_header sentinel, causing packet_rcv_spkt() to overflow its push-length calculation and trigger a full kernel panic.

Why it matters: Using legacy SOCK_PACKET sockets with CAN interfaces could panic the machine.

0a04c0cb860628bc1ef69961

CAN unique skb identifier regression dropped legitimate frames under RPS

With RPS enabled, the flow dissector assigned every CAN frame the same non-zero hash, causing raw_rcv() to mistake legitimate frames for duplicates and drop them. The CAN UID now lives in a dedicated skb extension.

Why it matters: CAN frames could be silently dropped on multi-CPU systems with RPS, breaking CAN communication.

7093c3b8314a

Intel wired networking

i40e and ice skip unnecessary VF reset when changing trust setting

Changing VF trust unconditionally triggered a VF reset, causing a roughly 10-second delay during bonding setup. The reset is now skipped when granting trust, and only performed on revocation when advanced features are configured.

Why it matters: Bonding setup on Intel i40e/ice SR-IOV VFs becomes significantly faster, avoiding roughly 10-second stalls.

74bbbc9359a50a01e1df137f

iavf MAC address change deadlock with netdev instance lock

After the netdev instance lock was held during sysfs operations, iavf_set_mac() deadlocked because the watchdog and adminq tasks also needed the same lock. The MAC change request is now sent synchronously instead of being queued.

Why it matters: Changing the MAC address on Intel iavf (VF) interfaces no longer deadlocks the system.

436729a56dd4

e1000e disables K1 power saving on system with 40% packet loss

A specific system experienced 40% packet loss due to K1 power saving re-enablement; adding it to the disable list resolves the issue.

Why it matters: Users of the affected system with Intel e1000e networking regain normal LAN reliability.

1d6500523b8d

Ethernet and NIC drivers

bnxt_en DMA mapping overrun on small padded packets

Packets smaller than 52 bytes, such as untagged ARP frames, were padded but the DMA mapping length was not increased, causing DMA read faults on page boundaries, especially on VLAN/macvlan interfaces with Intel IOMMU.

Why it matters: Broadcom NetXtreme-E NICs could experience TX queue timeouts and DMA faults when sending small packets like ARP on VLAN interfaces.

a51d233ccd48

bnxt_en driver init fixed in kdump kernels behind PCIe switches

When the NIC is behind a PCIe switch in smart mode, the switch may need to see BARs initialized before passing memory read/write TLPs, causing fatal AER errors during kdump kernel initialization.

Why it matters: Systems with Broadcom bnxt_en NICs behind certain PCIe switches could fail to initialize networking in kdump/crashdump kernels, hampering network-based crash recovery.

386f887c8290

mlx5e completion-queue doorbell ordering fixed

The driver updated the ICOSQ consumer counter before the CQ doorbell record, violating an ordering requirement that can cause a CQ overrun. The doorbell is now updated first, with a dma_wmb() before the consumer counter.

Why it matters: Prevents rare completion-queue overruns that can disrupt receive processing on Mellanox/NVIDIA ConnectX NICs.

b056ca4d3742

stmmac 802.1ad (QinQ) VLAN stripping fixed

vlan_rx_hw() hardcoded ETH_P_8021Q instead of using the actual packet protocol, causing QinQ packets to be misidentified. Separately, rx-vlan-stag-hw-parse was advertised as enabled even when VLAN stripping was disabled.

Why it matters: QinQ networking on stmmac-based interfaces now works correctly, and ethtool feature reporting is accurate.

da17990421d7c63ce7b9c7e7

Cadence MACB crash and corruption fixes (hits Raspberry Pi CM5)

The driver modified skbs before checking TX ring space, so a NETDEV_TX_BUSY requeue could handle an already-freed or grown skb; it also appended the FCS in place to shared skbs, making pktgen clone_skb traffic hit a BQL BUG_ON that killed a Raspberry Pi CM5 within seconds. The ring is now checked first and shared skbs are copied.

Why it matters: Fixes crashes and memory corruption on systems using Cadence GEM/MACB Ethernet, including the Raspberry Pi CM5 via RP1.

6b48ed85ae0c9151d6c42799

bcmgenet TX permanently disabled after WoL suspend/resume

When the PHY link was down and UMAC was held in reset with WoL enabled, the resume sequence left UMAC_TX never enabled again on link up, permanently disabling transmission.

