← Back to archive

Weekly briefing · Sep 21–28, 2026

Linux mainline: week of Sep 21

A weekly briefing built from 7 published daily update(s).

In brief

This weekly briefing gathers the meaningful changes that entered Linux mainline over the previous seven days.

Bug fixes

Guard against inode reference failure in parent repair

xrep_findparent_from_dcache now handles igrab returning NULL when looking up the parent inode from the dentry cache during online repair, instead of assuming it always succeeds.

Why it matters: Avoids a possible NULL dereference in the online repair path.

5b644229bd67

Don't assert on HEALTHY scrub type when new corruption appears

XFS_SCRUB_TYPE_HEALTHY is a synthetic scrub type used by xfs_scrub to tell the kernel a scan found no problems. If the health system records a new corruption just before this request, the old logic could trip an assertion because HEALTHY has no health-group mapping.

Why it matters: Prevents an assertion failure in a race between xfs_scrub and new error records.

afbccf99f7f8

Fix attribute-fork block count comparison in inode repair

xrep_inode_blockcounts compared the attribute-fork block count with the data-fork block count, so it could incorrectly validate an inode's attribute fork.

Why it matters: Online repair of inode records now uses the correct block count for the attribute fork.

bb991b7f79dd

Release orphanage inode reference if chown fails

If moving a file to the orphanage succeeds but the chown step fails, the extra inode reference was leaked.

Why it matters: Fixes an inode reference leak in online repair failure handling.

1c32cdc98646

Release AGFL earlier during rmapbt repair

rmapbt repair held the AGFL (allocation group free list) locked for the whole scrub transaction after walking it; the patch releases it once the AGFL blocks have been recorded.

Why it matters: Reduces lock hold time during online repair of the reverse-mapping btree.

8b4ad2814274

Use proper jiffies comparison in scrub pacing

xchk_maybe_relax used raw >= to compare jiffies values; jiffies wraps around, so the correct time_after_eq helper is needed.

Why it matters: Avoids scrub pacing mistakes after jiffies wrap.

984aab2d905a

Validate padding field in commit-range ioctl

xfs_ioc_commit_range did not check the padding field in the ioctl struct.

Why it matters: Tightens the new file-range commit ioctl before it sees wider use.

3083ba8dde76

Skip finish work on file-range exchange dry runs

A dry-run exchange still called xfs_exchange_range_finish, which could strip privileges, flush dirty data, and trim COW (copy-on-write) staging events. The patch exits early on DRY_RUN.

Why it matters: Dry runs now behave like dry runs instead of performing side effects.

8fc18580ec17

Correct block reservations for realtime rmap/refcount recovery

Log recovery used the wrong reservation size for realtime rmap and refcount intent items after a crash.

Why it matters: Avoids incorrect block reservations during recovery of realtime metadata operations.

471e0b6e2dda

Fix integer overflow in xbitmap set functions

xbitmap set functions could underflow or overflow when computing left and right pointers, returning wrong values for very large ranges.

Why it matters: Hardens bitmap range handling used by scrub and repair.

46c1b6674a7b

Don't flag dir3 block blocks for zero padding

Directory scrub checked for zero padding in both dir3_data and dir3_block formats, but block-format directories don't have that padding field.

Why it matters: Prevents false preen flags on block-format directories.

c54110d814c3

Correct di_forkoff validation in scrub

The inode fork offset check used the wrong base for the byte count, so it could miss values larger than the literal area.

Why it matters: Inode scrub now validates di_forkoff within the inode's literal area correctly.

e9193f2f1ce3

Handle NULL cached zone in xfs_get_cached_zone

The cached zone pointer can be NULL after resampling under i_flags_lock; the patch accounts for that.

Why it matters: Avoids a NULL pointer dereference in zone allocation caching.

14e379600d3e

Refresh realtime quota prealloc limits after default limits

If default realtime block quota limits are installed, the precomputed preallocation watermark limits must be updated too.

Why it matters: Realtime quota preallocation watermarks stay in sync with default rtb limits.

065f3ce5936e

Fix rtgroup repair space estimates

Online repair of the realtime refcount btree didn't include the refcount btree size in its reserved-space estimate.

Why it matters: Avoids underestimating repair space for realtime refcount btree repairs.

41c4c41cf6c4

Don't cross-reference rmapbt with incomplete bitmaps

If computing space usage bitmaps failed with an out-of-memory error, rmapbt scrub silently dropped the error and cross-referenced with incomplete data.

Why it matters: Scrub now reports an incomplete scrub instead of bogus cross-reference errors.

d7b92cbe566f

Don't leak blocks on memory failure during btree repair

A memory allocation failure in xrep_newbt_add_blocks could leak already-allocated blocks and leave online repair unable to back out cleanly. The patch changes the small reservation allocation to a no-fail allocation.

Why it matters: Removes a memory-failure leak and potential filesystem shutdown path in online btree repair.

ab1c416d2377

Don't merge different file I/O error types

The file range health monitor could merge health events with different error types into one record.

Why it matters: Health monitoring keeps different I/O errors distinct.

d80993655f7b

Fix blockgc group quota scan when user quota isn't enforced

A copy-paste error meant the group-quota prealloc scan failed to set FLAG_GID when only group limits were near, so it might not free preallocations and could hit an unnecessary EDQUOT.

Why it matters: The blockgc background scanner can now free preallocations correctly for group quota enforcement.

f8f6382ff131

Fix unlinked inode bucket recovery

Log recovery of iunlink buckets had several pointer and state bugs that could cause use-after-free, leaks, or unlinked-list loops.

Why it matters: Makes crash recovery of unlinked inode lists safer.

65f39d09d737

Drop dquot flush lock when buffer can't be found

xfs_qm_flush_one could fail to drop the dquot flush lock if the associated buffer couldn't be found.

Why it matters: Fixes a dquot flush lock leak in quota writeback.

ffb48dccce19

Prevent hidden_space underflow in metafile reservation

xfs_metafile_resv_init could subtract used space from an already-small available count, making hidden_space negative and causing a huge free-block count subtraction.

Why it matters: Avoids free-space accounting corruption when reserving metadata btree file space.

476582d754cd

Fix wild memcpy when formatting ondisk rtrefcount btree root

The formatting code copied two sets of keys into a node-block root, but node blocks contain only one set; this over-copies past the source data.

Why it matters: Fixes potential memory corruption when writing realtime refcount btree roots.

fe2f9135df43

HID: memory-safety and race fixes

A batch of HID drivers got fixes for invalid frees, out-of-bounds reads, and teardown races. The winwing force-feedback driver freed a devm-managed allocation with kfree, leading to a double free; Wacom's pen serial enforcement could read past the report; the Alps touchpad had a use-after-free and a leaked input device; the OneXPlayer driver could tear down while delayed work was still running; the AMD sensor hub now validates its PCI BAR size; and roccat got locking fixes.

Why it matters: Prevents crashes, memory corruption, and a possible out-of-bounds read on device removal, suspend, or with malformed HID descriptors.

a1a5ad37e50c9aa237cf6649d3aba3442798aa9dde93e05aabd24922c2a965bcc5f89704d76994443eed

HID: report handling quirks and BPF fix

A HID-BPF kfunc was dropping the report ID byte for USB/I2C transports, breaking unnumbered reports. Several device quirks were added: a Lenovo Yoga Slim 7x keyboard no longer waits a full second on reset, a Hynitron touchpad no longer floods logs with incomplete-report errors, an SDINNOVATION keyboard gets always-poll, and an ASUS ROG Z13 touchpad gets a report-ID mismatch quirk.

Why it matters: Fixes HID-BPF programs on real hardware, speeds up resume on one laptop, and restores full touchpad functionality on an ASUS convertible.

c4afa4862b8739e8e085710a58d97b45f3f4cdb669a3b8f8aaaea79efba5

Qualcomm remoteproc: IOMMU and error handling fixes

The ADSP driver now unmaps with the correct IOVA instead of the physical address, the PAS shutdown error code is no longer overwritten by the DTB shutdown, the handover IRQ is not enabled on attach (SMP2P drops transitions while masked), and the modem driver no longer requires the PAS service for memory protection on platforms that only use TZ memory assignment.

Why it matters: Avoids leaked IOMMU mappings, missed shutdown errors, and probe failures on SC7180 Chromebooks and similar devices.

0d8e2195bce69db31edf92dd34b8b2d78b62b85385729358

Memory management: hugetlb, rmap, DAMON, and writeback

Hugetlb gets two fixes: dissolving gigantic pages without runtime support no longer corrupts the free list, and mremap advances the destination address by the source delta when skipping page tables. A missing barrier between anon_vma initialization and publishing could hang tasks on arm64. DAMON had quota bookkeeping bugs that could skip the last region or stop a scheme if the target process exited. The writeback cgwb drain loop now reports a Tasks-RCU quiescent state on preemptible kernels.

Why it matters: Prevents memory corruption, hangs, DAMON misbehavior, and long RCU stalls on cgroup-heavy systems.

a363c62a653c9bdad082d44bb6ac0b3f6013b3723b596b54eb649482497839c0ceedd545f166586f74dd407a5d205179

s390: fix HMAC partial block handling

The s390 HMAC driver now generates an intermediate chaining value for API partial block handling, instead of always computing the final hash.

Why it matters: Correct HMAC results for partial block updates on s390.

10396a2d6d41

pinctrl: serialize generic DT node-to-map parsing

pinctrl_generic_dt_node_to_map() adds groups and functions without taking pctldev->mutex, despite the add functions documenting that the caller must lock. Two devices probing against the same pin controller can race on the same selector index.

Why it matters: Fixes a potential crash or misconfiguration on systems with multiple devices sharing one pin controller.

51ae99659469

pinctrl: Allwinner: keep shadow output latch to avoid GPIO corruption

Reading an Allwinner data register returns the actual pin level, not the output latch, for pins muxed as inputs. The GPIO set path's read-modify-write can therefore overwrite latches of input-muxed pins in the same bank, breaking emulated open-drain lines.

Why it matters: Corrects GPIO output behavior on Allwinner SoCs; particularly important for bit-banged I2C.

a13f7f5d14af

pinctrl: Allwinner A523: fix voltage withstand encoding

The A523 uses the same voltage-threshold mechanism as earlier SoCs but with an inverted encoding for 1.8V vs 3.3V. The patch adds a new bias type and also enables the CTL register so thresholds can be disabled for other voltages.

Why it matters: Fixes eMMC and Ethernet operation on some A523 boards.

ef56085dfd1d

pinctrl: Qualcomm Nord: distinguish QUP1 SE2/SE3 lane pairs

QUP1 SE2/SE3 put each lane pair on two pins with different mux values, but both values were named the same function. The mux code always picked the first entry, so the I2C lanes were never selected.

Why it matters: Restores correct I2C and UART pin selection on Qualcomm Nord platforms.

b0be01f133aa

pinctrl: Tegra238: fix AON register bank

Tegra238's AON pin controller has a single register region, but the AON pin groups were assigned bank 1. This caused an invalid index into pmx->regs[] during probe.

Why it matters: Fixes pinmux register access for Tegra238 AON pins.

ae2c5bf96957

arm64: prevent PMZR_EL0 write trap on nVHE

The EL2 fine-grained trap configuration wrote the same mask to HDFGRTR2_EL2 and HDFGWTR2_EL2, but PMZR_EL0 is write-only and its trap bit lives only in the write mask. A userspace PMZR_EL0 write then trapped to EL2 and hit a BUG() in the nVHE hypervisor.

Why it matters: Prevents a host crash when kernel.perf_user_access=1 allows userspace PMU register access.

2bc6b218717b

arm64: reject PROT_NONE in ioremap_prot()

generic_access_phys() passes user PTE protection to ioremap_prot(). On arm64, PROT_NONE PTEs are present-invalid, so pte_present() is true and the protection was accepted, triggering a WARN in the /dev/mem path.

Why it matters: Removes a spurious WARN and blocks non-user protection values from reaching ioremap_prot().

bb756b11ad63

arm64: fix erratum MIDR matching for per-CPU workarounds

The MIDR range check used by errata workarounds ignored the @midr argument passed for the CPU being checked and instead scanned the whole target CPU list. That allowed a fixed CPU to make an affected CPU exempt.

Why it matters: Ensures arm64 errata workarounds are applied only when the actual CPU is affected.

b7403afb7a5f

parisc: increase kernel stack to 32kB

64-bit parisc defaulted to a 16kB kernel stack, which overflowed during kernel builds with gcc 17, causing a panic. The patch raises THREAD_SIZE_ORDER to give 32kB stacks.

Why it matters: Prevents stack-overflow panics on parisc under heavy workloads.

94b7e3a7e871

parisc: parse early parameters in setup_arch()

parisc never called parse_early_param() from setup_arch(), so HugeTLB options like hugepages= and hugetlb_cma= were parsed after mm_core_init_early() had already consumed the defaults, silently dropping them.

Why it matters: Makes HugeTLB command-line parameters work on parisc.

289e99e7a263

Hash map batch lookup could lock CPU for over 77 seconds

__htab_map_lookup_and_delete_batch() lacked any rescheduling point, so a single batch call against a large LRU hash map (16M buckets) on a 144-CPU arm64 host held a CPU for 77+ seconds and tripped the soft lockup watchdog.

Why it matters: Systems using large BPF hash maps with batch operations can avoid soft lockup panics and CPU stalls.

85136bf22404

SRv6 seg6local programs could trigger dangling pointer writes

An LWT_SEG6LOCAL program could invalidate its cached SRH pointer with bpf_lwt_seg6_adjust_srh() and then reallocate skb->head via bpf_skb_pull_data(), leaving a dangling per-CPU SRH pointer that post-program validation writes through.

Why it matters: A BPF SRv6 program could trigger kernel memory corruption through a dangling pointer.

e4a62833adff

Sockmap self-redirect double-counts copied_seq causing TCP warnings

When a BPF stream_verdict program redirects an skb back to the same socket, tcp_eat_skb() and the later copied_from_self path both advance copied_seq, doubling the offset and triggering a TCP recvmsg seq bug warning.

Why it matters: Users of BPF sockmap self-redirect may see TCP sequence mismatch warnings and potential data corruption.

490a83d6386e

Map batch operations overflow on maps exceeding 4GB

Several batch operation implementations used u32 arithmetic for offset calculations, which overflowed when map sizes exceeded 4GB, corrupting values in userspace memory or failing to delete/update keys.

Why it matters: Applications using large BPF maps (>4GB) with batch operations could silently corrupt data or miss key updates.

953824e508b2

Arm64 BPF JIT exception callback uses wrong frame pointer from subprogram

The arm64 JIT did not set up BPF_REG_FP for exception callbacks because the exception_cb path skipped push_callee_regs(), so if bpf_throw() was called from a subprogram with its own BPF stack, the callback read from the subprogram's frame instead of the callback's own frame.

Why it matters: BPF exception callbacks on arm64 could read incorrect stack data when thrown from subprograms using their own BPF stack.

ef1fb82f1218

Memalloc use-after-free from concurrent ttrace list consumption

Syzkaller found a UAF in alloc_bulk() where concurrent consumption of waiting_for_gp_ttrace lists freed nodes still referenced by llist_del_first(). The fix adds proper synchronization to the RCU tasks trace free path.

Why it matters: Concurrent BPF memory allocator operations could trigger a use-after-free under specific timing conditions.

1c21452d02ee

btf_struct_walk() divides by zero on flexible array of empty structs

When a struct's last member is a flexible array of zero-sized elements, btf_struct_walk() computed (off - moff) % t->size with t->size == 0, causing a kernel divide error at program load time.

Why it matters: Loading a BPF program whose BTF type ends with a flexible array of empty structs could crash the kernel.

b0b3dc665296

Post-verification instruction rewrites made killable

Post-verification rewrite passes such as bpf_opt_remove_nops() had quadratic complexity and neither checked for signals nor rescheduled, so a privileged loader submitting 131K jumps could pin a CPU and block SIGKILL until the rewrite finished.

