Commit Graph

76275 Commits

Author SHA1 Message Date
Hitendra Prajapati
bac60a09b6 vim: Fix for CVE-2026-28417, CVE-2026-32249, CVE-2026-45130
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 79348dbbc0
[2] 36d6e87542
[3] 9299332917
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28417
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-32249
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-45130

(From OE-Core rev: e61095581f25a79964ee426899ee72236118f570)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
ba66043d77 vim: fix for CVE-2026-28421, CVE-2026-41411 & CVE-2026-44656
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 65c1a143c3
[2] c78194e41d
[3] 190cb3c2b9
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-28421
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-41411
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-44656

More info :
CVE-2026-28421 - Validate block tree indices and readfile() line bounds.
CVE-2026-41411 - Disallow backticks before attempting to expand filenames.
CVE-2026-44656 - Prevent shell execution from 'path' backticks via modelines.

(From OE-Core rev: 3fe9e5132aab67f1ee3139c88a89d5c6c94313c1)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Hitendra Prajapati
623f85f957 vim: fix for CVE-2026-34982, CVE-2026-34714 & CVE-2026-35177
Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]

[1] 75661a66a1
[2] 664701eb75
[3] 7088926316
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-34982
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-34714
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-35177

More info :
CVE-2026-34982 - vim: arbitrary command execution via modeline sandbox bypass.
CVE-2026-34714 - vim: Arbitrary code execution via crafted file.
CVE-2026-35177 - vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass.

(From OE-Core rev: 1b4ee99b86262ade31b69a2ba9f80791b15ea130)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
d29b27fb31 dhcpcd: patch CVE-2026-56117
Backport patch [1] mentionned in [2]

[1] 78ea09ed16

[2] https://security-tracker.debian.org/tracker/CVE-2026-56117

(From OE-Core rev: 5c94b031f12c8623dc6eb9e05b87a004826345c1)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
4e6df49262 dhcpcd: patch CVE-2026-56114
Backport patch [1] mentionned in [2]

[1] 2f00c7bfc4

[2] https://security-tracker.debian.org/tracker/CVE-2026-56114

(From OE-Core rev: daaaedd30aac04f3440e11682b0a9ecbb2b75b1f)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:32 +01:00
Theo Gaige (Schneider Electric)
c223541984 dhcpcd: patch CVE-2026-56113
Backport patch [1] mentionned in [2]

[1] 5733d3c59a

[2] https://security-tracker.debian.org/tracker/CVE-2026-56113

(From OE-Core rev: fbfee67ed5d0c799bc1011f8463741c3b0910885)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Jaipaul Cheernam
37b718ecb9 curl: fix CVE-2026-5773 - wrong reuse of SMB connection
libcurl's SMB handler marks connections for reuse (connkeep) without
verifying that subsequent requests target the same share. This allows
a second SMB request to the same host to reuse a connection
authenticated for a different share, potentially accessing data
without proper authorization.

The upstream fix removes connection reuse for SMB entirely in
lib/protocol.c, a file introduced in curl 8.20.0. For 8.7.1, the
equivalent fix is changing connkeep() to connclose() in lib/smb.c,
which prevents the connection from being returned to the pool.

Tested with SMBv1 server (Docker dperson/samba):
  Without patch: "Re-using existing connection" for different shares
  With patch: New connection per request, no reuse

Binary verified: Curl_conncontrol arg changes from 0 (KEEP) to 1 (CLOSE)

Reference: https://curl.se/docs/CVE-2026-5773.html

(From OE-Core rev: 7736f905e78162ac657d7a1c790dfa5701dd6b19)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Nate Kent
b8085938de sudo: fix pam-wheel sed for sudo 1.9.17p2 sudoers
[YOCTO #16321]

In version 1.9.17p2, the line that the recipe uses to add the 'wheel'
group to the sudoers file does not exist. This updates the sed usage to
the actual line in question.

(From OE-Core rev: 55f7bf8cd9516971d6d01c1c890bc4c1df62b008)

Signed-off-by: Nate Kent <nathan@otiv.ai>
Tested-by: Siva Balasubramanian <sivakumar.bs@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 76231f202a437be221c2580d4fa0fc100c453e92)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Himanshu Jadon
75cbb0daa1 tar: Fix CVE-2026-5704
Backport the upstream 3-commit fix chain for CVE-2026-5704.

The final CVE fix is [1], which depends on the earlier cleanup in [2]
and the behavioral change in [3]. Keep this patch order so the final
fix applies cleanly and preserves the upstream logic.

Also include upstream follow-up [4] to fix the --no-overwrite-dir ptest
regression caused by the CVE backport. Without this follow-up, tar can
temporarily chmod an existing directory even when --no-overwrite-dir is
used, which breaks the upstream --no-overwrite-dir ptest.

[1] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b8d8a61b25588caca4efaf9bdd2e3f1a49da77e3
[2] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=112ead79312ea308e58414b74623f101b8c06f0b
[3] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=b009124ffde415515081db844d7a104e1d1c6c58
[4] https://cgit.git.savannah.gnu.org/cgit/tar.git/commit/?id=4e742fc8674064a9fa00d4483d06aca48d5b0463
[5] https://security-tracker.debian.org/tracker/CVE-2026-5704

(From OE-Core rev: 86360db7d1ea4e5d2bac9889cf8fefe6148a90b4)

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 872d86b99ad3e77a105b386331a41f7fa40c2b72)
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Daniel Turull
c70d4a799a libssh2: fix CVE-2026-55199
Backport patch to fix CVE-2026-55199.
https://nvd.nist.gov/vuln/detail/CVE-2026-55199

Upstream fix:
  17626857d2

Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0

Reviewed-by: Anders Heimer <anders.heimer@est.tech>
(From OE-Core rev: 2da74d75a8719db63979f132b456afdbd80395ef)

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
(cherry picked from commit 5b52af4a02849c1ce74491056a2d13e4e3b6ad2d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Daniel Turull
af5ab14071 libssh2: fix CVE-2026-55200
Backport patch to fix CVE-2026-55200.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200

Upstream fix:
  97acf3dfda

Tested with ptest:
Before: PASSED: 3, FAILED: 0, SKIPPED: 0
After: PASSED: 3, FAILED: 0, SKIPPED: 0

Reviewed-by: Anders Heimer <anders.heimer@est.tech>
(From OE-Core rev: a610461f9040644bec9f1b9be23dcfff121df888)

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
(cherry picked from commit 42c8c6ec3066dc47b9eeeba0247ffa927193abff)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-20 09:04:31 +01:00
Antonin Godard
e146cbbc73 docs-wide: fix various broken links
Fix various broken links found using the linkcheck builder, in various
places of the documentation. For most, the replacing link is the
equivalent new link.

(From yocto-docs rev: 5f708a1bc31ae94dd3513615b0ce079aa7897628)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 358519ca6406a89fee42c45dcaf63a37a374f33c)
[AG: fix conflict in variables.rst, due to changes to new variables in master]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
cbaaf0dcf7 migration-guides/release-notes-5.0.rst: remove broken link
https://no-color.org seems down, so remove the link.

(From yocto-docs rev: 615ae29b1d00e56b76bc86982848a152392ee691)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 45f54eca0f7ba4a56ce7dd8a1a388eef1eeffc45)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
84db80f823 ref-manual/images.rst: update obsolete VMWare links
VMWare Player has been discontinued in 2024 so remove the link. What
seems to be remaining is VMWare Fusions and Workstation so provide that
link only.

(From yocto-docs rev: f139c98f658e83328169cb90d119855e43a5bc83)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 7c969dcbebf5cccb28ccbf2370dc8b52cbd08974)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
6dc01c1e09 ref-manual/classes.rst: replace obsolete mailing list thread
I found this one by looking at the archive of the link on
https://web.archive.org and then locating the thread on
lists.yoctoproject.org by its title.

(From yocto-docs rev: a39ce713ec34964776cb7562c6bd7dad9e4b675d)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 5e792ff01d463a7eca21b7be50124d7c10ff8559)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
be96cd2ddb docs-wide: fix broken path links
Fix link that forget to add a leading '/', by looking at the output of
'grep -E -r --no-filename -o 'href="http.://[^/"]+' | sort | uniq' in
the HTML output.

(From yocto-docs rev: 5e1aade33c75ce58bfb20f0118a0c862b03f7b7b)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 12a5d2add529e789480fa782af3803dada982869)
[AG: fix conflicts: only applies to
 migration-guides/release-notes-3.4.2.rst]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
fbbf0d711c migration-guides/release-notes-3.4.2.rst: fix a broken link
Remove the extra '`'.

(From yocto-docs rev: 95ca2f097165b7689498575db282937a0fb0212a)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 4fd8cc10d3749f6ab3a372f943b5586f465565fb)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Robert P. J. Day
be05e58dcf ref-manual: add "KERNEL_IMAGE_STRIP_EXTRA_SECTIONS" to variables
Add this variable to the variables glossary, and add links to it and
back to the do_strip() task for completeness.

