Weekly briefing · Sep 21–28, 2026
Linux mainline: week of Sep 21
A weekly briefing built from 7 published daily update(s).
In brief
This weekly briefing gathers the meaningful changes that entered Linux mainline over the previous seven days.
Bug fixes
Guard against inode reference failure in parent repair
xrep_findparent_from_dcache now handles igrab returning NULL when looking up the parent inode from the dentry cache during online repair, instead of assuming it always succeeds.
Why it matters: Avoids a possible NULL dereference in the online repair path.
Don't assert on HEALTHY scrub type when new corruption appears
XFS_SCRUB_TYPE_HEALTHY is a synthetic scrub type used by xfs_scrub to tell the kernel a scan found no problems. If the health system records a new corruption just before this request, the old logic could trip an assertion because HEALTHY has no health-group mapping.
Why it matters: Prevents an assertion failure in a race between xfs_scrub and new error records.
Fix attribute-fork block count comparison in inode repair
xrep_inode_blockcounts compared the attribute-fork block count with the data-fork block count, so it could incorrectly validate an inode's attribute fork.
Why it matters: Online repair of inode records now uses the correct block count for the attribute fork.
Release orphanage inode reference if chown fails
If moving a file to the orphanage succeeds but the chown step fails, the extra inode reference was leaked.
Why it matters: Fixes an inode reference leak in online repair failure handling.
Release AGFL earlier during rmapbt repair
rmapbt repair held the AGFL (allocation group free list) locked for the whole scrub transaction after walking it; the patch releases it once the AGFL blocks have been recorded.
Why it matters: Reduces lock hold time during online repair of the reverse-mapping btree.
Use proper jiffies comparison in scrub pacing
xchk_maybe_relax used raw >= to compare jiffies values; jiffies wraps around, so the correct time_after_eq helper is needed.
Why it matters: Avoids scrub pacing mistakes after jiffies wrap.
Validate padding field in commit-range ioctl
xfs_ioc_commit_range did not check the padding field in the ioctl struct.
Why it matters: Tightens the new file-range commit ioctl before it sees wider use.
Skip finish work on file-range exchange dry runs
A dry-run exchange still called xfs_exchange_range_finish, which could strip privileges, flush dirty data, and trim COW (copy-on-write) staging events. The patch exits early on DRY_RUN.
Why it matters: Dry runs now behave like dry runs instead of performing side effects.
Correct block reservations for realtime rmap/refcount recovery
Log recovery used the wrong reservation size for realtime rmap and refcount intent items after a crash.
Why it matters: Avoids incorrect block reservations during recovery of realtime metadata operations.
Fix integer overflow in xbitmap set functions
xbitmap set functions could underflow or overflow when computing left and right pointers, returning wrong values for very large ranges.
Why it matters: Hardens bitmap range handling used by scrub and repair.
Don't flag dir3 block blocks for zero padding
Directory scrub checked for zero padding in both dir3_data and dir3_block formats, but block-format directories don't have that padding field.
Why it matters: Prevents false preen flags on block-format directories.
Correct di_forkoff validation in scrub
The inode fork offset check used the wrong base for the byte count, so it could miss values larger than the literal area.
Why it matters: Inode scrub now validates di_forkoff within the inode's literal area correctly.
Handle NULL cached zone in xfs_get_cached_zone
The cached zone pointer can be NULL after resampling under i_flags_lock; the patch accounts for that.
Why it matters: Avoids a NULL pointer dereference in zone allocation caching.
Refresh realtime quota prealloc limits after default limits
If default realtime block quota limits are installed, the precomputed preallocation watermark limits must be updated too.
Why it matters: Realtime quota preallocation watermarks stay in sync with default rtb limits.
Fix rtgroup repair space estimates
Online repair of the realtime refcount btree didn't include the refcount btree size in its reserved-space estimate.
Why it matters: Avoids underestimating repair space for realtime refcount btree repairs.
Don't cross-reference rmapbt with incomplete bitmaps
If computing space usage bitmaps failed with an out-of-memory error, rmapbt scrub silently dropped the error and cross-referenced with incomplete data.
Why it matters: Scrub now reports an incomplete scrub instead of bogus cross-reference errors.
Don't leak blocks on memory failure during btree repair
A memory allocation failure in xrep_newbt_add_blocks could leak already-allocated blocks and leave online repair unable to back out cleanly. The patch changes the small reservation allocation to a no-fail allocation.
Why it matters: Removes a memory-failure leak and potential filesystem shutdown path in online btree repair.
Don't merge different file I/O error types
The file range health monitor could merge health events with different error types into one record.
Why it matters: Health monitoring keeps different I/O errors distinct.
Fix blockgc group quota scan when user quota isn't enforced
A copy-paste error meant the group-quota prealloc scan failed to set FLAG_GID when only group limits were near, so it might not free preallocations and could hit an unnecessary EDQUOT.
Why it matters: The blockgc background scanner can now free preallocations correctly for group quota enforcement.
Fix unlinked inode bucket recovery
Log recovery of iunlink buckets had several pointer and state bugs that could cause use-after-free, leaks, or unlinked-list loops.
Why it matters: Makes crash recovery of unlinked inode lists safer.
Drop dquot flush lock when buffer can't be found
xfs_qm_flush_one could fail to drop the dquot flush lock if the associated buffer couldn't be found.
Why it matters: Fixes a dquot flush lock leak in quota writeback.
Prevent hidden_space underflow in metafile reservation
xfs_metafile_resv_init could subtract used space from an already-small available count, making hidden_space negative and causing a huge free-block count subtraction.
Why it matters: Avoids free-space accounting corruption when reserving metadata btree file space.
Fix wild memcpy when formatting ondisk rtrefcount btree root
The formatting code copied two sets of keys into a node-block root, but node blocks contain only one set; this over-copies past the source data.
Why it matters: Fixes potential memory corruption when writing realtime refcount btree roots.
HID: memory-safety and race fixes
A batch of HID drivers got fixes for invalid frees, out-of-bounds reads, and teardown races. The winwing force-feedback driver freed a devm-managed allocation with kfree, leading to a double free; Wacom's pen serial enforcement could read past the report; the Alps touchpad had a use-after-free and a leaked input device; the OneXPlayer driver could tear down while delayed work was still running; the AMD sensor hub now validates its PCI BAR size; and roccat got locking fixes.
Why it matters: Prevents crashes, memory corruption, and a possible out-of-bounds read on device removal, suspend, or with malformed HID descriptors.
a1a5ad37e50c9aa237cf6649d3aba3442798aa9dde93e05aabd24922c2a965bcc5f89704d76994443eed
HID: report handling quirks and BPF fix
A HID-BPF kfunc was dropping the report ID byte for USB/I2C transports, breaking unnumbered reports. Several device quirks were added: a Lenovo Yoga Slim 7x keyboard no longer waits a full second on reset, a Hynitron touchpad no longer floods logs with incomplete-report errors, an SDINNOVATION keyboard gets always-poll, and an ASUS ROG Z13 touchpad gets a report-ID mismatch quirk.
Why it matters: Fixes HID-BPF programs on real hardware, speeds up resume on one laptop, and restores full touchpad functionality on an ASUS convertible.
c4afa4862b8739e8e085710a58d97b45f3f4cdb669a3b8f8aaaea79efba5
Qualcomm remoteproc: IOMMU and error handling fixes
The ADSP driver now unmaps with the correct IOVA instead of the physical address, the PAS shutdown error code is no longer overwritten by the DTB shutdown, the handover IRQ is not enabled on attach (SMP2P drops transitions while masked), and the modem driver no longer requires the PAS service for memory protection on platforms that only use TZ memory assignment.
Why it matters: Avoids leaked IOMMU mappings, missed shutdown errors, and probe failures on SC7180 Chromebooks and similar devices.
Memory management: hugetlb, rmap, DAMON, and writeback
Hugetlb gets two fixes: dissolving gigantic pages without runtime support no longer corrupts the free list, and mremap advances the destination address by the source delta when skipping page tables. A missing barrier between anon_vma initialization and publishing could hang tasks on arm64. DAMON had quota bookkeeping bugs that could skip the last region or stop a scheme if the target process exited. The writeback cgwb drain loop now reports a Tasks-RCU quiescent state on preemptible kernels.
Why it matters: Prevents memory corruption, hangs, DAMON misbehavior, and long RCU stalls on cgroup-heavy systems.
a363c62a653c9bdad082d44bb6ac0b3f6013b3723b596b54eb649482497839c0ceedd545f166586f74dd407a5d205179
s390: fix HMAC partial block handling
The s390 HMAC driver now generates an intermediate chaining value for API partial block handling, instead of always computing the final hash.
Why it matters: Correct HMAC results for partial block updates on s390.
pinctrl: serialize generic DT node-to-map parsing
pinctrl_generic_dt_node_to_map() adds groups and functions without taking pctldev->mutex, despite the add functions documenting that the caller must lock. Two devices probing against the same pin controller can race on the same selector index.
Why it matters: Fixes a potential crash or misconfiguration on systems with multiple devices sharing one pin controller.
pinctrl: Allwinner: keep shadow output latch to avoid GPIO corruption
Reading an Allwinner data register returns the actual pin level, not the output latch, for pins muxed as inputs. The GPIO set path's read-modify-write can therefore overwrite latches of input-muxed pins in the same bank, breaking emulated open-drain lines.
Why it matters: Corrects GPIO output behavior on Allwinner SoCs; particularly important for bit-banged I2C.
pinctrl: Allwinner A523: fix voltage withstand encoding
The A523 uses the same voltage-threshold mechanism as earlier SoCs but with an inverted encoding for 1.8V vs 3.3V. The patch adds a new bias type and also enables the CTL register so thresholds can be disabled for other voltages.
Why it matters: Fixes eMMC and Ethernet operation on some A523 boards.
pinctrl: Qualcomm Nord: distinguish QUP1 SE2/SE3 lane pairs
QUP1 SE2/SE3 put each lane pair on two pins with different mux values, but both values were named the same function. The mux code always picked the first entry, so the I2C lanes were never selected.
Why it matters: Restores correct I2C and UART pin selection on Qualcomm Nord platforms.
pinctrl: Tegra238: fix AON register bank
Tegra238's AON pin controller has a single register region, but the AON pin groups were assigned bank 1. This caused an invalid index into pmx->regs[] during probe.
Why it matters: Fixes pinmux register access for Tegra238 AON pins.
arm64: prevent PMZR_EL0 write trap on nVHE
The EL2 fine-grained trap configuration wrote the same mask to HDFGRTR2_EL2 and HDFGWTR2_EL2, but PMZR_EL0 is write-only and its trap bit lives only in the write mask. A userspace PMZR_EL0 write then trapped to EL2 and hit a BUG() in the nVHE hypervisor.
Why it matters: Prevents a host crash when kernel.perf_user_access=1 allows userspace PMU register access.
arm64: reject PROT_NONE in ioremap_prot()
generic_access_phys() passes user PTE protection to ioremap_prot(). On arm64, PROT_NONE PTEs are present-invalid, so pte_present() is true and the protection was accepted, triggering a WARN in the /dev/mem path.
Why it matters: Removes a spurious WARN and blocks non-user protection values from reaching ioremap_prot().
arm64: fix erratum MIDR matching for per-CPU workarounds
The MIDR range check used by errata workarounds ignored the @midr argument passed for the CPU being checked and instead scanned the whole target CPU list. That allowed a fixed CPU to make an affected CPU exempt.
Why it matters: Ensures arm64 errata workarounds are applied only when the actual CPU is affected.
parisc: increase kernel stack to 32kB
64-bit parisc defaulted to a 16kB kernel stack, which overflowed during kernel builds with gcc 17, causing a panic. The patch raises THREAD_SIZE_ORDER to give 32kB stacks.
Why it matters: Prevents stack-overflow panics on parisc under heavy workloads.
parisc: parse early parameters in setup_arch()
parisc never called parse_early_param() from setup_arch(), so HugeTLB options like hugepages= and hugetlb_cma= were parsed after mm_core_init_early() had already consumed the defaults, silently dropping them.
Why it matters: Makes HugeTLB command-line parameters work on parisc.
Hash map batch lookup could lock CPU for over 77 seconds
__htab_map_lookup_and_delete_batch() lacked any rescheduling point, so a single batch call against a large LRU hash map (16M buckets) on a 144-CPU arm64 host held a CPU for 77+ seconds and tripped the soft lockup watchdog.
Why it matters: Systems using large BPF hash maps with batch operations can avoid soft lockup panics and CPU stalls.
SRv6 seg6local programs could trigger dangling pointer writes
An LWT_SEG6LOCAL program could invalidate its cached SRH pointer with bpf_lwt_seg6_adjust_srh() and then reallocate skb->head via bpf_skb_pull_data(), leaving a dangling per-CPU SRH pointer that post-program validation writes through.
Why it matters: A BPF SRv6 program could trigger kernel memory corruption through a dangling pointer.
Sockmap self-redirect double-counts copied_seq causing TCP warnings
When a BPF stream_verdict program redirects an skb back to the same socket, tcp_eat_skb() and the later copied_from_self path both advance copied_seq, doubling the offset and triggering a TCP recvmsg seq bug warning.
Why it matters: Users of BPF sockmap self-redirect may see TCP sequence mismatch warnings and potential data corruption.
Map batch operations overflow on maps exceeding 4GB
Several batch operation implementations used u32 arithmetic for offset calculations, which overflowed when map sizes exceeded 4GB, corrupting values in userspace memory or failing to delete/update keys.
Why it matters: Applications using large BPF maps (>4GB) with batch operations could silently corrupt data or miss key updates.