Why it matters: A privileged BPF program loader can no longer pin a CPU in verifier rewrites, improving system responsiveness.

261b61d3735b

TCP Fast Open use-after-free via retransmit hint

An unprivileged TFO client can arm a dangling retransmit_skb_hint using an attacker-supplied ICMP fragmentation-needed message, then trigger a use-after-free when a simultaneous open frees the armed SYN skb.

Why it matters: A local unprivileged user could corrupt kernel memory or potentially escalate privileges on systems using TCP Fast Open.

fe99bbeee5c5

RDS IB scatterlist use-after-free enables local privilege escalation

rds_ib_map_frmr() stores the caller's scatterlist in the MR before DMA mapping can succeed; on failure the MR is returned to the pool with a stale pointer, leading to a use-after-free.

Why it matters: A local user could leverage this memory corruption bug to escalate privileges on systems using RDS over InfiniBand.

58eb1b3325ed

Kernel DHCP client buffer overflow in hostname/vendor-class options

ic_dhcp_init_options() appended hostname (option 12) and vendor-class (option 60) into a fixed 312-byte buffer without bounds checking; a long hostname plus a 252-byte dhcpclass identifier overflows the buffer.

Why it matters: Systems using kernel-level DHCP (ipconfig) with long hostnames or dhcpclass identifiers could fail to boot or panic during network configuration.

e47a1958e12a

Open vSwitch and act_ct conntrack helper use-after-free via extension reallocation

When helpers wire a raw pointer into the expectations list for an unconfirmed connection, subsequent extension additions can reallocate the extension space, leaving a dangling pointer that is later accessed during expectation removal.

Why it matters: Systems using Open vSwitch or TC act_ct with conntrack helpers could be vulnerable to use-after-free memory corruption.

26b2bd70d2241a4151e6be57f85009dfcd65dad19b59da05

VXLAN neighbour reply out-of-bounds write via headroom TOCTOU race

vxlan_na_create() samples needed_headroom twice; a concurrent vxlan_changelink() can increase it between reads, causing the second value to exceed the skb allocation and write the Ethernet header out of bounds.

Why it matters: A local user could trigger an out-of-bounds memory write on systems using VXLAN, potentially leading to corruption or crashes.

481506a756dc

GUE remote checksum offload out-of-bounds write

Invalid REMCSUM offsets where the checksum field offset is less than the start offset could underflow a u16 and cause a NETIF_F_HW_CSUM driver to write two bytes about 64 KiB beyond the destination buffer.

Why it matters: Prevents a crafted forwarded packet from corrupting kernel memory via the GUE encapsulation path.

2566866fc309

IPv6 extension header parsing out-of-bounds via ipv6_find_hdr()

ipv6_find_hdr() could return an offset past the end of the packet because header lengths were not checked against skb->len, causing Open vSwitch to read and write transport checksums out of bounds.

Why it matters: Fixes a slab-use-after-free triggered through OVS on IPv6 packets with crafted extension headers.

ee319bd3a0e9

ARP ioctl and seg6 netlink out-of-bounds reads leak kernel memory

The ARP ioctl could read past a stack object due to unterminated device names, and SEG6_ATTR_DST short attributes triggered a 16-byte out-of-bounds read past skb->tail, leaking uninitialized head memory to userspace.

Why it matters: Unprivileged users could read uninitialized kernel memory through the ARP ioctls or segment routing netlink interface.

d8b6529e80bc2d959c75c27f

ip_gre changelink can hijack another tunnel's metadata receive entry

Enabling collect_md mode via changelink on an existing GRE/ERSPAN device is not subject to the uniqueness check enforced during newlink, so it can replace another device's metadata receive entry in the same netns.

Why it matters: Misconfigured or malicious GRE tunnel changes could disrupt metadata-based tunneling for other devices in the same network namespace.

a3f315be9d30

net/sched em_text_dump leaks kernel stack memory

em_text_dump() allocated struct tcf_em_text on the stack without zeroing it, then used strscpy which left trailing bytes uninitialized; nla_put_nohdr copied the full struct to the netlink response.

Why it matters: An unprivileged user could read uninitialized kernel stack memory through the traffic-control text-match filter dump interface.

9c572a83037a

TCP skb collapsing across device encryption boundaries

Retransmission or SACK shifting could merge a TCP skb queued after a switch to device encryption (such as PSP) into an earlier skb queued before the switch, bypassing the intended encryption fence.

Why it matters: Prevents potential data corruption or security gaps where network traffic meant to be encrypted by hardware could be transmitted unencrypted due to TCP internal merging behavior.

fc6d80eb5044

UDP 4-tuple hash table not updated on re-connect or disconnect

A connected UDP socket that reconnects to a different peer was not re-filed in the 4-tuple hash table, and a disconnected socket kept its stale entry, causing incoming packets to miss fast-path lookup.

Why it matters: Applications that repeatedly connect or disconnect UDP sockets (e.g., some DNS or media servers) will see more correct and efficient packet delivery.

5fd0783b99d49e95b1a94c9c

Netfilter flowtable use-after-free in HW_DEAD publication

The flow offload worker published NF_FLOW_HW_DEAD before clearing NF_FLOW_HW_PENDING, allowing concurrent garbage collection to RCU-free the flow while the worker still accessed it.

Why it matters: Prevents a use-after-free crash on systems using hardware flow offload under connection teardown.

d644b23afe1e

act_ct panic from benign flow_offload_alloc failure

flow_offload_alloc() can fail when a conntrack entry is dying or under memory pressure, both expected conditions, but the code WARNed on this path. With panic_on_warn=1 an unprivileged user could panic the box.

Why it matters: Removes a kernel panic vector exploitable by unprivileged users on systems using tc conntrack action with panic_on_warn enabled.

47abe7a5c4eb

HFSC qdisc soft lockup from infinite classify walk

hfsc_classify() could loop forever between two interior classes whose levels were raised after binding, holding the qdisc lock with BH disabled and triggering a soft lockup from a single packet.

Why it matters: Fixes a soft lockup that could hang a CPU on systems using the HFSC traffic-control qdisc.

8a60ade2277e

virtio_net zerocopy deadlock in non-NAPI transmit path

Without NAPI, virtio-net frees completed skbs lazily on the next transmit, so senders using zerocopy (e.g. PACKET_TX_RING) can deadlock if they cannot send more packets.

Why it matters: Users of PACKET_TX_RING or vhost_net zerocopy on virtio-net devices can avoid transmit deadlocks and ring slot exhaustion.

07e1a9408b6c

SCTP use-after-free on stale-cookie bundled DATA

When an SCTP association is in COOKIE-ECHOED state and a bundled ERROR(Stale Cookie)+DATA packet arrives from a non-primary address, the stale-cookie handler removes non-primary transports including the one the arriving packet references.

Why it matters: SCTP peers could trigger a kernel crash via a crafted packet, affecting any system using the SCTP protocol.

4498467a8af0

veth use-after-free of XDP program pointers during channel resize

veth_set_channels() tore down XDP resources for removed RX queues without clearing rq->xdp_prog; if the program was detached, a later channel increase re-enabled NAPI and ran the freed BPF program.

Why it matters: Resizing veth channels while XDP programs are attached no longer risks executing freed BPF code, a common scenario in container networking.

7104a3707143

IPv6 lwtunnel massive heap corruption on VLAN interfaces

seg6, ioam6, and rpl lwtunnels sized skb_cow_head() using dst_dev_overhead() which left LL_RESERVED_SPACE (16 bytes for Ethernet), but mac header rebuild needed skb->mac_len bytes. On VLAN devices with longer mac headers the memmove wrote about 64 KB past the skb buffer.

Why it matters: Routing IPv6 traffic through seg6/ioam6/rpl lwtunnels on VLAN interfaces no longer risks massive heap corruption.

87cd6b717e40

Stranded skbs on offline CPUs cause page_pool stalls and netdev teardown hangs

dev_cpu_dead() did not flush skb_defer_nodes when a CPU went offline, leaving skbs stranded. If those skbs held page_pool fragments, page_pool_destroy() could stall indefinitely waiting for inflight pages.

Why it matters: Systems with hotpluggable CPUs may experience indefinite hangs when unregistering network devices while a CPU is offline.

06e3f54e8b22

Hardware timestamping via PHY broken after legacy ioctl removal

Removing the legacy hardware timestamping ioctl fallback made the NDO callbacks mandatory, but devices that only timestamp in their PHY implement neither, causing SIOCSHWTSTAMP to fail and PTP to stop working.

Why it matters: Network devices relying on PHY-level timestamping for PTP regain working hardware timestamping configuration.

31995571219c

ovpn driver fixes for endpoint handling, routing, and peer validation

Multiple fixes to the in-tree ovpn VPN driver: preserve IPv6 scope IDs for link-local peers, skip UDP source validation for unspecified addresses, track mutable socket route keys for dst cache validity, prevent torn reads of RCU-published bind addresses, and reject invalid or duplicate peer VPN addresses.

Why it matters: Users of the kernel's native OpenVPN-compatible driver get more reliable IPv6 connectivity, correct routing after socket changes, and clearer configuration errors.

7a6d08ee0f0e77393b4d72df7c66b7a4ae80fa603710bdb9aea934a221ec7d8104988f42b43beccb3713d25e885b31a0025af3a0a8925940f3407b78

ops.dequeue() could self-deadlock by holding DSQ lock

ops.dequeue() was invoked with the source user DSQ's lock still held, so a BPF scheduler that iterated that DSQ from within ops.dequeue() would self-deadlock with IRQs disabled, wedging the system.

Why it matters: Custom BPF schedulers using sched_ext can avoid system-locking deadlocks when iterating DSQs from ops.dequeue().

cb86607ada73

Task reenqueue race during SCX_OPSS_DISPATCHING window

A task could be found on a DSQ while still in the DISPATCHING state; reenqueueing it in that window ran ops.enqueue() and set QUEUED before the dispatcher's final store overwrote it with NONE, dropping all later dispatches of the task.

Why it matters: sched_ext users may see tasks that silently stop being dispatched under specific timing conditions.

7de9a6fb44eadf5cdc2c832c

Pass initial CPU mask to cid-form ops.enable()

The cid-form scheduler API now provides a task's initial CPU mask through a new struct scx_enable_args passed to ops.enable(), closing a gap where schedulers had no reliable way to obtain the mask on fork, sub-sched enable, or re-home paths.

Why it matters: Improves the sched_ext BPF scheduler API so that custom schedulers correctly receive CPU affinity information when a task enters the scheduler.

3bd46666cfe5

Atheros atl1c/atl1e/atl1 soft lockup during PCIe link reset

During PCIe link or MAC resets, the hardware can report an out-of-range consumer index (0xffff), causing the TX cleanup loop to spin forever and trigger a soft lockup. The fix treats out-of-range values as nothing to clean.

Why it matters: Users of Atheros AR8151 and related NICs may experience system hangs or watchdog timeouts during link flap events.

36c2009d90f2374bf9e4b90f43e746821f5f

cgroup pids.events notifications lost in local event accounting mode

When local event accounting is selected, pids_event() returns after notifying only events_local_file, leaving pids.events pollers asleep so that forks rejected by the pids controller do not generate notifications on the shared pids.events file.

Why it matters: Users monitoring cgroup PID limits via pids.events may miss notifications when local event mode is enabled.

1765a153d985

Landlock tracepoint improvements for ptrace, signals, and ruleset versioning

Landlock denial tracepoints now report the actual ptrace tracer and effective signal number, and the ruleset version counter was widened to 64 bits to prevent trace identity collision from counter wrapping.

Why it matters: Tooling that consumes Landlock audit or tracing events gets more complete and reliable information for debugging and monitoring sandbox policies.

7ad69ac633150889db596a25e7e0a54300a8

Restore keepalived compatibility for IFLA_INET_CONF netlink messages

A previous validation change required NLA_F_NESTED to be set on IFLA_INET_CONF attributes, breaking userspace tools like keepalived that did not set the flag when configuring macvlans.

Why it matters: Fixes keepalived and other userspace tools that stopped working after a stricter netlink attribute validation was introduced.

6c096bb08de9

Fix HDMI audio on older Nouveau GPUs with SCDC-capable displays

Nouveau no longer rejects HDMI configuration on pre-Maxwell-2 cards when the sink supports SCDC, so AVI/VSI infoframes are sent and audio works again.

Why it matters: Users with older Nvidia graphics cards get HDMI audio working when connected to modern displays.

1717fcc5be57

Revert virtio-gpu prime buffer import that broke 3D acceleration

Reverts a change that allowed importing prime buffers with 3D enabled because it caused failures with virglrenderer in virtual machines.

Why it matters: Fixes regressions for virtio-gpu users (e.g., QEMU/KVM guests) using 3D acceleration and imported buffers like mouse cursor images.

1e3b08de6327

Fix endless loop in i915 GEM busy ioctl during object destruction

The RCU-based fence iteration in i915_gem_busy_ioctl could loop forever if the GEM object was destroyed concurrently, because the fence list was freed without installing a new one. The fix corrects the RCU teardown order.

Why it matters: Prevents hangs in Intel GPU userspace when querying buffer busy status.

d2da6696e0c4

Fix spurious AMD GPU resets from wrong user queue timeout conversion

The hang detection timeout was stored in jiffies but converted again with msecs_to_jiffies(), shortening the window to about 500 ms and triggering false GPU resets. The fix passes jiffies directly.

Why it matters: Avoids unexpected GPU resets and queue disruptions for AMD GPU users.

cd195f1616b2

Fix Intel GPU display corruption on Xen PV dom0

On Xen PV, DMA buffers are not machine-contiguous, so bounce buffering broke Xe's coherency assumptions. Limiting SG segment size to PAGE_SIZE applies the same workaround i915 uses.

Why it matters: Stable display output for Xen PV users with Intel GPUs.

141008dec735

Fix VirtIO GPU data corruption and crash on fence allocation failure

Guest-bound transfers now sync shmem backing before returning data, and a NULL fence from allocation failure is properly checked, fixing stale data and a NULL pointer dereference.

Why it matters: Reliable VirtIO GPU operation in virtual machines.

598c1c3e8955846b3c64fe3e

Fix AMD display stream use-after-free on modeset failure

An extra reference put could drop the stream reference owned by the new CRTC state when color management setup failed, leading to premature stream release. The fix balances the reference count correctly.

Why it matters: Prevents potential crashes during modeset failures on AMD GPUs.

c5fd4eaad50d

Fix stale PSR2 selective fetch state on Intel displays

Selective fetch enable bits were not cleared when a plane was disabled while PSR2 sel fetch was off, causing the hardware to resume fetching for disabled planes and reserving DDB. The fix clears them on disable.

Why it matters: Avoids display corruption and resource waste on Intel GPUs with PSR2.

2777ec985227

Fix PCI BAR resize for devices on a root bus

The PCI core skipped reassigning device BARs after a resize when the device was directly on a root bus, leaving them unassigned. The fix ensures BARs are reassigned even without a bridge window to adjust.

Why it matters: Restores resizable BAR functionality (e.g., AMD Smart Access Memory) for GPUs and other devices attached directly to a root bus.

d58384c22739

Avoid NULL dereference when generating PCI bus properties

The dynamic OF helpers dereferenced pdev->subordinate without checking for NULL, which could cause a boot hang on systems with bridges lacking a secondary bus. They now generate 'bus-range' and 'interrupt-map' properties only when a subordinate bus exists.

Why it matters: Prevents early boot crashes on device-tree based systems with unconfigured PCI bridges.

8805840aad73

Extend Samsung LPM quirk to AMD SATA controllers

The existing Samsung low-power mode quirk only matched ATI controllers, but Samsung SSDs on AMD 600-series chipsets also time out during suspend. The quirk now applies to AMD controllers as well.

Why it matters: Fixes system suspend timeouts for Samsung SSDs (e.g., 870 QVO) on AMD platforms.

e6bae5034ef4

Fix KVM nested virtualization state page error handling

KVM now re-pends the GET_NESTED_STATE_PAGES request when page retrieval fails, preventing re-entry with stale PFNs, and fills kvm_run exit fields in common error paths so userspace receives correct exit information.