(From yocto-docs rev: cc4b7ffb3b2558ae796decbd216302e253addf02)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit f43fc622d2fd6bc832a2993841b2020f86c6475c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Robert P. J. Day
9ba4cbc08e ref-manual: expand on kernel "do_sizecheck" task
Expand on the description of do_sizecheck() to mention that it will
size-check on *all* kernel images listed in KERNEL_IMAGETYPES.

(From yocto-docs rev: 0a7d6b399d6354985527ed5fa7c2a0b132e0b640)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
[AG: kilobytes -> kibibytes
 See https://lore.kernel.org/r/DJUQAEXAC03Q.2T7IDXHKVIX95@bootlin.com]
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b01fb11a4909fe2d3afa6cb01bd7b179429e382c)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
84ecefc9f2 ref-manual/variables.rst: document the LOCALE_UTF8_IS_DEFAULT variable
Added by commit fcde0c43f7b5 ("libc-package.bbclass: add
LOCALE_UTF8_IS_DEFAULT") in OE-Core.

(From yocto-docs rev: dcf4ecb7f0dfab1b33d4ce557d04f53dff94a8ed)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 0d5a45cb46f89bd09ed9ac59e09cff77f2868b2d)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-15 18:39:01 +01:00
Antonin Godard
6b7474f7ca ref-manual/variables.rst: document the IMAGE_*_DEBUGFS variables
Added by commit 41316293e442 ("lib/oe/image.py: Add image generation
for companion debug filesystem") in OE-Core.

(From yocto-docs rev: 51c53ef1e8b4ec4afbb84252e59dd5501f405064)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 75a69c94f5ba556fbe182c96a9bab2c561a0358e)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
2f9c3b01d1 ref-manual/variables.rst: document the LOCALE_PATHS variable
Added by commit 0ffc7cf01225 ("lib/oe/package: add LOCALE_PATHS to
add define all locations for locales") in OE-Core.

(From yocto-docs rev: f8c795f6e9b94d0a747b6ccbd3fcc55c84b16919)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b2267d27de5ac5ac163be4c740d725a181f3f2cf)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
4d3cdfe6ce ref-manual/variables.rst: document missing CONFLICT_*_FEATURES variables
Those are part of the features_check class.

(From yocto-docs rev: 297003a537798e6a4beafdd4ad520ed1c47c355a)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit fb38ef19e67b31f855bddb61ad990020d5cef234)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Antonin Godard
26efce957c ref-manual/variables.rst: document the CCACHE_NATIVE_RECIPES_ALLOWED variable
Added by commit 87cb2be71e0c ("ccache.bbclass: Add allowed list for
native recipes") in OE-Core.

(From yocto-docs rev: 67abd242b2fa08d3ebc3f1147058d683a4e1ef85)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 8881547719215a86a4a2e51ae3362462419a335b)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Robert P. J. Day
3899ca2590 ref-manual: remove all traces of "kernel_menuconfig" task
It's not clear why the non-existent "kernel_menuconfig" task was
documented in the reference manual, but it does not appear to have
ever existed so delete all references to it and replace with pointers
to rewritten "menuconfig" task.

(From yocto-docs rev: 5bd2aab3ad66bcc9f0b58e1b0643d71697a63da7)

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit fdeabae4ba20e34c428ceb133ad41c4f3fedcf24)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Paul Barker
a448bff87a recipe-style-guide: Clarify when License-Update tag is needed
As discussed in a patch review call, we don't need License-Update tags
in commits where the upstream license has not changed, and we are
instead changing the LICENSE variable to fix incorrect data.

(From yocto-docs rev: d4e19136ffee4fabfdfc5048835da64f0cfbb3eb)

Signed-off-by: Paul Barker <paul@pbarker.dev>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit db04faf56afded6c5f846cc60a9062e0a1ffa741)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-03 11:19:21 +01:00
Paul Barker
bb98354685 build-appliance-image: Update to scarthgap head revisions
(From OE-Core rev: 2814f0962f56c8d1afa4de76d2895ba9b5cb767d)

Signed-off-by: Paul Barker <paul@pbarker.dev>
yocto-5.0.19
2026-07-02 13:52:11 +01:00
Paul Barker
ba193efe20 poky.conf: Bump version for 5.0.19 release
(From meta-yocto rev: 2f749ae477c3b94dce71038f025180d7f612dab0)

Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Richard Purdie
98335a279f recipetool: Recognise https://git. as git urls
If a url has git. in it, assume it is likely to be a git cloneable url
and should be treated as such.

This allows us to switch from https://git.yoctoproject.org/git/XXX urls to
the preferred https://git.yoctoproject.org/XXX form.

(From OE-Core rev: be8b46f3a31b679b5ab532dd6e16888f868ce076)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit cedc9209e3bae0da8d61423b16c74c49a132aa63)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Richard Purdie
4db556863d oeqa: Drop /git/ from our urls
Using /git/ in our urls is rather old school and not the preferred format now.
Update the urls to the preferred form even if the other ones still work.

(From OE-Core rev: 50f40609b27c169e9da1f076172daabbf55732d0)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 8ac7c0c3493a6141476093bb2c1c79004c55857d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Amaury Couderc
f47c0cb3bf python3: fix CVE-2026-4224
Backport patch to fix CVE-2026-4224.
https://nvd.nist.gov/vuln/detail/CVE-2026-4224

Upstream fix:
  642865ddf4

Tested with ptest:
Before: PASSED: 40007, FAILED: 0, SKIPPED: 1877
After: PASSED: 40006, FAILED: 0, SKIPPED: 1877

(From OE-Core rev: 736dd8c8f90d43e4bcdb0954a99764a62fccc20e)

Signed-off-by: Amaury Couderc <amaury.couderc@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Sudhir Dumbhare
2c373fb9b9 nfs-utils: fix CVE-2025-12801
- This patch applies the upstream fix [5] as referenced in [7].
- To successfully apply the fixed commit, apply the dependent commits [2] to [4]
  which are included in v2.8.6, as referenced in [7].
- Additionally, include dependent commit [1] from v2.8.3, as referenced in [8]
  under the [2.5.4-38.2] description, along with compilation fix commit [6]
  from v2.7.1
- Reference:
  [1] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=cd90f2925790
  [2] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=7e8b36522f58
  [3] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=42f01e6a78fe
  [4] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=51738ae56d92
  [5] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=f36bd900a899
  [6] https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=a2c95e4f557a
  [7] https://security-tracker.debian.org/tracker/CVE-2025-12801
  [8] https://linux.oracle.com/errata/ELSA-2026-3940.html

(From OE-Core rev: a866d0438d30b1625450f68fea19e9315a4e4b36)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Anil Dongare
d144337355 libusb1: fix CVE-2026-23679 and CVE-2026-47104
- Pick the upstream patch [1] as mentioned in [2] and [3].
- To successfully apply the fixed commit, apply the dependent commits [4], which are
  included in v1.0.28.

[1] bc0886173e
[2] https://security-tracker.debian.org/tracker/CVE-2026-23679.
[3] https://security-tracker.debian.org/tracker/CVE-2026-47104.
[4] 016a0de33a

(From OE-Core rev: c4d5735228e83c3a9afce48a39707b2ff5460fde)

Signed-off-by: Anil Dongare <adongare@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
9504d658b8 xwayland: Fix CVE-2026-34003
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34003

(From OE-Core rev: 798e81f20e73b07255bdd6e669c146da905f6c00)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
e28bf42780 xwayland: Fix CVE-2026-34002
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34002

(From OE-Core rev: 0df72cf8effda9d82088062aa57159df2b197945)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:26 +01:00
Vijay Anusuri
f54d73ee0d xwayland: Fix CVE-2026-34001
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34001

(From OE-Core rev: 1411caa0781811b7ee452edb04ffdcf3acc92a91)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Vijay Anusuri
de68828aa2 xwayland: Fix CVE-2026-34000
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-34000

(From OE-Core rev: af54fbd683bf8a143b2327a74babe372e1b6f909)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Vijay Anusuri
b96bba2f35 xwayland: Fix CVE-2026-33999
Pick patch according to [2]

[1] https://lists.x.org/archives/xorg-announce/2026-April/003679.html
[2] https://security-tracker.debian.org/tracker/CVE-2026-33999

(From OE-Core rev: 7060d5970c1c80631ac0c5857fe6b76176f535c9)

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Theo Gaige (Schneider Electric)
e2d512c2e7 go: patch CVE-2026-27145
Backport patch from [1]

[1] https://go.dev/cl/783621

(From OE-Core rev: 209a1b3a48b8e3996e1b53f2d7efe335855b7375)

Signed-off-by: Theo Gaige (Schneider Electric) <tgaige.opensource@witekio.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
61f170a32d libsoup: fix for CVE-2026-2369
Pick patch from [1] also mentioned at Debian report in [2]

[1] af4bde9902
[2] https://security-tracker.debian.org/tracker/CVE-2026-2369

Note: Issue introduced by the fix for CVE-2025-32052.

