======================================= Sat, 12 Sep 2026 - Debian 13.7 released ======================================= ========================================================================= [Date: Sat, 12 Sep 2026 07:25:31 -0000] [ftpmaster: Archive Administrator] Removed the following packages from trixie: ata-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf ata-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el ata-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 ata-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf ata-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el ata-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 ata-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf ata-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el ata-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 ata-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf ata-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el ata-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 ata-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf ata-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el ata-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 ata-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf ata-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el ata-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 btrfs-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf btrfs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el btrfs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 btrfs-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x btrfs-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf btrfs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el btrfs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 btrfs-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x btrfs-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf btrfs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el btrfs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 btrfs-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x btrfs-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf btrfs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el btrfs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 btrfs-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x btrfs-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf btrfs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el btrfs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 btrfs-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x btrfs-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf btrfs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el btrfs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 btrfs-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x cdrom-core-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf cdrom-core-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el cdrom-core-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 cdrom-core-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x cdrom-core-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf cdrom-core-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el cdrom-core-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 cdrom-core-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x cdrom-core-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf cdrom-core-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el cdrom-core-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 cdrom-core-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x cdrom-core-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf cdrom-core-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el cdrom-core-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 cdrom-core-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x cdrom-core-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf cdrom-core-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el cdrom-core-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 cdrom-core-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x cdrom-core-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf cdrom-core-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el cdrom-core-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 cdrom-core-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x crypto-dm-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf crypto-dm-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el crypto-dm-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 crypto-dm-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x crypto-dm-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf crypto-dm-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el crypto-dm-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 crypto-dm-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x crypto-dm-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf crypto-dm-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el crypto-dm-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 crypto-dm-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x crypto-dm-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf crypto-dm-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el crypto-dm-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 crypto-dm-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x crypto-dm-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf crypto-dm-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el crypto-dm-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 crypto-dm-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x crypto-dm-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf crypto-dm-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el crypto-dm-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 crypto-dm-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x crypto-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf crypto-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el crypto-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 crypto-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x crypto-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf crypto-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el crypto-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 crypto-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x crypto-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf crypto-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el crypto-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 crypto-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x crypto-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf crypto-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el crypto-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 crypto-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x crypto-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf crypto-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el crypto-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 crypto-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x crypto-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf crypto-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el crypto-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 crypto-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x dasd-extra-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x dasd-extra-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x dasd-extra-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x dasd-extra-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x dasd-extra-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x dasd-extra-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x dasd-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x dasd-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x dasd-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x dasd-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x dasd-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x dasd-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x drm-core-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf drm-core-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el drm-core-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 drm-core-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf drm-core-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el drm-core-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 drm-core-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf drm-core-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el drm-core-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 drm-core-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf drm-core-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el drm-core-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 drm-core-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf drm-core-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el drm-core-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 drm-core-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf drm-core-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el drm-core-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 ext4-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf ext4-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el ext4-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 ext4-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x ext4-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf ext4-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el ext4-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 ext4-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x ext4-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf ext4-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el ext4-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 ext4-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x ext4-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf ext4-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el ext4-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 ext4-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x ext4-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf ext4-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el ext4-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 ext4-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x ext4-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf ext4-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el ext4-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 ext4-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x f2fs-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf f2fs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el f2fs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 f2fs-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x f2fs-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf f2fs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el f2fs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 f2fs-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x f2fs-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf f2fs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el f2fs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 f2fs-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x f2fs-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf f2fs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el f2fs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 f2fs-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x f2fs-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf f2fs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el f2fs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 f2fs-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x f2fs-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf f2fs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el f2fs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 f2fs-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x fat-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf fat-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el fat-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 fat-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x fat-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf fat-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el fat-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 fat-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x fat-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf fat-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el fat-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 fat-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x fat-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf fat-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el fat-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 fat-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x fat-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf fat-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el fat-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 fat-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x fat-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf fat-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el fat-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 fat-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x fb-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf fb-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el fb-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 fb-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf fb-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el fb-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 fb-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf fb-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el fb-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 fb-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf fb-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el fb-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 fb-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf fb-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el fb-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 fb-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf fb-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el fb-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 firewire-core-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el firewire-core-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el firewire-core-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el firewire-core-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el firewire-core-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el firewire-core-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el hypervisor-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el hypervisor-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el hypervisor-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el hypervisor-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el hypervisor-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el hypervisor-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el input-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf input-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el input-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 input-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf input-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el input-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 input-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf input-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el input-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 input-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf input-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el input-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 input-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf input-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el input-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 input-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf input-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el input-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 isofs-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf isofs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el isofs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 isofs-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x isofs-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf isofs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el isofs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 isofs-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x isofs-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf isofs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el isofs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 isofs-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x isofs-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf isofs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el isofs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 isofs-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x isofs-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf isofs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el isofs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 isofs-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x isofs-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf isofs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el isofs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 isofs-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x jfs-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf jfs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el jfs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 jfs-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf jfs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el jfs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 jfs-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf jfs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el jfs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 jfs-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf jfs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el jfs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 jfs-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf jfs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el jfs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 jfs-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf jfs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el jfs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 kernel-image-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf kernel-image-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el kernel-image-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 kernel-image-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x kernel-image-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf kernel-image-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el kernel-image-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 kernel-image-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x kernel-image-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf kernel-image-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el kernel-image-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 kernel-image-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x kernel-image-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf kernel-image-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el kernel-image-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 kernel-image-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x kernel-image-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf kernel-image-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el kernel-image-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 kernel-image-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x kernel-image-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf kernel-image-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el kernel-image-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 kernel-image-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x linux | 6.12.86-1 | source linux | 6.12.95-1 | source linux | 6.12.96-1 | source linux | 6.12.100-1 | source linux | 6.12.101-1 | source linux | 6.12.105-1 | source linux-doc | 6.12.86-1 | all linux-doc | 6.12.95-1 | all linux-doc | 6.12.96-1 | all linux-doc | 6.12.100-1 | all linux-doc | 6.12.101-1 | all linux-doc | 6.12.105-1 | all linux-doc-6.12 | 6.12.86-1 | all linux-doc-6.12 | 6.12.95-1 | all linux-doc-6.12 | 6.12.96-1 | all linux-doc-6.12 | 6.12.100-1 | all linux-doc-6.12 | 6.12.101-1 | all linux-doc-6.12 | 6.12.105-1 | all linux-headers-6.12.100+deb13-amd64 | 6.12.100-1 | amd64 linux-headers-6.12.100+deb13-arm64 | 6.12.100-1 | arm64 linux-headers-6.12.100+deb13-arm64-16k | 6.12.100-1 | arm64 linux-headers-6.12.100+deb13-armmp | 6.12.100-1 | armhf linux-headers-6.12.100+deb13-armmp-lpae | 6.12.100-1 | armhf linux-headers-6.12.100+deb13-cloud-amd64 | 6.12.100-1 | amd64 linux-headers-6.12.100+deb13-cloud-arm64 | 6.12.100-1 | arm64 linux-headers-6.12.100+deb13-common | 6.12.100-1 | all linux-headers-6.12.100+deb13-common-rt | 6.12.100-1 | all linux-headers-6.12.100+deb13-powerpc64le | 6.12.100-1 | ppc64el linux-headers-6.12.100+deb13-powerpc64le-64k | 6.12.100-1 | ppc64el linux-headers-6.12.100+deb13-riscv64 | 6.12.100-1 | riscv64 linux-headers-6.12.100+deb13-rpi | 6.12.100-1 | armel linux-headers-6.12.100+deb13-rt-amd64 | 6.12.100-1 | amd64 linux-headers-6.12.100+deb13-rt-arm64 | 6.12.100-1 | arm64 linux-headers-6.12.100+deb13-rt-armmp | 6.12.100-1 | armhf linux-headers-6.12.100+deb13-s390x | 6.12.100-1 | s390x linux-headers-6.12.101+deb13-amd64 | 6.12.101-1 | amd64 linux-headers-6.12.101+deb13-arm64 | 6.12.101-1 | arm64 linux-headers-6.12.101+deb13-arm64-16k | 6.12.101-1 | arm64 linux-headers-6.12.101+deb13-armmp | 6.12.101-1 | armhf linux-headers-6.12.101+deb13-armmp-lpae | 6.12.101-1 | armhf linux-headers-6.12.101+deb13-cloud-amd64 | 6.12.101-1 | amd64 linux-headers-6.12.101+deb13-cloud-arm64 | 6.12.101-1 | arm64 linux-headers-6.12.101+deb13-common | 6.12.101-1 | all linux-headers-6.12.101+deb13-common-rt | 6.12.101-1 | all linux-headers-6.12.101+deb13-powerpc64le | 6.12.101-1 | ppc64el linux-headers-6.12.101+deb13-powerpc64le-64k | 6.12.101-1 | ppc64el linux-headers-6.12.101+deb13-riscv64 | 6.12.101-1 | riscv64 linux-headers-6.12.101+deb13-rpi | 6.12.101-1 | armel linux-headers-6.12.101+deb13-rt-amd64 | 6.12.101-1 | amd64 linux-headers-6.12.101+deb13-rt-arm64 | 6.12.101-1 | arm64 linux-headers-6.12.101+deb13-rt-armmp | 6.12.101-1 | armhf linux-headers-6.12.101+deb13-s390x | 6.12.101-1 | s390x linux-headers-6.12.105+deb13-amd64 | 6.12.105-1 | amd64 linux-headers-6.12.105+deb13-arm64 | 6.12.105-1 | arm64 linux-headers-6.12.105+deb13-arm64-16k | 6.12.105-1 | arm64 linux-headers-6.12.105+deb13-armmp | 6.12.105-1 | armhf linux-headers-6.12.105+deb13-armmp-lpae | 6.12.105-1 | armhf linux-headers-6.12.105+deb13-cloud-amd64 | 6.12.105-1 | amd64 linux-headers-6.12.105+deb13-cloud-arm64 | 6.12.105-1 | arm64 linux-headers-6.12.105+deb13-common | 6.12.105-1 | all linux-headers-6.12.105+deb13-common-rt | 6.12.105-1 | all linux-headers-6.12.105+deb13-powerpc64le | 6.12.105-1 | ppc64el linux-headers-6.12.105+deb13-powerpc64le-64k | 6.12.105-1 | ppc64el linux-headers-6.12.105+deb13-riscv64 | 6.12.105-1 | riscv64 linux-headers-6.12.105+deb13-rpi | 6.12.105-1 | armel linux-headers-6.12.105+deb13-rt-amd64 | 6.12.105-1 | amd64 linux-headers-6.12.105+deb13-rt-arm64 | 6.12.105-1 | arm64 linux-headers-6.12.105+deb13-rt-armmp | 6.12.105-1 | armhf linux-headers-6.12.105+deb13-s390x | 6.12.105-1 | s390x linux-headers-6.12.86+deb13-amd64 | 6.12.86-1 | amd64 linux-headers-6.12.86+deb13-arm64 | 6.12.86-1 | arm64 linux-headers-6.12.86+deb13-arm64-16k | 6.12.86-1 | arm64 linux-headers-6.12.86+deb13-armmp | 6.12.86-1 | armhf linux-headers-6.12.86+deb13-armmp-lpae | 6.12.86-1 | armhf linux-headers-6.12.86+deb13-cloud-amd64 | 6.12.86-1 | amd64 linux-headers-6.12.86+deb13-cloud-arm64 | 6.12.86-1 | arm64 linux-headers-6.12.86+deb13-common | 6.12.86-1 | all linux-headers-6.12.86+deb13-common-rt | 6.12.86-1 | all linux-headers-6.12.86+deb13-powerpc64le | 6.12.86-1 | ppc64el linux-headers-6.12.86+deb13-powerpc64le-64k | 6.12.86-1 | ppc64el linux-headers-6.12.86+deb13-riscv64 | 6.12.86-1 | riscv64 linux-headers-6.12.86+deb13-rpi | 6.12.86-1 | armel linux-headers-6.12.86+deb13-rt-amd64 | 6.12.86-1 | amd64 linux-headers-6.12.86+deb13-rt-arm64 | 6.12.86-1 | arm64 linux-headers-6.12.86+deb13-rt-armmp | 6.12.86-1 | armhf linux-headers-6.12.86+deb13-s390x | 6.12.86-1 | s390x linux-headers-6.12.95+deb13-amd64 | 6.12.95-1 | amd64 linux-headers-6.12.95+deb13-arm64 | 6.12.95-1 | arm64 linux-headers-6.12.95+deb13-arm64-16k | 6.12.95-1 | arm64 linux-headers-6.12.95+deb13-armmp | 6.12.95-1 | armhf linux-headers-6.12.95+deb13-armmp-lpae | 6.12.95-1 | armhf linux-headers-6.12.95+deb13-cloud-amd64 | 6.12.95-1 | amd64 linux-headers-6.12.95+deb13-cloud-arm64 | 6.12.95-1 | arm64 linux-headers-6.12.95+deb13-common | 6.12.95-1 | all linux-headers-6.12.95+deb13-common-rt | 6.12.95-1 | all linux-headers-6.12.95+deb13-powerpc64le | 6.12.95-1 | ppc64el linux-headers-6.12.95+deb13-powerpc64le-64k | 6.12.95-1 | ppc64el linux-headers-6.12.95+deb13-riscv64 | 6.12.95-1 | riscv64 linux-headers-6.12.95+deb13-rpi | 6.12.95-1 | armel linux-headers-6.12.95+deb13-rt-amd64 | 6.12.95-1 | amd64 linux-headers-6.12.95+deb13-rt-arm64 | 6.12.95-1 | arm64 linux-headers-6.12.95+deb13-rt-armmp | 6.12.95-1 | armhf linux-headers-6.12.95+deb13-s390x | 6.12.95-1 | s390x linux-headers-6.12.96+deb13-amd64 | 6.12.96-1 | amd64 linux-headers-6.12.96+deb13-arm64 | 6.12.96-1 | arm64 linux-headers-6.12.96+deb13-arm64-16k | 6.12.96-1 | arm64 linux-headers-6.12.96+deb13-armmp | 6.12.96-1 | armhf linux-headers-6.12.96+deb13-armmp-lpae | 6.12.96-1 | armhf linux-headers-6.12.96+deb13-cloud-amd64 | 6.12.96-1 | amd64 linux-headers-6.12.96+deb13-cloud-arm64 | 6.12.96-1 | arm64 linux-headers-6.12.96+deb13-common | 6.12.96-1 | all linux-headers-6.12.96+deb13-common-rt | 6.12.96-1 | all linux-headers-6.12.96+deb13-powerpc64le | 6.12.96-1 | ppc64el linux-headers-6.12.96+deb13-powerpc64le-64k | 6.12.96-1 | ppc64el linux-headers-6.12.96+deb13-riscv64 | 6.12.96-1 | riscv64 linux-headers-6.12.96+deb13-rpi | 6.12.96-1 | armel linux-headers-6.12.96+deb13-rt-amd64 | 6.12.96-1 | amd64 linux-headers-6.12.96+deb13-rt-arm64 | 6.12.96-1 | arm64 linux-headers-6.12.96+deb13-rt-armmp | 6.12.96-1 | armhf linux-headers-6.12.96+deb13-s390x | 6.12.96-1 | s390x linux-image-6.12.100+deb13-amd64-dbg | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-amd64-unsigned | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-arm64-16k-dbg | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-arm64-16k-unsigned | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-arm64-dbg | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-arm64-unsigned | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-armmp | 6.12.100-1 | armhf linux-image-6.12.100+deb13-armmp-dbg | 6.12.100-1 | armhf linux-image-6.12.100+deb13-armmp-lpae | 6.12.100-1 | armhf linux-image-6.12.100+deb13-armmp-lpae-dbg | 6.12.100-1 | armhf linux-image-6.12.100+deb13-cloud-amd64-dbg | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-cloud-amd64-unsigned | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-cloud-arm64-dbg | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-cloud-arm64-unsigned | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-powerpc64le | 6.12.100-1 | ppc64el linux-image-6.12.100+deb13-powerpc64le-64k | 6.12.100-1 | ppc64el linux-image-6.12.100+deb13-powerpc64le-64k-dbg | 6.12.100-1 | ppc64el linux-image-6.12.100+deb13-powerpc64le-dbg | 6.12.100-1 | ppc64el linux-image-6.12.100+deb13-riscv64 | 6.12.100-1 | riscv64 linux-image-6.12.100+deb13-riscv64-dbg | 6.12.100-1 | riscv64 linux-image-6.12.100+deb13-rpi | 6.12.100-1 | armel linux-image-6.12.100+deb13-rpi-dbg | 6.12.100-1 | armel linux-image-6.12.100+deb13-rt-amd64-dbg | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-rt-amd64-unsigned | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-rt-arm64-dbg | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-rt-arm64-unsigned | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-rt-armmp | 6.12.100-1 | armhf linux-image-6.12.100+deb13-rt-armmp-dbg | 6.12.100-1 | armhf linux-image-6.12.100+deb13-s390x | 6.12.100-1 | s390x linux-image-6.12.100+deb13-s390x-dbg | 6.12.100-1 | s390x linux-image-6.12.101+deb13-amd64-dbg | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-amd64-unsigned | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-arm64-16k-dbg | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-arm64-16k-unsigned | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-arm64-dbg | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-arm64-unsigned | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-armmp | 6.12.101-1 | armhf linux-image-6.12.101+deb13-armmp-dbg | 6.12.101-1 | armhf linux-image-6.12.101+deb13-armmp-lpae | 6.12.101-1 | armhf linux-image-6.12.101+deb13-armmp-lpae-dbg | 6.12.101-1 | armhf linux-image-6.12.101+deb13-cloud-amd64-dbg | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-cloud-amd64-unsigned | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-cloud-arm64-dbg | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-cloud-arm64-unsigned | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-powerpc64le | 6.12.101-1 | ppc64el linux-image-6.12.101+deb13-powerpc64le-64k | 6.12.101-1 | ppc64el linux-image-6.12.101+deb13-powerpc64le-64k-dbg | 6.12.101-1 | ppc64el linux-image-6.12.101+deb13-powerpc64le-dbg | 6.12.101-1 | ppc64el linux-image-6.12.101+deb13-riscv64 | 6.12.101-1 | riscv64 linux-image-6.12.101+deb13-riscv64-dbg | 6.12.101-1 | riscv64 linux-image-6.12.101+deb13-rpi | 6.12.101-1 | armel linux-image-6.12.101+deb13-rpi-dbg | 6.12.101-1 | armel linux-image-6.12.101+deb13-rt-amd64-dbg | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-rt-amd64-unsigned | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-rt-arm64-dbg | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-rt-arm64-unsigned | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-rt-armmp | 6.12.101-1 | armhf linux-image-6.12.101+deb13-rt-armmp-dbg | 6.12.101-1 | armhf linux-image-6.12.101+deb13-s390x | 6.12.101-1 | s390x linux-image-6.12.101+deb13-s390x-dbg | 6.12.101-1 | s390x linux-image-6.12.105+deb13-amd64-dbg | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-amd64-unsigned | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-arm64-16k-dbg | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-arm64-16k-unsigned | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-arm64-dbg | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-arm64-unsigned | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-armmp | 6.12.105-1 | armhf linux-image-6.12.105+deb13-armmp-dbg | 6.12.105-1 | armhf linux-image-6.12.105+deb13-armmp-lpae | 6.12.105-1 | armhf linux-image-6.12.105+deb13-armmp-lpae-dbg | 6.12.105-1 | armhf linux-image-6.12.105+deb13-cloud-amd64-dbg | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-cloud-amd64-unsigned | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-cloud-arm64-dbg | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-cloud-arm64-unsigned | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-powerpc64le | 6.12.105-1 | ppc64el linux-image-6.12.105+deb13-powerpc64le-64k | 6.12.105-1 | ppc64el linux-image-6.12.105+deb13-powerpc64le-64k-dbg | 6.12.105-1 | ppc64el linux-image-6.12.105+deb13-powerpc64le-dbg | 6.12.105-1 | ppc64el linux-image-6.12.105+deb13-riscv64 | 6.12.105-1 | riscv64 linux-image-6.12.105+deb13-riscv64-dbg | 6.12.105-1 | riscv64 linux-image-6.12.105+deb13-rpi | 6.12.105-1 | armel linux-image-6.12.105+deb13-rpi-dbg | 6.12.105-1 | armel linux-image-6.12.105+deb13-rt-amd64-dbg | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-rt-amd64-unsigned | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-rt-arm64-dbg | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-rt-arm64-unsigned | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-rt-armmp | 6.12.105-1 | armhf linux-image-6.12.105+deb13-rt-armmp-dbg | 6.12.105-1 | armhf linux-image-6.12.105+deb13-s390x | 6.12.105-1 | s390x linux-image-6.12.105+deb13-s390x-dbg | 6.12.105-1 | s390x linux-image-6.12.86+deb13-amd64-dbg | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-amd64-unsigned | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-arm64-16k-dbg | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-arm64-16k-unsigned | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-arm64-dbg | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-arm64-unsigned | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-armmp | 6.12.86-1 | armhf linux-image-6.12.86+deb13-armmp-dbg | 6.12.86-1 | armhf linux-image-6.12.86+deb13-armmp-lpae | 6.12.86-1 | armhf linux-image-6.12.86+deb13-armmp-lpae-dbg | 6.12.86-1 | armhf linux-image-6.12.86+deb13-cloud-amd64-dbg | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-cloud-amd64-unsigned | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-cloud-arm64-dbg | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-cloud-arm64-unsigned | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-powerpc64le | 6.12.86-1 | ppc64el linux-image-6.12.86+deb13-powerpc64le-64k | 6.12.86-1 | ppc64el linux-image-6.12.86+deb13-powerpc64le-64k-dbg | 6.12.86-1 | ppc64el linux-image-6.12.86+deb13-powerpc64le-dbg | 6.12.86-1 | ppc64el linux-image-6.12.86+deb13-riscv64 | 6.12.86-1 | riscv64 linux-image-6.12.86+deb13-riscv64-dbg | 6.12.86-1 | riscv64 linux-image-6.12.86+deb13-rpi | 6.12.86-1 | armel linux-image-6.12.86+deb13-rpi-dbg | 6.12.86-1 | armel linux-image-6.12.86+deb13-rt-amd64-dbg | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-rt-amd64-unsigned | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-rt-arm64-dbg | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-rt-arm64-unsigned | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-rt-armmp | 6.12.86-1 | armhf linux-image-6.12.86+deb13-rt-armmp-dbg | 6.12.86-1 | armhf linux-image-6.12.86+deb13-s390x | 6.12.86-1 | s390x linux-image-6.12.86+deb13-s390x-dbg | 6.12.86-1 | s390x linux-image-6.12.95+deb13-amd64-dbg | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-amd64-unsigned | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-arm64-16k-dbg | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-arm64-16k-unsigned | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-arm64-dbg | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-arm64-unsigned | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-armmp | 6.12.95-1 | armhf linux-image-6.12.95+deb13-armmp-dbg | 6.12.95-1 | armhf linux-image-6.12.95+deb13-armmp-lpae | 6.12.95-1 | armhf linux-image-6.12.95+deb13-armmp-lpae-dbg | 6.12.95-1 | armhf linux-image-6.12.95+deb13-cloud-amd64-dbg | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-cloud-amd64-unsigned | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-cloud-arm64-dbg | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-cloud-arm64-unsigned | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-powerpc64le | 6.12.95-1 | ppc64el linux-image-6.12.95+deb13-powerpc64le-64k | 6.12.95-1 | ppc64el linux-image-6.12.95+deb13-powerpc64le-64k-dbg | 6.12.95-1 | ppc64el linux-image-6.12.95+deb13-powerpc64le-dbg | 6.12.95-1 | ppc64el linux-image-6.12.95+deb13-riscv64 | 6.12.95-1 | riscv64 linux-image-6.12.95+deb13-riscv64-dbg | 6.12.95-1 | riscv64 linux-image-6.12.95+deb13-rpi | 6.12.95-1 | armel linux-image-6.12.95+deb13-rpi-dbg | 6.12.95-1 | armel linux-image-6.12.95+deb13-rt-amd64-dbg | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-rt-amd64-unsigned | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-rt-arm64-dbg | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-rt-arm64-unsigned | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-rt-armmp | 6.12.95-1 | armhf linux-image-6.12.95+deb13-rt-armmp-dbg | 6.12.95-1 | armhf linux-image-6.12.95+deb13-s390x | 6.12.95-1 | s390x linux-image-6.12.95+deb13-s390x-dbg | 6.12.95-1 | s390x linux-image-6.12.96+deb13-amd64-dbg | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-amd64-unsigned | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-arm64-16k-dbg | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-arm64-16k-unsigned | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-arm64-dbg | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-arm64-unsigned | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-armmp | 6.12.96-1 | armhf linux-image-6.12.96+deb13-armmp-dbg | 6.12.96-1 | armhf linux-image-6.12.96+deb13-armmp-lpae | 6.12.96-1 | armhf linux-image-6.12.96+deb13-armmp-lpae-dbg | 6.12.96-1 | armhf linux-image-6.12.96+deb13-cloud-amd64-dbg | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-cloud-amd64-unsigned | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-cloud-arm64-dbg | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-cloud-arm64-unsigned | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-powerpc64le | 6.12.96-1 | ppc64el linux-image-6.12.96+deb13-powerpc64le-64k | 6.12.96-1 | ppc64el linux-image-6.12.96+deb13-powerpc64le-64k-dbg | 6.12.96-1 | ppc64el linux-image-6.12.96+deb13-powerpc64le-dbg | 6.12.96-1 | ppc64el linux-image-6.12.96+deb13-riscv64 | 6.12.96-1 | riscv64 linux-image-6.12.96+deb13-riscv64-dbg | 6.12.96-1 | riscv64 linux-image-6.12.96+deb13-rpi | 6.12.96-1 | armel linux-image-6.12.96+deb13-rpi-dbg | 6.12.96-1 | armel linux-image-6.12.96+deb13-rt-amd64-dbg | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-rt-amd64-unsigned | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-rt-arm64-dbg | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-rt-arm64-unsigned | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-rt-armmp | 6.12.96-1 | armhf linux-image-6.12.96+deb13-rt-armmp-dbg | 6.12.96-1 | armhf linux-image-6.12.96+deb13-s390x | 6.12.96-1 | s390x linux-image-6.12.96+deb13-s390x-dbg | 6.12.96-1 | s390x linux-kbuild-6.12.100+deb13 | 6.12.100-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-kbuild-6.12.101+deb13 | 6.12.101-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-kbuild-6.12.105+deb13 | 6.12.105-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-kbuild-6.12.86+deb13 | 6.12.86-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-kbuild-6.12.95+deb13 | 6.12.95-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-kbuild-6.12.96+deb13 | 6.12.96-1 | amd64, arm64, armel, armhf, i386, ppc64el, riscv64, s390x linux-libc-dev | 6.12.86-1 | all linux-libc-dev | 6.12.95-1 | all linux-libc-dev | 6.12.96-1 | all linux-libc-dev | 6.12.100-1 | all linux-libc-dev | 6.12.101-1 | all linux-libc-dev | 6.12.105-1 | all linux-source | 6.12.86-1 | all linux-source | 6.12.95-1 | all linux-source | 6.12.96-1 | all linux-source | 6.12.100-1 | all linux-source | 6.12.101-1 | all linux-source | 6.12.105-1 | all linux-source-6.12 | 6.12.86-1 | all linux-source-6.12 | 6.12.95-1 | all linux-source-6.12 | 6.12.96-1 | all linux-source-6.12 | 6.12.100-1 | all linux-source-6.12 | 6.12.101-1 | all linux-source-6.12 | 6.12.105-1 | all linux-support-6.12.100+deb13 | 6.12.100-1 | all linux-support-6.12.101+deb13 | 6.12.101-1 | all linux-support-6.12.105+deb13 | 6.12.105-1 | all linux-support-6.12.86+deb13 | 6.12.86-1 | all linux-support-6.12.95+deb13 | 6.12.95-1 | all linux-support-6.12.96+deb13 | 6.12.96-1 | all loop-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf loop-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el loop-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 loop-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x loop-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf loop-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el loop-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 loop-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x loop-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf loop-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el loop-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 loop-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x loop-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf loop-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el loop-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 loop-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x loop-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf loop-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el loop-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 loop-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x loop-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf loop-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el loop-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 loop-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x md-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf md-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el md-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 md-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x md-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf md-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el md-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 md-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x md-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf md-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el md-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 md-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x md-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf md-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el md-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 md-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x md-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf md-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el md-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 md-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x md-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf md-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el md-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 md-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x mmc-core-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 mmc-core-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 mmc-core-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 mmc-core-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 mmc-core-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 mmc-core-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 mmc-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf mmc-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 mmc-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf mmc-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 mmc-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf mmc-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 mmc-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf mmc-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 mmc-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf mmc-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 mmc-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf mmc-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 mtd-core-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el mtd-core-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x mtd-core-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el mtd-core-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x mtd-core-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el mtd-core-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x mtd-core-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el mtd-core-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x mtd-core-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el mtd-core-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x mtd-core-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el mtd-core-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x mtd-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf mtd-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 mtd-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf mtd-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 mtd-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf mtd-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 mtd-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf mtd-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 mtd-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf mtd-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 mtd-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf mtd-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 multipath-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf multipath-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el multipath-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 multipath-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x multipath-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf multipath-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el multipath-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 multipath-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x multipath-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf multipath-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el multipath-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 multipath-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x multipath-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf multipath-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el multipath-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 multipath-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x multipath-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf multipath-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el multipath-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 multipath-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x multipath-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf multipath-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el multipath-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 multipath-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x nbd-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf nbd-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el nbd-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 nbd-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x nbd-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf nbd-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el nbd-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 nbd-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x nbd-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf nbd-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el nbd-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 nbd-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x nbd-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf nbd-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el nbd-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 nbd-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x nbd-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf nbd-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el nbd-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 nbd-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x nbd-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf nbd-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el nbd-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 nbd-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x nic-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf nic-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el nic-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 nic-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x nic-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf nic-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el nic-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 nic-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x nic-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf nic-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el nic-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 nic-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x nic-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf nic-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el nic-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 nic-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x nic-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf nic-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el nic-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 nic-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x nic-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf nic-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el nic-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 nic-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x nic-shared-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf nic-shared-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el nic-shared-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 nic-shared-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf nic-shared-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el nic-shared-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 nic-shared-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf nic-shared-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el nic-shared-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 nic-shared-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf nic-shared-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el nic-shared-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 nic-shared-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf nic-shared-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el nic-shared-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 nic-shared-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf nic-shared-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el nic-shared-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 nic-usb-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf nic-usb-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el nic-usb-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 nic-usb-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf nic-usb-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el nic-usb-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 nic-usb-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf nic-usb-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el nic-usb-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 nic-usb-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf nic-usb-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el nic-usb-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 nic-usb-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf nic-usb-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el nic-usb-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 nic-usb-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf nic-usb-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el nic-usb-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 nic-wireless-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf nic-wireless-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el nic-wireless-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 nic-wireless-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf nic-wireless-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el nic-wireless-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 nic-wireless-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf nic-wireless-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el nic-wireless-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 nic-wireless-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf nic-wireless-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el nic-wireless-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 nic-wireless-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf nic-wireless-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el nic-wireless-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 nic-wireless-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf nic-wireless-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el nic-wireless-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 pata-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf pata-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 pata-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf pata-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 pata-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf pata-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 pata-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf pata-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 pata-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf pata-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 pata-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf pata-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 ppp-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf ppp-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el ppp-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 ppp-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf ppp-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el ppp-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 ppp-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf ppp-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el ppp-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 ppp-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf ppp-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el ppp-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 ppp-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf ppp-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el ppp-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 ppp-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf ppp-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el ppp-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 sata-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf sata-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el sata-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 sata-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf sata-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el sata-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 sata-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf sata-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el sata-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 sata-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf sata-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el sata-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 sata-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf sata-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el sata-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 sata-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf sata-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el sata-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 scsi-core-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf scsi-core-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el scsi-core-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 scsi-core-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x scsi-core-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf scsi-core-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el scsi-core-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 scsi-core-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x scsi-core-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf scsi-core-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el scsi-core-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 scsi-core-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x scsi-core-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf scsi-core-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el scsi-core-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 scsi-core-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x scsi-core-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf scsi-core-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el scsi-core-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 scsi-core-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x scsi-core-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf scsi-core-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el scsi-core-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 scsi-core-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x scsi-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf scsi-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el scsi-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 scsi-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x scsi-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf scsi-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el scsi-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 scsi-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x scsi-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf scsi-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el scsi-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 scsi-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x scsi-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf scsi-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el scsi-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 scsi-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x scsi-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf scsi-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el scsi-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 scsi-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x scsi-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf scsi-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el scsi-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 scsi-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x scsi-nic-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf scsi-nic-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el scsi-nic-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 scsi-nic-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf scsi-nic-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el scsi-nic-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 scsi-nic-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf scsi-nic-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el scsi-nic-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 scsi-nic-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf scsi-nic-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el scsi-nic-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 scsi-nic-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf scsi-nic-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el scsi-nic-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 scsi-nic-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf scsi-nic-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el scsi-nic-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 serial-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el serial-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el serial-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el serial-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el serial-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el serial-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el sound-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf sound-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf sound-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf sound-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf sound-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf sound-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf speakup-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf speakup-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf speakup-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf speakup-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf speakup-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf speakup-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf squashfs-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf squashfs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el squashfs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 squashfs-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf squashfs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el squashfs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 squashfs-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf squashfs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el squashfs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 squashfs-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf squashfs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el squashfs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 squashfs-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf squashfs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el squashfs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 squashfs-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf squashfs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el squashfs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 udf-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf udf-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el udf-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 udf-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x udf-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf udf-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el udf-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 udf-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x udf-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf udf-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el udf-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 udf-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x udf-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf udf-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el udf-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 udf-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x udf-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf udf-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el udf-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 udf-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x udf-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf udf-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el udf-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 udf-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x uinput-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf uinput-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el uinput-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf uinput-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el uinput-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf uinput-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el uinput-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf uinput-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el uinput-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf uinput-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el uinput-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf uinput-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el usb-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf usb-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el usb-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 usb-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf usb-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el usb-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 usb-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf usb-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el usb-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 usb-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf usb-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el usb-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 usb-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf usb-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el usb-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 usb-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf usb-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el usb-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 usb-serial-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf usb-serial-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el usb-serial-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 usb-serial-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf usb-serial-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el usb-serial-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 usb-serial-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf usb-serial-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el usb-serial-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 usb-serial-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf usb-serial-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el usb-serial-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 usb-serial-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf usb-serial-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el usb-serial-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 usb-serial-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf usb-serial-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el usb-serial-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 usb-storage-modules-6.12.100+deb13-armmp-di | 6.12.100-1 | armhf usb-storage-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el usb-storage-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 usb-storage-modules-6.12.101+deb13-armmp-di | 6.12.101-1 | armhf usb-storage-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el usb-storage-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 usb-storage-modules-6.12.105+deb13-armmp-di | 6.12.105-1 | armhf usb-storage-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el usb-storage-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 usb-storage-modules-6.12.86+deb13-armmp-di | 6.12.86-1 | armhf usb-storage-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el usb-storage-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 usb-storage-modules-6.12.95+deb13-armmp-di | 6.12.95-1 | armhf usb-storage-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el usb-storage-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 usb-storage-modules-6.12.96+deb13-armmp-di | 6.12.96-1 | armhf usb-storage-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el usb-storage-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 xfs-modules-6.12.100+deb13-powerpc64le-di | 6.12.100-1 | ppc64el xfs-modules-6.12.100+deb13-riscv64-di | 6.12.100-1 | riscv64 xfs-modules-6.12.100+deb13-s390x-di | 6.12.100-1 | s390x xfs-modules-6.12.101+deb13-powerpc64le-di | 6.12.101-1 | ppc64el xfs-modules-6.12.101+deb13-riscv64-di | 6.12.101-1 | riscv64 xfs-modules-6.12.101+deb13-s390x-di | 6.12.101-1 | s390x xfs-modules-6.12.105+deb13-powerpc64le-di | 6.12.105-1 | ppc64el xfs-modules-6.12.105+deb13-riscv64-di | 6.12.105-1 | riscv64 xfs-modules-6.12.105+deb13-s390x-di | 6.12.105-1 | s390x xfs-modules-6.12.86+deb13-powerpc64le-di | 6.12.86-1 | ppc64el xfs-modules-6.12.86+deb13-riscv64-di | 6.12.86-1 | riscv64 xfs-modules-6.12.86+deb13-s390x-di | 6.12.86-1 | s390x xfs-modules-6.12.95+deb13-powerpc64le-di | 6.12.95-1 | ppc64el xfs-modules-6.12.95+deb13-riscv64-di | 6.12.95-1 | riscv64 xfs-modules-6.12.95+deb13-s390x-di | 6.12.95-1 | s390x xfs-modules-6.12.96+deb13-powerpc64le-di | 6.12.96-1 | ppc64el xfs-modules-6.12.96+deb13-riscv64-di | 6.12.96-1 | riscv64 xfs-modules-6.12.96+deb13-s390x-di | 6.12.96-1 | s390x ------------------- Reason ------------------- [auto-cruft] obsolete version ---------------------------------------------- ========================================================================= ========================================================================= [Date: Sat, 12 Sep 2026 07:26:49 -0000] [ftpmaster: Archive Administrator] Removed the following packages from trixie: ata-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 ata-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 ata-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 ata-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 ata-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 ata-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 btrfs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 btrfs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 btrfs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 btrfs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 btrfs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 btrfs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 cdrom-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 cdrom-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 cdrom-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 cdrom-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 cdrom-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 cdrom-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 crypto-dm-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 crypto-dm-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 crypto-dm-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 crypto-dm-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 crypto-dm-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 crypto-dm-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 crypto-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 crypto-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 crypto-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 crypto-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 crypto-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 crypto-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 drm-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 drm-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 drm-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 drm-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 drm-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 drm-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 ext4-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 ext4-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 ext4-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 ext4-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 ext4-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 ext4-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 f2fs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 f2fs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 f2fs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 f2fs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 f2fs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 f2fs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 fat-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 fat-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 fat-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 fat-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 fat-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 fat-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 fb-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 fb-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 fb-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 fb-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 fb-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 fb-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 firewire-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 firewire-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 firewire-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 firewire-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 firewire-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 firewire-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 input-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 input-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 input-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 input-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 input-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 input-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 isofs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 isofs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 isofs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 isofs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 isofs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 isofs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 jfs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 jfs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 jfs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 jfs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 jfs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 jfs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 kernel-image-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 kernel-image-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 kernel-image-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 kernel-image-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 kernel-image-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 kernel-image-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 linux-image-6.12.100+deb13-amd64 | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-cloud-amd64 | 6.12.100-1 | amd64 linux-image-6.12.100+deb13-rt-amd64 | 6.12.100-1 | amd64 linux-image-6.12.101+deb13-amd64 | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-cloud-amd64 | 6.12.101-1 | amd64 linux-image-6.12.101+deb13-rt-amd64 | 6.12.101-1 | amd64 linux-image-6.12.105+deb13-amd64 | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-cloud-amd64 | 6.12.105-1 | amd64 linux-image-6.12.105+deb13-rt-amd64 | 6.12.105-1 | amd64 linux-image-6.12.86+deb13-amd64 | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-cloud-amd64 | 6.12.86-1 | amd64 linux-image-6.12.86+deb13-rt-amd64 | 6.12.86-1 | amd64 linux-image-6.12.95+deb13-amd64 | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-cloud-amd64 | 6.12.95-1 | amd64 linux-image-6.12.95+deb13-rt-amd64 | 6.12.95-1 | amd64 linux-image-6.12.96+deb13-amd64 | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-cloud-amd64 | 6.12.96-1 | amd64 linux-image-6.12.96+deb13-rt-amd64 | 6.12.96-1 | amd64 linux-signed-amd64 | 6.12.86+1 | source linux-signed-amd64 | 6.12.95+1 | source linux-signed-amd64 | 6.12.96+1 | source linux-signed-amd64 | 6.12.100+1 | source linux-signed-amd64 | 6.12.101+1 | source linux-signed-amd64 | 6.12.105+1 | source loop-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 loop-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 loop-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 loop-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 loop-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 loop-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 md-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 md-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 md-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 md-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 md-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 md-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 mmc-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 mmc-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 mmc-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 mmc-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 mmc-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 mmc-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 mmc-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 mmc-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 mmc-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 mmc-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 mmc-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 mmc-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 mtd-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 mtd-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 mtd-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 mtd-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 mtd-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 mtd-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 multipath-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 multipath-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 multipath-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 multipath-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 multipath-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 multipath-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nbd-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nbd-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nbd-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nbd-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nbd-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nbd-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nic-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nic-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nic-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nic-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nic-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nic-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nic-pcmcia-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nic-pcmcia-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nic-pcmcia-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nic-pcmcia-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nic-pcmcia-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nic-pcmcia-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nic-shared-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nic-shared-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nic-shared-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nic-shared-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nic-shared-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nic-shared-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nic-usb-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nic-usb-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nic-usb-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nic-usb-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nic-usb-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nic-usb-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 nic-wireless-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 nic-wireless-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 nic-wireless-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 nic-wireless-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 nic-wireless-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 nic-wireless-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 pata-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 pata-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 pata-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 pata-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 pata-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 pata-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 pcmcia-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 pcmcia-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 pcmcia-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 pcmcia-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 pcmcia-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 pcmcia-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 pcmcia-storage-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 pcmcia-storage-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 pcmcia-storage-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 pcmcia-storage-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 pcmcia-storage-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 pcmcia-storage-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 ppp-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 ppp-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 ppp-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 ppp-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 ppp-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 ppp-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 rfkill-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 rfkill-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 rfkill-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 rfkill-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 rfkill-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 rfkill-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 sata-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 sata-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 sata-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 sata-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 sata-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 sata-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 scsi-core-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 scsi-core-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 scsi-core-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 scsi-core-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 scsi-core-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 scsi-core-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 scsi-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 scsi-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 scsi-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 scsi-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 scsi-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 scsi-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 scsi-nic-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 scsi-nic-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 scsi-nic-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 scsi-nic-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 scsi-nic-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 scsi-nic-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 serial-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 serial-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 serial-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 serial-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 serial-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 serial-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 sound-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 sound-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 sound-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 sound-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 sound-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 sound-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 speakup-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 speakup-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 speakup-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 speakup-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 speakup-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 speakup-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 squashfs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 squashfs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 squashfs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 squashfs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 squashfs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 squashfs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 udf-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 udf-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 udf-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 udf-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 udf-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 udf-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 uinput-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 uinput-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 uinput-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 uinput-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 uinput-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 uinput-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 usb-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 usb-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 usb-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 usb-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 usb-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 usb-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 usb-serial-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 usb-serial-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 usb-serial-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 usb-serial-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 usb-serial-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 usb-serial-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 usb-storage-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 usb-storage-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 usb-storage-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 usb-storage-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 usb-storage-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 usb-storage-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 xfs-modules-6.12.100+deb13-amd64-di | 6.12.100-1 | amd64 xfs-modules-6.12.101+deb13-amd64-di | 6.12.101-1 | amd64 xfs-modules-6.12.105+deb13-amd64-di | 6.12.105-1 | amd64 xfs-modules-6.12.86+deb13-amd64-di | 6.12.86-1 | amd64 xfs-modules-6.12.95+deb13-amd64-di | 6.12.95-1 | amd64 xfs-modules-6.12.96+deb13-amd64-di | 6.12.96-1 | amd64 ------------------- Reason ------------------- [auto-cruft] obsolete version ---------------------------------------------- ========================================================================= ========================================================================= [Date: Sat, 12 Sep 2026 07:27:25 -0000] [ftpmaster: Archive Administrator] Removed the following packages from trixie: ata-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 ata-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 ata-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 ata-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 ata-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 ata-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 btrfs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 btrfs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 btrfs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 btrfs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 btrfs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 btrfs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 cdrom-core-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 cdrom-core-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 cdrom-core-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 cdrom-core-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 cdrom-core-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 cdrom-core-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 crypto-dm-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 crypto-dm-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 crypto-dm-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 crypto-dm-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 crypto-dm-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 crypto-dm-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 crypto-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 crypto-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 crypto-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 crypto-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 crypto-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 crypto-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 ext4-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 ext4-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 ext4-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 ext4-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 ext4-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 ext4-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 f2fs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 f2fs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 f2fs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 f2fs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 f2fs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 f2fs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 fat-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 fat-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 fat-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 fat-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 fat-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 fat-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 fb-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 fb-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 fb-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 fb-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 fb-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 fb-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 input-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 input-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 input-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 input-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 input-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 input-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 isofs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 isofs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 isofs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 isofs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 isofs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 isofs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 jfs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 jfs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 jfs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 jfs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 jfs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 jfs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 kernel-image-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 kernel-image-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 kernel-image-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 kernel-image-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 kernel-image-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 kernel-image-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 