Commit Graph

76272 Commits

Author SHA1 Message Date
Bruce Ashfield
e0d2943590 linux-yocto/6.6: update to v6.6.136
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    142cd8382222 Linux 6.6.136
    deeaba4c54ae md/raid1: fix data lost for writemostly rdev
    1fa36cf495b0 rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
    09427bcb1715 crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed
    b5c14bd4da1f crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed
    607ba280f2ad crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed
    c89c768734f3 crypto: testmgr - Hide ENOENT errors better
    695cac6ed284 crypto: testmgr - Hide ENOENT errors
    74e2db36fe50 net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
    f6634af5de72 ALSA: caiaq: take a reference on the USB device in create_card()
    86fc28191418 ALSA: usb-audio: apply quirk for MOONDROP JU Jiu
    ef57cd3329b4 f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()
    8d5729350b23 ksmbd: use check_add_overflow() to prevent u16 DACL size overflow
    ffbce350c6fd ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
    a34d456934fe smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
    b53b8e98c233 smb: client: require a full NFS mode SID before reading mode bits
    0521a67e4b0f smb: server: fix max_connections off-by-one in tcp accept path
    97f8d2648ef4 smb: server: fix active_num_conn leak on transport allocation failure
    b3e0e7dd53f1 fuse: quiet down complaints in fuse_conn_limit_write
    f1441a1ecace fuse: Check for large folio with SPLICE_F_MOVE
    d23ad78bfd20 fuse: reject oversized dirents in page cache
    a76c1cad4e80 f2fs: fix to avoid memory leak in f2fs_rename()
    f90b8a1798b7 fs/ntfs3: validate rec->used in journal-replay file record check
    a6bcf8010af0 rxrpc: only handle RESPONSE during service challenge
    d6a76b3600e1 rxrpc: Fix anonymous key handling
    6669cf805940 scripts/dtc: Remove unused dts_version in dtc-lexer.l
    cf044df0901f Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave"
    e2c9dc6b6e96 ocfs2: fix out-of-bounds write in ocfs2_write_end_inline
    37f074e65f24 ocfs2: validate inline data i_size during inode read
    4bf8cd09f427 ocfs2: add inline inode consistency check to ocfs2_validate_inode_block()
    c98b6fa86b33 rxrpc: Fix key quota calculation for multitoken keys
    e297bb2c2568 KVM: x86: Use __DECLARE_FLEX_ARRAY() for UAPI structures with VLAs
    f363c496e203 scripts: generate_rust_analyzer.py: define scripts
    ceb73484e720 PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup
    7ad01905831c net: annotate data-races around sk->sk_{data_ready,write_space}
    fa5d5baf67f6 i40e: Fix preempt count leak in napi poll tracepoint
    71ca90c26eef net: ethernet: mtk_eth_soc: initialize PPE per-tag-layer MTU registers
    f77b51bcee7b wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
    10f4ff4baeb6 md/raid1,raid10: don't ignore IO flags
    50352fc10392 ipv6: add NULL checks for idev in SRv6 paths
    e238ab12556b PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
    ebc8815a917f Revert "perf unwind-libdw: Fix invalid reference counts"
    45cbaf5c7cdc media: hackrf: fix to not free memory after the device is registered in hackrf_probe()
    e3957eb26a3d media: vidtv: fix pass-by-value structs causing MSAN warnings
    7318e3549518 nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map
    cb8092038e95 media: as102: fix to not free memory after the device is registered in as102_usb_probe()
    47fa09fe7f3e bcache: fix cached_dev.sb_bio use-after-free and crash
    e88354b381e2 ALSA: 6fire: fix use-after-free on disconnect
    b5d141ea15f1 media: em28xx: fix use-after-free in em28xx_v4l2_open()
    9a9bdaf9dc42 media: mediatek: vcodec: fix use-after-free in encoder release path
    17cb7957c979 media: vidtv: fix nfeeds state corruption on start_streaming failure
    115a5266749d mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
    cec74b2ab7df mm/kasan: fix double free for kasan pXds
    887632163b54 ASoC: qcom: q6apm: move component registration to unmanaged version
    dc6a6c3db3a4 KVM: x86: Use scratch field in MMIO fragment to hold small write values
    24b1e0d5d254 checkpatch: add support for Assisted-by tag
    e0c211a0c261 ice: Fix memory leak in ice_set_ringparam()
    e6661add2d9c nf_tables: nft_dynset: fix possible stateful expression memleak in error path
    aaba6ee63ba6 blktrace: fix __this_cpu_read/write in preemptible context
    9df613ef6e8e nfc: nci: complete pending data exchange on device close
    4604b7b4eee6 net: sched: fix TCF_LAYER_TRANSPORT handling in tcf_get_base_ptr()
    5afb9356a2e5 KVM: nVMX: Fold requested virtual interrupt check into has_nested_events()
    002a73470b56 net: add proper RCU protection to /proc/net/ptype
    f9d4b618f1b9 iio: common: st_sensors: Fix use of uninitialize device structs
    36f127b971c0 btrfs: merge btrfs_orig_bbio_end_io() into btrfs_bio_end_io()
    128b03ccb258 net: skb: fix cross-cache free of KFENCE-allocated skb head
    b670833749ff KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
    6575f9fbf084 ocfs2: handle invalid dinode in ocfs2_group_extend
    6f072daefcab ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
    4b80b5a838a3 ocfs2: fix possible deadlock between unlink and dio_end_io_write
    b7efb4c94797 media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections
    426ef05e82ee dcache: Limit the minimal number of bucket to two
    452894005b4a ALSA: ctxfi: Limit PTP to a single page
    6718df49e5a7 Docs/admin-guide/mm/damon/reclaim: warn commit_inputs vs param updates race
    554391e7da68 USB: serial: option: add Telit Cinterion FN990A MBIM composition
    779412e0e391 staging: sm750fb: fix division by zero in ps_to_hz()
    f632987306bc wifi: rtw88: fix device leak on probe failure
    e2f8c5d134f7 scripts: generate_rust_analyzer.py: avoid FD leak
    cce24f70090e fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
    301857c5ac27 usb: port: add delay after usb_hub_set_port_power()
    8fb82e3555a7 USB: cdc-acm: Add quirks for Yoga Book 9 14IAH10 INGENIC touchscreen
    9dec3276d122 usb: storage: Expand range of matched versions for VL817 quirks entry
    885c8591784d usbip: validate number_of_packets in usbip_pack_ret_submit()
    745a535461bb ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
    b5b5d5936a50 ksmbd: require 3 sub-authorities before reading sub_auth[2]
    4b73376feecb ksmbd: validate EaNameLength in smb2_get_ea()
    bfbc74df8bbe smb: client: fix off-by-8 bounds check in check_wsl_eas()
    1b2bfedccc4f usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
    9ceff1251904 usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
    0f156bb5334e usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
    859a239d58a8 fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
    f856f4b6efd5 ALSA: fireworks: bound device-supplied status before string array lookup
    63c11b19cdc1 drm/vc4: platform_get_irq_byname() returns an int
    2819f34e08bd NFC: digital: Bounds check NFC-A cascade depth in SDD response handler
    d4e1946bea8d net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
    932ae5309e53 HID: core: clamp report_size in s32ton() to avoid undefined shift
    c8cc765253ad HID: alps: fix NULL pointer dereference in alps_raw_event()
    c65ee4d3be5d staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
    fa00738ab30b i2c: s3c24xx: check the size of the SMBUS message before using it
    5e9cfffad898 can: raw: fix ro->uniq use-after-free in raw_rcv()
    0eb1263a3b8c nfc: llcp: add missing return after LLCP_CLOSED checks
    e2e0e7884314 drm/i915/psr: Do not use pipe_src as borders for SU area
    7ab1832fe163 objtool: Remove max symbol name length limitation
    29d39948ce52 ALSA: usb-audio: Improve Focusrite sample rate filtering
    c5e918390002 netfilter: conntrack: add missing netlink policy validations
    e86ab1e56613 crypto: algif_aead - Fix minimum RX size check for decryption
    cfab2c817d2e perf/x86/intel/uncore: Skip discovery table for offline dies
    1981e469558b gpio: tegra: fix irq_release_resources calling enable instead of disable
    9ccce02d5013 l2tp: Drop large packets with UDP encap
    ae8343a19ccb net: ipa: fix event ring index not programmed for IPA v5.0+
    a7d326dfb13b net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+
    b9232421a77a af_unix: read UNIX_DIAG_VFS data under unix_state_lock
    00e1d650fa4b net: txgbe: leave space for null terminators on property_entry
    288138418bef netfilter: ip6t_eui64: reject invalid MAC header for all packets
    36bf0d98e180 netfilter: xt_multiport: validate range encoding in checkentry
    368c22aea490 netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
    730663352c91 ipvs: fix NULL deref in ip_vs_add_service error path
    c4d93470aff0 selftests: net: bridge_vlan_mcast: wait for h1 before querier check
    d3125c541a96 xfrm_user: fix info leak in build_mapping()
    b66920a3348c xfrm: Wait for RCU readers during policy netns exit
    a55793e5a97d xsk: validate MTU against usable frame size on bind
    81ab60836b27 xsk: fix XDP_UMEM_SG_FLAG issues
    cfcc8a82ad03 xsk: respect tailroom for ZC setups
    a03975beb9f6 xsk: tighten UMEM headroom validation to account for tailroom and min frame
    c9eef0760db4 e1000: check return value of e1000_read_eeprom
    d8a747057a17 ixgbevf: add missing negotiate_features op to Hyper-V ops table
    feba4907c302 tracing/probe: reject non-closed empty immediate strings
    7a01c81120f5 dt-bindings: net: Fix Tegra234 MGBE PTP clock
    366f890831ff net: stmmac: Fix PTP ref clock for Tegra234
    d8c2aa3c4a1e nfc: s3fwrn5: allocate rx skb before consuming bytes
    47a8bf52156a ipv4: icmp: fix null-ptr-deref in icmp_build_probe()
    363a38044b8c net: lapbether: handle NETDEV_PRE_TYPE_CHANGE
    eb3765b90eb8 net: sched: act_csum: validate nested VLAN headers
    a6566cd33f6f eventpoll: defer struct eventpoll free to RCU grace period
    34160cca50ec drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock
    dd5c49787a32 drm/vc4: Fix a memory leak in hang state error path
    a812008fe3a0 drm/vc4: Fix memory leak of BO array in hang state
    5befb65dca90 drm/vc4: Release runtime PM reference after binding V3D
    96f71e3a7f9b PCI: hv: Set default NUMA node to 0 for devices without affinity info
    6948caaff66d arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency
    d4d11b70a30f soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching
    f0288da67320 ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J
    3ec7437e9d11 wifi: brcmfmac: validate bsscfg indices in IF events
    cf50a1178dfc ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585
    e6a445513fbc HID: roccat: fix use-after-free in roccat_report_event
    40f40229baa7 ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10
    e73692e0e271 HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3
    a9098b43562f platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug
    36af81124ca8 pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer)
    b17dcf3c9cb4 ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx
    5d4fe469fe7d fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
    7b73bea718fe ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex
    e51cd8954919 ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list
    b6ba1eacf276 wifi: wl1251: validate packet IDs before indexing tx_frames
    d7b59c2e6109 ALSA: hda/realtek: add quirk for Framework F111:000F
    fa4f1f52528c netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
    b345586c9fe8 ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx
    c09a7446aab5 btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
    aa77bd6d08f0 can: mcp251x: add error handling for power enable in open and resume
    5c37bd025068 ASoC: SOF: topology: reject invalid vendor array size in token parser
    64e4ced7dd47 ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF
    719df67c2003 ALSA: asihpi: avoid write overflow check warning
    384c3f844f53 media: rkvdec: reduce stack usage in rkvdec_init_v4l2_vp9_count_tbl()
    e0c656cbb2a7 ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC
    1e1015643535 ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk
    2cd86c2cd771 ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA
    62298a48f8b8 RDMA/irdma: Fix double free related to rereg_user_mr

(From OE-Core rev: e1b84d7426c14f41676c40bc3056fb4636ea7900)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
47c59204c5 linux-yocto/6.6: update to v6.6.135
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    9760bf04666d Linux 6.6.135
    53b86879e92b Revert "PCI: Enable ACS after configuring IOMMU for OF platforms"
    9853917f9edf rxrpc: Fix missing error checks for rxkad encryption/decryption failure
    1355eb244aa5 rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING)
    9ce36d28f67c rxrpc: fix reference count leak in rxrpc_server_keyring()
    47073aab8a3a rxrpc: reject undecryptable rxkad response tickets
    b8f66447448d rxrpc: Only put the call ref if one was acquired
    f1a7a3ab0f35 rxrpc: Fix key reference count leak from call->key
    93fc15be44a3 rxrpc: Fix call removal to use RCU safe deletion
    e63265f188ea net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool()
    88591194df73 mm: filemap: fix nr_pages calculation overflow in filemap_map_pages()
    b7b8012193fd net: stmmac: fix integer underflow in chain mode
    9a56735581d5 net: qualcomm: qca_uart: report the consumed byte on RX skb allocation failure
    6468cab1173f mmc: vub300: fix NULL-deref on disconnect
    80fd0de89805 pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled
    0985b18c95eb net/mlx5: Update the list of the PCI supported devices
    ca3f48c3567d drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
    2f55b58b5a0b batman-adv: hold claim backbone gateways by reference
    2eb9d67704ca net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
    0e43e0a3c940 net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
    d3de72e2a2b9 EDAC/mc: Fix error path ordering in edac_mc_alloc()
    672b526def1f X.509: Fix out-of-bounds access when parsing extensions
    69d61639bc7e batman-adv: reject oversized global TT response buffers
    07cb6c72e66b nfc: pn533: allocate rx skb before consuming bytes
    0f36273a4b24 arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges
    e3d84395a16d arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity
    e85ee7bd042c arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V
    03c00ef6d6df Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower"
    4bf41c2731a0 wifi: brcmsmac: Fix dma_free_coherent() size
    3bcf7aca63f0 tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
    c221ed63a276 xfrm: clear trailing padding in build_polexpire()
    070abdf1b043 netfilter: nft_ct: fix use-after-free in timeout object destroy
    533e0a0454d0 Revert "drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug"
    32bad10de347 netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
    84d458018b14 seg6: separate dst_cache for input and output paths in seg6 lwtunnel
    3e9bf8c3ba89 Revert "mptcp: add needs_id for netlink appending addr"
    8ec6a58586f1 usb: gadget: f_hid: move list and spinlock inits from bind to alloc
    e8984f068e90 virtio_net: clamp rss_max_key_size to NETDEV_RSS_KEY_LEN
    0dc539b888fb scsi: ufs: core: Fix use-after free in init error and remove paths
    146e25625378 ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()
    811b3dccfb0a MIPS: mm: Rewrite TLB uniquification for the hidden bit feature
    591f030449ad MIPS: mm: Suppress TLB uniquification on EHINV hardware
    8a4de6bcaf01 MIPS: Always record SEGBITS in cpu_data.vmbits
    00a4b91f8fac Input: uinput - take event lock when submitting FF request "event"
    546c18a14924 Input: uinput - fix circular locking dependency with ff-core
    3fd6547f5b8a mptcp: fix slab-use-after-free in __inet_lookup_established
    673d2a3eef6e net: rfkill: prevent unlimited numbers of rfkill events from being created
    e0c8542c3d09 xfrm_user: fix info leak in build_report()
    1de5c76bf40e wifi: rt2x00usb: fix devres lifetime
    066c760acead lib/crypto: chacha: Zeroize permuted_state before it leaves scope
    91f02726b220 x86/CPU: Fix FPDSS on Zen1