Arm64 BPF JIT exception callback uses wrong frame pointer from subprogram
The arm64 JIT did not set up BPF_REG_FP for exception callbacks because the exception_cb path skipped push_callee_regs(), so if bpf_throw() was called from a subprogram with its own BPF stack, the callback read from the subprogram's frame instead of the callback's own frame.
Why it matters: BPF exception callbacks on arm64 could read incorrect stack data when thrown from subprograms using their own BPF stack.
Memalloc use-after-free from concurrent ttrace list consumption
Syzkaller found a UAF in alloc_bulk() where concurrent consumption of waiting_for_gp_ttrace lists freed nodes still referenced by llist_del_first(). The fix adds proper synchronization to the RCU tasks trace free path.
Why it matters: Concurrent BPF memory allocator operations could trigger a use-after-free under specific timing conditions.
btf_struct_walk() divides by zero on flexible array of empty structs
When a struct's last member is a flexible array of zero-sized elements, btf_struct_walk() computed (off - moff) % t->size with t->size == 0, causing a kernel divide error at program load time.
Why it matters: Loading a BPF program whose BTF type ends with a flexible array of empty structs could crash the kernel.
Post-verification instruction rewrites made killable
Post-verification rewrite passes such as bpf_opt_remove_nops() had quadratic complexity and neither checked for signals nor rescheduled, so a privileged loader submitting 131K jumps could pin a CPU and block SIGKILL until the rewrite finished.
Why it matters: A privileged BPF program loader can no longer pin a CPU in verifier rewrites, improving system responsiveness.
TCP Fast Open use-after-free via retransmit hint
An unprivileged TFO client can arm a dangling retransmit_skb_hint using an attacker-supplied ICMP fragmentation-needed message, then trigger a use-after-free when a simultaneous open frees the armed SYN skb.
Why it matters: A local unprivileged user could corrupt kernel memory or potentially escalate privileges on systems using TCP Fast Open.
RDS IB scatterlist use-after-free enables local privilege escalation
rds_ib_map_frmr() stores the caller's scatterlist in the MR before DMA mapping can succeed; on failure the MR is returned to the pool with a stale pointer, leading to a use-after-free.
Why it matters: A local user could leverage this memory corruption bug to escalate privileges on systems using RDS over InfiniBand.
Kernel DHCP client buffer overflow in hostname/vendor-class options
ic_dhcp_init_options() appended hostname (option 12) and vendor-class (option 60) into a fixed 312-byte buffer without bounds checking; a long hostname plus a 252-byte dhcpclass identifier overflows the buffer.
Why it matters: Systems using kernel-level DHCP (ipconfig) with long hostnames or dhcpclass identifiers could fail to boot or panic during network configuration.
Open vSwitch and act_ct conntrack helper use-after-free via extension reallocation
When helpers wire a raw pointer into the expectations list for an unconfirmed connection, subsequent extension additions can reallocate the extension space, leaving a dangling pointer that is later accessed during expectation removal.
Why it matters: Systems using Open vSwitch or TC act_ct with conntrack helpers could be vulnerable to use-after-free memory corruption.
VXLAN neighbour reply out-of-bounds write via headroom TOCTOU race
vxlan_na_create() samples needed_headroom twice; a concurrent vxlan_changelink() can increase it between reads, causing the second value to exceed the skb allocation and write the Ethernet header out of bounds.
Why it matters: A local user could trigger an out-of-bounds memory write on systems using VXLAN, potentially leading to corruption or crashes.
GUE remote checksum offload out-of-bounds write
Invalid REMCSUM offsets where the checksum field offset is less than the start offset could underflow a u16 and cause a NETIF_F_HW_CSUM driver to write two bytes about 64 KiB beyond the destination buffer.
Why it matters: Prevents a crafted forwarded packet from corrupting kernel memory via the GUE encapsulation path.
IPv6 extension header parsing out-of-bounds via ipv6_find_hdr()
ipv6_find_hdr() could return an offset past the end of the packet because header lengths were not checked against skb->len, causing Open vSwitch to read and write transport checksums out of bounds.
Why it matters: Fixes a slab-use-after-free triggered through OVS on IPv6 packets with crafted extension headers.
ARP ioctl and seg6 netlink out-of-bounds reads leak kernel memory
The ARP ioctl could read past a stack object due to unterminated device names, and SEG6_ATTR_DST short attributes triggered a 16-byte out-of-bounds read past skb->tail, leaking uninitialized head memory to userspace.
Why it matters: Unprivileged users could read uninitialized kernel memory through the ARP ioctls or segment routing netlink interface.
ip_gre changelink can hijack another tunnel's metadata receive entry
Enabling collect_md mode via changelink on an existing GRE/ERSPAN device is not subject to the uniqueness check enforced during newlink, so it can replace another device's metadata receive entry in the same netns.
Why it matters: Misconfigured or malicious GRE tunnel changes could disrupt metadata-based tunneling for other devices in the same network namespace.
net/sched em_text_dump leaks kernel stack memory
em_text_dump() allocated struct tcf_em_text on the stack without zeroing it, then used strscpy which left trailing bytes uninitialized; nla_put_nohdr copied the full struct to the netlink response.
Why it matters: An unprivileged user could read uninitialized kernel stack memory through the traffic-control text-match filter dump interface.
TCP skb collapsing across device encryption boundaries
Retransmission or SACK shifting could merge a TCP skb queued after a switch to device encryption (such as PSP) into an earlier skb queued before the switch, bypassing the intended encryption fence.
Why it matters: Prevents potential data corruption or security gaps where network traffic meant to be encrypted by hardware could be transmitted unencrypted due to TCP internal merging behavior.
UDP 4-tuple hash table not updated on re-connect or disconnect
A connected UDP socket that reconnects to a different peer was not re-filed in the 4-tuple hash table, and a disconnected socket kept its stale entry, causing incoming packets to miss fast-path lookup.
Why it matters: Applications that repeatedly connect or disconnect UDP sockets (e.g., some DNS or media servers) will see more correct and efficient packet delivery.
Netfilter flowtable use-after-free in HW_DEAD publication
The flow offload worker published NF_FLOW_HW_DEAD before clearing NF_FLOW_HW_PENDING, allowing concurrent garbage collection to RCU-free the flow while the worker still accessed it.
Why it matters: Prevents a use-after-free crash on systems using hardware flow offload under connection teardown.
act_ct panic from benign flow_offload_alloc failure
flow_offload_alloc() can fail when a conntrack entry is dying or under memory pressure, both expected conditions, but the code WARNed on this path. With panic_on_warn=1 an unprivileged user could panic the box.
Why it matters: Removes a kernel panic vector exploitable by unprivileged users on systems using tc conntrack action with panic_on_warn enabled.
HFSC qdisc soft lockup from infinite classify walk
hfsc_classify() could loop forever between two interior classes whose levels were raised after binding, holding the qdisc lock with BH disabled and triggering a soft lockup from a single packet.
Why it matters: Fixes a soft lockup that could hang a CPU on systems using the HFSC traffic-control qdisc.
virtio_net zerocopy deadlock in non-NAPI transmit path
Without NAPI, virtio-net frees completed skbs lazily on the next transmit, so senders using zerocopy (e.g. PACKET_TX_RING) can deadlock if they cannot send more packets.
Why it matters: Users of PACKET_TX_RING or vhost_net zerocopy on virtio-net devices can avoid transmit deadlocks and ring slot exhaustion.
SCTP use-after-free on stale-cookie bundled DATA
When an SCTP association is in COOKIE-ECHOED state and a bundled ERROR(Stale Cookie)+DATA packet arrives from a non-primary address, the stale-cookie handler removes non-primary transports including the one the arriving packet references.
Why it matters: SCTP peers could trigger a kernel crash via a crafted packet, affecting any system using the SCTP protocol.
veth use-after-free of XDP program pointers during channel resize
veth_set_channels() tore down XDP resources for removed RX queues without clearing rq->xdp_prog; if the program was detached, a later channel increase re-enabled NAPI and ran the freed BPF program.
Why it matters: Resizing veth channels while XDP programs are attached no longer risks executing freed BPF code, a common scenario in container networking.
IPv6 lwtunnel massive heap corruption on VLAN interfaces
seg6, ioam6, and rpl lwtunnels sized skb_cow_head() using dst_dev_overhead() which left LL_RESERVED_SPACE (16 bytes for Ethernet), but mac header rebuild needed skb->mac_len bytes. On VLAN devices with longer mac headers the memmove wrote about 64 KB past the skb buffer.
Why it matters: Routing IPv6 traffic through seg6/ioam6/rpl lwtunnels on VLAN interfaces no longer risks massive heap corruption.
Stranded skbs on offline CPUs cause page_pool stalls and netdev teardown hangs
dev_cpu_dead() did not flush skb_defer_nodes when a CPU went offline, leaving skbs stranded. If those skbs held page_pool fragments, page_pool_destroy() could stall indefinitely waiting for inflight pages.
Why it matters: Systems with hotpluggable CPUs may experience indefinite hangs when unregistering network devices while a CPU is offline.
Hardware timestamping via PHY broken after legacy ioctl removal
Removing the legacy hardware timestamping ioctl fallback made the NDO callbacks mandatory, but devices that only timestamp in their PHY implement neither, causing SIOCSHWTSTAMP to fail and PTP to stop working.
Why it matters: Network devices relying on PHY-level timestamping for PTP regain working hardware timestamping configuration.
ovpn driver fixes for endpoint handling, routing, and peer validation
Multiple fixes to the in-tree ovpn VPN driver: preserve IPv6 scope IDs for link-local peers, skip UDP source validation for unspecified addresses, track mutable socket route keys for dst cache validity, prevent torn reads of RCU-published bind addresses, and reject invalid or duplicate peer VPN addresses.
Why it matters: Users of the kernel's native OpenVPN-compatible driver get more reliable IPv6 connectivity, correct routing after socket changes, and clearer configuration errors.
7a6d08ee0f0e77393b4d72df7c66b7a4ae80fa603710bdb9aea934a221ec7d8104988f42b43beccb3713d25e885b31a0025af3a0a8925940f3407b78
ops.dequeue() could self-deadlock by holding DSQ lock
ops.dequeue() was invoked with the source user DSQ's lock still held, so a BPF scheduler that iterated that DSQ from within ops.dequeue() would self-deadlock with IRQs disabled, wedging the system.
Why it matters: Custom BPF schedulers using sched_ext can avoid system-locking deadlocks when iterating DSQs from ops.dequeue().
Task reenqueue race during SCX_OPSS_DISPATCHING window
A task could be found on a DSQ while still in the DISPATCHING state; reenqueueing it in that window ran ops.enqueue() and set QUEUED before the dispatcher's final store overwrote it with NONE, dropping all later dispatches of the task.
Why it matters: sched_ext users may see tasks that silently stop being dispatched under specific timing conditions.
Pass initial CPU mask to cid-form ops.enable()
The cid-form scheduler API now provides a task's initial CPU mask through a new struct scx_enable_args passed to ops.enable(), closing a gap where schedulers had no reliable way to obtain the mask on fork, sub-sched enable, or re-home paths.
Why it matters: Improves the sched_ext BPF scheduler API so that custom schedulers correctly receive CPU affinity information when a task enters the scheduler.
Atheros atl1c/atl1e/atl1 soft lockup during PCIe link reset
During PCIe link or MAC resets, the hardware can report an out-of-range consumer index (0xffff), causing the TX cleanup loop to spin forever and trigger a soft lockup. The fix treats out-of-range values as nothing to clean.
Why it matters: Users of Atheros AR8151 and related NICs may experience system hangs or watchdog timeouts during link flap events.
cgroup pids.events notifications lost in local event accounting mode
When local event accounting is selected, pids_event() returns after notifying only events_local_file, leaving pids.events pollers asleep so that forks rejected by the pids controller do not generate notifications on the shared pids.events file.
Why it matters: Users monitoring cgroup PID limits via pids.events may miss notifications when local event mode is enabled.
Landlock tracepoint improvements for ptrace, signals, and ruleset versioning
Landlock denial tracepoints now report the actual ptrace tracer and effective signal number, and the ruleset version counter was widened to 64 bits to prevent trace identity collision from counter wrapping.
Why it matters: Tooling that consumes Landlock audit or tracing events gets more complete and reliable information for debugging and monitoring sandbox policies.
Restore keepalived compatibility for IFLA_INET_CONF netlink messages
A previous validation change required NLA_F_NESTED to be set on IFLA_INET_CONF attributes, breaking userspace tools like keepalived that did not set the flag when configuring macvlans.
Why it matters: Fixes keepalived and other userspace tools that stopped working after a stricter netlink attribute validation was introduced.
Fix HDMI audio on older Nouveau GPUs with SCDC-capable displays
Nouveau no longer rejects HDMI configuration on pre-Maxwell-2 cards when the sink supports SCDC, so AVI/VSI infoframes are sent and audio works again.
Why it matters: Users with older Nvidia graphics cards get HDMI audio working when connected to modern displays.
Revert virtio-gpu prime buffer import that broke 3D acceleration
Reverts a change that allowed importing prime buffers with 3D enabled because it caused failures with virglrenderer in virtual machines.
Why it matters: Fixes regressions for virtio-gpu users (e.g., QEMU/KVM guests) using 3D acceleration and imported buffers like mouse cursor images.
Fix endless loop in i915 GEM busy ioctl during object destruction
The RCU-based fence iteration in i915_gem_busy_ioctl could loop forever if the GEM object was destroyed concurrently, because the fence list was freed without installing a new one. The fix corrects the RCU teardown order.
Why it matters: Prevents hangs in Intel GPU userspace when querying buffer busy status.
Fix spurious AMD GPU resets from wrong user queue timeout conversion
The hang detection timeout was stored in jiffies but converted again with msecs_to_jiffies(), shortening the window to about 500 ms and triggering false GPU resets. The fix passes jiffies directly.