linux-image-6.12.100+deb13-arm64 | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-arm64-16k | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-cloud-arm64 | 6.12.100-1 | arm64 linux-image-6.12.100+deb13-rt-arm64 | 6.12.100-1 | arm64 linux-image-6.12.101+deb13-arm64 | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-arm64-16k | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-cloud-arm64 | 6.12.101-1 | arm64 linux-image-6.12.101+deb13-rt-arm64 | 6.12.101-1 | arm64 linux-image-6.12.105+deb13-arm64 | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-arm64-16k | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-cloud-arm64 | 6.12.105-1 | arm64 linux-image-6.12.105+deb13-rt-arm64 | 6.12.105-1 | arm64 linux-image-6.12.86+deb13-arm64 | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-arm64-16k | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-cloud-arm64 | 6.12.86-1 | arm64 linux-image-6.12.86+deb13-rt-arm64 | 6.12.86-1 | arm64 linux-image-6.12.95+deb13-arm64 | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-arm64-16k | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-cloud-arm64 | 6.12.95-1 | arm64 linux-image-6.12.95+deb13-rt-arm64 | 6.12.95-1 | arm64 linux-image-6.12.96+deb13-arm64 | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-arm64-16k | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-cloud-arm64 | 6.12.96-1 | arm64 linux-image-6.12.96+deb13-rt-arm64 | 6.12.96-1 | arm64 linux-signed-arm64 | 6.12.86+1 | source linux-signed-arm64 | 6.12.95+1 | source linux-signed-arm64 | 6.12.96+1 | source linux-signed-arm64 | 6.12.100+1 | source linux-signed-arm64 | 6.12.101+1 | source linux-signed-arm64 | 6.12.105+1 | source loop-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 loop-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 loop-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 loop-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 loop-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 loop-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 md-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 md-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 md-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 md-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 md-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 md-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 mmc-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 mmc-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 mmc-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 mmc-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 mmc-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 mmc-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 multipath-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 multipath-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 multipath-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 multipath-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 multipath-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 multipath-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 nbd-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 nbd-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 nbd-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 nbd-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 nbd-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 nbd-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 nic-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 nic-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 nic-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 nic-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 nic-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 nic-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 nic-shared-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 nic-shared-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 nic-shared-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 nic-shared-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 nic-shared-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 nic-shared-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 nic-usb-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 nic-usb-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 nic-usb-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 nic-usb-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 nic-usb-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 nic-usb-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 nic-wireless-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 nic-wireless-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 nic-wireless-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 nic-wireless-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 nic-wireless-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 nic-wireless-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 ppp-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 ppp-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 ppp-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 ppp-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 ppp-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 ppp-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 sata-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 sata-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 sata-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 sata-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 sata-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 sata-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 scsi-core-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 scsi-core-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 scsi-core-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 scsi-core-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 scsi-core-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 scsi-core-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 scsi-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 scsi-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 scsi-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 scsi-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 scsi-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 scsi-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 scsi-nic-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 scsi-nic-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 scsi-nic-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 scsi-nic-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 scsi-nic-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 scsi-nic-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 sound-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 sound-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 sound-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 sound-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 sound-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 sound-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 speakup-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 speakup-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 speakup-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 speakup-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 speakup-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 speakup-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 squashfs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 squashfs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 squashfs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 squashfs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 squashfs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 squashfs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 udf-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 udf-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 udf-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 udf-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 udf-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 udf-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 uinput-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 uinput-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 uinput-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 uinput-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 uinput-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 uinput-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 usb-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 usb-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 usb-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 usb-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 usb-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 usb-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 usb-serial-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 usb-serial-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 usb-serial-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 usb-serial-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 usb-serial-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 usb-serial-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 usb-storage-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 usb-storage-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 usb-storage-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 usb-storage-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 usb-storage-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 usb-storage-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 xfs-modules-6.12.100+deb13-arm64-di | 6.12.100-1 | arm64 xfs-modules-6.12.101+deb13-arm64-di | 6.12.101-1 | arm64 xfs-modules-6.12.105+deb13-arm64-di | 6.12.105-1 | arm64 xfs-modules-6.12.86+deb13-arm64-di | 6.12.86-1 | arm64 xfs-modules-6.12.95+deb13-arm64-di | 6.12.95-1 | arm64 xfs-modules-6.12.96+deb13-arm64-di | 6.12.96-1 | arm64 ------------------- Reason ------------------- [auto-cruft] obsolete version ---------------------------------------------- ========================================================================= akonadi-search (4:24.12.3-1+deb13u1) trixie; urgency=medium . [ Fab Stz ] * Fix "akonadi_html_to_text is crashing a lot" (Closes: #1104598) * Added a patch to not crash on empty input. alsa-lib (1.2.14-1+deb13u1) trixie; urgency=medium . * CVE-2026-25068 (Closes: #1126629) ansible-core (2.19.11-0+deb13u1) trixie; urgency=medium . * d/salsa-ci.yml: Run lintian CI against trixie for this branch New upstream * New upstream version 2.19.5 - Fix ``AnsibleModule.human_to_bytes()``, which was never adjusted after the standalone ``human_to_bytes()`` got a new parameter ``default_unit`` (https://github.com/ansible/ansible/pull/85259). - Variable loading now uses file source instead of variables when invalidly formmated vars file is loaded. - ansible-test - The runtime-metadata sanity test now ignores pre-release and build identifiers in collection versions. This prevents errors if a tombstone version is ``X.0.0``, while the collection's version is ``X.0.0-prerelease`` (https://github.com/ansible/ansible/issues/85193)." - first_found - Correct the "Include tasks only if one of the files exists, otherwise skip" example. - get_url - fix regex for GNU Digest line which is used in comparing checksums (https://github.com/ansible/ansible/issues/86132). * New upstream version 2.19.6 - ansible-test - Replace RHEL 10.0 remote with 10.1. - ansible-test - Replace RHEL 9.5 remote with 9.7. - Fix Windows LIB env var corruption. - ansible_local will no longer trigger variable injection default value deprecation. - package, service, gather_facts - fix templating module_defaults for modules executed by these action plugins. - winrm - Provide a better error message if a domain user is specified using a User Principal Name (UPN) but the pykerberos library is not installed so Kerberos is unavailable. * New upstream version 2.19.7 - ansible-test - Update URL used to download FreeBSD wheels for managed remotes. - ansible-test - Use the new API endpoint for the Ansible Core CI service. - Fix up the Action plugin _make_tmp_path error to only include the command run rather than the shell's dataclass repr from mkdtemp. - local connection - Pass correct type to become plugins when checking password * New upstream version 2.19.8 - ansible-test - Add container/remote aliases for more loosely specifying managed test environments. - ansible-test - Add support for using the Ansible Core CI service from GitHub Actions. * New upstream version 2.19.9 - ansible-test - Generate dist_info when running tests. - ansible-test - Replace the parallels managed macOS provider with a new mac provider. - ansible-test - Switch managed macOS remotes from x86_64 to aarch64. - ansible-galaxy collection - Fix using the server configuration for validate_certs when downloading collections. * New upstream version 2.19.10 - psrp - Do not log raw stdout/stderr on verbosity 5 when task has "no_log: true" set - winrm - Do not log raw stdout/stderr on verbosity 5 when task has "no_log: true" set - ansible-test remote alias - Alias values for `--controller` and `--target` are properly resolved for `remote`. Previously, remote alias values (e.g. `fedora/latest`) resolved correctly only for the legacy `--remote` arg, failing with unknown image error for newer args. - module_utils/basic.py - Fix `AnsibleModule.run_command()` to handle `None` return from non-blocking pipe reads (https://github.com/ansible/ansible/issues/86920). * New upstream version 2.19.11 - ansible-test - Replace FreeBSD 14.2 with 14.3. - ansible-galaxy install - Ensure role requirements are passed as positional arguments to `git clone`. Previously, a malicious role author could inject arbitrary git configuration in role dependencies. (CVE-2026-11332) (Closes: #1139175) - module_utils sanitize_keys and remove_value functions now sort their input to ensure matching subsets are always obscured. ansible-core (2.19.4-1) unstable; urgency=medium . * Stay on 2.19 for now since ansible-community 13 isn't released yet * New upstream version 2.19.4 * Drop fix-play-tags-handler-regression.patch (applied upstream) * Explicit thanks to Colin Watson for debugging hard to reproduce CI failures and for providing a fix in the previous upload! aom (3.12.1-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Backport upstream security fixes for four encoder vulnerabilities. - debian/patches/0004-CVE-2026-56209-56210-56211-svc-layer-id-bounds-check.patch: Validate the spatial and temporal layer ids passed to the AOME_SET_SPATIAL_LAYER_ID and AV1E_SET_SVC_LAYER_ID codec controls against the configured number of layers. Fixes: CVE-2026-56210, CVE-2026-56209 and CVE-2026-56211. - debian/patches/0005-CVE-2026-56208-lap-stats-buffer-overflow.patch: Size the first-pass stats buffer to at least MAX_GF_LENGTH_LAP + 1, use a compacting sliding window in Look-Ahead Processing mode and correct an off-by-one in the rest_frames computation, fixing an out-of-bounds access to the first-pass stats array triggered by a small g_lag_in_frames (CVE-2026-56208). * debian/patches/0006-svc-add-more-spatial-temporal-layer-validation.patch: Reject SVC spatial and temporal layer counts outside the supported range in AOME_SET_NUMBER_SPATIAL_LAYERS and AV1E_SET_SVC_PARAMS, and report an invalid parameter rather than relying on an assert() for the fixed-SVC layer count limit. This is a pre-existing out-of-bounds access in 3.12.1, included here because the layer id validation added above derives its bounds from these counts. apr-util (1.6.3-3+deb13u1) trixie-security; urgency=high . * Non-maintainer upload on behalf of Apache Team. (Closes: #1143837) * Fix CVE-2025-49506: Function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack. * Fix CVE-2026-32327: A stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function * Fix CVE-2026-34191: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. * Fix CVE-2026-34501: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. * Fix CVE-2026-34502: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client at-spi2-core (2.56.2-1+deb13u2) trixie; urgency=medium . [ Valentin Haudiquet ] * patches/debian-atkversion-c-linkage.patch: Fix atkversion.h header for C++ (Closes: #1145539) at-spi2-core (2.56.2-1+deb13u2~bpo12+1) bookworm-backports; urgency=medium . * Backport to bookworm. - Revert t64 change. - Revert libgirepository1.0-dev build-dep change. audit (1:4.0.2-2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * d/p/04-riscv64.patch: backport riscv64 support from version 4.0.3 * debian/rules: Pass --with-riscv to configure (Closes: #1136948) auto-apt-proxy (16.8+deb13u2) trixie; urgency=medium . * hit(): prevent apt-helper call from recursing into auto-apt-proxy (Closes: #1142542) * wait for network to be online * debian/tests/timeout: fix tests to be more reliable awffull (3.10.2-10+deb13u2) trixie; urgency=medium . * QA upload. * debian/patches/pcre2.patch: Fix Visits/Pages statistics, thanks Martin Argalas / CyberFoundry.net (Closes: #1129599). base-files (13.8+deb13u7) trixie; urgency=medium . * Update debian_version and os-release for Debian 13.7 point release. * Add AGPL-3.0, Artistic-2.0, BSL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC-BY-SA-4.0, GFDL-1.1 and OFL-1.1 to common-licenses. Closes: #1136090. Packages in forky/sid which decide to refer to those licenses at their common-licenses location will now be easier to backport for trixie. bcg729 (1.1.1-3+deb13u1) trixie; urgency=medium . * Fix SIGFPE due to a division by zero in bcg729Encoder(). Patch taken from upstream. bettercap (2.33.0-1+deb13u2) trixie; urgency=medium . * Non-maintainer upload. . [ Francisco Vilmar Cardoso Ruviaro ] * Drop debian/bettercap.install to stop installing bettercap.service by default (Closes: #1141754) bettercap (2.33.0-1+deb13u1) trixie; urgency=medium . * Add debian/patches/CVE-2026-8276.patch. (Closes: #1136448, CVE-2026-8276) bind9 (1:9.20.26-1~deb13u1) trixie-security; urgency=high . * New upstream version 9.20.26 + [CVE-2026-10723]: Correct verification of NSEC3 signer name. + [CVE-2026-10822]: Malformed DNSKEY records could trigger an assertion. + [CVE-2026-11331]: Fix handling of RPZ CNAME expansion that returns too-long name. + [CVE-2026-11605]: Prevent excessive validation work from crafted negative responses. + [CVE-2026-11622]: Prevent cache exhaustion under sustained attack. + [CVE-2026-11721]: Stop accepting invalid signed wildcard records. + [CVE-2026-12617]: Do not assert for some specific CNAME and DNAME queries. + [CVE-2026-13204]: Prevent crash from malformed NSEC/NSEC3 response. + [CVE-2026-13321]: Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. bind9 (1:9.20.26-1~deb13u1~bpo12+1) bookworm-backports; urgency=high . * Rebuild for trixie-backports. bind9 (1:9.20.24-1) unstable; urgency=medium . * New upstream version 9.20.24 bind9 (1:9.20.23-1) unstable; urgency=high . * New upstream version 9.20.23 + [CVE-2026-3592]: Limit resolver server list size. + [CVE-2026-3039]: Fix GSS-API resource leak. + [CVE-2026-5946]: Disable recursion, UPDATE, and NOTIFY for non-IN views. + [CVE-2026-5950]: Avoid unbounded recursion loop. + [CVE-2026-5947]: Fix crash in resolver when SIG(0)-signed responses are received under load. + [CVE-2026-3593]: Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. binwalk (2.4.3+dfsg1-2+deb13u1) trixie; urgency=medium . * Team upload. * d/p/*: Add prevent-path-traversal-in-wince.patch fixing CVE-2026-7179; thanks to Fukui Daichi for providing the patch (Closes: #1136010). bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream . bubblewrap (0.12.0-1) unstable; urgency=high . * New upstream release - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release * d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. . bubblewrap (0.11.2-2) unstable; urgency=medium . * d/rules: Stop allowing bubblewrap to run when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * d/control, d/NEWS, d/README.Debian: Update documentation accordingly * Standards-Version: 4.7.4 (no changes required) bubblewrap (0.11.2-2) unstable; urgency=medium . * d/rules: Stop allowing bubblewrap to run when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * d/control, d/NEWS, d/README.Debian: Update documentation accordingly * Standards-Version: 4.7.4 (no changes required) bubblewrap (0.11.2-1) unstable; urgency=medium . * New upstream release - Fixes a root privilege escalation vulnerability if bwrap has been made setuid root locally (CVE-2026-41163, Closes: #1134704). Most Debian systems have a non-setuid bubblewrap and therefore are unaffected by this. * d/rules: Temporarily allow bubblewrap to be setuid root. This configuration is a security risk and rarely necessary, so the option is deprecated, and a future upstream version will unconditionally refuse to run if it detects that it has been run setuid root. * d/README.Debian: Update to reflect deprecation of setuid-root bwrap * d/NEWS: Mention deprecation of setuid-root mode bubblewrap (0.11.1-1) unstable; urgency=medium . * New upstream release * Stop overriding kernel.unprivileged_userns_clone sysctl. The setting we use has been the default for several years. * d/control: Remove Recommends on procps. This was only needed as a way to force the required value of kernel.unprivileged_userns_clone during the transition from Debian 10 to 11, and even then, only on non-systemd systems. * d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Refresh patch to apply after a grammatical fix upstream * d/control: Replace transitional libselinux1-dev with libselinux-dev * d/control: Bump Standards-Version to 4.7.3. Remove Priority: optional, no longer required with current dpkg-dev. * d/copyright: Stop quoting the FSF's former postal address * d/rules: Stop overriding build system. This was only necessary while bubblewrap supported both Meson and Autotools builds, which it hasn't since 0.11.0. * d/clean: Remove another Autotools remnant * d/rules: Install NEWS.md as the upstream changelog * Stop using debhelper's historical special case for a single binary package. Explicitly list what we intend to install, instead. * d/watch: Update to v5 format * d/README.Debian: Mention glycin as a prominent use of bubblewrap * d/README.Debian: Reduce focus on pre-Debian-10 kernels caddy (2.6.2-12+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Backport upstream fixes for multiple security issues: CVE-2026-27585, CVE-2026-27587, CVE-2026-27588, CVE-2026-27589, CVE-2026-27590, CVE-2026-45692, CVE-2026-52845, CVE-2026-52846 * d/control: change Built-Using to Static-Built-Using (as in 2.11.2-1). chromium (150.0.7871.181-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15899: Use after free in CameraCapture. Reported by Google. - CVE-2026-15900: Use after free in GPU. Reported by Google. - CVE-2026-15901: Use after free in Network. Reported by Google. - CVE-2026-15902: Use after free in Cast. Reported by Google. - CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-15904: Use after free in Ozone. Reported by Google. - CVE-2026-15905: Use after free in Aura. Reported by Google. - CVE-2026-16420: Type Confusion in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt. - CVE-2026-16421: Inappropriate implementation in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt. - CVE-2026-16413: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-16414: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-16415: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-16416: Integer overflow in Chromecast. Reported by Google. - CVE-2026-16417: Uninitialized Use in Skia. Reported by Google. - CVE-2026-16418: Stack buffer overflow in V8. Reported by Google. - CVE-2026-16419: Out of bounds read and write in ANGLE. Reported by Google. - CVE-2026-16422: Insufficient validation of untrusted input in Certificate. Reported by Google. - CVE-2026-16423: Use after free in UI. Reported by Google. - CVE-2026-16424: Use after free in GPU. Reported by Google. chromium (150.0.7871.124-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15764: Use after free in Ozone. Reported by Google. - CVE-2026-15765: Use after free in Ozone. Reported by Google. - CVE-2026-15766: Uninitialized Use in Skia. Reported by Google. - CVE-2026-15767: Heap buffer overflow in libyuv. Reported by Google. - CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. Reported by Google. - CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. Reported by Google. - CVE-2026-15770: Uninitialized Use in V8. Reported by Google. - CVE-2026-15771: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-15772: Use after free in GPU. Reported by Google. - CVE-2026-15773: Use after free in Core. Reported by xinchaotian of Microsoft. - CVE-2026-15774: Use after free in Skia. Reported by Google. - CVE-2026-15775: Insufficient policy enforcement in V8. Reported by wang1r923096443@gmail.com. - CVE-2026-15776: Type Confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-15777: Use after free in UI. Reported by Google. - CVE-2026-15778: Insufficient validation of untrusted input in Navigation. Reported by Google. * d/patches/upstream/libyuv-loongarch-fix-row_lsx.cc-and-row_lasx.cc.patch: drop, merged upstream. chromium (150.0.7871.124-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15764: Use after free in Ozone. Reported by Google. - CVE-2026-15765: Use after free in Ozone. Reported by Google. - CVE-2026-15766: Uninitialized Use in Skia. Reported by Google. - CVE-2026-15767: Heap buffer overflow in libyuv. Reported by Google. - CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. Reported by Google. - CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. Reported by Google. - CVE-2026-15770: Uninitialized Use in V8. Reported by Google. - CVE-2026-15771: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-15772: Use after free in GPU. Reported by Google. - CVE-2026-15773: Use after free in Core. Reported by xinchaotian of Microsoft. - CVE-2026-15774: Use after free in Skia. Reported by Google. - CVE-2026-15775: Insufficient policy enforcement in V8. Reported by wang1r923096443@gmail.com. - CVE-2026-15776: Type Confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-15777: Use after free in UI. Reported by Google. - CVE-2026-15778: Insufficient validation of untrusted input in Navigation. Reported by Google. * d/patches/upstream/libyuv-loongarch-fix-row_lsx.cc-and-row_lasx.cc.patch: drop, merged upstream. chromium (150.0.7871.114-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15112: Use after free in Ozone. Reported by Google. - CVE-2026-15129: Use after free in Views. Reported by Google. - CVE-2026-15132: Uninitialized Use in V8. Reported by Pierre Langlois from Arm. - CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-15108: Integer overflow in Extensions API. Reported by Google. - CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-15110: Use after free in Extensions. Reported by Google. - CVE-2026-15111: Use after free in Views. Reported by Google. - CVE-2026-15113: Use after free in Autofill. Reported by Google. - CVE-2026-15114: Out of bounds read and write in Codecs. Reported by Google. - CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-15116: Use after free in Actor. Reported by Google. - CVE-2026-15117: Use after free in Payments. Reported by Google. - CVE-2026-15118: Use after free in Input. Reported by Google. - CVE-2026-15119: Inappropriate implementation in GetUserMedia. Reported by Google. - CVE-2026-15120: Use after free in Core. Reported by Google. - CVE-2026-15121: Use after free in WebRTC. Reported by Google. - CVE-2026-15122: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-15123: Insufficient data validation in DOM. Reported by Google - CVE-2026-15124: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-15125: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15126: Use after free in Forms. Reported by Google. - CVE-2026-15127: Inappropriate implementation in WebGL. Reported by Google. - CVE-2026-15128: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15130: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-15107: Use after free in IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-15131: Insufficient data validation in Navigation. Reported by Google. chromium (150.0.7871.114-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15112: Use after free in Ozone. Reported by Google. - CVE-2026-15129: Use after free in Views. Reported by Google. - CVE-2026-15132: Uninitialized Use in V8. Reported by Pierre Langlois from Arm. - CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-15108: Integer overflow in Extensions API. Reported by Google. - CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-15110: Use after free in Extensions. Reported by Google. - CVE-2026-15111: Use after free in Views. Reported by Google. - CVE-2026-15113: Use after free in Autofill. Reported by Google. - CVE-2026-15114: Out of bounds read and write in Codecs. Reported by Google. - CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-15116: Use after free in Actor. Reported by Google. - CVE-2026-15117: Use after free in Payments. Reported by Google. - CVE-2026-15118: Use after free in Input. Reported by Google. - CVE-2026-15119: Inappropriate implementation in GetUserMedia. Reported by Google. - CVE-2026-15120: Use after free in Core. Reported by Google. - CVE-2026-15121: Use after free in WebRTC. Reported by Google. - CVE-2026-15122: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-15123: Insufficient data validation in DOM. Reported by Google - CVE-2026-15124: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-15125: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15126: Use after free in Forms. Reported by Google. - CVE-2026-15127: Inappropriate implementation in WebGL. Reported by Google. - CVE-2026-15128: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15130: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-15107: Use after free in IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-15131: Insufficient data validation in Navigation. Reported by Google. chromium (150.0.7871.114-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-15112: Use after free in Ozone. Reported by Google. - CVE-2026-15129: Use after free in Views. Reported by Google. - CVE-2026-15132: Uninitialized Use in V8. Reported by Pierre Langlois from Arm. - CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-15108: Integer overflow in Extensions API. Reported by Google. - CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-15110: Use after free in Extensions. Reported by Google. - CVE-2026-15111: Use after free in Views. Reported by Google. - CVE-2026-15113: Use after free in Autofill. Reported by Google. - CVE-2026-15114: Out of bounds read and write in Codecs. Reported by Google. - CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-15116: Use after free in Actor. Reported by Google. - CVE-2026-15117: Use after free in Payments. Reported by Google. - CVE-2026-15118: Use after free in Input. Reported by Google. - CVE-2026-15119: Inappropriate implementation in GetUserMedia. Reported by Google. - CVE-2026-15120: Use after free in Core. Reported by Google. - CVE-2026-15121: Use after free in WebRTC. Reported by Google. - CVE-2026-15122: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-15123: Insufficient data validation in DOM. Reported by Google - CVE-2026-15124: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-15125: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15126: Use after free in Forms. Reported by Google. - CVE-2026-15127: Inappropriate implementation in WebGL. Reported by Google. - CVE-2026-15128: Inappropriate implementation in Forms. Reported by Google. - CVE-2026-15130: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-15107: Use after free in IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-15131: Insufficient data validation in Navigation. Reported by Google. chromium (150.0.7871.100-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE list still to be announced. * debian/patches/ungoogled/remove-navigation-source-param.patch: fix crash related to the previous version's resynch. Thanks to plmaneo for the suggested patch (closes: #1141488). cinnamon (6.4.10-2+deb13u1) trixie; urgency=medium . * d/patches: add upstream patch to gracefully handle a missing content-length header during downloads, fixing download and update of spices (applets, desklets, extensions and themes), broken by a server-side change (Closes: #1142724) cockpit (337-1+deb13u2) trixie-security; urgency=medium . * ws: Free "language" string also when it comes from the cookie. Fixes remote unauthenticated DoS and huge memory usage (throttled at 75% and capped at 90% via systemd slice resource control). [CVE-2026-76235] (Closes: #1144975) * pkg/systemd: robustify argument quoting. Fixes arbitrary command execution via crafted links to the system logs user interface. Patch backported from upstream commit e3a47d70f99a0d, and hand-applied in debian/rules to the built bundle, as this branch does not yet rebuild the bundles during package build. [CVE-2026-4802] has no effect; instead apply the equivalent change to the shipped dist/systemd/logs.js.gz via sed in debian/rules. curl (8.14.1-2+deb13u5) trixie; urgency=medium . [ Carlos Henrique Lima Melara ] * d/p/CVE-2026-3784.patch: remove trailing whitespace from patch . [ Samuel Henrique ] * d/p/openssl_fix_openssl_engines.patch: New patch to fix engine support (closes: #1137539) cyrus-imapd (3.10.2-1+deb13u2) trixie; urgency=medium . * Backport security fixes from upstream 3.10.3 (Closes: #1142925) (https://www.cyrusimap.org/imap/download/release-notes/3.10/x/3.10.3.html): - CVE-2026-47084: LOCALDELETE bypassed ACL checks, allowing non-admin users to delete mailboxes without permission. - CVE-2026-47086: GENURLAUTH issued URLAUTH tokens without checking ACL_READ on the target mailbox. - CVE-2026-47087: URLAUTH tokens kept working after the authorizer's access was revoked. - CVE-2026-47081: XAPPLEPUSHSERVICE allowed probing for mailbox existence and hijacking push notifications on other users' folders. - CVE-2026-47089: LISTRIGHTS was not restricted to users with admin access on the target mailbox. - CVE-2026-47085: URLAUTH tokens could be forged via a predictable empty mboxkey. - CVE-2026-47083: MULTISEARCH/ESEARCH allowed a cross-user folder and content enumeration oracle. - CVE-2026-47088: heap out-of-bounds read when parsing nested MIME comments in RFC 822 headers. - CVE-2026-47082: vacation "fcc" delivery skipped the ACL check on the destination mailbox. * This revision adds DEP-3 metadata to the new patches and restores upstream Cassandane regression tests that were missing from the initial debdiff (thanks, Codin!) for several of the fixes. cyrus-imapd (3.10.2-1+deb13u1) trixie; urgency=medium . * http_jmap: allow JMAP EventSource without WebSocket/wslay; backport upstream commit d510b3d2b (released 3.12.0). (Closes: #1141956) dcmtk (3.6.9-5+deb13u3) trixie; urgency=medium . * Team upload. * d/patches/*-CVE-2026-*.patch: new security patches. This change includes a patch queue addressing CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868 and CVE-2026-44628. The latter CVE-2026-44628 is divided into two patches to match upstream's commits. These changes fix a range of issues, including risks of path traversals, denial of services and information leaks. (Closes: #1141411) debian-edu-config (2.13.2~deb13u1) trixie; urgency=medium . * Release to trixie. debian-edu-config (2.13.1) unstable; urgency=medium . [ Daniel Teichmann ] * testsuite/ldap-server: Check /var/lib/ldap exists and is owned by openldap:openldap. Regression check for Debian bug #1144741. * debian/debian-edu-config.lintian-overrides: Fix stale reference. (Fixes commit: 63575146) * Drop unused wicd preconnect hook. wicd is no longer in Debian. The hook was the only remaining wicd integration and is not referenced anywhere else in the package. * testsuite/hostname: escape regex dot and exit non-zero on failure. The unescaped dot in the 'tjener.intern' grep matched any character. Escape it so the FQDN check is exact. Both error paths now exit 1 so a broken hostname fails the test instead of silently passing. * share/debian-edu-config/d-i/pre-pkgsel: resolve leftover merge conflict. * debian/control: Depend on iproute2 * testsuite/network: Stop using net-tools, use ip from iproute2 instead * ldap-tools/ldap-debian-edu-install: Get MAC addresses via ip link instead of ifconfig * share/debian-edu-config/testsuite-lib.sh: Use ss instead of netstat * testsuite/ldap-server: Use ss instead of netstat * debian/control: Drop Depends: net-tools * share/debian-edu-config/d-i/pre-pkgsel: Tighten hostname= parsing and sanitization from /proc/cmdline. Handle hostname= as first cmdline token, ignore empty values and strip characters invalid in hostnames. * share/debian-edu-config/d-i/pre-pkgsel: strip hyphens only when present. Use 's/^-+//' / 's/-+$//' instead of '-*' so the substitution only fires when there actually is a leading/trailing hyphen to remove. * tools/create-debian-edu-certs: Switch root CA and server key generation to ECDSA prime256v1. RSA with 2048 bits is the bare minimum with OpenSSL 3. Replace 'openssl genrsa' with 'openssl genpkey -algorithm EC' using the prime256v1 (secp256r1 / NIST P-256) curve. * tools/create-server-cert: Switch key generation to ECDSA prime256v1 and drop keyEncipherment key usage keyEncipherment is only meaningful for RSA keys. For ECDSA server certificates only the digitalSignature key usage is applicable (RFC 5480). * v3.cnf: Drop keyEncipherment from server cert key usage keyEncipherment is not applicable to ECDSA keys (RFC 5480), only digitalSignature is required for TLS server certificates. . [ Mike Gabriel ] * debian/control: Add to D: (debian-edu-config): procps. (Closes: #1136493). * ldap-tools/ldap-debian-edu-install: Make sure interactions with debconf are UTF-8 based. This resolves GECOS field transliteration after having retrieved debian-edu-config/first-user-fullname from the debconf db. (Closes: #939717). * share/debian-edu-config/d-i/pre-pkgsel: white-space cleanup * share/debian-edu-config/d-i/pre-pkgsel: Use 'tjener' in /etc/hostname and derive FQDN from /etc/hosts. (Closes: #893394). * testsuite/hostname: Test that /etc/hostname on installation profile Main-Server is set correctly * cf3/cf.cfengine3: Stop cfengine3 service on all Debian Edu machines. Esp. cf-execd (calling cf-agent command) clobbers the log on all Debian Edu clients (Debian Edu 12 and onwards) and thus on syslog.intern (aka tjener). In Debian Edu, we use cfengine3 for managing configuration adjustments via manual invocation of the cf-agent command, but we don't support (yet?) to use cfengine3 for constant system management. Partially addresses #1051834. * sbin/debian-edu-ltsp-install: Use KERNEL_PARAMETERS variable, if we define it * sbin/debian-edu-ltsp-install: Fix variable interpretation in sed commands ... by using double quotes, not single quotes. * sbin/update-hostname-from-ip: white-space cleanup * sbin/update-hostname-from-ip: Stop using net-tools, use ip command from iproute2 instead * share/debian-edu-config/d-i/pre-pkgsel: Support hostname override via /proc/cmdline. (Closes: #1008597). . [ Wolfgang Schweer ] * share/debian-edu-config/d-i/pre-pkgsel: Cleanup pre-pkgsel from cruft. (Closes: #1055648). . [ Serhii Horichenko ] * ltsp: Add 'quiet splash' to hide boot details on clients. (Closes: #1065564). * etc/nagios3/debian-edu/commands.cfg: Add key -l for check_apt to list packages available for upgrade. debian-edu-config (2.13.0) unstable; urgency=medium . [ Mike Gabriel ] * sbin/debian-edu-fsautoresize: - Avoid division by zero error on unused mountpoints. * sbin/debian-edu-pxeinstall: - Support overriding tasksel/desktop selection via mydesktop parameter in /etc/debian-edu/pxeinstall.conf. - Fix comment about mapping debconf template keywords to kernel cmdline keywords and drop unused variable assignment. - sbin/debian-edu-pxeinstall: Regression fix, only adjust desktop to mydesktop from pxeinstall.conf if we are processing the tasksel/desktop setting. * share/debian-edu-config/tools/copy-host-keytab: - Support SSH publickey login to tjener, if this is possible (e.g. if admin is using SSH agent forwarding). . [ Daniel Teichmann ] * Add new file 'debian-edu-router.ldif'. Empty proxy groups should be installed on all new Tjeners. * ldap-bootstrap/debian-edu-router.ldif: Add 'server-hosts' nisNetgroup to 'proxy-trusted' nisNetgroup, via 'memberNisNetgroup' attribute. * share/debian-edu-config/gosa.conf.template: Activate nisNetgroup tab for user accounts. * apache2 debian-edu-default.conf: Do not force HTTPS on *.crt (including Debian-Edu_rootCA.crt). (Closes: #1068388) * etc/dovecot/local.conf: Fix passdb block syntax for Dovecot 2.4.x compatibility. * debian/control: Add 'Conflicts: firefox-esr-mobile-config'. (Closes: #1126881) * v3CA.cnf: Fix Root CA X.509v3 extensions for OpenSSL 3 compatibility. * v3.cnf: Fix server cert X.509v3 extensions for OpenSSL 3 compatibility. * tools/create-debian-edu-certs: Fix script to apply correct configurations. * tools/create-server-cert: Add OpenSSL 3 extensions and fix base config. debian-edu-config (2.12.904) unstable; urgency=medium . * share/glib-2.0/schemas/32-debian-edu.arctica-greeter.gschema.override: + Drop file. This setting is theme-specific and should be shipped in debian-edu-artwork- if diverting from system defaults. * cf3/: + Support recognizing FAI based installations of Debian Edu systems (except from main server). debian-edu-config (2.12.903) unstable; urgency=medium . * etc/apache2/sites-available/debian-edu-default.conf: Use SERVER_ADDRESS in RewriteRule instead of hard-coded 'www'. Supports https redirection if connected to e.g. a VPN IP owned by TJENER. * cf3/promises.cf: Regression fix: Drop desktop bundle from bundlesequence. The desktop bundle has been removed since d-e-c 2.12.901. debian-edu-install (2.12.11+deb13u1) trixie; urgency=medium . [ Daniel Teichmann ] * preseed-values/defaults.main-server: Preseed icinga2-ido-mysql/dbconfig-install to false. Needed after debian-edu 2.13.1 (d5c688a7) and debian-edu-config 858a9689. debian-installer (20250803+deb13u7) trixie; urgency=medium . * Bump Linux kernel ABI to 6.12.107+deb13. * Adjust linux-image build-deps accordingly. debian-installer-netboot-images (20250803+deb13u7) trixie; urgency=medium . * Update to 20250803+deb13u7, from trixie-proposed-updates. designate (1:20.0.0-2+deb13u1) trixie-security; urgency=medium . * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). dhcpcd (1:10.1.0-11+deb13u4) trixie; urgency=medium . * [patches] + Cherry-pick upstream fix for CVE-2026-14258 (commit 75289ca). = Refresh all patches. dnsdist (1.9.16-0+deb13u1) trixie-security; urgency=medium . * New upstream version 1.9.16, fixing security issue CVE-2026-52682 dnsmasq (2.91-1+deb13u2) trixie; urgency=medium . * d/p/*: - CVE-2026-12725.patch: Fix heap-based buffer overflow. - CVE-2026-12969.patch: Fix out-of-bounds read vulnerability. docker.io (26.1.5+dfsg1-9+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Engine fixes are cherry-picked from the upstream 25.0 LTS branch, which carries official backports of all of them; BuildKit fixes are taken from BuildKit v0.28.1 as vendored by moby/moby: CVE-2026-41568, CVE-2026-42306, CVE-2026-34040, CVE-2026-33997, CVE-2026-33747, CVE-2026-33748. * Add engine-go1.24-os-root-mkdirall.patch. The upstream CVE-2026-41568 fix calls os.Root.MkdirAll, added in Go 1.25; trixie has Go 1.24, so the two calls are replaced by an equivalent helper built on os.Root.Mkdir. emacs (1:30.1+1-6+deb13u1) trixie-security; urgency=high . * Mark esh-proc-test/kill-pipeline as unstable for now. Skip it since it fails sporadically on at least s390x. Add 0024-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch to address the issue. . * Fix an SVG-related vulnerability (CVE-2026-6861). Add 0025-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch which includes the upstream patch to fix the problem. Thanks to Salvatore Bonaccorso for reporting the issue. (Closes: 1134692) . * Don't run bytecomp-tests--dest-mountpoint where bwrap doesn't work. Add 0026-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch to address the issue. Thanks to Santiago Vila for reporting the issue. (Closes: 1129189) . * Skip two more proced-tests in debian that are skipped on darwin to avoid hanging during the tests. Add 0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch to address the issue. . * Mitigate a risk of executing arbitrary code when opening a file. The vulnerability that has been mitigated could allow a specially crafted file to trigger execution of arbitrary Emacs Lisp code immediately upon visiting it in Emacs. The broader issue is described here: https://debbugs.gnu.org/80574 . Add 0030-Mitigate-arbitrary-code-execution-vulnerability.patch to include the upstream patch addressing the problem. Thanks to Nicholas D Steeves for reporting the issue. erlang (1:27.3.4.1+dfsg-1+deb13u3) trixie-security; urgency=medium . [ Aron Xu ] * Add a series of patches by upstream, which fix a set of vulnerabilities: - Fix CVE-2026-48855: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-48856: Sensitive Data Exposure vulnerability in Erlang OTP inets application (httpc_response module). - Fix CVE-2026-48858: Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp application (ftp_internal module). - Fix CVE-2026-48859: Observable Timing Discrepancy vulnerability in Erlang/OTP ssh application (ssh_auth, ssh_options modules). - Fix CVE-2026-48860: Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl application (inet_tls_dist module). - Fix CVE-2026-49759: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv). - Fix CVE-2026-49760: Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface). Closes: #1139727, #1139823. - Fix CVE-2026-53422: Observable Response Discrepancy vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54886: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54887: Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl application (DTLS server) - Fix CVE-2026-54891: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl application (tls_gen_connection module). - Fix CVE-2026-55950: Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl application (dtls_packet_demux module). - Fix CVE-2026-55952: The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. Closes: #1141414. - Fix CVE-2026-42792: Improper Handling of Exceptional Conditions vulnerability in Erlang/OTP epmd daemon. - Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP stdlib (zip module). - Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability in Erlang/OTP erts. - Fix CVE-2026-55737: Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang/OTP erts. - Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. - Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. - Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory. - Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service. Closes: #1142985. - Fix CVE-2026-28808: Incorrect Authorization vulnerability in Erlang/OTP (inets modules) allows unauthenticated access to CGI scripts. - Fix CVE-2026-28810: Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. - Fix CVE-2026-32144: Improper Certificate Validation vulnerability in Erlang/OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. - Fix CVE-2026-32147: Vulnerability in the SFTP server where file attributes could be modified outside the configured root directory. - Fix CVE-2026-42789: Improper Following of a Certificate's Chain of Trust vulnerability in Erlang/OTP public_key application allows a non-CA certificate to be accepted as an intermediate issuer. - Fix CVE-2026-42790: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. - Fix CVE-2026-42791: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. exim4 (4.98.2-1+deb13u4) trixie-security; urgency=high . * Fix two local privilege escalation issues. EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1) Using command-line arguments intended for transferring queue-name through an Exim execution chain, files outside the spool area can be accessed. This can be used for a privilege escalation. CVE-2026-66140 EXIM-Security-2026-06-22.3 (GCVE-25-2026-07-45-3) A local user having a .forward file can use a string-expansion there. With certain Exim configurations this can be used as a privilege escalation. CVE-2026-66141 expat (2.8.3-1~deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upload 2.8.3 to trixie-security. expat (2.8.2-1) unstable; urgency=high . * New upstream release (closes: #1138862, #1140387, #1140388, #1140557): - fixes CVE-2026-56131: protect XML_ResumeParser() from being called from a handler, - fixes CVE-2026-56132: fix out-of-bound scaffolding index store in doProlog(), - fixes CVE-2026-50219: disallow calls to some functions to guard Expat bindings from memory corruption, - fixes CVE-2026-56403: integer overflow in storeAtts(), - fixes CVE-2026-56404: integer overflow in addBinding(), - fixes CVE-2026-56405: integer overflow in getAttributeId(), - fixes CVE-2026-56406: integer overflow in XML_ParseBuffer(), - fixes CVE-2026-56407: integer overflow in textLen handling, - fixes CVE-2026-56408: integer overflow in copyString(), - fixes CVE-2026-56409: integer overflow in output path join in xmlwf, - fixes CVE-2026-56410: integer overflow in resolveSystemId() in xmlwf, - fixes CVE-2026-56411: Integer overflow in notation list allocation in xmlwf, - fixes CVE-2026-56412: guard XML_TOK_DATA_CHARS handler calls in doCdataSection(). expat (2.8.2-1~deb13u1) trixie-security; urgency=high . * Upload 2.8.2 to trixie-security. expat (2.8.1-1) unstable; urgency=medium . * New upstream release. expat (2.8.0-2) unstable; urgency=high . * Backport upstream fixes for self-testing: - drop casts around malloc that C99 does not need, - drop casts around XML_GetUserData that C99 does not need. * Backport upstream fixes for CVE-2026-45186: attribute name collision checks allowed denial of service attacks through moderately sized crafted XML input (closes: #1136164). expat (2.8.0-1) unstable; urgency=high . * New upstream release: - fixes CVE-2026-41080: improve protection against hash flooding (closes: #1134732). * Update libexpat1 symbols. expat (2.7.5-1) unstable; urgency=high . * New upstream release: - fixes CVE-2026-32776: NULL function pointer dereference for empty external parameter entities (closes: #1131117), - fixes CVE-2026-32777: protect from XML_TOK_INSTANCE_START infinite loop in entityValueProcessor() (closes: #1131118), - fixes CVE-2026-32778: NULL dereference in setContext() on retry after an earlier ouf-of-memory condition (closes: #1131119). expat (2.7.4-1) unstable; urgency=high . * New upstream release: - fixes CVE-2026-25210: integer overflow check for tag buffer reallocation (closes: #1126697), - no longer ships expat.m4 file. * Update watch file. expat (2.7.3-2) unstable; urgency=high . * Backport upstream fix for CVE-2026-24515: make XML_ExternalEntityParserCreate() copy unknown encoding handler user data (closes: 1126277). * Remove now redundant Rules-Requires-Root value. expat (2.7.3-1) unstable; urgency=high . * New upstream release: - fix alignment of internal allocations for some non-amd64 architectures, fixes up on the fix to CVE-2025-59375, - fix a class of false positives where input should have been rejected with error XML_ERROR_ASYNC_ENTITY; regression from CVE-2024-8176. expat (2.7.2-1) unstable; urgency=high . * New upstream release: - fixes CVE-2025-59375: disallow use of disproportional amounts of dynamic memory from within an Expat parser (closes: #1115298). * Update fix-expat-cmake patch. * Update libexpat1 symbols. * Update Standards-Version to 4.7.2 . firefox-esr (140.15.0esr-1~deb13u1) trixie-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-84, also known as: CVE-2026-75874, CVE-2026-16365, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84124, CVE-2026-16371, CVE-2026-84131, CVE-2026-84143, CVE-2026-84145. . * third_party/rust/glslopt/.cargo-checksum.json, third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h: Fix conficting types for once_flag and call_once. Fixes: #1128875. firefox-esr (140.14.0esr-2) unstable; urgency=medium . * third_party/rust/glslopt/.cargo-checksum.json, third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h: Fix conficting types for once_flag and call_once. Fixes: #1128875. firefox-esr (140.14.0esr-1~deb13u1) trixie-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-70, also known as: CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74948, CVE-2026-74949, CVE-2026-74953, CVE-2026-74957, CVE-2026-74959, CVE-2026-74960, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74967, CVE-2026-74969, CVE-2026-74971, CVE-2026-74972, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74983, CVE-2026-74987, CVE-2026-74990. . * python/mach/mach/command_util.py: Fix AST parsing in DecoratorVisitor for Python 3.14. bz#1993797. * python/mozbuild/mozbuild/frontend/reader.py, python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py: Change uses of ast.Str with ast.Constant. bz#1969769. * python/mozbuild/mozbuild/vendor/vendor_python.py, third_party/python/jsonschema/jsonschema/validators.py: Patch jsonschema to work with Python 3.14+. bz#1983736. firefox-esr (140.13.0esr-2) unstable; urgency=medium . * python/mach/mach/command_util.py: Fix AST parsing in DecoratorVisitor for Python 3.14. bz#1993797. * python/mozbuild/mozbuild/frontend/reader.py, python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py: Change uses of ast.Str with ast.Constant. bz#1969769. * python/mozbuild/mozbuild/vendor/vendor_python.py, third_party/python/jsonschema/jsonschema/validators.py: Patch jsonschema to work with Python 3.14+. bz#1983736. firefox-esr (140.13.0esr-1) unstable; urgency=medium . * New upstream release. * Fixes for mfsa2026-70, also known as: CVE-2026-15718, CVE-2026-15719, CVE-2026-16349, CVE-2026-16350, CVE-2026-16362, CVE-2026-16351, CVE-2026-16352, CVE-2026-16363, CVE-2026-16353, CVE-2026-16354, CVE-2026-16368, CVE-2026-16369, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16371, CVE-2026-16374, CVE-2026-16375, CVE-2026-16377, CVE-2026-16379, CVE-2026-16358, CVE-2026-16381, CVE-2026-16383, CVE-2026-16387, CVE-2026-16390, CVE-2026-16391, CVE-2026-16359, CVE-2026-16396, CVE-2026-16405, CVE-2026-16412, CVE-2026-16360, CVE-2026-16361. firefox-esr (140.13.0esr-1~deb13u1) trixie-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-70, also known as: CVE-2026-15718, CVE-2026-15719, CVE-2026-16349, CVE-2026-16350, CVE-2026-16362, CVE-2026-16351, CVE-2026-16352, CVE-2026-16363, CVE-2026-16353, CVE-2026-16354, CVE-2026-16368, CVE-2026-16369, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16371, CVE-2026-16374, CVE-2026-16375, CVE-2026-16377, CVE-2026-16379, CVE-2026-16358, CVE-2026-16381, CVE-2026-16383, CVE-2026-16387, CVE-2026-16390, CVE-2026-16391, CVE-2026-16359, CVE-2026-16396, CVE-2026-16405, CVE-2026-16412, CVE-2026-16360, CVE-2026-16361. firefox-esr (140.12.0esr-1) unstable; urgency=medium . * New upstream release. * Fixes for mfsa2026-58, also known as: CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12292, CVE-2026-12294, CVE-2026-12295, CVE-2026-12298, CVE-2026-12296, CVE-2026-12297, CVE-2026-12299, CVE-2026-12329, CVE-2026-12302, CVE-2026-12304, CVE-2026-12305, CVE-2026-12306, CVE-2026-12307, CVE-2026-12308, CVE-2026-12309, CVE-2026-12310, CVE-2026-12311, CVE-2026-12312, CVE-2026-12313, CVE-2026-12314, CVE-2026-12315, CVE-2026-12330, CVE-2026-12324, CVE-2026-12325, CVE-2026-12327, CVE-2026-12328. flask (3.1.1-1+deb13u1) trixie; urgency=medium . * Team upload * d/patches: backport upstream fix for CVE-2026-27205 (Closes: #1128620) flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal fluidsynth (2.4.4+dfsg-1+deb13u3) trixie; urgency=medium . * CVE-2026-58264 * CVE-2026-61714 freecad (1.0.0+dfsg-8+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2026-34398, CVE-2026-34399: arbitrary Python code execution via eval() on untrusted input in the BIM workbench * CVE-2026-34789: restrict imports to modules located under FreeCAD's own Mod and macro directories. * CVE-2026-73233: the escaping helper in the FEM displacement constraint task dialog neutralised quotation marks but not backslashes, allowing Python code injection through a crafted displacement formula. * CVE-2026-73235: the Xerces SAX2 reader for FCStd Document.xml resolved external entities and loaded external DTDs, allowing local file disclosure via file: URIs and SSRF via http: URIs. * CVE-2026-73234: PropertyFileIncluded::Restore() concatenated an attacker-controlled file attribute from Document.xml with the document transient path without rejecting directory components, absolute paths or parent references, so a crafted FCStd archive could write anywhere the user can write. gimp (3.0.4-3+deb13u10) trixie-security; urgency=medium . * CVE-2026-18301 * CVE-2026-18302 * CVE-2026-18303 * CVE-2026-18304 * CVE-2026-18305 * CVE-2026-18306 * CVE-2026-18307 * CVE-2026-18308 * CVE-2026-42170 * CVE-2026-58379 (Closes: #1141415) * CVE-2026-58380 * CVE-2026-58381 * CVE-2026-58384 * CVE-2026-59088 (Closes: #1144528) * CVE-2026-59090 (Closes: #1144526) * CVE-2026-66758 (Closes: #1142991) * CVE-2026-66759 (Closes: #1142992) glib2.0 (2.84.4-3~deb13u5) trixie; urgency=medium . * Add patches from upstream 2.89.x to fix parsing of XDG MIME magic datafiles - d/p/CVE-2026-16118/xdgmime-Check-if-caches-are-set-before-dumping-them.patch: Fix a crash when running tests on a minimal system - d/p/CVE-2026-16118/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch: Fix an out-of-bounds write if parsing attacker-controlled MIME-magic data. This is unlikely to be exploitable in practice, because an attacker with write access to $XDG_DATA_HOME/mime/magic is likely to have other ways to cause arbitrary code execution. (CVE-2026-16118, glib#3992 upstream, Closes: #1142717) . glib2.0 (2.84.4-3~deb13u4) trixie; urgency=medium . * Edit previous changelog entry to correlate CVE fixes with upstream bug numbers and releases * Add patches from upstream 2.86.5 to fix out-of-bounds accesses: - d/p/gvariant-Fix-an-off-by-one-error-in-an-offset-comparison.patch: Fix a potential out of bounds read by 1 byte (CVE-2026-58010, glib#3915 upstream) - d/p/gmarkup-Fix-potential-one-byte-overread-in-g_markup_escap.patch: Fix a potential out of bounds read by 1 byte when escaping text that is not valid UTF-8 (not considered to be a vulnerability, glib#3916 upstream) - d/p/gdatetime-Factor-out-a-couple-of-magic-constants.patch, d/p/gdatetime-Add-missing-range-validation-to-g_date_time_add.patch: Fix an out of bounds read by up to 2 bytes after parsing an out-of-range date (CVE-2026-58011, glib#3917 upstream) - d/p/gregex-Fix-case-changing-substitutions-with-G_REGEX_RAW.patch: Fix a potential buffer overflow when changing the case of an incomplete UTF-8 sequence while using G_REGEX_RAW (CVE-2026-58012, glib#3918 upstream) - d/p/gregex-Fix-use-of-wrong-option-flags-set-for-checking-for.patch, d/p/gregex-Rename-the-compile_opts-members-to-clarify-their-t.patch: Fix an out-of-bounds read when g_regex_split_full() acts on invalid UTF-8 (not considered to be a vulnerability, glib#3919 upstream) * Add patches from upstream 2.88.1 to fix several issues that were reported as potential security vulnerabilities: - d/p/giochannel-Fix-memcmp-off-the-end-of-the-buffer-with-long.patch: Fix out-of-bounds read if a GIOChannel is configured with a long line-terminator (CVE-2026-58013, glib#3825 upstream) - d/p/gkeyfile-Fix-a-one-byte-heap-under-read-with-g_key_file_g.patch: Fix out-of-bounds read if a list of locale-dependent strings in a GKeyFile is empty (CVE-2026-58014, glib#3930 upstream) - d/p/gdbusmessage-Fix-types-of-integer-arithmetic-in-message-l.patch: Fix an integer overflow that could lead to accepting overly large messages on peer-to-peer D-Bus connections (no CVE ID, glib#3933 upstream) - d/p/gdbusauthmechanismsha1-Validate-cookie-context.patch, d/p/gdbusauthmechanismsha1-Improve-validation-of-cookie-ID.patch, d/p/gdbusauthmechanism-Expose-client-reject-reason-as-a-new-v.patch, d/p/tests-Add-a-unit-test-for-GDBusAuthMechanismSha1-cookie-c.patch: Prevent path traversal and file-content disclosure if a D-Bus client connects to a malicious peer-to-peer D-Bus server (CVE-2026-58015, glib#3931 upstream) * Add patch from upstream 2.88.3 fixing a possible denial of service: - d/p/gdbusauth-Limit-length-of-lines-read-from-client.patch: Fix resource exhaustion if a malicious client can contact a GDBusServer (CVE-2026-15588, glib#3985 upstream, Closes: #1142835) * Add patches from upstream 2.89.0 to harden D-Bus introspection parsing - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch, d/p/tests-Improve-D-Bus-introspection-test-paths.patch, d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch, d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch: Avoid a possible integer underflow if parsing malformed D-Bus introspection XML sent by a malicious service (glib#3932 upstream, CVE-2026-58016, Closes: #1141316) * d/salsa-ci.yml: Disable uscan job as not relevant to this stable branch glib2.0 (2.84.4-3~deb13u4) trixie; urgency=medium . * Edit previous changelog entry to correlate CVE fixes with upstream bug numbers and releases * Add patches from upstream 2.86.5 to fix out-of-bounds accesses: - d/p/gvariant-Fix-an-off-by-one-error-in-an-offset-comparison.patch: Fix a potential out of bounds read by 1 byte (CVE-2026-58010, glib#3915 upstream) - d/p/gmarkup-Fix-potential-one-byte-overread-in-g_markup_escap.patch: Fix a potential out of bounds read by 1 byte when escaping text that is not valid UTF-8 (not considered to be a vulnerability, glib#3916 upstream) - d/p/gdatetime-Factor-out-a-couple-of-magic-constants.patch, d/p/gdatetime-Add-missing-range-validation-to-g_date_time_add.patch: Fix an out of bounds read by up to 2 bytes after parsing an out-of-range date (CVE-2026-58011, glib#3917 upstream) - d/p/gregex-Fix-case-changing-substitutions-with-G_REGEX_RAW.patch: Fix a potential buffer overflow when changing the case of an incomplete UTF-8 sequence while using G_REGEX_RAW (CVE-2026-58012, glib#3918 upstream) - d/p/gregex-Fix-use-of-wrong-option-flags-set-for-checking-for.patch, d/p/gregex-Rename-the-compile_opts-members-to-clarify-their-t.patch: Fix an out-of-bounds read when g_regex_split_full() acts on invalid UTF-8 (not considered to be a vulnerability, glib#3919 upstream) * Add patches from upstream 2.88.1 to fix several issues that were reported as potential security vulnerabilities: - d/p/giochannel-Fix-memcmp-off-the-end-of-the-buffer-with-long.patch: Fix out-of-bounds read if a GIOChannel is configured with a long line-terminator (CVE-2026-58013, glib#3825 upstream) - d/p/gkeyfile-Fix-a-one-byte-heap-under-read-with-g_key_file_g.patch: Fix out-of-bounds read if a list of locale-dependent strings in a GKeyFile is empty (CVE-2026-58014, glib#3930 upstream) - d/p/gdbusmessage-Fix-types-of-integer-arithmetic-in-message-l.patch: Fix an integer overflow that could lead to accepting overly large messages on peer-to-peer D-Bus connections (no CVE ID, glib#3933 upstream) - d/p/gdbusauthmechanismsha1-Validate-cookie-context.patch, d/p/gdbusauthmechanismsha1-Improve-validation-of-cookie-ID.patch, d/p/gdbusauthmechanism-Expose-client-reject-reason-as-a-new-v.patch, d/p/tests-Add-a-unit-test-for-GDBusAuthMechanismSha1-cookie-c.patch: Prevent path traversal and file-content disclosure if a D-Bus client connects to a malicious peer-to-peer D-Bus server (CVE-2026-58015, glib#3931 upstream) * Add patch from upstream 2.88.3 fixing a possible denial of service: - d/p/gdbusauth-Limit-length-of-lines-read-from-client.patch: Fix resource exhaustion if a malicious client can contact a GDBusServer (CVE-2026-15588, glib#3985 upstream, Closes: #1142835) * Add patches from upstream 2.89.0 to harden D-Bus introspection parsing - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch, d/p/tests-Improve-D-Bus-introspection-test-paths.patch, d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch, d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch: Avoid a possible integer underflow if parsing malformed D-Bus introspection XML sent by a malicious service (glib#3932 upstream, CVE-2026-58016, Closes: #1141316) * d/salsa-ci.yml: Disable uscan job as not relevant to this stable branch glibc (2.41-12+deb13u4) trixie; urgency=medium . * debian/patches/git-updates.diff: update from upstream stable branch: - Fix build against linux 7.0 headers. Closes: #1135405. - Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #1134544. - Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543. - Suppress iconv intermediate errors with //TRANSLIT. goaccess (1:1.9.3-1+deb13u1) trixie; urgency=high . * Apply security updates (Closes: #1143181) Includes fixes for the following vulnerabilities: - CVE-2026-54715: Heap Out-of-Bounds Write in GoAccess `parse_browser()` - CVE-2026-55768: GoAccess WebSocket server: signed 32 bit truncation of the 64 bit frame length causes a remote pre authentication denial of service - CVE-2026-55777: Out-of-bounds heap read in parse_ios() via crafted User-Agent (opesys.c:323) lead to remote crash/DoS * debian/salsa-ci.yml: disable uscan test for this branch gpsd (3.25-5+deb13u2) trixie; urgency=medium . * Fix CVE-2026-58459 (see #1141962). A command injection vulnerability exists in the gpsprof client. The subtype field, sourced from a DEVICES JSON log entry or an NMEA PGRMT sentence, is written into the generated gnuplot program via a set title statement with only double quote characters escaped. An attacker who controls the GPS device subtype can embed backtick payloads and execute arbitrary shell commands as the user running gnuplot when the generated plot is rendered. * Fix CVE-2026-60122. A code injection vulnerability exists in the gpsprof client. The SKY.satellites[].used field is inserted unsanitized into a gnuplot heredoc data block. An attacker who controls the GPS input data can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode. gst-plugins-bad1.0 (1.26.2-3+deb13u3) trixie-security; urgency=medium . * CVE-2026-19387 * CVE-2026-52722 * CVE-2026-52720 * CVE-2026-12892 * CVE-2026-12891 gzip (1.13-1+deb13u1) trixie; urgency=medium . * d/p/CVE-2026-41991-a.patch, d/p/CVE-2026-41991-b.patch: use -C if lacking mktemp, closes: #1141442, CVE-2026-41991 * d/p/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z, closes: #1141443, CVE-2026-41992 hplip (3.22.10+dfsg0-8.1+deb13u1) trixie-security; urgency=high . * CVE-2026-8631 (Closes: #1137374) a potential security vulnerability might allow escalation of privileges and/or arbitrary code execution when handling crafted print data. * CVE-2026-8632 a potential security vulnerability might allow escalation of privileges and/or arbitrary code execution via operating system command injection. * with the help of Marc Deslauriers from Ubuntu, patches are extracted from hplip 3.26.4 imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium . * Fix CVE-2026-56362: A heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex. * Fix CVE-2026-56366: A memory leak vulnerability in the META reader when processing APP1JPEG input paths. * Fix CVE-2026-56372: A heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. * Fix CVE-2026-56373: A use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. * Fix CVE-2026-56374: A heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. * Fix CVE-2026-56375: A memory leak vulnerability in the ASHLAR coder when an action fails * Fix CVE-2026-61464: A heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title. * Fix CVE-2026-61465: A missing a check was found, for the allowed memory allocation limit in matrix-backed operations such as -canny. * Fix CVE-2026-61857: A heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. * Fix CVE-2026-61858: A policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. * Fix CVE-2026-61859: A policy bypass vulnerability in the -script operation due to missing security policy checks. * Fix CVE-2026-61860: a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. * Fix CVE-2026-61861: A use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. * Fix CVE-2026-61862: When a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed. * Fix CVE-2026-61863: A memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. * Fix CVE-2026-61864: A memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. * Fix CVE-2026-61865: A memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. * Fix CVE-2026-61866: A memory leak vulnerability in the JNG encoder when a blob cannot be opened. * Fix CVE-2026-61867: A memory leak vulnerability in the TIFF encoder when memory allocation fails. * Fix CVE-2026-61868: a memory leak in the YUV decoder that occurs when opening of the blob fails. * Fix CVE-2026-61869: A memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing. * Fix CVE-2026-61870: A memory leak vulnerability in the VIFF encoder when memory allocation fails. * Fix CVE-2026-61871: A memory leak in the ICON decoder that occurs when a memory allocation fails. * Fix CVE-2026-61872: a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. imagemagick (8:7.1.1.43+dfsg1-1+deb13u11) trixie-security; urgency=medium . * Fix CVE-2026-53466: An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. * Fix CVE-2026-53467: The MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. * Backport MagickCore/draw.c from 7.1.2-26 * Fix CVE-2026-55577: A heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. * Fix CVE-2026-55594: A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. * Fix CVE-2026-55597: An incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder * Fix CVE-2026-55628: The `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. * Fix CVE-2026-56361: Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations. * Fix CVE-2026-56363: An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash. * Fix CVE-2026-56364: A memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service. * Fix CVE-2026-56365: A memory leak vulnerability in the PNG encoder when writing MNG images. * Fix CVE-2026-56367: An integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. * Fix CVE-2026-56368: A memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service. * Fix CVE-2026-56370: ImageMagick contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution. * Fix CVE-2026-56371; A memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. * Fix CVE-2026-56376: A heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service. * Fix CVE-2026-56377: ImageMagick contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. * Fix CVE-2026-56378: ImageMagick contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte. incus (6.0.4-2+deb13u10) trixie; urgency=medium . * Cherry-pick fixes for the following security issues - CVE-2026-81500 / GHSA-9pqw-c7m4-xvg7 - CVE-2026-81501 / GHSA-c6wx-8679-hpr9 incus (6.0.4-2+deb13u9) trixie-security; urgency=high . * Cherry-pick upstream fix for large nft ruleset performance * Cherry-pick fixes for the following security issues: - CVE-2026-62313 / GHSA-53cg-qvg7-m8vg - CVE-2026-62867 / GHSA-q7xw-r4w2-2wcm - CVE-2026-62940 / GHSA-qw5c-v953-38gw - CVE-2026-62941 / GHSA-mq9x-prm8-3vpw - CVE-2026-63125 / GHSA-6rqx-22hc-qm36 - CVE-2026-63343 / GHSA-fmjx-5j3g-997p - GHSA-26gp-p5fw-3r2h - GHSA-4qxq-p5hm-3q3p - GHSA-67qw-68v3-36h6 - GHSA-m3j6-p3v3-qmjv - GHSA-p2v3-6wvc-cv3p * Cherry-pick four additional security fixes not assigned CVEs ironic (1:29.0.5-0+deb13u3) trixie-security; urgency=medium . * Add follow-up patch for CVE-2026-46447 (erata1): "Fix kernel parameter parsing for quoted values and whitespace". * CVE-2026-54421: Sensitive properties returned unredacted in POST and PATCH HTTP responses. Added upstream patch: "Fix sensitive properties returned on volume targets" (Closes: #1140012). * CVE-2026-43003 / OSSN-2026-0100: Command injection via chroot execution of tenant-controlled binaries. Added upstream patch: "Add an agent flag to disable installing boatloaders" (Closes: #1140187). * CVE-2026-44918: multiple related vulnerabilities in Ironic RBAC. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. Applied upstream patch: "Prevent rehoming resources to nodes with different owner". (Closes: #1141716). * CVE-2026-54423: A malicious user with access to deploy a node directly via Ironic can specify the IPMI `send_raw` deployment step with a malicious payload and send commands to that nodes' BMC. Applied upstream patches: - Add operator-configurable step disallow lists - block vendor.send_raw (Closes: #1141717). * OSSN-0106: API ramdisk endpoints require network-level access controls. Added upstream patch: "Add [api] enable_ramdisk_endpoints config option" (Closes: #1144214). jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. keystone (2:27.0.0-3+deb13u5) trixie-security; urgency=medium . * CVE-2026-80184: Delegation bypass in trust, OAuth1, and application credential operations. * CVE-2026-80182: Tokens obtained via application credential or EC2 credential authentication can escape their intended project scope through token-method reauthentication. An application-credential token scoped to one project can be exchanged via POST /v3/auth/tokens with no explicit scope, causing Keystone to issue a new token scoped to the owner's default project. For EC2-derived tokens the bypass is broader: because they carry no delegation markers, they can rescope to any project where the underlying user has role assignments. * Add new patches (Closes: #1145669): - CVE-2026-80182_CVE-2026-80184_1_Block_app_credential_token_resco....patch - CVE-2026-80182_CVE-2026-80184_2_auth_encode_ec2credential_and_oa....patch - CVE-2026-80182_CVE-2026-80184_3_trusts_oauth1_app-creds_reject_d....patch - CVE-2026-80182_CVE-2026-80184_4_auth_reject_delegated_tokens_fro....patch * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch kitty (0.41.1-2+deb13u2) trixie-security; urgency=medium . * Re-diff 0016-CVE-2026-33633 patch * Fixing following CVEs: (Closes: #1139898) - CVE-2026-42850 - CVE-2026-42851 - CVE-2026-54055 - CVE-2026-54057 lemonldap-ng (2.21.2+ds-1+deb13u3) trixie-security; urgency=medium . * Use OTP to store GitHub/LinkedIn states (Closes: CVE-2026-19349) * Improve CDC filtering (Closes: CVE-2026-12804) libdatetime-timezone-perl (1:2.65-1+2026c) trixie; urgency=medium . * Update data to Olson database version 2026c. This update contains contemporary changes for Alberta, CA and Morocco. libdbd-csv-perl (0.6200-1+deb13u1) trixie; urgency=medium . * Team upload. . [ gregor herrmann ] * Add patch from upstream Git to fix test failure. (Closes: #1139509) libdbi-perl (1.652-2~deb13u1) trixie-security; urgency=high . * Team upload. * Rebuild for trixie-security * Revert "Remove «Priority: optional», which is the current default." * Revert "Remove «Rules-Requires-Root: no», which is the current default." * Revert "Declare compliance with Debian Policy 4.7.4." * Revert "Reformat debian/control." . libdbi-perl (1.652-2) unstable; urgency=medium . * Add patch from upstream Git to fix 32bit test failure. Thanks to Adrian Bunk for the bug report. (Closes: #1144851) . libdbi-perl (1.652-1) unstable; urgency=medium . * Import upstream version 1.652. + Limit statements to 292 Mb in preparse (CVE-2026-73193) (Closes: #1144470) + Force placeholder limit on :# and :p# too (CVE-2026-73194) (Closes: #1144471) * Install new SECURITY.md file. * Refresh t__40profile.t__NTP.patch (offset). . libdbi-perl (1.651-1) unstable; urgency=medium . * Import upstream version 1.651. - Fix inverted comparisons for strings in DBI::SQL::Nano (CVE-2026-15043) - Fix DBD::File to ensure that the table is not a symlink outside of f_dir (CVE-2026-15392) - Fix an out-of-bounds error when a statement handle has no fields but the source row is not empty (CVE-2026-60082) - Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData (CVE-2026-60081) Closes: #1142072 . libdbi-perl (1.650-1) unstable; urgency=medium . * Import upstream version 1.650. - Set a hard limit of 99999 on '?' placeholders (CVE-2026-14739) - Fix out-of-bounds read in preparse of SQL that starts with a comment (CVE-2026-14740) - Fix code injection via Profile DSN attribute or DBI_PROFILE variable (CVE-2026-14380) Closes: #1141667 * Install new upstream document. . libdbi-perl (1.649-1) unstable; urgency=medium . * Import upstream version 1.649. . libdbi-perl (1.648-1) unstable; urgency=medium . * Import upstream version 1.648. Fixes CVE-2026-9698 and CVE-2026-10879. * Update years of upstream and packaging copyright. * Declare compliance with Debian Policy 4.7.4. * Remove «Rules-Requires-Root: no», which is the current default. * Remove «Priority: optional», which is the current default. libdbi-perl (1.652-1) unstable; urgency=medium . * Import upstream version 1.652. + Limit statements to 292 Mb in preparse (CVE-2026-73193) (Closes: #1144470) + Force placeholder limit on :# and :p# too (CVE-2026-73194) (Closes: #1144471) * Install new SECURITY.md file. * Refresh t__40profile.t__NTP.patch (offset). libdbi-perl (1.651-1) unstable; urgency=medium . * Import upstream version 1.651. - Fix inverted comparisons for strings in DBI::SQL::Nano (CVE-2026-15043) - Fix DBD::File to ensure that the table is not a symlink outside of f_dir (CVE-2026-15392) - Fix an out-of-bounds error when a statement handle has no fields but the source row is not empty (CVE-2026-60082) - Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData (CVE-2026-60081) Closes: #1142072 libdbi-perl (1.650-1) unstable; urgency=medium . * Import upstream version 1.650. - Set a hard limit of 99999 on '?' placeholders (CVE-2026-14739) - Fix out-of-bounds read in preparse of SQL that starts with a comment (CVE-2026-14740) - Fix code injection via Profile DSN attribute or DBI_PROFILE variable (CVE-2026-14380) Closes: #1141667 * Install new upstream document. libdbi-perl (1.649-1) unstable; urgency=medium . * Import upstream version 1.649. libdbi-perl (1.648-1) unstable; urgency=medium . * Import upstream version 1.648. Fixes CVE-2026-9698 and CVE-2026-10879. * Update years of upstream and packaging copyright. * Declare compliance with Debian Policy 4.7.4. * Remove «Rules-Requires-Root: no», which is the current default. * Remove «Priority: optional», which is the current default. libde265 (1.0.15-1+deb13u2) trixie-security; urgency=medium . * CVE-2026-33164 (Closes: #1131469) * CVE-2026-33165 (Closes: #1131468) libde265 (1.0.15-1+deb13u1) trixie-security; urgency=medium . * Non-maintainer upload by the Security Team. * Backport upstream security fixes CVE-2024-38949, CVE-2024-38950, CVE-2025-61147, CVE-2026-45382, CVE-2026-45383, CVE-2026-49295, CVE-2026-49337, CVE-2026-49346, CVE-2026-54240, CVE-2026-54241 libgd2 (2.3.3-14~deb13u1) trixie-security; urgency=high . * Change the homepage to https://libgd.github.io (Closes: #1143151) * libgd patch for CVE-2026-9672 libgit2 (1.9.0+ds-2+deb13u1) trixie-security; urgency=high . * Fix CVE-2026-5917: shell command injection in SSH transport (Closes: #1144465) * Fix CVE-2026-53583: inverted cert validity check for IP addresses * Fix CVE-2026-53584: unsanitized submodule paths * Fix CVE-2026-53585: limit pack object size to 2GiB * Fix CVE-2026-53586: pass correct hostname to auth layer after redirect * Fix CVE-2026-53587: read buffer overflow in capability check libheif (1.19.8-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fixed issues: CVE-2025-68431, CVE-2026-32882, CVE-2026-32740, CVE-2026-47247, CVE-2026-32741, CVE-2026-47709, CVE-2026-49271, CVE-2026-62292, CVE-2026-47714, CVE-2026-48029, CVE-2026-62289 and GHSA-2h34-fcv6-jqvh * Mitigated CVE-2026-47178: rejected files affected by the issue with heif_error_Unsupported_feature instead of being decoded. libhttp-tiny-perl (0.090-1+deb13u1) trixie; urgency=medium . * [Security] CVE-2026-7010: CRLF-validation in HTTP::Tiny. (Closes: #1146064) * [Security] CVE-2026-7017: HTTP::Tiny credential forwarding on redirects. (Closes: #1141638) libio-compress-perl (2.213-1+deb13u1) trixie; urgency=medium . * [Security] CVE-2025-15649: header parsing in IO::Uncompress::Unzip. (Closes: #1146065) * [Security] CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip. (Closes: #1138051) * [Security] CVE-2026-48961: crash in zipdetails. (Closes: #1138052) * [Security] CVE-2026-48962: code execution in IO-Compress via output globs. (Closes: #1138055) * Add debian/source/include-binaries for CVE-2025-15649 test case. libmodule-cpants-analyse-perl (1.02-1+deb13u1) trixie; urgency=medium . * Add 0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch. Backport fix for interoperability with Archive::Tar >= 3.08. Patch taken from upstream Git as included in 1.03. (Closes: #1146144) libmongocrypt (1.13.2-1+deb13u1) trixie; urgency=medium . * Fix CVE-2026-81523: validate db and collection names libnet-cidr-set-perl (0.15-1+deb13u1) trixie; urgency=medium . * CVE-2026-49940+49942.patch: Only accept ASCII digits for netmasks and IP addresses (Fixes CVE-2026-49940 and CVE-2026-49942). * CVE-2026-49941.patch: Improve strictness of IP address matching (Fixes CVE-2026-49941). * The newly added tests build-depend on libtest-exception-perl. libnet-dns-perl (1.56-0+deb13u1) trixie-security; urgency=high . * Team upload. * Import upstream version 1.56. Includes fixes for CVE-2026-64193 and CVE-2026-64194. (Closes: #1142503) libnet-dns-perl (1.55-1) unstable; urgency=medium . * Team upload. * Import upstream version 1.55. * Declare compliance with Debian Policy 4.7.4. libnet-dns-perl (1.54-1) unstable; urgency=medium . * Team upload. * Import upstream version 1.54. * Declare compliance with Debian Policy 4.7.3. libnet-dns-perl (1.53-1) unstable; urgency=medium . * Team upload. * Import upstream version 1.53. * Remove «Rules-Requires-Root: no», which is the current default. * Remove «Priority: optional», which is the current default. libnfs (5.0.2-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2026-53689 (Closes: #1139731) fix validation of string size to prevent integer overflow * debian/control: fix Maintainer: entry librabbitmq (0.15.0-1+deb13u2) trixie-security; urgency=medium . * [9bc0956] d/patches/CVE-2026-59986.patch: added from upstream. Fix amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read) (GHSA-jgjf-7fwf-f3c7, CVE-2026-59986) * [58e0219] d/patches/CVE-2026-61547.patch: added from upstream. Fix Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY (GHSA-hfjv-vcp3-39wh, CVE-2026-61547) libraw (0.21.4-2+deb13u1) trixie; urgency=high . * Non-maintainer upload. * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read due to missing buffer and dimension validation (closes: #1132655). * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability (closes: #1133845). * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow vulnerability (closes: #1133845). * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow vulnerability (closes: #1133845). * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow vulnerability (closes: #1133845). * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow vulnerability (closes: #1133845). * Add d/salsa-ci.yml for Salsa CI. libsdl2-image (2.8.8+dfsg-1+deb13u1) trixie; urgency=medium . [ Aquila Macedo Costa ] * d/p/Fixed-out-of-bounds-read-in-XCF-image-loader-thanks-Sebas.patch: Import upstream patch for CVE-2026-35444 (Closes: #1133010) * d/patches: Add selected upstream malformed-image parser robustness fixes: - d/p/xpm-Remove-QUICK_COLORHASH-replace-it-with-inline-code-th.patch: check XPM color hash entries before use - d/p/Fix-heap-buffer-overflow-WRITE-in-LBM-palette-CWE-122.patch: fix LBM palette overflow - d/p/xcf-Fix-heap-buffer-overflow-READ-in-XCF-RLE-decoder-CWE-.patch: add XCF RLE decoder bounds checks - d/p/Fix-heap-buffer-overflow-READ-in-XCF-do_layer_surface-CWE.patch, d/p/xcf-Added-an-SDL_SetError-when-rejecting-out-of-bounds-ti.patch: add XCF do_layer_surface tile bounds check, report invalid XCF tile data through SDL_SetError() - d/p/xcf-fix-null-pointer-dereference-when-read_xcf_hierarchy-.patch: check XCF hierarchy read failures before dereferencing - d/p/tga-reject-images-with-zero-width-or-height.patch: reject TGA images with zero width or height - d/p/Fixed-out-of-bound-read-in-GIF-decoder.patch: fix out-of-bounds reads in the GIF decoder . [ Simon McVittie ] * d/control, d/gbp.conf: Branch for trixie * d/patches: Improve patch metadata: add CVE ID, Debian bug number, upstream commit references, etc. * d/patches: Re-export patches with their mechanically-generated names and apply them in the same order that upstream did, to make it more obvious how this version compares with 2.8.12 * d/patches: Add additional robustness fixes for parsing malformed images: - d/p/xcf-Permit-empty-strings-in-read_string.patch: Avoid an out-of-bounds write if XCF files contain a zero-length string - d/p/IMG_xcf.c-read_string-add-back-the-positive-string-size-c.patch: Harden XCF parsing against extremely long strings libsdl3-image (3.2.4+ds-1+deb13u1) trixie; urgency=medium . * d/control, d/gbp.conf: Branch for trixie * d/patches: Add a malformed-image parser robustness fix from 3.4.2: - d/p/Fixed-out-of-bounds-read-in-XCF-image-loader-thanks-Sebas.patch: Avoid an out-of-bounds read when loading invalid XCF images (CVE-2026-35444, same issue as #1133010 in libsdl2-image) * d/patches: Add selected upstream malformed-image parser robustness fixes from 3.4.4: - d/p/xpm-Remove-QUICK_COLORHASH-replace-it-with-inline-code-th.patch: Check XPM colour hash entries before use - d/p/Fix-heap-buffer-overflow-WRITE-in-LBM-palette-CWE-122.patch Avoid an out-of-bounds write when parsing LBM images - d/p/Fix-heap-underflow-WRITE-in-XCF-read_string-CWE-787.patch Avoid an out-of-bounds write if XCF files contain a zero-length string - d/p/Fix-heap-buffer-overflow-READ-in-XCF-do_layer_surface-CWE.patch, d/p/xcf-Added-an-SDL_SetError-when-rejecting-out-of-bounds-ti.patch: Avoid an out-of-bounds read when parsing XCF file tile data, and report the resulting error correctly - d/p/Fix-heap-buffer-overflow-READ-in-XCF-RLE-decoder-CWE-122.patch: Avoid an out-of-bounds read when parsing XCF files with RLE encoding - d/p/xcf-fix-null-pointer-dereference-when-read_xcf_hierarchy-.patch: Check XCF hierarchy read failures before dereferencing - d/p/tga-reject-images-with-zero-width-or-height.patch: Reject zero-sized TGA images as invalid - d/p/Fixed-out-of-bound-read-in-GIF-decoder.patch: Avoid out-of-bounds reads in the GIF decoder * d/patches: Add an additional parser robustness fix from upstream git: - d/p/IMG_xcf.c-read_string-add-back-the-positive-string-size-c.patch Harden XCF parsing against extremely long strings * Thanks to Aquila Macedo Costa libsocket-perl (2.038-1+deb13u1) trixie; urgency=medium . [ Kentaro Hayashi ] * Backport patch to fix CVE-2026-12087 (out-of-bounds heap read in pack_ip_mreq_source()). - Added CVE-2026-12087.patch - Added CVE-2026-12087-test.patch for testing . Closes: #1146063 libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium . * New upstream security/bug fix release 0.11.4: - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() - CVE-2026-3731: Read buffer overrun when handling SFTP extensions - Note: CVE-2025-14821 is Windows specific, does not apply to Linux https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/ (Closes: #1127693) * New upstream security/bug fix release 0.11.5: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction - CVE-2026-59843: Denial of service via zero advertised channel packet size - CVE-2026-59844: Denial of service via oversized SFTP read length - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs - CVE-2026-59849: Denial of service via automatic certificate authentication loop - CVE-2026-59850: Use-after-free via data callbacks on closed channels - Zero-initialize every ssh_string https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ (Closes: #1142537) libssh (0.11.3-1) unstable; urgency=medium . * New upstream security/bug fix release: - CVE-2025-8114: Fix NULL pointer dereference after allocation failure (Closes: #1109860) - CVE-2025-8277: Fix memory leak of ephemeral key pair during repeated wrong KEX (Closes: #1114859) - Potential use-after-free when send() fails during key exchange - Fix possible timeout during KEX if client sends authentication too early - Cleanup OpenSSL PKCS#11 provider when loaded - Zeroize buffers containing private key blobs during export libssh2 (1.11.1-1+deb13u2) trixie; urgency=medium . * d/patches: Fix CVEs CVE-2026-66032 CVE-2026-66033 CVE-2026-66034 CVE-2026-66035 CVE-2026-58050 CVE-2026-58051 (Backport from unstable) libvirt (11.3.0-3+deb13u3) trixie; urgency=medium . * [7061212] patches: Add backports - backport/qemuMonitorJSONMigrate-Drop-detach-QMP-option.patch - Closes: #1145836 * [eaa378a] patches: Add backports - backport/remote-Fix-integer-overflow-in-RPC-handler-[...] - CVE-2026-18917 * [1b35d45] patches: Add backports - backport/conf-reject-line-breaks-in-DNS-TXT-record-[...] - backport/conf-reject-line-breaks-in-DNS-SRV-domain-[...] - backport/network-reject-line-breaks-before-writing-[...] - backport/tests-cover-line-break-rejection-in-DNS-[...] - CVE-2026-61477 * [4378d69] patches: Add backports - backport/src-fix-crash-searching-for-XML-context-string-[...] - CVE-2026-61478 * [fd7eaa5] patches: Add backports - backport/util-virFileChownFiles-do-not-follow-symlinks.patch - CVE-2026-63622 * [eccf219] patches: Add backports - backport/storage-create-images-with-a-private-umask-[...] - CVE-2026-63623 libwebsockets (4.3.5-1+deb13u2) trixie; urgency=medium . * Backport upstream security fix for CVE-2026-10650: resource consumption in the lws_ssh_parse_plaintext() function (closes: #1139178). * Backport upstream security fix for CVE-2026-78161: LECP CBOR position out of bounds write (closes: #1145789). libxfont (1:2.0.6-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * bitscale: fix integer overflow in BitmapScaleBitmaps bytestoalloc (CVE-2026-56001) (Closes: #1141702) * pcfread: validate bitmap sizes and offsets against per-glyph metrics (CVE-2026-56002) (Closes: #1141702) * bitscale: add bounds check to computeProps for property buffer (CVE-2026-56003) (Closes: #1141702) libxfont (1:2.0.6-1+deb12u1) bookworm-security; urgency=medium . * Add upstream patches for security issues: - CVE-2026-56001: integer overflow in BitmapScaleBitmaps bytestoalloc - CVE-2026-56002: validate bitmap sizes and offsets in pcfread - CVE-2026-56003: bounds check to computeProps for property buffer libyaml-syck-perl (1.34-2+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * fix: prevent buffer underflow in base60 (sexagesimal) parsing (CVE-2026-5089) * rebase: apply review feedback * fix: prevent memory leaks when Load/LoadJSON croak on parse errors * Fix four libsyck memory-safety CVEs reachable from YAML::Syck::Load() (CVE-2026-57075, CVE-2026-57076, CVE-2026-57077, CVE-2026-13713) (Closes: #1142267) linux (6.12.107-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.106 - PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept - ALSA: scarlett2: Use a private URB for the notification endpoint - rndis_host: add overflow check in rndis_rx_fixup() - gpio: ml-ioh: use raw_spinlock_t for the register lock (CVE-2026-80562) - gve: fix zero-length skb frag with header-split - hwmon: (ltc4286) Fix symbol namespace of MODULE_IMPORT_NS() - netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() (CVE-2026-64216) - inet: frags: add inet_frag_putn() helper - ipv4: frags: remove ipq_put() - inet: frags: change inet_frag_kill() to defer refcount updates - inet: frags: save a pair of atomic operations in reassembly - inet: frags: publish queues before arming timer (CVE-2026-74662) - serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx (CVE-2026-74653) - NTB: ntb_netdev: Preserve RX queue depth on allocation failure (CVE-2026-74626) - serial: amba-pl011: synchronize DMA teardown - serial: sc16is7xx: rename EFR mutex with generic name - serial: sc16is7xx: use guards for simple mutex locks - serial: sc16is7xx: enable THRI before filling TX FIFO - xfs: namespace the maximum length/refcount symbols - xfs: don't use a xfs_log_iovec for ri_buf in log