(From OE-Core rev: 4536d25fbba2ce23dfb91b25729efe83ac102f61)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
171afa565f linux-yocto/6.6: update to v6.6.134
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    8cee53b8eaeb5 Linux 6.6.134
    6b63a54a790a6 net: sfp: Fix Ubiquiti U-Fiber Instant SFP module on mvneta
    79bc854d44f9f MPTCP: fix lock class name family in pm_nl_create_listen_socket
    83170a05908b6 ext4: handle wraparound when searching for blocks for indirect mapped blocks
    a070d5a872ffe ext4: publish jinode after initialization
    e2316c5d759d3 dmaengine: fsl-edma: fix channel parameter config for fixed channel requests
    72c0f5de91098 dmaengine: fsl-edma: change to guard(mutex) within fsl_edma3_xlate()
    892ba47ef7140 x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling()
    7ddcf4a245c1c mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
    15f5241d5a523 scsi: target: tcm_loop: Drain commands in target_reset handler
    d88541ffd56d6 net: mana: fix use-after-free in add_adev() error path
    ed71cf465c75f net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback
    a2d3c892115e1 net: macb: Move devm_{free,request}_irq() out of spin lock area
    9e7d5b7581ce1 iio: imu: inv_icm42600: fix odr switch when turning buffer off
    d1e3aa80e6e04 wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free
    c6da4fed7537a usb: gadget: f_uac1_legacy: validate control request size
    cb5316b37288a usb: gadget: f_rndis: Protect RNDIS options with mutex
    75776a055b656 usb: gadget: f_subset: Fix unbalanced refcnt in geth_free
    c78e463ee134b usb: gadget: uvc: fix NULL pointer dereference during unbind race
    f6813c2b2ae78 usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop
    3db70e16fccb4 LoongArch: vDSO: Emit GNU_EH_FRAME correctly
    cddea0c721106 gfs2: Validate i_depth for exhash directories
    514784b8951e7 gfs2: Improve gfs2_consist_inode() usage
    3a9fd45afadec btrfs: do not free data reservation in fallback from inline due to -ENOSPC
    681377e4e229d btrfs: fix the qgroup data free range for inline data extents
    f5b469a84400a usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer
    5aa776c8615be USB: dummy-hcd: Fix interrupt synchronization error
    791966f85b439 USB: dummy-hcd: Fix locking/synchronization error
    2516336e825fc thunderbolt: Fix property read in nhi_wake_supported()
    4b8e527aca357 misc: fastrpc: possible double-free of cctx->remote_heap
    9e796001af97a thermal: core: Fix thermal zone device registration error path
    e208c45c63258 gpio: mxc: map Both Edge pad wakeup to Rising Edge
    da39ee627fd82 cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path
    8a71911fc7eee net: ftgmac100: fix ring allocation unwind on open failure
    602596c69a70e vxlan: validate ND option lengths in vxlan_na_create
    28a371be901ef counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev member
    885aa739a07ab counter: rz-mtu3-cnt: prevent counter from being toggled multiple times
    6cea34d7ec682 netfilter: ipset: drop logically empty buckets in mtype_del
    aca0938d0bb44 nvmem: imx: assign nvmem_cell_info::raw_len
    eeb496e82b916 dt-bindings: connector: add pd-disable dependency
    1603dd471f477 comedi: me4000: Fix potential overrun of firmware buffer
    c16ac4e173a05 comedi: me_daq: Fix potential overrun of firmware buffer
    f517646e008fe comedi: ni_atmio16d: Fix invalid clean-up after failed attach
    c01bcc67a9a69 comedi: Reinit dev->spinlock between attachments to low-level drivers
    d5d9df8b08d68 comedi: dt2815: add hardware detection to prevent crash
    787c21d2cc13b cdc-acm: new quirk for EPSON HMD
    e0bfd6d4dc77a bridge: br_nd_send: validate ND option lengths
    2e5cbab8ccbfc fork: defer linking file vma until vma is fully initialized
    13e8e5bd99849 vfio/pci: Insert full vma on mmap'd MMIO fault
    1a0a115843ec4 vfio/pci: Use unmap_mapping_range()
    764438b5c5d15 vfio: Create vfio_fs_type with inode per device
    cfca84f5986af usb: cdns3: gadget: fix state inconsistency on gadget init failure
    9ab9b0e5fcdac usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
    beab10429439e usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop()
    af1e68c43ed88 usb: ehci-brcm: fix sleep during atomic
    95e09b07e5029 usb: usbtmc: Flush anchored URBs in usbtmc_release
    aaeae6533d77e usb: ulpi: fix double free in ulpi_register_interface() error path
    a6f374ba81dde usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive
    1f83e4f8509aa iio: gyro: mpu3050: Fix out-of-sequence free_irq()
    2a4537653d200 iio: gyro: mpu3050: Move iio_device_register() to correct location
    8f237c408f300 iio: gyro: mpu3050: Fix irq resource leak
    a09171d3f23e1 iio: gyro: mpu3050: Fix incorrect free_irq() variable
    4cda5db84e917 iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only
    11aaba2824a14 iio: imu: bmi160: Remove potential undefined behavior in bmi160_config_pin()
    dae6048cb63fe iio: light: vcnl4035: fix scan buffer on big-endian
    13f4f2d046661 iio: dac: ad5770r: fix error return in ad5770r_read_raw()
    97d908087e85c iio: accel: fix ADXL355 temperature signature value
    81b90c03dd65f Input: xpad - add support for Razer Wolverine V3 Pro
    6260b66c005fa Input: xpad - add support for BETOP BTP-KP50B/C controller's wireless mode
    92b1a92857002 Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table
    a6d5d972460ca Input: synaptics-rmi4 - fix a locking bug in an error path
    fa64aab25aba4 iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()
    624e292e74769 USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam
    619d8d1cc4688 USB: serial: option: add support for Rolling Wireless RW135R-GL
    d3f78e9cd0bbe USB: serial: io_edgeport: add support for Blackbox IC135A
    beadc871ccf86 drm/i915/dp: Use crtc_state->enhanced_framing properly on ivb/hsw CPU eDP
    32ac48642e71e drm/ast: dp501: Fix initialization of SCU2C
    7759f105e9c89 iio: adc: ti-adc161s626: fix buffer read on big-endian
    43fa022b56dcd mips: mm: Allocate tlb_vpn array atomically
    37ae8fadc74ed hwmon: (occ) Fix division by zero in occ_show_power_1()
    4c10f326f628e MIPS: Fix the GCC version check for `__multi3' workaround
    91649c02c1baa Bluetooth: SMP: force responder MITM requirements before building the pairing response
    b1c6a8e554a39 Bluetooth: SMP: derive legacy responder STK authentication from MITM state
    c8859675f1cf9 ALSA: ctxfi: Fix missing SPDIFI1 index handling
    a82c1bce2d129 ALSA: caiaq: fix stack out-of-bounds read in init_card
    2de70a6149e03 USB: serial: option: add MeiG Smart SRM825WN
    ffbed27ba15ef wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()
    9907ac9b9a18b wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
    489f2ef2b9088 drm/ioc32: stop speculation on the drm_compat_ioctl path
    0320474d92c69 riscv: kgdb: fix several debug register assignment bugs
    e01779a5c0283 mips: ralink: update CPU clock index
    649ceac79c831 hwmon: (occ) Fix missing newline in occ_show_extended()
    164a1b397da0c hwmon: (tps53679) Fix device ID comparison and printing in tps53676_identify()
    cb048be568a85 dt-bindings: gpio: fix microchip #interrupt-cells
    220f29e819244 hwmon: (pxe1610) Check return value of page-select write in probe
    2dd67966f39a2 accel/qaic: Handle DBC deactivation if the owner went away
    690509a2eea89 iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one
    8755066f7bd0f bpf: reject direct access to nullable PTR_TO_BUF pointers
    5e4ee5dbea134 ipv6: avoid overflows in ip6_datagram_send_ctl()
    36a5d17d7ddad net: hsr: fix VLAN add unwind on slave errors
    4a09f72007201 net/sched: cls_flow: fix NULL pointer dereference on shared blocks
    18328eff2f97d net/sched: cls_fw: fix NULL pointer dereference on shared blocks
    1734bd85c5e0a net/x25: Fix overflow when accumulating packets
    143d4fa68ae9e net/x25: Fix potential double free of skb
    1fc7fbac8b98f net/mlx5: Avoid "No data available" when FW version queries fail
    7129632cab3e4 net/mlx5: lag: Check for LAG device before creating debugfs
    e1f6f47d6e60d net: macb: properly unregister fixed rate clocks
    b3f799cdf830d net: macb: fix clk handling on PCI glue driver removal
    a14b568633486 net/sched: sch_netem: fix out-of-bounds access in packet corruption
    8d597e3e74027 bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().
    6b0a8de67ac0c rds: ib: reject FRMR registration before IB connection is established
    244b639e6a3a8 Bluetooth: MGMT: validate mesh send advertising payload length
    5fb69e1eeea9d Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
    f71695e81f4cb Bluetooth: MGMT: validate LTK enc_size on load
    adb90cd0f9f7a Bluetooth: SCO: fix race conditions in sco_sock_connect()
    2504ce3fc39ed Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if immediate
    4b12a3cc3f075 netfilter: nf_tables: reject immediate NF_QUEUE verdict
    f00ac65c90ea4 netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP
    2ea0f35f235f7 netfilter: ctnetlink: ignore explicit helper on new expectations
    a76157a1eee5f netfilter: nf_conntrack_expect: store netns and zone in expectation
    e7ccaa0a62a8f netfilter: nf_conntrack_expect: use expect->helper
    d81c3205085b5 netfilter: nf_conntrack_expect: honor expectation helper field
    2898080c054ea netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent
    2cf2737c85a2b netfilter: nf_conntrack_helper: pass helper to expect cleanup
    1b842ade214b9 netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr
    c2d4a3abb15ca netfilter: x_tables: ensure names are nul-terminated
    607245c4dbb86 netfilter: nfnetlink_log: account for netlink header size
    5382bb03e9c33 netfilter: flowtable: strictly check for maximum number of actions
    6c7fbdb8ffde6 net: ipv6: flowlabel: defer exclusive option free until RCU teardown
    b99d82706bd15 bpf: Fix regsafe() for pointers to packet
    236b564165b49 net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec
    2c1fadd221b21 NFC: pn533: bound the UART receive buffer
    e35f5195cd44f net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak
    7d9f2f4aabd11 ipv6: prevent possible UaF in addrconf_permanent_addr()
    584d8648f859f ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add rollback on failure
    c56f78614e778 net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
    658261898130d bridge: br_nd_send: linearize skb before parsing ND options
    a0c4ce9900a10 ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
    3d5127d998de6 ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
    c64dc67d70da6 tg3: Fix race for querying speed/duplex
    d1b041080086e net/ipv6: ioam6: prevent schema length wraparound in trace fill
    7f56d87e527bb net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak
    0fda873092b54 net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak
    3e52e1b121c28 net: fec: fix the PTP periodic output sysfs interface
    7cdf2c6381b21 crypto: af-alg - fix NULL pointer dereference in scatterwalk
    31022cfde5235 crypto: caam - fix overflow on long hmac keys
    a7ecf06d3ee06 crypto: caam - fix DMA corruption on long hmac keys
    4073217be3df0 wifi: ath11k: Pass the correct value of each TID during a stop AMPDU session
    18e28353074a3 wifi: ath11k: Use dma_alloc_noncoherent for rx_tid buffer allocation
    12322d8654cf9 wifi: ath11k: skip status ring entry processing
    90afe0af4452b dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix common property warning
    ea553dfb630e1 spi: geni-qcom: Check DMA interrupts early in ISR
    295f8075d0044 btrfs: reject root items with drop_progress and zero drop_level
    b404e6b9863ea i2c: tegra: Don't mark devices with pins as IRQ safe
    c7a27bb4d0f65 HID: multitouch: Check to ensure report responses match the request
    e9126544fd779 objtool: Fix Clang jump table detection
    960159a9f8468 tg3: replace placeholder MAC address with device property
    c9fc98beeedf0 btrfs: don't take device_list_mutex when querying zone info
    b256d055da472 atm: lec: fix use-after-free in sock_def_readable()
    8bd690ac12423 HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
    7b56b67776520 arm64/scs: Fix handling of advance_loc4
    80de0a9581338 Linux 6.6.133
    9a3a2ae5efbbc xattr: switch to CLASS(fd)
    16d41d32b7c76 Revert "xattr: switch to CLASS(fd)"

(From OE-Core rev: 65242fa5eaa679398d2cb782aea5219e49054cfb)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
c1e0c27492 linux-yocto/6.6: update to v6.6.132
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    08667c1437c07 Linux 6.6.132
    866c39b567bde Revert "rust: pin-init: add references to previously initialized fields"
    e7ccb57fe7164 Revert "rust: pin-init: internal: init: document load-bearing fact of field accessors"
    29242a6238213 Linux 6.6.131
    e10af36ac3f7b tcp: Fix bind() regression for v6-only wildcard and v4-mapped-v6 non-wildcard addresses.
    de7c0c04ad868 futex: Clear stale exiting pointer in futex_lock_pi() retry path
    37cf97e37498a dmaengine: idxd: Fix freeing the allocated ida too late
    509ff03a3f188 dmaengine: idxd: Remove usage of the deprecated ida_simple_xx() API
    e3387416ad6b2 btrfs: fix lost error when running device stats on multiple devices fs
    94054ffd311a1 btrfs: fix leak of kobject name for sub-group space_info
    1ddab07bf2ed5 btrfs: fix super block offset in error message in btrfs_validate_super()
    5a0538380d29e dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA
    ab4a8624b999a dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction
    26271695302c8 dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA
    a3142cc1581a5 dmaengine: xilinx: xilinx_dma: Fix dma_device directions
    4b6e1da50b22e dmaengine: xilinx: xdma: Fix regmap init error handling
    afc39537cddcb dmaengine: dw-edma: Fix multiple times setting of the CYCLE_STATE and CYCLE_BIT bits for HDMA.
    5893ae3b4591b phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types()
    54d77cc0c40ca dmaengine: idxd: Fix memory leak when a wq is reset
    2bb9e9e93adff dmaengine: idxd: Fix not releasing workqueue on .release()
    cfadf46a67b68 erofs: fix "BUG: Bad page state in z_erofs_do_read_page"
    75669e987137f xfs: save ailp before dropping the AIL lock in push callbacks
    7121b22b0bac8 xfs: avoid dereferencing log items after push callbacks
    aba546061341b mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]
    2efbc838a26d3 nvme: fix admin queue leak on controller reset
    5a1e865e51063 xattr: switch to CLASS(fd)
    bb42e9627aa92 libbpf: Fix -Wdiscarded-qualifiers under C23
    4913592a3358f gfs2: Fix unlikely race in gdlm_put_lock
    8c93e73af8563 mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D mode
    8cdc84415a4d2 mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D mode
    0890fba6129dc rust: pin-init: internal: init: document load-bearing fact of field accessors
    c28fc9b0dbc7a rust: pin-init: add references to previously initialized fields
    ef41a85a55022 tracing: Fix potential deadlock in cpu hotplug with osnoise
    5a9f33294cc04 tracing: Switch trace_osnoise.c code over to use guard() and __free()
    c9b95ef6f5039 ksmbd: fix memory leaks and NULL deref in smb2_lock()
    9e785f004cbc5 ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
    d3c4458707e70 powerpc64/bpf: do not increment tailcall count when prog is NULL
    d419788a834f7 arm64: dts: imx8mn-tqma8mqnl: fix LDO5 power off
    1c82f863f090a ext4: always drain queued discard work in ext4_mb_release()
    ca99cbcc316cd ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths
    c84c0272e0b66 ext4: fix the might_sleep() warnings in kvfree()
    9449f99ba04f5 ext4: fix use-after-free in update_super_work when racing with umount
    b77de3fceafbb ext4: reject mount if bigalloc with s_first_data_block != 0
    2d31a5073f86a ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()
    ecc50bfca9b5c ext4: avoid infinite loops caused by residual data
    65c6c30ce6362 ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
    df3cecfc5036f ext4: make recently_deleted() properly work with lazy itable initialization
    2b7bf66a09873 ext4: fix fsync(2) for nojournal mode
    850e68a1d3b06 ext4: fix stale xarray tags after writeback
    699bac4d4c951 ext4: convert inline data to extents when truncate exceeds inline size
    17c21b951e87c ext4: fix journal credit check when setting fscrypt context
    813f372a3b8aa xfs: fix ri_total validation in xlog_recover_attri_commit_pass2
    d38135af04a3a xfs: stop reclaim before pushing AIL during unmount
    f458dceaa6a35 LoongArch: Workaround LS2K/LS7A GPU DMA hang bug
    ebf6860ef7093 dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock
    79c4796b2711e dmaengine: sh: rz-dmac: Protect the driver specific lists
    75552b2c17124 irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment
    d536a00f1b451 jbd2: gracefully abort on checkpointing state corruptions
    fd28c56186991 KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
    78c8b090a3d5c net: macb: Use dev_consume_skb_any() to free TX SKBs
    d20d3eedbd04e scsi: ses: Handle positive SCSI error from ses_recv_diag()
    4ed727e35b0ab scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
    c9e137c26cd45 alarmtimer: Fix argument order in alarm_timer_forward()
    5c8ecdcfbfb0b erofs: add GFP_NOIO in the bio completion if needed
    a58d298a83a3a s390/entry: Scrub r12 register on kernel entry
    fedd2e1630cac virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
    1a0d9083c24fb media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
    ebdd28353b958 hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible()
    7c0666a26b290 hwmon: (peci/cputemp) Fix crit_hyst returning delta instead of absolute temperature
    844a18493173f hwmon: (pmbus/isl68137) Add mutex protection for AVS enable sysfs attributes
    d4f4364974460 KVM: arm64: Discard PC update state on vcpu reset
    501559fbe2097 platform/x86: ISST: Correct locked bit width
    2e2c7a6b2958e cpufreq: conservative: Reset requested_freq on limits change
    cb3d6efa78460 can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    54ecdf76a55e7 can: gw: fix OOB heap access in cgw_csum_crc8_rel()
    9e7f353710f85 ASoC: SOF: ipc4-topology: Allow bytes controls without initial payload
    a2842de6856a7 ALSA: firewire-lib: fix uninitialized local variable
    6fafc4c4238e5 ksmbd: do not expire session on binding failure
    358cdaa1f7fbf ksmbd: fix potencial OOB in get_file_all_info() for compound requests
    c3a89e3ec1ccf ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()
    a11911d94c032 s390/barrier: Make array_index_mask_nospec() __always_inline
    7a5260fbc6e79 s390/syscalls: Add spectre boundary for syscall dispatch table
    adb25339b6611 spi: spi-fsl-lpspi: fix teardown order issue (UAF)
    ffd860907d0cb ASoC: adau1372: Fix clock leak on PLL lock failure
    94577b2e936f0 ASoC: adau1372: Fix unchecked clk_prepare_enable() return value
    227b7e14ae408 sysctl: fix uninitialized variable in proc_do_large_bitmap
    6ec394998c42a hwmon: (adm1177) fix sysfs ABI violation and current unit conversion
    e23602eb07797 drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
    9c886e63b6965 ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
    d997deaa7de36 ASoC: Intel: catpt: Fix the device initialization
    9014a30df4365 spi: sn-f-ospi: Fix resource leak in f_ospi_probe()
    b5f87d8493f54 PM: hibernate: Drain trailing zero pages on userspace restore
    8dda015822771 PM: hibernate: Don't ignore return from set_memory_ro()
    6a492d10c2f88 drm/i915/gmbus: fix spurious timeout on 512-byte burst reads
    daf1396e8f42a x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size
    8212295549e47 scsi: scsi_transport_sas: Fix the maximum channel scanning issue
    ad5085d7ef1c5 RDMA/irdma: Return EINVAL for invalid arp index error
    acb060bc2609c RDMA/irdma: Fix deadlock during netdev reset with active connections
    45897c22a93ec RDMA/irdma: Remove reset check from irdma_modify_qp_to_err()
    2175c64d27e27 RDMA/irdma: Clean up unnecessary dereference of event->cm_node
    18386d84d2ad3 RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce()
    d783393d2122b RDMA/irdma: Update ibqp state to error if QP is already in error state
    af310407f79d5 RDMA/irdma: Initialize free_qp completion before using it
    e82f2775b50cc RDMA/rw: Fall back to direct SGE on MR pool exhaustion
    96c60fb6896e6 regmap: Synchronize cache for the page selector
    9524634194516 net: macb: use the current queue number for stats
    fcec5ce2d73a4 netfilter: ctnetlink: use netlink policy range checks
    fe463e76c9b4b netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp
    168145c874446 netfilter: nf_conntrack_expect: skip expectations in other netns via proc
    c6a503a9f4deb netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
    a8365d1064ded netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD
    2dcf324855c34 tls: Purge async_hold in tls_decrypt_async_wait()
    6fba3c3d48c92 Bluetooth: btusb: clamp SCO altsetting table indices
    52667c859fe33 Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop
    5f84e845648df Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock
    8d83194e8a880 Bluetooth: hci_sync: Remove remaining dependencies of hci_request
    0ee469ba7c58c Bluetooth: Remove 3 repeated macro definitions
    50c1e5fc7c444 Bluetooth: L2CAP: Fix send LE flow credits in ACL link
    acfb29f82223e dma-mapping: add missing `inline` for `dma_free_attrs`
    47d5f290fab3c net: enetc: fix the output issue of 'ethtool --show-ring'
    2297e38114316 udp: Fix wildcard bind conflict check when using hash2
    5b5af243e566b tcp: optimize inet_use_bhash2_on_bind()
    79a5c9344eaaf tcp: Rearrange tests in inet_csk_bind_conflict().
    34f5fe33e43bc tcp: Use bhash2 for v4-mapped-v6 non-wildcard address.
    654386baef228 net: fix fanout UAF in packet_release() via NETDEV_UP race
    a8ec35bb7b503 ipv6: Don't remove permanent routes with exceptions from tb6_gc_hlist.
    9241d441feb40 ipv6: Remove permanent routes from tb6_gc_hlist when all exceptions expire.
    6ae421f59bf80 ice: use ice_update_eth_stats() for representor stats
    0677d6bf6e853 platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen
    b04420f5b9315 rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size
    81acbd345d405 net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer
    c1f97152df8df openvswitch: validate MPLS set/set_masked payload length
    42f0d3d812096 openvswitch: defer tunnel netdev_put to RCU release
    4c3e25a7b711a net: openvswitch: Avoid releasing netdev before teardown completes
    eb435d150ca74 nfc: nci: fix circular locking dependency in nci_close_device
    cfd863d4a3f2e ionic: fix persistent MAC address override on PF
    a4fd36bb000db pinctrl: mediatek: common: Fix probe failure for devices without EINT
    a04a760c06bb5 Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
    28904375d54b4 Bluetooth: hci_ll: Fix firmware leak on error path
    45aaca995e4a7 Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
    477ad49760720 Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv()
    a4bda464c0deb can: statistics: add missing atomic access in hot path
    d6923498e972b dma: swiotlb: add KMSAN annotations to swiotlb_bounce()
    d3225e6b9bd51 af_key: validate families in pfkey_send_migrate()
    6a3ec6efbc4f9 esp: fix skb leak with espintcp and async crypto
    e17b0106447ed xfrm: Fix the usage of skb->sk
    86f130cf52504 xfrm: call xdo_dev_state_delete during state update
    7aac2b997e614 spi: intel-pci: Add support for Nova Lake mobile SPI flash
    56bc8de780720 usb: core: new quirk to handle devices with zero configurations
    1eed0199dbf41 objtool: Handle Clang RSP musical chairs
    006ce15577e76 ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390
    f264d4e3a9261 ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk
    c57276ced3c32 btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create
    2635d0c715f3f HID: apple: avoid memory leak in apple_report_fixup()
    d9365789a6fd7 dma-buf: Include ioctl.h in UAPI header
    9d43a897a9122 ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits()
    cb4954fc2520d ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg()
    082f15d288732 module: Fix kernel panic when a symbol st_shndx is out of bounds
    f18c38cb24c9c HID: asus: add xg mobile 2023 external hardware support
    4d36b7ad2c18b HID: mcp2221: cancel last I2C command on read error
    952e41b0f9238 net: usb: r8152: add TRENDnet TUC-ET2G
    7edfe4346b052 HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
    eac08882569bc HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2
    6f12734c4b619 nvme-pci: ensure we're polling a polled queue
    50063c576c6ed platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10
    0ab508ace30c7 platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1
    94cfabcf28209 nvme-fabrics: use kfree_sensitive() for DHCHAP secrets
    c69b5dd587f6f nvme-pci: cap queue creation to used queues
    79dc4ced3bb62 platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list
    f20f17cffbe34 HID: asus: avoid memory leak in asus_report_fixup()
    694ea55f1b1c7 bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
    d47bba0cfdd4c bpf: Release module BTF IDR before module unload
    0f46fd10de29e sh: platform_early: remove pdev->driver_override check
    0af982240b8f4 hwmon: axi-fan: don't use driver_override as IRQ name
    e73121faf530e hwmon: (axi-fan-control) Make use of dev_err_probe()
    50fe5fbf98290 hwmon: (axi-fan-control) Use device firmware agnostic API
    bd738f986f6a0 cxl/hdm: Avoid incorrect DVSEC fallback when HDM decoders are enabled
    656f35b463995 perf: Make sure to use pmu_ctx->pmu for groups
    79cda13757901 perf: Extract a few helpers