Why it matters: Avoids unexpected GPU resets and queue disruptions for AMD GPU users.
Fix Intel GPU display corruption on Xen PV dom0
On Xen PV, DMA buffers are not machine-contiguous, so bounce buffering broke Xe's coherency assumptions. Limiting SG segment size to PAGE_SIZE applies the same workaround i915 uses.
Why it matters: Stable display output for Xen PV users with Intel GPUs.
Fix VirtIO GPU data corruption and crash on fence allocation failure
Guest-bound transfers now sync shmem backing before returning data, and a NULL fence from allocation failure is properly checked, fixing stale data and a NULL pointer dereference.
Why it matters: Reliable VirtIO GPU operation in virtual machines.
Fix AMD display stream use-after-free on modeset failure
An extra reference put could drop the stream reference owned by the new CRTC state when color management setup failed, leading to premature stream release. The fix balances the reference count correctly.
Why it matters: Prevents potential crashes during modeset failures on AMD GPUs.
Fix stale PSR2 selective fetch state on Intel displays
Selective fetch enable bits were not cleared when a plane was disabled while PSR2 sel fetch was off, causing the hardware to resume fetching for disabled planes and reserving DDB. The fix clears them on disable.
Why it matters: Avoids display corruption and resource waste on Intel GPUs with PSR2.
Fix PCI BAR resize for devices on a root bus
The PCI core skipped reassigning device BARs after a resize when the device was directly on a root bus, leaving them unassigned. The fix ensures BARs are reassigned even without a bridge window to adjust.
Why it matters: Restores resizable BAR functionality (e.g., AMD Smart Access Memory) for GPUs and other devices attached directly to a root bus.
Avoid NULL dereference when generating PCI bus properties
The dynamic OF helpers dereferenced pdev->subordinate without checking for NULL, which could cause a boot hang on systems with bridges lacking a secondary bus. They now generate 'bus-range' and 'interrupt-map' properties only when a subordinate bus exists.
Why it matters: Prevents early boot crashes on device-tree based systems with unconfigured PCI bridges.
Extend Samsung LPM quirk to AMD SATA controllers
The existing Samsung low-power mode quirk only matched ATI controllers, but Samsung SSDs on AMD 600-series chipsets also time out during suspend. The quirk now applies to AMD controllers as well.
Why it matters: Fixes system suspend timeouts for Samsung SSDs (e.g., 870 QVO) on AMD platforms.
Fix KVM nested virtualization state page error handling
KVM now re-pends the GET_NESTED_STATE_PAGES request when page retrieval fails, preventing re-entry with stale PFNs, and fills kvm_run exit fields in common error paths so userspace receives correct exit information.
Why it matters: Improves stability and security for users of nested virtualization (e.g., running VMs inside VMs) by avoiding stale memory mappings and confusing exit reasons.
Disable enhanced PCIe atomics on AMD NBIO 7.7/7.11 to prevent data corruption
AMD NBIO 7.7 and 7.11 controllers can corrupt 64-bit DMA transfers when PCIe enhanced atomics are enabled. The kernel now disables this feature on affected systems via SMN.
Why it matters: Prevents data corruption and system instability on affected AMD platforms during DMA transfers.
Cache-aware scheduler fixes
LLC stands for last-level cache. These patches fix cache-aware load balancing: counters for LLC-preferring tasks now match the runnable set, active load balance honors the migrate_llc_task migration type, the cache group is decoupled from mm_struct to avoid a use-after-free, kernel threads are skipped, and LLC capacity is refreshed after CPU hotplug.
Why it matters: Prevents tasks from being moved away from their preferred LLC and avoids a scheduler use-after-free on multi-cache systems.
0d6526f82c3cd6013e2465d928f9c0e0a0b9b636fef85bda65efcccddc833cb0243767fd
Intel PEBS constraints and data-source corrections
PEBS is Intel's precise event-based sampling. This set fixes load/store direction for latency events on Gracemont, Crestmont, and Darkmont, removes incorrect data-source constraints on Lion Cove and Panther Cove, corrects Panther Cove snoop states, adds missing extra-register scheduling for precise memory events on DMR/NVL, constrains Panther Cove UOPS_DISPATCHED events, and renames offcore_rsp to offmodule_rsp on DMR/NVL.
Why it matters: Profiling samples from recent Intel CPUs should classify loads/stores and data sources more accurately, and the sysfs rename avoids tooling confusion.
89dc568e8c0be961d6db42d18302c5f475fa7c944595cc439f93d33ad65a0ac5d6ca2c3b04a7ef3b7aa3ff1621adfdd70102c8c7fdfcd4d9ccbad527
perf/core: task-context and branch-record fixes
Fixes a NULL pmu_ctx passed to armv8pmu_sched_task, makes sched_task() run for PMUs with only CPU-wide events so branch records do not leak across task boundaries, fills perf_branch_entry fields with one assignment to avoid uninitialized data in BRBE records, and fixes a refcount leak in attach_perf_ctx_data(). BRBE is Arm's hardware branch recording.
Why it matters: Prevents crashes and stale or uninitialized branch sampling data on Arm and x86.
perf/x86/intel: KVM guest PEBS MSR handling
When PEBS MSRs are switched between host and guest, the new code masks PERF_GLOBAL_CTRL with perf's desired value, avoids writing PEBS_ENABLED on CPUs that isolate PEBS, and skips DS_AREA/PEBS_DATA_CFG loads when PEBS is unused in the guest.
Why it matters: Avoids reserved bits and stuck PEBS_ENABLED states on VM-Entry/VM-Exit, and removes unnecessary MSR writes on VMX transitions.
x86/mce: preserve hardware debug registers across migration
The machine-check entry path saved and restored DR7 around user handling, but if the task migrated during scheduling, the restore ran on the wrong CPU. The save/restore pair is now CPU-local.
Why it matters: Prevents the new CPU's DR7 from being corrupted and the old CPU's DR7 from being left disabled.
sched/core: charge PSI IRQ time to the execution context
PSI stands for Pressure Stall Information. In proxy execution, the scheduling context can be a blocked donor while a different task burns CPU. IRQ time was charged to the donor's cgroup; it is now charged to rq->curr, the task actually running.
Why it matters: Makes PSI IRQ pressure attribution match the cgroup that is actually consuming CPU time.
cgroup/cpuset: reject conflicting remote partitions
A remote partition created under a local partition could warn and then enable on CPUs already owned by the ancestor's subpartitions. It now returns PERR_NOCPUS instead of proceeding.
Why it matters: Prevents invalid exclusive-CPU partition configurations from being enabled.
workqueue: avoid NULL current_pwq deref in flush dependency check
check_flush_dependency() can run on a kworker that is not currently executing a work item, such as when the worker thread is acting as pool manager during an OOM allocation. current_pwq is NULL in that state, so the dereference is now guarded.
Why it matters: Fixes a possible NULL pointer fault during memory-pressure handling.
i2c: qcom-geni: select correct clock performance index
The Qualcomm GENI I2C driver wrote a hardcoded 0 into SE_GENI_CLK_SEL, which always selects the first clock performance-table entry. It now resolves the index that matches the actual source clock.
Why it matters: Avoids incorrect I2C bus frequencies on platforms where the matching entry is not at index 0.
sched_ext: make BPF topology struct size-safe
scx_bpf_cid_topo() now takes a buffer size and copies the smaller of the BPF-provided buffer and the kernel's struct, with CO-RE relocation, so struct scx_cid_topo can grow without breaking existing BPF schedulers.
Why it matters: Prevents load failures or buffer overruns when the kernel-side struct grows.
debugfs: quiet false 'not initialized' warnings
Ref-tracker files created before debugfs is mounted triggered warnings even though the files appear later under /sys/kernel/debug/ref_tracker/. The warning is now suppressed for the error-parent case.
Why it matters: Removes two confusing boot-time errors on debugfs/ref_tracker builds.
x86/sev: make vTPM SVSM calls preemption-safe
SVSM vTPM calls fetched the per-CPU calling-area address without disabling preemption. The fetch now happens inside the interrupt-disabled call protocol, so migration cannot leave the call using a stale per-CPU address.
Why it matters: Prevents wrong-CPU SVSM calls on AMD SEV-SNP systems using vTPM.
Hardware support
New HID devices: Logitech, Steelseries, ELECOM
Added IDs for the Logitech G502 X Lightspeed in wired mode, the Steelseries Arctis 7 (2018) headset (with battery clamping), and the 2025 ELECOM EX-G M-XT4DRBK trackball (with a report descriptor fixup). Also corrected the bus type for the ELECOM M-XGL20DLBK so its special driver quirk actually matches.
Why it matters: These peripherals now get proper HID handling: battery reporting, button mapping, and driver quirks.
sfc: add X4D PF support
Adds support for the X4D controller, which is an X4 controller instance implemented as an IP block in an SoC, with the same feature set as the standalone X4.
Why it matters: Enables the Solarflare sfc driver on SoC platforms incorporating the X4D network controller IP block.
Quectel EG120K-EA LTE and MeiG Smart SRM821 5G module support
The qmi_wwan driver gains support for the Quectel EG120K-EA LTE Cat.12 module, and the cdc_mbim driver adds the MeiG Smart SRM821 5G module to its ZLP conformance whitelist to prevent firmware crashes.
Why it matters: Users of these cellular modules can now use them for data connectivity without firmware crashes or unbound interfaces.
Intel XWAY PHY 100BASE-TX link-up failure workaround
MaxLinear GSW1xx switches incorporating Intel XWAY PHYs can sporadically fail to link up in 100BASE-TX mode after power-on. The workaround enables then disables Cable Diagnostic Mode on all ports after power-on, as specified in the errata.
Why it matters: Users of Intel XWAY / MaxLinear GSW1xx Ethernet PHYs may experience faster or more reliable link-up at 100 Mbps after power-on.
Performance
Speed up cgroup writeback cleanup with many inodes
cleanup_offline_cgwb() now rotates scanned inodes to avoid quadratic rescans, preventing soft lockups when draining dying cgroup writeback domains with millions of inodes.
Why it matters: Improves responsiveness on systems with heavy cgroup usage and large file counts.
Fix hibernation deadlocks by reordering kernel thread freeze
Hibernation memory preallocation was happening after kernel threads were frozen, and swap I/O can depend on those threads, causing intermittent deadlocks. This moves preallocation before freezing kernel threads.
Why it matters: More reliable hibernation for users who suspend to disk.
Fix stale thermal mitigation vote with shared cooling devices
The step_wise governor could leave a cooling device active after a trip cleared when multiple thermal zones share it and one uses a non-zero lower bound. The fix corrects the target state calculation.
Why it matters: Better thermal management and power savings on systems with shared cooling devices.
Security and hardening
Raw HCI socket security filter bypass via out-of-range OCF
The raw HCI socket security filter masked the 10-bit OCF with 127, allowing an unprivileged socket to submit a reserved OCF that aliases an allowlisted command modulo 128. The fix rejects OCF values the filter cannot represent.
Why it matters: An unprivileged process with raw HCI socket access could bypass the security filter to send commands that should be blocked.
SMP Security Request mishandled on BR/EDR causing headphone disconnects
Dual-mode devices such as Bose QC Ultra headphones can send an LE-style SMP Security Request over the BR/EDR fixed channel, which the kernel mistakenly processes as an LE link, causing the controller to reject LE_START_ENC and disconnect with authentication failure.
Why it matters: Users of certain Bluetooth dual-mode headphones may experience unexpected disconnections on BR/EDR links.
BNEP and RFCOMM frame processing out-of-bounds reads and crashes
Fixes multiple out-of-bounds reads and a control-frame fallthrough in BNEP processing that could leak heap memory on short frames, and fixes a NULL dereference and short-frame handling in RFCOMM.
Why it matters: Users of Bluetooth PAN (BNEP) and serial-port-over-Bluetooth (RFCOMM) profiles are protected against potential information leaks and crashes from malformed frames.
mgmt race causes heap out-of-bounds write during controller setup
read_unconf_index_list() could count controllers before a flag transition makes them eligible, then write past the allocated response buffer during the fill pass. The fix allocates space for every device on the list.
Why it matters: Rapid controller setup could trigger a kernel heap out-of-bounds write.
Intel PCIe Bluetooth driver validates DMA-supplied indices
The btintel_pcie driver now bounds-checks device-controlled frbd_tag and cr_hia values used as array indices and loop counters, preventing out-of-bounds accesses from a malicious or malfunctioning device.
Why it matters: Systems with Intel Bluetooth PCIe adapters are protected against potential memory corruption from rogue firmware or device behavior.
L2CAP and HCI socket out-of-bounds reads from malformed frames/events
Short ERTM or streaming-mode L2CAP frames could cause out-of-bounds reads of control and FCS fields, and malformed HCI events could trigger OOB reads in the packet filter before event header validation.
Why it matters: A malicious or buggy Bluetooth controller or vhci device could trigger kernel memory reads past buffer boundaries.
Memory-reading kfuncs now require CAP_PERFMON
Tracing-related kfuncs such as bpf_rdonly_cast() and probe-read helpers were accessible with plain CAP_BPF, unlike their old-style BPF helper equivalents which require CAP_PERFMON. A new KF_PERFMON flag gates these kfuncs.
Why it matters: Unprivileged or CAP_BPF-only BPF programs can no longer read kernel memory via kfuncs that should require perfmon-level privileges.
Unsound pruning of packet pointer ranges could allow out-of-bounds access
regsafe() did not preserve the displacement between registers sharing a packet pointer ID, so two individually narrower ranges could prune an explored path even when their relative displacement had changed, potentially accepting an out-of-bounds packet access.