Why it matters: Raspberry Pi and other bcmgenet users could lose TX capability entirely after suspend/resume when WoL was enabled with the link down.

5857e5a196b0

ASIX ax88179/178A USB Ethernet delivered frames with extra trailing bytes

A previous fix replaced skb_clone() with a copy that included a 2-byte IP alignment pseudo header, delivering non-last packets in bulk transfers with two extra trailing bytes, breaking MACsec and other length-sensitive protocols.

Why it matters: USB Ethernet adapters using the ASIX ax88179/178A chipset could deliver frames with incorrect lengths, breaking MACsec.

9b6c20f78847

Virtualization and cloud

Azure MANA forwarding slowdown fixed

A memory-efficiency change handed out RX buffers with zero headroom, so every forwarded packet failed the skb_cow() check in ip_forward() and had to be reallocated and copied by pskb_expand_head(). RX buffers now reserve the needed headroom.

Why it matters: Restores wire-speed forwarding performance for virtual machines using Microsoft's MANA network interfaces on Azure.

259c4a519100

virtio_net GSO packets always dissected for correct validation

A check added to avoid false positives in GSO validation inadvertently bypassed flow dissection for GSO packets from tun, virtio_net, and raw sockets because skb->network_header was zero-initialized, causing VLAN-tagged GSO packets to be rejected or mishandled.

Why it matters: Virtualization and tunneling users could experience dropped or missegmented GSO packets, especially with VLAN tagging.

44378d02c5aa

vsock/virtio rx_bytes underflow broke stream reads

After a partial stream receive, virtio_transport_read_skb() passed the full packet length instead of the unread suffix, underflowing rx_bytes and causing SIOCINQ to report negative values, empty recv to return ELOOP, and poll to report empty sockets as readable.

Why it matters: vsock stream users could see broken receive behavior after partial reads, with data appearing unavailable or poll reporting readiness incorrectly.

a463f55c791b

Filesystems

ext4 data=journal mode marked deprecated

ext4's data=journal mount option, which journals file data as well as metadata, is now formally deprecated, with documentation noting it will be removed in January 2028.

Why it matters: Users or distros relying on full data journaling in ext4 need to plan a migration to another mode or filesystem before the removal date.

3e78d7b06323

Source commits130 entries +
74bbbc9359a5

i40e: skip unnecessary VF reset when setting trust

Jose Ignacio Tornos Martinez · Apr 28, 2026 · 1 files

05165f7b3b9a

Revert "wifi: ath12k: add panic handler"