(From OE-Core rev: f95c69b567abe9a87b15ac38b98b2836cb9a8f0c)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
73edbddc7f linux-yocto/6.6: update to v6.6.130
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    c09fbcd31ae6 Linux 6.6.130
    1dacf6b3718a xen/privcmd: add boot control for restricted usage in domU
    1879319d790f xen/privcmd: restrict usage in unprivileged domU
    2cf5eff223fc tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure
    c1bfc25d62d8 lib/bootconfig: check xbc_init_node() return in override path
    df1f4a7d9cf6 drm/i915/gt: Check set_default_submission() before deferencing
    b0158d9d6f4e ksmbd: fix use-after-free in durable v2 replay of active file handles
    806f13752652 ksmbd: fix use-after-free of share_conf in compound request
    87158a633e9a drm/amd/display: Fix DisplayID not-found handling in parse_edid_displayid_vrr()
    6ec8f8ebd023 mtd: rawnand: brcmnand: skip DMA during panic write
    a80291e577b4 mtd: rawnand: serialize lock/unlock against other NAND operations
    69aece634a7e i2c: cp2615: fix serial string NULL-deref at probe
    2aeb380c731f i2c: cp2615: replace deprecated strncpy with strscpy
    7864c667aed0 netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
    c51957601d32 x86/platform/uv: Handle deconfigured sockets
    197fc4dda1c0 i2c: pxa: defer reset on Armada 3700 when recovery is used
    c40387488be0 i2c: fsi: Fix a potential leak in fsi_i2c_probe()
    994b301a217f USB: serial: f81232: fix incomplete serial port generation
    2124d82fd25e Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
    eec4d5758f33 drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug
    5b0578a9a9ec hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit()
    5fcef2e370f3 hwmon: (pmbus/mp2975) Add error check for pmbus_read_word_data() return value
    b61529c357f1 icmp: fix NULL pointer dereference in icmp_tag_validation()
    1a0c3c7b5b14 net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths
    ff0c54f088f7 net: mvpp2: guard flow control update with global_tx_fc in buffer switching
    224f4678812e nfnetlink_osf: validate individual option lengths in fingerprints
    adee3436ccd2 netfilter: nf_tables: release flowtable after rcu grace period on error
    d016c216bc75 netfilter: bpf: defer hook memory release until rcu readers are done
    0a3f8cd3f370 net: bonding: fix NULL deref in bond_debug_rlb_hash_show
    a05a2149386f udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
    3dffc083292e net/mlx5e: Fix race condition during IPSec ESN update
    99aaee927800 net/mlx5e: Prevent concurrent access to IPSec ASO context
    7712b5ff6967 net/mlx5: qos: Restrict RTNL area to avoid a lock cycle
    5da8009be419 net: macb: fix uninitialized rx_fs_lock
    edf4c2aaee08 ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
    a6dc74209462 wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom
    0a4da176ae4b wifi: mac80211: fix NULL deref in mesh_matches_local()
    58f74dc73d1b iavf: fix VLAN filter lost on add/delete race
    fb602ed4b19e igc: fix missing update of skb->tail in igc_xmit_frame()
    4de6a43e8ecf net: usb: aqc111: Do not perform PM inside suspend callback
    a73d95b57bf9 clsact: Fix use-after-free in init/destroy rollback asymmetry
    125f932a76a9 net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
    f1c7701d3ac9 net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
    21c89a0a8de7 net/sched: teql: Fix double-free in teql_master_xmit
    f00fc26c8a06 net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
    39f2d86f2ddd PM: runtime: Fix a race condition related to device removal
    fd8278ffba49 sched: idle: Consolidate the handling of two special cases
    249e90557158 net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown
    fcdf56bbdade net: bcmgenet: increase WoL poll timeout
    f5e4f4e4cdb7 netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
    262beb78e95e netfilter: xt_time: use unsigned int for monthday bit shift
    63b8097cea19 netfilter: xt_CT: drop pending enqueued packets on template removal
    e68a8db3a054 netfilter: nft_ct: drop pending enqueued packets on removal
    b477ef7fa612 netfilter: nft_ct: add seqadj extension for natted connections
    52235bf88159 netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
    528b4509c9df netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()
    f04cc86d5990 netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()
    9e5021a90653 netfilter: ctnetlink: remove refcounting in expectation dumpers
    a75d3be96d70 mpls: add missing unregister_netdevice_notifier to mpls_init
    0c9fb70a206a net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect
    e160b869b0a8 Bluetooth: qca: fix ROM version reading on WCN3998 chips
    11a87dd5df42 Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
    45ebe5b90020 Bluetooth: HIDP: Fix possible UAF
    f35209cf4826 Bluetooth: hci_sync: Fix hci_le_create_conn_sync
    2d3deaa162a7 Bluetooth: ISO: Fix defer tests being unstable
    e7899dc538f3 Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy
    c02860835673 Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU
    b5c20c899246 Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU
    d30acb4ecbe2 firmware: arm_scpi: Fix device_node reference leak in probe path
    37e776e2e0a5 wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down
    256f7d4c1123 wifi: mac80211: Fix static_branch_dec() underflow for aql_disable.
    d21923a8059f soc: fsl: qbman: fix race condition in qman_destroy_fq
    d0a466caf4ac cache: ax45mp: Fix device node reference leak in ax45mp_cache_init()
    ccb2262681d6 btrfs: tree-checker: fix misleading root drop_level error message
    56e72c8b02d9 btrfs: log new dentries when logging parent dir of a conflicting inode
    df656e45774f drm/amd/display: Wrap dcn32_override_min_req_memclk() in DC_FP_{START, END}
    9085ad02eff0 drm/amdgpu: apply state adjust rules to some additional HAINAN vairants
    41b0edc1be8d drm/radeon: apply state adjust rules to some additional HAINAN vairants
    2a28ad57d12e drm/amdgpu/mmhub3.0: add bounds checking for cid
    46411902afd1 drm/amdgpu/mmhub3.0.2: add bounds checking for cid
    0fabdcd12c29 drm/amdgpu/mmhub3.0.1: add bounds checking for cid
    6b257be5d3ad drm/amdgpu/mmhub2.3: add bounds checking for cid
    aa3c80150b0e drm/amdgpu/mmhub2.0: add bounds checking for cid
    9f41b9f82ecf drm/amdgpu/gmc9.0: add bounds checking for cid
    447f2c6ef11c serial: uartlite: fix PM runtime usage count underflow on probe
    59e13f1c9a8c serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART BUSY
    d2719a0a9c34 serial: 8250: Fix TX deadlock when using DMA
    092cb022a454 serial: 8250_pci: add support for the AX99100
    85654456e394 iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry
    d8570211a2b1 mtd: Avoid boot crash in RedBoot partition table parser
    2a79fd98b961 mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init()
    d55ff6f213be mtd: rawnand: pl353: make sure optimal timings are applied
    f13100b1f5f1 spi: fix statistics allocation
    6bbd385b30c7 spi: fix use-after-free on controller registration failure
    9443202d9138 pmdomain: bcm: bcm2835-power: Increase ASB control timeout
    4ada013fd7da mmc: sdhci: fix timing selection for 1-bit bus width
    451816d430b3 mmc: sdhci-pci-gli: fix GL9750 DMA write corruption
    0c5026178856 net: macb: Reinitialize tx/rx queue pointer registers and rx ring during resume
    fbbd4c07a537 net: macb: Introduce gem_init_rx_ring()
    2fd0bdd49e57 net: macb: queue tie-off or disable during WOL suspend
    8afb437ea1f7 nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
    1ada20331f2d batman-adv: avoid OGM aggregation when skb tailroom is insufficient
    fc77e0a5600e iio: light: bh1780: fix PM runtime leak on error path
    64ad49597d14 btrfs: fix transaction abort on file creation due to name hash collision
    b19c0465e4da btrfs: fix transaction abort on set received ioctl due to item overflow
    6bce705b699c btrfs: fix transaction abort when snapshotting received subvolumes
    3f04f871a1d4 kprobes: Remove unneeded warnings from __arm_kprobe_ftrace()
    61cfa81f19b9 kprobes: Remove unneeded goto
    6ebef4a220a1 ksmbd: unset conn->binding on failed binding request
    9229709ec8bf smb: client: fix krb5 mount with username option
    807bd1258453 Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
    dd3b221e2107 Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()
    935c716be860 parisc: Flush correct cache in cacheflush() syscall
    5653af416a48 net: macb: fix use-after-free access to PTP clock
    70662874f646 NFC: nxp-nci: allow GPIOs to sleep
    67f2796354bf LoongArch: Give more information if kmem access failed
    e48bf8f1d2b1 nvdimm/bus: Fix potential use after free in asynchronous initialization
    41f6ba6c98a6 sunrpc: fix cache_request leak in cache_release
    d1a19217995d NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd
    439a6728ec46 io_uring/kbuf: check if target buffer list is still legacy on recycle
    d77401968c78 mm/mempolicy: fix wrong mmap_read_unlock() in migrate_to_node()
    8e7715193e5a s390/zcrypt: Enable AUTOSEL_DOM for CCA serialnr sysfs attribute
    2c5c0f4dc8cc s390/stackleak: Fix __stackleak_poison() inline assembly constraint
    3e0619a2a61b s390/xor: Fix xor_xc_2() inline assembly constraints
    1b3ff4d88b50 mptcp: pm: in-kernel: always set ID as avail when rm endp
    268fd5502281 net: stmmac: remove support for lpi_intr_o
    fbab8c08e1a6 binfmt_misc: restore write access before closing files opened by open_exec()
    8c1befea57db sched/fair: Fix pelt clock sync when entering idle
    d1365d2abfaf f2fs: zone: fix to avoid inconsistence in between SIT and SSA
    3da45ec1e485 rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access
    8af210df4f71 platform/x86/amd/pmc: Add support for Van Gogh SoC
    9c05cd8f4232 x86/uprobes: Fix XOL allocation failure for 32-bit tasks
    1b24d3e8792b drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free
    2e147aa3169b drm/exynos: vidi: fix to avoid directly dereferencing user pointer
    21ca24ba51a2 drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
    e1903358b215 drm/amdgpu: Add basic validation for RAS header
    ce63943f9bce l2tp: do not use sock_hold() in pppol2tp_session_get_sock()
    da249eb3206c drm/amd/pm: Use pm_display_cfg in legacy DPM (v2)
    b3367ee3e557 drm/amd/display: Add pixel_clock to amd_pp_display_configuration
    ec2b34acb189 net: dsa: properly keep track of conduit reference
    0643aa246819 bpf: Forget ranges when refining tnum after JSET
    2cbef9ea5a0a net: fix segmentation of forwarding fraglist GRO
    e19201b0c67d net: gso: fix tcp fraglist segmentation after pull from frag_list
    1f2b859225eb net: add support for segmenting TCP fraglist GSO packets
    9b03768037d9 tracing: Add recursion protection in kernel stack trace recording
    eba0c75670c0 dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
    33743ec6679a riscv: Sanitize syscall table indexing under speculation
    4357e02cafab btrfs: do not strictly require dirty metadata threshold for metadata writepages
    bfc717be833f iomap: allocate s_dio_done_wq for async reads as well
    a426f29ac3fa rxrpc: Fix data-race warning and potential load/store tearing
    fc3454a20bef x86/sev: Check for MWAITX and MONITORX opcodes in the #VC handler
    03c29d6d3719 x86/sev: Harden #VC instruction emulation somewhat
    f69fec628756 ipv6: use RCU in ip6_xmit()
    897d9006e75f dm-verity: disable recursive forward error correction
    0464bf75590d rxrpc: Fix recvmsg() unconditional requeue
    1b0edd6022a3 ext4: always allocate blocks only from groups inode can use
    90336fc3d6f5 eth: bnxt: always recalculate features after XDP clearing, fix null-deref
    1e3769aa0946 usb: typec: ucsi: Move unregister out of atomic section
    c57387d447a2 pNFS: Fix a deadlock when returning a delegation during open()
    a4810f8beb01 NFS: Fix a deadlock involving nfs_release_folio()
    1562138b9cab nfs: pass explicit offset/count to trace events
    815db2363e51 dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
    64d8abd8c530 btrfs: fix NULL dereference on root when tracing inode eviction
    54322d95309d arm64: mm: Don't remap pgtables for allocate vs populate
    6a36c8e88af7 arm64: mm: Batch dsb and isb when populating pgtables
    37413d064396 arm64: mm: Don't remap pgtables per-cont(pte|pmd) block
    7d115eb231a6 net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz
    9dcd86cb22e1 btrfs: always fallback to buffered write if the inode requires checksum
    dbc4e10619ed ext4: fix dirtyclusters double decrement on fs shutdown
    db489778e6f2 f2fs: fix to avoid migrating empty section
    5d305a95130a net/tcp-md5: Fix MAC comparison to be constant-time
    307afccb751f ksmbd: Compare MACs in constant time
    946054b773ed smb: client: Compare MACs in constant time
    26a29582980b xfs: ensure dquot item is deleted from AIL only after log shutdown
    50c0e03072fc xfs: fix integer overflow in bmap intent sort comparator
    2bfc83cee05f crypto: atmel-sha204a - Fix OOM ->tfm_count leak
    0629a1a187e4 cifs: open files should not hold ref on superblock
    0a47c3889fcd net: macb: Shuffle the tx ring before enabling tx
    0bc70491e466 drm/bridge: ti-sn65dsi83: halve horizontal syncs for dual LVDS output
    920467466d2d drm/msm: Fix dma_free_attrs() buffer size
    fec5c70b82af ksmbd: Don't log keys in SMB3 signing and encryption key generation
    d1cdf0c63947 iomap: reject delalloc mappings during writeback
    0ba544dacec2 mm/kfence: fix KASAN hardware tag faults during late enablement
    816fa1dfae45 KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated
    5d1e72015b90 KVM: SVM: Add a helper to look up the max physical ID for AVIC
    32ca7117e153 KVM: SVM: Limit AVIC physical max index based on configured max_vcpu_ids
    d146f2775804 usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling
    c24c06ed1849 can: gs_usb: gs_can_open(): always configure bitrates before starting device
    dfc314d7c767 net/sched: act_gate: snapshot parameters with RCU on replace
    0be8c9627556 kbuild: Leave objtool binary around with 'make clean'
    2d53b863b401 selftests: mptcp: join: check RM_ADDR not sent over same subflow
    1ec68e2096ef selftests: mptcp: add a check for 'add_addr_accepted'
    05799c2f1ca5 mptcp: pm: in-kernel: always mark signal+subflow endp as used
    a29641dc1267 mptcp: pm: avoid sending RM_ADDR over same subflow
    7f3b7dc8c6ca drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink
    c33523b8fd2d net: phy: register phy led_triggers during probe to avoid AB-BA deadlock
    71511dae56a7 gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL
    f9f1660b7ffc x86/sev: Allow IBPB-on-Entry feature for SNP guests
    c8ddb2d30d03 platform/x86: hp-bioscfg: Support allocations of larger data
    3c5c818c78b0 wifi: libertas: fix use-after-free in lbs_free_adapter()
    cf29329a13df ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths
    ca049ef5c8c7 gve: defer interrupt enabling until NAPI registration
    212b9632718c drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode with HPD
    3161ae587816 i3c: mipi-i3c-hci: Add missing TID field to no-op command descriptor
    0911fd8e400e i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort
    dcd66a0c0388 i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors
    5c485bc32551 iio: imu: inv_icm42600: fix odr switch to the same value
    27c324ef1638 iio: gyro: mpu3050-i2c: fix pm_runtime error handling
    2a86a396aa00 iio: gyro: mpu3050-core: fix pm_runtime error handling
    10ea2df061f3 iio: buffer: Fix wait_queue not being removed
    dd7b7093bb77 iio: chemical: bme680: Fix measurement wait duration calculation
    342e5f67fb99 iio: potentiometer: mcp4131: fix double application of wiper shift
    dcdf1e92674e iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas()
    5a3952ba82f8 iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas()
    fa87bb35b917 iio: frequency: adf4377: Fix duplicated soft reset mask
    8f9fca12f2f3 iio: dac: ds4424: reject -128 RAW value
    fa6fd9aec721 btrfs: abort transaction on failure to update root in the received subvol ioctl
    40f7c69eb00d smb: client: fix iface port assignment in parse_server_interfaces
    438e77435aee smb: client: fix in-place encryption corruption in SMB2_write()
    dcd1f1321034 smb: client: fix atomic open with O_DIRECT & O_SYNC
    2ca6bdf449b1 lib/bootconfig: check bounds before writing in __xbc_open_brace()
    bbdb80f29ee9 lib/bootconfig: fix snprintf truncation check in xbc_node_compose_key_after()
    f59193807211 x86/apic: Disable x2apic on resume if the kernel expects so
    35e3ec8e589b scsi: core: Fix error handling for scsi_alloc_sdev()
    cc7d44c59ea5 lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error
    b373ff56ed2d s390/dasd: Copy detected format information to secondary device
    3a67baa8eec4 s390/dasd: Move quiesce state with pprc swap
    41e91dff2d39 xfs: fix undersized l_iclog_roundoff values
    eaaaa3abbb20 cifs: make default value of retrans as zero
    e9311e199ac6 tracing: Fix trace_buf_size= cmdline parameter with sizes >= 2G
    aeb7255531ba drm/i915: Fix potential overflow of shmem scatterlist length
    624f991cac21 drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding
    2550d63cc350 drm/amd: Set num IP blocks to 0 if discovery fails
    c658c1c85ec2 drm/amdgpu: Fix use-after-free race in VM acquire
    3704ac6a0d9a net: dsa: microchip: Fix error path in PTP IRQ setup
    81431da77792 net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
    599625881978 net: ncsi: fix skb leak in error paths
    302fef75512b ksmbd: fix use-after-free by using call_rcu() for oplock_info
    b720c84087cb smb: server: fix use-after-free in smb2_open()
    bf4d66d72e4a ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
    d156b1c24f72 pmdomain: bcm: bcm2835-power: Fix broken reset status read
    57e35502faa9 parisc: Check kernel mapping earlier at bootup
    344fde7a3dc0 parisc: Fix initial page table creation for boot
    52db5ef163c9 hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read
    7003352d4327 arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation
    fad178ae8949 nouveau/dpcd: return EBUSY for aux xfer if the device is asleep
    5699359529c6 parisc: Increase initial mapping to 64 MB with KALLSYMS
    f3ca45673dab batman-adv: Avoid double-rtnl_lock ELP metric worker
    422b4524320c tracing: Fix syscall events activation by ensuring refcount hits zero
    9298b0806923 ice: fix retry for AQ command 0x06EE
    5138cd978bab net: mana: Ring doorbell at 4 CQ wraparounds
    1a6da3dbb998 media: dvb-net: fix OOB access in ULE extension header tables
    768f25613a9f staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie
    740bca8bbdb7 staging: rtl8723bs: properly validate the data in rtw_get_ie_ex()
    627cf4d1f0ea ixgbevf: fix link setup issue
    aac3ac27e6da ice: reintroduce retry mechanism for indirect AQ
    1fc8c3a0d249 irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS supports
    3cfdf8d27b66 device property: Allow secondary lookup in fwnode_get_next_child_node()
    54f2f0591216 drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used
    98310fe3a2a7 drm/bridge: samsung-dsim: Fix memory leak in error path
    f3333543326c Revert "tcpm: allow looking for role_sw device in the main node"
    70c78429ef38 scsi: hisi_sas: Fix NULL pointer exception during user_scan()
    8be15087d037 scsi: hisi_sas: Use macro instead of magic number
    228c626df8d5 scsi: hisi_sas: Add time interval between two H2D FIS following soft reset spec
    a6a894413b04 scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend
    069307ae8cb9 i3c: dw-i3c-master: Set SIR_REJECT in DAT on device attach and reattach
    7d86de3847c5 time/jiffies: Mark jiffies_64_to_clock_t() notrace
    657dc653b06a ceph: fix memory leaks in ceph_mdsc_build_path()
    b3f5513141ec ceph: fix i_nlink underrun during async unlink
    59c7bf668c20 libceph: admit message frames only in CEPH_CON_S_OPEN state
    5f2806684b05 libceph: Use u32 for non-negative values in ceph_monmap_decode()
    50156622eb08 libceph: prevent potential out-of-bounds reads in process_message_header()
    3e2e36e9b9f3 libceph: reject preamble if control segment is empty
    8bb87547e92d libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
    8b6767e4141b kprobes: avoid crash when rmmod/insmod after ftrace killed
    a360d3815aae tipc: fix divide-by-zero in tipc_sk_filter_connect()
    a8e9cab16771 ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start
    270277c2ab63 mmc: core: Avoid bitfield RMW for claim/retune flags
    d8f20b282418 mm/kfence: disable KFENCE upon KASAN HW tags enablement