(From OE-Core rev: 6ca4635dfe2c7fb277af3409931c66f7863af890)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Hitendra Prajapati
8820ef32b5 libsoup: fix for CVE-2025-11021
Pick patch from [1] also mentioned at Debian report in [2]

[1] 9e1a427d2f
[2] https://security-tracker.debian.org/tracker/CVE-2025-11021

(From OE-Core rev: f360fdedfb500cecf6d4e860d599c57b11d6e31d)

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
[YC: The CVE fixing patch is d010b0bbd in 3.6.6 (current master/wrynose)]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Yoann Congal
e9dcaec506 gawk-native: fix gcc-15/C23 compilation issues
On Ubuntu 26.04, GCC 15 defaults to std=c23 and that results in build
failure:
| ../gawk-5.3.0/io.c: In function ‘iop_alloc’:
| ../gawk-5.3.0/io.c:3389:31: error: assignment to ‘ssize_t (*)(int,  void *, size_t)’ {aka ‘long int (*)(int,  void *, long unsigned int)’} from incompatible pointer type ‘ssize_t (*)(void)’ {aka ‘long int (*)(void)’} [-Wincompatible-pointer-types]
|  3389 |         iop->public.read_func = ( ssize_t(*)() ) read;
|       |                               ^

Fix this by (partially) backporting an upstream patch.

(From OE-Core rev: 790bccfd8b82809e87311b24f71cf9f8e6a02b5e)

Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Ross Burton
2bf810addd gawk: trim native build configuration
When we build gawk-native it is only for use in builds where the host
gawk output isn't reproducible across versions[1]. As such it doesn't
need support for readline or mprf, and by removing those from gawk-native
we can get building gawk-native sooner.

[1] oe-core c5bbf0a60b ("gawk: use native gawk when building glibc and grub")

(From OE-Core rev: c80a422c9c1392127a431c2dd38b203266b0b1ed)

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 1e6b810f60fd45856fc6a57270bf85342bcd9415)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Richard Purdie
09e4ebfa59 grub/glibc: Bump versions to resolve hashequiv/reproducibility issues
After the gawk dependency change, we need to change PR/hashequiv version
to replace the corrupted sstate/hashequiv data.

(From OE-Core rev: a455b21f9170b3f2d74763b5bf99625dbda81ff9)

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f0f7632595792a73ea0a935b924e8bdf9954ec7b)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Alexander Kanavin
1c5f26e47e gawk: use native gawk when building glibc and grub
Different versions of gawk can produce different output,
so depending on which version is installed on the build host,
reproducibility issues can occur:
https://bugzilla.yoctoproject.org/show_bug.cgi?id=16072

So far only glibc and grub have been identified to have
the issue; probably more fixes of similar nature will be
required going forward.

Adjust the gawk recipe to apply target-only tweaks
(particularly the removal of awk symlink to allow for alternatives)
to only target and nativesdk variants, so that native installs
both awk and gawk executables.

[YOCTO #16072]

(From OE-Core rev: 288ecfd7d9cd24222cc0f1277105c15cf0889718)

Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit c5bbf0a60b1d63e68f849a63e5d3872954e7cd3f)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-02 13:42:25 +01:00
Bruce Ashfield
3482e7f32a linux-yocto/6.6: address ltp hang
Integrating the following commit(s) to linux-yocto/6.6:

1/1 [
    Author: Baokun Li
    Email: libaokun1@huawei.com
    Subject: ext4: get rid of ppath in get_ext_path()
    Date: Thu, 22 Aug 2024 10:35:32 +0800

    The use of path and ppath is now very confusing, so to make the code more
    readable, pass path between functions uniformly, and get rid of ppath.

    After getting rid of ppath in get_ext_path(), its caller may pass an error
    pointer to ext4_free_ext_path(), so it needs to teach ext4_free_ext_path()
    and ext4_ext_drop_refs() to skip the error pointer. No functional changes.

    Signed-off-by: Baokun Li <libaokun1@huawei.com>
    Reviewed-by: Jan Kara <jack@suse.cz>
    Reviewed-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
    Tested-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
    Link: https://patch.msgid.link/20240822023545.1994557-13-libaokun@huaweicloud.com
    Signed-off-by: Theodore Ts'o <tytso@mit.edu>
]

(From OE-Core rev: 737293bead3e7b994347e47f09bc69437479d50c)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
[YC: more detail at https://lore.kernel.org/openembedded-core/DJGKEQF8GRU1.RF7JY64COTAA@smile.fr/T/#u]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
8cfb09a6b0 linux-yocto/6.6: genericarm64 fix configuration audit warning
Integrating the following commit(s) to linux-yocto/.:

1/1 [
    Author: Bruce Ashfield
    Email: bruce.ashfield@gmail.com
    Subject: genericarm64/serial: change SERIAL_IMX_CONSOLE to =y
    Date: Fri, 19 Jun 2026 00:54:55 +0200

    With the following upstream commit, this option is no longer
    tristate, so we set it to =y instead:

      commit 3f8b835a63341163da0400befb3c6e8f6d4085da
      Author: Randy Dunlap <rdunlap@infradead.org>
      Date:   Sat Jan 10 15:26:40 2026 -0800

          serial: imx: change SERIAL_IMX_CONSOLE to bool

          [ Upstream commit 79527d86ba91c2d9354832d19fd12b3baa66bd10 ]

          SERIAL_IMX_CONSOLE is a build option for the imx driver (SERIAL_IMX).
          It does not build a separate console driver file, so it can't be built
          as a module since it isn't built at all.

          Change the Kconfig symbol from tristate to bool and update the help
          text accordingly.

          Fixes: 0db4f9b91c86 ("tty: serial: imx: enable imx serial console port as module")
          Signed-off-by: Randy Dunlap <rdunlap@infradead.org>
          Link: https://patch.msgid.link/20260110232643.3533351-2-rdunlap@infradead.org
          Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
          Signed-off-by: Sasha Levin <sashal@kernel.org>

    Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
    (cherry picked from commit 465cb5bcefd72f429e0b3ad6ab5b3fcff5b390fc)
    Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
    Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
]

(From OE-Core rev: 535c5940d92c39d220ab2d36b15c2dc31b41b8e0)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
He Zhe
e5db0f30c8 lttng-modules: Fix trace_hrtimer_start build failure
Fix the following build failure

probes/../../include/lttng/tracepoint-event-impl.h:133:6: error: conflicting
types for 'trace_hrtimer_start'; have 'void(struct hrtimer *, enum hrtimer_mode)'
  133 | void trace_##_name(_proto);
      |      ^~~~~~

(From OE-Core rev: e0598e2bbf9513ad71dea185a540de16996c4114)