Why it matters: A crafted BPF program could bypass verifier bounds checks and access packet data out of bounds.
CO-RE relocation ordering and poisoning hardening
CO-RE relocations are now applied before subprogram validation to prevent unresolved relocations from creating invalid control flow that breaks verifier invariants and can write past per-subprogram arrays. Poisoning is also restricted to valid relocatable instruction forms.
Why it matters: Closes a class of BPF verifier bugs where crafted CO-RE metadata could corrupt verifier state or bypass validation.
Global subprograms verified in wrong sleepability context
Global subprograms were always verified with the main program's sleepability state, but workqueue and task-work callbacks run in a sleepable context even when the program is not. This allowed RCU-protected kptrs to produce trusted pointers in non-RCU contexts.
Why it matters: A BPF program could retain RCU-protected kernel pointers outside of a valid RCU read-side critical section, leading to use-after-free.
Self-referential local kptrs could exhaust kernel stack
A self-referential or deeply chained local kptr type could cause bpf_obj_free_fields() to recurse arbitrarily deep and exhaust the kernel stack. The BTF checker now bounds ownership depth and rejects cycles with -ELOOP.
Why it matters: Prevents a local user with BPF access from crashing the kernel through crafted BTF type definitions.
Verifier fixes for stack offsets, dynptrs, arenas, and sockmap
Fixes non-negative stack offsets accepted for iterator state, skb-backed dynptr bounds underflow, arena ALU operations producing wrong results across code paths, and sockmap max_entries values causing signed integer overflow during cleanup.
Why it matters: These fixes prevent crafted BPF programs from corrupting or reading out-of-bounds memory, closing potential privilege-escalation vectors.
Dev-bound-only programs could run on unrelated devices
A bound-only BPF program with NULL offdev could match an unrelated netdev in __bpf_offload_dev_match(), allowing a veth-bound program to run on a tun device and read beyond tun's bare-stack xdp_buff as a veth_xdp_buff.
Why it matters: A privileged BPF user could crash the kernel by running driver-specific XDP metadata kfuncs against an incompatible device.
Multiple NFC input-validation and use-after-free fixes
Multiple NFC drivers and the LLCP core had missing length checks allowing OOB reads, use-after-free on accept-queue races, WKS SAP hijacking via prefix match, and list corruption on DM handling.
Why it matters: Malformed NFC frames from a malicious peer or device could crash the kernel or bypass service-name access control; these fixes harden the NFC subsystem against a cluster of security-relevant bugs.
686f942332b1a653c01ce447bf1460acdf8c092c6a605cbdc3eef2f988a3dcab71a70119273f9d667cde66f4300206b8408cff6bd6067dcf371a3563b61732f47316
Fix BPF binfmt_misc interpreter selection race and out-of-bounds read
Two fixes close memory-safety holes in the BPF hooks that choose and configure interpreters for binfmt_misc. One prevents an out-of-bounds strcmp() when a BPF map value is concurrently modified, and the other prevents staged interpreter paths and arguments from being changed between validation and use.
Why it matters: Users relying on binfmt_misc with BPF programs get protection against local memory corruption and potential privilege escalation via race conditions.
Reject iSCSI Data-In PDUs for write commands
The iSCSI initiator now verifies the data direction before processing a Data-In PDU, so a malicious or buggy target cannot write target-supplied data into the pages of a write command.
Why it matters: Protects iSCSI users from data corruption and potential security issues when connecting to untrusted storage targets.
Fix multiple use-after-free vulnerabilities in Nouveau
Three patches fix use-after-free bugs in Nouveau's VMM teardown, UVMM mapping, and scheduler lifetime, all reachable from userspace.
Why it matters: Nouveau users get improved stability and security; these bugs could crash the system or be exploited by local users.
Prevent shift overflow when mounting crafted SquashFS images
SquashFS now validates the XZ dictionary size before shifting, preventing a shift-out-of-bounds crash on malformed images.
Why it matters: Makes mounting untrusted SquashFS filesystems safer and avoids kernel crashes.
Harden SMB client against malformed create contexts
Multiple fixes validate SMB create-context lengths and offsets, prevent out-of-bounds reads, preserve parsing errors, and close handles after parsing failures.
Why it matters: Protects SMB users against crafted responses from malicious servers that could crash the client or leak kernel memory.
Fix kernel stack leak in GPIO character device error path
If the GPIO chip guard acquisition failed, the ioctl returned before zeroing the info structure, potentially leaking kernel stack contents to userspace. The fix propagates the error and moves the zeroing earlier.
Why it matters: Prevents information disclosure through /dev/gpiochip.
Fix missing inode locking in BPF LSM xattr kfuncs on path hooks
The BPF verifier assumed i_rwsem was held for path_unlink/path_rmdir and used the _locked variants of bpf_set/remove_dentry_xattr, but those hooks run before VFS takes the lock. The fix keeps the locking variants for those hooks.
Why it matters: Prevents race conditions and potential xattr corruption for sleepable BPF LSM programs attached to path_unlink/path_rmdir.
Fix use-after-free when auditing newly loaded IPE policy
IPE audited a new policy after publishing it and dropping the directory inode lock, allowing a concurrent delete to free the policy. The audit now happens under the lock.
Why it matters: Eliminates a crash/security bug in IPE policy loading.
Protect IPE dm-verity root hash with RCU
IPE could free a dm-verity root hash on ->preresume while policy evaluation was still dereferencing it. The hash is now RCU-protected.
Why it matters: Fixes a race condition in IPE's dm-verity trust provider, improving reliability and security.
Keep vCPUs from re-entering a dead VM
KVM previously could clear the KVM_REQ_VM_DEAD request, allowing a vCPU to attempt entry into a dead VM. The fix prevents clearing this request, ensuring vCPUs never re-enter a dead guest.
Why it matters: Hardens KVM against use-after-free and other bugs that could occur if userspace insists on re-running a vCPU after a fatal VM error.
Bound ATA pass-through sense descriptor writes to avoid buffer overrun
The ATA pass-through error path trusted a device-supplied sense length, allowing a faulty or malicious ATAPI device to cause out-of-bounds kernel buffer writes. The descriptor writes are now properly bounded.
Why it matters: Hardens the kernel against storage devices that return malformed sense data, preventing potential memory corruption when using tools like smartctl or hdparm.
Source commits577 entries +
landlock: Add counted_by in landlock_domain
Tingmao Wang · Feb 8, 2026 · 1 files
selftests/filesystems: fix missing and stale TARGETS entries
Disha Goel · Jul 3, 2026 · 1 files
nfc: port100: reject frames whose declared length exceeds the received data
Doruk Tan Ozturk · Jul 11, 2026 · 1 files
squashfs: Add dictionary size range check to prevent shift-out-of-bounds
Ran Hongyun · Jul 13, 2026 · 1 files
nfc: nfcmrvl: validate helper command length before pull
Pengpeng Hou · Jul 15, 2026 · 1 files
nfc: st21nfca: validate received frame size
Pengpeng Hou · Jul 15, 2026 · 1 files
nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
Aldo Ariel Panzardo · Jul 16, 2026 · 1 files
selftests: nci: Correct pthread_create return value check
Lei Zhu · Jul 29, 2026 · 1 files
drm/amdgpu: move userq fence wait out of signalling section
Prike Liang · Jul 31, 2026 · 3 files
RISC-V: KVM: Synchronize hrtimer callback during teardown
Myeonghun Pak · Jul 31, 2026 · 1 files
remoteproc: qcom: q6v5_pas: Don't enable handover IRQ on attach
Shawn Guo · Aug 1, 2026 · 1 files
scsi: libiscsi_tcp: Check the data direction of a Data-In PDU
Yehyeong Lee · Aug 1, 2026 · 1 files
RISC-V: KVM: Fix the conversion between vsip and hvip
Yicong Yang · Aug 4, 2026 · 4 files
HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
Lovekesh Solanki · Aug 4, 2026 · 1 files
KVM: Never clear KVM_REQ_VM_DEAD from a vCPU's requests
Sean Christopherson · Aug 6, 2026 · 5 files
drm/nouveau: fix autosuspend cleanup during teardown
Guangshuo Li · Aug 8, 2026 · 1 files
KVM: arm64: Fix AArch32 DBGBXVR<n> handling
Karl Mehltretter · Aug 10, 2026 · 1 files
RISC-V: KVM: Serialize IMSIC attributes with vCPU migration
Xie Bo · Aug 10, 2026 · 1 files
RISC-V: KVM: Release unused page after MMU invalidation
Xie Bo · Aug 10, 2026 · 1 files
RISC-V: KVM: Propagate interrupted G-stage faults
Xie Bo · Aug 10, 2026 · 2 files
perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
Puranjay Mohan · Aug 10, 2026 · 1 files
perf/core: Run sched_task() for PMUs with only CPU-wide events
Puranjay Mohan · Aug 10, 2026 · 1 files
perf/core: Fill branch entries with a single assignment
Puranjay Mohan · Aug 10, 2026 · 5 files
s390/uv: Fix loop condition in uv_find_secrets
Steffen Eiden · Aug 12, 2026 · 1 files
s390/uv: Prevent potential out-of-bounds read
Steffen Eiden · Aug 12, 2026 · 1 files
HID: winwing: fix use-after-free in force feedback teardown
René Onier · Aug 12, 2026 · 1 files
HID: alps: unregister DualPoint Stick input device on remove
Chen Changcheng · Aug 14, 2026 · 1 files
HID: alps: fix use-after-free on input2 registration failure
Chen Changcheng · Aug 14, 2026 · 1 files
crypto: s390/hmac - Generate intermediate CV for API partial block handling
Holger Dengler · Aug 14, 2026 · 1 files
drm/virtio: sync shmem backing on guest-bound transfers
Benjamin Leggett · Aug 14, 2026 · 3 files
drm/nouveau/dmem: pin VRAM for the whole registered range
Junrui Luo · Aug 17, 2026 · 1 files
HID: elecom: fix bus type for M-XGL20DLBK
Oscar Priego Verdugo · Aug 17, 2026 · 1 files
pinctrl: meson: Fix typo in s4 group name
Sean Anderson · Aug 17, 2026 · 1 files
HID: corsair-void: Fix firmware event packet description
Stuart Hayhurst · Aug 18, 2026 · 1 files
s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config
Anthony Krowiak · Aug 18, 2026 · 1 files
netfilter: flowtable: publish HW_DEAD after worker is done
Jérémy Jean · Aug 18, 2026 · 1 files
remoteproc: qcom_q6v5_pas: Fix error masking in qcom_pas_stop()
Vignesh Viswanathan · Aug 19, 2026 · 1 files
drm/amd/display: Bump frame warning limit for clang builds of dml
Ivan Lipski · Aug 21, 2026 · 1 files
KVM: arm64: vgic-its: Free the caches when GITS_BASER changes
Fuad Tabba · Aug 21, 2026 · 1 files
Revert "KVM: arm64: vgic-its: Don't save collections the table cannot hold"
Fuad Tabba · Aug 21, 2026 · 1 files
KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save
Fuad Tabba · Aug 21, 2026 · 1 files
KVM: arm64: selftests: Add ITS table save tests
Fuad Tabba · Aug 21, 2026 · 2 files
remoteproc: qcom_q6v5_mss: Don't require PAS for memory protection
Paul Hollinsky · Aug 21, 2026 · 1 files
mm/hugetlb: do not dissolve gigantic pages without runtime support
Longlong Xia · Aug 23, 2026 · 1 files
HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
Junjie Cao · Aug 24, 2026 · 2 files
RISC-V: KVM: Preserve firmware counter value across stop/start
SeungJu Cheon · Aug 25, 2026 · 1 files
RISC-V: KVM: Report snapshot write failure to the guest
SeungJu Cheon · Aug 25, 2026 · 1 files
RISC-V: KVM: Fix perf-backed counter accounting across stop and read
SeungJu Cheon · Aug 25, 2026 · 1 files
KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve()
Fuad Tabba · Aug 25, 2026 · 1 files
KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure
Fuad Tabba · Aug 25, 2026 · 1 files
KVM: arm64: Key unpin_host_sve_state() on the state it unpins
Fuad Tabba · Aug 25, 2026 · 1 files
KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2
Fuad Tabba · Aug 25, 2026 · 1 files
RISC-V: KVM: Fix sdata leak and stale snapshot_addr in snapshot_set_shmem
Zongmin Zhou · Aug 26, 2026 · 1 files
KVM: riscv: Fix NACL hfence entry update order
Zongmin Zhou · Aug 26, 2026 · 1 files
KVM: selftests: Use __GLIBC__, not _GNU_SOURCE, to detect actual glibc
Sean Christopherson · Aug 26, 2026 · 1 files
HID: fix semantic patch and improve its performance
Julia Lawall · Aug 27, 2026 · 1 files
remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
Mostafa Saleh · Aug 27, 2026 · 1 files
drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping
Asad Kamal · Aug 28, 2026 · 1 files
drm/virtio: Add pixel blend mode property to cursor plane