    f36ab071abd0 mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index()
    b88ce81232bb mm/tracing: rss_stat: ensure curr is false from kthread context
    155f471e38aa usb: image: mdc800: kill download URB on timeout
    e7b3d154eb08 usb: mdc800: handle signal and read racing
    9c6159d5b72d usb: renesas_usbhs: fix use-after-free in ISR during device removal
    4ee3062bf2c9 usb: class: cdc-wdm: fix reordering issue in read code path
    659c0c7d50a4 USB: core: Limit the length of unkillable synchronous timeouts
    39bd4097292f USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts
    fc26e98b6cb8 USB: usbcore: Introduce usb_bulk_msg_killable()
    2872b67951fe usb: roles: get usb role switch from parent only for usb-b-connector
    52950203880b usb: cdc-acm: Restore CAP_BRK functionnality to CH343
    24aa4caf7f95 usb: core: don't power off roothub PHYs if phy_set_mode() fails
    19ef3da0a82d usb: misc: uss720: properly clean up reference in uss720_probe()
    f1c8b8183abc usb: dwc3: pci: add support for the Intel Nova Lake -H
    939e3d17b843 usb: yurex: fix race in probe
    b2dd9abf8c06 usb: xhci: Prevent interrupt storm on host controller error (HCE)
    2e2baa8fb5aa usb: xhci: Fix memory leak in xhci_disable_slot()
    2f2418efd495 USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb speed
    9105f4d74762 usb/core/quirks: Add Huawei ME906S-device to wakeup quirk
    551f82df759c USB: add QUIRK_NO_BOS for video capture several devices
    ad4394f269dc KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC
    22bd6fea06bc ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA
    af834b026bfc net: usb: lan78xx: skip LTM configuration for LAN7850
    2aaf0a7be0b8 net: usb: lan78xx: fix TX byte statistics for small packets
    e94d81319259 net: usb: lan78xx: fix silent drop of packets with checksum errors
    c5c5a6c53cf3 ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces
    629cf09464cf ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()
    3dfd1328c052 cgroup: fix race between task migration and iteration
    343d4b4a21a5 Revert "arm64: dts: qcom: sdm845-oneplus: Mark l14a regulator as boot-on"
    ce0caaed5940 usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks()
    3e2f1628faa3 octeontx2-af: devlink: fix NIX RAS reporter to use RAS interrupt status
    e4a4ca0b69c5 octeontx2-af: devlink health: use retained error fmsg API
    fa3183e7c748 octeontx2-af: devlink: fix NIX RAS reporter recovery condition
    cf6099ef493b net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled
    764039ff6515 ASoC: detect empty DMI strings
    35c7624d30cb ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition
    e15b56da10b5 ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address()
    0a1fc25deaba e1000/e1000e: Fix leak in DMA error cleanup
    e611b36efca1 i40e: fix src IP mask checks and memcpy argument names in cloud filter
    628773eba024 nvme-pci: Fix race bug in nvme_poll_irqdisable()
    83e6edd63583 nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set
    f691272c3e8c sched: idle: Make skipping governor callbacks more consistent
    ac8f2dfcecbd regulator: pca9450: Correct interrupt type
    28986d1c093f regulator: pca9450: Make IRQ optional
    540803559993 netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    4a1f6ee69267 netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()
    47b1c5d1b094 netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path
    9b94f0e42ed2 netfilter: x_tables: guard option walkers against 1-byte tail reads
    0a55d62cdb62 netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()
    61243ff7e757 amd-xgbe: prevent CRC errors during RX adaptation with AN disabled
    df65ae0f1330 amd-xgbe: fix link status handling in xgbe_rx_adaptation
    86f5334fcb48 mctp: route: hold key->lock in mctp_flow_prepare_output()
    a3a1ea5d1f8d can: hi311x: hi3110_open(): add check for hi3110_power_enable() return value
    d7900a43b0a3 mctp: i2c: fix skb memory leak in receive path
    8460187b4852 serial: caif: hold tty->link reference in ldisc_open and ser_release
    bba6c0806a8c net: sfp: improve Huawei MA5671a fixup
    17f69ee2ed08 net: sfp: add quirk for Potron SFP+ XGSPON ONU Stick
    2369830617a5 net: sfp: improve Nokia GPON sfp fixup
    783025a3babb net: sfp: re-implement ignoring the hardware TX_FAULT signal
    d9744892b8ed ASoC: simple-card-utils: fix graph_util_is_ports0() for DT overlays
    e03f8d141911 ASoC: simple-card-utils: use __free(device_node) for device node
    317a9298c54b ASoC: soc-core: flush delayed work before removing DAIs and widgets
    8b76136bd446 ASoC: soc-core: drop delayed_work_pending() check before flush
    59b06d8b9bdb net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
    383b37c04a48 net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery
    957d2a58f7f8 net/mlx5: Fix deadlock between devlink lock and esw->wq
    87db2efa8327 net/mlx5: Query to see if host PF is disabled
    0e4dd5078b0c net/mlx5: IFC updates for disabled host PF
    11762a893ffc bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states
    43723dff1a59 drm/msm/dsi: fix pclk rate calculation for bonded dsi
    7c370f2cb7fc drm/msm/dsi: Document DSC related pclk_rate and hdisplay calculations
    c58dcaac49b6 net: dsa: realtek: rtl8365mb: remove ifOutDiscards from rx_packets
    74c39a47856b xprtrdma: Decrement re_receiving on the early exit paths
    2f91ef68d0ed smb/server: Fix another refcount leak in smb2_open()
    fd4ff8c64639 powerpc: 83xx: km83xx: Fix keymile vendor prefix
    a971ce3a39e5 remoteproc: mediatek: Unprepare SCP clock during system suspend
    f3394234b849 remoteproc: sysmon: Correct subsys_name_len type in QMI request
    80bc3c57dd32 powerpc/uaccess: Fix inline assembly for clang build on PPC32
    9e5df7e19c44 ALSA: usb-audio: Check max frame size for implicit feedback mode, too
    8d66e46ff0f4 ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0
    32af15506450 scsi: ufs: core: Fix shift out of bounds when MAXQ=32
    0614f5618c24 scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace()
    7b640a732689 ASoC: cs42l43: Report insert for exotic peripherals
    f43a420065f0 ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table
    80e35a0a8ab5 scsi: ses: Fix devices attaching to different hosts
    486519660bd9 ACPI: OSI: Add DMI quirk for Acer Aspire One D255
    b006c61a5d97 wifi: mac80211: set default WMM parameters on all links
    d7963d6997fe unshare: fix unshare_fs() handling
    7da755e0d02e scsi: mpi3mr: Add NULL checks when resetting request and reply queues
    5bb47c03024e ACPI: PM: Save NVS memory on Lenovo G70-35
    e7919a293f9b scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT
    ae10787d955f apparmor: fix race between freeing data and fs accessing it
    6ef1f2926c41 apparmor: fix race on rawdata dereference
    f90e3ecd9e1e apparmor: fix differential encoding verification
    17debf558602 apparmor: fix unprivileged local user can do privileged policy management
    55ef2af7490a apparmor: Fix double free of ns_name in aa_replace_profiles()
    7c7cf05e0606 apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
    5a184f7cbdea apparmor: fix side-effect bug in match_char() macro usage
    3f8699b3ee0c apparmor: fix: limit the number of levels of policy namespaces
    33959a491e9f apparmor: replace recursive profile removal with iterative approach
    663ce34786e7 apparmor: fix memory leak in verify_header
    07cf6320f40e apparmor: validate DFA start states are in bounds in unpack_pdb
    7f4d6a5d3429 net: tcp: accept old ack during closing
    5a110ddcc99b net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
    59c15b9cc453 tracing: Add NULL pointer check to trigger_data_free()
    c7919c1c1d80 selftest/arm64: Fix sve2p1_sigill() to hwcap test
    a0fb59f527d0 xdp: produce a warning when calculated tailroom is negative
    d5f7daed130c i40e: use xdp.frame_sz as XDP RxQ info frag_size
    7b9c0ee7fed9 i40e: fix registering XDP RxQ info
    183f940bdf90 xsk: introduce helper to determine rxq->frag_size
    8701504563fa xdp: use modulo operation to calculate XDP frag tailroom
    5b1449301ca0 net/sched: act_ife: Fix metalist update behavior
    b299121e7453 net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
    5f93e6b4d12b net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
    a12cdaa3375f net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
    29629dd7d373 net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
    3cdb52d6eba0 net: stmmac: Fix error handling in VLAN add and delete paths
    722a28b635ec nfc: rawsock: cancel tx_work before socket teardown
    edc188322caa nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback
    dcbcccfc5195 nfc: nci: free skb on nci_transceive early error paths
    f7d8b5d649dd net: nfc: nci: Fix zero-length proprietary notifications
    dbd58b0730aa net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs
    e42ff5abbd14 nvme: fix memory allocation in nvme_pr_read_keys()
    be3b61ebcafe nvme: reject invalid pr_read_keys() num_keys values
    5d53fe502ef4 drm/sched: Fix kernel-doc warning for drm_sched_job_done()
    0c3dce09e8ef amd-xgbe: fix sleep while atomic on suspend/resume
    581800298313 ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
    db93ff008d2e smb/client: fix buffer size for smb311_posix_qinfo in SMB311_posix_query_info()
    99acd1ea3499 smb/client: fix buffer size for smb311_posix_qinfo in smb2_compound_op()
    9b02c5c4147f bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
    4bb55e430d82 bpf: export bpf_link_inc_not_zero.
    39959a7d3efe xen/acpi-processor: fix _CST detection using undersized evaluation buffer
    8babb2714033 net/rds: Fix circular locking dependency in rds_tcp_tune
    11fc15378e87 indirect_call_wrapper: do not reevaluate function pointer
    7ae7b093b7db wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()
    a6605f619131 wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()
    aca4c9e4901b wifi: wlcore: Fix a locking bug
    78bb63bbabb3 wifi: cw1200: Fix locking in error paths
    3bf4ee25f051 octeon_ep: avoid compiler and IQ/OQ reordering
    4818b80d20de octeon_ep: Relocate counter updates before NAPI
    5c262bd0e393 bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
    f8db044a0a47 net: dsa: realtek: rtl8365mb: fix rtl8365mb_phy_ocp_write return value
    14cecde3eb07 kunit: tool: copy caller args in run_kernel to prevent mutation
    eb5632fae6a3 rust: kunit: fix warning when !CONFIG_PRINTK
    b73832292cd9 can: mcp251x: fix deadlock in error path of mcp251x_open
    70e951afad4c can: bcm: fix locking for bcm_op runtime updates
    b4d1e6d27f93 amd-xgbe: fix MAC_TCR_SS register width for 2.5G and 10M speeds
    622062f24644 atm: lec: fix null-ptr-deref in lec_arp_clear_vccs
    c7becfe3e604 dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
    420bc92cc966 dpaa2-switch: do not clear any interrupts automatically
    fb64be8e20dc xsk: Fix zero-copy AF_XDP fragment drop
    5172adf9efb8 xsk: Fix fragment node deletion to prevent buffer leak
    eb66c67b0847 xsk: s/free_list_node/list_node/
    560c974b7ccd xsk: Get rid of xdp_buff_xsk::xskb_list_node
    4e58b99c3c33 net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling in ALE table
    391396b5052d drm/solomon: Fix page start when updating rectangle in page addressing mode
    352d940bcdbd drm/ssd130x: Replace .page_height field in device info with a constant
    3327bb9d474d drm/ssd130x: Store the HW buffer in the driver-private CRTC state
    be3079b7a328 drm/ssd130x: Use bool for ssd130x_deviceinfo flags
    9328cc4e511c e1000e: clear DPG_EN after reset to avoid autonomous power-gating
    337ecf555a4b hwmon: (it87) Check the it87_lock() return value
    95b14ecc5688 pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
    cc06e3f73390 platform/x86: thinkpad_acpi: Fix errors reading battery thresholds
    896449ad9053 pinctrl: equilibrium: fix warning trace on load
    27fad3a507d6 pinctrl: equilibrium: rename irq_chip function callbacks
    70cde1f24ffb hwmon: (aht10) Fix initialization commands for AHT20
    166678027ad4 hwmon: (aht10) Add support for dht20
    cc7f6f0a2666 ARM: clean up the memset64() C wrapper
    ec312cb9bd97 selftests: mptcp: join: check removing signal+subflow endp
    047de213219d selftests: mptcp: more stable simult_flows tests
    7c01b680beaf scsi: core: Fix refcount leak for tagset_refcnt
    3990f352bb0a smb: client: Don't log plaintext credentials in cifs_set_cifscreds
    f65c92e81cb4 smb: client: fix broken multichannel with krb5+signing
    874c47503e0f smb: client: fix cifs_pick_channel when channels are equally loaded
    6f1d1614f841 drbd: fix null-pointer dereference on local read error
    e91d8d6565b7 drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
    6b847d65f5b0 Squashfs: check metadata block offset is within range
    e8ef82cb6443 scsi: target: Fix recursive locking in __configfs_open_file()
    7dbffffd5761 net/sched: ets: fix divide by zero in the offload path
    1b1fac4c7a3a RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
    d0148965dbca IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
    22a9adea7e26 wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
    650981e718e6 wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
    fa18639deab4 wifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
    129c8bb320a7 wifi: radiotap: reject radiotap with unknown bits
    a0c6ae2ea845 ALSA: usb-audio: Use correct version for UAC3 header validation
    cf48c2d1db3a platform/x86: dell-wmi: Add audio/mic mute key codes
    411ba3cd837f platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
    6a25e2527928 x86/efi: defer freeing of boot services memory
    6e330889e6c8 HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
    888f164453f2 can: usb: f81604: handle bulk write errors properly
    9b740ff5bc64 can: usb: f81604: handle short interrupt urb messages properly
    f6e90c113c92 can: usb: etas_es58x: correctly anchor the urb in the read bulk callback
    13b646eec3ba can: ucan: Fix infinite loop from zero-length messages
    54ee74307165 can: usb: f81604: correctly anchor the urb in the read bulk callback
    1818974e1b5e can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message
    7f8505c7ce3f net: usb: pegasus: validate USB endpoints
    12c0243de0ae net: usb: kalmia: validate USB endpoints
    72f90f481c6a net: usb: kaweth: validate USB endpoints
    d1f6d20b3c26 nfc: pn533: properly drop the usb interface reference on disconnect
    af050ab44fa1 media: dvb-core: fix wrong reinitialization of ringbuffer on reopen
    5f8463e43720 eventpoll: Fix integer overflow in ep_loop_check_proc()
    1b3ae721257e drm/amdgpu: keep vga memory on MacBooks with switchable graphics
    aa7f9ef72eae drm/amd: Drop special case for yellow carp without discovery
    4b4eee6d0c00 net: arcnet: com20020-pci: fix support for 2.5Mbit cards
    efc159492b5c ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314
    f3cb23e1fcf3 hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race
    020bfaac6cb4 ALSA: hda/conexant: Add quirk for HP ZBook Studio G4
    c676ab65519c drm/amd: Fix hang on amdgpu unload by using pci_dev_is_disconnected()
    d637f6ec149f usb: cdns3: fix role switching during resume
    3de5fd27af5b usb: cdns3: call cdns_power_is_lost() only once in cdns_resume()
    3097fb95e244 usb: cdns3: remove redundant if branch
    7b900a94d716 clk: tegra: tegra124-emc: fix device leak on set_rate()
    8acf534d5a58 arm64: dts: rockchip: Fix rk356x PCIe range mappings
    3469112edc5c mfd: omap-usb-host: Fix OF populate on driver rebind
    1d4ea57730bf mfd: omap-usb-host: Convert to platform remove callback returning void
    59b76ae68764 mfd: qcom-pm8xxx: Fix OF populate on driver rebind
    a97ff3b70ff5 mfd: qcom-pm8xxx: Convert to platform remove callback returning void
    57e83bfbe1e4 ext4: fix e4b bitmap inconsistency reports
    e33256b2f927 ext4: convert bd_buddy_page to bd_buddy_folio
    ccab2af6c19f ext4: convert bd_bitmap_page to bd_bitmap_folio
    ceee57fd7207 ext4: delete redundant calculations in ext4_mb_get_buddy_page_lock()
    31c4c67dec33 mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()
    c42ffd816c0f mailbox: Allow controller specific mapping using fwnode
    cfdb216691ec mailbox: Use guard/scoped_guard for con_mutex
    bef5ecf09d70 mailbox: Use dev_err when there is error
    5e99cbdfcd15 mailbox: remove unused header files
    235359afbe0a mailbox: sort headers alphabetically
    97b60acdca6f mailbox: don't protect of_parse_phandle_with_args with con_mutex
    49ada773c180 mailbox: Use of_property_match_string() instead of open-coding
    dc7c9b9d03a5 ext4: drop extent cache when splitting extent fails
    f0931a5c1700 ext4: drop extent cache after doing PARTIAL_VALID1 zeroout
    67cdb7bd7442 ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O
    11406eb96a19 ext4: correct the comments place for EXT4_EXT_MAY_ZEROOUT
    ed0096fc86b2 ext4: get rid of ppath in ext4_ext_handle_unwritten_extents()
    d7b04ea31c6e ext4: get rid of ppath in ext4_ext_convert_to_initialized()
    c24ce099bea9 ext4: get rid of ppath in ext4_convert_unwritten_extents_endio()
    147a6a2725b1 ext4: get rid of ppath in ext4_split_convert_extents()
    cda8a34348d7 ext4: get rid of ppath in ext4_split_extent()
    58ddae5d77b1 ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
    e766534911b3 ext4: subdivide EXT4_EXT_DATA_VALID1
    ffb68fc57207 ext4: get rid of ppath in ext4_split_extent_at()
    fb138df7d886 ext4: get rid of ppath in ext4_ext_insert_extent()
    8f6e910852d8 ext4: get rid of ppath in ext4_ext_create_new_leaf()
    cafb151eb180 ext4: get rid of ppath in ext4_find_extent()
    a4a7024448ab bus: omap-ocp2scp: fix OF populate on driver rebind
    e4be2bd01a76 bus: omap-ocp2scp: Convert to platform remove callback returning void
    43bb0a265b26 drm/tegra: dsi: fix device leak on probe
    ec3be7dc9391 KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()
    5e8bf325ed12 KVM: x86: WARN if a vCPU gets a valid wakeup that KVM can't yet inject
    ca921be7a117 media: tegra-video: Fix memory leak in __tegra_channel_try_format()
    7a9c901edcaf media: tegra-video: Use accessors for pad config 'try_*' fields
    32a1889f7bb0 KVM: x86: Return "unsupported" instead of "invalid" on access to unsupported PV MSR
    469a8a038d8b KVM: x86: Rename KVM_MSR_RET_INVALID to KVM_MSR_RET_UNSUPPORTED
    626ccc6daa7a KVM: x86: Fix KVM_GET_MSRS stack info leak
    fa0e278a1230 PCI: Use resource_set_range() that correctly sets ->end
    ffe8617e2e5b resource: Add resource set range and size helpers
    fffdb0fece19 PCI: Use resource names in PCI log messages
    bc440d87e655 PCI: Update BAR # and window messages
    b9eccd59697f memory: mtk-smi: fix device leak on larb probe
    b16599fedf49 memory: mtk-smi: fix device leaks on common probe
    646ac65db6c1 memory: mtk-smi: Convert to platform remove callback returning void
    5f5997339cf0 PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value
    8a95fb9df110 bpf: Fix stack-out-of-bounds write in devmap
    dfe079bb6ab3 btrfs: fix compat mask in error messages in btrfs_check_features()
    a1b82706c233 btrfs: fix warning in scrub_verify_one_metadata()
    6eac621b2deb btrfs: fix objectid value in error message in check_extent_data_ref()
    ad567ccfd90c btrfs: fix incorrect key offset in error message in check_dev_extent_item()
    ab69bf6f8970 btrfs: add support for inserting raid stripe extents
    cbca08a23773 btrfs: read raid stripe tree from disk
    fff272a83847 btrfs: add raid stripe tree definitions
    9895ddc5efec btrfs: move btrfs_extref_hash into inode-item.h
    d928f8aec88d btrfs: remove btrfs_crc32c wrapper
    971658d3932b btrfs: move btrfs_crc32c_final into free-space-cache.c
    37fc52528383 ALSA: hda: cs35l56: Fix signedness error in cs35l56_hda_posture_put()
    996d43a72d11 ALSA: pci: hda: use snd_kcontrol_chip()
    4f8d58123378 perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
    949e15a8dbde ALSA: usb-audio: Use inclusive terms
    6ec99e9c90f4 ALSA: usb-audio: Cap the packet size pre-calculations
    133c3f3dde72 scsi: ufs: core: Move link recovery for hibern8 exit failure to wl_resume
    0990188985f5 rseq: Clarify rseq registration rseq_size bound check comment
    7b2c39f7bada ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite devices
    8b00427317ba scsi: pm8001: Fix use-after-free in pm8001_queue_command()
    be4c63507aca scsi: lpfc: Properly set WC for DPP mapping
    2edbd1733091 irqchip/sifive-plic: Fix frozen interrupt due to affinity setting
    0bd326dffd9e drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse()
    7e55d0788b36 drm/vmwgfx: Return the correct value in vmw_translate_ptr functions
    2106a0153b5d drm/vmwgfx: Fix invalid kref_put callback in vmw_bo_dirty_release