Yingying Tang · Jun 12, 2026 · 4 files

0a01e1df137f

ice: skip unnecessary VF reset when setting trust

Jose Ignacio Tornos Martinez · Jun 15, 2026 · 1 files

436729a56dd4

iavf: send MAC change request synchronously

Jose Ignacio Tornos Martinez · Jun 22, 2026 · 3 files

ff9b465ddb95

wifi: nxpwifi: protect sta_list against concurrent add and delete

Linmao Li · Aug 7, 2026 · 2 files

128411832c62

wifi: nxpwifi: delete the station entry on the uAP deauth event

Linmao Li · Aug 7, 2026 · 1 files

916c484d29d8

wifi: mt76: mt7915: disable rx napi when removing device

Nicolas Cavallari · Aug 10, 2026 · 1 files

5c9260d7c699

wifi: nxpwifi: wait for the wakeup timer before the adapter is freed

Linmao Li · Aug 13, 2026 · 1 files

d68d6d8d8bbb

wifi: nxpwifi: free the aggregation buffer when the RA list disappears

Linmao Li · Aug 13, 2026 · 1 files

050f03bb0eff

wifi: nxpwifi: zero the channel statistics array

Linmao Li · Aug 13, 2026 · 2 files

f5e0b20f6c6d

wifi: mt76: mt7996: program a link again if the driver holds it

Felix Fietkau · Aug 18, 2026 · 1 files

0ec14f8c8c5d

wifi: mt76: mt7996: take over connection monitoring

Felix Fietkau · Aug 18, 2026 · 1 files

752770d7a58c

wifi: mt76: account non-AQL frames per peer rather than per link

Felix Fietkau · Aug 18, 2026 · 2 files

7769bb2457fc

wifi: nxpwifi: fix the authentication frame length handling

Linmao Li · Aug 20, 2026 · 1 files

7fa5fb9976c4

wifi: nxpwifi: handle authentication frame allocation failures

Linmao Li · Aug 20, 2026 · 1 files

9c9e4e4c8b45

wifi: mt76: mt7996: fix struct mt7996_mcu_wed_rro_ba_delete_event layout

Tao Gong · Aug 23, 2026 · 1 files

7f85d1170575

usb: f81604: fix struct f81604_int_data size mismatch

Ji-Ze Hong (Peter Hong) · Aug 24, 2026 · 1 files

32d1a000e996

wifi: nxpwifi: fix inverted check in Tx BA stream entry deletion

David Carlier · Aug 25, 2026 · 1 files

5e99bdb94720

wifi: nxpwifi: do not delete Rx reorder entries under RCU

David Carlier · Aug 25, 2026 · 1 files

8f9e5807671e

wifi: mt76: mt7925: restore the legacy BSS after MLO teardown

Aaron Ma · Aug 26, 2026 · 1 files

7c2e6b43c308

wifi: mt76: use ALTX queue for packets to disassociated stations

Felix Fietkau · Sep 1, 2026 · 3 files

456de496b53a

wifi: mt76: mt7603: initialize global station WCID

Cristian Papa · Sep 4, 2026 · 1 files

af97bf5a7e72

wifi: mt76: mt792x: pick the SAR table layout from the table itself

Devin Wittmayer · Sep 5, 2026 · 2 files

45f53d98cbaa

wifi: mt76: mt792x: treat 0xff ACPI SAR entries as no limit

Junjie Cao · Sep 10, 2026 · 1 files

5796b2bf9ff7

wifi: mt76: mt7925: don't put the band auto marker in TGID

Devin Wittmayer · Sep 11, 2026 · 1 files

9d1afbf60ed5

Bluetooth: RFCOMM: free the skb when the DLC has no owner

Maxim Skokov · Sep 15, 2026 · 1 files

0a04c0cb8606

can: dev: init_can_skb(): restore skb header initialization

zjamg · Sep 17, 2026 · 1 files

4b1d04693e5e

MAINTAINERS: name the ext4 dev branch

Matthias Goergens · Sep 23, 2026 · 1 files

08a3f02fea63

wifi: brcmfmac: fix P2P device removal race in brcmf_detach()

Michele Dionisio · Sep 24, 2026 · 1 files

3e78d7b06323

ext4: mark data=journal as deprecated and will be removed in January 2028.

Theodore Ts'o · Sep 24, 2026 · 2 files

86ef0f58bdec

Bluetooth: MGMT: Fix status of pending commands flushed on power off

Iaroslav Voitovych · Sep 24, 2026 · 1 files

af0524bf4ce1

ibmveth: h_free logical LAN on open-fail after register

Mingming Cao · Sep 25, 2026 · 1 files

84bec0bf0352

ibmveth: fix TX LTB and filter unwind on open-fail

Mingming Cao · Sep 25, 2026 · 1 files

5158353121ba

net: bridge: avoid recursive multicast port cleanup

Zixuan Chai · Sep 26, 2026 · 1 files

816fb1590a4c

Bluetooth: SCO: serialise sco_conn lifetime against sco_recv_scodata()

Aldo Ariel Panzardo · Sep 26, 2026 · 1 files

0843b2389064

lib/dim: fix 32-bit overflow in dim_calc_stats() rates

Shashank Mohan Jain · Sep 27, 2026 · 1 files

636035157a81

lib/dim: add KUnit test for dim_calc_stats()

Shashank Mohan Jain · Sep 27, 2026 · 3 files

3acdd44385bc

tipc: destroy topsrv workqueues before closing connections

Yuqi Xu · Sep 28, 2026 · 1 files

28bc1ef69961

net/packet: guard the ll header push in packet_rcv_spkt()