Shixiong Ou · Aug 28, 2026 · 1 files
KVM: s390: Fix dirty marking in adapter_indicators_set*()
Claudio Imbrenda · Aug 28, 2026 · 1 files
KVM: s390: Fix compile warning for kvm_s390_update_cmma_dirty()
Claudio Imbrenda · Aug 28, 2026 · 2 files
KVM: s390: Fix _gaccess_shadow_fault()
Claudio Imbrenda · Aug 28, 2026 · 1 files
KVM: s390: Refactor dat_set_slot()
Claudio Imbrenda · Aug 28, 2026 · 3 files
KVM: s390: Move all code into s390_kvm_mmu_prepare_memory_region()
Claudio Imbrenda · Aug 28, 2026 · 3 files
KVM: s390: Add missing srcu in kvm_s390_set_irq_state()
Claudio Imbrenda · Aug 28, 2026 · 1 files
KVM: s390: Fix potential races in dat skey functions
Claudio Imbrenda · Aug 28, 2026 · 1 files
KVM: s390: Fix race in _destroy_pages_crste()
Claudio Imbrenda · Aug 28, 2026 · 1 files
ovpn: always unhash old VPN addresses before rehashing
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: reject duplicate peer VPN addresses
Ralf Lici · Aug 28, 2026 · 3 files
ovpn: reject multipeer peers without VPN addresses
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: reject invalid peer VPN addresses
Ralf Lici · Aug 28, 2026 · 1 files
selftests: ovpn: validate peer VPN addresses
Ralf Lici · Aug 28, 2026 · 3 files
ovpn: preserve IPv6 scope id for netlink peer endpoints
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: skip UDP source validation for unspecified addresses
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: track UDP socket route key for peer dst cache
Ralf Lici · Aug 28, 2026 · 3 files
ovpn: validate peer state before caching UDP dst
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: replace bind when learning local endpoint
Ralf Lici · Aug 28, 2026 · 1 files
ovpn: replace bind when clearing stale local source
Ralf Lici · Aug 28, 2026 · 1 files
pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()
Sarah Emery · Aug 28, 2026 · 1 files
KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0
Karl Mehltretter · Aug 29, 2026 · 1 files
KVM: arm64: selftests: Test empty SMCCC filter range at base 0
Karl Mehltretter · Aug 29, 2026 · 1 files
pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions
Shawn Guo · Aug 30, 2026 · 2 files
nfc: st21nfca: validate ISO15693 inventory length
Pengpeng Hou · Aug 30, 2026 · 1 files
pinctrl: mpfs-mssio: fix width of unused bank voltage setting
Conor Dooley · Aug 31, 2026 · 1 files
pinctrl: mpfs-mssio: use correct regmap function to set bank voltage
Conor Dooley · Aug 31, 2026 · 1 files
scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()
Bart Van Assche · Aug 31, 2026 · 1 files
HID: logitech-hidpp: Add support for G502 X Lightspeed USB mouse
Andres Diaz · Sep 1, 2026 · 1 files
selftests: nci: Fix uninitialized family ID on missing attribute
Chaithanya Lagisetty · Sep 1, 2026 · 1 files
KVM: arm64: Fix spurious warning for benign stage 2 teardown race
Lorenzo Stoakes (ARM) · Sep 1, 2026 · 1 files
KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race
Lorenzo Stoakes (ARM) · Sep 1, 2026 · 1 files
HID: steelseries: Add support for Arctis 7 (2018)
Erik Håkansson · Sep 1, 2026 · 4 files
KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP
Mark Brown · Sep 1, 2026 · 1 files
drm/nouveau: RCU-free the scheduler-containing nouveau_sched
Jonghyuk Kim(MalHyuk) · Sep 2, 2026 · 2 files
HID: roccat: fix locking in roccat_connect() and roccat_disconnect()
Dmitry Antipov · Sep 2, 2026 · 1 files
nfc: llcp: Fix race condition in accept_queue lifecycle
Lee Jones · Sep 2, 2026 · 3 files
bpf: Allow terminal gotox instructions
Siddharth Chintamaneni · Sep 2, 2026 · 1 files
selftests/bpf: Test terminal gotox instructions
Siddharth Chintamaneni · Sep 2, 2026 · 1 files
KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr()
Jim Mattson · Sep 2, 2026 · 2 files
selftests/cgroup: account for zswap shrinker writeback
Joshua Hahn · Sep 2, 2026 · 1 files
netfilter: nfnetlink_queue: hold nfnl mutex in event notifier
Florian Westphal · Sep 3, 2026 · 1 files
bpf: Fix u32 overflow issue in map batch operations
Masoud Aghasi · Sep 3, 2026 · 2 files
pinctrl: sunxi: keep a shadow copy of the data register output latches
Ilya Titov · Sep 3, 2026 · 2 files
bpf: Fix out-of-bounds read of rtt_min in sock_ops
Jiayuan Chen · Sep 3, 2026 · 1 files
bpf: Use kvfree() in xdp_test_run_teardown()
Zhixing Chen · Sep 3, 2026 · 1 files
drm/i915: fix incorrect RCU teardown order
Christian König · Sep 3, 2026 · 1 files
debugfs: don't warn about uninitialized debugfs for an error parent
Mikhail Gavrilov · Sep 3, 2026 · 1 files
mailmap: update Haowen Bai's email address
Haowen Bai · Sep 3, 2026 · 1 files
HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
Youth Cao · Sep 3, 2026 · 1 files
mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()
Nathan Gao · Sep 4, 2026 · 1 files
drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach
Li Youhong · Sep 4, 2026 · 1 files
ocfs2: make ocfs2_calc_xattr_init() return void
Joseph Qi · Sep 4, 2026 · 3 files
selftests/nci: Fix out-of-bounds store on thread join
Chris Gellermann · Sep 4, 2026 · 1 files
HID: hid-oxp: use cancel_delayed_work_sync() in remove
Tristan Madani · Sep 4, 2026 · 1 files
xfs: remove unused xfs_reflink_remap_range declaration
Anuj Gupta · Sep 4, 2026 · 1 files
selftests/hid: add define for commonly used buf size
Benjamin Tissoires · Sep 4, 2026 · 2 files
HID: bpf: fix __hid_bpf_hw_check_params report length
Benjamin Tissoires · Sep 4, 2026 · 1 files
selftests/hid: add unnumbered variant to the hid_bpf tests
Benjamin Tissoires · Sep 4, 2026 · 3 files
nfc: virtual_ncidev: Add missing ioctl compat handler
Chris Gellermann · Sep 4, 2026 · 1 files
bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk
Pu Lehui · Sep 5, 2026 · 1 files
pinctrl: qcom: ipq5210: Publish the OF module alias
hpp.iscas · Sep 5, 2026 · 1 files
netfilter: ip6t_rpfilter: reject routes without inet6_dev
Weiming Shi · Sep 6, 2026 · 1 files
arm64: errata: match the target implementation CPU's own MIDR
David Carlier · Sep 6, 2026 · 1 files
netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
Luxiao Xu · Sep 6, 2026 · 1 files
drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1
Ankit Nautiyal · Sep 7, 2026 · 1 files
drm/client: fix restore of partially initialized client
shechenglong · Sep 7, 2026 · 1 files
drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM
Peiyang He · Sep 7, 2026 · 1 files
s390/pci/docs: Fix sriov_numvfs attribute name
Karl Mehltretter · Sep 7, 2026 · 1 files
s390: Fix typos in comments
Hemanth Selam · Sep 7, 2026 · 4 files
MAINTAINERS: update Xu Xin's email
Xu Xin · Sep 7, 2026 · 2 files
bpf: Fix bpf_skb_change_tail wrt csum partial skbs
Daniel Borkmann · Sep 7, 2026 · 1 files
selftests/bpf: Add test for bpf_skb_change_tail on csum partial skbs
Daniel Borkmann · Sep 7, 2026 · 2 files
bpf, arm64: set up the frame pointer for the exception callback
Donggeun Yoo · Sep 7, 2026 · 1 files
selftests/bpf: cover the exception callback using its own BPF stack
Donggeun Yoo · Sep 7, 2026 · 2 files
mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
SJ Park · Sep 7, 2026 · 1 files
drm/i915/dp_mst: Fix configuring FEC for a disconnected stream
Imre Deak · Sep 7, 2026 · 1 files
drm/i915/dp_mst: Fix configuring TUs for a disconnected stream
Imre Deak · Sep 7, 2026 · 3 files
HID: elecom: Add support for ELECOM M-XT4DRBK (018E)
Berke Durak · Sep 7, 2026 · 3 files
MAINTAINERS: add Baoquan and Baolin as MGLRU reviewers
Baolin Wang · Sep 8, 2026 · 1 files
bpf, sockmap: Fix self-redirect copied_seq double-counting
Geliang Tang · Sep 8, 2026 · 1 files
KVM: arm64: Transfer the hyp stack pages out of the host stage-2
Fuad Tabba · Sep 8, 2026 · 1 files
KVM: arm64: Match hyp text by physical address in fix_host_ownership()
Fuad Tabba · Sep 8, 2026 · 3 files
KVM: arm64: Move the private VA allocation cursor to __io_map_next
Fuad Tabba · Sep 8, 2026 · 1 files
KVM: arm64: Check every private mapping is hyp-owned at pKVM init
Fuad Tabba · Sep 8, 2026 · 5 files
drm/virtio: fix memory leak of fence event on execbuffer failure
Peiyang He · Sep 8, 2026 · 1 files
mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
Jinjiang Tu · Sep 8, 2026 · 2 files
mm/damon/core: fix unconditionally skip last region
Liew Rui Yan · Sep 8, 2026 · 1 files
mm/damon/core: allow esz to be set to zero
Liew Rui Yan · Sep 8, 2026 · 1 files
nfc: llcp: fix slab-out-of-bounds reads when logging service names
Ömer Mete Kaya · Sep 8, 2026 · 2 files
x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11
Mario Limonciello · Sep 8, 2026 · 1 files
HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
Wei Jie LAW · Sep 9, 2026 · 1 files
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Weiming Shi · Sep 9, 2026 · 1 files
nfc: fix use-after-free in nfc_get_local_general_bytes
Luxiao Xu · Sep 9, 2026 · 12 files
block: Fix start and length check added to iov_iter_extract_bvecs()
David Howells · Sep 9, 2026 · 1 files
fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbot's "WARNING in do_new_mount" saga
Christian Brauner · Sep 9, 2026 · 1 files
drm/virtio: fix NULL pointer dereference on fence allocation failure
Peiyang He · Sep 9, 2026 · 1 files
selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
Sven Schnelle · Sep 9, 2026 · 1 files
drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable
Nemesa Garg · Sep 9, 2026 · 4 files
drm/xe/gt_throttle: Report power brake as a throttle reason on CRI
Sk Anirban · Sep 9, 2026 · 2 files
nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()
Ömer Mete Kaya · Sep 9, 2026 · 1 files
nfc: llcp: fix -ENOMEM on connect with zero-length service name
Ömer Mete Kaya · Sep 9, 2026 · 1 files
bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()
Jose Fernandez (Anthropic) · Sep 9, 2026 · 1 files
writeback: report a Tasks-RCU quiescent state per cgwb drain pass
Josef Bacik · Sep 9, 2026 · 1 files
super: make iterate_supers_type() deletion-safe
Christian Brauner · Sep 9, 2026 · 2 files
xfs: guard against igrab failure in xrep_findparent_from_dcache
Darrick J. Wong · Sep 10, 2026 · 1 files
xfs: don't assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption
Darrick J. Wong · Sep 10, 2026 · 1 files
xfs: fix attr fork block count checks in xrep_inode_blockcounts
Darrick J. Wong · Sep 10, 2026 · 1 files
xfs: release orphanage dir inode if chown fails
Darrick J. Wong · Sep 10, 2026 · 1 files
xfs: release AGFL after walking it during rmapbt repair
Darrick J. Wong · Sep 10, 2026 · 1 files
xfs: use correct jiffies comparison function in xchk_maybe_relax
Darrick J. Wong · Sep 10, 2026 · 1 files
HID: i2c-hid: add reset quirk for Lenovo Yoga Slim 7x Gen 11 keyboard
Oleg Keri · Sep 10, 2026 · 2 files
s390/cio: Fix cio_update_schib() to not cache invalid schib
Vineeth Vijayan · Sep 10, 2026 · 1 files
s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points
Vineeth Vijayan · Sep 10, 2026 · 1 files
s390/cio: Guard PMCW field accesses with dnv check
Vineeth Vijayan · Sep 10, 2026 · 5 files
bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
Jiayuan Chen · Sep 10, 2026 · 1 files
tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context
Jiayuan Chen · Sep 10, 2026 · 1 files
selftests/bpf: Test bpf_sock_destroy() on TIME_WAIT and listener socks
Jiayuan Chen · Sep 10, 2026 · 2 files
bpf: Fix divide-by-zero in btf_struct_walk()
Jiayuan Chen · Sep 10, 2026 · 1 files
selftests/bpf: Test BTF walk into a flexible array of zero-sized elements
Jiayuan Chen · Sep 10, 2026 · 2 files
mm/damon/core: reset invalid quota->charge_target_from
SJ Park · Sep 10, 2026 · 1 files
xsk: Use a 32-bit compare in xsk_map_gen_lookup
Zhiling Zou · Sep 10, 2026 · 1 files
bpf: Clear scalar delta on narrowing stack spill
Daniel Borkmann · Sep 10, 2026 · 1 files
netfilter: nft_synproxy: use the family-aware checksum helper
Karl Mehltretter · Sep 10, 2026 · 1 files
bpf: Add KF_PERFMON kfunc flag
Daniel Borkmann · Sep 10, 2026 · 3 files
bpf: Require CAP_PERFMON for kfuncs reading memory
Daniel Borkmann · Sep 10, 2026 · 1 files
bpf: Require CAP_PERFMON for untrusted read-only memory reads
Daniel Borkmann · Sep 10, 2026 · 1 files
selftests/bpf: Add tests for the KF_PERFMON gates
Daniel Borkmann · Sep 10, 2026 · 2 files
arm64: io: Reject non-user protection in ioremap_prot()
Zeng Heng · Sep 11, 2026 · 1 files
xfs: check padding field in xfs_ioc_commit_range
Darrick J. Wong · Sep 11, 2026 · 1 files
xfs: don't call xfs_exchange_range_finish for a dry run
Darrick J. Wong · Sep 11, 2026 · 1 files
xfs: use the correct reservations for rtrmap/refcount recovery
Darrick J. Wong · Sep 11, 2026 · 2 files
xfs: fix integer overflows in xbitmap set functions
Darrick J. Wong · Sep 11, 2026 · 1 files
xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks
Darrick J. Wong · Sep 11, 2026 · 1 files
xfs: check di_forkoff correctly in scrub
Darrick J. Wong · Sep 11, 2026 · 1 files
xfs: fix typos and repeated words in comments
Hemanth Selam · Sep 11, 2026 · 17 files
net: txgbe: fix FDIR filter restore for VF rules
Zhang Yunfei · Sep 11, 2026 · 1 files
ipvs: revalidate ihl before icmp_send
Julian Anastasov · Sep 11, 2026 · 1 files
Revert "drm/virtio: Allow importing prime buffers when 3D is enabled"
Dmitry Osipenko · Sep 11, 2026 · 1 files
KVM: arm64: nv: Fix life cycle of the nested_mmus array
Marc Zyngier · Sep 11, 2026 · 4 files
KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction
Marc Zyngier · Sep 11, 2026 · 3 files
arm64: Add override for WFxT
Yureka Lilian · Sep 11, 2026 · 2 files
writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes
Patrick Lu (Anthropic) · Sep 11, 2026 · 1 files
netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
Naman Gulati · Sep 12, 2026 · 1 files
scsi: ufs: core: Keep internal commands dispatchable during error handling
Stanley Jhu · Sep 12, 2026 · 1 files
pinctrl: single: free the IRQ on domain creation failure
Myeonghun Pak · Sep 13, 2026 · 1 files
nfc: trf7970a: power down on startup RX gain failure
Myeonghun Pak · Sep 13, 2026 · 1 files
tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
Eric Dumazet · Sep 13, 2026 · 1 files
parisc: unwind: Replace open-coded binary search with bsearch()
Sean Young · Sep 13, 2026 · 1 files
x86/sev: Make vTPM SVSM calls preemption-safe
Melody Wang · Sep 14, 2026 · 1 files
octeontx2-af: use seq_file for rsrc_alloc debugfs
Heyang Tan · Sep 14, 2026 · 1 files
RISC-V: KVM: Fix HSM hart status error propagation
Tan Chi · Sep 14, 2026 · 1 files
net/sched: reject IDR error pointers when deleting actions
Weiming Shi · Sep 14, 2026 · 1 files
xfs: remove duplicate INO1_WRITTEN check
Jiangshan Yi · Sep 14, 2026 · 1 files
accel/ivpu: Use separate flag for job timeout
Jakub Pawlak · Sep 14, 2026 · 5 files
KVM: arm64: Don't WARN on an unknown VM ioctl in protected mode
Fuad Tabba · Sep 14, 2026 · 1 files
HID: amd_sfh: Validate PCI BAR size before mapping
Slawomir Stepien · Sep 14, 2026 · 2 files
pinctrl: sunxi: A523: fix voltage withstand encoding
Andre Przywara · Sep 14, 2026 · 4 files
xfs: don't try to get a reference to a NULL oz in xfs_get_cached_zone
Christoph Hellwig · Sep 14, 2026 · 1 files
netfilter: nf_tables: skip expired catchall elements on insert and delete
Aohan Mei · Sep 14, 2026 · 1 files
nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure
Cong Nguyen · Sep 14, 2026 · 1 files
KVM: selftests: fix steal_time for arm64 with host page size > 4K
Sebastian Ott · Sep 14, 2026 · 1 files
bpf: Verify global subprogs in each sleepability context
Kumar Kartikeya Dwivedi · Sep 14, 2026 · 2 files
selftests/bpf: Test global subprog callback contexts
Kumar Kartikeya Dwivedi · Sep 14, 2026 · 1 files
mm/hugetlb: preserve mremap address delta when skipping page tables
Jaewook You · Sep 14, 2026 · 1 files
bpf: Bound ownership depth through local kptrs and graph roots
Kumar Kartikeya Dwivedi · Sep 14, 2026 · 2 files
selftests/bpf: Check local object ownership depth
Kumar Kartikeya Dwivedi · Sep 14, 2026 · 1 files
scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction
Geert Uytterhoeven · Sep 14, 2026 · 1 files
netfs: Fix netfs_read_gaps() to use separate sink folios
David Howells · Sep 14, 2026 · 1 files
bpf: Skip unsettled links in link iterator
Weiming Shi · Sep 14, 2026 · 1 files
net: ethtool: keep rtnl_lock for the ioctl self test
Alexander Duyck · Sep 14, 2026 · 4 files
eth: fbnic: Handle maximum standalone channels
Björn Töpel · Sep 14, 2026 · 1 files
eth: fbnic: use the Rx queue napi pointer to find the napi vector
Alexander Duyck · Sep 14, 2026 · 1 files
eth: fbnic: reset num_napi when the napi vectors are freed
Alexander Duyck · Sep 14, 2026 · 1 files
eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox
Alexander Duyck · Sep 14, 2026 · 2 files
eth: fbnic: Handle FW mailbox completions flagged with an error
Alexander Duyck · Sep 14, 2026 · 4 files
drm/xe/tlb_inval: Treat wedged-device invalidations as complete
Shuicheng Lin · Sep 14, 2026 · 1 files
net: usb: catc: bound the RX packet length in catc_rx_done()
Aamir Ahmed · Sep 14, 2026 · 1 files
gpio: mvebu: keep resume masks within the irqchip cache
Rosen Penev · Sep 15, 2026 · 1 files
fs: avoid repeated scans in evict_inodes()
Julian Sun · Sep 15, 2026 · 1 files
Bluetooth: btintel_pcie: validate device-supplied DMA indices
Ravindra · Sep 15, 2026 · 1 files
xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: fix rtgroup repair estimations
Darrick J. Wong · Sep 15, 2026 · 2 files
xfs: don't cross reference rmapbt with bitmaps if they're incomplete
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: don't let memory failures leak blocks and kill repairs
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: don't merge different file IO error types
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: fix blockgc group quota scanning when usrquota isn't enforced
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: fix cursor and pointer handling when recovering iunlink buckets
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: drop dquot flush lock when we can't find a buffer to flush
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: don't let hidden_space go negative in xfs_metafile_resv_init
Darrick J. Wong · Sep 15, 2026 · 1 files
xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots
Darrick J. Wong · Sep 15, 2026 · 1 files
drm/virtio: fix object leak when drm_gem_handle_create() fails
Junrui Luo · Sep 15, 2026 · 1 files
drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()
Junrui Luo · Sep 15, 2026 · 1 files
drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()
Junrui Luo · Sep 15, 2026 · 1 files
drm/virtio: release the GEM object on virtio_gpu_vram_create() errors
Junrui Luo · Sep 15, 2026 · 1 files
vlan: require the MAC header to be present in __vlan_insert_inner_tag()
Xiang Mei · Sep 15, 2026 · 1 files
sctp: avoid livelock while updating retransmit path
Yiqi Sun · Sep 15, 2026 · 1 files
eth: fbnic: Fix payload page pool error cleanup
Björn Töpel · Sep 15, 2026 · 1 files
net/mlx5: devcom, Base component size on linked devices
Shay Drory · Sep 15, 2026 · 1 files
net/mlx5: SD, unload reps on shared FDB create error path
Shay Drory · Sep 15, 2026 · 1 files
net/mlx5: LAG, reload IB reps of LAG master before the rest
Shay Drory · Sep 15, 2026 · 1 files
Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel
Lee Jones · Sep 15, 2026 · 1 files
perf/arm-cmn: Fix multi-filter encoding
Robin Murphy · Sep 15, 2026 · 1 files
mm: memblock: add missing HugeTLB flag name
Meijing Zhao · Sep 15, 2026 · 1 files
net: gue: reject invalid REMCSUM offsets
Jérémy Jean · Sep 15, 2026 · 1 files
net/sched: act_ct: don't WARN on benign flow_offload_alloc() failure
Nguyen Ngoc Thang · Sep 15, 2026 · 1 files
Bluetooth: mgmt: fix race in read_unconf_index_list()
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: L2CAP: validate frame length before control and FCS access
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: hci_sock: validate event length before filtering
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: ISO: balance the parent hold in hci_bind_bis()
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: hci_sock: reject out-of-range OCF values
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: hci_conn: fix CIS hold ownership on reuse
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
Bluetooth: ISO: release unused CIS holds after channel attach
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
drm/i915/dp: use EXPORT_SYMBOL_IF_KUNIT() for kunit helpers
Jani Nikula · Sep 15, 2026 · 2 files
netfs, afs: Fix symlink reading
David Howells · Sep 15, 2026 · 1 files
vsock: ignore empty child namespace mode writes
Aldo Ariel Panzardo · Sep 15, 2026 · 1 files
scsi: devinfo: Add BLIST_SKIP_IO_HINTS for EMC Symmetrix
Ewan D. Milne · Sep 15, 2026 · 1 files
net: pcs: rzn1-miic: Fix config array initialization
Kyle Hendry · Sep 15, 2026 · 1 files
KVM: Ensure memory attributes xarray nodes are accounted to the caller's memcg
David Ballesteros · Sep 15, 2026 · 1 files
nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()
Aamir Ahmed · Sep 15, 2026 · 1 files
landlock: Work around gcc-16 -Wuninitialized warning
Arnd Bergmann · Sep 15, 2026 · 1 files
mailmap: add entry for Wei Wang
Wei Wang · Sep 15, 2026 · 1 files
scsi: leapraid: Avoid -Wformat-security warning
Arnd Bergmann · Sep 15, 2026 · 2 files
net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset
Quentin Armitage · Sep 15, 2026 · 1 files
sched_ext: Wait for SCX_OPSS_DISPATCHING before reenqueueing a task
Tejun Heo · Sep 15, 2026 · 3 files
Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump()
Zijun Hu · Sep 16, 2026 · 1 files
octeontx2-af: Fix memory scaling limitation in SR-IOV mode
Ratheesh Kannoth · Sep 16, 2026 · 1 files
pinctrl: tegra238: Fix register bank for AON pin groups
Prathamesh Shete · Sep 16, 2026 · 1 files
gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()
Wentao Liang · Sep 16, 2026 · 1 files
drm/amd/display: Fix dc stream excess put in dm_update_crtc_state()
Wentao Liang · Sep 16, 2026 · 1 files
drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc()
Wentao Liang · Sep 16, 2026 · 1 files
drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()
Wentao Liang · Sep 16, 2026 · 1 files
drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()
Wentao Liang · Sep 16, 2026 · 1 files
net/sched: cls_u32: fix manual hash table handle IDR aliasing
Jamal Hadi Salim · Sep 16, 2026 · 1 files
selftests/tc-testing: add u32 manual table handle IDR tests
Jamal Hadi Salim · Sep 16, 2026 · 1 files
drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()
Wentao Liang · Sep 16, 2026 · 1 files
drm/xe: harden adjust_idledly() against divide-by-zero and overflow
Tangudu Tilak Tirumalesh · Sep 16, 2026 · 1 files
drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms
Tangudu Tilak Tirumalesh · Sep 16, 2026 · 3 files
drm/nouveau: fix double-free in nvif_vmm_dtor
Peiyang He · Sep 16, 2026 · 2 files
ipv4: fib: fix data-race and stale genid check around nh->nh_saddr
Linkui Xiao · Sep 16, 2026 · 1 files
sfc: add X4D PF support
Andy Moreton · Sep 16, 2026 · 1 files
net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure
Lorenzo Bianconi · Sep 16, 2026 · 1 files
Bluetooth: SMP: reject Security Request over BR/EDR
Christiano Amora · Sep 16, 2026 · 1 files
scsi: block: Fix zones_cond out-of-bounds write on zone report
ZHOU Jiaxiang · Sep 16, 2026 · 1 files
scsi: sd_zbc: Reject disks with too many zones
ZHOU Jiaxiang · Sep 16, 2026 · 1 files
s390/pci: Fix leak of struct pci_dev reference in zpci_report_status()
Niklas Schnelle · Sep 16, 2026 · 3 files
s390/pci: Fix missing device lock in zpci_report_status()
Niklas Schnelle · Sep 16, 2026 · 2 files
s390/pci: Report SCLP status on error events when no pdev is associated
Niklas Schnelle · Sep 16, 2026 · 1 files
s390/pci: Don't report recovery success on skipped recovery
Niklas Schnelle · Sep 16, 2026 · 1 files
smb: client: fix create context out-of-bounds reads
Zihan Xi · Sep 16, 2026 · 2 files
smb: client: validate POSIX create context length
Zihan Xi · Sep 16, 2026 · 1 files
smb: client: close handle after create-context parsing failure
Zihan Xi · Sep 16, 2026 · 1 files
smb: client: clean up failed cached directory opens
Zihan Xi · Sep 16, 2026 · 1 files
smb: client: close completed creates on compound wait errors
Zihan Xi · Sep 16, 2026 · 3 files
smb: client: preserve create-context parsing errors
Zihan Xi · Sep 16, 2026 · 1 files
s390/debug: Fix NULL pointer dereference in debug_info_copy()
Mikhail Zaslonko · Sep 16, 2026 · 1 files
s390/debug: Reject NULL debug info in debug_dump()
Mikhail Zaslonko · Sep 16, 2026 · 1 files
drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV
Szymon Acedański · Sep 16, 2026 · 1 files
drm/nouveau: Fix bridge reference leak in nv1a_ram_new()
Wentao Liang · Sep 16, 2026 · 1 files
drm/nouveau: Fix gem reference leak in validate_init()
Wentao Liang · Sep 16, 2026 · 1 files
drm/nouveau: Fix runtime PM leak in nouveau_connector_detect()
Wentao Liang · Sep 16, 2026 · 1 files
ipv6: do not let ipv6_find_hdr() return an offset past the packet end
Norbert Szetei · Sep 16, 2026 · 1 files
selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode
Eva Kurchatova · Sep 16, 2026 · 1 files
sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags
Tejun Heo · Sep 16, 2026 · 1 files
ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().