(From OE-Core rev: 5a3cfb5dd393656dae18eece3c006fb1a3dc244a)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Bruce Ashfield
fe8122e97d linux-yocto/6.6: update to v6.6.129
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    4fc00fe35d46 Linux 6.6.129
    acf7c8972775 Revert "x86/kexec: add a sanity check on previous kernel's ima kexec buffer"
    682d8e2f892b Linux 6.6.128
    0ac0e02183c5 arm64: Fix sampling the "stable" virtual counter in preemptible section
    18845fb30921 drm/i915/wakeref: clean up INTEL_WAKEREF_PUT_* flag macros
    fe418ef21efd NTB: ntb_transport: Fix too small buffer for debugfs_name
    1cdff5d564fe tracing: Wake up poll waiters for hist files when removing an event
    e4e5026252b4 tracing: Fix checking of freed trace_event_file for hist files
    ad058a4317db net: nfc: nci: Fix parameter validation for packet data
    dc99b25ed4f7 arm64: Force the use of CNTVCT_EL0 in __delay()
    ad3640895956 x86/kexec: Copy ACPI root pointer address from config table
    9c735a7d98c9 net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash()
    1e300c33ef3c net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
    6ccfcad1b582 ASoC: amd: yc: Add DMI quirk for ASUS Vivobook Pro 15X M6501RR
    c854ab481ece cifs: some missing initializations on replay
    6a3ce8c8ad80 fbcon: Remove struct fbcon_display.inverse
    b6de6d481cc2 fbdev: ffb: fix corrupted video output on Sun FFB1
    3ed019654234 fbdev: of: display_timing: fix refcount leak in of_get_display_timings()
    e8c5d5f6cd66 fbdev: vt8500lcdfb: fix missing dma_free_coherent()
    a785c4e2a999 fbcon: check return value of con2fb_acquire_newinfo()
    632d233cf2e6 ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
    e075ec9b08f8 atm: fore200e: fix use-after-free in tasklets during device removal
    9f8ad199844c net: intel: fix PCI device ID conflict between i40e and ipw2200
    6eb571a37631 io_uring/filetable: clamp alloc_hint to the configured alloc range
    0f4dcba31bf4 tracing: Fix to set write permission to per-cpu buffer_size_kb
    ec4445ae9e58 net: macb: Fix tx/rx malfunction after phy link down and up
    013ac469596a octeontx2-af: CGX: fix bitmap leaks
    0f85a9655445 net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean()
    63afc078bba6 net: ethernet: marvell: skge: remove incorrect conflicting PCI ID
    710657d3d31f LoongArch: Disable instrumentation for setup_ptwalker()
    6868bd64dc90 LoongArch: Guard percpu handler under !CONFIG_PREEMPT_RT
    a50371c6ad99 LoongArch: Prefer top-down allocation after arch_mem_init()
    bb1a54f7f011 LoongArch: Make cpumask_of_node() robust against NUMA_NO_NODE
    9efa154609cd ceph: supply snapshot context in ceph_zero_partial_object()
    103e9d1d43e6 MIPS: rb532: Fix MMIO UART resource registration
    953953abb66e cifs: Fix locking usage for tcon fields
    cc3f83b6fb37 staging: rtl8723bs: fix null dereference in find_network
    369d369ed08f parisc: kernel: replace kfree() with put_device() in create_tree_node()
    a19b61fdb958 PCI: Fix pci_slot_trylock() error handling
    65e794574069 net: cpsw_new: Fix unnecessary netdev unregistration in cpsw_probe() error path
    4857c37c7ba9 drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
    7a4fd19c567f tipc: fix RCU dereference race in tipc_aead_users_dec()
    8e875cf8851b mtd: rawnand: pl353: Fix software ECC support
    f5da4c24aa6d usb: dwc2: fix resume failure if dr_mode is host
    76c1123ffccf usb: dwc3: gadget: Move vbus draw to workqueue context
    aa8d68d97c7f scsi: ufs: core: Flush exception handling work when RPM level is zero
    d3e837e11ee9 perf/arm-cmn: Reject unsupported hardware configurations
    9bd98d088f47 remoteproc: imx_rproc: Fix invalid loaded resource table detection
    d99a08c2b4d5 btrfs: continue trimming remaining devices on failure
    41a09925ec68 arm64: Fix non-atomic __READ_ONCE() with CONFIG_LTO=y
    1047ca2d8169 PCI/IOV: Fix race between SR-IOV enable/disable and hotplug
    639265296fe6 Revert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV"
    cfccd3b8c51b kexec: derive purgatory entry from symbol
    bb273b68c171 ocfs2: fix reflink preserve cleanup issue
    649c2e853608 rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net()
    81c44a4bc168 mm/highmem: fix __kmap_to_page() build error
    1eabfd2c437b iio: gyro: itg3200: Fix unchecked return value in read_raw
    9d0ca11258e7 powerpc/smp: Add check for kcalloc() failure in parse_thread_groups()
    442f5db91317 tools: Fix bitfield dependency failure
    e4709950acd4 dm mpath: make pg_init_delay_msecs settable
    542dd6da35eb bus: fsl-mc: fix an error handling in fsl_mc_device_add()
    65f5a17b6d56 usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN
    22e460b6333a x86/kexec: add a sanity check on previous kernel's ima kexec buffer
    57c4fd0f4b02 nvmem: Drop OF node reference on nvmem_add_one_cell() failure
    13c1f31f777c nfsd: fix return error code for nfsd_map_name_to_[ug]id
    d92b8fac294b md/bitmap: fix GPF in write_page caused by resize race
    142b1bba3299 PCI: endpoint: Fix swapped parameters in pci_{primary/secondary}_epc_epf_unlink() functions
    708e20c66b27 KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()
    a6f660d62bc1 xfs: fix remote xattr valuelblk check
    38613c01f69e xfs: fix freemap adjustments when adding xattrs to leaf blocks
    ffaf5c99d0f8 xfs: delete attr leaf freemap entries when empty
    e2e7c275f557 mfd: core: Add locking around 'mfd_of_node_list'
    01aed2f1d7cb iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode
    a5b1ddbe31f4 media: verisilicon: AV1: Fix tile info buffer size
    8be53110395e xfs: mark data structures corrupt on EIO and ENODATA
    297bb8b1db60 selftests/mm/charge_reserved_hugetlb: drop mount size for hugetlbfs
    aa5f25d55cda mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP allocations
    8dcff1979381 drm: of: drm_of_panel_bridge_remove(): fix device_node leak
    52920a853381 media: venus: vdec: restrict EOS addr quirk to IRIS2 only
    225f2221b422 media: venus: vdec: fix error state assignment for zero bytesused
    272d44fa7bce arm64: dts: rockchip: Do not enable hdmi_sound node on Pinebook Pro
    ed36f6ae0039 dm-unstripe: fix mapping bug when there are multiple targets in a table
    fb49f209995f dm-integrity: fix recalculation in bitmap mode
    de7934627cc4 s390/pci: Handle futile config accesses of disabled devices directly
    1c7c87cf18da clk: tegra: tegra124-emc: Fix potential memory leak in tegra124_clk_register_emc()
    0f0809bfe4fa media: i2c: ov01a10: Fix digital gain range
    85cc6574f21b clk: clk-apple-nco: Add "apple,t8103-nco" compatible
    3880e331b0b3 KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation
    e113339cc7d2 soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
    d451bf970a0c soc: ti: k3-socinfo: Fix regmap leak on probe failure
    7daf279c674d dm: clear cloned request bio pointer when last clone bio completes
    2d10a3dad8d6 dm-integrity: fix a typo in the code for write/discard race
    d03a29cb36d6 media: i2c: ov5647: use our own mutex for the ctrl lock
    089625cccd7e media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode
    c146483bad46 media: i2c: ov5647: Sensor should report RAW color space
    e5f4aad2627d media: i2c: ov5647: Correct minimum VBLANK value
    1f413dac763a media: i2c: ov5647: Correct pixel array offset
    cabd025182cf media: i2c: ov5647: Initialize subdev before controls
    c9af1818387f media: ccs: Avoid possible division by zero
    0c074e80921f media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()
    8de39720e7a3 media: i2c: ov01a10: Fix test-pattern disabling
    a14a3cef8017 media: i2c: ov01a10: Add missing v4l2_subdev_cleanup() calls
    567a03fe8d08 media: i2c: ov01a10: Fix analogue gain range
    e2f6d78dc3a8 media: i2c: ov01a10: Fix reported pixel-rate value
    bb2b049f75f1 media: i2c: ov01a10: Fix the horizontal flip control
    ccb92def042a media: i2c/tw9906: Fix potential memory leak in tw9906_probe()
    9cb9eca33d20 media: i2c/tw9903: Fix potential memory leak in tw9903_probe()
    046c5db6bbba media: cx25821: Add missing unmap in snd_cx25821_hw_params()
    544215cc37d0 media: cx23885: Add missing unmap in snd_cx23885_hw_params()
    10ab64f8efc2 media: cx88: Add missing unmap in snd_cx88_hw_params()
    27c508f61963 media: radio-keene: fix memory leak in error path
    dd8508820246 media: verisilicon: AV1: Set IDR flag for intra_only frame type
    8305902ac038 arm64: dts: apple: t8112-j473: Keep the HDMI port powered on
    b74bf7d0d01f HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
    3f1b21cc67a1 HID: prodikeys: Check presence of pm->input_ep82
    243e1165eb03 HID: magicmouse: Do not crash on missing msc->input
    449004434e1f HID: hid-pl: handle probe errors
    cad7442ff23b arm64: Disable branch profiling for all arm64 code
    deb8f6dfd31d KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding
    275e15fd1cf7 ARM: omap2: Fix reference count leaks in omap_control_init()
    b44eb959159f media: verisilicon: AV1: Fix tx mode bit setting
    8ad7e6ea46a9 media: verisilicon: AV1: Fix enable cdef computation
    564fd3a63efc media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
    12cafc15d246 media: mtk-mdp: Fix error handling in probe function
    637510cb5bed media: mediatek: encoder: Fix uninitialized scalar variable issue
    031f2adc1499 dm-verity: correctly handle dm_bufio_client_create() failure
    a9ddc035050a fpga: dfl: use subsys_initcall to allow built-in drivers to be added
    d6f5aed42760 ASoC: SOF: ipc4-control: Keep the payload size up to date
    e1dd7092fa8f ASoC: SOF: ipc4-control: Use the correct size for scontrol->ipc_control_data
    59fe643f21b9 ASoC: SOF: ipc4-topology: Correct the allocation size for bytes controls
    3a5a4b066329 ASoC: SOF: ipc4-control: If there is no data do not send bytes update
    955e2d6e5e0a clk: renesas: rzg2l: Select correct div round macro
    a4be3b90ba9d clk: renesas: rzg2l: Fix intin variable size
    90c8353f4718 rpmsg: core: fix race in driver_override_show() and use core helper
    7ef82863d422 netfilter: nf_conntrack_h323: fix OOB read in decode_choice()
    b690635d4719 dpaa2-switch: validate num_ifs to prevent out-of-bounds write
    9ac6aebef4b4 net: consume xmit errors of GSO frames
    175881094756 net/mlx5: Fix missing devlink lock in SRIOV enable error path
    54fb0577ebe7 net/mlx5: DR, Fix circular locking dependency in dump
    b324327ff6f4 RDMA/umem: Fix double dma_buf_unpin in failure path
    35854ed5c40b net: usb: pegasus: enable basic endpoint checking
    df001db47708 RDMA/efa: Fix typo in efa_alloc_mr()
    337d7b4112a4 net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets
    52d469319ced RDMA/core: Fix stale RoCE GIDs during netdev events at registration
    0b7d596da5de tipc: fix duplicate publication key in tipc_service_insert_publ()
    481ea39b342c Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ
    efcdb4da480c Bluetooth: L2CAP: Fix not checking output MTU is acceptable on L2CAP_ECRED_CONN_REQ
    1a138921ce56 Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ
    1d93a369b5aa Bluetooth: hci_qca: Cleanup on all setup failures
    7247f340f824 Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ
    2983b39f8c0d Remove WARN_ALL_UNSEEDED_RANDOM kernel config option
    1f40fde29349 wifi: cfg80211: wext: fix IGTK key ID off-by-one
    322437972f0a net: ethernet: xscale: Check for PTP support properly
    854f5997df49 net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()
    19f359963ae8 net: usb: lan78xx: scan all MDIO addresses on LAN7801
    ef9b10a02050 net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode
    166801e49a5b xfrm: always flush state and policy upon NETDEV_UNREGISTER event
    56d5c0557e53 ipmi: ipmb: initialise event handler read bytes
    f13e4fe961a7 xfrm: skip templates check for packet offload tunnel mode
    719918fc88df xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
    d0559d07afab ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut
    85c9daa1f831 ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access
    a4557dc20df4 rtc: zynqmp: correct frequency value
    61bd8787c605 drm/amd/display: Remove conditional for shaper 3DLUT power-on
    0b284a7ce311 btrfs: replace BUG() with error handling in __btrfs_balance()
    8995fc0e00b3 ALSA: usb-audio: Add sanity check for OOB writes at silencing
    6a997eb80644 drm/radeon: Add HAINAN clock adjustment
    5b9af0342402 drm/amdgpu: Add HAINAN clock adjustment
    c26bde6301f2 ALSA: usb-audio: Update the number of packets properly at receiving
    d2e92247b24a drm/amdgpu: Adjust usleep_range in fence wait
    068dee782c8c drm/amd/display: Avoid updating surface with the same surface under MPO
    1a7f1116c7f8 ARM: 9467/1: mm: Don't use %pK through printk
    44373b1e9c12 include: uapi: netfilter_bridge.h: Cover for musl libc
    9f33e83c8393 thermal: int340x: Fix sysfs group leak on DLVR registration failure
    e1dc45d97975 libceph: define and enforce CEPH_MAX_KEY_LEN
    a87a445ac1d9 ceph: supply snapshot context in ceph_uninline_data()
    2f5c626ea792 fs/ntfs3: avoid calling run_get_entry() when run == NULL in ntfs_read_run_nb_ra()
    ad0d779cdc26 fs/ntfs3: drop preallocated clusters for sparse and compressed files
    8d8c70b57dbe fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
    af839013c70a fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
    68e32694be23 fs: ntfs3: check return value of indx_find to avoid infinite loop
    6dedf0369f2a MIPS: Loongson: Make cpumask_of_node() robust against NUMA_NO_NODE
    da08099d5f7a iio: magnetometer: Remove IRQF_ONESHOT
    53f2152b48d5 iio: Use IRQF_NO_THREAD
    be5465701341 Revert "mfd: da9052-spi: Change read-mask to write-mask"
    dc3bc979814b phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature
    afb941338c8e phy: mvebu-cp110-utmi: fix dr_mode property read from dts
    d476130e53d3 watchdog: imx7ulp_wdt: handle the nowayout option
    0883ddd583ed binder: don't use %pK through printk
    1d7120244b54 fix it87_wdt early reboot by reporting running timer
    4ff5ab3e7141 serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done
    8311bb40698b staging: rtl8723bs: fix memory leak on failure path
    03a2f7f9864c misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66
    ece3722169ba misc: bcm_vk: Fix possible null-pointer dereferences in bcm_vk_read()
    c219c20cc357 dmaengine: stm32-mdma: initialize m2m_hw_period and ccr to fix warnings
    f89324e2e09d dmaengine: sun6i: Choose appropriate burst length under maxburst
    f9305dda5015 fpga: of-fpga-region: Fail if any bridge is missing
    b2bbcaa36c1a usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed PDOs
    32ccda4895ba serial: 8250_dw: handle clock enable errors in runtime_resume
    52b42c24750a staging: rtl8723bs: fix missing status update on sdio_alloc_irq() failure
    cd496527efa8 soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded of NUC15)
    3be7beef4a05 m68k: nommu: fix memmove() with differently aligned src and dest for 68000
    6ce681cf8082 clk: microchip: core: correct return value on *_get_parent()
    e2809ad08252 mailbox: sprd: clear delivery flag before handling TX done
    4c4679b31b9d remoteproc: mediatek: Break lock dependency to `prepare_lock`
    332fb842181e mailbox: sprd: mask interrupts that are not handled
    17ee46882b3e mailbox: imx: Skip the suspend flag for i.MX7ULP
    51edcbd17c8d mailbox: pcc: Remove spurious IRQF_ONESHOT usage
    f720e653aa1a remoteproc: imx_dsp_rproc: Skip RP_MBOX_SUSPEND_SYSTEM when mailbox TX channel is uninitialized
    cb6c4aa73491 tracing: Fix false sharing in hwlat get_sample()
    9566c87101b2 vhost: fix caching attributes of MMIO regions by setting them explicitly
    f1bf5ebd5fda scsi: buslogic: Reduce stack usage
    d16337560750 hisi_acc_vfio_pci: update status after RAS error
    559e227b1df7 ata: libata: avoid long timeouts on hot-unplugged SATA DAS
    55de264a4d32 RDMA/rtrs-clt: For conn rejection use actual err number
    3819890d6ab2 nfc: nxp-nci: remove interrupt trigger type
    392e3d44841d myri10ge: avoid uninitialized variable use
    6e2a6100ac5b PCI: Mark Nvidia GB10 to avoid bus reset
    846b226065fe PCI: Add ACS quirk for Qualcomm Hamoa & Glymur
    ec494c0260bf PCI: Enable ACS after configuring IOMMU for OF platforms
    a2376e912723 PCI: Fix pci_slot_lock () device locking
    f5ea62163a78 PCI: Mark ASM1164 SATA controller to avoid bus reset
    391200c274e9 net/rds: Clear reconnect pending bit
    f713dcd2ce83 vmw_vsock: bypass false-positive Wnonnull warning with gcc-16
    7a8acafd45a9 net: usb: sr9700: remove code to drive nonexistent multicast filter
    87465580215c wifi: ath10k: fix lock protection in ath10k_wmi_event_peer_sta_ps_state_chg()
    b015d4c70c9a wifi: rtw89: pci: restore LDO setting after device resume
    d9b549b6951b octeontx2-af: Workaround SQM/PSE stalls by disabling sticky
    37f4e6804d98 Bluetooth: btusb: Add device ID for Realtek RTL8761BU
    c051ef2f61f4 Bluetooth: btusb: Add new VID/PID for RTL8852CE
    07960da05c0d Bluetooth: hci_conn: use mod_delayed_work for active mode timeout
    c06dbfd954c9 Bluetooth: hci_conn: Set link_policy on incoming ACL connections
    9eaeba5600e5 ipv4: fib: Annotate access to struct fib_alias.fa_state.
    31d4bb68f436 wifi: iwlegacy: add missing mutex protection in il3945_store_measurement()
    941e3066441c wifi: iwlegacy: add missing mutex protection in il4965_store_tx_power()
    2ace7ac88cb0 net: hns3: extend HCLGE_FD_AD_QID to 11 bits
    d5cd3bb7794e ipv4: igmp: annotate data-races around idev->mr_maxdelay
    ab2848d3783a gro: change the BUG_ON() in gro_pull_from_frag0()
    f0f729bdffb0 net/rds: No shortcut out of RDS_CONN_ERROR
    db62e9f44838 wifi: iwlwifi: mvm: check the validity of noa_len
    116bc0980e91 net: usb: r8152: fix transmit queue timeout
    f4bf64072c36 openrisc: define arch-specific version of nop()
    07a9b32eaae7 netfilter: xt_tcpmss: check remaining length before reading optlen
    89f50775d883 netfilter: nf_conntrack: Add allow_clash to generic protocol handler
    99c75e53cec0 ext4: mark group extend fast-commit ineligible
    0d5fcb063cda ext4: move ext4_percpu_param_init() before ext4_mb_init()
    83b074b69022 ext4: mark group add fast-commit ineligible
    46ed4e9c8d30 ipv6: exthdrs: annotate data-race over multiple sysctl
    55170230de66 ipv6: annotate data-races in ip6_multipath_hash_{policy,fields}()
    f73528f140f1 wifi: ath12k: fix preferred hardware mode calculation
    c5547727bd1c wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1
    ddfe47664cc6 PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port
    d880c9b73890 wifi: rtw89: wow: add reason codes for disassociation in WoWLAN mode
    f2f65b28d802 iommu/amd: move wait_on_sem() out of spinlock
    5bfb25495e39 wifi: libertas: fix WARNING in usb_tx_block
    9ff4843e6ea3 iommu/arm-smmu-v3: Improve CMDQ lock fairness and efficiency
    4f9e7ca933a9 dm: remove fake timeout to avoid leak request
    df379f57c2cd dm: replace -EEXIST with -EBUSY
    dd181178c245 wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H
    a96d161cfdb1 wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode()
    9fdce77e38c1 wifi: rtw88: fix DTIM period handling when conf->dtim_period is zero
    f70fcbc2ac7c jfs: nlink overflow in jfs_rename
    68f7fc769243 jfs: Add missing set_freezable() for freezable kthread
    34506cb119bb ALSA: usb-audio: Add iface reset and delay quirk for AB13X USB Audio
    8fb5c4c979ae modpost: Amend ppc64 save/restfpr symnames for -Os build
    fecfe41f7ed0 ASoC: es8328: Add error unwind in resume
    18c67fb3750b hwmon: (f71882fg) Add F81968 support
    f8ddbe303419 hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE
    2d48f60307e6 ASoC: codecs: max98390: Check return value of devm_gpiod_get_optional() in max98390_i2c_probe()
    3383271464b7 spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end
    19513daa8d13 ASoC: sunxi: sun50i-dmic: Add missing check for devm_regmap_init_mmio
    d1b6536ac20d gpio: aspeed-sgpio: Change the macro to support deferred probe
    98c0e07dc7d6 ALSA: hda/conexant: Add headset mic fix for MECHREVO Wujie 15X Pro
    49afc2e5bfae HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK
    4df1e6252d07 HID: multitouch: add eGalaxTouch EXC3188 support
    876bb1eabdb1 media: rkisp1: Fix filter mode register configuration
    ac2d898da509 drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release
    80b8b0df370f drm/atmel-hlcdc: don't reject the commit if the src rect has fractional parts
    ec40702029b0 drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback
    af67b50311e7 virt: vbox: uapi: Mark inner unions in packed structs as packed
    34eae7e0ab61 hyper-v: Mark inner union in hv_kvp_exchg_msg_value as packed
    bbfaa5761f58 drm: Account property blob allocations to memcg
    e97de3e924b3 drm/amdkfd: Fix GART PTE for non-4K pagesize in svm_migrate_gart_map()
    30aaed311f97 media: v4l2-async: Fix error handling on steps after finding a match
    4010e596d23c media: cx25821: Fix a resource leak in cx25821_dev_setup()
    33af366211ee media: solo6x10: Check for out of bounds chip_id
    4ba5c7a1aade media: pvrusb2: fix URB leak in pvr2_send_request_ex
    45d9a0cd1b88 media: adv7180: fix frame interval in progressive mode
    f5a5a824f0ac media: amphion: Clear last_buffer_dequeued flag for DEC_CMD_START
    81bc7d5e7897 spi: spi-mem: Limit octal DTR constraints to octal DTR situations
    822530fb85d8 ASoC: wm8962: Don't report a microphone if it's shorted to ground on plug
    21f6e02a1910 ASoC: wm8962: Add WM8962_ADC_MONOMIX to "3D Coefficients" mask
    04184bcb50f5 HID: apple: Add "SONiX KN85 Keyboard" to the list of non-apple keyboards
    55462d16cb9c drm/amdgpu: avoid a warning in timedout job handler
    40e0b938db37 drm/amdgpu: add support for HDP IP version 6.1.1
    b0d35bc9c159 media: mediatek: vcodec: Don't try to decode 422/444 VP9
    38ef3e1e1e9b media: omap3isp: set initial format
    d490523d2374 media: omap3isp: isppreview: always clamp in preview_try_format()
    a9d1d7d27151 media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes
    2663ef70c612 drm/v3d: Set DMA segment size to avoid debug warnings
    50e8aac244e7 spi: stm32: fix Overrun issue at < 8bpw
    8b971c21603a media: dvb-core: dmxdevfilter must always flush bufs
    b2a97f2259f6 spi-geni-qcom: use xfer->bits_per_word for can_dma()
    5d0814ad6654 spi-geni-qcom: initialize mode related registers to 0
    ac9a7c329a56 drm/display/dp_mst: Add protection against 0 vcpi
    afa0bfe1437d parisc: Prevent interrupts during reboot
    12535a5d5d64 arm64: tegra: smaug: Add usb-role-switch support
    1da904e84de6 pstore: ram_core: fix incorrect success return when vmap() fails
    a4345acbe390 char: tpm: cr50: Remove IRQF_ONESHOT
    3e656f767407 mailbox: bcm-ferxrm-mailbox: Use default primary handler
    7b9394e49720 crypto: hisilicon/qm - move the barrier before writing to the mailbox register
    5f007c6acaa7 PCI/MSI: Unmap MSI-X region on error
    f557c206c32e clocksource/drivers/timer-integrator-ap: Add missing Kconfig dependency on OF
    6f113ab549b8 clocksource/drivers/sh_tmu: Always leave device running after probe
    c8a34bceefbc bpf: verifier improvement in 32bit shift sign extension pattern
    47bbd0cb7db3 sparc: don't reference obsolete termio struct for TC* constants
    6aa04820dbfe sparc: Synchronize user stack on fork and clone
    648aa7ce0bd8 blk-mq-debugfs: add missing debugfs_mutex in blk_mq_debugfs_register_hctxs()
    9150176cbf71 xenbus: Use .freeze/.thaw to handle xenbus devices
    2050a5cff32c perf/cxlpmu: Replace IRQF_ONESHOT with IRQF_NO_THREAD
    84a17b7b292d s390/perf: Disable register readout on sampling events
    bafd4aa1908a cpufreq: dt-platdev: Block the driver from probing on more QC platforms
    a61c1bc84c4a md-cluster: fix NULL pointer dereference in process_metadata_update
    b4a0b646cc28 ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP
    01e8751b37a3 ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()
    64eb63f573f4 EFI/CPER: don't go past the ARM processor CPER record buffer
    e0ec99115e13 APEI/GHES: ensure that won't go past CPER allocated record
    5a9b1dda8481 EFI/CPER: don't dump the entire memory region
    6ea4b7bc2e7b x86/xen/pvh: Enable PAE mode for 32-bit guest only when CONFIG_X86_PAE is set
    30868a6a5238 rnbd-srv: Zero the rsp buffer before using it
    fd7e360845d3 arm64: Add support for TSV110 Spectre-BHB mitigation
    94ab05af1d96 perf/arm-cmn: Support CMN-600AE
    61cd0b287fb9 s390/purgatory: Add -Wno-default-const-init-unsafe to KBUILD_CFLAGS
    7823e09a68b5 tools/power cpupower: Reset errno before strtoull()
    93e8e3ee165a smb: client: prevent races in ->query_interfaces()
    e428670cfb29 gfs2: fiemap page fault fix
    048b58edc57d smb: client: add proper locking around ses->iface_last_update
    8b5dcfa97bf3 btrfs: handle user interrupt properly in btrfs_trim_fs()
    2bb588cede1c minix: Add required sanity checking to minix_check_superblock()
    43ccadb866de i3c: master: svc: Initialize 'dev' to NULL in svc_i3c_master_ibi_isr()
    de9affb698d5 hfsplus: pretend special inodes as regular files