Signed-off-by: He Zhe <zhe.he@windriver.com>
[YC: backported from wrynose commit e32cbc177dae ("lttng-modules: Fix
trace_hrtimer_start build failure").
This is a partial backport of commit 7dae5f40e394 ("lttng-modules:
fix build against kernel 7.1+")]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
b61b34f6f8 linux-yocto/6.6: update to v6.6.142
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    924b4a879cbb Linux 6.6.142
    cefa4265b111 security/keys: fix missed RCU read section on lookup
    105c6a594b3f LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
    1f9c82855641 net: gro: don't merge zcopy skbs
    f504118252af pds_core: ensure null-termination for firmware version strings
    d3f3d6fa0cad pds_core: add an error code check in pdsc_dl_info_get
    01f7f893d5e1 net: mana: validate rx_req_idx to prevent out-of-bounds array access
    3dee2fe0c818 ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
    d798b25c24f4 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
    0f1fd5e83f0b gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n)
    cd87492b79d1 string: add mem_is_zero() helper to check if memory area is all zeros
    c9ea01768903 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
    40fc66218ad1 net: ag71xx: check error for platform_get_irq
    2a1905730e0c Bluetooth: btmtk: fix urb->setup_packet leak in error paths
    f04578422154 Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c
    73377cf3056a Bluetooth: btmtk: rename btmediatek_data
    aa58d8366269 Bluetooth: btusb: mediatek: refactor the function btusb_mtk_reset
    b748250d778e Bluetooth: btmtk: add the function to get the fw name
    e91687643c44 tracing: Avoid NULL return from hist_field_name() on truncation
    8ba1c4ddbb1c ALSA: seq: Serialize UMP output teardown with event_input
    e5604a480487 ALSA: seq: ump: Use guard() for locking
    b6d3d3816c67 ptrace: Convert ptrace_attach() to use lock guards
    60ef1675b652 pds_core: fix debugfs_lookup dentry leak and error handling
    3231aff8ab26 pds_core: fix error handling in pdsc_devcmd_wait
    1900ca8acb92 bridge: mcast: Fix a possible use-after-free when removing a bridge port
    6e79715b7b8a net: bridge: Flush multicast groups when snooping is disabled
    00904a73272b RDMA/rtrs: Fix use-after-free in path file creation cleanup
    a7685f4d90c1 platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
    527a7990e663 platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
    6ea1690b24e9 platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
    32ba2ce2b15f platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
    566f42fb67a7 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
    314a94c47d28 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
    1bddf306212a net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw
    d2be607d042d net: dsa: mt7530: fix FDB entries not aging out with short timeout
    69a0885079c9 wifi: ath11k: fix peer resolution on rx path when peer_id=0
    070e40acc59e drm/msm/snapshot: fix dumping of the unaligned regions
    dd844b31f4ea spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
    5c54c482934b net/mlx5: Do not restore destination-less TC rules
    d65b279a1898 tls: Preserve sk_err across recvmsg() when data has been copied
    1822997aa8c2 x86/xen: Fix xen_e820_swap_entry_with_ram()
    06cc5ad2c112 net: phy: DP83TC811: add reading of abilities
    d04494596b5e net: phy: c45: add genphy_c45_pma_read_ext_abilities() function
    acdc12b71c9a net: tls: prevent chain-after-chain in plain text SG
    131ef12057d9 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
    d38ba387244e net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
    a09d07ac45e2 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
    7256e54583ae drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
    567b5e976e2e drm/msm/dsi: don't dump registers past the mapped region
    b40e10c72df5 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
    720c76b930c5 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
    9baafc2fea09 accel/qaic: Add overflow check to remap_pfn_range during mmap
    f775be13d342 HID: quirks: really enable the intended work around for appledisplay
    a5db6a7c062f wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
    3d675896ea03 wifi: ath11k: fix error path leaks in some WMI WOW calls
    b77be98447c4 net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
    78cf08b3be47 net: ethernet: cortina: Carry over frag counter
    68c9c3ac9ce5 net: ethernet: cortina: Drop half-assembled SKB
    3b249988d774 net: ethernet: cortina: Make RX SKB per-port
    00efe58bbdcc netfs: Fix overrun check in netfs_extract_user_iter()
    0df68fd72b2a zonefs: handle integer overflow in zonefs_fname_to_fno
    eef4f71b46a9 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
    6760af11a26e irqchip/ath79-cpu: Remove unused function
    6af5fd2ffda1 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access
    b0cc58e8f749 net: lan966x: avoid unregistering netdev on register failure
    9e1c9b957344 ice: fix locking in ice_dcb_rebuild()
    07d77d774f71 tcp: Fix imbalanced icsk_accept_queue count.
    08d355936fcf test_kprobes: clear kprobes between test runs
    8a5f01446021 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
    99948d73a8c7 netfilter: x_tables: unregister the templates first
    26b2290baaf6 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
    542b49d2cf12 ALSA: hda: cs35l56: Put ACPI device after setting companion
    508b1193d63b ARM: integrator: Fix early initialization
    fb3ff02dd444 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
    7d694570281a kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
    0df3f3031517 kunit: config: Enable KUNIT_DEBUGFS by default
    8b0f4e3b7ad6 firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
    adfff93d08a2 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
    58ab91af4124 HID: uclogic: Fix regression of input name assignment
    a2d1c819348b hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
    20d626463e3f hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
    cba4f1122dfb hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
    6b5573b63e30 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple
    4d1da9a6be5a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
    60c4b9fe1a3d hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
    d94ceb16e55b hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
    f85c81e93dbd hwmon: (pmbus/adm1266) reject implausible blackbox record_count
    025cfc7a09c5 hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
    32edd2a28e11 batman-adv: tt: fix negative tt_buff_len
    22d59c72f4a4 batman-adv: tt: fix negative last_changeset_len
    c2c88736022c batman-adv: tp_meter: fix race condition in send error reporting
    0b1bedf114ea batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
    53f931e0146a batman-adv: tp_meter: avoid use of uninit sender vars
    48663158222b batman-adv: bla: fix report_work leak on backbone_gw purge
    b54e459cf869 batman-adv: frag: disallow unicast fragment in fragment
    c1bac194733a batman-adv: fix tp_meter counter underflow during shutdown
    f653b040dad1 batman-adv: fix fragment reassembly length accounting
    866ac1d57040 batman-adv: dat: handle forward allocation error
    6de089b545db batman-adv: clear current gateway during teardown
    70bcb678561f batman-adv: mcast: fix use-after-free in orig_node RCU release
    90c398e822ca drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
    fb30a3890d62 drm/amd/display: Validate GPIO pin LUT table size before iterating
    266b21b57fbb drm/amd/display: Fix integer overflow in bios_get_image()
    e4d3d33ab7bd drm/bridge: megachips: remove bridge when irq request fails
    25473edcdaef drm/bridge: it66121: acquire reset GPIO in probe
    21ab64c77a30 drm/virtio: use uninterruptible resv lock for plane updates
    371f53925a67 device property: set fwnode->secondary to NULL in fwnode_init()
    fb3539b367f5 LoongArch: Remove unused code to avoid build warning
    14553be882d9 RDMA/siw: Reject MPA FPDU length underflow before signed receive math
    f2dc841d7dc9 spi: ti-qspi: fix use-after-free after DMA setup failure
    450c319dd04d spi: sprd: fix error pointer deref after DMA setup failure
    309c6058622d scsi: isci: Fix use-after-free in device removal path
    9d5ae6b8d9ec phy: tegra: xusb: Fix per-pad high-speed termination calibration
    45760b72e84c spi: qup: fix error pointer deref after DMA setup failure
    3c83a6912c24 drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
    dab9f93251b2 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
    e0790046f6be arm64: probes: Handle probes on hinted conditional branch instructions
    f383cff9fb38 tracing: Do not call map->ops->elt_free() if elt_alloc() fails
    bdc349a87f1f cifs: Fix busy dentry used after unmounting
    1ced0f5a851f wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
    a3a4366731a5 ice: fix setting promisc mode while adding VID filter
    add70e2682c0 ixgbevf: fix use-after-free in VEPA multicast source pruning
    3c5411fa4944 ipv4: raw: reject IP_HDRINCL packets with ihl < 5
    f50c3ff97c83 wifi: ath11k: clear shared SRNG pointer state on restart
    ce29d3bf79a2 vsock/virtio: reset connection on receiving queue overflow
    cc27e989a5df vsock/vmci: fix UAF when peer resets connection during handshake
    273a1481c556 ring-buffer: Fix reporting of missed events in iterator
    3904b993cc17 qed: fix double free in qed_cxt_tables_alloc()
    c161ad9157f5 netfilter: nft_inner: Fix IPv6 inner_thoff desync
    c281e018af98 netfilter: ipset: stop hash:* range iteration at end
    1e5e20031c5e netfilter: nf_queue: hold bridge skb->dev while queued
    41ec2e242f17 netfilter: ip6t_hbh: reject oversized option lists
    16bd798cb6d8 net: ifb: report ethtool stats over num_tx_queues
    289499907399 net: bcmgenet: keep RBUF EEE/PM disabled
    8420aa490041 phonet/pep: disable BH around forwarded sk_receive_skb()
    be43e6b40431 Bluetooth: serialize accept_q access
    a143ce77a529 Bluetooth: MGMT: validate Add Extended Advertising Data length
    9d20d48be2c4 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
    fe69f634b076 Bluetooth: bnep: Fix UAF read of dev->name
    3af41ee7ebec Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
    5d86d2f1b4d9 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
    6f63a60580eb net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
    686b4283f82c drivers/base/memory: fix memory block reference leak in poison accounting
    29cd94e678fc efi: Allocate runtime workqueue before ACPI init
    7b6f8c8eb93f ALSA: asihpi: Fix potential OOB array access at reading cache
    41a766c64729 ALSA: pcm: Don't setup bogus iov_iter for silencing
    dade81458966 ALSA: ua101: Reject too-short USB descriptors
    0dbf64c50244 hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
    adcfb16ae402 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
    7df1df6f40c0 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
    9d378e17c864 ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
    e43cb36d4d78 ksmbd: fix null pointer dereference in compare_guid_key()
    082351f9d400 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
    31527d80234c sysfs: don't remove existing directory on update failure
    ad7520628c74 Revert "af_unix: Reject SIOCATMARK on non-stream sockets"
    f624070c322d Revert "s390/cio: Update purge function to unregister the unused subchannels"
    7963b6141b4c Revert "ice: Remove jumbo_remove step from TX path"
    6331b0f7b71e Revert "ice: fix double-free of tx_buf skb"
    2035acfb1722 smb: client: reject userspace cifs.spnego descriptions
    3106f326f67c af_unix: Give up GC if MSG_PEEK intervened.
    3a436932eb39 ksmbd: close durable scavenger races against m_fp_list lookups
    712cdf917e77 ksmbd: validate owner of durable handle on reconnect
    7f0cb478703c ksmbd: add durable scavenger timer
    50a23fa28e76 ksmbd: avoid reclaiming expired durable opens by the client
    2682bf9a804b Revert "x86/vdso: Fix output operand size of RDPID"
    ba5b43db126a wifi: mac80211: check tdls flag in ieee80211_tdls_oper
    a052c2d8399a s390/debug: Reject zero-length input before trimming a newline
    492349e5e4a3 driver core: platform: use generic driver_override infrastructure
    64a3ee535bd7 driver core: generalize driver_override in struct device
    fabfed1afe27 spi: spidev: fix lock inversion between spi_lock and buf_lock
    6a3af482188f mptcp: pm: ADD_ADDR rtx: free sk if last
    9426265e157d mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
    19a3ec9ef176 mptcp: pm: ADD_ADDR rtx: allow ID 0
    b386aa38b81d mptcp: sync the msk->sndbuf at accept() time