Quchaosheng · Sep 28, 2026 · 1 files

17e73bae400f

tipc: hold a reference to nodes found by link name

Chengfeng Ye · Sep 28, 2026 · 1 files

bcf2573a68a8

net: xilinx: axienet: Free outstanding DMA buffers on dmaengine stop

Suraj Gupta · Sep 28, 2026 · 2 files

afae89de73dd

amt: send the relay's General Query directly from the receive path

Omar Ramadan · Sep 28, 2026 · 2 files

c41817fcaf39

selftests: net: amt: check that the relay's queries bypass the amt device

Omar Ramadan · Sep 28, 2026 · 1 files

11705541e7d4

net: stmmac: Remove VLAN perfect matching dead code

Ovidiu Panait · Sep 28, 2026 · 3 files

69aa9e76677c

net: stmmac: Stop toggling the EDVLP bit

Ovidiu Panait · Sep 28, 2026 · 1 files

354b07bc1dca

net: stmmac: Rename double VLAN references to svlan

Ovidiu Panait · Sep 28, 2026 · 5 files

c63ce7b9c7e7

net: stmmac: Do not advertise S-VLAN stripping when it is disabled

Ovidiu Panait · Sep 28, 2026 · 1 files

da17990421d7

net: stmmac: Disable S-Tag processing on dwmac4

Ovidiu Panait · Sep 28, 2026 · 1 files

1402fc67d2f4

ice: fix use-after-free in dynamic port cleanup

Xuanqiang Luo · Sep 28, 2026 · 1 files

7a579dec8423

ice: Restore Ordered MMIO Writes for Tx Doorbells

Bryan Fraschetti · Sep 28, 2026 · 1 files

58858b8f1480

ice: fix metadata_dst refcount handling on representor teardown

Tristan Madani · Sep 28, 2026 · 1 files

1465494e8d07

Bluetooth: btintel_pcie: Add shared HW reset for clean start

Sai Teja Aluvala · Sep 29, 2026 · 1 files

baa53af641c9

Bluetooth: btintel_pcie: fix TX descriptor bounds check

Ravindra · Sep 29, 2026 · 1 files

aaaaf87ea99b

openvswitch: fix soft lockup in the netlink flow dump

Denis V. Lunev · Sep 29, 2026 · 1 files

ac022970e9fb

Bluetooth: RFCOMM: connect the session socket without rfcomm_mutex

Mikhail Gavrilov · Sep 29, 2026 · 2 files

232d49dd4b40

net: stmmac: propagate PTP addend and system time programming errors

Lorenzo Bianconi · Sep 29, 2026 · 2 files

4c9dc0faca98

cxgb4/ch_ktls: disable softirqs around tid_list erases

Sang-Hoon Choi · Sep 29, 2026 · 1 files

71a77ab76e74

net: allwinner: remove dmaengine_desc_free()

Frank Li · Sep 29, 2026 · 1 files

538b529509c7

sctp: copy zeroed stats to user in sctp_getsockopt_pr_streamstatus() when !streamoute

Hui Peng · Sep 30, 2026 · 1 files

7e170da2edec

net: airoha: Add retry mechanism to airoha_qdma_set_trtcm_param()

Leto Liu (刘涛) · Sep 30, 2026 · 2 files

c9728fcf2e7f

net/sched: em_text: reject unterminated algo before autoload

Jamal Hadi Salim · Sep 30, 2026 · 1 files

25016fe8c1ed

Bluetooth: btintel_pcie: use managed IRQ teardown

Runyu Xiao · Sep 30, 2026 · 1 files

52f6a065e081

wifi: mt76: mt7996: fix uninitialized buf read in mt7996_variant_fem_init()

Lu Huang · Sep 30, 2026 · 1 files

8b1f0af1fd5f

tcp: reject net_iov in zerocopy receive mapping hints

Daehyeon Ko · Sep 30, 2026 · 1 files

23609bce9e1d

pfcp: make sure the SEID is linear before reading it

Haishuang Yan · Sep 30, 2026 · 1 files

fe4114221364

net/mlx5: Lag, split aggregate speed into oper and max helpers

Or Har-Toov · Sep 30, 2026 · 1 files

73670ddb91a4

gve: fix XSK buffer leak when rings are stopped

Joshua Washington · Sep 30, 2026 · 1 files

9fed6a8ab8a5

gve: fix XSK buffer leak on error descriptor

Joshua Washington · Sep 30, 2026 · 1 files

0cb6939a4dfe

gve: fix napi_disable deadlock when attempting to disable XSK pools

Joshua Washington · Sep 30, 2026 · 1 files

5857e5a196b0

net: bcmgenet: if UMAC was suspended in SW_RESET, restore it to SW_RESET

Justin Chen · Sep 30, 2026 · 1 files

d333c8bca6dc

net: make dev_xdp_sb_prog_count() see programs attached through a link

Jakub Kicinski · Oct 1, 2026 · 1 files

184b5ddf82d4

bonding: fix the program leak when XDP is replaced

Jakub Kicinski · Oct 1, 2026 · 1 files

c5381ae1cd14

devlink: fix devlink_rel reference leak when notify work is pending

Haishuang Yan · Oct 1, 2026 · 1 files

7093c3b8314a

can: fix unique skb identifier regression under RPS

Oliver Hartkopp · Oct 1, 2026 · 8 files

a463f55c791b

vsock/virtio: account only unread bytes in read_skb()