    f5d27ad99fca audit: add missing syscalls to read class
    c1b6227555c5 fs/buffer: add alert in try_to_free_buffers() for folios without buffers
    bccd4ebbdac3 hfsplus: fix volume corruption issue for generic/498
    91e27bc79c3b audit: add fchmodat2() to change attributes class
    4bde6678bc54 rtc: interface: Alarm race handling should not discard preceding error
    4927e2d29b74 libperf build: Always place libperf includes first
    5cf6e76e4f4f libperf: Don't remove -g when EXTRA_CFLAGS are used
    66e9b70c64df libsubcmd: Fix null intersection case in exclude_cmds()
    56042755b72f perf callchain: Fix srcline printing with inlines
    eddddf4ed7f6 perf unwind-libdw: Fix invalid reference counts
    985d844a5997 perf test stat tests: Fix for virtualized machines
    fa99e8717a68 perf test stat: Update test expectations and events
    8f36abf181c2 ASoC: dt-bindings: asahi-kasei,ak5558: Fix the supply names
    f939f666ec02 ASoC: dt-bindings: asahi-kasei,ak4458: Fix the supply names
    ce18fa88b154 ASoC: dt-bindings: asahi-kasei,ak4458: set unevaluatedProperties:false
    655c9ba9915f SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path
    df10f23defff SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths
    97503a852d3b ata: libata-scsi: refactor ata_scsi_translate()
    51680e9a1680 ata: pata_ftide010: Fix some DMA timings
    f18f70123962 ext4: use optimized mballoc scanning regardless of inode format
    4a79fde8db7e ext4: fix memory leak in ext4_ext_shift_extents()
    93b2ebbbcb2e ext4: don't cache extent during splitting extent
    c0155dee51b9 MIPS: Work around LLVM bug when gp is used as global register variable
    c941c268ad00 drm/amd/display: Use same max plane scaling limits for all 64 bpp formats
    da0959402742 ASoC: rockchip: i2s-tdm: Use param rate if not provided by set_sysclk
    5fed5f6c6a02 x86/hyperv: Fix error pointer dereference
    1ee1d006c9fe btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found
    b7bc182ec184 efi: Fix reservation of unaccepted memory table
    3222c8020aeb s390/kexec: Make KEXEC_SIG available when CONFIG_MODULES=n
    9e5cb7e67fbd spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe()
    a98d73dcc339 spi: wpcm-fiu: Simplify with dev_err_probe()
    978137e940de spi: wpcm-fiu: Fix uninitialized res
    87e463136302 spi: wpcm-fiu: Use devm_platform_ioremap_resource_byname()
    971bf8e61e9b drm/amdkfd: Fix watch_id bounds checking in debug address watch v2
    17e94789c216 drm/amdkfd: fix debug watchpoints for logical devices
    e975148b2c29 ASoC: codecs: aw88261: Fix erroneous bitmask logic in Awinic init
    3a2f5a21285b drm/i915/acpi: free _DSM package when no connectors
    29b2fbe3498d ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put()
    f8a5426652bd drm/amdgpu: Fix memory leak in amdgpu_ras_init()
    e87c73a80a12 drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()
    8dc6beca70f0 apparmor: fix aa_label to return state from compount and component match
    b25298e89a29 apparmor: fix invalid deref of rawdata when export_binary is unset
    dbbe0a2e3e4b apparmor: make label_match return a consistent value
    0563743d3f70 apparmor: remove apply_modes_to_perms from label_match
    32928c1749e8 apparmor: refcount the pdb
    f89b657e1785 apparmor: provide separate audit messages for file and policy checks
    e78e00cf9eba apparmor: use passed in gfp flags in aa_alloc_null()
    1f736dfe27c8 apparmor: fix rlimit for posix cpu timers
    24bb7d11dc30 apparmor: return -ENOMEM in unpack_perms_table upon alloc failure
    0dc19bca2260 apparmor: fix NULL sock in aa_sock_file_perm
    a4ff9e4f4ad4 net/mlx5: Fix multiport device check over light SFs
    f94a0de7b9f3 bonding: alb: fix UAF in rlb_arp_recv during bond up/down
    8bc48c4fb636 octeontx2-af: Fix default entries mcam entry action
    3f483a90634d inet: move icmp_global_{credit,stamp} to a separate cache line
    c9141a794fdc cache: add __cacheline_group_{begin, end}_aligned() (+ couple more)
    8dacf34eb427 netns-ipv4: reorganize netns_ipv4 fast path variables
    1402ebe132a9 cache: enforce cache groups
    4ec8a98b3dc3 tcp: Set pingpong threshold via sysctl
    b4d5e97679bc tcp: defer regular ACK while processing socket backlog
    22023ffad74c icmp: prevent possible overflow in icmp_global_allow()
    b0da61015db2 icmp: icmp_msgs_per_sec and icmp_msgs_burst sysctls become per netns
    e0987b6c3b34 icmp: move icmp_global.credit and icmp_global.stamp to per netns storage
    19c7d8ac5198 macvlan: observe an RCU grace period in macvlan_common_newlink() error path
    b5c84070333a ping: annotate data-races in ping_lookup()
    6b6b2fbd66d8 bpftool: Fix truncated netlink dumps
    db4636748c22 ipv6: fix a race in ip6_sock_set_v6only()
    7017745068a9 netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    9464ca7a6e56 net: remove WARN_ON_ONCE when accessing forward path array
    60e921703943 netfilter: nf_conntrack_h323: don't pass uninitialised l3num value
    f199874c199b selftests: forwarding: vxlan_bridge_1d_ipv6: fix test failure with br_netfilter enabled
    3c2b767a8ae2 selftests: forwarding: vxlan_bridge_1d: fix test failure with br_netfilter enabled
    d0fdad1bdd21 net: bridge: mcast: always update mdb_n_entries for vlan contexts
    779a9ae0ef22 net/rds: rds_sendmsg should not discard payload_len
    88b0fced1bbb xen-netback: reject zero-queue configuration from guest
    163d04897e57 net: usb: catc: enable basic endpoint checking
    b067e6c7973b net: sparx5/lan969x: fix PTP clock max_adj value
    bcc60ad129ae ipv6: Fix out-of-bound access in fib6_add_rt2node().
    cc1b179f778f net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()
    357a3544a385 net: mscc: ocelot: split xmit into FDMA and register injection paths
    487fac2388ad net: mscc: ocelot: extract ocelot_xmit_timestamp() helper
    d6f03772d9c0 net: sparx5/lan969x: fix DWRR cost max to match hardware register width
    9eefda7a03ef selftests: mlxsw: tc_restrictions: Fix test failure with new iproute2
    5c577ac939bc cpuidle: Skip governor when only one idle state is available
    7bb9178df6f0 ACPI: PM: Add unused power resource quirk for THUNDEROBOT ZERO
    d389943443c5 selftests/memfd: use IPC semaphore instead of SIGSTOP/SIGCONT
    2efc98314a61 selftests/memfd: delete unused declarations
    d809ee17c0d1 kbuild: Add objtool to top-level clean target
    e156a104ba26 powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version check
    727992102836 ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online CPUs
    a584b9d1059b fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot
    71c8b966ec56 fs/ntfs3: prevent infinite loops caused by the next valid being the same
    fb2d7c30d030 io_uring/cancel: de-unionize file and user_data in struct io_cancel_data
    533d495f15e4 dmaengine: fsl-edma: don't explicitly disable clocks in .remove()
    592833ea0051 dmaengine: fsl-edma-main: Convert to platform remove callback returning void
    a489f1fd52bc backlight: qcom-wled: Change PM8950 WLED configurations
    82f2eaab2f94 backlight: qcom-wled: Support ovp values for PMI8994
    97790c9b255d leds: qcom-lpg: Check the return value of regmap_bulk_write()
    99cc7352156c pinctrl: single: fix refcount leak in pcs_add_gpio_func()
    eccf17c0a801 pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition
    e8e960c3d23f iio: sca3000: Fix a resource leak in sca3000_probe()
    43b6f69e1806 ovl: Fix uninit-value in ovl_fill_real
    d26685b2d9ad pinctrl: equilibrium: Fix device node reference leak in pinbank_init()
    4f531b1a5468 usb: bdc: fix sleep during atomic
    c5bde5357e10 drivers: iio: mpu3050: use dev_err_probe for regulator request
    29040d42d641 mfd: simple-mfd-i2c: Add Delta TN48M CPLD support
    fd1a3a0b98a9 mfd: simple-mfd-i2c: Keep compatible strings in alphabetical order
    d9e5d3e1924a mfd: simple-mfd-i2c: Add SpacemiT P1 support
    07fb61ff35fd mfd: simple-mfd-i2c: Add compatible strings for Layerscape QIXIS FPGA
    b07aa526d053 mfd: simple-mfd-i2c: Add MAX77705 support
    3ea01691738b mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() failure
    9c858ef369bb Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms"
    b359ca27c589 coresight: etm3x: Fix cpulocked warning on cpuhp
    2fad88d7760c watchdog: starfive-wdt: Fix PM reference leak in probe error path
    7281a0c907cc iio: pressure: mprls0025pa: fix scan_type struct
    6dd1e95cc554 mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms
    24ec8015beca serial: SH_SCI: improve "DMA support" prompt
    c233e1e81873 serial: imx: change SERIAL_IMX_CONSOLE to bool
    65f2c608096d staging: greybus: lights: avoid NULL deref
    e230aee60444 dma: dma-axi-dmac: fix SW cyclic transfers
    6be32baf6541 dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX
    06c8ed283635 clk: mediatek: Fix error handling in runtime PM setup
    547ae2f17349 clk: qcom: gfx3d: add parent to parent request map
    bb5de8aca640 clk: qcom: dispcc-sdm845: Enable parents for pixel clocks
    ae56e2c27f6d clk: Move clk_{save,restore}_context() to COMMON_CLK section
    d81b51c8a7ed clk: qcom: gcc-ipq5018: flag sleep clock as critical
    048fbee3e431 clk: qcom: gcc-msm8917: Remove ALWAYS_ON flag from cpp_gdsc
    df1c437bfca4 clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc
    915e7579855e clk: qcom: gcc-qdu1000: Update the SDCC RCGs to use shared_floor_ops
    d31b1b143819 clk: qcom: gcc-sdx75: Update the SDCC RCGs to use shared_floor_ops
    45a013dabc5f clk: qcom: gcc-sm8450: Update the SDCC RCGs to use shared_floor_ops
    ac003c1a80d9 clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs
    1e1664eb6f24 clk: qcom: rcg2: compute 2d using duty fraction directly
    8cb92d27454e clk: qcom: gcc-sm8550: Use floor ops for SDCC RCGs
    3e5349e54113 fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
    68dae7b64c31 fbdev: of_display_timing: Fix device node reference leak in of_get_display_timings()
    ca81f7811dfe tracing: Remove duplicate ENABLE_EVENT_STR and DISABLE_EVENT_STR macros
    7e6556e9329b tracing: Properly process error handling in event_hist_trigger_parse()
    aa6e847e2795 fs/nfs: Fix readdir slow-start regression
    c1f244f7868c nvdimm: virtio_pmem: serialize flush requests
    25d623f0d77c scsi: csiostor: Fix dereference of null pointer rn
    94a6c85a68bc scsi: ufs: host: mediatek: Require CONFIG_PM
    fdf1188cfa80 scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()
    8e3d91135417 pNFS: fix a missing wake up while waiting on NFS_LAYOUT_DRAIN
    34276d267742 RDMA/uverbs: Add __GFP_NOWARN to ib_uverbs_unmarshall_recv() kmalloc
    685163733ed1 power: supply: qcom_battmgr: Recognize "LiP" as lithium-polymer
    d2a6ca4c0748 mtd: spinand: Fix kernel doc
    9fbbd62436ce mtd: parsers: ofpart: fix OF node refcount leak in parse_fixed_partitions()
    5f1a84bb4a95 cxl: Fix premature commit_end increment on decoder commit failure
    db830aea65e4 RDMA/core: add rdma_rw_max_sge() helper for SQ sizing
    6faf28106ea1 svcrdma: Reduce the number of rdma_rw contexts per-QP
    63a45e2a1264 svcrdma: Increase the per-transport rw_ctx count
    46ccddede7be svcrdma: Clean up comment in svc_rdma_accept()
    4965711d22a0 svcrdma: Remove queue-shortening warnings
    91cb7ff68604 RDMA/core: Fix a couple of obvious typos in comments
    756c93d6df7c RDMA/rxe: Fix race condition in QP timer handlers
    bf1feed1a788 RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send
    0f5e62ea5c43 mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse()
    1733d168099e crypto: ccp - Send PSP_CMD_TEE_RING_DESTROY when PSP_CMD_TEE_RING_INIT fails
    2abf05a122cf crypto: ccp - Factor out ring destroy handling to a helper
    b2e7e269aba9 crypto: ccp - Move direct access to some PSP registers out of TEE
    54541017ac6a crypto: ccp - Add an S4 restore flow
    21f422a86ded mtd: rawnand: cadence: Fix return type of CDMA send-and-wait helper
    bc779d426ef1 tools/power/x86/intel-speed-select: Fix file descriptor leak in isolate_cpus()
    26793db60925 RDMA/rxe: Fix double free in rxe_srq_from_init
    9a0323f5e54e RDMA/rtrs-srv: fix SG mapping
    86183153c299 power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed()
    3af85f239648 power: supply: bq27xxx: fix wrong errno when bus ops are unsupported
    7ac6501b587c power: reset: nvmem-reboot-mode: respect cell size for nvmem_cell_write
    2078830c32d1 power: supply: sbs-battery: Fix use-after-free in power_supply_changed()
    af261f218a76 power: supply: rt9455: Fix use-after-free in power_supply_changed()
    77ea437faa4c power: supply: goldfish: Fix use-after-free in power_supply_changed()
    cbb9b07f88a9 power: supply: cpcap-battery: Fix use-after-free in power_supply_changed()
    0de95d29d847 power: supply: bq25980: Fix use-after-free in power_supply_changed()
    cb5c743936ed power: supply: bq256xx: Fix use-after-free in power_supply_changed()
    697bb5dc0cb4 power: supply: act8945a: Fix use-after-free in power_supply_changed()
    f50433f2603d power: supply: ab8500: Fix use-after-free in power_supply_changed()
    2ad50784c9eb RDMA/hns: Notify ULP of remaining soft-WCs during reset
    70a5eb757ace RDMA/hns: Fix WQ_MEM_RECLAIM warning
    2fb573fa9d71 IB/cache: update gid cache on client reregister event
    04b41f1d0e33 RDMA/rtrs: server: remove dead code
    d858a1d814d3 octeontx2-pf: Unregister devlink on probe failure
    320b54651a59 ionic: Rate limit unknown xcvr type messages
    69042a930eae octeon_ep: ensure dbell BADDR updation
    664355e6f130 octeon_ep: set backpressure watermark for RX queues
    dc4d11c5f316 octeon_ep: disable per ring interrupts
    2c33c53a9c8c octeon_ep: support Octeon CN10K devices
    a40e276b9696 octeon_ep: restructured interrupt handlers
    77c641b3bd4e octeon_ep: support to fetch firmware info
    331e2b705163 serial: caif: fix use-after-free in caif_serial ldisc_close()
    2c1f59005da9 xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path
    d621dd67a72d net: Switch to skb_dstref_steal/skb_dstref_restore for ip_route_input callers
    31ca4fbf56d1 net: Add skb_dstref_steal and skb_dstref_restore
    dea1465394ff net: sunhme: Fix sbus regression
    e3f80666c273 net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
    e131aac543cd smb: client: correct value for smbd_max_fragmented_recv_size
    0e64bd46a04a procfs: fix missing RCU protection when reading real_parent in do_task_stat()
    6dc10494cfe2 net: hns3: fix double free issue for tx spare buffer
    44b2256b17f1 PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404]
    f1535d56fc3f netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets
    f7eb1903c6e0 netfilter: nft_counter: fix reset of counters on 32bit archs
    cfe35cb86256 netfilter: nft_set_hash: fix get operation on big endian
    77eef9f2eef0 nfc: hci: shdlc: Stop timers and work before freeing context
    db76b75ede38 inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
    43f4661e9b2c bonding: only set speed/duplex to unknown, if getting speed failed
    8b5ed7c5417b octeontx2-af: Fix PF driver crash with kexec kernel booting
    cf5967514735 mptcp: fix receive space timestamp initialization
    2622f355e621 of: unittest: fix possible null-pointer dereferences in of_unittest_property_copy()
    e7c1e60802d8 ucount: check for CAP_SYS_RESOURCE using ns_capable_noaudit()
    7dc4778ee848 ipc: don't audit capability check in ipc_permissions()
    2c80b0974047 PCI/ACPI: Restrict program_hpx_type2() to AER bits
    89db6475c0b4 PCI: Add defines for bridge window indexing
    82bd7f9d08ce PCI: Add PCIE_MSG_CODE_ASSERT_INTx message macros
    1f5438cb5d78 PCI: Log bridge info when first enumerating bridge
    f49c44723a70 PCI: Log bridge windows conditionally
    988b8b98103c PCI: Supply bridge device, not secondary bus, to read window details
    7fd6672a1bb0 PCI: Move pci_read_bridge_windows() below individual window accessors
    a79a3d1fd32c PCI: Initialize RCB from pci_configure_device()
    a7c08278f2d0 wifi: ath10k: sdio: add missing lock protection in ath10k_sdio_fw_crashed_dump()
    62c2290dc976 tcp: tcp_tx_timestamp() must look at the rtx queue
    d3b7ffa90f61 fat: avoid parent link count underflow in rmdir
    243f71ed873f nfsd: never defer requests during idmap lookup
    0114244ec49a dm: use bio_clone_blkg_association
    c93f23375d8c iommu/vt-d: Flush cache for PASID table before using it
    bff7ac6b98fa PCI: Mark 3ware-9650SA Root Port Extended Tags as broken
    af0f0d30fd02 kallsyms/ftrace: set module buildid in ftrace_mod_address_lookup()
    ecb0af907733 module: add helper function for reading module_buildid()
    767f1a8c8483 netfilter: nf_conncount: fix tracking of connections from localhost
    abaa1508d5db netfilter: nft_compat: add more restrictions on netlink attributes
    0792ad077d77 netfilter: nf_conncount: increase the connection clean up limit to 64
    d12e9e90632c netfilter: nf_conncount: make nf_conncount_gc_list() to disable BH
    5802782366ba netfilter: nf_tables: reset table validation state on abort
    4d7a05da767e wifi: cfg80211: stop NAN and P2P in cfg80211_leave
    11f832532440 mctp i2c: initialise event handler read bytes
    f03666259d22 net: mctp-i2c: fix duplicate reception of old data
    37ccd48cf35f quota: fix livelock between quotactl and freeze_super
    96ac80ce22bc PCI/portdrv: Fix potential resource leak
    cf7e6dbb51a7 PCI: Do not attempt to set ExtTag for VFs
    a4176432d41e Documentation: tracing: Add PCI tracepoint documentation
    60b896647d88 Documentation: trace: Refactor toctree
    b2f972293451 docs: fix WARNING document not included in any toctree
    bd43a6e85779 Documentation: tracing: Add ring-buffer mapping
    baa42b756d18 PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails
    d8e7624e2113 PCI/PM: Avoid redundant delays on D3hot->D3cold
    63d3556c9a8e Documentation: PCI: endpoint: Fix ntb/vntb copy & paste errors
    24c190a5a24e PCI: mediatek: Fix IRQ domain leak when MSI allocation fails
    f448acd86835 Revert "hwmon: (ibmpex) fix use-after-free in high/low store"
    1ae5fd122398 spi: tools: Add include folder to .gitignore
    169ae51f31b0 platform/chrome: cros_ec_lightbar: Fix response size initialization
    e3311645c7c1 media: uvcvideo: Fix allocation for small frame sizes
    01fe5a26ccc6 platform/chrome: cros_typec_switch: Don't touch struct fwnode_handle::dev
    0347548ccf07 drm/msm/a2xx: fix pixel shader start on A225
    661152ffb0f2 media: ccs: Accommodate C-PHY into the calculation
    e7815709bc97 drm/msm/dpu: fix CMD panels on DPU 1.x - 3.x
    33acf9a4d6eb HID: playstation: Add missing check for input_ff_create_memless
    f0a6e4b27bad regulator: core: move supply check earlier in set_machine_constraints()
    2d5b17e8364b drm/msm/disp/dpu: add merge3d support for sc7280
    83d3d9ec347a drm/amdgpu: Use explicit VCN instance 0 in SR-IOV init
    f721f873d3e1 ASoC: nau8821: Fixup nau8821_enable_jack_detect()
    88a6bed89eb8 ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
    e19f5b5d1059 ASoC: nau8821: Consistently clear interrupts before unmasking
    1c7ee23dfcd1 smack: /smack/doi: accept previously used values
    661d87242dd6 smack: /smack/doi must be > 0
    34bacb3cc343 workqueue: Process rescuer work items one-by-one using a cursor
    c906c9d81fdf workqueue: Only assign rescuer work when really needed
    c17f947a6fca workqueue: Factor out assign_rescuer_work()
    e3b15841172e arm64: dts: qcom: sm6115: Add CX_MEM/DBGC GPU regions
    4ffe98b89c9c arm64: dts: qcom: sdm845-db845c: specify power for WiFi CH1
    c77d1b2f5e51 arm64: dts: qcom: sdm845-db845c: drop CS from SPIO0
    1895ad99349e arm64: dts: amlogic: g12: assign the MMC A signal clock
    44cd81bbb21b arm64: dts: amlogic: g12: assign the MMC B and C signal clocks
    6a47c69a8bba arm64: dts: amlogic: gx: assign the MMC signal clocks
    59f3138d11cc arm64: dts: amlogic: axg: assign the MMC signal clocks
    716c8ebe0409 arm: dts: lpc32xx: add clocks property to Motor Control PWM device tree node
    8461f646f68a ARM: dts: lpc32xx: Set motor PWM #pwm-cells property value to 3 cells
    87a1f93986aa powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event handling
    06195456c4e4 soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()
    993d41578772 soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in cmd_db_dev_probe
    c43e0a0353e5 powerpc/uaccess: Move barrier_nospec() out of allow_read_{from/write}_user()
    ac2c85d2a2f6 ARM: dts: allwinner: sun5i-a13-utoo-p66: delete "power-gpios" property
    dc62cf0814fa arm64: dts: qcom: sdm845-oneplus: Mark l14a regulator as boot-on
    1aeb4ed95c3f arm64: dts: qcom: sdm845-oneplus: Don't mark ts supply boot-on
    93aaa53ecf20 arm64: dts: qcom: sdm630: fix gpu_speed_bin size
    e15f1e18cdf4 clk: qcom: Return correct error code in qcom_cc_probe_by_index()
    458f7417fae0 arm64: dts: tqma8mpql-mba8mpxl: Fix HDMI CEC pad control settings
    063898a3f9ac EDAC/i5400: Fix snprintf() limit calculation in calculate_dimm_size()
    e37f5e05b5bc EDAC/i5000: Fix snprintf() size calculation in calculate_dimm_size()
    8afa17757873 soc: qcom: smem: handle ENOMEM error during probe
    cff0ef043e16 pstore/ram: fix buffer overflow in persistent_ram_save_old()
    8ad5577b2d4a sched/rt: Skip currently executing CPU in rto_next_cpu()
    322154c3981e mfd: wm8350-core: Use IRQF_ONESHOT
    3db9471b23f5 EDAC/altera: Remove IRQF_ONESHOT
    adb69cc223d7 scsi: efct: Use IRQF_ONESHOT and default primary handler
    ddc34a1b8550 bpf: Fix bpf_xdp_store_bytes proto for read-only arg
    74081d6c1da1 crypto: hisilicon/trng - support tfms sharing the device
    260a9e382996 crypto: hisilicon/trng - modifying the order of header files
    9681044e45c9 bpf, sockmap: Fix FIONREAD for sockmap
    acaf1ea47bbf bpf, sockmap: Fix incorrect copied_seq calculation
    7111701a09cc hrtimer: Fix trace oddity
    33a30bf9e0d4 crypto: hisilicon/sec2 - support skcipher/aead fallback for hardware queue unavailable
    6eae58af0c31 crypto: hisilicon/zip - adjust the way to obtain the req in the callback function
    ab8b2eaf7add crypto: hisilicon/zip - remove zlib and gzip
    70b2f4fc1ede crypto: hisilicon/zip - support deflate algorithm
    0aa430f4661d crypto: octeontx - fix dma_free_coherent() size
    53e97a309cc3 crypto: cavium - fix dma_free_coherent() size
    2b757fea9f4f ARM: VDSO: Patch out __vdso_clock_getres() if unavailable
    e1767524765e libbpf: Fix OOB read in btf_dump_get_bitfield_value
    542bf32cf757 selftests/bpf: veristat: fix printing order in output_stats()
    6e6abc72accf crypto: qat - fix warning on adf_pfvf_pf_proto.c
    abb6e07f46a7 s390/cio: Fix device lifecycle handling in css_alloc_subchannel()
    27d7a35b8052 PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races
    70e8af620210 perf: arm_spe: Properly set hw.state on failures
    3deb7b6a2e31 PM: wakeup: Handle empty list in wakeup_sources_walk_start()
    d6749d0b8ddc Partial revert "x86/xen: fix balloon target initialization for PVH dom0"
    ef3b74d20f5e x86/xen: make some functions static
    31cac6acf77e ublk: Validate SQE128 flag before accessing the cmd
    8f3d79abdec0 iomap: fix submission side handling of completion side errors
    597ec9e7f5cc md/raid10: fix any_working flag handling in raid10_sync_request
    72b2db83705b cpuidle: governors: menu: Always check timers with tick stopped
    0add3e6f91aa cpuidle: menu: Cleanup after loadavg removal
    ca762fa01f64 io_uring/sync: validate passed in offset
    f2cf475d23b8 ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch()
    9cc9efa703f0 xen/virtio: Don't use grant-dma-ops when running as Dom0
    7425453ea16d smb: client: fix potential UAF and double free in smb2_open_file()
    e3d1fd084319 btrfs: fix block_group_tree dirty_list corruption
    46fb7ee9f852 btrfs: qgroup: return correct error when deleting qgroup relation item
    a51cff9be046 tpm: st33zp24: Fix missing cleanup on get_burstcount() error
    948966e546f2 tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure
    20ac431e02dc i3c: dw: Initialize spinlock to avoid upsetting lockdep
    d87268326b27 gfs2: Fix use-after-free in iomap inline data write path
    4991b13cc9f1 gfs2: Add metapath_dibh helper
    7e3b7a47867a gfs2: Retries missing in gfs2_{rename,exchange}
    b68be2b8b564 i3c: master: Update hot-join flag only on success
    5560116126da fs: add <linux/init_task.h> for 'init_fs'
    4b2a0a4e9428 i3c: Move device name assignment after i3c_bus_init
    e2647d540bea audit: move the compat_xxx_class[] extern declarations to audit_arch.h
    979c708e6c9d rcu: Fix rcu_read_unlock() deadloop due to softirq
    dffd52d0d14e rcu: Remove local_irq_save/restore() in rcu_preempt_deferred_qs_handler()
    3ccd035ef99d rcu: Refactor expedited handling check in rcu_read_unlock_special()
    6cc7a424a39a rcu/exp: Move expedited kthread worker creation functions above rcutree_prepare_cpu()
    cb9eaff659dd rcu: s/boost_kthread_mutex/kthread_mutex
    7b57ada854b3 hfsplus: return error when node already exists in hfs_bnode_create
    2e000d8a5306 auxdisplay: arm-charlcd: fix release_mem_region() size
    a6a3e4af1099 RDMA/umad: Reject negative data_len in ib_umad_write
    ffba40b67663 RDMA/siw: Fix potential NULL pointer dereference in header processing