Why it matters: Improves stability and security for users of nested virtualization (e.g., running VMs inside VMs) by avoiding stale memory mappings and confusing exit reasons.

10180a277549c1214f293d77

Disable enhanced PCIe atomics on AMD NBIO 7.7/7.11 to prevent data corruption

AMD NBIO 7.7 and 7.11 controllers can corrupt 64-bit DMA transfers when PCIe enhanced atomics are enabled. The kernel now disables this feature on affected systems via SMN.

Why it matters: Prevents data corruption and system instability on affected AMD platforms during DMA transfers.

4fde44822512

Cache-aware scheduler fixes

LLC stands for last-level cache. These patches fix cache-aware load balancing: counters for LLC-preferring tasks now match the runnable set, active load balance honors the migrate_llc_task migration type, the cache group is decoupled from mm_struct to avoid a use-after-free, kernel threads are skipped, and LLC capacity is refreshed after CPU hotplug.

Why it matters: Prevents tasks from being moved away from their preferred LLC and avoids a scheduler use-after-free on multi-cache systems.

0d6526f82c3cd6013e2465d928f9c0e0a0b9b636fef85bda65efcccddc833cb0243767fd

Intel PEBS constraints and data-source corrections

PEBS is Intel's precise event-based sampling. This set fixes load/store direction for latency events on Gracemont, Crestmont, and Darkmont, removes incorrect data-source constraints on Lion Cove and Panther Cove, corrects Panther Cove snoop states, adds missing extra-register scheduling for precise memory events on DMR/NVL, constrains Panther Cove UOPS_DISPATCHED events, and renames offcore_rsp to offmodule_rsp on DMR/NVL.

Why it matters: Profiling samples from recent Intel CPUs should classify loads/stores and data sources more accurately, and the sysfs rename avoids tooling confusion.

89dc568e8c0be961d6db42d18302c5f475fa7c944595cc439f93d33ad65a0ac5d6ca2c3b04a7ef3b7aa3ff1621adfdd70102c8c7fdfcd4d9ccbad527

perf/core: task-context and branch-record fixes

Fixes a NULL pmu_ctx passed to armv8pmu_sched_task, makes sched_task() run for PMUs with only CPU-wide events so branch records do not leak across task boundaries, fills perf_branch_entry fields with one assignment to avoid uninitialized data in BRBE records, and fixes a refcount leak in attach_perf_ctx_data(). BRBE is Arm's hardware branch recording.

Why it matters: Prevents crashes and stale or uninitialized branch sampling data on Arm and x86.

36bb85cf36ca3d8d7410095424b620729e53cca4980630b3

perf/x86/intel: KVM guest PEBS MSR handling

When PEBS MSRs are switched between host and guest, the new code masks PERF_GLOBAL_CTRL with perf's desired value, avoids writing PEBS_ENABLED on CPUs that isolate PEBS, and skips DS_AREA/PEBS_DATA_CFG loads when PEBS is unused in the guest.

Why it matters: Avoids reserved bits and stuck PEBS_ENABLED states on VM-Entry/VM-Exit, and removes unnecessary MSR writes on VMX transitions.

cec38d5c098a4b64dbdc5861d06260e99eb9

x86/mce: preserve hardware debug registers across migration

The machine-check entry path saved and restored DR7 around user handling, but if the task migrated during scheduling, the restore ran on the wrong CPU. The save/restore pair is now CPU-local.

Why it matters: Prevents the new CPU's DR7 from being corrupted and the old CPU's DR7 from being left disabled.

b8d1d5b63a8e

sched/core: charge PSI IRQ time to the execution context

PSI stands for Pressure Stall Information. In proxy execution, the scheduling context can be a blocked donor while a different task burns CPU. IRQ time was charged to the donor's cgroup; it is now charged to rq->curr, the task actually running.

Why it matters: Makes PSI IRQ pressure attribution match the cgroup that is actually consuming CPU time.

a0bb6fac53fa

cgroup/cpuset: reject conflicting remote partitions

A remote partition created under a local partition could warn and then enable on CPUs already owned by the ancestor's subpartitions. It now returns PERR_NOCPUS instead of proceeding.

Why it matters: Prevents invalid exclusive-CPU partition configurations from being enabled.

31c88350b7dd

workqueue: avoid NULL current_pwq deref in flush dependency check

check_flush_dependency() can run on a kworker that is not currently executing a work item, such as when the worker thread is acting as pool manager during an OOM allocation. current_pwq is NULL in that state, so the dereference is now guarded.

Why it matters: Fixes a possible NULL pointer fault during memory-pressure handling.

db6365ced4d5

i2c: qcom-geni: select correct clock performance index

The Qualcomm GENI I2C driver wrote a hardcoded 0 into SE_GENI_CLK_SEL, which always selects the first clock performance-table entry. It now resolves the index that matches the actual source clock.

Why it matters: Avoids incorrect I2C bus frequencies on platforms where the matching entry is not at index 0.

cb97bf3d4f91

sched_ext: make BPF topology struct size-safe

scx_bpf_cid_topo() now takes a buffer size and copies the smaller of the BPF-provided buffer and the kernel's struct, with CO-RE relocation, so struct scx_cid_topo can grow without breaking existing BPF schedulers.

Why it matters: Prevents load failures or buffer overruns when the kernel-side struct grows.

94480606a677

debugfs: quiet false 'not initialized' warnings

Ref-tracker files created before debugfs is mounted triggered warnings even though the files appear later under /sys/kernel/debug/ref_tracker/. The warning is now suppressed for the error-parent case.

Why it matters: Removes two confusing boot-time errors on debugfs/ref_tracker builds.

77be3641f3e3

x86/sev: make vTPM SVSM calls preemption-safe

SVSM vTPM calls fetched the per-CPU calling-area address without disabling preemption. The fetch now happens inside the interrupt-disabled call protocol, so migration cannot leave the call using a stale per-CPU address.

Why it matters: Prevents wrong-CPU SVSM calls on AMD SEV-SNP systems using vTPM.

6c43c72748ff

Hardware support

New HID devices: Logitech, Steelseries, ELECOM

Added IDs for the Logitech G502 X Lightspeed in wired mode, the Steelseries Arctis 7 (2018) headset (with battery clamping), and the 2025 ELECOM EX-G M-XT4DRBK trackball (with a report descriptor fixup). Also corrected the bus type for the ELECOM M-XGL20DLBK so its special driver quirk actually matches.

Why it matters: These peripherals now get proper HID handling: battery reporting, button mapping, and driver quirks.

fce551616dfa7e749a797282f3c2b266b8fd8e2a4b458ad2

sfc: add X4D PF support

Adds support for the X4D controller, which is an X4 controller instance implemented as an IP block in an SoC, with the same feature set as the standalone X4.

Why it matters: Enables the Solarflare sfc driver on SoC platforms incorporating the X4D network controller IP block.

24fedc7a569b

Quectel EG120K-EA LTE and MeiG Smart SRM821 5G module support

The qmi_wwan driver gains support for the Quectel EG120K-EA LTE Cat.12 module, and the cdc_mbim driver adds the MeiG Smart SRM821 5G module to its ZLP conformance whitelist to prevent firmware crashes.

Why it matters: Users of these cellular modules can now use them for data connectivity without firmware crashes or unbound interfaces.

0f2fd31f63c6f75f21ef3628

Intel XWAY PHY 100BASE-TX link-up failure workaround

MaxLinear GSW1xx switches incorporating Intel XWAY PHYs can sporadically fail to link up in 100BASE-TX mode after power-on. The workaround enables then disables Cable Diagnostic Mode on all ports after power-on, as specified in the errata.

Why it matters: Users of Intel XWAY / MaxLinear GSW1xx Ethernet PHYs may experience faster or more reliable link-up at 100 Mbps after power-on.

b94773dc4df7

Performance

Speed up cgroup writeback cleanup with many inodes

cleanup_offline_cgwb() now rotates scanned inodes to avoid quadratic rescans, preventing soft lockups when draining dying cgroup writeback domains with millions of inodes.

Why it matters: Improves responsiveness on systems with heavy cgroup usage and large file counts.

f6988c90671e

Fix hibernation deadlocks by reordering kernel thread freeze

Hibernation memory preallocation was happening after kernel threads were frozen, and swap I/O can depend on those threads, causing intermittent deadlocks. This moves preallocation before freezing kernel threads.

Why it matters: More reliable hibernation for users who suspend to disk.

41112a787f91

Fix stale thermal mitigation vote with shared cooling devices

The step_wise governor could leave a cooling device active after a trip cleared when multiple thermal zones share it and one uses a non-zero lower bound. The fix corrects the target state calculation.

Why it matters: Better thermal management and power savings on systems with shared cooling devices.

ec0d89150a93

Security and hardening

Raw HCI socket security filter bypass via out-of-range OCF

The raw HCI socket security filter masked the 10-bit OCF with 127, allowing an unprivileged socket to submit a reserved OCF that aliases an allowlisted command modulo 128. The fix rejects OCF values the filter cannot represent.

Why it matters: An unprivileged process with raw HCI socket access could bypass the security filter to send commands that should be blocked.

e93fad891c72

SMP Security Request mishandled on BR/EDR causing headphone disconnects

Dual-mode devices such as Bose QC Ultra headphones can send an LE-style SMP Security Request over the BR/EDR fixed channel, which the kernel mistakenly processes as an LE link, causing the controller to reject LE_START_ENC and disconnect with authentication failure.

Why it matters: Users of certain Bluetooth dual-mode headphones may experience unexpected disconnections on BR/EDR links.

f033482d76a9

BNEP and RFCOMM frame processing out-of-bounds reads and crashes

Fixes multiple out-of-bounds reads and a control-frame fallthrough in BNEP processing that could leak heap memory on short frames, and fixes a NULL dereference and short-frame handling in RFCOMM.

Why it matters: Users of Bluetooth PAN (BNEP) and serial-port-over-Bluetooth (RFCOMM) profiles are protected against potential information leaks and crashes from malformed frames.

f0ca020cbb9b46f8ffd0a1f16d91041bb38b

mgmt race causes heap out-of-bounds write during controller setup

read_unconf_index_list() could count controllers before a flag transition makes them eligible, then write past the allocated response buffer during the fill pass. The fix allocates space for every device on the list.

Why it matters: Rapid controller setup could trigger a kernel heap out-of-bounds write.

b5dbb41b212c

Intel PCIe Bluetooth driver validates DMA-supplied indices

The btintel_pcie driver now bounds-checks device-controlled frbd_tag and cr_hia values used as array indices and loop counters, preventing out-of-bounds accesses from a malicious or malfunctioning device.

Why it matters: Systems with Intel Bluetooth PCIe adapters are protected against potential memory corruption from rogue firmware or device behavior.

37a111293453

L2CAP and HCI socket out-of-bounds reads from malformed frames/events

Short ERTM or streaming-mode L2CAP frames could cause out-of-bounds reads of control and FCS fields, and malformed HCI events could trigger OOB reads in the packet filter before event header validation.

Why it matters: A malicious or buggy Bluetooth controller or vhci device could trigger kernel memory reads past buffer boundaries.

6c78a213d907b0a6cf99afd5

Memory-reading kfuncs now require CAP_PERFMON

Tracing-related kfuncs such as bpf_rdonly_cast() and probe-read helpers were accessible with plain CAP_BPF, unlike their old-style BPF helper equivalents which require CAP_PERFMON. A new KF_PERFMON flag gates these kfuncs.

Why it matters: Unprivileged or CAP_BPF-only BPF programs can no longer read kernel memory via kfuncs that should require perfmon-level privileges.

88ce88e933e481c975aae375f9191460cd80

Unsound pruning of packet pointer ranges could allow out-of-bounds access

regsafe() did not preserve the displacement between registers sharing a packet pointer ID, so two individually narrower ranges could prune an explored path even when their relative displacement had changed, potentially accepting an out-of-bounds packet access.

Why it matters: A crafted BPF program could bypass verifier bounds checks and access packet data out of bounds.

fd16449a9b3b

CO-RE relocation ordering and poisoning hardening

CO-RE relocations are now applied before subprogram validation to prevent unresolved relocations from creating invalid control flow that breaks verifier invariants and can write past per-subprogram arrays. Poisoning is also restricted to valid relocatable instruction forms.

Why it matters: Closes a class of BPF verifier bugs where crafted CO-RE metadata could corrupt verifier state or bypass validation.

c26e97721b17394ae398337c

Global subprograms verified in wrong sleepability context

Global subprograms were always verified with the main program's sleepability state, but workqueue and task-work callbacks run in a sleepable context even when the program is not. This allowed RCU-protected kptrs to produce trusted pointers in non-RCU contexts.

Why it matters: A BPF program could retain RCU-protected kernel pointers outside of a valid RCU read-side critical section, leading to use-after-free.

40c2096961b4

Self-referential local kptrs could exhaust kernel stack

A self-referential or deeply chained local kptr type could cause bpf_obj_free_fields() to recurse arbitrarily deep and exhaust the kernel stack. The BTF checker now bounds ownership depth and rejects cycles with -ELOOP.

Why it matters: Prevents a local user with BPF access from crashing the kernel through crafted BTF type definitions.

bfc888f04588

Verifier fixes for stack offsets, dynptrs, arenas, and sockmap

Fixes non-negative stack offsets accepted for iterator state, skb-backed dynptr bounds underflow, arena ALU operations producing wrong results across code paths, and sockmap max_entries values causing signed integer overflow during cleanup.

Why it matters: These fixes prevent crafted BPF programs from corrupting or reading out-of-bounds memory, closing potential privilege-escalation vectors.

79a9172f3ab4ed6eec97b534f85f5917aa2f814a81c842bd

Dev-bound-only programs could run on unrelated devices

A bound-only BPF program with NULL offdev could match an unrelated netdev in __bpf_offload_dev_match(), allowing a veth-bound program to run on a tun device and read beyond tun's bare-stack xdp_buff as a veth_xdp_buff.

Why it matters: A privileged BPF user could crash the kernel by running driver-specific XDP metadata kfuncs against an incompatible device.

6db1ce73e985

Multiple NFC input-validation and use-after-free fixes

Multiple NFC drivers and the LLCP core had missing length checks allowing OOB reads, use-after-free on accept-queue races, WKS SAP hijacking via prefix match, and list corruption on DM handling.

Why it matters: Malformed NFC frames from a malicious peer or device could crash the kernel or bypass service-name access control; these fixes harden the NFC subsystem against a cluster of security-relevant bugs.

686f942332b1a653c01ce447bf1460acdf8c092c6a605cbdc3eef2f988a3dcab71a70119273f9d667cde66f4300206b8408cff6bd6067dcf371a3563b61732f47316

Fix BPF binfmt_misc interpreter selection race and out-of-bounds read

Two fixes close memory-safety holes in the BPF hooks that choose and configure interpreters for binfmt_misc. One prevents an out-of-bounds strcmp() when a BPF map value is concurrently modified, and the other prevents staged interpreter paths and arguments from being changed between validation and use.

Why it matters: Users relying on binfmt_misc with BPF programs get protection against local memory corruption and potential privilege escalation via race conditions.

4f948b5949d21970fc4ecb52

Reject iSCSI Data-In PDUs for write commands

The iSCSI initiator now verifies the data direction before processing a Data-In PDU, so a malicious or buggy target cannot write target-supplied data into the pages of a write command.

Why it matters: Protects iSCSI users from data corruption and potential security issues when connecting to untrusted storage targets.

bce07e2f37b5

Fix multiple use-after-free vulnerabilities in Nouveau

Three patches fix use-after-free bugs in Nouveau's VMM teardown, UVMM mapping, and scheduler lifetime, all reachable from userspace.

Why it matters: Nouveau users get improved stability and security; these bugs could crash the system or be exploited by local users.