(From OE-Core rev: ba0f120f6cdbcc1d2782bef27c101e20a11f0f19)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00
Bruce Ashfield
1abb9145fc linux-yocto/6.6: update to v6.6.141
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:

    0a40c6fbd105 Linux 6.6.141
    f9957ea12103 netfs: Fix potential uninitialised var in netfs_extract_user_iter()
    989214c66884 net: skbuff: propagate shared-frag marker through frag-transfer helpers
    78bf6b6bb195 net: skbuff: preserve shared-frag marker during coalescing
    9115669faedc net/rds: reset op_nents when zerocopy page pin fails
    864889ea15f0 mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker
    013dcdc19615 mptcp: pm: ADD_ADDR rtx: fix potential data-race
    b21823f637e0 spi: sifive: fix controller deregistration
    524202b00b91 spi: sifive: Simplify clock handling with devm_clk_get_enabled()
    bf76b4a58c1a media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0
    9c7c941d2242 spi: st-ssc4: fix controller deregistration
    d8cd9fb5e655 spi: st-ssc4: switch to use modern name
    a7fb771314fb ksmbd: validate inherited ACE SID length
    190e570cc0fc RDMA/mana: Fix error unwind in mana_ib_create_qp_rss()
    8358a142f2a1 f2fs: fix false alarm of lockdep on cp_global_sem lock
    6b050c4cfade f2fs: fix incorrect file address mapping when inline inode is unwritten
    f63201f674ee mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0
    93a9014029e4 mptcp: pm: prio: skip closed subflows
    0750c7935feb mptcp: fix rx timestamp corruption on fastopen
    11fdbd033e4c mptcp: drop __mptcp_fastopen_gen_msk_ackseq()
    7d7c9f0fcd19 RDMA/mana: Validate rx_hash_key_len
    cc3c0a0f9657 btrfs: fix missing last_unlink_trans update when removing a directory
    397418a9456c btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I()
    546ca2e3e55a btrfs: use inode already stored in local variable at btrfs_rmdir()
    39aba0e6d5aa smb: client: Use FullSessionKey for AES-256 encryption key derivation
    cea7d2688ded drm/v3d: Reject empty multisync extension to prevent infinite loop
    958e032618c8 eventfs: Use list_add_tail_rcu() for SRCU-protected children list
    d2a675f2e238 btrfs: fix double free in create_space_info_sub_group() error path
    1ce1ec384486 btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type()
    707cb5df3eab pmdomain: core: Fix detach procedure for virtual devices in genpd
    c7d1eb27cf37 drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init
    4e04b564c005 drm/gma500/oaktrail_lvds: fix hang on init failure
    63a2b5906e15 drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
    4eb9d07b219f drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout()
    e5eb0a29a8aa drm/i915: skip __i915_request_skip() for already signaled requests
    2776f9016f1b iommu/vt-d: Disable DMAR for Intel Q35 IGFX
    534ebc08df97 libceph: handle rbtree insertion error in decode_choose_args()
    ea0d42137f0c libceph: Fix potential out-of-bounds access in crush_decode()
    d7a65a34d245 libceph: Fix potential null-ptr-deref in decode_choose_args()
    0d2dd7e6bb74 libceph: Fix potential out-of-bounds access in osdmap_decode()
    bcbbdae1b88f netfs: fix error handling in netfs_extract_user_iter()
    cad72955f8fb powerpc/warp: Fix error handling in pika_dtm_thread
    d6bda9df0c0a io-wq: check that the predecessor is hashed in io_wq_remove_pending()
    4bfdcefdaa60 ceph: fix a buffer leak in __ceph_setxattr()
    3d3b2b01a3e7 ALSA: usb-audio: Bound MIDI endpoint descriptor scans
    fafc97bd01e4 ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
    7eaa514be4c0 drm/i915/dp: Fix VSC dynamic range signaling for RGB formats
    b41598bf54b3 smb/client: fix possible infinite loop and oob read in symlink_data()
    a1d4f3d3c0dc ASoC: SOF: Intel: hda: Fix NULL pointer dereference
    0f9ac21618c0 ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio
    1eda406a9432 ASoC: SOF: Intel: hda-dai: remove dspless special case
    e3ccb11fc824 netfilter: nf_tables: unconditionally bump set->nelems before insertion
    dde6eca9afae KVM: x86: Fix Xen hypercall tracepoint argument assignment
    a99a25db131e KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
    01b71b930f15 KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
    5b6da42fd804 audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
    810d382802a5 net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled
    ecca618e1e33 netfilter: nft_ct: fix missing expect put in obj eval
    151ee470edc3 audit: fix incorrect inheritable capability in CAPSET records
    b92e124ef30a netfilter: nf_conntrack_sip: get helper before allocating expectation
    0088b3328a6f workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path
    a5712dc25d14 i40e: Cleanup PTP pins on probe failure
    e4c4a5074532 crypto: af_alg - Cap AEAD AD length to 0x80000000
    fa6794c968d4 bonding: fix NULL pointer dereference in actor_port_prio setting
    044dcbcb19c3 netconsole: avoid out-of-bounds access on empty string in trim_newline()
    feb754bde3ef net/sched: sch_pie: annotate more data-races in pie_dump_stats()
    bf3962084183 ksmbd: validate response sizes in ipc_validate_msg()
    52b9f8099369 net: bcmgenet: fix leaking free_bds
    dda1a2e898ad net: bcmgenet: Initialize u64 stats seq counter
    f17a4850d1ce crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
    d65a64755a3d smb: client: fix OOB reads parsing symlink error response
    ba302d3abb82 smb: client: correctly handle ErrorContextData as a flexible array
    2c7d07892ef8 Revert "crypto: nx - Migrate to scomp API"
    6c9970847516 Revert "crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx"
    cb4634cb537b Revert "crypto: nx - fix context leak in nx842_crypto_free_ctx"
    02ecc0978c45 ntfs: ->d_compare() must not block
    9ccd0c1686c3 net/sched: cls_flower: revert unintended changes
    131e50acfeed sfc: fix error code in efx_devlink_info_running_versions()
    688f12aa4451 net: tls: fix strparser anchor skb leak on offload RX setup failure
    3ad2471e61e9 ice: fix NULL pointer dereference in ice_reset_all_vfs()
    bee6158b8a36 iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler
    b90697dd4b45 iavf: wait for PF confirmation before removing VLAN filters
    5936b7f29a38 iavf: stop removing VLAN filters from PF on interface down
    ee587b3b97b7 iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING
    3b7265b3a82f bonding: 3ad: implement proper RCU rules for port->aggregator
    2353f43d7ee7 bonding: print churn state via netlink
    fcf04d6f6943 bonding: add support for per-port LACP actor priority
    60fcd5af8279 net: bonding: add broadcast_neighbor option for 802.3ad
    ee2217012b3a bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner
    71d591d33dc4 drm/amd/display: Read EDID from VBIOS embedded panel info
    3dce88cf11d7 drm/amd/display: Allow DCE link encoder without AUX registers
    e3f95b1ba242 futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
    d68f753d89f4 ALSA: hda/conexant: Fix missing error check for jack detection
    539604dcbf41 ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87
    35b7210e15a6 ALSA: hda/conexant: fix some typos
    3eaf81c3553e netconsole: propagate device name truncation in dev_name_store()
    3bc2c51a9ba1 net: netconsole: move newline trimming to function
    003b52afba79 net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
    a0f4e4e8e0f5 bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
    0928f17e86a5 ipv6: rename and move ip6_dst_lookup_tunnel()
    3bab544ae1e1 ipv4: add new arguments to udp_tunnel_dst_lookup()
    f933e5a43732 ipv4: remove "proto" argument from udp_tunnel_dst_lookup()
    0379c21610f0 ipv4: rename and move ip_route_output_tunnel()
    5cb1dd7093d3 sctp: discard stale INIT after handshake completion
    043e4b649b4b netfilter: skip recording stale or retransmitted INIT
    e3610ad82ebd ASoC: codecs: ab8500: Fix casting of private data
    b884ff67d62e drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring
    d4e0172a1b61 drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring
    ee035a9d3eed drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring
    63691e396105 drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring
    f675801889b2 drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring
    c12a5d35033c drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring
    e74fc9c72c1b drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings
    2c6fb056567e drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings
    f264019be80d drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings
    b233ba52fd2e net: phy: dp83869: fix setting CLK_O_SEL field.
    47d017fe3159 net: mctp i2c: check length before marking flow active
    924b961d293c ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams
    9247d59ca15b neigh: let neigh_xmit take skb ownership
    dbe42409bfeb neighbour: add RCU protection to neigh_tables[]
    ec2501e361b0 net/sched: taprio: fix NULL pointer dereference in class dump
    0d0dd383ac4d NFC: trf7970a: Ignore antenna noise when checking for RF field
    17e23e815008 net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit
    5db090ca07b2 net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
    3db8d078f7f6 vrf: Fix a potential NPD when removing a port from a VRF