(From OE-Core rev: 620a32621b5e7c33609fc6dbff01758303f41189)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Bruce Ashfield
7b46ef1a27 oeqa/runtime/parselogs: update pci BAR ignore for kernel 6.10
The format of the pci BAR warnings we get on qemu boots has
changed in 6.10+ via the following kernel commit:

    commit dc4e6f21c3f844ebc1c52b6920b8ec5dfc73f4e8
    Author: Puranjay Mohan <puranjay@kernel.org>
    Date:   Sat Nov 6 16:56:06 2021 +0530

        PCI: Use resource names in PCI log messages

        Use the pci_resource_name() to get the name of the resource and use it
        while printing log messages.

        [bhelgaas: rename to match struct resource * names, also use names in other BAR messages]
        Link: https://lore.kernel.org/r/20211106112606.192563-3-puranjay12@gmail.com
        Signed-off-by: Puranjay Mohan <puranjay12@gmail.com>
        Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>

Since it doesn't appear that we can do regex's in parselogs
and the bar number is now in the middle of the message, we
go with a slightly wider format of the message to ignore.

(From OE-Core rev: 004fc06a7792592f3847d92fc464347a279f998c)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 0a7126604b6536868600d43aff000a426384995c)
[YC: In scarthgap, the breaking backported commit is in >=6.6.130:
fffdb0fece19 ("PCI: Use resource names in PCI log messages")]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Sudhir Dumbhare
af76dc3437 rust,libstd-rs: set status for CVE-2024-3566
The vulnerability is Windows-specific and depends on command-line
handling through CreateProcess, which does not apply to Linux/Yocto
builds.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2024-3566

(From OE-Core rev: 8c56e85dd02063da5630c9b73fb242686a970e20)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Sudhir Dumbhare
5087e4b4a0 go: set status for CVE-2026-39836
This issue affects Windows only. The net.Dial and net.LookupPort
functions can panic when given input containing a NUL byte.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-39836
https://security-tracker.debian.org/tracker/CVE-2026-39836

(From OE-Core rev: 324359dcb7cbeb15ef51f5cc18924f590c81b1de)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Sudhir Dumbhare
f3fbf45c1d go-binary-native: set status for CVE-2026-39836
This issue affects Windows only. The net.Dial and net.LookupPort
functions can panic when given input containing a NUL byte.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-39836
https://security-tracker.debian.org/tracker/CVE-2026-39836

(From OE-Core rev: 8aab8b31425b3820ef65fc40061b9377c574607b)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Himanshu Jadon
4aa2dfec70 apr: Add CVE_PRODUCT to support product name
apr is tracked in NVD under apache:portable_runtime rather than the
recipe name apr. Set CVE_PRODUCT accordingly so cve-check uses the
correct NVD product identity for APR.

No additional alias was found to be necessary for this recipe.

(From OE-Core rev: d93c564790a51b53347bde257151c778e8867624)

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit bc3803e12d4938e2de514c39bd5d0f011f883ace)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Himanshu Jadon
b61a268160 apr-util: Add CVE_PRODUCT to support product name
apr-util is tracked in NVD under apache:apr-util, while a smaller set
of newer CVEs also appears under apache:portable_runtime_utility.
Set CVE_PRODUCT accordingly so cve-check can cover both the historical
and current NVD product identities used for APR-util.

(From OE-Core rev: 3a157840148e14ec9019a008ab94e7f708baac05)

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit 927b505c982ed7443aed348ca54b0073ac63d938)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Jonas Munsin
d3d5e50fc6 bzip2: set CVE_PRODUCT
Add CVE_PRODUCT to bzip2

(From OE-Core rev: b976aed4282df6becec170ba6085e54df281603f)

Signed-off-by: Jonas Munsin <jonas.munsin@gehealthcare.com>
Signed-off-by: Maxin John <maxin.john@gehealthcare.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit bc889ea799cc82f7fa018baabca0b821c1209897)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Adarsh Jagadish Kamini
c0d690e103 python3: CVE-2026-3087 not applicable
CVE link: https://nvd.nist.gov/vuln/detail/CVE-2026-3087

The CVE is only applicable to Windows OS

(From OE-Core rev: 96efecfbb2d1eaa24e1c96fbd6593a7087464844)

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Ross Burton
ba6b812929 classes/gtk-icon-cache: fix libdir passed to the postrm intercept
Back in 2015[1] I fixed the libdir passed to the postinst intercept, but
I forgot to also update the postrm intercept.  This should also be
libdir_native, not libdir.