Daehyeon Ko · Oct 1, 2026 · 1 files

b72e025ac556

net/sched: cls_route: reject change with no routing attribute

Victor Nogueira · Oct 1, 2026 · 1 files

6fa2e7db99fb

selftests: tc-testing: add cls_route no-routing-attribute change tests

Victor Nogueira · Oct 1, 2026 · 1 files

b7454f1940c5

net: team: stop reusing skb after queue override

Weiming Shi · Oct 1, 2026 · 1 files

489114c9ecae

net: team: free skb when broadcast has no txable port

Weiming Shi · Oct 1, 2026 · 1 files

99bda1ecbd56

flow_dissector: avoid u16 truncation of skb->len when computing thoff

Eric Dumazet · Oct 1, 2026 · 1 files

44378d02c5aa

net: always dissect GSO packets in __virtio_net_hdr_to_skb()

Eric Dumazet · Oct 1, 2026 · 4 files

ee2d4c2d7cc1

selftests: net: tun: add test for VLAN-tagged GSO without NEEDS_CSUM

Eric Dumazet · Oct 1, 2026 · 1 files

e3f33b0a1d89

ipv4: free inet_opt and ireq_opt after an RCU grace period

Eric Dumazet · Oct 1, 2026 · 2 files

1d6500523b8d

e1000e: add system to disable K1 list

Tony Nguyen · Oct 1, 2026 · 1 files

8bc60db48e8c

ip6_gre: remove obsolete ERSPAN PMTU update

Daehyeon Ko · Oct 2, 2026 · 1 files

6619e01855e6

ipv4: stop PMTU walk when nexthop group shrinks

Daehyeon Ko · Oct 2, 2026 · 1 files

4f4afc07dcb2

ipv4: stop exception dump when nexthop group shrinks

Daehyeon Ko · Oct 2, 2026 · 1 files

d3daa33c7af9

ipv4: stop route notification sizing when nexthop group shrinks

Daehyeon Ko · Oct 2, 2026 · 1 files

08e90633377f

Bluetooth: RFCOMM: Fix NULL tty_dev dereference in rfcomm_dev_shutdown

Palla Raghunath · Oct 2, 2026 · 1 files

9b6c20f78847

net: usb: ax88179_178a: fix rx frame length for non-last packets

Fredrik Nyberg · Oct 2, 2026 · 1 files

c57b2e60d4bf

bareudp: set the inner protocol to the protocol of the packet

Haishuang Yan · Oct 2, 2026 · 1 files

259c4a519100

net: mana: reserve RX buffer headroom to fix forwarding performance

Hamza Mahfooz · Oct 3, 2026 · 4 files

86b785b18f8f

Revert "net/mlx5: E-Switch, preserve max tx speed on vport state modification"

Or Har-Toov · Oct 4, 2026 · 2 files

381a0925c556

Bluetooth: hci_sock: Serialize dead-device detachment

Chengfeng Ye · Oct 4, 2026 · 1 files

555ff78fa719

Bluetooth: ISO: Reject concurrent BIS listener setup

Chengfeng Ye · Oct 4, 2026 · 1 files

9af12272061d

Bluetooth: hci_sync: Fix command skb lifetime during scan setup

Chengfeng Ye · Oct 4, 2026 · 2 files

ca5012757bf0

net: sparx5: start the TOD counters on non-PTP lan969x variants

Quentin Freimanis · Oct 5, 2026 · 1 files

e32d80293a0e

Bluetooth: ISO: Serialize concurrent connect calls

Chengfeng Ye · Oct 5, 2026 · 1 files

0984ebc63179

strparser: make sure __strp_recv isn't running before tearing down the parser

Sabrina Dubroca · Oct 5, 2026 · 3 files

8f5d59b9cfa6

bnxt_en: Add bnxt_clear_bars() helper

Michael Chan · Oct 5, 2026 · 1 files

386f887c8290

bnxt_en: Fix driver init in kdump kernel

Michael Chan · Oct 5, 2026 · 1 files

2e52da27096d

bnxt_en: Re-write the BARs following any type of PCIe errors

Pavan Chebbi · Oct 5, 2026 · 2 files

d5a007b9b457

Revert "net: stmmac: propagate PTP addend and system time programming errors"