    d4f8505517ff net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats()
    229ad4b2dd86 net/sched: sch_choke: annotate data-races in choke_dump_stats()
    bd426bda5741 net/sched: netem: check for negative latency and jitter
    5c4fe716511d net/sched: netem: fix slot delay calculation overflow
    3a3698b96688 net/sched: netem: validate slot configuration
    116f10027e61 net/sched: netem: only reseed PRNG when seed is explicitly provided
    39a66e83ea41 net/sched: netem: fix queue limit check to include reordered packets
    d2a74e0ea346 net/sched: netem: fix probability gaps in 4-state loss model
    818f7673ed7f netdevsim: zero initialize struct iphdr in dummy sk_buff
    47421f8401fc cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro()
    ea6e650b079e arm64/scs: Fix potential sign extension issue of advance_loc4
    b933de804c84 drm/sysfb: ofdrm: fix PCI device reference leaks
    8524b1c04adc spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ
    ea2ecd29b8f4 netfilter: nf_conntrack_sip: don't use simple_strtoul
    82664d0f1ba2 netfilter: xt_policy: fix strict mode inbound policy matching
    f60bc289c555 drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2)
    da602e831334 drm/amdgpu/uvd3.1: Don't validate the firmware when already validated
    03011db69f5e drm/amdgpu: fix spelling typos
    8c4254c8f583 drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
    1b8595d126ea nvme-pci: fix missed admin queue sq doorbell write
    ad9973df8e0e netfilter: arp_tables: fix IEEE1394 ARP payload parsing
    d7c8f95f599b nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
    cbf460bf9492 tracing: branch: Fix inverted check on stat tracer registration
    f8f643d5ebef btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent()
    03d3739a830e mailbox: mailbox-test: make data_ready a per-instance variable
    75a365c69bb7 mailbox: mailbox-test: initialize struct earlier
    3afca89fae50 mailbox: mailbox-test: don't free the reused channel
    14aed0d4e583 mailbox: add sanity check for channel array
    0a0ac6cd2e46 cgroup/rdma: fix integer overflow in rdmacg_try_charge()
    81c9e7e4030e mailbox: mailbox-test: free channels on probe error
    0d2edd20b61b fbdev: offb: fix PCI device reference leak on probe failure
    86094f62ba21 rtc: abx80x: Disable alarm feature if no interrupt attached
    a11372a8b1ce fs/adfs: validate nzones in adfs_validate_bblk()
    0897ccf6e930 vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll()
    0274f24485fc tipc: fix double-free in tipc_buf_append()
    0ace0ce02911 nfp: fix swapped arguments in nfp_encode_basic_qdr() calls
    6bedc3ff4ba4 net: dsa: realtek: rtl8365mb: fix mode mask calculation
    d394093ed06e net/sched: sch_sfb: annotate data-races in sfb_dump_stats()
    86a6243d8654 net/sched: sch_red: annotate data-races in red_dump_stats()
    717bec018ce1 net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats()
    7bdb2b038c35 net/sched: sch_pie: annotate data-races in pie_dump_stats()
    046b2d8c9606 net_sched: sch_hhf: annotate data-races in hhf_dump_stats()
    b6ba93a7b71e net/rds: zero per-item info buffer before handing it to visitors
    1ff46c9915c1 ksmbd: scope conn->binding slowpath to bound sessions only
    407b6e699ba8 ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
    27fca12b9c2c ksmbd: destroy async_ida in ksmbd_conn_free()
    8a3cd890fd2a ksmbd: add support for supplementary groups
    234681c54581 ksmbd: Use struct_size() to improve smb_direct_rdma_xmit()
    1f3235364037 ksmbd: destroy tree_conn_ida in ksmbd_session_destroy()
    8db8727ea8d1 arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number
    37537e42e6df slip: bound decode() reads against the compressed packet length
    c6980e8b1a86 slip: reject VJ receive packets on instances with no rstate array
    5d05de2f0928 netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
    32e50f92c7cf netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
    5241a3ab2c77 ipvs: fix MTU check for GSO packets in tunnel mode
    cbeb259f3138 netfilter: xtables: restrict several matches to inet family
    1c9fb8aeed06 netfilter: conntrack: remove sprintf usage
    8def8fbd23f4 netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
    554cc061ca13 netfilter: nft_osf: restrict it to ipv4
    f9ef3db77a38 openvswitch: cap upcall PID array size and pre-size vport replies
    8a5e840babc5 pppoe: drop PFC frames
    d67fbc6dea5d sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
    0069813e6ca9 ipv6: fix possible UAF in icmpv6_rcv()
    733a1b310297 e1000e: Unroll PTP in probe error handling
    8a254c6db3ee i40e: don't advertise IFF_SUPP_NOFCS
    ca6f9d9aee54 ice: fix double-free of tx_buf skb
    a753619ffecf ice: Remove jumbo_remove step from TX path
    982a56c888d3 tcp: annotate data-races around tp->plb_rehash
    993847e92765 tcp: annotate data-races around (tp->write_seq - tp->snd_nxt)
    a445beb84c83 tcp: annotate data-races around tp->dsack_dups
    60db862ea01e tcp: annotate data-races around tp->bytes_retrans
    3e1b40e4f186 tcp: annotate data-races around tp->bytes_sent
    409a02760834 tcp: add data-race annotations around tp->data_segs_out and tp->total_retrans
    eee072fe16c6 net/sched: taprio: fix use-after-free in advance_sched() on schedule switch
    aaac3bed0342 nexthop: fix IPv6 route referencing IPv4 nexthop
    616db97e3aff net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys
    497925275838 macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
    f250c3772dd7 arm64: dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT
    0fa0bcdebeb0 arm64: dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT
    3098c905af2f arm64: dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT
    6d9f35fe4638 PCMCIA: Fix garbled log messages for KERN_CONT
    ca962d175543 arm64: dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT
    7adb32513191 arm64: dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT
    640aea541eba arm64: dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT
    1f285713fb8d arm64: dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT
    827ccceff758 arm64: dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT
    eecee15e263c crypto: ccp - copy IV using skcipher ivsize
    f19a744d5271 crypto: sa2ul - Fix AEAD fallback algorithm names
    424df78c8a64 drm/i915/wm: Verify the correct plane DDB entry
    ed5ca5d5b97c drm/i915: Loop over all active pipes in intel_mbus_dbox_update
    c2577b18c6e2 drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update()
    c5de9ff7939b drm/i915: Simplify watermark state checker calling convention
    73abb7c1fffd drm/i915: Constify watermark state checker
    cea15f66b7b6 f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
    756d1a3954fe f2fs: Use sysfs_emit_at() to simplify code
    21fe517179f3 clk: visconti: pll: initialize clk_init_data to zero
    caa74d80d749 lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug()
    db62a24a07b3 clk: qcom: dispcc-sc7180: Add missing MDSS resets
    5db0537ddef4 dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets
    166db4ebae34 clk: xgene: Fix mapping leak in xgene_pllclk_init()
    bf94322387ab clk: qoriq: avoid format string warning
    4ba394f83b3c clk: imx8mq: Correct the CSI PHY sels
    a778bbd3ab28 clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels()
    0d2ba7e2e4c6 clk: imx: imx6q: Fix device node reference leak in pll6_bypassed()
    235c36a86cb7 clk: qcom: dispcc-sm8250: Enable parents for pixel clocks
    081d334fe42d clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk
    d18b05a09142 clk: qcom: gcc-sc8180x: Use retention for PCIe power domains
    9b54ebbe5d2f clk: qcom: gcc-sc8180x: Use retention for USB power domains
    a4cee425ae6b clk: qcom: gcc-sc8180x: Add missing GDSCs
    9109efceb709 dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs
    d7aef29573c7 scsi: target: core: Fix integer overflow in UNMAP bounds check
    b6007cfea4ed clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers
    c5f4a211e82d scsi: sg: Resolve soft lockup issue when opening /dev/sgX
    d85a906b4e51 scsi: sg: Fix sysctl sg-big-buff register during sg_init()
    f9c921fd5264 scsi: sg: Make sg_sysfs_class constant
    fa4e1c583c9d clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source
    137b5918931d RDMA/core: Prefer NLA_NUL_STRING
    ba0843c19558 platform/x86: dell-wmi-sysman: bound enumeration string aggregation
    622754397ac5 platform/x86: dell_rbu: avoid uninit value usage in packet_size_write()
    0b11fcbe80a5 fs/ntfs3: terminate the cached volume label after UTF-8 conversion
    a7fd0d0cb43f nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist()
    ccfa51ea8a40 mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata()
    3d0e610c43cb platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup
    fed8b8f33a46 tty: hvc_iucv: fix off-by-one in number of supported devices
    61599d438e2d leds: lgm-sso: Remove duplicate assignments for priv->mmap
    bc7998e70fa7 platform/surface: surfacepro3_button: Drop wakeup source on remove
    e87c4c0095ac backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt()
    c5be52529ad8 dev_printk: add new dev_err_probe() helpers
    10bb319b0b18 i3c: mipi-i3c-hci: fix IBI payload length calculation for final status