[ YOCTO #13896 ]

[1] oe-core 0fe8400717 ("gtk-icon-cache: pass the native libdir to the intercept")

(From OE-Core rev: cd46a25fa3f7ffe5518c7c95f280a7760455aac8)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 92dd67114be325e019c149bddaf5f874f6917094)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Ross Burton
e9a5a1ff70 oeqa/core/runner: stub addDuration in OETestResult
We have a custom TestResult implementation, and Python 3.12 added a new
method addDuration() to the TestResult interface.  This would be useful
to implement correctly, but for now stub it out to silence the warning
when running under Python 3.12:

/usr/lib64/python3.12/unittest/case.py:580: RuntimeWarning: TestResult has no addDuration method
  warnings.warn("TestResult has no addDuration method",

(From OE-Core rev: 9105e2bbf3245bfa02d2f4c55a010a7d2c3da6c2)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 2d6fff81b34476b890f6943997615fbf8d3d133f)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Yoann Congal
7a90e7adfb gdb: backport a patch to fix static_assert in recent GCC
On Ubuntu 26.04, gcc 15.2 defaults to --std=gnu23 in which static_assert
is a keyword, and not a macro to define like with older GCC. This make
MIPS64 code in gdb fail to compile with:
| In file included from ../../gdb-14.2/opcodes/mips16-opc.c:25:
| ../../gdb-14.2/opcodes/mips16-opc.c: In function ‘decode_mips16_operand’:
| ../../gdb-14.2/opcodes/mips-formats.h:86:7: error: expected identifier or ‘(’ before ‘static_assert’
|    86 |       static_assert[(1 << (SIZE)) == ARRAY_SIZE (MAP)]; \
|       |       ^~~~~~~~~~~~~
| ../../gdb-14.2/opcodes/mips16-opc.c:52:15: note: in expansion of macro ‘MAPPED_REG’
|    52 |     case '.': MAPPED_REG (0, 0, GP, reg_0_map);
|       |               ^~~~~~~~~~

(From OE-Core rev: 92a57b28a4e8e4fe917e4aa3d58079257ee9a41f)

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Hitendra Prajapati
c0aa173936 libinput: fix for CVE-2026-50292
Pick patch from [1] & [2] also mentioned at Debian report in [3].

[1] fc2262e1c1
[2] b2bde9504d
[3] https://security-tracker.debian.org/tracker/CVE-2026-50292

More details :
1. https://nvd.nist.gov/vuln/detail/CVE-2026-50292
2. https://www.openwall.com/lists/oss-security/2026/06/04/5

(From OE-Core rev: 19fc681a3fca99801e2e50d6a9c6c921c66a2ce9)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Peter Marko
ee3a1921cf openssl: upgrade 3.5.6 -> 3.5.7
Release information [1]:

OpenSSL 3.5.7 is a security patch release. The most severe CVE fixed in this release is High.
This release incorporates the following bug fixes and mitigations:
* Fixed heap use-after-free in PKCS7_verify(). (CVE-2026-45447)
* Fixed CMS AuthEnvelopedData processing may accept forged messages. (CVE-2026-34182)
* Fixed unbounded memory growth in the QUIC PATH_CHALLENGE handler. (CVE-2026-34183)
* Fixed NULL pointer dereference in QUIC server initial packet handling. (CVE-2026-42764)
* Fixed AES-OCB IV ignored on EVP_Cipher() path. (CVE-2026-45445)
* Fixed possible heap buffer overflow in ASN.1 multibyte string conversion. (CVE-2026-7383)
* Fixed out-of-bounds read in CMS password-based decryption. (CVE-2026-9076)
* Fixed heap buffer over-read in ASN.1 content parsing. (CVE-2026-34180)
* Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys. (CVE-2026-34181)
* Fixed possible NULL dereference in password-dased CMS decryption. (CVE-2026-42766)
* Fixed NULL pointer dereference in CRMF EncryptedValue decryption. (CVE-2026-42767)
* Fixed multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt(). (CVE-2026-42768)
* Fixed trust anchor substitution via cert/issuer typo in CMP rootCaKeyUpdate. (CVE-2026-42769)
* Fixed FFC-DH peer validation uses attacker-supplied q. (CVE-2026-42770)
* Fixed incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes. (CVE-2026-45446)

Refreshed patches.
Installed new test files to pass ptests.

[1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-356-and-openssl-357-9-jun-2026

(From OE-Core rev: ed3353c07f6a8a6e55d244c0039e37fb62c81712)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 9365ac47f994a7d6be92b8c011c51ecf48e8ef87)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Adarsh Jagadish Kamini
44408c481b libsolv: fix CVE-2026-9150
Backport patch to fix CVE-2026-9150.
https://nvd.nist.gov/vuln/detail/CVE-2026-9150

Upstream fix:
  https://github.com/openSUSE/libsolv/pull/616

(From OE-Core rev: 42214e12ad205e1da59cb839849e8bfb5c300de5)

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Shubham Pushpkar
09f201c834 dpkg: Fix CVE-2026-2219
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-2219

(From OE-Core rev: 66055d7f179d0d838c2139d9d2399a968c6f6529)

Signed-off-by: Shubham Pushpkar <spushpka@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:54 +01:00
Deepak Rathore
b04b16e965 qemu: Fix CVE-2024-6519
This patch applies the upstream v11.0.0-rc2 backport for
CVE-2024-6519. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2]. The individual
backported commit link is recorded in the embedded patch header.

[1] 4862d2c951
[2] https://security-tracker.debian.org/tracker/CVE-2024-6519

(From OE-Core rev: bb5a1f9c6562038d422ea0efd4e975737c9374c3)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
e61bf028a6 python3: Fix CVE-2025-13462
Apply the upstream v3.12 fix [1], aligned with the original v3.13 fix [2],
to address incorrect tarfile handling where GNU long name follow-up headers
could be normalized as directories, as referenced in [3].

[1] d10950739a
[2] ae99fe3a33
[3] https://security-tracker.debian.org/tracker/CVE-2025-13462

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-13462

(From OE-Core rev: 0b990a354ef858d903d4bed937b1233537c2c478)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
7731db5592 python3: Fix CVE-2026-6019
This patch applies the upstream fix [1] and follow-up fix [2], as
referenced in [3] and [4], to address an http.cookies.Morsel.js_output()
flaw where inline JavaScript output escaped quotes but did not neutralize
the HTML parser-sensitive </script> sequence.

[1] 3c59b8b53f
[2] e7d4c3ff42
[3] https://github.com/python/cpython/issues/149144
[4] https://security-tracker.debian.org/tracker/CVE-2026-6019

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-6019

(From OE-Core rev: e17af14ae72e21f7f63407ba5c88da160c73bea9)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
1401e6e003 python3: Fix CVE-2026-4519 and CVE-2026-4786
Apply the upstream v3.12 fix [1], aligned with the original v3.11 fix [2],
and follow-up fix [3] to address CVE-2026-4519 by disallowing URLs with
leading dashes when invoking browser commands, as referenced in [5].

CVE-2026-4786 [6] revealed the CVE-2026-4519 fix was incomplete, as %action
in URLs could bypass dash-prefix checks. Apply follow-up fix [4], noted in
[5], to revalidate the URL after %action expansion.

[1] cbba611939
[2] ceac1efc66
[3] 96fc504860
[4] f4654824ae
[5] https://security-tracker.debian.org/tracker/CVE-2026-4519
[6] https://security-tracker.debian.org/tracker/CVE-2026-4786

References:
https://nvd.nist.gov/vuln/detail/CVE-2026-4519
https://nvd.nist.gov/vuln/detail/CVE-2026-4786

(From OE-Core rev: e6d81b3be531e97058366c81056a38c0b6fa7380)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
703b680089 python3: Fix CVE-2026-3644 and CVE-2026-0672
Apply the upstream v3.13 fix [1], as referenced in [2], to address
CVE-2026-3644 by rejecting control characters in http.cookies.Morsel.update(),
the |= operator, and unpickling paths.

CVE-2026-3644 [2] revealed the CVE-2026-0672 fix was incomplete, as
Morsel.update(), |=, and unpickling could bypass input validation. The fix
also adds output validation to BaseCookie.js_output(), matching the
control-character safeguards already present in BaseCookie.output().

[1] d16ecc6c36
[2] https://security-tracker.debian.org/tracker/CVE-2026-3644

References:
https://security-tracker.debian.org/tracker/CVE-2026-3644
https://security-tracker.debian.org/tracker/CVE-2026-0672
https://nvd.nist.gov/vuln/detail/CVE-2026-3644
https://nvd.nist.gov/vuln/detail/CVE-2026-0672

(From OE-Core rev: ac763f139ba7f836d0fa9377295ef7d3b10f2238)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Deepak Rathore
327a87fffb binutils: Fix CVE-2025-69644
This patch updates the existing CVE-2025-69647 backport metadata for
CVE-2025-69644. NVD records for CVE-2025-69644 and CVE-2025-69647
reference the same upstream binutils fix commit [1], and the public
CVE advisories are referenced in [2] and [3].

[1] https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7
[2] https://nvd.nist.gov/vuln/detail/CVE-2025-69644
[3] https://nvd.nist.gov/vuln/detail/CVE-2025-69647

(From OE-Core rev: 267ff299a6fe6f65e0dd86f5e59bb013921526ce)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
7d782f3ed0 go: fix CVE-2026-32288
This patch applies the upstream fix [1], as referenced in [2],
to address unbounded sparse map handling in `archive/tar`.

[1] 82b0cdb741
[2] https://security-tracker.debian.org/tracker/CVE-2026-32288

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-32288

(From OE-Core rev: 775c3af36899eebe5612844accdfd2a8a2a9327a)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
3401fba731 go: fix CVE-2026-25679
This patch applies the upstream fix [1], as referenced in [2],
to address insufficient validation in `url.Parse`.

Debian marks older Go branches as not affected because the vulnerable
parseHost surface was introduced by the earlier CVE-2025-47912 fix.
This Scarthgap recipe already carries CVE-2025-47912.patch, so the
fix is applicable to the patched Go 1.22.12 source used here.

[1] d8174a9500
[2] https://security-tracker.debian.org/tracker/CVE-2026-25679

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-25679

(From OE-Core rev: 913b9dc19ea14edbbaf4b7a677507949e454e685)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Sudhir Dumbhare
b1af4c89b0 go: fix CVE-2025-58183
This patch applies the upstream fix [1], as referenced in [2],
to address unbounded memory consumption when reading GNU tar pax
1.0 sparse file regions in archive/tar.

[1] 613e746327
[2] https://security-tracker.debian.org/tracker/CVE-2025-58183

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-58183

(From OE-Core rev: e0285488a93cf3b369ad7424d55938791f57174f)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Naman Jain
719d921135 tiff: fix CVE-2026-4775
Fix CVE-2026-4775

Reference: 782a11d6b5

(From OE-Core rev: 5a9bd4598fb446330c991fb51eaed372d96f39ff)

Signed-off-by: Naman Jain <namanj1@kpit.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Adarsh Jagadish Kamini
12249ef220 openssh: fix CVE-2026-35386
CVE-2026-35386 is already fixed by the existing CVE-2025-61984 backport.

Rename CVE-2025-61984.patch to CVE-2025-61984_CVE-2026-35386.patch and
add the second CVE tag to document that one patch covers both CVEs.

https://nvd.nist.gov/vuln/detail/CVE-2026-35386

(From OE-Core rev: 36ee08f01311253bca4c4f8387446d35a55cc840)

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Mark Hatle
3f378fc245 pseudo: Update to version 1.9.8
Changelog:
    Makefile.in: Bump to 1.9.8
    pseudo_client.h: Fix typo in the comment
    client: permissions drop setuid and setgid
    tests: Add setuid permission check
    pseudo_client.h: Add +s to PSEUDO_DB_MODE for mkdir
    tests: Add test that returned stat is correct
    pseudo_client.h: Make it clear both macros must be updated together
    Makefile.in: Add pseudo_client.h as a dependency

(From OE-Core rev: d716fe7e4f1dd2156be8773408611bb979a94d5d)

Signed-off-by: Mark Hatle <mark.hatle@kernel.crashing.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit fa302de94c7da77a49ca0701580467ebaa8eda18)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:53 +01:00
Robert P. J. Day
802e4c1135 ref-manual: add more explanation to glossary variable LICENSE
Add the following to the variable glossary LICENSE entry:

  - it is a required variable in an OE recipe
  - it must be accompanied by LIC_FILES_CHKSUM, except in the
    case where LICENSE = "CLOSED"

(From yocto-docs rev: 1b819d324780a699d9307a2d4e68c69b576ab748)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit a75f75fe86c339246b94b78c593c54647a75ba6a)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
0e35838b91 ref-manual: document RM_WORK_EXCLUDE_ITEMS variable
Add an explanation of the RM_WORK_EXCLUDE_ITEMS variable to both the
Reference Manual variables and classes sections.

(From yocto-docs rev: fa007992c5df04e51de4fbd8edbcf29583cb49f0)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 62c96090be7aeffe7010b70e8dfd5166e506140f)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
267e62dae3 ref-manual: clarify use of "PACKAGE_ARCH" in a packagegroup
Warn the developer that if they need to set "PACKAGE_ARCH" in a
custom packagegroup file, that setting must precede the "inherit
packagegroup" line in the packagegroup recipe file.

(From yocto-docs rev: 9d84e1ccddb2cf17641447721cd2b0b524ef872f)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 98a14fe885370d52a6f46e940834c725bad6933d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
cee4047ae6 dev-manual: SysVinit is the default init manager for Poky
Correct the opening sentence of the Init Manager section to clarify
that SysVinit is the default init manager if one is using the Poky
distro.

(From yocto-docs rev: 16e6447ab91b53fed78128dc4d000bc8c086a221)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit d467da2ccb5a78ac6a5ca9d976a435b4d4e0e270)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
2bb53d9e91 dev-manual: update AUTOREV explanation to match current file
The code snippet for listing AUTOREV-enabled recipes needs updating
since it now inherits the "poky-bleeding" class file.

(From yocto-docs rev: f4db42b820d489cb20d5b306f66a4f244fdc9338)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit fcf87058a1e6ef77904d74128574028660d5a4ab)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
9ac1b69234 kernel-dev: remove references to defunct LTSI project
As the last kernel release under LTSI (Long-Term Support Initiative)
was back in 2018, remove references to it.

(From yocto-docs rev: dcd16f58847b9d6bb593e0ae934c4055a6468b02)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b2063f6bb4c80e533a11de87d0daddf54e16cd2b)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
8545287b86 dev-manual: fully define SOLIBS-related variables in bitbake.conf
The current (abridged) SOLIBS-related variables were not included in
their entirety so add the missing content.

(From yocto-docs rev: 9ff28bf8ef2c1d184b1e7b00287749b54f006734)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 6098e0887161ffda87e62dd460702197269d5982)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
df15896a9d dev-manual: fix broken grammar in "Libraries" section
(From yocto-docs rev: 2891c40e0f0b491fe45c215465ba74628d870a3f)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit ff83e149175dc7470770cc53fd75a243d0fc8191)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
de584eb9a8 dev-manual: fix grammatical error, missing word "with"
Add the missing word "with."

(From yocto-docs rev: f67b98070a069eebfe9826467fc681c6ddc3f68c)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b2820e987abc15b474152e51cd76e9bf30660a69)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
baa014ae15 dev-manual: drop "PREFERRED_VERSION" from x86-base.inc snippet
The machine include file "x86-base.inc" no longer includes the line
setting the PREFERRED VERSION -- that setting was removed in commit
298fa078fab58b64246376ffd70ad6a0c7589876 on Oct 1, 2023:

    qemux86/qemuarm: Drop kernel version overrides

    Drop the version overrides for the kernel for the x86 and arm machines
    so we can go back to following the distro versions. The reasons for
    these versions is mostly historical at this point as the issues were
    resolved.

(From yocto-docs rev: 5185c770c30f1041ae1f14290e75f5cc8cfe690d)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit a70ce32d8e314afa833079e17757dc9b19590c56)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Peter Marko
4ac62a70a3 build-manual: update ROOTFS_POSTPROCESS_COMMAND example
Some commands were moved from ROOTFS_POSTPROCESS_COMMAND to
ROOTFS_POSTUNINSTALL_COMMAND.
Since ROOTFS_POSTUNINSTALL_COMMAND is not in printed subset, just remove
the tasks instead of moving them.

Corresponding oe-core change:
https://git.openembedded.org/openembedded-core/commit/?id=c3097962ac925538e99b17b771c541950a8b8c26

(From yocto-docs rev: 692ef46378ab15dceba3248d825246f9187de02e)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit cee160c2387b9bb8befad6e2e7f59575a014418c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Robert P. J. Day
bb00844600 ref-manual: clarify that PACKAGE_EXCLUDE supports DEB packaging
As an accompaniment to earlier commit
0d05dedd62a6d4c726f120a23654ede1f0b23d8e, correct that the
PACKAGE_EXCLUDE variable supports the DEB packaging backend.

(From yocto-docs rev: 7cb1b61247852c0693950f034aa88dcd6dc3accd)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 195fc0981996998ba2939bb9ce8770f396e5f438)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-22 21:23:17 +01:00
Ross Burton
36687ffb9c python_setuptools_build_meta: clean the build directory in configure
It's not currently possible to set the build tree to be somewhere we
control, but we know it will always be in the build directory alongside
the pyproject.toml so we can [cleandirs] that.

MJ: this was later reverted in a532cb50151d773c1c351ffccf4d47a37f26f8aa:
  This is not needed: setuptools.build_meta does the build under a new
  temporary directory.

but the builds in scarthgap aren't using new temporary directory yet,
so this is still useful there:

Just rebuilding python3-tqdm in the same TMPDIR after cherry-picking this:

$ buildhistory-diff -p buildhistory build-minus-1 | grep PKGSIZE
python3-tqdm/python3-tqdm: PKGSIZE changed from 3309408 to 426880 (-87%)

$ wc -l python3-tqdm/4.66.3*/image/usr/lib/python3.12/site-packages/tqdm-4.66.3.dist-info/RECORD
  297 python3-tqdm/4.66.3-old/image/usr/lib/python3.12/site-packages/tqdm-4.66.3.dist-info/RECORD
   41 python3-tqdm/4.66.3/image/usr/lib/python3.12/site-packages/tqdm-4.66.3.dist-info/RECORD

(From OE-Core rev: d4950d6df0867dcd5c380d83ac4d138ec968e698)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
(cherry picked from commit 383862cfe4c5acf04124080827c8bc6d00b2e86d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-19 12:49:08 +01:00
Ross Burton
de8bb77450 setuptools3: clean the build directory in configure
It's not currently possible to set the build tree to be somewhere we
control, but we know it will always be in the build directory alongside
the setup.py so we can [cleandirs] that.

MJ: helps with build/lib directory being added when a recipe is rebuilt
in the same WORKDIR multiple times, e.g.:

Just rebuilding python3-tqdm in the same TMPDIR after cherry-picking this:

$ buildhistory-diff -p buildhistory build-minus-1 | grep PKGSIZE
python3-google-auth/python3-google-auth: PKGSIZE changed from 11752510 to 1315694 (-89%)
python3-googleapis-common-protos/python3-googleapis-common-protos: PKGSIZE changed from 7108856 to 794024 (-89%)

$ wc -l python3-google-auth/2.29.0*/image/usr/lib/python3.12/site-packages/google_auth-2.29.0.dist-info/RECORD
  554 python3-google-auth/2.29.0-old/image/usr/lib/python3.12/site-packages/google_auth-2.29.0.dist-info/RECORD
   66 python3-google-auth/2.29.0/image/usr/lib/python3.12/site-packages/google_auth-2.29.0.dist-info/RECORD

$ wc -l python3-googleapis-common-protos/1.63.0*/image/usr/lib/python3.12/site-packages/googleapis_common_protos-1.63.0.dist-info/RECORD
  1166 python3-googleapis-common-protos/1.63.0-old/image/usr/lib/python3.12/site-packages/googleapis_common_protos-1.63.0.dist-info/RECORD
   134 python3-googleapis-common-protos/1.63.0/image/usr/lib/python3.12/site-packages/googleapis_common_protos-1.63.0.dist-info/RECORD

(From OE-Core rev: a0151ab56cf3fcaa6587e240b5454fed5315a534)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
(cherry picked from commit f3854f4f60801e3b6788bee3a0a1850fc498d536)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-19 12:49:08 +01:00
Ross Burton
b660629c0c setuptools3_legacy: ensure ${B} is clean
We do builds in a separate directory in this class, so add it to cleandirs
to ensure that it is empty.

(From OE-Core rev: 9a32956dd5dcbcc380780bc25e4303280f2ca9f9)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 2575adeceedae72f6359c0a35ec5c5325a4ec363)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-19 12:49:08 +01:00
Vijay Anusuri
fb0a4eb7a8 xserver-xorg: Fix CVE-2026-34003
Pick patch according to [1]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003677.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34003

(From OE-Core rev: 5faf37e3de47291cffed048ae20d91033d94d686)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-19 12:49:08 +01:00
Vijay Anusuri
122701d321 xserver-xorg: Fix CVE-2026-34002
Pick patch according to [1]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003677.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34002

(From OE-Core rev: 5c30b1e0dd0e1cb65091787c9c931d3d16c0f93c)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-19 12:49:08 +01:00