Kuniyuki Iwashima · Sep 16, 2026 · 1 files
net: phy: micrel: Advance register data pointer in write loop
Abhishek Ojha · Sep 16, 2026 · 1 files
perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi · Sep 17, 2026 · 2 files
perf/x86/intel: Update arw_latency_data() mem-op direction handling
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Delete dead NVL PEBS data-source initcall
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Fix precise OMR event scheduling for DMR/NVL
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Rename DMR offcore_rsp attribute to offmodule_rsp
Dapeng Mi · Sep 17, 2026 · 1 files
perf/x86/intel: Rename NVL offcore_rsp attribute to offmodule_rsp
Dapeng Mi · Sep 17, 2026 · 1 files
sched_ext: Don't run ops.dequeue() with a DSQ lock held
fangqiurong · Sep 17, 2026 · 3 files
selftests/sched_ext: Test that ops.dequeue() can iterate the consumed DSQ
fangqiurong · Sep 17, 2026 · 3 files
udp: relocate a connected socket in the 4-tuple hash table on re-connect
Shardul Bankar · Sep 17, 2026 · 1 files
udp: remove a disconnected socket from the 4-tuple hash table
Shardul Bankar · Sep 17, 2026 · 1 files
net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget
Jamal Hadi Salim · Sep 17, 2026 · 1 files
selftests: tc-testing: add a lateral-drift hfsc classify-walk test
Jamal Hadi Salim · Sep 17, 2026 · 1 files
fsl/fman: Fix clk reference leak in read_dts_node()
Wentao Liang · Sep 17, 2026 · 1 files
net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()
Wentao Liang · Sep 17, 2026 · 1 files
fs: don't create the private nullfs mount under namespace_sem
Christian Brauner · Sep 17, 2026 · 1 files
net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()
Wentao Liang · Sep 17, 2026 · 1 files
Revert "selftests/filesystems: add mntns cleanup test"
Christian Brauner · Sep 17, 2026 · 4 files
Revert "put_mnt_ns(): leave mounts connected"
Christian Brauner · Sep 17, 2026 · 1 files
net/mlx5e: fix swapped IPv6 IPsec policy masks
Andrea Parri · Sep 17, 2026 · 1 files
net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
Wentao Liang · Sep 17, 2026 · 1 files
bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
Zhao Gongyi · Sep 17, 2026 · 1 files
net/mlx5e: advertise MACsec offload only when supported
Ralf Lici · Sep 17, 2026 · 2 files
drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait
Sunil Khatri · Sep 17, 2026 · 1 files
drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout
Sunil Khatri · Sep 17, 2026 · 1 files
drm/amdgpu/vcn5.0.1: fix video_timeout unit mismatch in jpeg reset wait
Sunil Khatri · Sep 17, 2026 · 1 files
dpll: use exact lookup for reference sync pin id
Ivan Vecera · Sep 17, 2026 · 1 files
gpiolib: use of_node_name if line-name is missing
Frank Wunderlich · Sep 17, 2026 · 1 files
tg3: clean up PHYLIB resources on probe failure
Myeonghun Pak · Sep 17, 2026 · 1 files
drm/nouveau/gsp/r570: Add support for INTERNAL_GCX_ENTRY_PREREQUISITE
Lyude Paul · Sep 17, 2026 · 11 files
drm/nouveau/gsp/r535: Add support for MEMSYS_GET_STATIC_CONFIG
Lyude Paul · Sep 17, 2026 · 5 files
drm/nouveau/gsp/r570: Add comp mode workaround from issue #3172217
Lyude Paul · Sep 17, 2026 · 2 files
drm/nouveau/gsp/r570: Start saving comptag backing stores
Lyude Paul · Sep 17, 2026 · 2 files
drm/nouveau/gsp/r570: Enable Gcoff in fbsr again
Lyude Paul · Sep 17, 2026 · 1 files
drm/xe: Keep walking on SVM eviction failure
Matthew Brost · Sep 17, 2026 · 1 files
fprobe: Terminate the fgraph_data list when the reservation is not filled
David Carlier · Sep 17, 2026 · 1 files
drm/nouveau/disp: don't reject HDMI config on cards without SCDC
Giuseppe Ranieri · Sep 17, 2026 · 1 files
net: stmmac: selftests: Support running selftests on DSA conduits
Maxime Chevallier · Sep 17, 2026 · 1 files
net: stmmac: selftests: Validate EEE based on the actual LPI timer value
Maxime Chevallier · Sep 17, 2026 · 1 files
net: stmmac: selftests: Check the dev->features for S-TAG offload testing
Maxime Chevallier · Sep 17, 2026 · 1 files
net: stmmac: selftests: Capture all packets for vlan checks
Maxime Chevallier · Sep 17, 2026 · 1 files
net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K
Maxime Chevallier · Sep 17, 2026 · 3 files
net: stmmac: size the RX buffers from the frame length, not the MTU
Maxime Chevallier · Sep 17, 2026 · 1 files
net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test
Maxime Chevallier · Sep 17, 2026 · 1 files
bpf: Make post-verification instruction rewrites killable
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 2 files
bpf: Preserve packet pointer class displacement in regsafe()
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
selftests/bpf: Test packet pointer class displacement pruning
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
bpf: Apply CO-RE relocations before subprogram validation
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files
selftests/bpf: Test early in-kernel CO-RE relocation
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
bpf: Restrict CO-RE poisoning to relocatable instructions
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
selftests/bpf: Test CO-RE instruction poisoning restrictions
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
bpf: Assign lock identity to callback map values
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files
selftests/bpf: Check callback map value lock identity
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files
libbpf: Reject truncated ldimm64 CO-RE relocations
Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files
net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621
Aleksei Sviridkin · Sep 18, 2026 · 1 files
net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq
Aleksei Sviridkin · Sep 18, 2026 · 1 files
drm/nouveau: don't bump pin count on failed re-pin in nouveau_bo_pin_locked()
Peiyang He · Sep 18, 2026 · 1 files
parisc: remove unused <asm/compat_ucontext.h> header
Ethan Nelson-Moore · Sep 18, 2026 · 1 files
vxlan: use one headroom snapshot for neighbour replies
Sanghyun Park · Sep 18, 2026 · 1 files
PCI: Fix BAR resize for devices on a root bus
Liz Fong-Jones · Sep 18, 2026 · 1 files
net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error
bui duc phuc · Sep 18, 2026 · 1 files
parisc: parse early parameters in setup_arch()
Zhenghui Hao · Sep 18, 2026 · 1 files
ipv6: Prevent rt6_insert_exception() for dying fib6_info.
Kuniyuki Iwashima · Sep 18, 2026 · 2 files
binfmt_misc: fix OOB read in bpf_binprm_select_interp()
Chris Mason · Sep 18, 2026 · 1 files
binfmt_misc: fix racy checks in bpf set_interp kfuncs
Chris Mason · Sep 18, 2026 · 1 files
net: don't require the hwtstamp NDOs when a PHY provides timestamping
Nicolai Buchwitz · Sep 18, 2026 · 1 files
net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports
Bernardo Soares · Sep 18, 2026 · 3 files
net/mlx5: Bridge, don't fail unlink of untracked/unsupported peer ports
Bernardo Soares · Sep 18, 2026 · 1 files
eth: fbnic: Avoid rounding zero ring sizes
Björn Töpel · Sep 18, 2026 · 1 files
ata: libata-core: Extend Samsung LPM quirk to AMD controllers
Niklas Cassel · Sep 18, 2026 · 2 files
ata: libata: Correct libata.force parameter documentation
Niklas Cassel · Sep 18, 2026 · 1 files
drm/xe/vm: nuke PTs only after unlinking contested VMAs
Matthew Auld · Sep 18, 2026 · 1 files
drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
Dan Carpenter · Sep 18, 2026 · 1 files
drm/nouveau/clk: don't use the pstate cursor after the loop
Francesco Magazzu · Sep 18, 2026 · 1 files
drm/nouveau/device: don't use the pstate cursor after the loop
Francesco Magazzu · Sep 18, 2026 · 1 files
drm/nouveau/clk: don't clobber reclock status when restoring volt/fan
Francesco Magazzu · Sep 18, 2026 · 1 files
sched/core: Account PSI IRQ time to the execution context, not the scheduling context
Zhan Xusheng · Sep 18, 2026 · 1 files
net/sched: fix potential stack infoleak in em_text_dump()
Bernard Ladenthin · Sep 18, 2026 · 1 files
selftests: net: fix CONFIG_SYSCTL sort order in configs
Yuya Kusakabe · Sep 18, 2026 · 2 files
s390/debug: Do not register views for failed static debug areas
Mikhail Zaslonko · Sep 18, 2026 · 2 files
landlock: Fix tracepoint fixed-width type names
Mickaël Salaün · Sep 18, 2026 · 1 files
landlock: Fix filesystem denial blocker reporting
Mickaël Salaün · Sep 18, 2026 · 3 files
landlock: Fix rule tracepoint context
Mickaël Salaün · Sep 18, 2026 · 9 files
landlock: Fix network denial trace context
Mickaël Salaün · Sep 18, 2026 · 6 files
landlock: Report the actual ptrace tracer
Mickaël Salaün · Sep 18, 2026 · 4 files
landlock: Report the effective signal number
Mickaël Salaün · Sep 18, 2026 · 4 files
selftests/landlock: Test filesystem denial blockers
Mickaël Salaün · Sep 18, 2026 · 1 files
selftests/landlock: Test network denial context
Mickaël Salaün · Sep 18, 2026 · 1 files
landlock: Fix tracepoint contract documentation
Mickaël Salaün · Sep 18, 2026 · 2 files
net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths
Théo Lebrun · Sep 18, 2026 · 1 files
PCI: of_property: Omit bus properties without a subordinate bus
Angel J · Sep 18, 2026 · 1 files
bonding: crypto offload enabled, non-offload slave failover, rekey failed
David Dai · Sep 18, 2026 · 1 files
net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection
Jonas Jelonek · Sep 18, 2026 · 1 files
genetlink: report the real command id for dump-only ops in policy dumps
Jakub Kicinski · Sep 18, 2026 · 1 files
selftests: net: nl_nlctrl: check the op ids in the policy map
Jakub Kicinski · Sep 18, 2026 · 1 files
dcache: unpoison the inline name buffer in __d_alloc()
Drif Abdelmalek Mohamed Said · Sep 18, 2026 · 1 files
tg3: use random MAC address when tg3_get_device_address fails
Ivan Delalande · Sep 18, 2026 · 1 files
sched_ext: Pass the initial cmask to cid-form ops.enable()
Tejun Heo · Sep 19, 2026 · 3 files
virtio_net: copy zerocopy frags in start_xmit without NAPI
Willem de Bruijn · Sep 19, 2026 · 1 files
packet: use ubuf_info completion for TX_RING packets
Willem de Bruijn · Sep 19, 2026 · 2 files
bpf: Compare stack frames in regs_exact()
Kumar Kartikeya Dwivedi · Sep 19, 2026 · 2 files
selftests/bpf: Cover frame changes in bounded loops
Kumar Kartikeya Dwivedi · Sep 19, 2026 · 1 files
bpf: Check params size before reading reserved fields
Yuqi Xu · Sep 19, 2026 · 1 files
net: ipconfig: bound DHCP option construction
Yuqi Xu · Sep 19, 2026 · 1 files
smb: client: delete compound mids on send failure before unlock
Adarsh Das · Sep 19, 2026 · 1 files
Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()
Hui Peng · Sep 19, 2026 · 1 files
Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO
Hui Peng · Sep 19, 2026 · 1 files
net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()
Shihuang Liu · Sep 19, 2026 · 1 files
selftests/sched_ext: Check the cmask cid-form ops.enable() receives
Tejun Heo · Sep 19, 2026 · 3 files
gpio: tps65219: Fix GPIO input value reads
Karl Mehltretter · Sep 19, 2026 · 1 files
gpio: tps65219: Use the variant-specific direction callback
Karl Mehltretter · Sep 19, 2026 · 1 files
gpio: tps65219: Fix TPS65214 GPIO direction programming
Karl Mehltretter · Sep 19, 2026 · 1 files
net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure
Coia Prant · Sep 19, 2026 · 1 files
net: spacemit: clear TX descriptor on fragment mapping failure
Muhammad Bilal · Sep 19, 2026 · 1 files
parisc: Increase kernel stack size to 32kb
Helge Deller · Sep 19, 2026 · 1 files
autofs: fix sbi->pipe file reference leak in autofs_kill_sb()
Hui Peng · Sep 19, 2026 · 1 files
Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough
Hui Peng · Sep 19, 2026 · 2 files
drm/imagination: clamp freelist reconstruction requests
Pengpeng Hou · Sep 20, 2026 · 1 files
net: usb: sr9700: include receive overhead in the length check
Pengpeng Hou · Sep 20, 2026 · 1 files
net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist
Ming Wang · Sep 20, 2026 · 1 files
net: bridge: mdb: restart port group walk after deletion
Fourie Zhang · Sep 20, 2026 · 1 files
bpf: Reject dev-bound-only programs on other devices
Weiming Shi · Sep 20, 2026 · 1 files
PM: hibernate: Freeze kernel threads after image preallocation
Florian Schmaus · Sep 20, 2026 · 1 files
net/sched: act_gate: budget the per-entry list in get_fill_size
Victor Nogueira · Sep 20, 2026 · 1 files
net: arp: terminate device name before lookup
Zijie Huang · Sep 20, 2026 · 1 files
ipv6: Fix dst leak for uncached routes.