97077ac87afe3359a372efb6f7eae6d8d768

Prevent shift overflow when mounting crafted SquashFS images

SquashFS now validates the XZ dictionary size before shifting, preventing a shift-out-of-bounds crash on malformed images.

Why it matters: Makes mounting untrusted SquashFS filesystems safer and avoids kernel crashes.

1f7745fb3580

Harden SMB client against malformed create contexts

Multiple fixes validate SMB create-context lengths and offsets, prevent out-of-bounds reads, preserve parsing errors, and close handles after parsing failures.

Why it matters: Protects SMB users against crafted responses from malicious servers that could crash the client or leak kernel memory.

67f4c1c6a1b5fa2e9900dd2a2e828035d5d7566820af017e

Fix kernel stack leak in GPIO character device error path

If the GPIO chip guard acquisition failed, the ioctl returned before zeroing the info structure, potentially leaking kernel stack contents to userspace. The fix propagates the error and moves the zeroing earlier.

Why it matters: Prevents information disclosure through /dev/gpiochip.

1feb5d39b05a

Fix missing inode locking in BPF LSM xattr kfuncs on path hooks

The BPF verifier assumed i_rwsem was held for path_unlink/path_rmdir and used the _locked variants of bpf_set/remove_dentry_xattr, but those hooks run before VFS takes the lock. The fix keeps the locking variants for those hooks.

Why it matters: Prevents race conditions and potential xattr corruption for sleepable BPF LSM programs attached to path_unlink/path_rmdir.

35d442ed1f86

Fix use-after-free when auditing newly loaded IPE policy

IPE audited a new policy after publishing it and dropping the directory inode lock, allowing a concurrent delete to free the policy. The audit now happens under the lock.

Why it matters: Eliminates a crash/security bug in IPE policy loading.

9814077275ec

Protect IPE dm-verity root hash with RCU

IPE could free a dm-verity root hash on ->preresume while policy evaluation was still dereferencing it. The hash is now RCU-protected.

Why it matters: Fixes a race condition in IPE's dm-verity trust provider, improving reliability and security.

2776e9c28513

Keep vCPUs from re-entering a dead VM

KVM previously could clear the KVM_REQ_VM_DEAD request, allowing a vCPU to attempt entry into a dead VM. The fix prevents clearing this request, ensuring vCPUs never re-enter a dead guest.

Why it matters: Hardens KVM against use-after-free and other bugs that could occur if userspace insists on re-running a vCPU after a fatal VM error.

8cd280282d12

Bound ATA pass-through sense descriptor writes to avoid buffer overrun

The ATA pass-through error path trusted a device-supplied sense length, allowing a faulty or malicious ATAPI device to cause out-of-bounds kernel buffer writes. The descriptor writes are now properly bounded.

Why it matters: Hardens the kernel against storage devices that return malformed sense data, preventing potential memory corruption when using tools like smartctl or hdparm.

80320b278fea

Source commits577 entries +
bd3a19800dd1

landlock: Add counted_by in landlock_domain

Tingmao Wang · Feb 8, 2026 · 1 files

d59ac79915da

selftests/filesystems: fix missing and stale TARGETS entries

Disha Goel · Jul 3, 2026 · 1 files

092c6a605cbd

nfc: port100: reject frames whose declared length exceeds the received data

Doruk Tan Ozturk · Jul 11, 2026 · 1 files

1f7745fb3580

squashfs: Add dictionary size range check to prevent shift-out-of-bounds

Ran Hongyun · Jul 13, 2026 · 1 files

686f942332b1

nfc: nfcmrvl: validate helper command length before pull

Pengpeng Hou · Jul 15, 2026 · 1 files

a653c01ce447

nfc: st21nfca: validate received frame size

Pengpeng Hou · Jul 15, 2026 · 1 files

bf1460acdf8c

nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()

Aldo Ariel Panzardo · Jul 16, 2026 · 1 files

3d8afc5243ea

selftests: nci: Correct pthread_create return value check

Lei Zhu · Jul 29, 2026 · 1 files

3022bdfe3e6d

drm/amdgpu: move userq fence wait out of signalling section

Prike Liang · Jul 31, 2026 · 3 files

aaad136d56d9

RISC-V: KVM: Synchronize hrtimer callback during teardown

Myeonghun Pak · Jul 31, 2026 · 1 files

34b8b2d78b62

remoteproc: qcom: q6v5_pas: Don't enable handover IRQ on attach

Shawn Guo · Aug 1, 2026 · 1 files

bce07e2f37b5

scsi: libiscsi_tcp: Check the data direction of a Data-In PDU

Yehyeong Lee · Aug 1, 2026 · 1 files

52c6b7d20d3e

RISC-V: KVM: Fix the conversion between vsip and hvip

Yicong Yang · Aug 4, 2026 · 4 files

aaaea79efba5

HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio

Lovekesh Solanki · Aug 4, 2026 · 1 files

8cd280282d12

KVM: Never clear KVM_REQ_VM_DEAD from a vCPU's requests

Sean Christopherson · Aug 6, 2026 · 5 files

fefd9480ec36

drm/nouveau: fix autosuspend cleanup during teardown

Guangshuo Li · Aug 8, 2026 · 1 files

6b1bca1b1ab7

KVM: arm64: Fix AArch32 DBGBXVR<n> handling

Karl Mehltretter · Aug 10, 2026 · 1 files

8ae12ccaec6e

RISC-V: KVM: Serialize IMSIC attributes with vCPU migration

Xie Bo · Aug 10, 2026 · 1 files

ed54fdb460a6

RISC-V: KVM: Release unused page after MMU invalidation

Xie Bo · Aug 10, 2026 · 1 files

f41fb17143df

RISC-V: KVM: Propagate interrupted G-stage faults

Xie Bo · Aug 10, 2026 · 2 files

36bb85cf36ca

perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()

Puranjay Mohan · Aug 10, 2026 · 1 files

3d8d74100954

perf/core: Run sched_task() for PMUs with only CPU-wide events

Puranjay Mohan · Aug 10, 2026 · 1 files

24b620729e53

perf/core: Fill branch entries with a single assignment

Puranjay Mohan · Aug 10, 2026 · 5 files

d12ce6bce5ec

s390/uv: Fix loop condition in uv_find_secrets

Steffen Eiden · Aug 12, 2026 · 1 files

f47190b08b71

s390/uv: Prevent potential out-of-bounds read

Steffen Eiden · Aug 12, 2026 · 1 files

a1a5ad37e50c

HID: winwing: fix use-after-free in force feedback teardown

René Onier · Aug 12, 2026 · 1 files

aa9dde93e05a

HID: alps: unregister DualPoint Stick input device on remove

Chen Changcheng · Aug 14, 2026 · 1 files

d3aba3442798

HID: alps: fix use-after-free on input2 registration failure

Chen Changcheng · Aug 14, 2026 · 1 files

10396a2d6d41

crypto: s390/hmac - Generate intermediate CV for API partial block handling

Holger Dengler · Aug 14, 2026 · 1 files

598c1c3e8955

drm/virtio: sync shmem backing on guest-bound transfers

Benjamin Leggett · Aug 14, 2026 · 3 files

64ca4cdd1031

drm/nouveau/dmem: pin VRAM for the whole registered range

Junrui Luo · Aug 17, 2026 · 1 files

8e2a4b458ad2

HID: elecom: fix bus type for M-XGL20DLBK

Oscar Priego Verdugo · Aug 17, 2026 · 1 files

692f32609a30

pinctrl: meson: Fix typo in s4 group name

Sean Anderson · Aug 17, 2026 · 1 files

1d00442cc469

HID: corsair-void: Fix firmware event packet description

Stuart Hayhurst · Aug 18, 2026 · 1 files

65e05ec252a9

s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config

Anthony Krowiak · Aug 18, 2026 · 1 files

d644b23afe1e

netfilter: flowtable: publish HW_DEAD after worker is done

Jérémy Jean · Aug 18, 2026 · 1 files

9db31edf92dd

remoteproc: qcom_q6v5_pas: Fix error masking in qcom_pas_stop()

Vignesh Viswanathan · Aug 19, 2026 · 1 files

18779dd84515

drm/amd/display: Bump frame warning limit for clang builds of dml

Ivan Lipski · Aug 21, 2026 · 1 files

8cd92f77ae4f

KVM: arm64: vgic-its: Free the caches when GITS_BASER changes

Fuad Tabba · Aug 21, 2026 · 1 files

30908e727247

Revert "KVM: arm64: vgic-its: Don't save collections the table cannot hold"

Fuad Tabba · Aug 21, 2026 · 1 files

cc5d96036e01

KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save

Fuad Tabba · Aug 21, 2026 · 1 files

6f182db39fb0

KVM: arm64: selftests: Add ITS table save tests

Fuad Tabba · Aug 21, 2026 · 2 files

b85385729358

remoteproc: qcom_q6v5_mss: Don't require PAS for memory protection

Paul Hollinsky · Aug 21, 2026 · 1 files

a363c62a653c

mm/hugetlb: do not dissolve gigantic pages without runtime support

Longlong Xia · Aug 23, 2026 · 1 files

cdb669a3b8f8

HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard

Junjie Cao · Aug 24, 2026 · 2 files

8b3fd1a8b305

RISC-V: KVM: Preserve firmware counter value across stop/start

SeungJu Cheon · Aug 25, 2026 · 1 files

057dd2639cea

RISC-V: KVM: Report snapshot write failure to the guest

SeungJu Cheon · Aug 25, 2026 · 1 files

c7e2cc38c561

RISC-V: KVM: Fix perf-backed counter accounting across stop and read

SeungJu Cheon · Aug 25, 2026 · 1 files

2a2eb10795a1

KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve()

Fuad Tabba · Aug 25, 2026 · 1 files

a1b3c788ad31

KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure

Fuad Tabba · Aug 25, 2026 · 1 files

0d62fbf34d8f

KVM: arm64: Key unpin_host_sve_state() on the state it unpins

Fuad Tabba · Aug 25, 2026 · 1 files

4f16c5fc8dc4

KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2

Fuad Tabba · Aug 25, 2026 · 1 files

b7749531a9b1

RISC-V: KVM: Fix sdata leak and stale snapshot_addr in snapshot_set_shmem

Zongmin Zhou · Aug 26, 2026 · 1 files

b3d346838ec6

KVM: riscv: Fix NACL hfence entry update order

Zongmin Zhou · Aug 26, 2026 · 1 files

f13368e0acff

KVM: selftests: Use __GLIBC__, not _GNU_SOURCE, to detect actual glibc

Sean Christopherson · Aug 26, 2026 · 1 files

31fe2cb51133

HID: fix semantic patch and improve its performance

Julia Lawall · Aug 27, 2026 · 1 files

0d8e2195bce6

remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage

Mostafa Saleh · Aug 27, 2026 · 1 files

c3a31087b1c8

drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping

Asad Kamal · Aug 28, 2026 · 1 files

6947b78df4d2

drm/virtio: Add pixel blend mode property to cursor plane

Shixiong Ou · Aug 28, 2026 · 1 files

d215f014b352

KVM: s390: Fix dirty marking in adapter_indicators_set*()

Claudio Imbrenda · Aug 28, 2026 · 1 files

ae12d2f9c119

KVM: s390: Fix compile warning for kvm_s390_update_cmma_dirty()

Claudio Imbrenda · Aug 28, 2026 · 2 files

faff4c8ff3db

KVM: s390: Fix _gaccess_shadow_fault()

Claudio Imbrenda · Aug 28, 2026 · 1 files

00c0ae5e4386

KVM: s390: Refactor dat_set_slot()

Claudio Imbrenda · Aug 28, 2026 · 3 files

19192a404327

KVM: s390: Move all code into s390_kvm_mmu_prepare_memory_region()

Claudio Imbrenda · Aug 28, 2026 · 3 files

f3a557067d57

KVM: s390: Add missing srcu in kvm_s390_set_irq_state()

Claudio Imbrenda · Aug 28, 2026 · 1 files

27554b9505dd

KVM: s390: Fix potential races in dat skey functions

Claudio Imbrenda · Aug 28, 2026 · 1 files

4ca00a9154f9

KVM: s390: Fix race in _destroy_pages_crste()

Claudio Imbrenda · Aug 28, 2026 · 1 files

b43beccb3713

ovpn: always unhash old VPN addresses before rehashing

Ralf Lici · Aug 28, 2026 · 1 files

d25e885b31a0

ovpn: reject duplicate peer VPN addresses

Ralf Lici · Aug 28, 2026 · 3 files

025af3a0a892

ovpn: reject multipeer peers without VPN addresses

Ralf Lici · Aug 28, 2026 · 1 files

5940f3407b78

ovpn: reject invalid peer VPN addresses

Ralf Lici · Aug 28, 2026 · 1 files

006208026819

selftests: ovpn: validate peer VPN addresses

Ralf Lici · Aug 28, 2026 · 3 files

7a6d08ee0f0e

ovpn: preserve IPv6 scope id for netlink peer endpoints

Ralf Lici · Aug 28, 2026 · 1 files

77393b4d72df

ovpn: skip UDP source validation for unspecified addresses

Ralf Lici · Aug 28, 2026 · 1 files

7c66b7a4ae80

ovpn: track UDP socket route key for peer dst cache

Ralf Lici · Aug 28, 2026 · 3 files

fa603710bdb9

ovpn: validate peer state before caching UDP dst

Ralf Lici · Aug 28, 2026 · 1 files

aea934a221ec

ovpn: replace bind when learning local endpoint

Ralf Lici · Aug 28, 2026 · 1 files

7d8104988f42

ovpn: replace bind when clearing stale local source

Ralf Lici · Aug 28, 2026 · 1 files

51ae99659469

pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()

Sarah Emery · Aug 28, 2026 · 1 files

64dc6f1db7e6

KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0

Karl Mehltretter · Aug 29, 2026 · 1 files

0a46eb5719fa

KVM: arm64: selftests: Test empty SMCCC filter range at base 0

Karl Mehltretter · Aug 29, 2026 · 1 files

b0be01f133aa

pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions

Shawn Guo · Aug 30, 2026 · 2 files

7f2ea5ed588c

nfc: st21nfca: validate ISO15693 inventory length

Pengpeng Hou · Aug 30, 2026 · 1 files

e6c5d6c58976

pinctrl: mpfs-mssio: fix width of unused bank voltage setting

Conor Dooley · Aug 31, 2026 · 1 files

8039b75af580

pinctrl: mpfs-mssio: use correct regmap function to set bank voltage

Conor Dooley · Aug 31, 2026 · 1 files

42d1221d321e

scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()

Bart Van Assche · Aug 31, 2026 · 1 files

fce551616dfa

HID: logitech-hidpp: Add support for G502 X Lightspeed USB mouse

Andres Diaz · Sep 1, 2026 · 1 files

eda518d2cdb6

selftests: nci: Fix uninitialized family ID on missing attribute

Chaithanya Lagisetty · Sep 1, 2026 · 1 files

38b70fc453c3

KVM: arm64: Fix spurious warning for benign stage 2 teardown race

Lorenzo Stoakes (ARM) · Sep 1, 2026 · 1 files

4c74e233cded

KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race

Lorenzo Stoakes (ARM) · Sep 1, 2026 · 1 files

7e749a797282

HID: steelseries: Add support for Arctis 7 (2018)

Erik Håkansson · Sep 1, 2026 · 4 files

089e4f3c4862

KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP

Mark Brown · Sep 1, 2026 · 1 files

f7eae6d8d768

drm/nouveau: RCU-free the scheduler-containing nouveau_sched

Jonghyuk Kim(MalHyuk) · Sep 2, 2026 · 2 files

d76994443eed

HID: roccat: fix locking in roccat_connect() and roccat_disconnect()

Dmitry Antipov · Sep 2, 2026 · 1 files

c3eef2f988a3

nfc: llcp: Fix race condition in accept_queue lifecycle

Lee Jones · Sep 2, 2026 · 3 files

0d7823cd4cda

bpf: Allow terminal gotox instructions

Siddharth Chintamaneni · Sep 2, 2026 · 1 files

ac781acaef49

selftests/bpf: Test terminal gotox instructions

Siddharth Chintamaneni · Sep 2, 2026 · 1 files

79a71cc2568f

KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr()