    54dc499e5cb3 perf util: Kill die() prototype, dead for a long time
    2f3548314715 ipmi: ssif_bmc: change log level to dbg in irq callback
    bffedb7a72e6 ipmi: ssif_bmc: fix message desynchronization after truncated response
    7d2a487c275c ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure
    128845823138 perf expr: Return -EINVAL for syntax error in expr__find_ids()
    ea0078135c6a perf lock: Fix option value type in parse_max_stack
    9bab7d2a2850 pinctrl: abx500: Fix type of 'argument' variable
    92170bd2eadd perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace
    aceabce300c3 perf branch: Avoid incrementing NULL
    8fe5240c7bd8 pinctrl: cy8c95x0: Avoid returning positive values to user space
    03e71cc07cba pinctrl: cy8c95x0: Unify messages with help of dev_err_probe()
    091709439f88 pinctrl: cy8c95x0: remove duplicate error message
    a79fdd593c84 pinctrl: pinctrl-pic32: Fix resource leak
    d216b34a9f69 bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT
    699e16e65962 bpf: allow UTF-8 literals in bpf_bprintf_prepare()
    520454e83971 bpf: Fix NULL deref in map_kptr_match_type for scalar regs
    2f954f8a04b7 bpf: Fix precedence bug in convert_bpf_ld_abs alignment check
    d0d124dbcef9 bpf, sockmap: Take state lock for af_unix iter
    a94d3dd78ee8 bpf, sockmap: Fix af_unix null-ptr-deref in proto update
    3cef33b9813b bpf, sockmap: Fix af_unix iter deadlock
    7fd3b41260c6 bpf, arm64: Fix off-by-one in check_imm signed range check
    ad4505d2ab3a HID: usbhid: fix deadlock in hid_post_reset()
    5897c1dd1bfe mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob
    295757c3b9de mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions
    560c0456e613 mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path
    cca2c083cfcb mtd: spi-nor: swp: check SR_TB flag when getting tb_mask
    b194ae62e9e7 mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation
    301e85ff299b mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook
    2e472d2bdc14 mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook
    036a794e7d7f mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations
    fab6b870dfe6 dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range
    ba91de4f0f98 mtd: physmap_of_gemini: Fix disabled pinctrl state check
    033939479b10 HID: asus: do not abort probe when not necessary
    08c4fa3f5a9b HID: asus: make asus_resume adhere to linux kernel coding standards
    5dcb51558e78 ima: check return value of crypto_shash_final() in boot aggregate
    9399a9298935 tracing: Rebuild full_name on each hist_field_name() call
    c258fbf57113 soundwire: cadence: Clear message complete before signaling waiting thread
    0b73d5dfa3fe dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register()
    5acbbb205a1c soundwire: bus: demote UNATTACHED state warnings to dev_dbg()
    faa66f358d30 dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function
    b9ae3942deec ocfs2: validate group add input before caching
    bb3c54d1e715 ocfs2: validate bg_bits during freefrag scan
    d919b905939e ocfs2: fix listxattr handling when the buffer is full
    f1e38ba97b1a ARM: dts: imx27-eukrea: replace interrupts with interrupts-extended
    064494145a70 arm64/xor: fix conflicting attributes for xor_block_template
    08c073e8f8d5 ARM: OMAP1: Fix DEBUG_LL and earlyprintk on OMAP16XX
    96a30f7cb8e0 arm64: dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP
    ccff9145cd52 soc: qcom: aoss: compare against normalized cooling state
    d672c7623306 soc: qcom: llcc: fix v1 SB syndrome register offset
    819d8ebad320 ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
    f37de46149db ocfs2/dlm: validate qr_numregions in dlm_match_regions()
    813a47b03090 unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure
    39a8c0df2d5a soc/tegra: cbb: Set ERD on resume for err interrupt
    b87992ddf49a arm64: dts: imx8qxp-mek: switch Type-C connector power-role to dual
    7d6481cf2987 arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot
    03d523e50662 arm64: dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl
    a37e61cde05a arm64: dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes
    7ce6aa2eca26 arm64: dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes
    1563a05cf920 arm64: dts: qcom: sm8550: Fix xo clock supply of platform SD host controller
    4322d8c7af96 arm64: dts: qcom: sm8550: Fix GIC_ITS range length
    97bacd872319 arm64: dts: qcom: sm8450: Fix GIC_ITS range length
    1e014285a3cd soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available
    9f54516bce15 soc: qcom: ocmem: register reasons for probe deferrals
    d45c46c0e84f soc: qcom: ocmem: use scoped device node handling to simplify error paths
    1637ce361b1d soc: qcom: ocmem: make the core clock optional
    2ecad03d6c5d arm64: dts: qcom: msm8953-xiaomi-daisy: fix backlight
    5a0dcba6178f arm64: dts: qcom: msm8953-xiaomi-vince: correct wled ovp value
    5b94fe0879bc arm64: dts: mediatek: mt7986a: Fix gpio-ranges pin count
    167e5fa8feee arm64: dts: mediatek: mt6795: Fix gpio-ranges pin count
    fe1d1423c524 iommufd: vfio compatibility extension check for noiommu mode
    700e54a2beba arm64: dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1)
    036f599234e4 arm64: dts: imx8-apalis: Fix LEDs name collision
    cecc17692ebf memory: tegra30-emc: Fix dll_change check
    7e19e72f3064 memory: tegra124-emc: Fix dll_change check
    c13c938a8058 ARM: dts: mediatek: mt7623: fix efuse fallback compatible
    8fcefe840fa8 ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
    8be69e9245f8 efi/capsule-loader: fix incorrect sizeof in phys array reallocation
    233a0945a4b1 gfs2: prevent NULL pointer dereference during unmount
    bf5fcd9c37c2 gfs2: add some missing log locking
    6678dde26570 quota: Fix race of dquot_scan_active() with quota deactivation
    f57b68b36571 ktest: Run POST_KTEST hooks on failure and cancellation
    aa6b9e38086c ktest: Honor empty per-test option overrides
    5bddd0d3a926 ktest: Avoid undef warning when WARNINGS_FILE is unset
    232d67974a61 gfs2: Call unlock_new_inode before d_instantiate
    18216b8ab690 crypto: jitterentropy - replace long-held spinlock with mutex
    f57498d2bf16 dm cache: fix missing return in invalidate_committed's error path
    3a77b05ff2c4 ALSA: sc6000: Keep the programmed board state in card-private data
    dcbc2e2b2434 ALSA: sc6000: Use standard print API
    3e79a563377a spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback
    fa7881f3b627 PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well
    bf98711d2f33 PCI: tegra194: Use DWC IP core version
    5d9c9dfef907 PCI: tegra194: Allow system suspend when the Endpoint link is not up
    2c87f49f2082 PCI: tegra194: Disable direct speed change for Endpoint mode
    272e9c4bcae8 PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select"
    997122b96544 PCI: tegra194: Disable PERST# IRQ only in Endpoint mode
    39564f51567e PCI: tegra194: Don't force the device into the D0 state before L2
    e81f33968542 PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0()
    fdb9c5a3a627 PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down
    8aa59b1e53a7 PCI: tegra194: Increase LTSSM poll time on surprise link down
    8f26b92dc606 PCI: tegra194: Fix polling delay for L2 state
    9e225563c5a9 ASoC: SOF: compress: return the configured codec from get_params
    2721d23db2e9 ALSA: scarlett2: Add missing sentinel initializer field
    7e805fdb16dc selftest: memcg: skip memcg_sock test if address family not supported
    05a3fd57cdfa Documentation: fix a hugetlbfs reservation statement
    11a810989a4d selftests/mm: skip migration tests if NUMA is unavailable
    07a5ecb94768 PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found
    0afb2eca25be PCI: Enable AtomicOps only if Root Port supports them
    9f1daac27ca2 ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]
    5f1035ba3ed9 crypto: qat - use swab32 macro
    1ac96689ce29 ASoC: qcom: qdsp6: topology: check widget type before accessing data
    d39e8c3724a6 ASoC: fsl_easrc: Change the type for iec958 channel status controls
    4d427d3f507a ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits()
    a2e9527bc88e ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits()
    4428887805ef ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put()
    0dddb5642d64 ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put()
    ceb388682ea1 ASoC: fsl_micfil: Fix event generation in micfil_quality_set()
    4605327fd688 ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state()
    a6bc5432055b ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode()
    62c4ab11840d ASoC: fsl_micfil: Fix event generation in hwvad_put_enable()
    6adc82ff2f20 ASoC: fsl_micfil: Add access property for "VAD Detected"
    4ba05463862c pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe()
    3a73abb39037 pmdomain: ti: omap_prm: Fix a reference leak on device node
    bad87bdd52f5 drm/msm/a6xx: Use barriers while updating HFI Q headers
    98fce340ec48 drm/msm/shrinker: Fix can_block() logic
    679a533d2235 drm/msm/a6xx: Fix HLSQ register dumping
    f101e4ebf1fc ASoC: SOF: Intel: hda: Place check before dereference
    2958b391d9c5 ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}')