Kuniyuki Iwashima · Sep 20, 2026 · 2 files
bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
Xu Yunxiang · Sep 20, 2026 · 1 files
selftests/bpf: Reject iterator destruction through fp+0
Xu Yunxiang · Sep 20, 2026 · 1 files
net: phylink: record the PHY only once bringup cannot fail
Aleksei Sviridkin · Sep 20, 2026 · 1 files
perf/core: Fix a refcount leak in attach_perf_ctx_data()
Namhyung Kim · Sep 20, 2026 · 1 files
smb: client: update POSIX extension specification references
ZhangGuoDong · Sep 21, 2026 · 1 files
ip_gre: Reject enabling collect metadata through changelink
Xuanqiang Luo · Sep 21, 2026 · 1 files
net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP
Nicolo Giuliani · Sep 21, 2026 · 1 files
ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST
Hui Peng · Sep 21, 2026 · 1 files
fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT
Hui Peng · Sep 21, 2026 · 1 files
mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag()
Hui Peng · Sep 21, 2026 · 1 files
net: libwx: fix races in Tx timestamp handling
Jiawen Wu · Sep 21, 2026 · 4 files
net: atl1c: fix soft lockup on out-of-range tpd_cons read
Gajdos Tamás · Sep 21, 2026 · 1 files
net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read
Gajdos Tamás · Sep 21, 2026 · 1 files
net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read
Gajdos Tamás · Sep 21, 2026 · 1 files
net: usb: qmi_wwan: add Quectel EG120K-EA
Gilberto Conde · Sep 21, 2026 · 1 files
sctp: discard the rest of the packet on a stale-cookie error
Aohan Mei · Sep 21, 2026 · 1 files
KVM: Don't pre-reserve xarray entries when storing empty/NULL attributes
Zeng Chi · Sep 21, 2026 · 1 files
KVM: Don't treat reserved xarray entries as having memory attributes
Zeng Chi · Sep 21, 2026 · 1 files
ovl: fix UAF in ovl_do_mkdir() debug print
Amir Goldstein · Sep 21, 2026 · 1 files
i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL
Viken Dadhaniya · Sep 21, 2026 · 1 files
net/sched: act_ife: validate metadata length before decoding
Fang Xieyan · Sep 21, 2026 · 4 files
s390/cmf: Fix virtual vs physical address confusion
Peter Oberparleiter · Sep 21, 2026 · 2 files
net: stmmac: clear stale buf->page after recycling on skb build failure
Lorenzo Bianconi · Sep 21, 2026 · 1 files
net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
Ilya Maximets · Sep 21, 2026 · 2 files
net: openvswitch: conntrack: remove 'add_helper' dead code
Ilya Maximets · Sep 21, 2026 · 1 files
net: openvswitch: conntrack: fix helper UAF due to extensions realloc
Ilya Maximets · Sep 21, 2026 · 1 files
net/sched: act_ct: avoid modifying shared unconfirmed ct entry
Ilya Maximets · Sep 21, 2026 · 1 files
net/sched: act_ct: remove 'add_helper' dead code
Ilya Maximets · Sep 21, 2026 · 1 files
net/sched: act_ct: fix helper UAF due to extensions realloc
Ilya Maximets · Sep 21, 2026 · 1 files
net: xps: reject an out of range traffic class
Norbert Szetei · Sep 21, 2026 · 1 files
net: ena: fix PHC cleanup on probe failure
Guangshuo Li · Sep 21, 2026 · 1 files
net: ena: fix MMIO read buffer leak on probe failure
Guangshuo Li · Sep 21, 2026 · 1 files
net: emac: move setting of netops to fix crash
Christian Lamparter · Sep 21, 2026 · 1 files
sctp: hold asoc or transport before mod_timer() in timer handlers
Xin Long · Sep 21, 2026 · 2 files
nfp: hold IPsec RX state under the XArray lock
Sang-Hoon Choi · Sep 21, 2026 · 1 files
perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
Sean Christopherson · Sep 21, 2026 · 1 files
perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
Sean Christopherson · Sep 21, 2026 · 1 files
perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
Sean Christopherson · Sep 21, 2026 · 1 files
perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
Sean Christopherson · Sep 21, 2026 · 1 files
net: devmem: document that bind-tx is unprivileged by design
Mina Almasry · Sep 21, 2026 · 2 files
macsec: initialize SecY before registering the netdevice
Haseeb Malik · Sep 21, 2026 · 1 files
net: ipv6: keep room for the mac header in dst_dev_overhead()
Yuya Kusakabe · Sep 21, 2026 · 1 files
KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails
Sean Christopherson · Sep 21, 2026 · 1 files
KVM: x86: Fill kvm_run exit fields in common get_nested_state_pages() error paths
Sean Christopherson · Sep 21, 2026 · 3 files
net/rds: size a connection's path set by the transport it ends up with
Allison Henderson · Sep 21, 2026 · 1 files
net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems
Florian Fainelli · Sep 21, 2026 · 1 files
net: bcmgenet: initialize u64 stats seq counter for all queues
Florian Fainelli · Sep 21, 2026 · 1 files
net: bcmgenet: do not skip WoL power up on GENET V1
Florian Fainelli · Sep 21, 2026 · 1 files
net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr
Florian Fainelli · Sep 21, 2026 · 1 files
net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT
Florian Fainelli · Sep 21, 2026 · 1 files
veth: manage XDP program pointers during channel resize
Jakub Kicinski · Sep 21, 2026 · 1 files
net: airoha: npu: cancel wdt_work after releasing the WDT IRQ
Myeonghun Pak · Sep 22, 2026 · 1 files
sched/cache: Keep nr_pref_llc_running in the runnable domain, to fix LLC mis-scheduling bug
Tim Chen · Sep 22, 2026 · 1 files
sched/cache: Honor migrate_llc_task semantics in active load balance, to fix LLC mis-scheduling bug
Lu Wang · Sep 22, 2026 · 1 files
sched/cache: Decouple sched_cache_group from mm to fix UAF
Tim Chen · Sep 22, 2026 · 4 files
sched/cache: Introduce task_struct->sched_cache_grp to fix UAF
Tim Chen · Sep 22, 2026 · 5 files
sched/cache: Skip kernel threads for cache aware scheduling to rubustify the code
Chen Yu · Sep 22, 2026 · 1 files
sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug
Davi Chaves Azevedo · Sep 22, 2026 · 3 files
bna: prevent IOC timer rearm during teardown
Myeonghun Pak · Sep 22, 2026 · 1 files
rds: ib: Clear the sg list when mapping an MR fails
Dongliang Qin · Sep 22, 2026 · 1 files
x86/mce: Fix hardware debug register corruption on task migration
Masami Hiramatsu (Google) · Sep 22, 2026 · 1 files
drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl()
Brajesh Gupta · Sep 22, 2026 · 1 files
drm/imagination: Fix page count for page table for map() interface
Brajesh Gupta · Sep 22, 2026 · 3 files
MAINTAINERS: add Nicolai Buchwitz as GENET maintainer
Nicolai Buchwitz · Sep 22, 2026 · 1 files
net/smc: fix UAF on lgr list traversal in smcr_port_err()
Sidraya Jayagond · Sep 22, 2026 · 2 files
net: phy: intel-xway: workaround 100BASE-TX Link-Up issue
Alexander Sverdlin · Sep 22, 2026 · 1 files
tipc: Fix a data race on mon->peer_cnt in mon_timeout()
Ginger Li · Sep 22, 2026 · 1 files
gpio: cdev: fix kernel stack leak to user-space in error path
Bartosz Golaszewski · Sep 22, 2026 · 1 files
gpio: zynq: fix runtime PM leak on request error path
Ridham Khurana · Sep 22, 2026 · 1 files
isofs: Fix handling of directories with tight blocks
Jan Kara · Sep 22, 2026 · 2 files
thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds
Manaf Meethalavalappu Pallikunhi · Sep 22, 2026 · 1 files
net: bcmgenet: stop Tx NAPI before disabling the queues
Nicolai Buchwitz · Sep 22, 2026 · 1 files
vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
Ido Schimmel · Sep 22, 2026 · 1 files
landlock: Widen ruleset versions to 64 bits
Mickaël Salaün · Sep 22, 2026 · 2 files
firewire: cdev: fix back-transition for iso_resource_auto client resource
Takashi Sakamoto · Sep 22, 2026 · 1 files
bpf: fs/xattr: don't assume the inode is locked in path_unlink/path_rmdir
Andrea Parri · Sep 22, 2026 · 1 files
bpf: Fix bounds check for skb-backed dynptrs
Emil Tsalapatis · Sep 22, 2026 · 1 files
selftests/bpf: Test dynptr slices past end of skb
Emil Tsalapatis · Sep 22, 2026 · 2 files
bpf: Fix bpf_sock context code generation
Emil Tsalapatis · Sep 22, 2026 · 1 files
selftests/bpf: Add selftests for rx_queue_mapping context access
Emil Tsalapatis · Sep 22, 2026 · 1 files
bpf: Reject pkt arguments in mutating subprogs
Emil Tsalapatis · Sep 22, 2026 · 1 files
selftests/bpf: Test rejection of pkt args to mutating subprogs
Emil Tsalapatis · Sep 22, 2026 · 1 files
bpf: Prevent variable arena/non-arena register contents
Emil Tsalapatis · Sep 22, 2026 · 2 files
selftests/bpf: Test for mixed arena/nonarena code paths
Emil Tsalapatis · Sep 22, 2026 · 1 files
smb: client: use GFP_KERNEL in get_targets()
Fredric Cover · Sep 22, 2026 · 1 files
arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
Fuad Tabba · Sep 22, 2026 · 2 files
s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()
Vineeth Vijayan · Sep 22, 2026 · 1 files
ipe: fix use-after-free when auditing a newly loaded policy
Fan Wu · Sep 23, 2026 · 2 files
ipe: protect the dm-verity root hash with RCU
Fan Wu · Sep 23, 2026 · 3 files
nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
Deepanshu Kartikey · Sep 23, 2026 · 1 files
af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
Dairui Zhang · Sep 23, 2026 · 1 files
netfs: Fix missing alloc tagging of direct mempool allocations
Hao Ge · Sep 23, 2026 · 3 files
bpf: Fix immediate JMP JEQ/JNE on MIPS32
Johan Almbladh · Sep 23, 2026 · 1 files
bpf: Fix BSWAP 32 and 16 on MIPS64
Johan Almbladh · Sep 23, 2026 · 1 files
sched_ext: Count SCX_EV_SUB_BYPASS_DISPATCH in the dispatch fallback
Liang Luo · Sep 23, 2026 · 1 files
smb: client: use finish_no_open() for non-regular inodes
Namjae Jeon · Sep 23, 2026 · 1 files
net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
Coia Prant · Sep 23, 2026 · 1 files
net: flush skb_defer_nodes in dev_cpu_dead()
Eric Dumazet · Sep 23, 2026 · 3 files
gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO
Eric Dumazet · Sep 23, 2026 · 1 files
KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV
Sean Christopherson · Sep 23, 2026 · 1 files
KVM: SEV: Do cache maintenance on the source VM during intra-host migration
Sean Christopherson · Sep 23, 2026 · 1 files
drm/amd/display: Relax DML frame limit with UBSAN
Alex Hung · Sep 23, 2026 · 2 files
ata: libata-scsi: bound the ATA passthru sense descriptor writes
Matthias Goergens · Sep 23, 2026 · 1 files
gve: fix TX drop when GSO MSS is too small for hw
Eddie Phillips · Sep 24, 2026 · 1 files
gve: DQO: reject TSO packets with an out of range MSS
Eric Dumazet · Sep 24, 2026 · 2 files
llc: reserve device headroom for allocated frames
Zixuan Chai · Sep 24, 2026 · 1 files
drm/amd/display: Bump frame warning limit for all builds of dml
Alex Deucher · Sep 24, 2026 · 2 files
cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict
Hui Peng · Sep 24, 2026 · 2 files
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
Yilin Zhang · Sep 24, 2026 · 1 files
llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
Eric Dumazet · Sep 24, 2026 · 2 files
bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
Eric Dumazet · Sep 24, 2026 · 1 files
net/sched: sch_teql: fix shadowed err in __teql_resolve()
Eric Dumazet · Sep 24, 2026 · 1 files
vlan: ensure sufficient headroom in vlan_dev_hard_header()
Eric Dumazet · Sep 24, 2026 · 1 files
cgroup/pids: Restore pids.events notifications in local mode
Guopeng Zhang · Sep 24, 2026 · 1 files
kprobes: Fix permanent hang when flushing the kprobe optimizer
Andrea Parri · Sep 24, 2026 · 1 files
bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
Donggeun Yoo · Sep 24, 2026 · 1 files
selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element
Donggeun Yoo · Sep 24, 2026 · 1 files
tcp: prevent collapsing skbs across boundary in rtx queue
Willem de Bruijn · Sep 24, 2026 · 1 files
MAINTAINERS: name the libata/linux for-next branch
Matthias Goergens · Sep 25, 2026 · 1 files
workqueue: Fix NULL current_pwq deref in flush dependency check
Pavankumar Kondeti · Sep 25, 2026 · 1 files
sched_ext: Add a size argument to scx_bpf_cid_topo() so struct scx_cid_topo can grow
Tejun Heo · Sep 26, 2026 · 3 files
Linux 7.3-rc5
Linus Torvalds · Sep 27, 2026 · 1 files