Jim Mattson · Sep 2, 2026 · 2 files

8c7fdc0b4c64

selftests/cgroup: account for zswap shrinker writeback

Joshua Hahn · Sep 2, 2026 · 1 files

9461613afc59

netfilter: nfnetlink_queue: hold nfnl mutex in event notifier

Florian Westphal · Sep 3, 2026 · 1 files

953824e508b2

bpf: Fix u32 overflow issue in map batch operations

Masoud Aghasi · Sep 3, 2026 · 2 files

a13f7f5d14af

pinctrl: sunxi: keep a shadow copy of the data register output latches

Ilya Titov · Sep 3, 2026 · 2 files

75f8cf22463d

bpf: Fix out-of-bounds read of rtt_min in sock_ops

Jiayuan Chen · Sep 3, 2026 · 1 files

7d70a0b02d26

bpf: Use kvfree() in xdp_test_run_teardown()

Zhixing Chen · Sep 3, 2026 · 1 files

d2da6696e0c4

drm/i915: fix incorrect RCU teardown order

Christian König · Sep 3, 2026 · 1 files

77be3641f3e3

debugfs: don't warn about uninitialized debugfs for an error parent

Mikhail Gavrilov · Sep 3, 2026 · 1 files

8d50c2f37bcc

mailmap: update Haowen Bai's email address

Haowen Bai · Sep 3, 2026 · 1 files

58d97b45f3f4

HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device

Youth Cao · Sep 3, 2026 · 1 files

f166586f74dd

mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()

Nathan Gao · Sep 4, 2026 · 1 files

ada667890773

drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach

Li Youhong · Sep 4, 2026 · 1 files

525c0edc032b

ocfs2: make ocfs2_calc_xattr_init() return void

Joseph Qi · Sep 4, 2026 · 3 files

6be581aeffc2

selftests/nci: Fix out-of-bounds store on thread join

Chris Gellermann · Sep 4, 2026 · 1 files

abd24922c2a9

HID: hid-oxp: use cancel_delayed_work_sync() in remove

Tristan Madani · Sep 4, 2026 · 1 files

c16b885ad6b5

xfs: remove unused xfs_reflink_remap_range declaration

Anuj Gupta · Sep 4, 2026 · 1 files

9d1e523b92d8

selftests/hid: add define for commonly used buf size

Benjamin Tissoires · Sep 4, 2026 · 2 files

c4afa4862b87

HID: bpf: fix __hid_bpf_hw_check_params report length

Benjamin Tissoires · Sep 4, 2026 · 1 files

b6f69097c827

selftests/hid: add unnumbered variant to the hid_bpf tests

Benjamin Tissoires · Sep 4, 2026 · 3 files

51814683e28f

nfc: virtual_ncidev: Add missing ioctl compat handler

Chris Gellermann · Sep 4, 2026 · 1 files

1c21452d02ee

bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk

Pu Lehui · Sep 5, 2026 · 1 files

447dcff90557

pinctrl: qcom: ipq5210: Publish the OF module alias

hpp.iscas · Sep 5, 2026 · 1 files

1b9b5323725e

netfilter: ip6t_rpfilter: reject routes without inet6_dev

Weiming Shi · Sep 6, 2026 · 1 files

b7403afb7a5f

arm64: errata: match the target implementation CPU's own MIDR

David Carlier · Sep 6, 2026 · 1 files

82313c169edd

netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read

Luxiao Xu · Sep 6, 2026 · 1 files

5271d81f99dd

drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1

Ankit Nautiyal · Sep 7, 2026 · 1 files

1fca688e9443

drm/client: fix restore of partially initialized client

shechenglong · Sep 7, 2026 · 1 files

3359a372efb6

drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM

Peiyang He · Sep 7, 2026 · 1 files

4525a9110495

s390/pci/docs: Fix sriov_numvfs attribute name

Karl Mehltretter · Sep 7, 2026 · 1 files

2f91fc9a96cd

s390: Fix typos in comments

Hemanth Selam · Sep 7, 2026 · 4 files

692dd08e03f4

MAINTAINERS: update Xu Xin's email

Xu Xin · Sep 7, 2026 · 2 files

3b55f350c68a

bpf: Fix bpf_skb_change_tail wrt csum partial skbs

Daniel Borkmann · Sep 7, 2026 · 1 files

15e2565f1c43

selftests/bpf: Add test for bpf_skb_change_tail on csum partial skbs

Daniel Borkmann · Sep 7, 2026 · 2 files

ef1fb82f1218

bpf, arm64: set up the frame pointer for the exception callback

Donggeun Yoo · Sep 7, 2026 · 1 files

26a43a5f8c31

selftests/bpf: cover the exception callback using its own BPF stack

Donggeun Yoo · Sep 7, 2026 · 2 files

39c0ceedd545

mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()

SJ Park · Sep 7, 2026 · 1 files

acbe9a3b60b9

drm/i915/dp_mst: Fix configuring FEC for a disconnected stream

Imre Deak · Sep 7, 2026 · 1 files

a443e0b8d647

drm/i915/dp_mst: Fix configuring TUs for a disconnected stream

Imre Deak · Sep 7, 2026 · 3 files

f3c2b266b8fd

HID: elecom: Add support for ELECOM M-XT4DRBK (018E)

Berke Durak · Sep 7, 2026 · 3 files

44fcc0bfb087

MAINTAINERS: add Baoquan and Baolin as MGLRU reviewers

Baolin Wang · Sep 8, 2026 · 1 files

490a83d6386e

bpf, sockmap: Fix self-redirect copied_seq double-counting

Geliang Tang · Sep 8, 2026 · 1 files

3a8c562892b9

KVM: arm64: Transfer the hyp stack pages out of the host stage-2

Fuad Tabba · Sep 8, 2026 · 1 files

5a8b505ede13

KVM: arm64: Match hyp text by physical address in fix_host_ownership()

Fuad Tabba · Sep 8, 2026 · 3 files

224584140114

KVM: arm64: Move the private VA allocation cursor to __io_map_next

Fuad Tabba · Sep 8, 2026 · 1 files

cfe80c3837f9

KVM: arm64: Check every private mapping is hyp-owned at pKVM init

Fuad Tabba · Sep 8, 2026 · 5 files

b74aad23d99b

drm/virtio: fix memory leak of fence event on execbuffer failure

Peiyang He · Sep 8, 2026 · 1 files

b6ac0b3f6013

mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish

Jinjiang Tu · Sep 8, 2026 · 2 files

b3723b596b54

mm/damon/core: fix unconditionally skip last region

Liew Rui Yan · Sep 8, 2026 · 1 files

90179da203ba

mm/damon/core: allow esz to be set to zero

Liew Rui Yan · Sep 8, 2026 · 1 files

7dcf371a3563

nfc: llcp: fix slab-out-of-bounds reads when logging service names

Ömer Mete Kaya · Sep 8, 2026 · 2 files

4fde44822512

x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11

Mario Limonciello · Sep 8, 2026 · 1 files

9aa237cf6649

HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()

Wei Jie LAW · Sep 9, 2026 · 1 files

e4a62833adff

bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL

Weiming Shi · Sep 9, 2026 · 1 files

dcab71a70119

nfc: fix use-after-free in nfc_get_local_general_bytes

Luxiao Xu · Sep 9, 2026 · 12 files

57a78ad2305f

block: Fix start and length check added to iov_iter_extract_bvecs()

David Howells · Sep 9, 2026 · 1 files

1abd643f3783

fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbot's "WARNING in do_new_mount" saga

Christian Brauner · Sep 9, 2026 · 1 files

846b3c64fe3e

drm/virtio: fix NULL pointer dereference on fence allocation failure

Peiyang He · Sep 9, 2026 · 1 files

d22c3e0088e8

selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc

Sven Schnelle · Sep 9, 2026 · 1 files

2777ec985227

drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable

Nemesa Garg · Sep 9, 2026 · 4 files

ea4debcd8016

drm/xe/gt_throttle: Report power brake as a throttle reason on CRI

Sk Anirban · Sep 9, 2026 · 2 files

408cff6bd606

nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()

Ömer Mete Kaya · Sep 9, 2026 · 1 files

c04981e42d94

nfc: llcp: fix -ENOMEM on connect with zero-length service name

Ömer Mete Kaya · Sep 9, 2026 · 1 files

85136bf22404

bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()

Jose Fernandez (Anthropic) · Sep 9, 2026 · 1 files

407a5d205179

writeback: report a Tasks-RCU quiescent state per cgwb drain pass

Josef Bacik · Sep 9, 2026 · 1 files

2d2a2d7aa987

super: make iterate_supers_type() deletion-safe

Christian Brauner · Sep 9, 2026 · 2 files

5b644229bd67

xfs: guard against igrab failure in xrep_findparent_from_dcache

Darrick J. Wong · Sep 10, 2026 · 1 files

afbccf99f7f8

xfs: don't assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption

Darrick J. Wong · Sep 10, 2026 · 1 files

bb991b7f79dd

xfs: fix attr fork block count checks in xrep_inode_blockcounts

Darrick J. Wong · Sep 10, 2026 · 1 files

1c32cdc98646

xfs: release orphanage dir inode if chown fails

Darrick J. Wong · Sep 10, 2026 · 1 files

8b4ad2814274

xfs: release AGFL after walking it during rmapbt repair

Darrick J. Wong · Sep 10, 2026 · 1 files

984aab2d905a

xfs: use correct jiffies comparison function in xchk_maybe_relax

Darrick J. Wong · Sep 10, 2026 · 1 files

39e8e085710a

HID: i2c-hid: add reset quirk for Lenovo Yoga Slim 7x Gen 11 keyboard

Oleg Keri · Sep 10, 2026 · 2 files

29d9e5835d89

s390/cio: Fix cio_update_schib() to not cache invalid schib

Vineeth Vijayan · Sep 10, 2026 · 1 files

f6f2985eabdb

s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points

Vineeth Vijayan · Sep 10, 2026 · 1 files

9590f4d83880

s390/cio: Guard PMCW field accesses with dnv check

Vineeth Vijayan · Sep 10, 2026 · 5 files

01b245ba016d

bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()

Jiayuan Chen · Sep 10, 2026 · 1 files

eaab8cab451b

tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context

Jiayuan Chen · Sep 10, 2026 · 1 files

8036d3a5a658

selftests/bpf: Test bpf_sock_destroy() on TIME_WAIT and listener socks

Jiayuan Chen · Sep 10, 2026 · 2 files

b0b3dc665296

bpf: Fix divide-by-zero in btf_struct_walk()

Jiayuan Chen · Sep 10, 2026 · 1 files

f77d21245710

selftests/bpf: Test BTF walk into a flexible array of zero-sized elements

Jiayuan Chen · Sep 10, 2026 · 2 files

eb6494824978

mm/damon/core: reset invalid quota->charge_target_from

SJ Park · Sep 10, 2026 · 1 files

70504de0bb62

xsk: Use a 32-bit compare in xsk_map_gen_lookup

Zhiling Zou · Sep 10, 2026 · 1 files

2936aed9b021

bpf: Clear scalar delta on narrowing stack spill

Daniel Borkmann · Sep 10, 2026 · 1 files

a311a8981727

netfilter: nft_synproxy: use the family-aware checksum helper

Karl Mehltretter · Sep 10, 2026 · 1 files

88ce88e933e4

bpf: Add KF_PERFMON kfunc flag

Daniel Borkmann · Sep 10, 2026 · 3 files

81c975aae375

bpf: Require CAP_PERFMON for kfuncs reading memory

Daniel Borkmann · Sep 10, 2026 · 1 files

f9191460cd80

bpf: Require CAP_PERFMON for untrusted read-only memory reads

Daniel Borkmann · Sep 10, 2026 · 1 files

a903f145a891

selftests/bpf: Add tests for the KF_PERFMON gates

Daniel Borkmann · Sep 10, 2026 · 2 files

bb756b11ad63

arm64: io: Reject non-user protection in ioremap_prot()

Zeng Heng · Sep 11, 2026 · 1 files

3083ba8dde76

xfs: check padding field in xfs_ioc_commit_range

Darrick J. Wong · Sep 11, 2026 · 1 files

8fc18580ec17

xfs: don't call xfs_exchange_range_finish for a dry run

Darrick J. Wong · Sep 11, 2026 · 1 files

471e0b6e2dda

xfs: use the correct reservations for rtrmap/refcount recovery

Darrick J. Wong · Sep 11, 2026 · 2 files

46c1b6674a7b

xfs: fix integer overflows in xbitmap set functions

Darrick J. Wong · Sep 11, 2026 · 1 files

c54110d814c3

xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks

Darrick J. Wong · Sep 11, 2026 · 1 files

e9193f2f1ce3

xfs: check di_forkoff correctly in scrub

Darrick J. Wong · Sep 11, 2026 · 1 files

2f3c2a6f963e

xfs: fix typos and repeated words in comments

Hemanth Selam · Sep 11, 2026 · 17 files

651010592bdc

net: txgbe: fix FDIR filter restore for VF rules

Zhang Yunfei · Sep 11, 2026 · 1 files

e29014556488

ipvs: revalidate ihl before icmp_send

Julian Anastasov · Sep 11, 2026 · 1 files

1e3b08de6327

Revert "drm/virtio: Allow importing prime buffers when 3D is enabled"

Dmitry Osipenko · Sep 11, 2026 · 1 files

33346f8960c7

KVM: arm64: nv: Fix life cycle of the nested_mmus array

Marc Zyngier · Sep 11, 2026 · 4 files

e5843f4effaa

KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction

Marc Zyngier · Sep 11, 2026 · 3 files

baaa9b126b87

arm64: Add override for WFxT

Yureka Lilian · Sep 11, 2026 · 2 files

f6988c90671e

writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes

Patrick Lu (Anthropic) · Sep 11, 2026 · 1 files

207d591c3532

netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name

Naman Gulati · Sep 12, 2026 · 1 files

b52d695d0620

scsi: ufs: core: Keep internal commands dispatchable during error handling

Stanley Jhu · Sep 12, 2026 · 1 files

1d9bb9c87063

pinctrl: single: free the IRQ on domain creation failure

Myeonghun Pak · Sep 13, 2026 · 1 files

d2acbde7e67d

nfc: trf7970a: power down on startup RX gain failure

Myeonghun Pak · Sep 13, 2026 · 1 files

99cc2a62e07a

tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow

Eric Dumazet · Sep 13, 2026 · 1 files

4485a01f4df1

parisc: unwind: Replace open-coded binary search with bsearch()