    ad08dd4476eb drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board
    ef1c7aaa1319 drm/amd/pm/ci: Fill DW8 fields from SMC
    9e6d83f651ac drm/amd/pm/ci: Clear EnabledForActivity field for memory levels
    4cf77e3298e4 drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0
    37f93b3159fa drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock
    cc88a98c873b drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs
    33da7d5b6a50 drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled
    9a7f12105f0e ALSA: core: Validate compress device numbers without dynamic minors
    0558d1b0b5f0 drm/panel: simple: Correct G190EAN01 prepare timing
    c4fc7ed73a0a drm/panel: sharp-ls043t1le01: make use of prepare_prev_first
    97d360a0112e drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0
    af6825d3e446 drm/msm/dsi: add the missing parameter description
    9830999c9e06 drm/msm/dpu: fix mismatch between power and frequency
    94d99e853617 spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo
    8ebaa3deb04f drm/amdgpu/gfx10: look at the right prop for gfx queue priority
    a6d44f477000 padata: Put CPU offline callback in ONLINE section to allow failure
    0e664e99abb4 padata: Remove cpu online check from cpu add and removal
    39024f54f098 crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs
    59fce560694d crypto: atmel - Use unregister_{aeads,ahashes,skciphers}
    60c571a7d8d0 crypto: atmel - Remove cfb and ofb
    3cd5cae11afa fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break
    6f866e941a7e dm init: ensure device probing has finished in dm-mod.waitfor=
    5af3d8f2acb6 drm/amdgpu: Add default case in DVI mode validation
    ef0d045ebbaf drm/sun4i: Fix resource leaks
    6040b24095a8 spi: fsl-qspi: Use reinit_completion() for repeated operations
    dc97ec849559 drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check
    b01a582c8c6f drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs
    5302015daf26 drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()
    d4ac87567f86 dm log: fix out-of-bounds write due to region_count overflow
    15c30997dca6 dm cache metadata: fix memory leak on metadata abort retry
    2ebe1ab83292 platform/chrome: chromeos_tbmc: Drop wakeup source on remove
    12105c7f1837 dm cache: fix dirty mapping checking in passthrough mode switching
    89e04987574a dm cache: support shrinking the origin device
    d90accff225f dm cache: fix concurrent write failure in passthrough mode
    ac5ee9944389 dm cache policy smq: fix missing locks in invalidating cache blocks
    ecb10c193cbe dm cache: fix write hang in passthrough mode
    ceff6df26691 dm cache: fix write path cache coherency in passthrough mode
    0aa745fea1f8 dm cache: fix null-deref with concurrent writes in passthrough mode
    002a5f925d42 ASoC: sti: use managed regmap_field allocations
    686a6b305ec8 ASoC: sti: Return errors from regmap_field_alloc()
    cf615b90a11a drm/sun4i: backend: fix error pointer dereference
    d8a541906860 drm/komeda: fix integer overflow in AFBC framebuffer size check
    866d3d9b8775 net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master
    1943e71a0d6a sctp: fix missing encap_port propagation for GSO fragments
    cc4dead22ede net: phy: qcom: at803x: Use the correct bit to disable extended next page
    22f22f1346b4 net: phy: move at803x PHY driver to dedicated directory
    e30356c3cf2f net: phy: add Rust Asix PHY driver
    014860036d1f net: phy: aquantia: move to separate directory
    77a853aec710 Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
    6b4d226d01ab Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
    a673cf6c4ac7 Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
    315acf971d75 Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU
    0a04db240eff bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
    61a9b216ca5b net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic()
    02c1256f1990 net/mlx5e: Fix features not applied during netdev registration
    4f1ca61e5311 dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110
    b3682e7ad450 net: ipa: Fix decoding EV_PER_EE for IPA v5.0+
    f7361841d0ce net: ipa: Fix programming of QTIME_TIMESTAMP_CFG
    954745d0223e ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
    e19c5ed9f192 bpf: Fix OOB in pcpu_init_value
    07035306bf72 net/rds: Restrict use of RDS/IB to the initial network namespace
    2c7883d606aa net/rds: Optimize rds_ib_laddr_check
    f23424a0ddad net/sched: act_ct: Only release RCU read lock after ct_ft
    e9cf4018d742 net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
    f4ed5d750b4a 6pack: propagage new tty types
    b1f7158a86f3 bpf: Fix RCU stall in bpf_fd_array_map_clear()
    8849b50e81a2 netfilter: nft_fwd_netdev: check ttl/hl before forwarding
    9ca570236cc0 netfilter: xt_socket: enable defrag after all other checks
    e8206538cbaf net: bcmgenet: fix racing timeout handler
    1b0865a6efce net: bcmgenet: switch to use 64bit statistics
    991cd78f95f2 net: bcmgenet: support reclaiming unsent Tx packets
    355b61569e84 net: bcmgenet: move DESC_INDEX flow to ring 0
    df3a1bb0ae1a net: bcmgenet: add bcmgenet_has_* helpers
    d650d12d58ef net: bcmgenet: Remove custom ndo_poll_controller()
    2a7459017042 net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
    03d97b558d80 arm64: kexec: Remove duplicate allocation for trans_pgd
    0e72fd7f05ae ACPI: AGDI: fix missing newline in error message
    3ff85ae79e1a bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
    26b380a3ca0b bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks
    d3f280be48f1 wifi: brcmfmac: Fix error pointer dereference
    a713b72ff88c bpf: Fix stale offload->prog pointer after constant blinding
    b4b5a20bed82 bpf: fix end-of-list detection in cgroup_storage_get_next_key()
    1aa61a6f42ad macvlan: annotate data-races around port->bc_queue_len_used
    0adec27bde44 selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
    81bc3a2ccc37 selftests/powerpc: Re-order *FLAGS to follow lib.mk
    7ca35863213c powerpc/crash: fix backup region offset update to elfcorehdr
    6e474972b85e r8152: fix incorrect register write to USB_UPHY_XTAL
    ea04b9881534 wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap()
    571a05ea1baa bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
    eefe0c2ea2c3 bpf, devmap: Remove unnecessary if check in for loop
    6d5202409467 wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
    66f2a0becd35 wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event
    6cf44608d5e6 arm64: cpufeature: Make PMUVer and PerfMon unsigned
    63fe66f10283 wifi: mt76: mt7996: fix FCS error flag check in RX descriptor
    4dd75a78cdfb wifi: mt76: mt7915: fix use_cts_prot support
    382cbdf6e484 wifi: mt76: mt7615: fix use_cts_prot support
    c8e46d0664c4 wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr()
    231b895daa02 module: Fix freeing of charp module parameters when CONFIG_SYSFS=n
    e6962cb18a89 params: Replace __modinit with __init_or_module
    edc90a12073b s390/bpf: Zero-extend bpf prog return values and kfunc arguments
    e70b9c2292cc dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n
    6e8d309bc69b dpaa2: add independent dependencies for FSL_DPAA2_SWITCH
    c7ad31fb948f bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
    5d81743ee3cc bpf: Add CHECKSUM_COMPLETE to bpf test progs
    008c456b76e9 wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
    255cc1d30f32 wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt()
    a5af71c6181e firmware: dmi: Correct an indexing error in dmi.h
    240f832a9c20 locking: Fix rwlock support in <linux/spinlock_up.h>
    ca2d280b9b38 hrtimer: Reduce trace noise in hrtimer_start()
    ece8be21d8c9 hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns()
    16774f7333fc hrtimers: Update the return type of enqueue_hrtimer()
    b54f14e1460c irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter
    c4295487124f s390/cio: use generic driver_override infrastructure
    9d606425a752 s390/cio: convert sprintf()/snprintf() to sysfs_emit()
    3d0cfecf4ff7 s390/cio: make sch->lock spinlock pointer a member
    6325eea40a95 debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str()
    f9c489418b8e debugfs: check for NULL pointer in debugfs_create_str()
    fc6ecb4b8ef9 thermal/drivers/spear: Fix error condition for reading st,thermal-flags
    f75ea8cdca54 devres: fix missing node debug info in devm_krealloc()
    d172f1c8a8b3 ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver
    9a6f4d85a016 ACPI: x86: cmos_rtc: Clean up address space handler driver
    da8255040938 pstore/ram: fix resource leak when ioremap() fails
    4048ed98860d blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
    b88f905d4449 nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
    5dd9d864eb96 loop: fix partition scan race between udev and loop_reread_partitions()
    282e06e6d494 drbd: Balance RCU calls in drbd_adm_dump_devices()
    131ea3e57fc2 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
    467289e0d0f2 blk-cgroup: wait for blkcg cleanup before initializing new disk

(From OE-Core rev: 050911a7705f3bb17d30034f3f16372b2e79b85d)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-06-26 16:55:55 +01:00