Jakub Kicinski · Oct 6, 2026 · 2 files

6d25ffca055a

cipso: adjust cached option offsets when removing CIPSO

Daehyeon Ko · Oct 6, 2026 · 1 files

6b48ed85ae0c

net: macb: check TX ring before modifying skb

Nicolai Buchwitz · Oct 6, 2026 · 1 files

9151d6c42799

net: macb: copy shared skbs before appending the FCS

Nicolai Buchwitz · Oct 6, 2026 · 1 files

f394cbd0980c

wifi: mac80211: don't estimate airtime for unsupported rate widths

François Roux · Oct 6, 2026 · 1 files

b056ca4d3742

net/mlx5e: Order ICOSQ cc update after CQ doorbell

Li RongQing · Oct 6, 2026 · 1 files

7ea07afb230f

mlxsw: spectrum_flower: Fix port range register leak in tmplt_create()

Petr Machata · Oct 6, 2026 · 3 files

71198b59df56

selftests: mlxsw: Test port range occupancy on template create

Petr Machata · Oct 6, 2026 · 1 files

3f090039995f

veth: fix peer NETDEV_XDP_ACT_NDO_XMIT after GRO is toggled while down

Tianyi Gao · Oct 6, 2026 · 1 files

c017800af5c7

selftests: net: veth: test peer ndo-xmit after GRO toggle while down

Tianyi Gao · Oct 6, 2026 · 1 files

f202578efc73

flow_dissector: avoid u16 truncation of hlen in bpf_flow_dissect()

Eric Dumazet · Oct 7, 2026 · 1 files

a51d233ccd48

bnxt_en: fix DMA mapping length for padded small packets

Eric Dumazet · Oct 7, 2026 · 1 files

fc13ba44da19

net: dsa: microchip: fix KSZ8765 fiber detection

Sebastien Royen · Oct 7, 2026 · 1 files

2b82e16d6084

net: sparx5: free the matchall entry on destroy

Daniel Machon · Oct 7, 2026 · 1 files

ab9414ed70bd

net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()

Josef Bacik · Oct 7, 2026 · 1 files

089e58805c45

xen/netfront: drop RX packets with a short Ethernet header

Josef Bacik · Oct 7, 2026 · 1 files

513e23857a3a

net/packet: call packet_parse_headers after virtio_net_hdr_to_skb

Willem de Bruijn · Oct 7, 2026 · 1 files

93ccaf1c26e2

xen/netfront: don't leak the skb when xennet_fill_frags() fails

Josef Bacik · Oct 7, 2026 · 1 files

f8c8bd159a9b

ptp: ocp: fix PCIe delay estimation calculation

Vadim Fedorenko · Oct 7, 2026 · 1 files

9727d1c4e1c9

Revert "wifi: libertas: reject short monitor TX frames"

Johannes Berg · Oct 7, 2026 · 1 files

6785011f8b16

ipv4: validate checksum_start before completing checksum

Michael S. Tsirkin · Oct 7, 2026 · 6 files

e02a5b658816

ipv4: do not warn on route notification size race

Daehyeon Ko · Oct 8, 2026 · 1 files

c97426ec649d

ipv6: do not warn on route notification size race

Daehyeon Ko · Oct 8, 2026 · 1 files

64a6b36b0e18

net/smc: protect clcsock lifetime in smc_getname

Chengfeng Ye · Oct 8, 2026 · 1 files

3c6a4b11330f

net: openvswitch: validate transport header presence in set_ipv6_addr

Fernando Fernandez Mancera · Oct 8, 2026 · 1 files

65ab9de4bdd4

wireguard: queueing: preserve tstamp_type when encapsulating packet

Ramses de Norre · Oct 8, 2026 · 1 files

d0305f8d9002

wireguard: noise: reject response consumption after intermediate initiation

Jason A. Donenfeld · Oct 8, 2026 · 1 files

7c24a4e87e21

vsock: Fix memory leak in vmci_transport_recv_dgram_cb()

Ilia Gavrilov · Oct 8, 2026 · 1 files