Sean Young · Sep 13, 2026 · 1 files

6c43c72748ff

x86/sev: Make vTPM SVSM calls preemption-safe

Melody Wang · Sep 14, 2026 · 1 files

39c6580765da

octeontx2-af: use seq_file for rsrc_alloc debugfs

Heyang Tan · Sep 14, 2026 · 1 files

41e81f7e3ef9

RISC-V: KVM: Fix HSM hart status error propagation

Tan Chi · Sep 14, 2026 · 1 files

c82b797abe66

net/sched: reject IDR error pointers when deleting actions

Weiming Shi · Sep 14, 2026 · 1 files

ce2b91bebc7b

xfs: remove duplicate INO1_WRITTEN check

Jiangshan Yi · Sep 14, 2026 · 1 files

72b782097e53

accel/ivpu: Use separate flag for job timeout

Jakub Pawlak · Sep 14, 2026 · 5 files

49d9d295d69d

KVM: arm64: Don't WARN on an unknown VM ioctl in protected mode

Fuad Tabba · Sep 14, 2026 · 1 files

65bcc5f89704

HID: amd_sfh: Validate PCI BAR size before mapping

Slawomir Stepien · Sep 14, 2026 · 2 files

ef56085dfd1d

pinctrl: sunxi: A523: fix voltage withstand encoding

Andre Przywara · Sep 14, 2026 · 4 files

14e379600d3e

xfs: don't try to get a reference to a NULL oz in xfs_get_cached_zone

Christoph Hellwig · Sep 14, 2026 · 1 files

70194dc37670

netfilter: nf_tables: skip expired catchall elements on insert and delete

Aohan Mei · Sep 14, 2026 · 1 files

66f4300206b8

nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure

Cong Nguyen · Sep 14, 2026 · 1 files

96e6757cb067

KVM: selftests: fix steal_time for arm64 with host page size > 4K

Sebastian Ott · Sep 14, 2026 · 1 files

40c2096961b4

bpf: Verify global subprogs in each sleepability context

Kumar Kartikeya Dwivedi · Sep 14, 2026 · 2 files

a452e729b7be

selftests/bpf: Test global subprog callback contexts

Kumar Kartikeya Dwivedi · Sep 14, 2026 · 1 files

9bdad082d44b

mm/hugetlb: preserve mremap address delta when skipping page tables

Jaewook You · Sep 14, 2026 · 1 files

bfc888f04588

bpf: Bound ownership depth through local kptrs and graph roots

Kumar Kartikeya Dwivedi · Sep 14, 2026 · 2 files

0288ed67482b

selftests/bpf: Check local object ownership depth

Kumar Kartikeya Dwivedi · Sep 14, 2026 · 1 files

c9ee65113326

scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction

Geert Uytterhoeven · Sep 14, 2026 · 1 files

fc3ae66514ca

netfs: Fix netfs_read_gaps() to use separate sink folios

David Howells · Sep 14, 2026 · 1 files

50e80e2bb5e2

bpf: Skip unsettled links in link iterator

Weiming Shi · Sep 14, 2026 · 1 files

1b82958f3f03

net: ethtool: keep rtnl_lock for the ioctl self test

Alexander Duyck · Sep 14, 2026 · 4 files

1f4c73064a50

eth: fbnic: Handle maximum standalone channels

Björn Töpel · Sep 14, 2026 · 1 files

b5d9e9d4d0c1

eth: fbnic: use the Rx queue napi pointer to find the napi vector

Alexander Duyck · Sep 14, 2026 · 1 files

4bcc4a92c603

eth: fbnic: reset num_napi when the napi vectors are freed

Alexander Duyck · Sep 14, 2026 · 1 files

8947f13e436a

eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox

Alexander Duyck · Sep 14, 2026 · 2 files

1b97a269a5bd

eth: fbnic: Handle FW mailbox completions flagged with an error

Alexander Duyck · Sep 14, 2026 · 4 files

c7a925c84704

drm/xe/tlb_inval: Treat wedged-device invalidations as complete

Shuicheng Lin · Sep 14, 2026 · 1 files

9d565b6b72fe

net: usb: catc: bound the RX packet length in catc_rx_done()

Aamir Ahmed · Sep 14, 2026 · 1 files

02af7eac17bc

gpio: mvebu: keep resume masks within the irqchip cache

Rosen Penev · Sep 15, 2026 · 1 files

7459c0218742

fs: avoid repeated scans in evict_inodes()

Julian Sun · Sep 15, 2026 · 1 files

37a111293453

Bluetooth: btintel_pcie: validate device-supplied DMA indices

Ravindra · Sep 15, 2026 · 1 files

065f3ce5936e

xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits

Darrick J. Wong · Sep 15, 2026 · 1 files

41c4c41cf6c4

xfs: fix rtgroup repair estimations

Darrick J. Wong · Sep 15, 2026 · 2 files

d7b92cbe566f

xfs: don't cross reference rmapbt with bitmaps if they're incomplete

Darrick J. Wong · Sep 15, 2026 · 1 files

ab1c416d2377

xfs: don't let memory failures leak blocks and kill repairs

Darrick J. Wong · Sep 15, 2026 · 1 files

d80993655f7b

xfs: don't merge different file IO error types

Darrick J. Wong · Sep 15, 2026 · 1 files

f8f6382ff131

xfs: fix blockgc group quota scanning when usrquota isn't enforced

Darrick J. Wong · Sep 15, 2026 · 1 files

65f39d09d737

xfs: fix cursor and pointer handling when recovering iunlink buckets

Darrick J. Wong · Sep 15, 2026 · 1 files

ffb48dccce19

xfs: drop dquot flush lock when we can't find a buffer to flush

Darrick J. Wong · Sep 15, 2026 · 1 files

476582d754cd

xfs: don't let hidden_space go negative in xfs_metafile_resv_init

Darrick J. Wong · Sep 15, 2026 · 1 files

fe2f9135df43

xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots

Darrick J. Wong · Sep 15, 2026 · 1 files

36570ef2244c

drm/virtio: fix object leak when drm_gem_handle_create() fails

Junrui Luo · Sep 15, 2026 · 1 files

477bc3068fc3

drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()

Junrui Luo · Sep 15, 2026 · 1 files

24b6d5c76414

drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()

Junrui Luo · Sep 15, 2026 · 1 files

036d28db1818

drm/virtio: release the GEM object on virtio_gpu_vram_create() errors

Junrui Luo · Sep 15, 2026 · 1 files

ab888242fce4

vlan: require the MAC header to be present in __vlan_insert_inner_tag()

Xiang Mei · Sep 15, 2026 · 1 files

d2c31b837406

sctp: avoid livelock while updating retransmit path

Yiqi Sun · Sep 15, 2026 · 1 files

8e0b235bd918

eth: fbnic: Fix payload page pool error cleanup

Björn Töpel · Sep 15, 2026 · 1 files

d09e8f64653c

net/mlx5: devcom, Base component size on linked devices

Shay Drory · Sep 15, 2026 · 1 files

e1e29ada2b93

net/mlx5: SD, unload reps on shared FDB create error path

Shay Drory · Sep 15, 2026 · 1 files

bae23d1ae620

net/mlx5: LAG, reload IB reps of LAG master before the rest

Shay Drory · Sep 15, 2026 · 1 files

71af682ba469

Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel

Lee Jones · Sep 15, 2026 · 1 files

406aa2b186d3

perf/arm-cmn: Fix multi-filter encoding

Robin Murphy · Sep 15, 2026 · 1 files

ba13f1f32d96

mm: memblock: add missing HugeTLB flag name

Meijing Zhao · Sep 15, 2026 · 1 files

2566866fc309

net: gue: reject invalid REMCSUM offsets

Jérémy Jean · Sep 15, 2026 · 1 files

47abe7a5c4eb

net/sched: act_ct: don't WARN on benign flow_offload_alloc() failure

Nguyen Ngoc Thang · Sep 15, 2026 · 1 files

b5dbb41b212c

Bluetooth: mgmt: fix race in read_unconf_index_list()

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

6c78a213d907

Bluetooth: L2CAP: validate frame length before control and FCS access

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

b0a6cf99afd5

Bluetooth: hci_sock: validate event length before filtering

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

4c94557dd025

Bluetooth: ISO: balance the parent hold in hci_bind_bis()

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

e93fad891c72

Bluetooth: hci_sock: reject out-of-range OCF values

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

e06d549fcd4a

Bluetooth: hci_conn: fix CIS hold ownership on reuse

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

0fcd4dad555c

Bluetooth: ISO: release unused CIS holds after channel attach

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

bb2635be7646

drm/i915/dp: use EXPORT_SYMBOL_IF_KUNIT() for kunit helpers

Jani Nikula · Sep 15, 2026 · 2 files

c51e89c5b5db

netfs, afs: Fix symlink reading

David Howells · Sep 15, 2026 · 1 files

2ec28c09b320

vsock: ignore empty child namespace mode writes

Aldo Ariel Panzardo · Sep 15, 2026 · 1 files

f06a44e235ef

scsi: devinfo: Add BLIST_SKIP_IO_HINTS for EMC Symmetrix

Ewan D. Milne · Sep 15, 2026 · 1 files

daf677c2c644

net: pcs: rzn1-miic: Fix config array initialization

Kyle Hendry · Sep 15, 2026 · 1 files

382e5d514b6f

KVM: Ensure memory attributes xarray nodes are accounted to the caller's memcg

David Ballesteros · Sep 15, 2026 · 1 files

273f9d667cde

nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()

Aamir Ahmed · Sep 15, 2026 · 1 files

c4e941bb7654

landlock: Work around gcc-16 -Wuninitialized warning

Arnd Bergmann · Sep 15, 2026 · 1 files

c0078f4d8c8f

mailmap: add entry for Wei Wang

Wei Wang · Sep 15, 2026 · 1 files

278210c60c6f

scsi: leapraid: Avoid -Wformat-security warning

Arnd Bergmann · Sep 15, 2026 · 2 files

6c096bb08de9

net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset

Quentin Armitage · Sep 15, 2026 · 1 files

7de9a6fb44ea

sched_ext: Wait for SCX_OPSS_DISPATCHING before reenqueueing a task

Tejun Heo · Sep 15, 2026 · 3 files

f2bbb3642658

Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump()

Zijun Hu · Sep 16, 2026 · 1 files

d06f2ebf67ff

octeontx2-af: Fix memory scaling limitation in SR-IOV mode

Ratheesh Kannoth · Sep 16, 2026 · 1 files

ae2c5bf96957

pinctrl: tegra238: Fix register bank for AON pin groups

Prathamesh Shete · Sep 16, 2026 · 1 files

e9d810279f84

gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()

Wentao Liang · Sep 16, 2026 · 1 files

c5fd4eaad50d

drm/amd/display: Fix dc stream excess put in dm_update_crtc_state()

Wentao Liang · Sep 16, 2026 · 1 files

a997baa61179

drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc()

Wentao Liang · Sep 16, 2026 · 1 files

b4f7b4459b1b

drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()

Wentao Liang · Sep 16, 2026 · 1 files

2b86ab1bd667

drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()

Wentao Liang · Sep 16, 2026 · 1 files

0a5f5d9e94de

net/sched: cls_u32: fix manual hash table handle IDR aliasing

Jamal Hadi Salim · Sep 16, 2026 · 1 files

960ab631f3d8

selftests/tc-testing: add u32 manual table handle IDR tests

Jamal Hadi Salim · Sep 16, 2026 · 1 files

aea841bc62a7

drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()

Wentao Liang · Sep 16, 2026 · 1 files

90f467577ebc

drm/xe: harden adjust_idledly() against divide-by-zero and overflow

Tangudu Tilak Tirumalesh · Sep 16, 2026 · 1 files

cc319238e3f6

drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms

Tangudu Tilak Tirumalesh · Sep 16, 2026 · 3 files

97077ac87afe

drm/nouveau: fix double-free in nvif_vmm_dtor

Peiyang He · Sep 16, 2026 · 2 files

46bc52d13594

ipv4: fib: fix data-race and stale genid check around nh->nh_saddr

Linkui Xiao · Sep 16, 2026 · 1 files

24fedc7a569b

sfc: add X4D PF support

Andy Moreton · Sep 16, 2026 · 1 files

310d1ac61a4d

net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure

Lorenzo Bianconi · Sep 16, 2026 · 1 files

f033482d76a9

Bluetooth: SMP: reject Security Request over BR/EDR

Christiano Amora · Sep 16, 2026 · 1 files

7c431d61b69a

scsi: block: Fix zones_cond out-of-bounds write on zone report

ZHOU Jiaxiang · Sep 16, 2026 · 1 files

b6ec0f797459

scsi: sd_zbc: Reject disks with too many zones

ZHOU Jiaxiang · Sep 16, 2026 · 1 files

09b7040a1b79

s390/pci: Fix leak of struct pci_dev reference in zpci_report_status()

Niklas Schnelle · Sep 16, 2026 · 3 files

0261aef4b15e

s390/pci: Fix missing device lock in zpci_report_status()

Niklas Schnelle · Sep 16, 2026 · 2 files

a1120bea9bc8

s390/pci: Report SCLP status on error events when no pdev is associated

Niklas Schnelle · Sep 16, 2026 · 1 files

3a43be7a1fd0

s390/pci: Don't report recovery success on skipped recovery

Niklas Schnelle · Sep 16, 2026 · 1 files

67f4c1c6a1b5

smb: client: fix create context out-of-bounds reads

Zihan Xi · Sep 16, 2026 · 2 files

fa2e9900dd2a

smb: client: validate POSIX create context length

Zihan Xi · Sep 16, 2026 · 1 files

566820af017e

smb: client: close handle after create-context parsing failure

Zihan Xi · Sep 16, 2026 · 1 files

d2ff5fb93ea8

smb: client: clean up failed cached directory opens

Zihan Xi · Sep 16, 2026 · 1 files

6c5c547f037b

smb: client: close completed creates on compound wait errors

Zihan Xi · Sep 16, 2026 · 3 files

2e828035d5d7

smb: client: preserve create-context parsing errors

Zihan Xi · Sep 16, 2026 · 1 files

012bfcd5a510

s390/debug: Fix NULL pointer dereference in debug_info_copy()

Mikhail Zaslonko · Sep 16, 2026 · 1 files

4467df89dbca

s390/debug: Reject NULL debug info in debug_dump()

Mikhail Zaslonko · Sep 16, 2026 · 1 files

141008dec735

drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV

Szymon Acedański · Sep 16, 2026 · 1 files

67b4411538c8

drm/nouveau: Fix bridge reference leak in nv1a_ram_new()

Wentao Liang · Sep 16, 2026 · 1 files

5ea72f7b7139

drm/nouveau: Fix gem reference leak in validate_init()

Wentao Liang · Sep 16, 2026 · 1 files

1e04611d3735

drm/nouveau: Fix runtime PM leak in nouveau_connector_detect()

Wentao Liang · Sep 16, 2026 · 1 files

ee319bd3a0e9

ipv6: do not let ipv6_find_hdr() return an offset past the packet end

Norbert Szetei · Sep 16, 2026 · 1 files

c774ec8f0a5d

selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode

Eva Kurchatova · Sep 16, 2026 · 1 files

df5cdc2c832c

sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags

Tejun Heo · Sep 16, 2026 · 1 files

dd47bcf279f1

ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().

Kuniyuki Iwashima · Sep 16, 2026 · 1 files

95c4d54ed022

net: phy: micrel: Advance register data pointer in write loop

Abhishek Ojha · Sep 16, 2026 · 1 files

89dc568e8c0b

perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification

Dapeng Mi · Sep 17, 2026 · 1 files

e961d6db42d1

perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification

Dapeng Mi · Sep 17, 2026 · 1 files

8302c5f475fa

perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification

Dapeng Mi · Sep 17, 2026 · 2 files

335b0642812e

perf/x86/intel: Update arw_latency_data() mem-op direction handling

Dapeng Mi · Sep 17, 2026 · 1 files

7c944595cc43

perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints

Dapeng Mi · Sep 17, 2026 · 1 files

9f93d33ad65a

perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints

Dapeng Mi · Sep 17, 2026 · 1 files

0ac5d6ca2c3b

perf/x86/intel: Fix Panther Cove PEBS data-source snoop states

Dapeng Mi · Sep 17, 2026 · 1 files

858b37ca19d3

perf/x86/intel: Delete dead NVL PEBS data-source initcall

Dapeng Mi · Sep 17, 2026 · 1 files

04a7ef3b7aa3

perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3

Dapeng Mi · Sep 17, 2026 · 1 files

ff1621adfdd7

perf/x86/intel: Fix precise OMR event scheduling for DMR/NVL

Dapeng Mi · Sep 17, 2026 · 1 files

0102c8c7fdfc

perf/x86/intel: Rename DMR offcore_rsp attribute to offmodule_rsp

Dapeng Mi · Sep 17, 2026 · 1 files

d4d9ccbad527

perf/x86/intel: Rename NVL offcore_rsp attribute to offmodule_rsp

Dapeng Mi · Sep 17, 2026 · 1 files

cb86607ada73

sched_ext: Don't run ops.dequeue() with a DSQ lock held

fangqiurong · Sep 17, 2026 · 3 files

9ec7ba20c97d

selftests/sched_ext: Test that ops.dequeue() can iterate the consumed DSQ

fangqiurong · Sep 17, 2026 · 3 files

5fd0783b99d4

udp: relocate a connected socket in the 4-tuple hash table on re-connect

Shardul Bankar · Sep 17, 2026 · 1 files

9e95b1a94c9c

udp: remove a disconnected socket from the 4-tuple hash table

Shardul Bankar · Sep 17, 2026 · 1 files

8a60ade2277e

net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget

Jamal Hadi Salim · Sep 17, 2026 · 1 files

1e24c4f2ee44

selftests: tc-testing: add a lateral-drift hfsc classify-walk test

Jamal Hadi Salim · Sep 17, 2026 · 1 files

a644f09b2090

fsl/fman: Fix clk reference leak in read_dts_node()

Wentao Liang · Sep 17, 2026 · 1 files

999e8295bc41

net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()

Wentao Liang · Sep 17, 2026 · 1 files

517924152140

fs: don't create the private nullfs mount under namespace_sem

Christian Brauner · Sep 17, 2026 · 1 files

0bf6bb567f0e

net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()

Wentao Liang · Sep 17, 2026 · 1 files

76ebb69da677

Revert "selftests/filesystems: add mntns cleanup test"

Christian Brauner · Sep 17, 2026 · 4 files

2e2142a35d80

Revert "put_mnt_ns(): leave mounts connected"

Christian Brauner · Sep 17, 2026 · 1 files

10de7ed8ef48

net/mlx5e: fix swapped IPv6 IPsec policy masks

Andrea Parri · Sep 17, 2026 · 1 files

17741334d00b

net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()

Wentao Liang · Sep 17, 2026 · 1 files

814a81c842bd

bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc

Zhao Gongyi · Sep 17, 2026 · 1 files

4581c3d2adc3

net/mlx5e: advertise MACsec offload only when supported

Ralf Lici · Sep 17, 2026 · 2 files

6b13ddbf5bb8

drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait

Sunil Khatri · Sep 17, 2026 · 1 files

cd195f1616b2

drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout

Sunil Khatri · Sep 17, 2026 · 1 files

f952ed353a27

drm/amdgpu/vcn5.0.1: fix video_timeout unit mismatch in jpeg reset wait

Sunil Khatri · Sep 17, 2026 · 1 files

7cce782d8327

dpll: use exact lookup for reference sync pin id

Ivan Vecera · Sep 17, 2026 · 1 files

d54a489c8c4b

gpiolib: use of_node_name if line-name is missing

Frank Wunderlich · Sep 17, 2026 · 1 files

a92e1a412c53

tg3: clean up PHYLIB resources on probe failure

Myeonghun Pak · Sep 17, 2026 · 1 files

cb4c7603678c

drm/nouveau/gsp/r570: Add support for INTERNAL_GCX_ENTRY_PREREQUISITE

Lyude Paul · Sep 17, 2026 · 11 files

3217000f0b7e

drm/nouveau/gsp/r535: Add support for MEMSYS_GET_STATIC_CONFIG

Lyude Paul · Sep 17, 2026 · 5 files

c7ef611a43bb

drm/nouveau/gsp/r570: Add comp mode workaround from issue #3172217

Lyude Paul · Sep 17, 2026 · 2 files

82f4394bbe22

drm/nouveau/gsp/r570: Start saving comptag backing stores

Lyude Paul · Sep 17, 2026 · 2 files

adb87c20081e

drm/nouveau/gsp/r570: Enable Gcoff in fbsr again

Lyude Paul · Sep 17, 2026 · 1 files

be1df8badae5

drm/xe: Keep walking on SVM eviction failure

Matthew Brost · Sep 17, 2026 · 1 files

1d653a183973

fprobe: Terminate the fgraph_data list when the reservation is not filled

David Carlier · Sep 17, 2026 · 1 files

1717fcc5be57

drm/nouveau/disp: don't reject HDMI config on cards without SCDC

Giuseppe Ranieri · Sep 17, 2026 · 1 files

d68acbf93531

net: stmmac: selftests: Support running selftests on DSA conduits

Maxime Chevallier · Sep 17, 2026 · 1 files

c8c1795aa810

net: stmmac: selftests: Validate EEE based on the actual LPI timer value

Maxime Chevallier · Sep 17, 2026 · 1 files

ba804b23d76d

net: stmmac: selftests: Check the dev->features for S-TAG offload testing

Maxime Chevallier · Sep 17, 2026 · 1 files

960db6f65788

net: stmmac: selftests: Capture all packets for vlan checks

Maxime Chevallier · Sep 17, 2026 · 1 files

b42e7012773a

net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K

Maxime Chevallier · Sep 17, 2026 · 3 files

b8a26d46c0a4

net: stmmac: size the RX buffers from the frame length, not the MTU

Maxime Chevallier · Sep 17, 2026 · 1 files

c4ac6e94eb94

net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test

Maxime Chevallier · Sep 17, 2026 · 1 files

261b61d3735b

bpf: Make post-verification instruction rewrites killable

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 2 files

fd16449a9b3b

bpf: Preserve packet pointer class displacement in regsafe()

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

2059d9af54f0

selftests/bpf: Test packet pointer class displacement pruning

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

c26e97721b17

bpf: Apply CO-RE relocations before subprogram validation

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files

968ee7c06b62

selftests/bpf: Test early in-kernel CO-RE relocation

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

394ae398337c

bpf: Restrict CO-RE poisoning to relocatable instructions

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

3440505aca92

selftests/bpf: Test CO-RE instruction poisoning restrictions

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

71919742c83c

bpf: Assign lock identity to callback map values

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files

04ae4ffc57a6

selftests/bpf: Check callback map value lock identity

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 3 files

b4e875d397da

libbpf: Reject truncated ldimm64 CO-RE relocations

Kumar Kartikeya Dwivedi · Sep 17, 2026 · 1 files

c2cdef41e0b4

net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621

Aleksei Sviridkin · Sep 18, 2026 · 1 files

0d80ba0a204c

net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq

Aleksei Sviridkin · Sep 18, 2026 · 1 files

6a6870d3077f

drm/nouveau: don't bump pin count on failed re-pin in nouveau_bo_pin_locked()

Peiyang He · Sep 18, 2026 · 1 files

cb917b1e1c23

parisc: remove unused <asm/compat_ucontext.h> header

Ethan Nelson-Moore · Sep 18, 2026 · 1 files

481506a756dc

vxlan: use one headroom snapshot for neighbour replies

Sanghyun Park · Sep 18, 2026 · 1 files

d58384c22739

PCI: Fix BAR resize for devices on a root bus

Liz Fong-Jones · Sep 18, 2026 · 1 files

ac4334522e4b

net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error

bui duc phuc · Sep 18, 2026 · 1 files

289e99e7a263

parisc: parse early parameters in setup_arch()

Zhenghui Hao · Sep 18, 2026 · 1 files

0346ec2f080b

ipv6: Prevent rt6_insert_exception() for dying fib6_info.

Kuniyuki Iwashima · Sep 18, 2026 · 2 files

4f948b5949d2

binfmt_misc: fix OOB read in bpf_binprm_select_interp()

Chris Mason · Sep 18, 2026 · 1 files

1970fc4ecb52

binfmt_misc: fix racy checks in bpf set_interp kfuncs

Chris Mason · Sep 18, 2026 · 1 files

31995571219c

net: don't require the hwtstamp NDOs when a PHY provides timestamping

Nicolai Buchwitz · Sep 18, 2026 · 1 files

35e6f970f553

net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports

Bernardo Soares · Sep 18, 2026 · 3 files

2e51097c982b

net/mlx5: Bridge, don't fail unlink of untracked/unsupported peer ports

Bernardo Soares · Sep 18, 2026 · 1 files

0160953d8eec

eth: fbnic: Avoid rounding zero ring sizes

Björn Töpel · Sep 18, 2026 · 1 files

e6bae5034ef4

ata: libata-core: Extend Samsung LPM quirk to AMD controllers

Niklas Cassel · Sep 18, 2026 · 2 files

88a0474d92ba

ata: libata: Correct libata.force parameter documentation

Niklas Cassel · Sep 18, 2026 · 1 files

24a22fb3c731

drm/xe/vm: nuke PTs only after unlinking contested VMAs

Matthew Auld · Sep 18, 2026 · 1 files

aff09d9e37e0

drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update

Dan Carpenter · Sep 18, 2026 · 1 files

866dbd17c3d5

drm/nouveau/clk: don't use the pstate cursor after the loop

Francesco Magazzu · Sep 18, 2026 · 1 files

7ca7b8b5f2cc

drm/nouveau/device: don't use the pstate cursor after the loop

Francesco Magazzu · Sep 18, 2026 · 1 files

e5cccdafc855

drm/nouveau/clk: don't clobber reclock status when restoring volt/fan

Francesco Magazzu · Sep 18, 2026 · 1 files

a0bb6fac53fa

sched/core: Account PSI IRQ time to the execution context, not the scheduling context

Zhan Xusheng · Sep 18, 2026 · 1 files

9c572a83037a

net/sched: fix potential stack infoleak in em_text_dump()

Bernard Ladenthin · Sep 18, 2026 · 1 files

be581d663557

selftests: net: fix CONFIG_SYSCTL sort order in configs

Yuya Kusakabe · Sep 18, 2026 · 2 files

28e29992b034

s390/debug: Do not register views for failed static debug areas

Mikhail Zaslonko · Sep 18, 2026 · 2 files

f71ecaece401

landlock: Fix tracepoint fixed-width type names

Mickaël Salaün · Sep 18, 2026 · 1 files

0de33ca344fb

landlock: Fix filesystem denial blocker reporting

Mickaël Salaün · Sep 18, 2026 · 3 files

1a985d3890ed

landlock: Fix rule tracepoint context

Mickaël Salaün · Sep 18, 2026 · 9 files

98b04ab00f0e

landlock: Fix network denial trace context

Mickaël Salaün · Sep 18, 2026 · 6 files

7ad69ac63315

landlock: Report the actual ptrace tracer

Mickaël Salaün · Sep 18, 2026 · 4 files

0889db596a25

landlock: Report the effective signal number

Mickaël Salaün · Sep 18, 2026 · 4 files

c6dea91d846f

selftests/landlock: Test filesystem denial blockers

Mickaël Salaün · Sep 18, 2026 · 1 files

c8dcb17205a6

selftests/landlock: Test network denial context

Mickaël Salaün · Sep 18, 2026 · 1 files

3fa5aa398edf

landlock: Fix tracepoint contract documentation

Mickaël Salaün · Sep 18, 2026 · 2 files

23d42b9a3bcd

net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths

Théo Lebrun · Sep 18, 2026 · 1 files

8805840aad73

PCI: of_property: Omit bus properties without a subordinate bus

Angel J · Sep 18, 2026 · 1 files

00efbbd40bd5

bonding: crypto offload enabled, non-offload slave failover, rekey failed

David Dai · Sep 18, 2026 · 1 files

89a8a1eef2d4

net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection

Jonas Jelonek · Sep 18, 2026 · 1 files

261e8a37ecba

genetlink: report the real command id for dump-only ops in policy dumps

Jakub Kicinski · Sep 18, 2026 · 1 files

a87529034b9c

selftests: net: nl_nlctrl: check the op ids in the policy map

Jakub Kicinski · Sep 18, 2026 · 1 files

76d8e697242e

dcache: unpoison the inline name buffer in __d_alloc()

Drif Abdelmalek Mohamed Said · Sep 18, 2026 · 1 files

4eb3f195ef08

tg3: use random MAC address when tg3_get_device_address fails

Ivan Delalande · Sep 18, 2026 · 1 files

3bd46666cfe5

sched_ext: Pass the initial cmask to cid-form ops.enable()

Tejun Heo · Sep 19, 2026 · 3 files

07e1a9408b6c

virtio_net: copy zerocopy frags in start_xmit without NAPI

Willem de Bruijn · Sep 19, 2026 · 1 files

951840561386

packet: use ubuf_info completion for TX_RING packets

Willem de Bruijn · Sep 19, 2026 · 2 files

8901cee9316d

bpf: Compare stack frames in regs_exact()

Kumar Kartikeya Dwivedi · Sep 19, 2026 · 2 files

070587848985

selftests/bpf: Cover frame changes in bounded loops

Kumar Kartikeya Dwivedi · Sep 19, 2026 · 1 files

a11212910cf0

bpf: Check params size before reading reserved fields

Yuqi Xu · Sep 19, 2026 · 1 files

e47a1958e12a

net: ipconfig: bound DHCP option construction

Yuqi Xu · Sep 19, 2026 · 1 files

8f6f8a48399f

smb: client: delete compound mids on send failure before unlock

Adarsh Das · Sep 19, 2026 · 1 files

6d91041bb38b

Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()

Hui Peng · Sep 19, 2026 · 1 files

46f8ffd0a1f1

Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO

Hui Peng · Sep 19, 2026 · 1 files

3b4e0b0c008a

net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()

Shihuang Liu · Sep 19, 2026 · 1 files

d781d1b78acf

selftests/sched_ext: Check the cmask cid-form ops.enable() receives

Tejun Heo · Sep 19, 2026 · 3 files

4cbe530c0233

gpio: tps65219: Fix GPIO input value reads

Karl Mehltretter · Sep 19, 2026 · 1 files

93cf8cedeaaa

gpio: tps65219: Use the variant-specific direction callback

Karl Mehltretter · Sep 19, 2026 · 1 files

270437f3fe62

gpio: tps65219: Fix TPS65214 GPIO direction programming

Karl Mehltretter · Sep 19, 2026 · 1 files

9892d71cf0ce

net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure

Coia Prant · Sep 19, 2026 · 1 files

2d14720beb58

net: spacemit: clear TX descriptor on fragment mapping failure

Muhammad Bilal · Sep 19, 2026 · 1 files

94b7e3a7e871

parisc: Increase kernel stack size to 32kb

Helge Deller · Sep 19, 2026 · 1 files

aa5e44b29ffe

autofs: fix sbi->pipe file reference leak in autofs_kill_sb()

Hui Peng · Sep 19, 2026 · 1 files

f0ca020cbb9b

Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough

Hui Peng · Sep 19, 2026 · 2 files

45585c3aa285

drm/imagination: clamp freelist reconstruction requests

Pengpeng Hou · Sep 20, 2026 · 1 files

c06bde80ae7a

net: usb: sr9700: include receive overhead in the length check

Pengpeng Hou · Sep 20, 2026 · 1 files

f75f21ef3628

net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist

Ming Wang · Sep 20, 2026 · 1 files

ab1404ac8115

net: bridge: mdb: restart port group walk after deletion

Fourie Zhang · Sep 20, 2026 · 1 files

6db1ce73e985

bpf: Reject dev-bound-only programs on other devices

Weiming Shi · Sep 20, 2026 · 1 files

41112a787f91

PM: hibernate: Freeze kernel threads after image preallocation

Florian Schmaus · Sep 20, 2026 · 1 files

cfa165cbfbed

net/sched: act_gate: budget the per-entry list in get_fill_size

Victor Nogueira · Sep 20, 2026 · 1 files

d8b6529e80bc

net: arp: terminate device name before lookup

Zijie Huang · Sep 20, 2026 · 1 files

be31fe6333f5

ipv6: Fix dst leak for uncached routes.

Kuniyuki Iwashima · Sep 20, 2026 · 2 files

79a9172f3ab4

bpf: Reject non-negative offsets in stack_slot_obj_get_spi()

Xu Yunxiang · Sep 20, 2026 · 1 files

8244668cbbff

selftests/bpf: Reject iterator destruction through fp+0

Xu Yunxiang · Sep 20, 2026 · 1 files

a940003f44e7

net: phylink: record the PHY only once bringup cannot fail

Aleksei Sviridkin · Sep 20, 2026 · 1 files

cca4980630b3

perf/core: Fix a refcount leak in attach_perf_ctx_data()

Namhyung Kim · Sep 20, 2026 · 1 files

a1259e92e1e8

smb: client: update POSIX extension specification references

ZhangGuoDong · Sep 21, 2026 · 1 files

a3f315be9d30

ip_gre: Reject enabling collect metadata through changelink

Xuanqiang Luo · Sep 21, 2026 · 1 files

6b491af01aa5

net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP

Nicolo Giuliani · Sep 21, 2026 · 1 files

2d959c75c27f

ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST

Hui Peng · Sep 21, 2026 · 1 files

d22609f3d13f

fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT

Hui Peng · Sep 21, 2026 · 1 files

26cc0e69cce0

mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag()

Hui Peng · Sep 21, 2026 · 1 files

3173cba11701

net: libwx: fix races in Tx timestamp handling

Jiawen Wu · Sep 21, 2026 · 4 files

36c2009d90f2

net: atl1c: fix soft lockup on out-of-range tpd_cons read

Gajdos Tamás · Sep 21, 2026 · 1 files

374bf9e4b90f

net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read

Gajdos Tamás · Sep 21, 2026 · 1 files

43e746821f5f

net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read

Gajdos Tamás · Sep 21, 2026 · 1 files

0f2fd31f63c6

net: usb: qmi_wwan: add Quectel EG120K-EA

Gilberto Conde · Sep 21, 2026 · 1 files

4498467a8af0

sctp: discard the rest of the packet on a stale-cookie error

Aohan Mei · Sep 21, 2026 · 1 files

119e9db233ad

KVM: Don't pre-reserve xarray entries when storing empty/NULL attributes

Zeng Chi · Sep 21, 2026 · 1 files

277d3623d99a

KVM: Don't treat reserved xarray entries as having memory attributes

Zeng Chi · Sep 21, 2026 · 1 files

ae146bc1abde

ovl: fix UAF in ovl_do_mkdir() debug print

Amir Goldstein · Sep 21, 2026 · 1 files

cb97bf3d4f91

i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL

Viken Dadhaniya · Sep 21, 2026 · 1 files

d6ec384c87cc

net/sched: act_ife: validate metadata length before decoding

Fang Xieyan · Sep 21, 2026 · 4 files

f4d04425e66a

s390/cmf: Fix virtual vs physical address confusion

Peter Oberparleiter · Sep 21, 2026 · 2 files

0a7822e34a0b

net: stmmac: clear stale buf->page after recycling on skb build failure

Lorenzo Bianconi · Sep 21, 2026 · 1 files

26b2bd70d224

net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry

Ilya Maximets · Sep 21, 2026 · 2 files

5e6c14dd42a1

net: openvswitch: conntrack: remove 'add_helper' dead code

Ilya Maximets · Sep 21, 2026 · 1 files

1a4151e6be57

net: openvswitch: conntrack: fix helper UAF due to extensions realloc

Ilya Maximets · Sep 21, 2026 · 1 files

f85009dfcd65

net/sched: act_ct: avoid modifying shared unconfirmed ct entry

Ilya Maximets · Sep 21, 2026 · 1 files

00df72e39f30

net/sched: act_ct: remove 'add_helper' dead code

Ilya Maximets · Sep 21, 2026 · 1 files

dad19b59da05

net/sched: act_ct: fix helper UAF due to extensions realloc

Ilya Maximets · Sep 21, 2026 · 1 files

4da3b7b8b50f

net: xps: reject an out of range traffic class

Norbert Szetei · Sep 21, 2026 · 1 files

0958ea4355e2

net: ena: fix PHC cleanup on probe failure

Guangshuo Li · Sep 21, 2026 · 1 files

9476b4468862

net: ena: fix MMIO read buffer leak on probe failure

Guangshuo Li · Sep 21, 2026 · 1 files

7c9f391ec89c

net: emac: move setting of netops to fix crash

Christian Lamparter · Sep 21, 2026 · 1 files

cae23ae3f788

sctp: hold asoc or transport before mod_timer() in timer handlers

Xin Long · Sep 21, 2026 · 2 files

1a983a4e14c6

nfp: hold IPsec RX state under the XArray lock

Sang-Hoon Choi · Sep 21, 2026 · 1 files

cec38d5c098a

perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits

Sean Christopherson · Sep 21, 2026 · 1 files

4b64dbdc5861

perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED

Sean Christopherson · Sep 21, 2026 · 1 files

d06260e99eb9

perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused

Sean Christopherson · Sep 21, 2026 · 1 files

a391618e1d56

perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()

Sean Christopherson · Sep 21, 2026 · 1 files

73b3fc67a493

net: devmem: document that bind-tx is unprivileged by design

Mina Almasry · Sep 21, 2026 · 2 files

c2de369c5c5b

macsec: initialize SecY before registering the netdevice

Haseeb Malik · Sep 21, 2026 · 1 files

87cd6b717e40

net: ipv6: keep room for the mac header in dst_dev_overhead()

Yuya Kusakabe · Sep 21, 2026 · 1 files

10180a277549

KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails

Sean Christopherson · Sep 21, 2026 · 1 files

c1214f293d77

KVM: x86: Fill kvm_run exit fields in common get_nested_state_pages() error paths

Sean Christopherson · Sep 21, 2026 · 3 files

ba3d1f480c7a

net/rds: size a connection's path set by the transport it ends up with

Allison Henderson · Sep 21, 2026 · 1 files

0e2bec77ea62

net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems

Florian Fainelli · Sep 21, 2026 · 1 files

3aeaa609fda1

net: bcmgenet: initialize u64 stats seq counter for all queues

Florian Fainelli · Sep 21, 2026 · 1 files

cbbc1aee7776

net: bcmgenet: do not skip WoL power up on GENET V1

Florian Fainelli · Sep 21, 2026 · 1 files

273941c85fc2

net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr

Florian Fainelli · Sep 21, 2026 · 1 files

d64e277b955b

net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT

Florian Fainelli · Sep 21, 2026 · 1 files

7104a3707143

veth: manage XDP program pointers during channel resize

Jakub Kicinski · Sep 21, 2026 · 1 files

4bdee8060d1e

net: airoha: npu: cancel wdt_work after releasing the WDT IRQ

Myeonghun Pak · Sep 22, 2026 · 1 files

0d6526f82c3c

sched/cache: Keep nr_pref_llc_running in the runnable domain, to fix LLC mis-scheduling bug

Tim Chen · Sep 22, 2026 · 1 files

d6013e2465d9

sched/cache: Honor migrate_llc_task semantics in active load balance, to fix LLC mis-scheduling bug

Lu Wang · Sep 22, 2026 · 1 files

28f9c0e0a0b9

sched/cache: Decouple sched_cache_group from mm to fix UAF

Tim Chen · Sep 22, 2026 · 4 files

b636fef85bda

sched/cache: Introduce task_struct->sched_cache_grp to fix UAF

Tim Chen · Sep 22, 2026 · 5 files

65efcccddc83

sched/cache: Skip kernel threads for cache aware scheduling to rubustify the code

Chen Yu · Sep 22, 2026 · 1 files

3cb0243767fd

sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug

Davi Chaves Azevedo · Sep 22, 2026 · 3 files

77b1718e39e5

bna: prevent IOC timer rearm during teardown

Myeonghun Pak · Sep 22, 2026 · 1 files

58eb1b3325ed

rds: ib: Clear the sg list when mapping an MR fails

Dongliang Qin · Sep 22, 2026 · 1 files

b8d1d5b63a8e

x86/mce: Fix hardware debug register corruption on task migration

Masami Hiramatsu (Google) · Sep 22, 2026 · 1 files

7b824c293a6b

drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl()

Brajesh Gupta · Sep 22, 2026 · 1 files

0a8224058a58

drm/imagination: Fix page count for page table for map() interface

Brajesh Gupta · Sep 22, 2026 · 3 files

fdfec06ac1eb

MAINTAINERS: add Nicolai Buchwitz as GENET maintainer

Nicolai Buchwitz · Sep 22, 2026 · 1 files

61cb282fe97b

net/smc: fix UAF on lgr list traversal in smcr_port_err()

Sidraya Jayagond · Sep 22, 2026 · 2 files

b94773dc4df7

net: phy: intel-xway: workaround 100BASE-TX Link-Up issue

Alexander Sverdlin · Sep 22, 2026 · 1 files

8e1937fed673

tipc: Fix a data race on mon->peer_cnt in mon_timeout()

Ginger Li · Sep 22, 2026 · 1 files

1feb5d39b05a

gpio: cdev: fix kernel stack leak to user-space in error path

Bartosz Golaszewski · Sep 22, 2026 · 1 files

e9438ab5328a

gpio: zynq: fix runtime PM leak on request error path

Ridham Khurana · Sep 22, 2026 · 1 files

883b776abe48

isofs: Fix handling of directories with tight blocks

Jan Kara · Sep 22, 2026 · 2 files

ec0d89150a93

thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds

Manaf Meethalavalappu Pallikunhi · Sep 22, 2026 · 1 files

7e87508b5c4d

net: bcmgenet: stop Tx NAPI before disabling the queues

Nicolai Buchwitz · Sep 22, 2026 · 1 files

ab7aa05c06ae

vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets

Ido Schimmel · Sep 22, 2026 · 1 files

e7e0a54300a8

landlock: Widen ruleset versions to 64 bits

Mickaël Salaün · Sep 22, 2026 · 2 files

c6b51091caff

firewire: cdev: fix back-transition for iso_resource_auto client resource

Takashi Sakamoto · Sep 22, 2026 · 1 files

35d442ed1f86

bpf: fs/xattr: don't assume the inode is locked in path_unlink/path_rmdir

Andrea Parri · Sep 22, 2026 · 1 files

ed6eec97b534

bpf: Fix bounds check for skb-backed dynptrs

Emil Tsalapatis · Sep 22, 2026 · 1 files

4fd72eb9f1c9

selftests/bpf: Test dynptr slices past end of skb

Emil Tsalapatis · Sep 22, 2026 · 2 files

4a4852376e3a

bpf: Fix bpf_sock context code generation

Emil Tsalapatis · Sep 22, 2026 · 1 files

dec0c209a680

selftests/bpf: Add selftests for rx_queue_mapping context access

Emil Tsalapatis · Sep 22, 2026 · 1 files

a6c1edfbe240

bpf: Reject pkt arguments in mutating subprogs

Emil Tsalapatis · Sep 22, 2026 · 1 files

1ed69a54d318

selftests/bpf: Test rejection of pkt args to mutating subprogs

Emil Tsalapatis · Sep 22, 2026 · 1 files

f85f5917aa2f

bpf: Prevent variable arena/non-arena register contents

Emil Tsalapatis · Sep 22, 2026 · 2 files

a9e86dd9de4f

selftests/bpf: Test for mixed arena/nonarena code paths

Emil Tsalapatis · Sep 22, 2026 · 1 files

031fe051abb3

smb: client: use GFP_KERNEL in get_targets()

Fredric Cover · Sep 22, 2026 · 1 files

2bc6b218717b

arm64/boot: Disable trapping of PMZR_EL0 writes to EL2

Fuad Tabba · Sep 22, 2026 · 2 files

5b76268dac96

s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()

Vineeth Vijayan · Sep 22, 2026 · 1 files

9814077275ec

ipe: fix use-after-free when auditing a newly loaded policy

Fan Wu · Sep 23, 2026 · 2 files

2776e9c28513

ipe: protect the dm-verity root hash with RCU

Fan Wu · Sep 23, 2026 · 3 files

b61732f47316

nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()

Deepanshu Kartikey · Sep 23, 2026 · 1 files

56d82862a0a2

af_packet: fix integer overflow in prb_calc_retire_blk_tmo()

Dairui Zhang · Sep 23, 2026 · 1 files

b78b728e21c3

netfs: Fix missing alloc tagging of direct mempool allocations

Hao Ge · Sep 23, 2026 · 3 files

db762fd96be2

bpf: Fix immediate JMP JEQ/JNE on MIPS32

Johan Almbladh · Sep 23, 2026 · 1 files

8110ba097778

bpf: Fix BSWAP 32 and 16 on MIPS64

Johan Almbladh · Sep 23, 2026 · 1 files

4409a85735cd

sched_ext: Count SCX_EV_SUB_BYPASS_DISPATCH in the dispatch fallback

Liang Luo · Sep 23, 2026 · 1 files

e66cf1625ec4

smb: client: use finish_no_open() for non-regular inodes

Namjae Jeon · Sep 23, 2026 · 1 files

8db67bb6a1ff

net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails

Coia Prant · Sep 23, 2026 · 1 files

06e3f54e8b22

net: flush skb_defer_nodes in dev_cpu_dead()

Eric Dumazet · Sep 23, 2026 · 3 files

83769c23fb18

gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO

Eric Dumazet · Sep 23, 2026 · 1 files

12c1f6e03f94

KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV

Sean Christopherson · Sep 23, 2026 · 1 files

93de2a6a4b91

KVM: SEV: Do cache maintenance on the source VM during intra-host migration

Sean Christopherson · Sep 23, 2026 · 1 files

0fd5e9ddf362

drm/amd/display: Relax DML frame limit with UBSAN

Alex Hung · Sep 23, 2026 · 2 files

80320b278fea

ata: libata-scsi: bound the ATA passthru sense descriptor writes

Matthias Goergens · Sep 23, 2026 · 1 files

3b430ea62340

gve: fix TX drop when GSO MSS is too small for hw

Eddie Phillips · Sep 24, 2026 · 1 files

296c83b5ccc8

gve: DQO: reject TSO packets with an out of range MSS

Eric Dumazet · Sep 24, 2026 · 2 files

72b5b9a28b99

llc: reserve device headroom for allocated frames

Zixuan Chai · Sep 24, 2026 · 1 files

15814c01ac57

drm/amd/display: Bump frame warning limit for all builds of dml

Alex Deucher · Sep 24, 2026 · 2 files

31c88350b7dd

cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict

Hui Peng · Sep 24, 2026 · 2 files

fe99bbeee5c5

tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

Yilin Zhang · Sep 24, 2026 · 1 files

72f9dd522f8d

llc: fix skb UAF and leaks on llc_mac_hdr_init() failure

Eric Dumazet · Sep 24, 2026 · 2 files

ac704ff08e51

bridge: check llc_mac_hdr_init() return value in br_send_bpdu()

Eric Dumazet · Sep 24, 2026 · 1 files

907b978e82cb

net/sched: sch_teql: fix shadowed err in __teql_resolve()

Eric Dumazet · Sep 24, 2026 · 1 files

cd5dd68267c4

vlan: ensure sufficient headroom in vlan_dev_hard_header()

Eric Dumazet · Sep 24, 2026 · 1 files

1765a153d985

cgroup/pids: Restore pids.events notifications in local mode

Guopeng Zhang · Sep 24, 2026 · 1 files

5bfa9f1a9dcb

kprobes: Fix permanent hang when flushing the kprobe optimizer

Andrea Parri · Sep 24, 2026 · 1 files

c3a66e5f5bab

bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element

Donggeun Yoo · Sep 24, 2026 · 1 files

3422808f4e95

selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element

Donggeun Yoo · Sep 24, 2026 · 1 files

fc6d80eb5044

tcp: prevent collapsing skbs across boundary in rtx queue

Willem de Bruijn · Sep 24, 2026 · 1 files

113dcdfadf30

MAINTAINERS: name the libata/linux for-next branch

Matthias Goergens · Sep 25, 2026 · 1 files

db6365ced4d5

workqueue: Fix NULL current_pwq deref in flush dependency check

Pavankumar Kondeti · Sep 25, 2026 · 1 files

94480606a677

sched_ext: Add a size argument to scx_bpf_cid_topo() so struct scx_cid_topo can grow

Tejun Heo · Sep 26, 2026 · 3 files

72d3fcf802c4

Linux 7.3-rc5

Linus Torvalds · Sep 27, 2026 · 1 files