recovery - xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536) - xfs: hoist per-bucket unlinked list check to helper - xfs: don't livelock in scrub on a circular unlinked list - ALSA: dummy: Check card index validity at probe - ocfs2: fix missing metadata reservation for large xattrs - null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows - kcov: fix data corruption and race conditions on PREEMPT_RT - ext4: stop retrying saturated xattr cache entries - ext4: clear error before retrying inode xattr space fallback - ext4: propagate errors from fast commit range replay - xfs: validate attr entry pointer before field access - libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557) - nfc: digital: clamp SENSF_RES length to the destination buffer - nfc: fdp: bound the device-reported read length and fix an skb leak - nfc: microread: validate target discovery payload lengths - nfc: llcp: bound the connect_sn TLV walk to the skb - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers - nfc: llcp: reject PDUs shorter than the LLCP header - nfc: pn533: purge fragmented skbs during cleanup - nfc: st21nfca: validate ATR_REQ length against the received frame - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers - nfc: nci: free destination parameters when closing a connection - ndisc: ndisc_send_redirect() cleanup - Input: byd - synchronize timer deletion before freeing private data (CVE-2026-80572) - ipv4: reject undersized MTUs in ip_do_fragment() - ipv6: fix use-after-free in ip6_finish_output2() - nvmet-auth: zero the AUTH_RECEIVE response buffer - nvmet-fc: fix invalid free in LS IOD error path - nvmet-tcp: bound SGL data length before allocating command buffers - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations - mptcp: pm: fix data race in add_addr timer callback - [arm64] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (CVE-2026-80583) - drm/xe: Fix DPT allocation paths. - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C - HID: magicmouse: re-enable multitouch after reset-resume - HID: magicmouse: do not keep a stale msc->input if no input is claimed - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID - HID: core: fix OOB read of field->usage in hid_set_field() - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ - xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (CVE-2026-64581) - ipv4: start using dst_dev_rcu() (CVE-2025-40074) - mptcp: pm: fix memory leak from alloc-during-teardown race - Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard - Input: atkbd - skip deactivate for HONOR ZQC-P - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() - HID: nintendo: register input device after capabilities are set - HID: nintendo: stop device IO before hid_hw_stop on probe failure - HID: core: fix number/pointer type confusion on long items - HID: sensor: custom: Fix use-after-free in enable_sensor - HID: hyperv: validate initial device info bounds - Bluetooth: hci_event: fix LE list UAF on reset - Bluetooth: hci_event: validate LE Set CIG Parameters response - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync - Bluetooth: hci_aml: validate firmware segment lengths - net: gro: properly validate BIG TCP aggregation criteria https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.107 - inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590) linux (6.12.105-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.102 - [amd64] x86/bugs: Make Safe-RET robust against interrupt injection (CVE-2026-68480) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.103 - netfilter: nf_conntrack_expect: restore helper propagation via expectation - netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() - net: mpls: initialize rtm_tos in mpls_getroute() - HID: logitech-dj: Standardise hid_report_enum variable nomenclature - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report - bpf: Reset register bounds before narrowing retval range in check_mem_access() - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197) - [amd64] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect - [arm64] pinctrl: qcom: Unconditionally mark gpio as wakeup enable - [arm64] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA - [amd64] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() - ata: sata_mv: accept 1 or 2 resources in platform probe - ata: libahci_platform: support non-consecutive port numbers - ahci: Introduce ahci_ignore_port() helper - ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup - of: reserved_mem: Add code to dynamically allocate reserved_mem array - of: reserved_mem: prevent OOB when too many dynamic regions are defined - btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag - btrfs: zoned: fix deadlock between metadata writeback and transaction commit - [arm64] phy-zynqmp: Postpone getting clock rate until actually needed - [arm64] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() - [arm64] phy: zynqmp: fix runtime PM leak on probe allocation failure - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() - [arm64] drm/mediatek: Check CRTC state before freeing - Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation - KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type - keys: fix out-of-bounds read in keyring_get_key_chunk() - keys: make keyring key-chunk byte order agree with keyring_diff_objects() - assoc_array: trim the final shortcut word using the current chunk end - netfilter: nf_tables: make nft_object rhltable per table - netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH - ipvs: fix the checksum validations - ipvs: fix places with wrong packet offsets - ipvs: do not mangle ICMP replies for non-first fragments - netfilter: nft_payload: fix mask build for partial field offload - rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (CVE-2026-68322) - rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() - [amd64,arm64] pinctrl-amd: Don't clear S4 wake bits at probe - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer - scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race - smb: client: fix buffer leaks in SMB1 read and write - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 - hwmon: (ina2xx) Add support for has_alerts configuration flag - hwmon: (ina2xx) Add support for INA260 - hwmon: (ina226) Add support for SY24655 - hwmon: (ina2xx) Make it easier to add more devices - hwmon: (ina2xx) Add support for INA234 - hwmon: (ina2xx) Shift INA234 shunt and current registers - hwmon: (ina2xx) Fix various overflow issues - hwmon: (ltc4282) Fix reading the minimum alarm voltage - hwmon: (sht3x) Fix unaligned accesses - hwmon: (lm90) Only report alarms if driver is ready - hwmon: (nzxt-smart2) DMA-align output buffer - net: do not send ICMP/NDISC Redirects when peer allocation fails - hwmon: (nct6775-core) Prevent access to unsupported weight registers - net: bridge: mrp: fix Option TLV length in MRP_Test frames - forcedeth: fix UAF of txrx_stats in nv_remove - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors - hwmon: (adt7470) Fix cache updated before hardware write on I2C error - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks - hwmon: (adt7470) Use cached PWM frequency value - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read - hwmon: (adt7470) Fix PWM auto temp state array and bounds check - rtase: fix double free of multi-frag skb on DMA map failure - [powerpc*] boot: Fix simpleboot CPU node lookup check - [powerpc*] boot: Fix treeboot-currituck CPU node lookup check - [powerpc*] boot: Fix treeboot-akebono CPU node lookup check - net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() - wifi: mac80211: validate individual TWT params before driver setup - net: ethernet: mtk_eth_soc: support named IRQs - net: ethernet: mtk_eth_soc: add consts for irq index - net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() - [amd64,arm64] idpf: adjust TxQ ring count minimum - [amd64,arm64] idpf: Fix mailbox IRQ name leak on request failure - Bluetooth: ISO: clear iso_data always when detaching conn from hcon - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() - Bluetooth: ISO: fix leaking sk after socket release - Bluetooth: ISO: avoid deadlocks in iso_sock_timeout - Bluetooth: btintel: Validate length before parsing diagnostics TLV - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() - Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync - net: phylink: put link_gpio if phylink_create fails - scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE - scsi: ufs: core: Cancel RTC work in active-active suspend - scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req - scsi: target: Clear cmd_cnt when initial counter enrollment fails - net: sxgbe: free TX rings on RX allocation failure - net: sxgbe: check descriptor ring allocation failures - can: isotp: check register_netdevice_notifier() error in module init - tracing/mmiotrace: Reset dropped_count in mmio_reset_data() - tracing: Remove TRACE_EVENT_FL_FILTERED logic - tracing/mmiotrace: Remove reference to unused per CPU data pointer - tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions - [riscv64] mm: Fix out-of-bounds page-table walk during memory hot-remove - [arm64] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend - [arm64] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling - net: libwx: fix FDIR ATR queue mismatch for software VLAN packets - [arm64] octeontx2-pf: Set correct sequence for carrier off and tx queue stop - sched/deadline: Use revised wakeup rule only for running dl_server - qede: sync udp_tunnel ports outside qede_lock in the recovery path - ksmbd: return success for deferred final close - ksmbd: fix use-after-free in __close_file_table_ids() - pinctrl: devicetree: don't free uninitialized dev_name on error path - erofs: cap LZMA stream pool size - pinctrl: bm1880: add missing select GENERIC_PINCONF - fortify: Disable -Wstringop-overread in tests - mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() - mm/hugetlb: fix list corruption in allocate_file_region_entries() - mm/vmstat: fold stranded per-cpu node stats when a node comes online - tracing/probes: Reject $arg0 in meta argument expansion - [amd64] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active - [s390x] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled - [s390x] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure - [s390x] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages - sctp: validate Adaptation Indication parameter length - audit: fix potential integer overflow in audit_log_n_string() - audit: fix potential use-after-free in audit_del_rule() - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() - Bluetooth: mgmt: fix pending command UAF in EIR updates - Bluetooth: mgmt: fix UAF in pair command cancellation - Bluetooth: hci_sync: Fix advertising data UAFs - Bluetooth: HIDP: reject frames without a transaction header - Bluetooth: HIDP: validate numbered report payloads - bpf: lwt: Fix dst reference leak on reroute failure - ALSA: 6fire: Fix UAF at error handling during probe - ALSA: lx6464es: fix period byte count for 16-bit streams - ALSA: pcm: wake linked drain waiters on unlink - ALSA: seq: Fix division by zero in initialize_timer() - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes - ALSA: ump: fix double free of out_cvts on rawmidi error - ASoC: tas2562: fix DVC coefficient write order - ASoC: tas2562: fix broken entries in the volume lookup table - ata: libata-eh: Increase STANDBY IMMEDIATE timeout - ata: libata-sata: fix ata_scsi_lpm_supported() iteration - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() - ALSA: usb-audio: fix stack info leak in RME Digiface status - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set - ALSA: usb-audio: Clamp frame size in implicit-feedback mode - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ - e1000: fix memory leak in e1000_probe() - igbvf: Fix leak in TX DMA error cleanup - ipvs: do not propagate one-packet flag to synced conns - net/smc: fix socket use-after-free during link group termination - netfilter: ipset: do not update comments from kernel-side hash adds - tipc: avoid use-after-free in poll trace queue dumps - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames - binfmt_misc: reject a flag character as the field delimiter - binfmt_misc: don't let an 'F' entry pin its own instance - mm/page_reporting: use system_freezable_wq to fix UAF during suspend - mm: memcg: initialize *locked in memcg1_oom_prepare() stub - net: bridge: stop fast-leave after deleting a port group - net: ipv6: clear suppressed fib6 rule result - [powerpc*] ps3: Fix map failure path in dma_ioc0_map_pages() - veth: convert frag_list skbs before running XDP - vxlan: re-fetch eth header after route_shortcircuit() - vxlan: unclone skb head before modifying eth header in route_shortcircuit() - vxlan: use neigh_ha_snapshot() in route_shortcircuit() - vxlan: use pskb_network_may_pull() in route_shortcircuit() - ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() - tracing: Check return value of __register_event() in trace_module_add_events() - tracing/filters: Fix false positive match in regex_match_full() - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write - sctp: reject stale cookies with mismatched verification tags - sctp: prevent peer transport count overflow - hwmon: (npcm750-pwm-fan): stop fan timer on device detach - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client - i2c: amd-mp2: Unregister callback on adapter add failure - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() - cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized - power: supply: bq25890: fix the -10 C NTC lookup entry - power: supply: max17040: handle missing status supplier - [s390x] pci: Fix s390_pci_mmio_write syscall error return without MIO - [s390x] qeth: Check CAP_NET_ADMIN for private ioctls - [s390x] dasd: Fix potential NULL pointer dereference - [s390x] dasd: Fix undersized format-check buffer - [s390x] zcrypt: Fix wrong domain value verification with EP11 CPRBs - [s390x] zcrypt: Validate length for CCA AES cipher key requests - [s390x] zcrypt: Validate length for CCA ECC private key requests - [arm64] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask - [arm64] phy: zynqmp: use read-modify-write for SERDES scrambler bypass - [arm64] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB - net: openvswitch: fix potential UAF on meter attach failure - net: openvswitch: fix skb leak on flow key update failure during recirculation - net: openvswitch: fix skb leak on flow key update failure during ct - ice: wait for reset completion in ice_resume() - ice: fix memory leak in ice_lbtest_prepare_rings() - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock - i2c: iproc: reset bus after timeout if START_BUSY is stuck - i2c: imx: Fix slave registration race and error handling - i2c: imx: Cancel hrtimer before clearing slave pointer - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured - can: ems_usb: validate CPC message lengths - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents - can: softing: fw_parse(): validate firmware record spans - can: peak_usb: add bounds check for USB channel index - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error - can: peak_usb: validate uCAN receive record lengths - can: ctucanfd: add missing MODULE_DEVICE_TABLE() - can: ctucanfd: use self-test mode for PRESUME_ACK - can: ctucanfd: unmap BAR0 using base address - can: ctucanfd: handle bus error interrupts - can: ctucanfd: mark error-active controller status valid - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs - [arm*] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size - [arm*] drm/vc4: Zero the tile state data array before each BIN job - [arm64] drm/panthor: reject firmware sections with oversized data - [arm64] drm/panthor: validate firmware interface structure sizes - [arm64] drm/mediatek: ovl_adaptor: balance component registrations - drm/amdgpu: restore UMD profile pstate after runtime resume - drm/amdgpu: cap GTT size to physical RAM on APUs - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames - drm/amd/display: use proper context for logging - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE - drm/amdkfd: fix QID bit leak in pqm_create_queue() - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment - drm/amdkfd: Handle invalid event type in CRIU event restore - drm/amdkfd: hold event_mutex while checkpointing CRIU events - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size - drm/vmwgfx: reject DX_BIND_QUERY without a DX context - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division - drm/vmwgfx: bound DMA command body size against suffix pointer - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure - drm/vmwgfx: use check_add_overflow for shader size+offset bound - drm/vmwgfx: validate external BO copy bounds for both stride paths - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX - HID: logitech-dj: Fix maxfield check in DJ short report validation - ata: libahci_platform: Do not set mask_port_map when not needed - ata: ahci: Make ahci_ignore_port() handle empty mask_port_map - of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release - drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting - drm/xe: Introduce xe_gt_dbg_printer() - drm/xe: Apply whitelist to engine save-restore - drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267) - drm/xe/rtp: Maintain OA whitelists separately - drm/xe/rtp: Keep track of non-OA nonpriv slots - drm/xe/rtp: Generalize whitelist_apply_to_hwe - drm/xe/rtp: Save OA nonpriv registers to register save/restore lists - drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs - drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt - drm/xe/oa: (De-)whitelist OA registers on OA stream open/release - drm/xe/rtp: Ensure locking/ref counting for OA whitelists - mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios - lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() - mm/slab: prevent unbounded recursion in free path with new kmalloc type - gpio: pch: use raw_spinlock_t for the register lock - usb: gadget: f_tcm: synchronize delayed set_alt with teardown (CVE-2026-68367) - usb: typec: ucsi: split connector lock classes - usb: typec: ucsi: Fix race condition and ordering in port unregistration - media: i2c: imx219: Rename VTS to FRM_LENGTH - media: imx219: Fix maximum frame length in lines - media: chips-media: wave5: Support CBP profile - media: uapi: rkisp: Correct name version enum - wifi: brcmfmac: drain bus_reset work on device removal (CVE-2026-64586) - wifi: ath6kl: fix use-after-free in aggr_reset_state() (CVE-2026-68198) - wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change - mptcp: pm: avoid code duplication to lookup endp - mptcp: add mptcp_userspace_pm_lookup_addr helper - mptcp: pm: use addr entry for get_local_id - mptcp: pm: userspace: fix use-after-free in get_local_id (CVE-2026-68169) - drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions - drm/amdgpu: Fix context pstate override handling (CVE-2026-68273) - drm/sched: Store the drm client_id in drm_sched_fence - drm/amdgpu: give each kernel job a unique id - drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (CVE-2026-68276) - drm/fb-helper: Allocate and release fb_info in single place - drm/tegra: fbdev: Remove offset into framebuffer memory - drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] - drm/xe: Wait on external BO kernel fences in exec IOCTL - [arm64] drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() - [arm64] drm/i915/vrr: require valid min/max vfreq for VRR (CVE-2026-68254) - drm/xe: Rename ___xe_bo_create_locked() - drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266) - [arm64] drm/i915/hdcp: Move to using intel_display in intel_hdcp - [arm64] drm/i915/hdcp: require monotonically increasing seq_num_v - [arm64] drm/i915/hdcp: Skip inactive MST connectors when building stream list - [arm64] drm/i915/hdcp: check streams[] bounds before overflow (CVE-2026-68253) - drm/xe: Stub out new pagefault layer - drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (CVE-2026-68264) - rxrpc: Generate rtt_min - rxrpc: Adjust the rxrpc_rtt_rx tracepoint - rxrpc: Fix the calculation and use of RTO - rxrpc: Manage RTT per-call rather than per-peer - rxrpc: Fix irq-disabled in local_bh_enable() (CVE-2025-38525) - can: use skb hash instead of private variable in headroom - can: isotp: fix timer drain order, wakeup handling and tx_gen ordering - usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path - drm/fb-helper: Fix a locking bug in an error path - [arm64,armhf] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.104 - mount: honour SB_NOUSER in the new mount API - drm/amd/display: Add AV mute wait frames to dce110_set_avmute - drm/amd/display: Check for tg ops in dce110_set_avmute - [s390x] zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call - [arm64] dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer - drm/bridge: ps8640: propagate AUX transfer register errors - [arm64] net: hns3: fix speed configuration residue after driver reload - Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor - enic: fix tx_hang_reset use-after-free on device removal - net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock - pds_core: keep the health thread stopped during reset - pds_core: cancel pending PCI reset work on AER recovery - netfilter: ipset: switch ext_size to atomic64_t - ipvs: avoid out-of-bounds write in ip_vs_nat_icmp - ipvs: return the csum validation for forward hook - watchdog: bd96801_wdt: Fix timeout for enabled WDG - btrfs: fix memory leak in btrfs_do_encoded_write() - bpf: Preserve pointer state for commuted arithmetic - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() - net/sched: cls_route: fix fastmap use-after-free on filter - [arm64] net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete - devlink: fix net namespace reference leak in reload - net/mlx5: fw_tracer, return NULL on create error - counter: microchip-tcb-capture: Fix DT channel validation - bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch - bpf: tcp: Make sure iter->batch always contains a full bucket snapshot - bpf: tcp: Get rid of st_bucket_done - bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items - bpf: tcp: Avoid socket skips and repeats during iteration - bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() - vhost/vdpa: reject overflowing PA map page counts on 32-bit - vdpa/mlx5: Fix buffer length in create_direct_keys() - tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() - xsk: require at least 16 bytes of TX metadata - udp: fix potential use-after-free in tunnel segmentation - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter - net/openvswitch: check Ethernet header length in key_extract() - net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers - hwmon: (nzxt-smart2) Check return value of init_device() in probe - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations - bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() - bnxt_en: Determine and store default RX ring in vnic structure - bnxt_en: Refresh VNIC default ring on queue restart if needed - bnxt_en: Fix PTP PPS setting bug - sctp: fix addip_serial increment on ASCONF_ACK allocation failure - tcp: fix TFO max_qlen accounting across reuseport migration - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length - net: prestera: validate firmware header length - net: remove WARN_ON_ONCE() from sk_mc_loop() - net/smc: fix TOCTOU race between smc_listen_out() and listener close - [amd64] net: thunderbolt: Tear down DMA paths before stopping the rings - ata: pata_sl82c105: fix bridge revision use-after-free - net/atm: fix slab-out-of-bounds read in vcc_setsockopt() - sctp: clear control chunk transport if it is being removed - tls: don't abort the connection on signal-interrupted sends - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination - hwmon: (ads7828) Fix external VREF regulator handling - hwmon: (ltc4282) Avoid overflow in maximum power calculation - hwmon: (ltc4282) Clamp negative current limits - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt - mm/vmscan: wake up flushers conditionally to avoid cgroup OOM (Closes: #1143545) - net: fec: do not release NULL pages when RX buffer allocation fails - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers - mtd: spinand: fix direct mapping creation sizes - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails - mtd: spinand: repeat reading in regular mode if continuous reading fails - swapfile: call cond_resched() before locking si->lock - Input: evdev - sanitize event type index when fetching event masks - ALSA: usb-audio: fix OOB write on Type II inbound URBs - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() - [amd64] thunderbolt: icm: Preserve USB4 proxy data-valid bit - usb: cdnsp: fix incorrect endian conversions for APB timeout register - usb: gadget: f_ncm: Use unsigned int for ndp_index - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() - net: usb: ipheth: fix carrier_work UAF on disconnect - vt: add permission check for KDSKBMETA ioctl - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get - Input: evdev - fix information leak in evdev_pass_values() - ima: fix out-of-bounds read in xattr_verify() - ipvs: stop estimator after disabled calc phase - ipvs: add totalconns for dest - ipvs: properly update the overload flag on dest edit - ipvs: clear IPv4 options after rebasing tunnel ICMP errors - packet: use consistent hard_header_len in non-ring send paths - packet: use consistent hard_header_len in TX_RING send path - net/packet: reset the MAC header on the packet-socket transmit path - packet: synchronize pressure clearing with ring reconfiguration - net: fix skb length accounting after generic XDP frag adjustment - net: openvswitch: reallocate update replies for mismatched IDs - net/sched: reject overly deep qdisc hierarchies - net: octeontx2-pf: Fix UB in shift operation - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header - mac802154: fix netdev use-after-free in beacon worker - netfilter: ebt_nflog: pin the NFLOG backend - net: bridge: mrp: fix uninitialised bytes on the wire - [s390x] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (CVE-2026-74514) - [s390x] KVM: s390: pci: Fix missing error codes and memory unaccounting - [s390x] KVM: s390: pci: Fix resource leak on IRQ registration failure - [s390x] KVM: s390: pci: Fix aisb calculation - block: Reorder the request allocation code in blk_mq_submit_bio() - blk-mq: pop cached request if it is usable (CVE-2026-64017) - blk-mq: reinsert cached request to the list - dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk - [amd64] crypto: ccp - Add new SEV/SNP platform shutdown API - [amd64] KVM: SVM: Add support to initialize SEV/SNP functionality in KVM - [amd64] crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length - [amd64] crypto: ccp - Abort doing SEV INIT if SNP INIT fails - futex: Prevent robust futex exit race some more - kunit/fortify: Replace "volatile" with OPTIMIZER_HIDE_VAR() - kunit/fortify: Add back "volatile" for sizeof() constants - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops - ipv4: fix use-after-free in fib_nhc_update_mtu() - mei: pull kvfree out of spinlock - nvmem: layouts: Add fixed-layout driver - serial: qcom-geni: fix TX DMA buffer flush - serial: 8250_dma: Clear stale RX state on shutdown - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() - staging: rtl8723bs: fix OOB read in WMM_param_handler() - staging: rtl8723bs: fix missing shared-key auth challenge length check - staging: rtl8723bs: validate monitor transmit frame lengths - misc: fastrpc: fix channel ctx ref leak when session alloc fails - misc: fastrpc: Remove buffer from list prior to unmap operation - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free - ring-buffer: Fix crash passing ERR_PTR to kthread_stop() - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs - ALSA: usx2y: bound the hwdep mmap fault offset - tracing: Fix race between update_event_fields and, event_define_fields - fbdev: bitblit: bound-check glyph index in bit_cursor() - ring-buffer: Prevent subbuf order change when resizing is disabled - mm/huge_memory: fix huge_zero_pfn race - net: smc: fix splice entry lifetime imbalance in smc_rx_splice - ipv6: prevent in6_dev_get() from resurrecting inet6_dev - netfilter: bridge: release template ct on non-IP path - netfilter: nf_conntrack: defer invalid log until after unlock - net: atlantic: free stranded TX buffers on ring deinit - net: atlantic: free RX pages of consumed but not refilled buffers - net/sched: act_ct: fix sk_buff leak when the header checks reject a packet - net/sched: act_gact, act_police: range check the fallback control action - ovl: don't warn when the mount is completed from another user namespace - binfmt_misc: don't warn when the mount is completed from another user namespace - Revert "drm/amdgpu: fix aperture mapping leak" - xdp: reject clones that overrun skb_shared_info tailroom - vxlan: do not arm the ageing timer on a device that is down - vsock/virtio: read virtqueues under worker locks - vsock/virtio: avoid refilling the RX queue after teardown - veth: fix skb length accounting after XDP frag adjustment - vhost: reset the vring metadata cache on vring reconfiguration - tls: don't leave a full plaintext sk_msg ring unpushed - tipc: read le->link under the node lock in tipc_node_link_down() - smb: client: Fix use-after-free in cifs_try_adding_channels() - [amd64] KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page - eventfs: Fix use-after-free in eventfs_remove_rec() - Revert "thermal/drivers/hwmon: Cleanup coding style a bit" - ptp: ocp: Fix board ID over-read - ipv6: fix Route Information option length validation - ip6_tunnel: clear skb2->cb[] in ip6ip6_err() - fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() - sched/psi: Shut down rtpoll_timer in psi_cgroup_free() - ima: Instantiate file_truncate and path_truncate hooks - fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions - fsverity: Fix silent truncation in bpf_get_fsverity_digest() - bpf, sockmap: Fix sk_redir use-after-free in send verdict - scsi: scsi_debug: Negate wrapped memcmp() result - sctp: keep chunk->transport in step with the list it is queued on - sctp: fix use-after-free of cached ASCONF chunk - sctp: clear new_transport when removing a peer - [amd64] thunderbolt: Bound the DROM dual link port number before indexing sw->ports - [amd64] thunderbolt: Fix bandwidth group reservation indexing - bpf: tcp: fix double sock release on batch realloc https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.105 - block: stop the timeout timer when releasing a never added disk - bpf: Fix linked reg delta tracking when src_reg == dst_reg (CVE-2026-53092) - bpf: Clear delta when clearing reg id for non-{add,sub} ops - f2fs: fix UAF issue in f2fs_merge_page_bio() (CVE-2025-40054) - mtd: ubi: skip programming unused bits in ubi headers - ubi: fastmap: fix ubi->fm memory leak - mm/damon/ops-common: putback folios on invalid migrate nid (CVE-2026-74644) - mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} - igc: fix netdev not re-attached after resume if interface is down - ipvs: separate destination availability state - net: mana: Fix EQ leak in mana_remove on NULL port - [amd64] crypto: ccp: Add external API interface for PSP module initialization - [amd64] KVM: SVM: Ensure PSP module is initialized if KVM module is built-in - selinux: require every boolean value to be defined - selinux: reject a class permission count below its inherited common - selinux: do not cancel a policy conversion that never started - selinux: reject an unclaimed class value in security_get_classes() - mptcp: avoid combining some incoming suboptions - mptcp: options: reset DSS fields in case of unexpected size - mptcp: fastopen: only mark MPTFO subflows with SYN data - [s390x] qeth: validate user buffer length in SNMP and ARP query ioctls - [amd64] ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() - fbdev: core: Fix pointer desynchronization in fb_io_read() - drm/panthor: skip zero-sized firmware sections - drm/amdgpu: reject oversized IBs with per-ring packet limits - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 - drm/amdgpu: fix aperture iounmap skipped on device removal - [amd64] ASoC: SOF: topology: Use acpi mach from the machine driver - Input: xpad - add support for ZENAIM LEVERLESS - Input: cs40l50-vibra - validate custom data from user space - [powerpc*] pseries: pci - logic bug - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet - Input: psxpad-spi - set driver data before use - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard - Input: iforce - validate input packet lengths - [powerpc*] pseries: lparcfg - fix kbuf[] underflow - Input: synaptics-rmi4 - zero report size on F54 work error - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer - Input: synaptics-rmi4 - block s_input when F54 queue is busy - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue - Input: hynitron_cstxxx - validate touch count and finger IDs - [arm64] crypto: qce - fix error path in devm_qce_register_algs - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind - [arm64] pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 - libceph: fix multiple unsafe decodes in decode_locker() - ftrace: Protect direct_functions in ftrace_find_rec_direct - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() - Input: sur40 - fix input device registration ordering - Input: sur40 - fix V4L error path cleanup - libceph: Avoid using invalid osd indices from primary_temp - ceph: fix MDS random selection readiness predicate - libceph: tolerate addrvecs with multiple entries of the same type - [armhf] mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit - mmc: sdhci: unmap the bounce buffer before device release - mmc: sdhci: make tuning_err a signed int - drm/connector/hdmi: Fix out of bounds memory read - drm/xe: Order ring writes before ring tail updates - drm/radeon: fix autosuspend cleanup during teardown - [s390x] vfio_ccw: Free all memory if cp_init() fails - [s390x] vfio_ccw: Limit the number of channel program segments - [s390x] vfio_ccw: Cancel existing workqueues - [s390x] vfio_ccw: Ensure index for read/write regions are within range - [s390x] vfio_ccw: Ensure first IDAW remains constant - [s390x] vfio_ccw: Fix out of bounds check on CCW array - [s390x] vfio_ccw: Move cp cleanup out of not operational - [s390x] vfio_ccw: Selectively expand io_mutex - [s390x] vfio_ccw: Calculate idal length based on idaw type - [s390x] vfio_ccw: Implement a crw lock - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE - drm/amdgpu: Reject UVD message with invalid number of h265 refs - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional - drm/amdgpu: check ASPM on the dGPU host link - drm/amdgpu: validate GEM_CREATE domain combinations - drm/amdgpu: Reject UVD message with dimensions above 4096 - drm/amdgpu: Implement insert_end for VCE 3 - drm/amdgpu: Fix UVD min buffer sizes - drm/amdgpu: Fix UVD dpb min size calculation for H264 - drm/amdgpu: Fix UVD decode image min size calculation - drm/amdgpu: disallow multiple FENCE chunks in one submit - xfs: clear zapped attr fork state when bmap repair finds no attr fork - xfs: zero i_nlink before repair puts inode on unlinked list - xfs: only check mergeability of bnobt records - xfs: don't double-lock when deleting a self-referential directory - xfs: set the prev pointer when reinserting an inode on the unlinked list - xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers - xfs: nlink scrub must take IOLOCK before determining ILOCK state - xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev - xfs: fix ilock leak on error in xfs_dq_get_next_id - xfs: don't zap the attr fork on repair when there are queued pptr updates - xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair - xfs: fix allocated inodes that show up in the unlinked list - xfs: fix another iunlink infinite loop bug in online fsck - xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers - xfs: avoid UAF on sc->tempip in xrep_tempfile_create - xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN - xfs: don't swallow dquot recovery verification errors - xfs: check xfarray iteration errors when committing unlinked inode lists - xfs: check v5 superblock features early - ceph: Remove ceph_writepage() - ceph: Use a folio in ceph_page_mkwrite() - ceph: Convert ceph_find_incompatible() to take a folio - ceph: Convert writepage_nounlock() to write_folio_nounlock() - ceph: fix writeback_count leak in write_folio_nounlock() - ceph: avoid fs reclaim while using current->journal_info - ceph: fix hanging __ceph_get_caps() with stale mds_wanted - libceph: Amend checking to fix `make W=1` build breakage - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159) - mm/khugepaged: guard is_zero_pfn() calls with pte_present() - userfaultfd: prevent registration of special VMAs (CVE-2026-68166) - libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082) - net/sched: serialize qdisc_rtab_list against concurrent get/put (CVE-2026-68138) - super: remove pointless s_root checks - super: skip dying superblocks early - super: use a common iterator (Part 1) - super: use common iterator (Part 2) - fs/super: fix emergency thaw double-unlock of s_umount - super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132) - smb: move smb_version_values to common/smbglob.h - smb: move get_rfc1002_len() to common/smbglob.h - smb/server: rename include guard in smb_common.h - ksmbd: rename smb2_get_msg to smb_get_msg - smb/server: fix minimum SMB1 PDU size - smb/server: fix minimum SMB2 PDU size - ksmbd: validate minimum PDU size for transform requests (CVE-2026-68431) - eventpoll: pin files while checking reverse paths - tcp: Pass flags to __tcp_send_ack - tcp: fast path functions later - tcp: reorganize tcp_sock_write_txrx group for variables later - tcp: challenge ACK for non-exact RST in SYN-RECEIVED (CVE-2026-68118) - iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace - btrfs: add debug build only WARN - btrfs: add space_info argument to btrfs_chunk_alloc() - btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() - btrfs: zoned: fix missing chunk metadata reservation - [amd64] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (CVE-2026-74517) - [arm64] ASoC: tas2562: Validate values for volume writes - ata: libata-scsi: terminate deferred commands on time out - igc: remove napi_synchronize() in igc_down() - ksmbd: conn lock to serialize smb2 negotiate - ksmbd: reject repeated SMB2 NEGOTIATE requests (CVE-2026-74494) - net: pktgen: fix code style (WARNING: Block comments) - net: pktgen: fix proc entry use-after-free (CVE-2026-74479) - binfmt_misc: don't leak the user namespace when the mount fails (CVE-2026-74483) - fsnotify, lsm: Decouple fsnotify from lsm - fsnotify: opt-in for permission events at file open time - fs: don't block write during exec on pre-content watched files - binfmt_misc: restore write access when removing an entry (CVE-2026-74487) - vrf: Make pcpu_dstats update functions available to other modules. - vxlan: Handle stats using NETDEV_PCPU_STAT_DSTATS. - vxlan: use pskb_network_may_pull() for transmit path header pulls (CVE-2026-74474) - ice: fix VF interrupts cleanup - include/linux/fs.h: add inode_lock_killable() - smb: client: fix race with fallocate(2) and AIO+DIO - cifs: add fscache_resize_cookie() to cifs_setsize() - can: rcar_canfd: change the initializing flow for clocks and resets - drm/amd/pm: Use same metric table for APU - drm/amd/pm: Use macro to initialize metrics table - drm/amd/pm: fix torn gpu metrics reads - drm/amdgpu: remove unused function parameter - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini - drm/amd/pm: adjust the visibility of pp_table sysfs node - drm/amd/pm: fix pptable use-after-free (CVE-2026-74450) - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684) - drm/vmwgfx: take fman->lock around fence list mutation in fifo_down - ring-buffer: Simplify functions with __free(kfree) to free allocations - ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() (CVE-2026-74602) - mm/pagewalk: split walk_page_range_novma() into kernel/user parts - mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF (CVE-2026-74672) - mm/ptdump: always stabilise against page table freeing using init_mm (CVE-2026-74599) - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (CVE-2026-74607) - ring-buffer: Simplify ring_buffer_read_page() with guard() - ring-buffer: Make ring_buffer_{un}map() simpler with guard(mutex) - ring-buffer: Prevent resizing of persistent ring buffer - [amd64] x86/mce: Remove __mcheck_cpu_init_early() - [amd64] x86/mce: Set CR4.MCE last during init - [amd64] x86/mce: Set up the polling timer before CMCI discovery - [amd64] ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup - net/x25: fix use-after-free of the socket by its timers (CVE-2026-74628) - [arm64] tegra: Add EL2 virtual timer interrupt for Tegra194 - crypto: ccm - Set rfc4309 maxauthsize from child - netfilter: ipset: fix refcount race between list:set GC and swap - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path - netfilter: flowtable: publish GC-visible tuple last - netfilter: ipset: fix list type element drift bug - netfilter: ipset: let destroy callbacks adjust ext mem size - ipvlan: inherit needed_headroom and needed_tailroom from phy_dev - macvlan: inherit needed_headroom and needed_tailroom from lowerdev - veth: fix queue index used to wake the peer txq in veth_poll - tcp: fix icsk_ack.ato bitfield overflow - net: packet: fix wrong transport_header when sending VLAN-tagged frame - net/tls: Fail tls_sw_splice_read() after a failed async decrypt - af_packet: Don't send zero-byte data in tpacket_snd(). - net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain - net/sched: cls_u32: skip hash tables in u32_bind_class() - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG - net/sched: cls_bpf: reject dev-bound programs bound to a different device - drm/xe/oa: Fix sync entry leak on OA config emit failure - erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms - perf: Unify perf_event_free_task() / perf_event_exit_task_context() - perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637) - fs: unlock the superblock during iterate_supers_type - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone - net: harmonize tstats and dstats - ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS - ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() - ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601) - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r - net: ethernet: mtk_eth_soc: only use legacy mode on missing IRQ name - net: ethernet: mtk_eth_soc: improve support for named interrupts . [ Salvatore Bonaccorso ] * drivers/mmc/host: Enable MMC_ALCOR as module (Closes: #1142912) * drivers/misc/cardreader: Enable MISC_ALCOR_PCI as module (Closes: #1142912) linux (6.12.101-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.101 - [amd64] platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug - net: airoha: Move airoha_eth driver in a dedicated folder - net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() - bpf: Fix ld_{abs,ind} failure path analysis in subprogs (CVE-2026-53090) - netfilter: nft_counter: serialize reset with spinlock (CVE-2026-45897) - netfilter: nft_quota: use atomic64_xchg for reset - netfilter: nf_tables: revert commit_mutex usage in reset path (CVE-2026-45901) - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race - seqlock: Cure some more scoped_seqlock() optimization fails - seqlock: Allow KASAN to fail optimizing - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing - [amd64] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (CVE-2026-64561) - [amd64] KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN - [amd64] KVM: nVMX: Hide shadow VMCS right after VMCLEAR (CVE-2026-64562) - [amd64] KVM: x86/mmu: Fix use-after-free on vendor module reload - can: bcm: add locking when updating filter and timer values - can: bcm: fix CAN frame rx/tx statistics - can: bcm: extend bcm_tx_lock usage for data and timer updates - can: bcm: validate frame length in bcm_rx_setup() for RTR replies - can: bcm: add missing device refcount for CAN filter removal - can: bcm: fix stale rx/tx ops after device removal - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() - can: bcm: track a single source interface for ANYDEV timeout/throttle ops - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER - can: isotp: serialize TX state transitions under so->rx_lock - dmaengine: sh: rz-dmac: Move interrupt request after everything is set up - Revert "arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc" - [arm64,armhf] gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin - xprtrdma: Clear receive-side ownership pointers on release - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (CVE-2026-64565) - Input: ims-pcu - fix logic error in packet reset - [arm64] tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 - IB/mad: Drop unmatched RMPP responses before reassembly - mtd: mtdswap: remove debugfs stats file on teardown - mtd: nand: mtk-ecc: stop on ECC idle timeouts - btrfs: reject free space cache with more entries than pages - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() - RDMA/cma: Fix hardware address comparison length in netevent callback - RDMA/umem: Add pinned revocable dmabuf import interface - RDMA/irdma: Prevent rereg_mr for non-mem regions - RDMA/erdma: initialize ret for empty receive WR lists - [arm64] RDMA/hns: Fix potential integer overflow in mhop hem cleanup - RDMA/siw: publish QP after initialization - mtd: fix double free and WARN_ON in add_mtd_device() error paths - RDMA/irdma: Prevent overflows in memory contiguity checks - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert - wifi: cfg80211: cancel sched scan results work on unregister - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() - wifi: mac80211_hwsim: clamp virtio RX length before skb_put - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure - wifi: mac80211: fix fils_discovery double free on alloc failure - wifi: libertas: fix memory leak in helper_firmware_cb() - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() - wifi: cfg80211: pass net_device to .set_monitor_channel - wifi: cfg80211: define and use wiphy guard - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock - wifi: nl80211: free RNR data on MBSSID mismatch - wifi: cfg80211: derive S1G beacon TSF from S1G fields - wifi: nl80211: validate nested MBSSID IE blobs - wifi: cfg80211: validate PMSR measurement type data - wifi: cfg80211: validate PMSR FTM preamble range - wifi: cfg80211: reject unsupported PMSR FTM location requests - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock - wifi: brcmfmac: initialize SDIO data work before cleanup - wifi: cfg80211: bound element ID read when checking non-inheritance - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() - ASoC: cs42l43: Correct report for forced microphone jack - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup - [arm64] firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF - ipv4: fib: free fib_alias with kfree_rcu() on insert error path - net/iucv: take a reference on the socket found in afiucv_hs_rcv() - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() - scsi: core: wake eh reliably when using scsi_schedule_eh - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered - ata: sata_dwc_460ex: use platform_get_irq() - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning - [amd64] accel/ivpu: Fix wrong register read in LNL failure diagnostics - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC - Bluetooth: qca: fix NVM tag length underflow in TLV parser - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds - Bluetooth: hci_qca: Clear memdump state on invalid dump size - smb/client: handle overlapping allocated ranges in fallocate - [amd64] drm/i915/gt: use correct selftest config symbol - [powerpc*] 85xx: Add fsl,ifc to common device ids - [powerpc*] time: Prepare to stop elapsing in dynticks-idle - [powerpc*] vtime: Initialize starttime at boot for native accounting - bpf, sockmap: Reject unhashed UDP sockets on sockmap update - [s390x] checksum: Fix csum_partial() without vector facility - [riscv64] hwprobe: Avoid uninitialized read in hwprobe_get_cpus() - can: j1939: fix lockless local-destination check - drm/xe/wopcm: fix WOPCM size for LNL+ - smb: move some duplicate definitions to common/cifsglob.h - ksmbd: pin conn during async oplock break notification - ksmbd: validate compound request size before reading StructureSize2 - net/sched: act_tunnel_key: Defer dst_release to RCU callback - sctp: fix auth_hmacs array size in struct sctp_cookie - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n - usb: core: sysfs: add lock to bos_descriptors_read() - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() - usb: core: port: Deattach Type-C connector on component unbind - USB: storage: add NO_ATA_1X quirk for Longmai USB Key - usb: chipidea: fix usage_count leak when autosuspend_delay is negative - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback - usb: gadget: f_midi: cancel pending IN work before freeing the midi object - usb: gadget: printer: fix infinite loop in printer_read() - USB: gadget: snps-udc: fix device name leak on probe failure - USB: gadget: fsl-udc: fix device name leak on probe failure - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer - USB: serial: ftdi_sio: add support for E+H FXA291 - USB: serial: io_edgeport: cap received transmit credits - USB: serial: keyspan_pda: fix data loss on receive throttling - USB: serial: option: add TDTECH MT5710-CN - crypto: rsa-pkcs1pad: Don't WARN on an empty digest - Revert "drm/amd/display: Add missing kdoc for ALLM parameters" - [riscv64] KVM: Serialize virtual interrupt pending state updates - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - firewire: net: Fix fragmented datagram reassembly - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read - wifi: carl9170: fix OOB read from off-by-two in TX status handler - wifi: carl9170: fix buffer overflow in rx_stream failover path - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps - btrfs: free mapping node on duplicate reloc root insert - ASoC: tas2781: bound firmware description string parsing - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (CVE-2025-40098) - ALSA: hda: cs35l41: validate and free ACPI mute object - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI - ASoC: cs35l56: Don't use devres to unregister component - ASoC: cs35l56: Fix potential probe() deadlock - ASoC: cs35l56: Use complete_all() to signal init_completion - wifi: iwlwifi: mvm: validate SAR GEO response payload size - wifi: iwlwifi: mvm: fix read in wake packet notification handler - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC - hwmon: (asus-ec-sensors) fix EC read intervals - hwmon: (asus-ec-sensors) add missed handle for ENOMEM - smb: client: validate DFS referral PathConsumed - hwmon: occ: validate poll response sensor blocks - regulator: mt6358: use regmap helper to read fixed LDO calibration - Bluetooth: btusb: validate Realtek vendor event length - netlink: specs: rt-link: convert bridge port flag attributes to u8 - net/packet: avoid fanout hook re-registration after unregister - bonding: fix devconf_all NULL dereference when IPv6 is disabled - rds: drop incoming messages that cross network namespace boundaries - gtp: parse extension headers before reading inner protocol - [arm64] dpaa2-eth: put MAC endpoint device on disconnect - [amd64] iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() - wifi: mac80211: tear down new links on vif update error path - nfp: Check resource mutex allocation - wan: wanxl: Only reset hardware after BAR mapping - wifi: mwifiex: bound uAP association event IEs to the event buffer - [amd64] iommu/amd: Bound the early ACPI HID map - [amd64] iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() - wifi: mac80211: recalculate TIM when a station enters power save - pds_core: reject component parameter in legacy firmware update - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN - net: txgbe: fix FDIR filter leak on remove - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid - pds_core: fix deadlock between reset thread and remove - pds_core: fix use-after-free on workqueue during remove - pds_core: yield the CPU while waiting for the adminq to drain - pds_core: order completion reads after the ownership check - pds_core: fix auxiliary device add/del races - pds_core: check for workqueue allocation failure - sctp: validate stream count in sctp_process_strreset_inreq() - net: mctp i3c: clean up notifier and buses if driver register fails - tls: device: push pending open record on splice EOF - gtp: check skb_pull_data() return in gtp1u_send_echo_resp() - nexthop: initialize extack in nh_res_bucket_migrate() - tipc: fix infinite loop in __tipc_nl_compat_dumpit - wifi: mt76: mt7925: guard link STA in decap offload - wifi: mt76: mt7915: guard HE capability lookups - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() - wifi: mt76: mt7925: fix crash in reset link replay - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning - ovl: fix trusted xattr escape prefix matching - amt: re-read skb header pointers after every pull - amt: make the head writable before rewriting the L2 header - net: bridge: vlan: fix vlan range dumps starting with pvid - net: hsr: fix memory leak on slave unregistration by removing synced VLANs - net: dpaa: fix mode setting - sctp: auth: verify auth requirement when auth_chunk is NULL - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets - iomap: correct the range of a partial dirty clear - tipc: fix u16 MTU truncation in media and bearer MTU validation - net: stmmac: fix l3l4 filter rejecting unsupported offload requests - net: stmmac: reset residual action in L3L4 filters on delete - net: stmmac: enable the MAC on link up for all supported speeds - net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM - octeontx2-vf: set TC flower flag on MCAM entry allocation - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup - ppp: use IFF_NO_QUEUE in virtual interfaces - ppp: convert to percpu netstats - ppp: enable TX scatter-gather - ppp: annotate data races in ppp_generic - [amd64,arm64] hinic: remove unused ethtool RSS user configuration buffers - net: qrtr: restrict socket creation to the initial network namespace - dpll: add clock quality level attribute and op - net/mlx5: DPLL, Add clock quality level op implementation - net/mlx5: Remove newline at the end of a netlink error message - net/mlx5: Refactor EEPROM query error handling to return status separately - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule - net/mlx5e: Report zero bandwidth for non-ETS traffic classes - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation - octeontx2-pf: tc: fix egress ratelimiting - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV - ice: fix LAG recipe to profile association - rds: tcp: unregister sysctl before tearing down listen socket - net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() - [arm64] drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers - [arm64] drm/dp/mst: fix buffer overflows in sideband chunk accumulation - [arm64] drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 - drm/nouveau: fix reversed error cleanup order in ucopy functions - drm/displayid: fix Tiled Display Topology ID size - [amd64] drm/i915/gem: Add missing nospec on parallel submit slot - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() - drm/radeon: fix r100_copy_blit for large BOs - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds - drm/amdkfd: Use kvcalloc to allocate arrays - drm/amdkfd: Check bounds in allocate_event_notification_slot - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference - drm/virtio: bound EDID block reads to the response buffer - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() - [amd64] drm/i915: Return NULL on error in active_instance - [amd64] drm/i915/bios: range check LFP Data Block panel_type2 - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() - [amd64] drm/i915/gem: Do not leak siblings[] on proto context error - [amd64] drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU - drm/amd/pm: fix smu14 power limit range calculation - drm/gfx10: Program DB_RING_CONTROL - [arm64] drm/panthor: return error on truncated firmware - drm/amdgpu: Fix VFCT bus number matching with soft filter - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) - drm/amd/display: set new_stream to NULL after release - drm/amd/display: dce100: skip non-DP stream encoders for DP MST - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved - drm/vmwgfx: Validate vmw_surface_metadata::array_size - drm/vc4: Prevent shader BO mappings from becoming writable - media: airspy: Return queued buffers on start_streaming() failure - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure - media: cec: seco: unregister adapter on IR probe failure - media: cedrus: clean up media device on probe failure - media: cedrus: Fix missing cleanup in error path - media: cedrus: skip invalid H.264 reference list entries - media: chips-media: wave5: Move src_buf Removal to finish_encode - media: cx231xx: fix devres lifetime - media: cx23885: add ioremap return check and cleanup - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges - media: marvell-cam: fix missing pci_disable_device() on remove - media: meson: vdec: Fix memory leak in error path of vdec_open - media: msi2500: Return queued buffers on start_streaming() failure - media: nuvoton: npcm-video: fix error handling in npcm_video_init() - media: nuvoton: npcm-video: fix memory leaks in probe and remove - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path - media: nxp: imx8-isi: Fix potential out-of-bounds issues - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding - media: pci: dm1105: Free allocated workqueue - media: pwc: Drain fill_buf on start_streaming() failure - media: pwc: Return queued buffers on start_streaming() failure - media: qcom: camss: Fix RDI streaming for CSID GEN2 - media: radio-si476x: Unregister v4l2_device on probe failure - media: rtl2832: fix use-after-free in rtl2832_remove() - media: rtl2832_sdr: Return queued buffers on start_streaming() failure - media: saa7134: Fix a possible memory leak in saa7134_video_init1 - media: stm32: dcmi: unregister notifier on probe failure - media: sun4i-csi: Return queued buffers on start_streaming() failure - media: tegra-video: vi: fix invalid u32 return value in format lookup - media: ti: vpe: unwind v4l2 device registration on probe error - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() - media: v4l2-ctrls: validate HEVC active reference counts - media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely - media: vb2: use ssize_t for vb2_read/vb2_write - media: vidtv: fix reference leak on failed device registration - media: vimc: fix reference leak on failed device registration - media: vivid: add vivid_update_reduced_fps() - media: vivid: check for vb2_is_busy() when toggling caps - media: vivid: fix cleanup bugs in vivid_init() - media: vpif_capture: fix OF node reference imbalance - ALSA: seq: close a re-opened queue timer in the destructor - ALSA: timer: drain a slave's callback before its master detaches it - ALSA: timer: don't re-enter an instance callback that is still running - wifi: ath6kl: fix OOB access from firmware ADDBA window size - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper - wifi: wilc1000: validate assoc response length before subtracting header - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses - wifi: brcmfmac: make release_scratchbuffers idempotent - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() - staging: rtl8723bs: fix inverted HT40 secondary channel offset - Bluetooth: hci_sync: Protect UUID list traversal - Bluetooth: RFCOMM: Fix session UAF in set_termios - exec: fix unsigned loop counter wrap in transfer_args_to_stack() - binfmt_misc: set have_execfd only once the interpreter is opened - objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL - firmware: stratix10-svc: fix memory leaks and list corruption bugs - [amd64] x86/boot/compressed: Disable jump tables - [amd64] comedi: comedi_parport: deal with premature interrupt - uio_hv_generic: Bind to FCopy device by default - serial: sc16is7xx: implement gpio get_direction() callback - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Closes: #1143721) - mei: bus: access mei_device under device_lock on cleanup - [amd64] intel_th: fix MSC output device reference leak - misc: nsm: only unlock nsm_dev on post-lock error paths - misc: nsm: pin the module while the device is open - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev - tracing: Fix resource leak on mmiotrace trace_pipe close - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() - tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() - [arm64] syscall: Ensure saved x0 is kept in-sync with tracer updates - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" - mptcp: decrement subflows counter on failed passive join - mptcp: only set DATA_FIN when a mapping is present - sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564) - sctp: avoid auth_enable sysctl UAF during netns teardown - sctp: close UDP tunnel sockets during netns teardown - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() - ceph: fix refcount leak in ceph_readdir() - libceph: bound get_version reply decode to front len - libceph: Fix multiplication overflow in decode_new_up_state_weight() - libceph: guard missing CRUSH type name lookup - libceph: refresh auth->authorizer_buf{,_len} after authorizer update - libceph: Reject monmaps advertising zero monitors - libceph: reject zero bucket types in crush_decode - libceph: remove debugfs files before client teardown - amt: fix use-after-free in AMT delayed works - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP - binfmt_elf_fdpic: only honour the first PT_INTERP - fs: preserve ACL_DONT_CACHE state in forget_cached_acl() - fscrypt: Add missing superblock check in find_or_insert_direct_key() - ftrace: Add global mutex to serialize trace_parser access - iomap: fix out-of-bounds bitmap_set() with zero-length range - [amd64] iommu/vt-d: Disallow SVA if page walk is not coherent - phonet: pep: fix use-after-free in pep_get_sb() - vxlan: require CAP_NET_ADMIN in the device netns for changelink - net: slip: serialize receive against buffer reallocation - geneve: require CAP_NET_ADMIN in the device netns for changelink - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() - net/iucv: fix use-after-free of a severed iucv_path - net/mlx5e: Use sender devcom for MPV master-up - net/x25: fix use-after-free in x25_kill_by_neigh() - net: gro: fix double aggregation of flush-marked skbs - net: hip04: fix RX buffer leak on build_skb failure - proc: Fix broken error paths for namespace links - ice: fix PTP Call Trace during PTP release - rbd: Reset positive result codes to zero in object map update path - ksmbd: defer destroy_previous_session() until after NTLM authentication - ice: reject out-of-range ptype in ice_parser_profile_init - ice: use READ_ONCE() to access cached PHC time - ila: reload IPv6 header after pskb_may_pull in checksum adjust - mac802154: hold an interface reference across the scan worker - mac802154: llsec: reject frames shorter than the authentication tag - mctp: serial: handle zero-length frames to prevent rx buffer overflow - openvswitch: fix GSO userspace truncation underflow - pppoe: reload header pointer after dev_hard_header() - rtase: Workaround for TX hang caused by hardware packet parsing - tcp: initialize standalone TCP-AO response padding - tipc: clear sock->sk on the failed-insert path in tipc_sk_create() - vsock/virtio: collapse receive queue under memory pressure - vxlan: mdb: Fix source list corruption on a failed replace - drm/amd/pm: fix amdgpu_pm_info power display units - drm/amd/pm: make pp_features read-only when scpm is enabled - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx8: drop unecessary BUG_ON() - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/vce: fix integer overflow in image size - drm/amdgpu/vcn4: avoid rereading IB param length - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() - drm/amdgpu: fix division by zero with invalid uvd dimensions - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd - drm/amdgpu: fix aperture mapping leak - drm/amd/pm: fix smu13 power limit range calculation - bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (CVE-2026-53078) - net: qrtr: ns: Raise node count limit to 512 - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL - ksmbd: bound DACL dedup walk to copied ACEs - ksmbd: validate ACE size against SID sub-authorities - fscrypt: Avoid dynamic allocation in fscrypt_get_devices() - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources - io_uring/rw: fix missing ERESTARTSYS conversion in read paths - net: pcs: xpcs: fix SGMII state reading - gve: fix Rx queue stall on alloc failure - mm/damon/core: validate ranges in damon_set_regions() - mm/damon/core: disallow overlapping input ranges for damon_set_regions() - iommufd: Reject invalid read count in iommufd_fault_fops_read() - iommufd: Break the loop on failure in iommufd_fault_fops_read() (CVE-2026-64290) - iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (CVE-2026-64280) - i2c: davinci: Unregister cpufreq notifier on probe failure - VFS/audit: introduce kern_path_parent() for audit - audit: widen ino fields to u64 - audit: use 'unsigned int' instead of 'unsigned' - audit: fix recursive locking deadlock in audit_dupe_exe() - i2c: i801: fix hardware state machine corruption in error path (CVE-2026-64205) - ALSA: hda: conexant: Remove mic bias threshold override - ALSA: hda: Fix cached processing coefficient verbs - rxrpc: Pull out certain app callback funcs into an ops table - rxrpc: serialize kernel accept preallocation with socket teardown - xfs: factor out xfs_attr3_leaf_init - xfs: don't replace the wrong part of the cow fork - fbcon: Rename struct fbcon_ops to struct fbcon_par - fbcon: Use correct type for vc_resize() return value - rxrpc: Fix CPU time starvation in I/O thread - rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack - rxrpc: Use irq-disabling spinlocks between app and I/O thread - rxrpc: Fix notification vs call-release vs recvmsg - rxrpc: Fix socket notification race - tipc: restrict socket queue dumps in enqueue tracepoints - vduse: Use fixed 4KB bounce pages for non-4KB page size - vduse: remove unused vaddr parameter of vduse_domain_free_coherent - vduse: take out allocations from vduse_dev_alloc_coherent - VDUSE: avoid leaking information to userspace - octeontx2: Annotate mmio regions as __iomem - octeontx2-vf: clear stale mailbox IRQ state before request_irq() - octeontx2-pf: clear stale mailbox IRQ state before request_irq() - [arm64] dts: qcom: correct RBR opp entry - [arm64] dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable - ASoC: mediatek: mt8192: Check runtime resume during probe - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks - ASoC: mediatek: mt8183: Check runtime resume during probe - netfilter: nf_conntrack_sip: remove net variable shadowing - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it - netfilter: bitwise: rename some boolean operation functions - netfilter: nf_tables: Remove unused nft_reduce_is_readonly() - netfilter: nf_tables: remove register tracking infrastructure - netfilter: nft_fib: reject fib expression on the netdev egress hook - gpu: Move DRM buddy allocator one level up (part two) - gpu/buddy: bail out of try_harder when alignment cannot be honoured - NFSD: pass nfsd_file to nfsd_iter_read() - sunrpc: allocate a separate bvec array for socket sends - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow - remoteproc: xlnx: Check remote core state - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch - mm/sparse-vmemmap: fix vmemmap accounting underflow - landlock: Prepare to use credential instead of domain for fowner - landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages - mtd: maps: vmu-flash: fix fault in unaligned fixup - mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c - mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization - dma: dw-edma: Fix build warning in dw_edma_pcie_probe() - dmaengine: dw-edma: Fix confusing cleanup.h syntax - dmaengine: dw-edma-pcie: Reject devices without driver data - i2c: imx: separate atomic, dma and non-dma use case - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) - xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] - xfrm: nat_keepalive: avoid double free on send error - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect - tcp: Decrement tcp_md5_needed static branch - nvmet: Introduce nvmet_req_transfer_len() - nvmet-auth: reject short AUTH_RECEIVE buffers - ovl: use linked upper dentry in copy-up tmpfile - block: add helper add_disk_final() - block: remove redundant GD_NEED_PART_SCAN in add_disk_final() - dm-integrity: fix leaking uninitialized kernel memory - cleanup: add a scoped version of CLASS() - cleanup: fix scoped_class() - cred: add kernel_cred() helper - cred: add scoped_with_kernel_creds() - dm: avoid leaking the caller's thread keyring via the table device file - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() - net: mana: Validate the packet length reported by the NIC - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink - gve: fix header buffer corruption with header-split and HW-GRO - gpio: mt7621: avoid corruption of shared interrupt trigger state - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() - ipmi: fix refcount leak in i_ipmi_request() - net/mlx5: HWS, Rearrange to prevent forward declaration - net/mlx5: HWS, fix matcher leak on resize target setup failure - octeontx2-pf: fix SQB pointer leak on init failure - ata: libata-core: Reject an invalid concurrent positioning ranges count - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list - net: macb: drop in-flight Tx SKBs on close - net: ipa: fix SMEM state handle leaks in SMP2P init - Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections - Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately - afs: Improve server refcount/active count tracing - afs: Make afs_lookup_cell() take a trace note - afs: Drop the net parameter from afs_unuse_cell() - rxrpc: Allow the app to store private data on peer structs - afs: Use the per-peer app data provided by rxrpc - afs: Fix afs_server ref accounting - afs: Simplify cell record handling - afs: Fix dynamic lookup to fail on cell lookup failure - afs: Fix lack of locking around modifications of net->cells_dyn_ino - USB: gadget: Use str_enable_disable-like helpers - USB: gadget: fsl-udc: fix dev_printk() device - usb: musb: omap2430: clean up probe error handling - usb: musb: omap2430: Do not put borrowed of_node in probe - net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query - gpu: Fix uninitialized buddy for built-in drivers - rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link - rxrpc: Fix locking issues with the peer record hash - wifi: nl80211: fix nl80211_start_radar_detection return value - net: ethernet: Remove accidental duplication in Kconfig file - afs: Set vllist to NULL if addr parsing fails - dpll: fix clock quality level reporting - afs: Fix delayed allocation of a cell's anonymous key - afs: handle CB.InitCallBackState3 requests without a server record - Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK - Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() - afs: Fix uninit var in afs_alloc_anon_key() - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Add sparse annotation for RCU." (context changes) * rhashtable: clear stale iter->p on table restart (CVE-2026-64563) linux (6.12.100-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.97 - smb/server: do not require delete access for non-replacing links - [amd64] iommu/vt-d: Clear Present bit before tearing down context entry (CVE-2026-45944) - tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). - bpf: Support for hardening against JIT spraying (CVE-2026-64508) - [amd64] x86/bugs: Enable IBPB flush on BPF JIT allocation (CVE-2026-64507) - bpf: Restrict JIT predictor flush to cBPF - bpf: Skip redundant IBPB in pack allocator - bpf: Prefer packs that won't trigger an IBPB flush on allocation - bpf: Prefer dirty packs for eBPF allocations - sched/fair: Only update stats for allowed CPUs when looking for dst group - crypto: algif_skcipher - force synchronous processing - [arm64] KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287) - [arm64] KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (CVE-2026-64286) - iommu: Pass old domain to set_dev_pasid op - [amd64] iommu/vt-d: Cleanup intel_context_flush_present() - [amd64] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry - timekeeping: Register default clocksource before taking tk_core.lock - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534) - nvmet-tcp: Fix potential UAF when ddgst mismatch (CVE-2026-64535) - vsock/virtio: fix zerocopy completion for multi-skb sends (CVE-2026-53365) - vsock/virtio: bind uarg before filling zerocopy skb (CVE-2026-63970) - [armhf] crypto: sun4i-ss - Remove insecure and unused rng_alg - [amd64] iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 - [amd64] iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 - [amd64] x86/mm: Fix check/use ordering in switch_mm_irqs_off() - net: dropreason: Gather SOCKET_ drop reasons. - af_unix: Set drop reason in unix_release_sock(). - af_unix: Set drop reason in manage_oob(). - af_unix: Set drop reason in unix_stream_read_skb(). - af_unix/scm: fix whitespace errors - af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg(). - af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). - af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). - af_unix: Drop all SCM attributes for SOCKMAP. (CVE-2026-53005) - crypto: crypto4xx - Remove ahash-related code - crypto: crypto4xx - Remove insecure and unused rng_alg - crypto: hisi-trng - Remove crypto_rng interface - time/jiffies: Register jiffies clocksource before usage - time/jiffies: Change register_refined_jiffies() to void __init - media: uvcvideo: Use hw timestaming if the clock buffer is full - media: uvcvideo: Avoid partial metadata buffers - media: uvcvideo: Fix buffer sequence in frame gaps - media: uvcvideo: Fix dev_sof filtering in hw timestamp - media: uvcvideo: Do not add clock samples with small sof delta - media: uvcvideo: Relax the constrains for interpolating the hw clock - media: uvcvideo: Fix sequence number when no EOF - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties - dt-bindings: power: imx93: Add MIPI PHY power domain - serial: msm: Disable DMA for kernel console UART - serial: max310x: implement gpio_chip::get_direction() - serial: 8250_omap: clear rx_running on zero-length DMA completes - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) - afs: Fix netns teardown to cancel the preallocation charger - afs: fix NULL pointer dereference in afs_get_tree() - afs: Fix further netns teardown to cancel the preallocation charger - fbcon: fix NULL pointer dereference for a console without vc_data - clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() - drm/rockchip: Test for imported buffers with drm_gem_is_imported() - drm/tidss: Drop extra drm_mode_config_reset() call - drm/gpuvm: Do not prepare NULL objects - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() - drm/radeon: fix integer overflow in radeon_align_pitch() - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure - libbpf: Report error when a negative kprobe offset is specified - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro - Documentation: proc: fix section numbering in table of contents - [arm64] dts: rockchip: Fix gmac0 reset pin for NanoPi R5S - [arm64] dts: qcom: sc8180x: Fix phy simple_bus_reg warning - [arm64] dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning - wifi: cfg80211: fix grammar in MLO group key error message - [arm64] tegra: Fix Tegra234 MGBE PTP clock - dt-bindings: pinctrl: nvidia,tegra234: Add missing required block - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() - wifi: rtw89: Correct data type for scan index to avoid infinite loop - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer - kconfig: fix potential NULL pointer dereference in conf_askvalue - soc: xilinx: Shutdown and free rx mailbox channel - wifi: ath9k: fix OOB access from firmware tx status queue ID - [armhf] dts: am335x-sl50: Fix audio bitclock and frame master endpoint - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure - media: cedrus: Fix failure to clean up hardware on probe failure - media: v4l2-common: Add YUV24 format info - memory: tegra: Wire up system sleep PM ops - [amd64] crypto: qat - fix heartbeat error injection - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path - drm/gpuvm: take refcount on DRM device - [arm64] dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc - [arm64] dts: imx8x-colibri: Correct SODIMM PAD settings - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). - [amd64] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one - crypto: atmel-sha204a - fix blocking and non-blocking rng logic - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (CVE-2026-64544) - dlm: fix add msg handle in send_queue ordered - nilfs2: fix backing_dev_info reference leak - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite - [amd64] iommu/amd: Fix a stale comment about which legacy mode is user visible - [arm64] dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host - clk: scmi: Fix clock rate rounding - [arm64] dts: qcom: kodiak: Fix ICE reg size - [arm64] dts: qcom: sm8450: Fix ICE reg size - [arm64] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() - [arm64] drm/hisilicon/hibmc: use clock to look up the PLL value - evm: terminate and bound the evm_xattrs read buffer - thermal: hwmon: Fix critical temperature attribute removal - clk: scpi: Unregister child clock providers on remove - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() - crypto: ccp - Treat zero-length cert chain as query for blob lengths - spi: hisi-kunpeng: Use dev_err_probe() for host registration failure - net/sched: sch_htb: do not change sch->flags in htb_dump() - net/sched: sch_htb: annotate data-races (I) - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD - IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier - RDMA/hns: Fix arithmetic overflow in calc_hem_config() - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference - RDMA/srpt: fix integer overflow in immediate data length check - [arm64] RDMA/hns: Initialize seqfile before creating file - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() - media: atomisp: gc2235: fix UAF and memory leak - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() - firmware: arm_scmi: Read sensor config as 32-bit value - sysfs: clamp show() return value in sysfs_kf_read() - bitops: use common function parameter names - regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions - net/sched: sch_drr: annotate data-races around cl->deficit - media: rockchip: rga: fix too small buffer size - [arm64] firmware: arm_scmi: Fix OOB in scmi_power_name_get() - [arm64] dts: qcom: sc7180: Add power-domain and iface clk for ice node - [arm64] dts: qcom: kodiak: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8450: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8650: Add power-domain and iface clk for ice node - tracing: Bound synthetic-field strings with seq_buf - writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() - device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() - driver core: Use mod_delayed_work to prevent lost deferred probe work - Revert "treewide: Fix probing of devices in DT overlays" - cpufreq: Documentation: fix sampling_down_factor range - cpufreq: conservative: Simplify frequency limit handling - pwm: imx27: Fix variable truncation in .apply() - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed - bus: sunxi-rsb: Always check register address validity - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs - RDMA/rxe: Fix a use-after-free problem in rxe_mmap - IB/mlx4: Fix refcount leak in add_port() error path - [arm64] RDMA/hns: Fix warning in poll cq direct mode - [arm64] RDMA/hns: Fix log flood after cmd_mbox failure - RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup - PM: sleep: Use complete() in device_pm_sleep_init() - jiffies: Define secs_to_jiffies() - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() - driver core: Guard deferred probe timeout extension with delayed_work_pending() - mtd: spi-nor: Drop duplicate Kconfig dependency - ALSA: seq: midi: Serialize output teardown with event_input - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table - pinctrl: cs42l43: Fix polarity on debounce - nvmet-tcp: fix page fragment cache leak in error path - nvme-multipath: fix flex array size in struct nvme_ns_head - workqueue: drop spurious '*' from print_worker_info() fn declaration - ipv6: guard against possible NULL deref in __in6_dev_stats_get() - net/sched: cls_bpf: prevent unbounded recursion in offload rollback - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove - gpu: host1x: Allow entries in BO caches to be freed - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() - gpu: host1x: Fix iommu_map_sgtable() return value check - drm/tegra: Fix iommu_map_sgtable() return value check - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada - libbpf: Harden parse_vma_segs() path parsing - bpftool: Fix typo in struct_ops map FD generation for light skeleton - libbpf: Fix UAF in strset__add_str() - dax/kmem: account for partial discontiguous resource upon removal - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() - ocfs2: don't BUG_ON an invalid journal dinode - ocfs2: kill osb->system_file_mutex lock - crypto: hisilicon/qm - disable error report before flr - crypto: tegra - Fix dma_free_coherent size error - crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm - sched/deadline: Always stop dl-server before changing parameters - sched/deadline: Reject debugfs dl_server writes for offline CPUs - [arm64] drm/msm/dp: fix HPD state status bit shift value - [arm64] drm/msm/dp: Fix the ISR_* enum values - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info - RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe - RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path - media: qcom: venus: drop extra padding in NV12 raw size calculation - media: qcom: venus: relax encoder frame/blur dimension steps on v4 - media: qcom: venus: relax encoder frame/blur step size on v6 - amba: use generic driver_override infrastructure - cdx: use generic driver_override infrastructure - Drivers: hv: vmbus: use generic driver_override infrastructure - rpmsg: use generic driver_override infrastructure - md/raid10: reset read_slot when reusing r10bio for discard - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback - ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble - NFSD: Fix delegation reference leak in nfsd4_revoke_states - HID: wiimote: Fix table layout and whitespace errors - ata: libata: Fix ata_exec_internal() - nvdimm/btt: Handle preemption in BTT lane acquisition - scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" - scsi: pm8001: Fix error code in non_fatal_log_show() - scsi: ufs: Fix wrong value printed in unexpected UPIU response case - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs - mm/fake-numa: fix under-allocation detection in uniform split - ext2: fix ignored return value of generic_write_sync() - sched: restore timer_slack_ns when resetting RT policy on fork - driver core: Use system_percpu_wq instead of system_wq - tick/sched: Fix TOCTOU in nohz idle time fetch - configfs_lookup(): don't leave ->s_dentry dangling on failure - drm/amdgpu: set sub_block_index for mca ras sub-blocks - bpftool: Use libbpf error code for flow dissector query - vhost: fix vhost_get_avail_idx for a non empty ring - [amd64] perf/x86/amd/core: Always use the NMI latency mitigation - [amd64] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems - [amd64] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains - xfrm: fix NAT-related field inheritance in SA migration - drm/amdkfd: always resume_all after suspend_all - ocfs2: rebase copied fsdlm LVB pointers in locking_state - ocfs2: fix buffer head management in ocfs2_read_blocks() - ocfs2: reject FITRIM ranges shorter than a cluster - ocfs2/dlm: require a ref for locking_state debugfs open - ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures - netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - netfilter: synproxy: drop packets if timestamp adjustment fails - netfilter: synproxy: adjust duplicate timestamp options - netfilter: synproxy: fix unaligned memory access in timestamp adjustment - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock - netfilter: conntrack: revert ct extension genid infrastructure - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() - RDMA/irdma: Fix OOB read during CQ MR registration - RDMA/irdma: Initialize iwmr->access during MR registration - [arm64] dts: imx95: Correct PCIe outbound address space configuration - [arm64] dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well - RDMA/siw: Fix endpoint/socket association handling - bpf: Check tail zero of bpf_prog_info - bpf: Update transport_header when encapsulating UDP tunnel in lwt - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication - wifi: wcn36xx: fix OOB read from short trigger BA firmware response - ALSA: seq: Fix partial userptr event expansion - [riscv64] cpu_ops: Change return value type of cpu_is_stopped() to bool - [riscv64] stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe - ALSA: seq: Clear variable event pointer on read - ACPI: IPMI: Fix message kref handling on dead device - cpufreq: Documentation: fix conservative governor freq_step description - thermal: testing: reject missing command arguments - IB/mlx5: Don't take the rereg_mr fallback without a new translation - IB/mlx5: Properly support implicit ODP rereg_mr - spi: ep93xx: fix double-free of zeropage on DMA setup failure - [amd64] ASoC: amd: acp-sdw-sof: Bound DAI link iteration - firmware_loader: Fix recursive lock in device_cache_fw_images() - configfs: fix lockless traversals of ->s_children - watchdog: unregister PM notifier on watchdog unregister - scsi: target: Fix hexadecimal CHAP_I handling - scsi: target: Remove tcm_loop target reset handling - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() - hwspinlock: qcom: avoid uninitialized struct members - sched/fair: Fix cpu_util runnable_avg arithmetic - wifi: mt76: mt7925: clean up DMA on probe failure - wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links - wifi: mt76: mt7925: keep TX BA state in the primary WCID - wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX - wifi: mt76: fix argument to ieee80211_is_first_frag() - wifi: mt76: mt7915: fix potential tx_retries underflow - wifi: mt76: mt7921: fix potential tx_retries underflow - wifi: mt76: mt7925: fix potential tx_retries underflow - wifi: mt76: mt7996: fix potential tx_retries underflow - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() - fbdev: sm501fb: Fix buffer errors in OF binding code - hwmon: (it87) Clamp negative values to zero in set_fan() - btrfs: zoned: don't account data relocation space-info in statfs free space - btrfs: fix deadlock cloning inline extent when using flushoncommit - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified - NFSD: Handle layout stid in nfsd4_drop_revoked_stid() - spi: meson-spifc: fix runtime PM leak on remove - ASoC: codecs: aw88261: fix incorrect masks for boost regs - vduse: hold vduse_lock across IDR lookup in open path - vhost/vdpa: validate virtqueue index in mmap and fault paths - virtio_console: read size from config space during device init - vduse: Requeue failed read to send_list head - vhost/net: complete zerocopy ubufs only once - tools/virtio: check mmap return value in vringh_test - vdpa/octeon_ep: Fix PF->VF mailbox data address calculation - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails - bonding: 3ad: fix mux port state on oper down - ext4: fix kernel BUG in ext4_write_inline_data_end - ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT - of: cpu: add check in __of_find_n_match_cpu_property() - vfio/qat: fix f_pos race in qat_vf_resume_write() - bpf: Tighten cgroup storage cookie checks for prog arrays - ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() - [s390x] process: Fix kernel thread function pointer type - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (CVE-2026-64539) - Bluetooth: hci_core: Fix UAF in hci_unregister_dev() - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path - Bluetooth: hci: validate codec capability element length - Bluetooth: vhci: validate devcoredump state before side effects - fs: efs: remove unneeded debug prints - RDMA/mlx5: Remove DCT restrack tracking - RDMA/mlx5: Remove raw RSS QP restrack tracking - RDMA/mlx5: Fix undefined shift of user RQ WQE size - RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one - ASoC: codecs: hdac_hdmi: Validate written enum value - ASoC: fsl: fsl_audmix: Validate written enum values - ASoC: tegra: tegra210_ahub: Validate written enum value - net: dsa: qca8k: fix led devicename when using external mdio bus - net/sched: cls_flow: Dont expose folded kernel pointers - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). - bridge: cfm: reject invalid CCM interval at configuration time (CVE-2026-64537) - sctp: validate embedded address parameter length - net: pfcp: allocate per-cpu tstats for PFCP netdevs - net/sched: sch_hfsc: Don't make class passive twice - tipc: require net admin for TIPCv2 netlink mutators - tipc: prevent snt_unacked underflow on CONN_ACK - tipc: reject inverted service ranges from peer bindings - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index - crypto: cavium/cpt - fix DMA cleanup using wrong loop index - crypto: rng - Free default RNG on module exit - ALSA: seq: Fix kernel heap address leak in bounce_error_event() - spi: xilinx: use FIFO occupancy register to determine buffer size - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO - power: supply: core: fix supplied_from allocations - handshake: Require admin permission for DONE command - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net: mana: initialize gdma queue id to INVALID_QUEUE_ID - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check - net: ethernet: mtk_wed: fix loading WO firmware for MT7986 - bpf: Run generic devmap egress prog on private skb - net/mlx5: Check max_macs devlink param value against max capability - octeontx2-af: npc: Fix size of entry2cntr_map - net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() - net: wwan: t7xx: check skb_clone in control TX - dpll: add reference-sync netlink attribute - dpll: add reference sync get/set - dpll: Allow associating dpll pin with a firmware node - dpll: Add notifier chain for dpll events - dpll: Support dynamic pin index allocation - dpll: Enhance and consolidate reference counting logic - dpll: fix stale iteration in dpll_pin_on_pin_unregister() - dpll: send delete notification before unregister in on-pin rollback - dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() - dpll: guard sync-pair removal on full pin unregister - dpll: balance create/delete notifications in __dpll_pin_(un)register - landlock: Fix unmarked concurrent access to socket family - net: bcmgenet: Use weighted round-robin TX DMA arbitration - kcm: use WRITE_ONCE() when changing lower socket callbacks - netfilter: nf_conncount: callers must hold rcu read lock - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() - cifs: remove all cifs files before kill super - smb/client: always return a value for FS_IOC_GETFLAGS - bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket - udf: fix nls leak on udf_fill_super() failure - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check - [powerpc*] perf: fix preempt count underflow in fsl_emb_pmu_del - [powerpc*] powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down - [powerpc*] kexec: fix double get_cpu() imbalance in kexec_prepare_cpus - KEYS: Use acquire when reading state in keyring search - tipc: fix UAF in tipc_l2_send_msg() - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) - net: airoha: Introduce ndo_select_queue callback - net: airoha: Add sched ETS offload support - net: airoha: Fix always-true condition in PPE1 queue reservation loop - net: ethernet: oa_tc6: Remove FCS size in RX frame - ionic: Fix check in ionic_get_link_ext_stats - ksmbd: fix use-after-free in same_client_has_lease() - mfd: rsmu: Fix page register setup - mfd: cs42l43: Sanity check firmware size - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write - net/9p: fix race condition on rdma->state in trans_rdma.c - eventpoll: expand top-of-file overview / locking doc - eventpoll: rename attach_epitem() to ep_attach_file() - eventpoll: split ep_insert() into alloc + register stages - eventpoll: extract ep_deliver_event() from ep_send_events() - eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers - eventpoll: rename epi->next and txlist for clarity - eventpoll: Fix epoll_wait() report false negative - gpiolib: acpi: Only trigger ActiveBoth interrupts on boot - staging: nvec: fix use-after-free in nvec_rx_completed() - coresight: cti: Fix DT filter signals silently ignored - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore - PCI/ASPM: Don't reconfigure ASPM entering low-power state - PCI: Introduce named defines for PCI ROM - PCI: Check ROM header and data structure addr before accessing - [amd64] x86/platform/olpc: xo15: Drop wakeup source on driver removal - [amd64] platform/x86: xo15-ebook: Fix wakeup source and GPE handling - PCI: loongson: Do not ignore downstream devices on external bridges - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() - PCI: qcom: Set max OPP before DBI access during resume - phy: phy-can-transceiver: Check driver match and driver data against NULL - clk: at91: sam9x7: Fix gmac_gclk clock definition - coresight: Fix source not disabled on idr_alloc_u32 failure - mailbox: mtk-adsp: fix UAF during device teardown - staging: most: video: avoid double free on video register failure - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() - usb: host: max3421: Reject hub port requests for non-existent ports - char: tlclk: fix use-after-free in tlclk_cleanup() - PCI: qcom: Disable ASPM L0s for SA8775P - iio: light: si1133: reset counter to prevent race condition - iio: light: si1133: prevent race condition on timeout - iio: magnetometer: ak8975: fix potential kernel stack memory leak - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() - iio: tcs3472: power down chip on probe failure - clk: at91: keep securam node alive while mapping it - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter - fs/ntfs3: add bounds check to run_get_highest_vcn() - fs/ntfs3: fix mount failure on 64K page-size kernels - drm/amd/display: Add missing kdoc for ALLM parameters - [amd64] thunderbolt: debugfs: Fix margining error counter buffer leak - dmaengine: imx-sdma: Refine spba bus searching in probe - perf: Fix off-by-one stack buffer overflow in kallsyms__parse() - dmaengine: qcom: gpi: set DMA_PRIVATE capability - dmaengine: Fix possible use after free - dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor - clk: qcom: a53: Corrected frequency multiplier for 1152MHz - pNFS/filelayout: fix cheking if a layout is striped - xprtrdma: Avoid 250 ms delay on backlog wakeup - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot - xprtrdma: Post receive buffers after RPC completion - xprtrdma: Use sendctx DMA state for Send signaling - xprtrdma: Decouple req recycling from RPC completion - NFSv4/pnfs: defer return_range callbacks until after inode unlock - nfs: keep PG_UPTODATE clear after read errors in page groups - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write - nfs: use nfsi->rwsem to protect traversal of the file lock list - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro - PCI: meson: Propagate devm_add_action_or_reset() failure - PCI: meson: Add missing remove callback - fs/ntfs3: resize log->one_page_buf when adopting on-disk page size - PCI: rcar-host: Remove unused LIST_HEAD(res) - xprtrdma: Fix ep kref imbalance on ADDR_CHANGE - xprtrdma: Initialize re_id before removal registration - xprtrdma: Check frwr_wp_create() during connect - xprtrdma: Document and assert reply-handler invariants - xprtrdma: Resize reply buffers before reposting receives - xprtrdma: Fix bcall rep leak and unbounded peek - xprtrdma: Sanitize the reply credit grant after parsing - xprtrdma: Repost Receive buffers for malformed replies - xprtrdma: Return sendctx slot after Send preparation failure - tools lib api: Fix missing null termination in filename__read_int/ull() - tools lib api: Fix filename__write_int() writing uninitialized stack data - tools lib api: Fix mount_overload() snprintf truncation and toupper range - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() - PCI: mediatek: Use actual physical address instead of virt_to_phys() - Revert "PCI/MSI: Unmap MSI-X region on error" - security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() - apparmor: check label build before no_new_privs test - apparmor: aa_label_alloc use aa_label_free on alloc failure - apparmor: fix rawdata_f_data implicit flex array - apparmor: grab ns lock and refresh when looking up changehat child profiles - apparmor: fix potential UAF in aa_replace_profiles - apparmor: remove or add symlinks to rawdata according to export_binary - apparmor: aa_getprocattr free procattr leak on format failure - apparmor: put secmark label after secid lookup - workqueue: Add new WQ_PERCPU flag - i3c: master: add WQ_PERCPU to alloc_workqueue users - i3c: master: Make hot-join workqueue freezable to block hot-join during suspend - i3c: master: Prevent reuse of dynamic address on device add failure - apparmor: fix label can not be immediately before a declaration - gpio: mlxbf3: fail probe if gpiochip registration fails - [amd64] drm/i915: clear CRTC color blob pointers after dropping refs - spi: dw: fix wrong BAUDR setting after resume - xfrm: Fix xfrm state cache insertion race - xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] - xfrm: validate selector family and prefixlen during match - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm - drm/amdgpu: initialize irq.lock spinlock earlier - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown - net: psample: fix info leak in PSAMPLE_ATTR_DATA (CVE-2026-64553) - sctp: hold socket lock when dumping endpoints in sctp_diag - PCI: iproc: Restore .map_irq() for the platform bus driver - spi: rpc-if: Use correct device for hardware reinitialization on resume - virtio-net: fix len check in receive_big() (CVE-2026-64552) - dpaa2-switch: fix VLAN upper check not rejecting bridge join - devlink: Fix parent ref leak in devl_rate_node_create() - flow_dissector: check device type before reading ETH_ADDRS - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints - [arm64] hw_breakpoint: reject unaligned watchpoints that would truncate BAS - thermal: intel: Fix dangling resources on thermal_throttle_online() failure - ACPI: resource: Amend kernel-doc style - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() - ieee802154: fix kernel-infoleak in dgram_recvmsg() - mac802154: Prevent overwrite return code in mac802154_perform_association() - md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry - netfilter: ipset: Fix data race between add and dump in all hash types - netfilter: ipset: annotate "pos" for concurrent readers/writers - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() - netfilter: ipset: make sure gc is properly stopped - netfilter: nf_reject: skip iphdr options when looking for icmp header - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() - irqchip/crossbar: Fix parent domain resource leak - net: marvell: prestera: initialize err in prestera_port_sfp_bind - tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (CVE-2026-64543) - net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths - octeontx2-af: mcs: Fix unsupported secy stats read - octeontx2-pf: Clear stats of all resources when freeing resources - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown - net/sched: act_ct: fix nf_connlabels leak on two error paths - ipv6: ndisc: fix NULL deref in accept_untracked_na() (CVE-2026-64542) - dpaa2-switch: do not accept VLAN uppers while bridged - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 - bpf: Fix stack slot index in nospec checks - bpftool: Fix vmlinux BTF leak in cgroup commands - bpf: zero-initialize the fib lookup flow struct - bpf: Fix effective prog array index with BPF_F_PREORDER - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() - drm/edid: fix OOB read in drm_parse_tiled_block() (CVE-2026-64546) - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 - ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() - ice: fix AQ error code comparison in ice_set_pauseparam() - ice: call netif_keep_dst() once when entering switchdev mode - ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info - ice: dpll: fix memory leak in ice_dpll_init_info error paths - i40e: Fix i40e_debug() to use struct i40e_hw argument - rtc: msc313: fix NULL deref in shared IRQ handler at probe - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (CVE-2026-64538) - net: bnxt: use ethtool string helpers - eth: bnxt: gather and report HW-GRO stats - eth: bnxt: rename ring_err_stats -> ring_drv_stats - eth: bnxt: improve the timing of stats - ipv4: fib: Don't ignore error route in local/main tables. - md/raid5: use stripe state snapshot in break_stripe_batch_list() - md/raid5: avoid R5_Overlap races while breaking stripe batches - bpf: Disable xfrm_decode_session hook attachment - netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Closes: #1130336) - netfilter: nft_synproxy: stop bypassing the priv->info snapshot - netfilter: nft_compat: ebtables emulation must reject non-bridge targets - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure - NTB: epf: Make db_valid_mask cover only real doorbell bits - NTB: epf: Report 0-based doorbell vector via ntb_db_event() - NTB: epf: Fix doorbell bitmask and IRQ vector handling - net, bpf: check master for NULL in xdp_master_redirect() (CVE-2026-64545) - net: dsa: sja1105: round up PTP perout pin duration - veth: fix NAPI leak in XDP enable error path - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) - ipv6: fix error handling in disable_ipv6 sysctl - ipv6: fix error handling in ignore_routes_with_linkdown sysctl - ipv6: fix error handling in forwarding sysctl - ipv6: fix error handling in disable_policy sysctl - rtnetlink: Add per-netns RTNL. - rtnetlink: Add assertion helpers for per-netns RTNL. - rtnetlink: Define rtnl_net_trylock(). - ipv6: Add __in6_dev_get_rtnl_net(). - ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL. - ipv6: fix missing notification for ignore_routes_with_linkdown - thermal: testing: zone: Flush work items during cleanup - ACPI: processor_idle: Mark LPI enter functions as __cpuidle - smb/client: preserve errors from smb2_set_sparse() - rtc: ds1307: Fix off-by-one issue with wday for rx8130 - rtc: cmos: unregister HPET IRQ handler on probe failure - net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() - octeontx2-af: Validate NIX maximum LFs correctly - net: mvneta: re-enable percpu interrupt on resume - net: sungem: fix probe error cleanup - net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count - udp_tunnel: remove rtnl_lock dependency - net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync - dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback - [arm64] net: hisilicon: hns3: use ethtool string helpers - [arm64] net: hns3: use string choices helper - [arm64] net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: clear hns alarm: comparison of integer expressions of different signedness - [arm64] net: hns3: unify copper port ksettings configuration path - [arm64] net: hns3: refactor MAC autoneg and speed configuration - [arm64] net: hns3: fix permanent link down deadlock after reset - [arm64] net: hns3: differentiate autoneg default values between copper and fiber - tracing: probes: fix typo in a log message - spi: sh-msiof: abort transfers when reset times out - gpio: mvebu: fail probe if gpiochip registration fails - gpio: htc-egpio: use managed gpiochip registration - seg6: validate SRH length before reading fixed fields - qede: fix out-of-bounds check for cqe->len_list[] - net: enetc: check the number of BDs needed for xdp_frame - sctp: fix SCTP_RESET_STREAMS stream list length limit - MIPS: DEC: Ensure RTC platform device deregistration upon failure - ASoC: codecs: lpass-va-macro: add SM6115 compatible - ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 - hwmon: adm1275: Prevent reading uninitialized stack - hwmon: (pmbus) Fix passing events to regulator core - hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (CVE-2026-64540) - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy - net: gianfar: dispose irq mappings on probe failure and device removal - net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF - bridge: stp: Fix a potential use-after-free when deleting a bridge - [arm64] drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() - [arm64] drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() - [arm64] drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced - [arm64] drm/panthor: Interrupt group start/resumption if group_bind_locked() fails - tracing/events: Fix to check the simple_tsk_fn creation - tracing: eprobe: read the complete FILTER_PTR_STRING pointer - irqchip/gic-v3-its: Fix OF node reference leak - irqchip/ts4800: Fix missing chained handler cleanup on remove - virtio_net: disable cb when NAPI is busy-polled - cxgb4: Fix decode strings dump for T6 adapters - net/sched: act_bpf: use rcu_dereference_bh() to read the filter - ksmbd: reject undersized DACLs before parsing ACEs - ksmbd: fix use-after-free of fp->owner.name in durable handle owner check - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe - pinctrl: meson: restore non-sleeping GPIO access - net/sched: hhf: clear heavy-hitter state on reset - fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid - afs: Fix error code in afs_extract_vl_addrs() - afs: Fix double netfs initialisation in afs_root_iget() - afs: use kvfree() to free memory allocated by kvcalloc() - afs: Remove erroneous seq |= 1 in volume lookup loop - afs: Make /afs/. as well as /afs/ mountpoints - afs: Add rootcell checks - afs: Make /afs/@cell and /afs/.@cell symlinks - afs: Fix afs_atcell_get_link() to handle RCU pathwalk - afs: Remove the "autocell" mount option - afs: Change dynroot to create contents on demand - afs: Fix misplaced inc of net->cells_outstanding - afs: Fix callback service message parsers to pass through -EAGAIN - afs: Fix missing NULL pointer check in afs_break_some_callbacks() - afs: Fix vllist leak - afs: Fix the volume AFS_VOLUME_RM_TREE is set on - afs: Fix unchecked-length string display in debug statement - minix: avoid overflow in bitmap block count calculation - ovl: fix comment about locking order - netfs: Fix writeback error handling - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() - drm/xe/hw_engine: Fix double-free of managed BO in error path - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays - netfs: Drop the error arg from netfs_read_subreq_terminated() - cifs: Fix missing credit release on failure in cifs_issue_read() - ata: sata_gemini: unwind clocks on IDE pinctrl errors - ata: libata-scsi: limit simulated SCSI command copy to response length - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() - HID: core: Fix OOB read in hid_get_report for numbered reports - [arm64] mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() - HID: bpf: Fix hid_bpf_get_data() range check - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (CVE-2026-64547) - gue: validate REMCSUM private option length - netfilter: xt_u32: reject invalid shift counts - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop - netfilter: xt_connmark: reject invalid shift parameters - net/mlx5: LAG, MPESW, Fix missing complete() on devcom error - net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation - net/mlx5e: Fix HV VHCA stats agent registration race - net: microchip: vcap: fix races on the shared Super VCAP block - qede: fix off-by-one in BD ring consumption on build_skb failure - net: qualcomm: rmnet: validate MAP frame length before ingress parsing (CVE-2026-64550) - net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket - amt: fix size calculation in amt_get_size() - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control - Bluetooth: MGMT: Fix adv monitor add failure cleanup - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (CVE-2026-64549) - ring-buffer: Fix event length with forced 8-byte alignment - net/tls: Consume empty data records in tls_sw_read_sock() - net: usb: lan78xx: move functions to avoid forward definitions - net: usb: lan78xx: disable VLAN filter in promiscuous mode - [arm64] drm/v3d: Reject invalid indirect BO handle in indirect CSD setup - net/sched: cake: reject overhead values that underflow length - octeontx2-pf: check DMAC extraction support before filtering - [amd64] perf/x86/amd/core: Avoid enabling BRS from the SVM reload path - gpio: mvebu: free generic chips on unbind - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() - ipv6: mcast: Replace locking comments with lockdep annotations. - ipv6: mcast: Fix potential UAF in MLD delayed work - netfilter: nft_lookup: fix catchall element handling with inverted lookups - ipvs: pass parsed transport offset to state handlers - ipvs: use parsed transport offset in TCP state lookup - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors - ipvs: ensure inner headers in ICMP errors are in headroom - [s390x] zcrypt: Remove the empty file - cifs: validate DFS referral string offsets - SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED - SUNRPC: pin upper rpc_clnt across the TLS connect_worker - dm era: fix NULL pointer dereference in metadata_open() - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK - net/mlx5: Fix L3 tunnel entropy refcount leak - octeontx2-af: fix VF bringup affecting PF promiscuous state - drm/xe: remove duplicate include - smb: client: fix overflow in passthrough ioctl bounds check - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get - ASoC: SOF: topology: validate vendor array size before parsing - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() - net: atm: reject out-of-range traffic classes in QoS validation - net: ife: require ETH_HLEN to be pullable in ife_decode() - [arm64] fpsimd: Fix type mismatch in sve_{save,load}_state() - [arm64] dts: qcom: sdm630: describe adsp_mem region properly - [arm64] dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc - [arm64] dts: imx8ulp-evk: Correct Type-C int GPIO flags - [s390x] KVM: s390: pci: Fix GISC refcount leak on AIF enable failure - [arm64] KVM: arm64: vgic: Check the interrupt is still ours before migrating it - [s390x] KVM: s390: pci: Fix handling of AIF enable without AISB - [amd64] KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs - [amd64] KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs - [arm64] KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 - [arm64] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (CVE-2026-64555) - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() - fbdev: sm712: Fix operator precedence in big_swap macro - fbdev: efifb: fix memory leak in efifb_probe() - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() - fbdev: i740fb: fix potential memory leak in i740fb_probe() - fbdev: s3fb: fix potential memory leak in s3_pci_probe() - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() - fbdev: vesafb: fix memory leak in vesafb_probe() - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control - ASoC: mediatek: mt8192: Release reserved memory on cleanup - ASoC: mediatek: mt8183: Release reserved memory on cleanup - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read - netfilter: nfnl_cthelper: apply per-class values when updating policies - netfilter: xt_cluster: reject template conntracks in hash match - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst - netfilter: nft_set_pipapo: don't leak bad clone into future transaction - netfilter: nf_nat_sip: reload possible stale data pointer - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag - netfilter: nf_conncount: fix zone comparison in tuple dedup - netfilter: ecache: fix inverted time_after() check - netfilter: xt_nat: reject unsupported target families - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (CVE-2026-64554) - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy - soc: fsl: qe: panic on ioremap() failure in qe_reset() - selinux: check connect-related permissions on TCP Fast Open - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() - selinux: fix incorrect execmem checks on overlayfs - leds: uleds: Fix potential buffer overread - mfd: sm501: Fix reference leak on failed device registration - [amd64] tools/power/x86/intel-speed-select: Harden daemon pidfile open - [amd64] x86/boot: Validate console=uart8250 baud rate to fix early boot hang - [amd64] x86/boot: Reject too long acpi_rsdp= values - [amd64] perf/x86/amd/lbr: Fix kernel address leakage - cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() - [s390x] perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() - batman-adv: gw: acquire ethernet header only after skb realloc - batman-adv: access unicast_ttvn skb->data only after skb realloc - batman-adv: dat: acquire ARP hw source only after skb realloc - batman-adv: bla: reacquire gw address after skb realloc - batman-adv: dat: ensure accessible eth_hdr proto field - batman-adv: dat: fix tie-break for candidate selection - batman-adv: tt: avoid request storms during pending request - batman-adv: fix VLAN priority offset - batman-adv: frag: free unfragmentable packet - batman-adv: frag: fix primary_if leak on failed linearization - batman-adv: mcast: avoid OOB read of num_dests header - batman-adv: tt: prevent TVLV OOB check overflow - cifs: invalidate cfid on unlink/rename/rmdir - mfd: tps6586x: Fix OF node refcount - HID: playstation: validate num_touch_reports in DualShock 4 reports - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready - Bluetooth: SCO: hold sk properly in sco_conn_ready - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() - nvdimm/btt: Free arenas on btt_init() error paths - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback - sunrpc: wait for in-flight TLS handshake callback when cancel loses race - lockd: Plug nlm_file leak when nlm_do_fopen() fails - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing - remoteproc: qcom: Fix leak when custom dump_segments addition fails - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak - mm/memory_hotplug: fix incorrect altmap passing in error path - mm/damon/core: make charge_addr_from aware of end-address exclusivity - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length - fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off - fs/ntfs3: validate lcns_follow in log_replay conversion (CVE-2026-64533) - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow - fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (CVE-2026-64532) - ntfs3: cap RESTART_TABLE free-chain walker at rt->used - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head - ntfs3: validate split-point offset in indx_insert_into_buffer - ntfs3: fix out-of-bounds read in decompress_lznt - power: supply: charger-manager: fix refcount leak in is_full_charged() - [riscv64] cacheinfo: Fix node reference leak in populate_cache_leaves - mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() - mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error - fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() - fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() - proc: only bump parent nlink when registering directories - mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE - kcov: use WRITE_ONCE() for selftest mode stores - mtd: slram: remove failed entries from the device list - 9p: skip nlink update in cacheless mode to fix WARN_ON - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() - scsi: sas: Skip opt_sectors when DMA reports no real optimization hint - ocfs2: use kzalloc for quota recovery bitmap allocation - mtd: rawnand: pl353: fix probe resource allocation - net/9p: fix infinite loop in p9_client_rpc on fatal signal - mtd: rawnand: fix condition in 'nand_select_target()' - ocfs2: avoid moving extents to occupied clusters - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits - ocfs2: add journal NULL check in ocfs2_checkpoint_inode() - ocfs2: reject dinodes with non-canonical i_mode type - ocfs2: reject dinodes whose i_rdev disagrees with the file type - ocfs2: reject non-inline dinodes with i_size and zero i_clusters - fpga: dfl: add bounds check in dfh_get_param_size() - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path - net: thunderbolt: Fix frags[] overflow by bounding frame_count - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() - [s390x] pkey: Check length in PKEY_VERIFYPROTK ioctl - [s390x] pkey: Check length in pkey_pckmo handler implementation - mtd: spi-nor: swp: Improve locking user experience - mtd: spi-nor: spansion: use die erase for multi-die devices only - mtd: rawnand: Pause continuous reads at block boundaries - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization - taskstats: retain dead thread stats in TGID queries - irqchip/crossbar: Use correct index in crossbar_domain_free() - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() - tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt - dmaengine: tegra: Fix burst size calculation - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK - [amd64] platform/x86: dell-laptop: fix missing cleanups in init error path - [amd64] platform/x86/amd/pmc: Check for intermediate wakeup in function - [amd64] platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops - [amd64] platform/x86/amd/pmc: Add delay_suspend module parameter - [amd64] platform/x86/amd/pmc: Don't log during intermediate wakeups - pkey: Move keytype check from pkey api to handler - smb: client: use kvzalloc() for megabyte buffer in simple fallocate - ksmbd: fix integer overflow in set_file_allocation_info() - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig - hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig - i2c: mediatek: fix WRRD for SoCs without auto_restart option - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() - ice: fix ice_init_link() error return preventing probe - xen/gntdev: fix error handling in ioctl - xfrm: use compat translator only for u64 alignment mismatch - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink - tpm: fix event_size output in tpm1_binary_bios_measurements_show - tpm: Make the TPM character devices non-seekable - time: Fix off-by-one in compat settimeofday() usec validation - spi: uniphier: Fix completion initialization order before devm_request_irq() - sctp: validate STALE_COOKIE cause length before reading staleness (CVE-2026-64551) - NFS: Charge unstable writes by request size, not folio size - nvmet-rdma: handle inline data with a nonzero offset - netdev-genl: report NAPI thread PID in the caller's pid namespace - can: esd_usb: kill anchored URBs before freeing netdevs - can: isotp: use unconditional synchronize_rcu() in isotp_release() - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure - can: bcm: add missing rcu list annotations and operations - bpf,fork: wipe ->bpf_storage before bailouts that access it - bpf: Add missing access_ok call to copy_user_syms - block: fix race in blk_time_get_ns() returning 0 - net: sparx5: unregister blocking notifier on init failure - dm thin metadata: fix superblock refcount leak on snapshot shadow failure - dm thin metadata: fix metadata snapshot consistency on commit failure - dm era: fix out-of-bounds memory access for non-zero start sector - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard - dm-ioctl: fix a possible overflow in list_version_get_info - dm-log: fix a bitset_size overflow on 32bit machines - dm-stats: fix dm_jiffies_to_msec64 - dm-stats: fix merge accounting - dm_early_create: fix freeing used table on dm_resume failure - dm-integrity: fix a bug if the bio is out of limits - dm-integrity: don't increment hash_offset twice - dm-verity: avoid double increment of &use_bh_wq_enabled - dm-verity: fix a possible NULL pointer dereference - dm-verity: increase sprintf buffer size - dm-verity: make error counter atomic - [amd64] accel/ivpu: Reject firmware log with size smaller than header - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() - scsi: sg: Report request-table problems when any status is set - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path - scsi: xen: scsiback: Free unsubmitted command instead of double-putting it - scsi: target: Bound PR-OUT TransportID parsing to the received buffer - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() - scsi: elx: efct: Fix I/O leak on unsupported additional CDB - Input: ims-pcu - fix use-after-free and double-free in disconnect - Input: ims-pcu - only expose sysfs attributes on control interface - Input: ims-pcu - release data interface on disconnect - Input: ims-pcu - validate control endpoint type - Input: ims-pcu - add response length checks - Input: ims-pcu - fix DMA mapping violation in line setup - Input: ims-pcu - fix firmware leak in async update - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing - Input: ims-pcu - fix race condition in reset_device sysfs callback - Input: ims-pcu - fix type confusion in CDC union descriptor parsing - net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete - tracing/user_events: Fix use-after-free in user_event_mm_dup() - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() - cpu: hotplug: Preserve per instance callback errors - cpu: hotplug: Bound hotplug states sysfs output - gpio: tegra: do not call pinctrl for GPIO direction - gpio-f7188x: Add support for NCT6126D version B - gpios: palmas: add .get_direction() op - net: sit: require CAP_NET_ADMIN in the device netns for changelink - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure - net: ixp4xx_hss: fix duplicate HDLC netdev allocation - net/sched: act_ct: preserve tc_skb_cb across defragmentation - net: ena: clean up XDP TX queues when regular TX setup fails - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ipip: require CAP_NET_ADMIN in the device netns for changelink - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink - octeontx2-af: Free BPID bitmap on setup failure - ieee802154: admin-gate legacy LLSEC dump operations - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation - ieee802154: ca8210: fix cas_ctl leak on spi_async failure - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit - [amd64] platform/x86/amd/pmc: Avoid logging "(null)" for DMI values - net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants - [s390x] Revert support for DCACHE_WORD_ACCESS (CVE-2026-64369) - batman-adv: retrieve ethhdr after potential skb realloc on RX - batman-adv: ensure minimal ethernet header on TX - batman-adv: clean untagged VLAN on netdev registration failure - espintcp: use sk_msg_free_partial to fix partial send - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() - rtc: mpfs: fix counter upload completion condition - hwmon: (w83627hf) remove VID sysfs files on error and remove - hwmon: (w83793) remove vrm sysfs file on probe failure - net: liquidio: fix BAR resource leak on PF number failure - hwmon: (occ) unregister sysfs devices outside occ lock - fsl/fman: Free init resources on KeyGen failure in fman_init() - net: lan743x: Initialize eth_syslock spinlock before use - net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked - net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked - fhandle: reject detached mounts in capable_wrt_mount() - hwmon: (max1619) add missing 'select REGMAP' to Kconfig - tracing/probes: Fix double addition of offset for @+FOFFSET - orangefs: keep the readdir entry size 64-bit in fill_from_part() - ata: pata_pxa: Fix DMA channel leak on probe error - net: wwan: iosm: bound device offsets in the MUX downlink decoder - hwmon: (asus_atk0110) Check package count before accessing element - [riscv64] probes: save original sp in rethook trampoline - mm/compaction: handle free_pages_prepare() properly in compaction_free() - irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure - [s390x] monwriter: Reject buffer reuse with different data length - mac802154: remove interfaces with RCU list deletion - llc: fix SAP refcount leak in llc_ui_autobind() - ipvs: use parsed transport offset in SCTP state lookup - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new - macsec: don't read an unset MAC header in macsec_encrypt() - [arm64] smp: Fix hot-unplug tearing by forcing unregistration - ata: libata-core: Skip HPA resize for locked drives - drbd: reject data replies with an out-of-range payload size - [riscv64] Prevent NULL pointer dereference in machine_kexec_prepare() - tracing/osnoise: Call synchronize_rcu() when unregistering - [s390x] mm: Fix type mismatch in get_align_mask(). - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed - pmdomain: imx: Fix i.MX8MP power notifier - pmdomain: imx: Fix i.MX8MP VC8000E power up sequence - [powerpc*] pseries: fix memory leak on krealloc failure in papr_init - wifi: rt2x00: avoid full teardown before work setup in probe - wifi: mwifiex: fix roaming to different channel in host_mlme mode - wifi: mac80211: fix memory leak in ieee80211_register_hw() - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets - net: openvswitch: reject oversized nested action attrs (CVE-2026-64531) - Bluetooth: btrtl: validate firmware patch bounds - llc: fix SAP refcount leak when creating incoming sockets - macsec: fix promiscuity refcount leak in macsec_dev_open() - memstick: ms_block: reject a card that reports too many blocks - ipvs: fix more places with wrong ipv6 transport offsets - ipvs: reload ip header after head reallocation - reset: sunxi: fix memory region leak on ioremap failure - [powerpc*] spufs: fix out-of-bounds access in spufs_mem_mmap_access() - wifi: mac80211: free ack status frame on TX header build failure - wifi: mwifiex: fix permanently busy scans after multiple roam iterations - mtd: onenand: samsung: report DMA completion timeouts - mtd: mchp23k256: use SPI match data for chip caps - mmc: vub300: defer reset until cmd_mutex is unlocked - mtd: rawnand: fsl_ifc: return errors for failed page reads - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout - mmc: block: fix RPMB device unregister ordering - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method - ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup - ACPI: driver: Check ACPI_COMPANION() against NULL during probe - ACPI: bus: Introduce devm_acpi_install_notify_handler() - ACPI: NFIT: core: Use devm_acpi_install_notify_handler() - ACPI: NFIT: core: Fix possible deadlock and missing notifications - iio: hid-sensor-rotation: Fix stale or zero output when reading raw values - iio: adc: ad7380: select REGMAP - iio: pressure: Remove redundant pm_runtime_mark_last_busy() calls - iio: pressure: mpl115: fix runtime PM leak on read error (CVE-2026-64493) - ALSA: aoa: check snd_ctl_new1() return value - ALSA: hda/cs35l41: Fix firmware load work teardown (CVE-2026-64481) - ALSA: scarlett2: Allow selecting config_set by firmware version - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 - vfio/mlx5: Fix racy bitfields and tighten struct layout (CVE-2026-64472) - PCI: altera: Fix resource leaks on probe failure (CVE-2026-64462) - PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() - PCI: mediatek: Switch to msi_create_parent_irq_domain() - PCI: mediatek: Convert bool to single quirks entry and bitmap - PCI: mediatek: Use generic MACRO for TPVPERL delay - PCI: mediatek: Fix IRQ domain leak when port fails to enable (CVE-2026-64461) - PCI: Use pbus_select_window() during BAR resize - PCI: Prevent resource tree corruption when BAR resize fails - PCI: Free saved list without holding pci_bus_sem - PCI: Fix restoring BARs on BAR resize rollback path - PCI: Move Resizable BAR code to rebar.c - PCI: Skip Resizable BAR restore on read error - staging: rtl8723bs: core: move constants to right side in comparison - staging: rtl8723bs: fix spaces around binary operators - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() - [amd64] crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438) - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (CVE-2026-64434) - gpio: sch: use raw_spinlock_t in the irq startup path (CVE-2026-64428) - io_uring/rw: ensure reissue path is correctly handled for IOPOLL - io_uring/rw: preserve partial result for iopoll - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code - media: nxp: imx8-isi: Fix use-after-free on remove (CVE-2026-64421) - netfilter: ebtables: Use vmalloc_array() to improve code - netfilter: ebtables: zero chainstack array (CVE-2026-64413) - Bluetooth: L2CAP: Fix not tracking outstanding TX ident - Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (CVE-2026-64206) - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO - Bluetooth: separate CIS_LINK and BIS_LINK link types - Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() (CVE-2026-64405) - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() - mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (CVE-2026-64416) - smb: client: Improve unlocking of a mutex in cifs_get_swn_reg() - smb: client: resolve SWN tcon from live registrations (CVE-2026-64401) - ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name - vfs: make LAST_XXX private to fs/namei.c - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create - ksmbd: use opener credentials for FSCTL mutations - ksmbd: centralize ksmbd_conn final release to plug transport leak - ksmbd: track the connection owning a byte-range lock (CVE-2026-64390) - proc: rename proc_setattr to proc_nochmod_setattr - proc: protect ptrace_may_access() with exec_update_lock (FD links) - [amd64] perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box() - HID: add haptics page defines - HID: multitouch: fix out-of-bounds bit access on mt_io_flags (CVE-2026-64364) - seqlock: Introduce scoped_seqlock_read() - seqlock: Change do_task_stat() to use scoped_seqlock_read() - proc: protect ptrace_may_access() with exec_update_lock (part 1) - treewide: Switch/rename to timer_delete[_sync]() - HID: appleir: fix UAF on pending key_up_timer in remove() (CVE-2026-64363) - HID: pidff: Fix missing blank lines after declarations - HID: pidff: Add missing spaces - HID: pidff: Rework pidff_upload_effect - HID: pidff: Use correct effect type in effect update - hfs/hfsplus: prevent getting negative values of offset/length - hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (CVE-2026-64361) - bpf: Convert lpm_trie.c to rqspinlock - bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() - bpf: Consistently use bpf_rcu_lock_held() everywhere - bpf: Allow LPM map access from sleepable BPF programs (CVE-2026-64352) - usb: iowarrior: remove inherent race with minor number - USB: iowarrior: fix use-after-free on disconnect race (CVE-2026-64341) - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() - crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 - crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A - usb: gadget: f_fs: initialize reset_work at allocation time - crypto: atmel-sha204a - fail on hwrng registration error in probe path - usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile - btrfs: concentrate the error handling of submit_one_sector() - btrfs: replace for_each_set_bit() with for_each_set_bitmap() - btrfs: remove folio parameter from ordered io related functions - btrfs: remove the COW fixup mechanism - btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC - [amd64] crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown - [amd64] crypto: ccp - Reset TMR size at SNP Shutdown - [amd64] crypto: ccp - Register SNP panic notifier only if SNP is enabled - [amd64] crypto: ccp - Move SEV/SNP Platform initialization to KVM - [amd64] crypto: ccp - Fix a case where SNP_SHUTDOWN is missed - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) - [amd64] crypto: qat - fix restarting state leak on allocation failure - exfat: remove unnecessary read entry in __exfat_rename() - exfat: rename argument name for exfat_move_file and exfat_rename_file - exfat: add exfat_get_dentry_set_by_ei() helper - exfat: move exfat_chain_set() out of __exfat_resolve_path() - exfat: fix incorrect directory checksum after rename to shorter name - exfat: preserve benign secondary entries during rename and move - btrfs: fix false IO failure after falling back to buffered write - btrfs: fix incorrect buffered IO fallback for append direct writes - slab: Introduce kmalloc_obj() and family - slab: Introduce kmalloc_flex() and family - add default_gfp() helper macro and use it in the new *alloc_obj() helpers - default_gfp(): avoid using the "newfangled" __VA_OPT__ trick - slab: recognize @GFP parameter as optional in kernel-doc - fscrypt: Fix key setup in edge case with multiple data unit sizes - fscrypt: Replace mk_users keyring with simple list - mm/damon/core: always put unsuccessfully committed target pids - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers - [arm64] KVM: arm64: Ensure level is always initialized when relaxing perms - [arm64] KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (CVE-2026-64192) - [amd64] perf/x86/amd/brs: Fix kernel address leakage - dibs: loopback: validate offset and size in move_data() - seqlock: fix scoped_seqlock_read kernel-doc - ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd - rtnetlink: Make per-netns RTNL dereference helpers to macro. - net: airoha: Fix channel configuration for ETS Qdisc - jiffies: Cast to unsigned long in secs_to_jiffies() conversion - afs: Fix afs_atcell_get_link() to check if ws_cell is unset first - afs: Fix afs_dynroot_readdir() to not use the RCU read lock - [amd64] crypto: ccp - Fix __sev_snp_shutdown_locked - [amd64] crypto: ccp - Fix dereferencing uninitialized error pointer - [amd64] crypto: ccp - Fix SNP panic notifier unregistration - udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() - Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state - Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle - [amd64] crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() - i40e: drop udp_tunnel_get_rx_info() call from i40e_open() - ice: drop udp_tunnel_get_rx_info() call from ndo_open() - [amd64] crypto: ccp - Fix leaking the same page twice - Bluetooth: L2CAP: Fix regressions caused by reusing ident - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev - Bluetooth: L2CAP: fix tx ident leak for commands without a response - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() - tools/testing: add linux/args.h header and fix radix, VMA tests https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.98 - ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.99 - mm: refactor mm_access() to not return NULL https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.100 - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (CVE-2026-64560) linux (6.12.96-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.96 - [arm64] bpf, arm64: Reject out-of-range B.cond targets - nfsd: fix file change detection in CB_GETATTR - nfsd: release layout stid on setlease failure - userfaultfd: gate must_wait writability check on pte_present() - perf: Fix dangling cgroup pointer in cpuctx backport - bcachefs: avoid truncating fiemap extent length - drm/amd: Fix set but not used warnings - gpio: rockchip: change the GPIO version judgment logic - gpio: rockchip: teardown bugs and resource leaks - gpio: rockchip: fix generic IRQ chip leak on remove (CVE-2026-53226) - mm/vmalloc: take vmap_purge_lock in shrinker (CVE-2026-46093) - device property: initialize the remaining fields of fwnode_handle in fwnode_init() - f2fs: validate orphan inode entry count - f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes - f2fs: fix potential deadlock in f2fs_balance_fs() - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() - f2fs: fix listxattr handling of corrupted xattr entries - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() - nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations - nfs_common: rename functions that invalidate LOCALIO nfs_clients - NFSv4/flexfiles: Remove cred local variable dependency - NFSv4/flexfiles: Add data structure support for striped layouts - NFSv4/flexfiles: reject zero filehandle version count - locking/rtmutex: Make sure we wake anything on the wake_q when we release the lock->wait_lock - apparmor: advertise the tcp fast open fix is applied - nfsd: move name lookup out of nfsd4_list_rec_dir() - nfsd: change nfs4_client_to_reclaim() to allocate data - bonding: fix xfrm offload feature setup on active-backup mode - block: add a store_limit operations for sysfs entries - block: fix queue freeze vs limits lock order in sysfs store methods (CVE-2025-21807) - mm/khugepaged: write all dirty file folios when collapsing - perf trace beauty fcntl: Fix build with older kernel headers - ACPI: CPPC: Suppress UBSAN warning caused by field misuse - ACPI: NFIT: core: Fix possible NULL pointer dereference - [amd64] platform/x86: intel-hid: Protect ACPI notify handler against recursion - perf/core: Detach event groups during remove_on_exec - [amd64] drm/i915: ensure segment offset never exceeds allowed max - usb: gadget: function: rndis: add length check to response query - usb: gadget: function: rndis: add length check for header - iio: accel: bmc150: clamp the device-reported FIFO frame count - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error - iio: adc: lpc32xx: Initialize completion before requesting IRQ - iio: adc: spear: Initialize completion before requesting IRQ - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable - iio: adc: ti-ads124s08: Return reset GPIO lookup errors - iio: backend: fix uninitialized data in debugfs - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug - iio: common: st_sensors: honour channel endianness in read_axis_data - iio: event: Fix event FIFO reset race - iio: gyro: bmg160: bail out when bandwidth/filter is not in table - iio: gyro: bmg160: wait full startup time after mode change at probe - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ - iio: imu: inv_icm42600: fix timestamp clock period by using lower value - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading - iio: imu: st_lsm6dsx: deselect shub page before reading whoami - iio: light: al3010: fix incorrect scale for the highest gain range - iio: light: gp2ap002: fix runtime PM leak on read error - iio: light: opt3001: fix missing state reset on timeout - iio: light: tsl2591: return actual error from probe IRQ failure - iio: light: veml6030: fix channel type when pushing events - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call - iio: resolver: ad2s1210: notify trigger and clear state on fault read error - iio: temperature: Build mlx90635 with CONFIG_MLX90635 - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start - ALSA: virtio: Add missing 384 kHz PCM rate mapping - ALSA: virtio: Validate control metadata from the device - ALSA: ymfpci: check snd_ctl_new1() return value - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser - ALSA: cmipci: check snd_ctl_new1() return value - ALSA: es1938: check snd_ctl_new1() return value - ALSA: firewire: isight: bound the sample count to the packet payload - ALSA: gus: check snd_ctl_new1() return value - ALSA: ice1712: check snd_ctl_new1() return value - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() - ALSA: usb-audio: avoid kobject path lookup in DualSense match - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks - ALSA: usb-audio: Roll back quirk control caches on write errors - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes - vfio/pci: Use a private flag to prevent power state change with VFs - vfio/pci: Latch disable_idle_d3 per device - vfio/pci: Release the VGA arbiter client on register_device() failure - vfio/pci: Fix racy bitfields and tighten struct layout - vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc - vfio: Remove device debugfs before releasing devres - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB - Bluetooth: btusb: fix use-after-free on registration failure - Bluetooth: btusb: fix use-after-free on marvell probe failure - Bluetooth: btusb: fix wakeup source leak on probe failure - [arm*] binder: fix UAF in binder_thread_release() - [arm*] binder: fix UAF in binder_free_transaction() - usb: xhci: Fix sleep in atomic context in xhci_free_streams() - usb: typec: tcpci_rt1711h: unregister TCPCI port with devres - PCI: host-common: Request bus reassignment when not probe-only - [arm*] PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling - mm/damon/ops-common: handle extreme intervals in damon_hot_score() - netfilter: ipset: fix race between dump and ip_set_list resize - virtio_pci: fix vq info pointer lookup via wrong index - virtio-mmio: fix device release warning on module unload - hwrng: virtio: clamp device-reported used.len at copy_data() - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() - usb: dwc3: run gadget disconnect from sleepable suspend context - 6lowpan: fix NHC entry use-after-free on error path - tipc: fix out-of-bounds read in broadcast Gap ACK blocks - staging: vme_user: bound slave read/write to the kern_buf size - smb: client: restrict implied bcc[0] exemption to responses without data area - staging: vme_user: fix location monitor leak in fake bridge - staging: vme_user: fix location monitor leak in tsi148 bridge - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe - staging: media: atomisp: reduce load_primary_binaries() stack usage - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop - staging: rtl8723bs: fix OOB write in HT_caps_handler() - crypto: amlogic - avoid double cleanup in meson_crypto_probe() - ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL - net: af_key: initialize alg_key_len for IPComp states - audit: Fix data races of skb_queue_len() readers on audit_queue - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete - coresight: etb10: restore atomic_t for shared reading state - debugobjects: Plug race against a concurrent OOM disable - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns - NTB: epf: Avoid calling pci_irq_vector() from hardirq context - gpio: eic-sprd: use raw_spinlock_t in the irq startup path - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item - netpoll: fix a use-after-free on shutdown path - ipv4: igmp: remove multicast group from hash table on device destruction - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes - mfd: cros_ec: Delay dev_set_drvdata() until probe success - mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() - mm: shrinker: fix shrinker_info teardown race with expansion - mm: shrinker: fix NULL pointer dereference in debugfs - mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup - netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump - netfilter: handle unreadable frags - netfilter: ebtables: module names must be null-terminated - netfilter: ebtables: terminate table name before find_table_lock() - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() - Bluetooth: bnep: pin L2CAP connection during netdev registration - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() - Bluetooth: fix UAF in bt_accept_dequeue() - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() - Bluetooth: L2CAP: validate option length before reading conf opt value - fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr - fs/ntfs3: fsync files by syncing parent inodes - fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio() - fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() (CVE-2026-53027) - coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() - smb/client: Fix error code in smb2_aead_req_alloc() - ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE - ksmbd: add a permission check for FSCTL_SET_ZERO_DATA - ksmbd: serialize QUERY_DIRECTORY requests per file - ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation - ksmbd: require source read access for duplicate extents - ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY - ksmbd: run set info with opener credentials - ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION - ksmbd: add per-handle permission check to FILE_LINK_INFORMATION - ksmbd: use opener credentials for delete-on-close - ksmbd: use opener credentials for ADS I/O - smb: client: fix query directory replay double-free - smb: client: fix query_info() replay double-free - smb: client: fix double-free in SMB2_ioctl() replay - smb: client: fix change notify replay double-free - smb: client: fix double-free in SMB2_flush() replay - smb: client: fix double-free in SMB2_open() replay - smb: client: fix double-free in SMB2_close() replay - smb: client: Fix next buffer leak in receive_encrypted_standard() - smb: client: use unaligned reads in parse_posix_ctxt() - smb: client: harden POSIX SID length parsing - smb: client: fix atime clamp check in read completion - smb: client: mask server-provided mode to 07777 in modefromsid - writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() - cpufreq: qcom-cpufreq-hw: Fix possible double free - firmware_loader: fix device reference leak in firmware_upload_register() - [amd64] cpufreq: intel_pstate: Sync policy->cur during CPU offline - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT - cpufreq: Fix hotplug-suspend race during reboot - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path - clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances - X.509: Fix validation of ASN.1 certificate header - mm/slab: do not limit zeroing to orig_size when only red zoning is enabled - tools/mm/slabinfo: Fix trace disable logic inversion - tools/mm/slabinfo: fix total_objects attribute name - HID: hid-goodix-spi: validate report size to prevent stack buffer overflow - HID: wacom: stop hardware after post-start probe failures - HID: letsketch: fix UAF on inrange_timer at driver unbind - HID: lg-g15: cancel pending work on remove to fix a use-after-free - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers - media: mtk-jpeg: cancel workqueue on release for supported platforms only - serial: 8250_mid: Disable DMA for selected platforms - xfs: use null daddr for unset first bad log block - xfs: release dquot buffer after dqflush failure - xfs: fix unreachable BIGTIME check in dquot flush validation - xfs: fix pointer arithmetic error on 32-bit systems - xfs: fix exchmaps reservation limit check - bpf: Reject fragmented frames in devmap - bpf: Restore sysctl new-value from 1 to 0 - bpf: Validate BTF repeated field counts before expansion - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() - usb: cdc_acm: Add quirk for Uniden BC125AT scanner - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() - usb: free iso schedules on failed submit - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler - usb: gadget: udc: Fix use-after-free in gadget_match_driver - usb: gadget: f_printer: take kref only for successful open - USB: idmouse: fix use-after-free on disconnect race - USB: ldusb: fix use-after-free on disconnect race - USB: iowarrior: fix use-after-free on disconnect - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD - USB: legousbtower: fix use-after-free on disconnect race - usb: sl811-hcd: disable controller wakeup on remove - USB: storage: include US_FL_NO_SAME in quirks mask - USB: misc: uss720: unregister parport on probe failure - usb: mtu3: unmap request DMA on queue failure - USB: serial: keyspan_pda: fix information leak - USB: serial: option: add Telit Cinterion FE990D50 compositions - USB: serial: digi_acceleport: fix broken rx after throttle - USB: serial: digi_acceleport: fix hard lockup on disconnect - USB: serial: digi_acceleport: fix write buffer corruption - USB: ulpi: fix memory leak on registration failure - USB: usb-storage: ene_ub6250: restore media-ready check - usbip: tools: support SuperSpeedPlus devices - usbip: vudc: fix NULL deref in vep_dequeue() - usb: typec: anx7411: use devm_pm_runtime_enable() - usb: typec: class: drop PD lookup reference - usb: typec: tcpm: Fix VDM type for Enter Mode commands - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() - usb: typec: ucsi: Invert DisplayPort role assignment - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove - usb: typec: ucsi: cancel pending work on system suspend - usb: gadget: f_fs: Fix DMA fence leak - block: skip sync_blockdev() on surprise removal in bdev_mark_dead() - [amd64] x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled - PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining - udf: validate free block extents against the partition length - udf: validate VAT header length against the VAT inode size - udf: validate sparing table length as an entry count, not a byte count - hwrng: jh7110 - fix refcount leak in starfive_trng_read() - nvme: target: rdma: fix ndev refcount leak on queue connect - dm-ioctl: report an error if a device has no table - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page - nvmet-auth: validate reply message payload bounds against transfer length - btrfs: do not trim a device which is not writeable - partitions: aix: bound the pp_count scan to the ppe array - isofs: bound Rock Ridge symlink components to the SL record - crypto: af_alg - Remove zero-copy support from skcipher and aead - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps again - crypto: ecc - Fix carry overflow in vli multiplication - crypto: pcrypt - restore callback for non-parallel fallback - [amd64] crypto: ccp - Do not initialize SNP for SEV ioctls - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) - crypto: drbg - Fix returning success on failure in CTR_DRBG - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels - crypto: drbg - Fix the fips_enabled priority boost - [amd64] crypto: qat - keep VFs enabled during reset - [amd64] crypto: qat - notify fatal error before AER reset preparation - [amd64] crypto: qat - protect service table iterations with service_lock - [amd64] crypto: qat - validate RSA CRT component lengths - [arm64] fpsimd: Fix type mismatch in sme_{save,load}_state() - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path - EDAC/i10nm: Don't fail probing if ADXL is missing - watchdog: apple: Add "apple,t8103-wdt" compatible - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() - i2c: core: fix hang on adapter registration failure - tracing: Prevent out-of-bounds read in glob matching - audit: fix potential integer overflow in audit_log_n_hex() - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC - module: decompress: check return value of module_extend_max_pages() - exfat: bound uniname advance in exfat_find_dir_entry() - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() - riscv: mm: Unconditionally sfence.vma for spurious fault - mm: fix mmap errno value when MAP_DROPPABLE is not supported - mm: do file ownership checks with the proper mount idmap - [amd64] iommu/amd: Don't split flush for amd_iommu_domain_flush_all() - iommufd: Set upper bounds on cache invalidation entry_num and entry_len - [amd64] KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs - [amd64] KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits - [amd64] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode - udmabuf: fix DMA direction mismatch in release_udmabuf() - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning - i2c: core: fix irq domain leak on adapter registration failure - i2c: core: fix NULL-deref on adapter registration failure - i2c: core: fix adapter probe deferral loop - i2c: core: fix adapter debugfs creation - i2c: core: fix adapter deregistration race - i2c: mpc: Fix timeout calculations - i2c: stm32f7: truncate clock period instead of rounding it - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count - Input: elan_i2c - prevent division by zero and arithmetic underflow - Input: goodix - clamp the device-reported contact count - Input: iforce - bound the device-reported force-feedback effect index - Input: mms114 - fix touch indexing for MMS134S and MMS136 - Input: touchwin - reset the packet index on every complete packet - Input: mms114 - reject an oversized device packet size - Input: maplemouse - fix NULL pointer dereference in open() - Input: mms114 - fix multi-touch slot corruption - Input: maple_keyb - set driver data before registering input device - Input: maplemouse - set driver data before registering input device - Input: maplecontrol - set driver data before registering input device - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg - RDMA/siw: bound Read Response placement to the RREAD length - fuse: fix device node leak in cuse_process_init_reply() - fuse: re-lock request before returning from fuse_ref_folio() - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req - usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks - smb: client: reject overlapping data areas in SMB2 responses - xfs: fix null pointer dereference in tracepoint - xfs: fail recovery on a committed log item with no regions - xfs: resample the data fork mapping after cycling ILOCK - xfs: don't wrap around quota ids in dqiterate - xfs: set xfarray killable sort correctly - xfs: clamp timestamp nanoseconds correctly - xfs: fully check the parent handle when it points to the rootdir - xfs: don't zap bmbt forks if they are MAXLEVELS tall . [ Han Gao ] * [riscv64] set NR_CPUS to 128 (Closes: #1140651) . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." (context changes) linux (6.12.95-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95 - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain - wifi: mt76: mt7921: fix a potential scan no APs - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (CVE-2026-53101) - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167) - gpiolib: Extract gpiochip_choose_fwnode() for wider use - gpiolib: Remove redundant assignment of return variable - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (CVE-2026-31732) - io_uring/net: Avoid msghdr on op_connect/op_bind async data - drm/xe/display: fix oops in suspend/shutdown without display (CVE-2026-53142) - [arm64] drm/v3d: Store the active job inside the queue's state - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139) - eventpoll: use hlist_is_singular_node() in __ep_remove() - eventpoll: split __ep_remove() - eventpoll: kill __ep_remove() - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() - eventpoll: rename ep_remove_safe() back to ep_remove() - eventpoll: move epi_fget() up - eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355) - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216) - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP - debugobjects: Do not fill_pool() if pi_blocked_on - debugobjects: Dont call fill_pool() in early boot hardirq context - RDMA/bnxt_re: zero shared page before exposing to userspace - i2c: stub: Reject I2C block transfers with invalid length - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe() (CVE-2026-53325) - bpf: Reject sleepable kprobe_multi programs at attach time (CVE-2026-43010) - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() - regulator: core: fix locking in regulator_resolve_supply() error path - dlm: prevent NPD when writing a positive value to event_done (CVE-2025-23131) - xfs: remove the expr argument to XFS_TEST_ERROR - xfs: fix error returns in CoW fork repair - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()" - net: bonding: add broadcast_neighbor option for 802.3ad - bonding: add support for per-port LACP actor priority - bonding: print churn state via netlink - bonding: 3ad: implement proper RCU rules for port->aggregator (CVE-2026-52975) - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) - bonding: fix NULL pointer dereference in actor_port_prio setting - staging: rtl8723bs: fix buffer over-read in rtw_update_protection (CVE-2026-53179) - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (CVE-2026-53341) - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs - hv: utils: handle and propagate errors in kvp_register - locking/mutex: Remove wakeups from under mutex::wait_lock - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued - phonet: Pass ifindex to fill_addr(). - phonet: Pass net and ifindex to phonet_address_notify(). - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157) - rxrpc: Fix the ACK parser to extract the SACK table for parsing (CVE-2026-53151) - fuse: re-lock request before replacing page cache folio - ftrace: Update the mcount_loc check of skipped entries - ftrace: Have ftrace pages output reflect freed pages - ftrace: Do not over-allocate ftrace memory - ftrace: Test mcount_loc addr before calling ftrace_call_addr() - ftrace: Check against is_kernel_text() instead of kaslr_offset() - net: ipv6: Make udp_tunnel6_xmit_skb() void - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070) - iio: light: veml6075: add bounds check to veml6075_it_ms index - iio: adc: ti-ads1298: add bounds check to pga_settings index - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero - ksmbd: reject non-VALID session in compound request branch - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si - virtiofs: fix UAF on submount umount - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support" - [amd64] KVM: SEV: Ignore MMIO requests of length '0' - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ - [amd64] KVM: SEV: Ignore Port I/O requests of length '0' - batman-adv: tp_meter: keep unacked list in ascending ordered - batman-adv: tp_meter: initialize dup_acks explicitly - batman-adv: tp_meter: initialize dec_cwnd explicitly - batman-adv: tp_meter: avoid window underflow - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd - batman-adv: tp_meter: fix fast recovery precondition - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection - batman-adv: tp_meter: add only finished tp_vars to lists - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE - batman-adv: prevent ELP transmission interval underflow - batman-adv: tp_meter: initialize last_recv_time during init - batman-adv: ensure bcast is writable before modifying TTL - batman-adv: fix (m|b)cast csum after decrementing TTL - batman-adv: frag: ensure fragment is writable before modifying TTL - batman-adv: frag: avoid underflow of TTL - batman-adv: v: prevent OGM aggregation on disabled hardif - batman-adv: tp_meter: restrict number of unacked list entries - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE - batman-adv: tp_meter: prevent parallel modifications of last_recv - batman-adv: tp_meter: handle overlapping packets - batman-adv: tt: don't merge change entries with different VIDs - batman-adv: tt: track roam count per VID - batman-adv: dat: prevent false sharing between VLANs - batman-adv: tvlv: enforce 2-byte alignment - batman-adv: tvlv: avoid race of cifsnotfound handler state - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362) - fs: constify file ptr in backing_file accessor helpers - lsm: add backing_file LSM hooks - selinux: fix overlayfs mmap() and mprotect() access checks - inet: add indirect call wrapper for getfrag() calls - ipv4: account for fraggap on the paged allocation path - ntfs3: reject direct userspace writes to reserved $LX* xattrs - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361) - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g - mac802154: llsec: add skb_cow_data() before in-place crypto - net: skmsg: preserve sg.copy across SG transforms - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink - apparmor: mediate the implicit connect of TCP fast open sendmsg - apparmor: fix use-after-free in rawdata dedup loop - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR - fbdev: fix use-after-free in store_modes() - kernel/fork: clear PF_BLOCK_TS in copy_process() - block: invalidate cached plug timestamp after task switch - err.h: use __always_inline on all error pointer helpers - KEYS: fix overflow in keyctl_pkey_params_get_2() - keys: Pin request_key_auth payload in instantiate paths - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer - wifi: ath11k: fix warning when unbinding - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor - wifi: rtw88: increase TX report timeout to fix race condition - wifi: rtw88: usb: fix memory leaks on USB write failures - wifi: iwlwifi: mvm: fix race condition in PTP removal - f2fs: validate compress cache inode only when enabled - f2fs: fix to round down start offset of fallocate for pin file - f2fs: validate ACL entry sizes in f2fs_acl_from_disk() - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() - f2fs: keep atomic write retry from zeroing original data - block: Avoid mounting the bdev pseudo-filesystem in userspace - bpf: use kvfree() for replaced sysctl write buffer - exfat: fix potential use-after-free in exfat_find_dir_entry() - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() - gfs2: fix use-after-free in gfs2_qd_dealloc - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() - hdlc_ppp: sync per-proto timers before freeing hdlc state - blk-cgroup: fix UAF in __blkcg_rstat_flush() - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done - pNFS: Fix use-after-free in pnfs_update_layout() - fpga: region: fix use-after-free in child_regions_with_firmware() - rpmsg: char: Fix use-after-free on probe error path - ocfs2: reject oversized group bitmap descriptors - 9p: avoid putting oldfid in p9_client_walk() error path - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() - [riscv64] mm: Extract helper mark_new_valid_map() - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect() - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var - fbdev: modedb: fix a possible UAF in fb_find_mode() - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode - i2c: core: fix adapter registration race - NFSD: Fix SECINFO_NO_NAME decode error cleanup - nfsd: fix posix_acl leak on SETACL decode failure - nfsd: check get_user() return when reading princhashlen - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race - nfsd: reset write verifier on deferred writeback errors - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr - NFS: Prevent resource leak in nfs_alloc_server() - ksmbd: fix out-of-bounds read in smb_check_perm_dacl() - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails - drivers/base/memory: set mem->altmap after successful device registration - Documentation: ioctl-number: Fix linuxppc-dev mailto link - Documentation: ioctl-number: Extend "Include File" column width - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources - [amd64] crypto: qat - remove unused character device and IOCTLs - net/tcp-ao: fix use-after-free of key in del_async path - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex - net: bonding: update the slave array for broadcast mode - bonding: annotate data-races arcound churn variables - bonding: do not set usable_slaves for broadcast mode . [ Salvatore Bonaccorso ] * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686) * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." . [ Uwe Kleine-König ] * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly (Closes: #1136179) linux (6.12.95-1~bpo12+1) bookworm-backports; urgency=medium . * Rebuild for bookworm-backports . linux (6.12.95-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95 - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain - wifi: mt76: mt7921: fix a potential scan no APs - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (CVE-2026-53101) - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167) - gpiolib: Extract gpiochip_choose_fwnode() for wider use - gpiolib: Remove redundant assignment of return variable - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (CVE-2026-31732) - io_uring/net: Avoid msghdr on op_connect/op_bind async data - drm/xe/display: fix oops in suspend/shutdown without display (CVE-2026-53142) - [arm64] drm/v3d: Store the active job inside the queue's state - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139) - eventpoll: use hlist_is_singular_node() in __ep_remove() - eventpoll: split __ep_remove() - eventpoll: kill __ep_remove() - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() - eventpoll: rename ep_remove_safe() back to ep_remove() - eventpoll: move epi_fget() up - eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355) - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216) - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP - debugobjects: Do not fill_pool() if pi_blocked_on - debugobjects: Dont call fill_pool() in early boot hardirq context - RDMA/bnxt_re: zero shared page before exposing to userspace - i2c: stub: Reject I2C block transfers with invalid length - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe() (CVE-2026-53325) - bpf: Reject sleepable kprobe_multi programs at attach time (CVE-2026-43010) - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() - regulator: core: fix locking in regulator_resolve_supply() error path - dlm: prevent NPD when writing a positive value to event_done (CVE-2025-23131) - xfs: remove the expr argument to XFS_TEST_ERROR - xfs: fix error returns in CoW fork repair - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()" - net: bonding: add broadcast_neighbor option for 802.3ad - bonding: add support for per-port LACP actor priority - bonding: print churn state via netlink - bonding: 3ad: implement proper RCU rules for port->aggregator (CVE-2026-52975) - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) - bonding: fix NULL pointer dereference in actor_port_prio setting - staging: rtl8723bs: fix buffer over-read in rtw_update_protection (CVE-2026-53179) - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (CVE-2026-53341) - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs - hv: utils: handle and propagate errors in kvp_register - locking/mutex: Remove wakeups from under mutex::wait_lock - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued - phonet: Pass ifindex to fill_addr(). - phonet: Pass net and ifindex to phonet_address_notify(). - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157) - rxrpc: Fix the ACK parser to extract the SACK table for parsing (CVE-2026-53151) - fuse: re-lock request before replacing page cache folio - ftrace: Update the mcount_loc check of skipped entries - ftrace: Have ftrace pages output reflect freed pages - ftrace: Do not over-allocate ftrace memory - ftrace: Test mcount_loc addr before calling ftrace_call_addr() - ftrace: Check against is_kernel_text() instead of kaslr_offset() - net: ipv6: Make udp_tunnel6_xmit_skb() void - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070) - iio: light: veml6075: add bounds check to veml6075_it_ms index - iio: adc: ti-ads1298: add bounds check to pga_settings index - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero - ksmbd: reject non-VALID session in compound request branch - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si - virtiofs: fix UAF on submount umount - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support" - [amd64] KVM: SEV: Ignore MMIO requests of length '0' - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ - [amd64] KVM: SEV: Ignore Port I/O requests of length '0' - batman-adv: tp_meter: keep unacked list in ascending ordered - batman-adv: tp_meter: initialize dup_acks explicitly - batman-adv: tp_meter: initialize dec_cwnd explicitly - batman-adv: tp_meter: avoid window underflow - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd - batman-adv: tp_meter: fix fast recovery precondition - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection - batman-adv: tp_meter: add only finished tp_vars to lists - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE - batman-adv: prevent ELP transmission interval underflow - batman-adv: tp_meter: initialize last_recv_time during init - batman-adv: ensure bcast is writable before modifying TTL - batman-adv: fix (m|b)cast csum after decrementing TTL - batman-adv: frag: ensure fragment is writable before modifying TTL - batman-adv: frag: avoid underflow of TTL - batman-adv: v: prevent OGM aggregation on disabled hardif - batman-adv: tp_meter: restrict number of unacked list entries - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE - batman-adv: tp_meter: prevent parallel modifications of last_recv - batman-adv: tp_meter: handle overlapping packets - batman-adv: tt: don't merge change entries with different VIDs - batman-adv: tt: track roam count per VID - batman-adv: dat: prevent false sharing between VLANs - batman-adv: tvlv: enforce 2-byte alignment - batman-adv: tvlv: avoid race of cifsnotfound handler state - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362) - fs: constify file ptr in backing_file accessor helpers - lsm: add backing_file LSM hooks - selinux: fix overlayfs mmap() and mprotect() access checks - inet: add indirect call wrapper for getfrag() calls - ipv4: account for fraggap on the paged allocation path - ntfs3: reject direct userspace writes to reserved $LX* xattrs - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361) - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g - mac802154: llsec: add skb_cow_data() before in-place crypto - net: skmsg: preserve sg.copy across SG transforms - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink - apparmor: mediate the implicit connect of TCP fast open sendmsg - apparmor: fix use-after-free in rawdata dedup loop - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR - fbdev: fix use-after-free in store_modes() - kernel/fork: clear PF_BLOCK_TS in copy_process() - block: invalidate cached plug timestamp after task switch - err.h: use __always_inline on all error pointer helpers - KEYS: fix overflow in keyctl_pkey_params_get_2() - keys: Pin request_key_auth payload in instantiate paths - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer - wifi: ath11k: fix warning when unbinding - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor - wifi: rtw88: increase TX report timeout to fix race condition - wifi: rtw88: usb: fix memory leaks on USB write failures - wifi: iwlwifi: mvm: fix race condition in PTP removal - f2fs: validate compress cache inode only when enabled - f2fs: fix to round down start offset of fallocate for pin file - f2fs: validate ACL entry sizes in f2fs_acl_from_disk() - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() - f2fs: keep atomic write retry from zeroing original data - block: Avoid mounting the bdev pseudo-filesystem in userspace - bpf: use kvfree() for replaced sysctl write buffer - exfat: fix potential use-after-free in exfat_find_dir_entry() - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() - gfs2: fix use-after-free in gfs2_qd_dealloc - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() - hdlc_ppp: sync per-proto timers before freeing hdlc state - blk-cgroup: fix UAF in __blkcg_rstat_flush() - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done - pNFS: Fix use-after-free in pnfs_update_layout() - fpga: region: fix use-after-free in child_regions_with_firmware() - rpmsg: char: Fix use-after-free on probe error path - ocfs2: reject oversized group bitmap descriptors - 9p: avoid putting oldfid in p9_client_walk() error path - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() - [riscv64] mm: Extract helper mark_new_valid_map() - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect() - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var - fbdev: modedb: fix a possible UAF in fb_find_mode() - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode - i2c: core: fix adapter registration race - NFSD: Fix SECINFO_NO_NAME decode error cleanup - nfsd: fix posix_acl leak on SETACL decode failure - nfsd: check get_user() return when reading princhashlen - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race - nfsd: reset write verifier on deferred writeback errors - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr - NFS: Prevent resource leak in nfs_alloc_server() - ksmbd: fix out-of-bounds read in smb_check_perm_dacl() - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails - drivers/base/memory: set mem->altmap after successful device registration - Documentation: ioctl-number: Fix linuxppc-dev mailto link - Documentation: ioctl-number: Extend "Include File" column width - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources - [amd64] crypto: qat - remove unused character device and IOCTLs - net/tcp-ao: fix use-after-free of key in del_async path - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex - net: bonding: update the slave array for broadcast mode - bonding: annotate data-races arcound churn variables - bonding: do not set usable_slaves for broadcast mode . [ Salvatore Bonaccorso ] * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686) * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." . [ Uwe Kleine-König ] * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly (Closes: #1136179) linux-signed-amd64 (6.12.107+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.107-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.106 - PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept - ALSA: scarlett2: Use a private URB for the notification endpoint - rndis_host: add overflow check in rndis_rx_fixup() - gpio: ml-ioh: use raw_spinlock_t for the register lock (CVE-2026-80562) - gve: fix zero-length skb frag with header-split - hwmon: (ltc4286) Fix symbol namespace of MODULE_IMPORT_NS() - netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() (CVE-2026-64216) - inet: frags: add inet_frag_putn() helper - ipv4: frags: remove ipq_put() - inet: frags: change inet_frag_kill() to defer refcount updates - inet: frags: save a pair of atomic operations in reassembly - inet: frags: publish queues before arming timer (CVE-2026-74662) - serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx (CVE-2026-74653) - NTB: ntb_netdev: Preserve RX queue depth on allocation failure (CVE-2026-74626) - serial: amba-pl011: synchronize DMA teardown - serial: sc16is7xx: rename EFR mutex with generic name - serial: sc16is7xx: use guards for simple mutex locks - serial: sc16is7xx: enable THRI before filling TX FIFO - xfs: namespace the maximum length/refcount symbols - xfs: don't use a xfs_log_iovec for ri_buf in log recovery - xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536) - xfs: hoist per-bucket unlinked list check to helper - xfs: don't livelock in scrub on a circular unlinked list - ALSA: dummy: Check card index validity at probe - ocfs2: fix missing metadata reservation for large xattrs - null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows - kcov: fix data corruption and race conditions on PREEMPT_RT - ext4: stop retrying saturated xattr cache entries - ext4: clear error before retrying inode xattr space fallback - ext4: propagate errors from fast commit range replay - xfs: validate attr entry pointer before field access - libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557) - nfc: digital: clamp SENSF_RES length to the destination buffer - nfc: fdp: bound the device-reported read length and fix an skb leak - nfc: microread: validate target discovery payload lengths - nfc: llcp: bound the connect_sn TLV walk to the skb - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers - nfc: llcp: reject PDUs shorter than the LLCP header - nfc: pn533: purge fragmented skbs during cleanup - nfc: st21nfca: validate ATR_REQ length against the received frame - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers - nfc: nci: free destination parameters when closing a connection - ndisc: ndisc_send_redirect() cleanup - Input: byd - synchronize timer deletion before freeing private data (CVE-2026-80572) - ipv4: reject undersized MTUs in ip_do_fragment() - ipv6: fix use-after-free in ip6_finish_output2() - nvmet-auth: zero the AUTH_RECEIVE response buffer - nvmet-fc: fix invalid free in LS IOD error path - nvmet-tcp: bound SGL data length before allocating command buffers - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations - mptcp: pm: fix data race in add_addr timer callback - [arm64] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (CVE-2026-80583) - drm/xe: Fix DPT allocation paths. - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C - HID: magicmouse: re-enable multitouch after reset-resume - HID: magicmouse: do not keep a stale msc->input if no input is claimed - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID - HID: core: fix OOB read of field->usage in hid_set_field() - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ - xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (CVE-2026-64581) - ipv4: start using dst_dev_rcu() (CVE-2025-40074) - mptcp: pm: fix memory leak from alloc-during-teardown race - Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard - Input: atkbd - skip deactivate for HONOR ZQC-P - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() - HID: nintendo: register input device after capabilities are set - HID: nintendo: stop device IO before hid_hw_stop on probe failure - HID: core: fix number/pointer type confusion on long items - HID: sensor: custom: Fix use-after-free in enable_sensor - HID: hyperv: validate initial device info bounds - Bluetooth: hci_event: fix LE list UAF on reset - Bluetooth: hci_event: validate LE Set CIG Parameters response - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync - Bluetooth: hci_aml: validate firmware segment lengths - net: gro: properly validate BIG TCP aggregation criteria https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.107 - inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590) linux-signed-amd64 (6.12.105+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.105-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.102 - [amd64] x86/bugs: Make Safe-RET robust against interrupt injection (CVE-2026-68480) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.103 - netfilter: nf_conntrack_expect: restore helper propagation via expectation - netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() - net: mpls: initialize rtm_tos in mpls_getroute() - HID: logitech-dj: Standardise hid_report_enum variable nomenclature - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report - bpf: Reset register bounds before narrowing retval range in check_mem_access() - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197) - [amd64] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect - [arm64] pinctrl: qcom: Unconditionally mark gpio as wakeup enable - [arm64] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA - [amd64] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() - ata: sata_mv: accept 1 or 2 resources in platform probe - ata: libahci_platform: support non-consecutive port numbers - ahci: Introduce ahci_ignore_port() helper - ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup - of: reserved_mem: Add code to dynamically allocate reserved_mem array - of: reserved_mem: prevent OOB when too many dynamic regions are defined - btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag - btrfs: zoned: fix deadlock between metadata writeback and transaction commit - [arm64] phy-zynqmp: Postpone getting clock rate until actually needed - [arm64] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() - [arm64] phy: zynqmp: fix runtime PM leak on probe allocation failure - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() - [arm64] drm/mediatek: Check CRTC state before freeing - Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation - KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type - keys: fix out-of-bounds read in keyring_get_key_chunk() - keys: make keyring key-chunk byte order agree with keyring_diff_objects() - assoc_array: trim the final shortcut word using the current chunk end - netfilter: nf_tables: make nft_object rhltable per table - netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH - ipvs: fix the checksum validations - ipvs: fix places with wrong packet offsets - ipvs: do not mangle ICMP replies for non-first fragments - netfilter: nft_payload: fix mask build for partial field offload - rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (CVE-2026-68322) - rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() - [amd64,arm64] pinctrl-amd: Don't clear S4 wake bits at probe - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer - scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race - smb: client: fix buffer leaks in SMB1 read and write - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 - hwmon: (ina2xx) Add support for has_alerts configuration flag - hwmon: (ina2xx) Add support for INA260 - hwmon: (ina226) Add support for SY24655 - hwmon: (ina2xx) Make it easier to add more devices - hwmon: (ina2xx) Add support for INA234 - hwmon: (ina2xx) Shift INA234 shunt and current registers - hwmon: (ina2xx) Fix various overflow issues - hwmon: (ltc4282) Fix reading the minimum alarm voltage - hwmon: (sht3x) Fix unaligned accesses - hwmon: (lm90) Only report alarms if driver is ready - hwmon: (nzxt-smart2) DMA-align output buffer - net: do not send ICMP/NDISC Redirects when peer allocation fails - hwmon: (nct6775-core) Prevent access to unsupported weight registers - net: bridge: mrp: fix Option TLV length in MRP_Test frames - forcedeth: fix UAF of txrx_stats in nv_remove - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors - hwmon: (adt7470) Fix cache updated before hardware write on I2C error - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks - hwmon: (adt7470) Use cached PWM frequency value - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read - hwmon: (adt7470) Fix PWM auto temp state array and bounds check - rtase: fix double free of multi-frag skb on DMA map failure - [powerpc*] boot: Fix simpleboot CPU node lookup check - [powerpc*] boot: Fix treeboot-currituck CPU node lookup check - [powerpc*] boot: Fix treeboot-akebono CPU node lookup check - net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() - wifi: mac80211: validate individual TWT params before driver setup - net: ethernet: mtk_eth_soc: support named IRQs - net: ethernet: mtk_eth_soc: add consts for irq index - net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() - [amd64,arm64] idpf: adjust TxQ ring count minimum - [amd64,arm64] idpf: Fix mailbox IRQ name leak on request failure - Bluetooth: ISO: clear iso_data always when detaching conn from hcon - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() - Bluetooth: ISO: fix leaking sk after socket release - Bluetooth: ISO: avoid deadlocks in iso_sock_timeout - Bluetooth: btintel: Validate length before parsing diagnostics TLV - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() - Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync - net: phylink: put link_gpio if phylink_create fails - scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE - scsi: ufs: core: Cancel RTC work in active-active suspend - scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req - scsi: target: Clear cmd_cnt when initial counter enrollment fails - net: sxgbe: free TX rings on RX allocation failure - net: sxgbe: check descriptor ring allocation failures - can: isotp: check register_netdevice_notifier() error in module init - tracing/mmiotrace: Reset dropped_count in mmio_reset_data() - tracing: Remove TRACE_EVENT_FL_FILTERED logic - tracing/mmiotrace: Remove reference to unused per CPU data pointer - tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions - [riscv64] mm: Fix out-of-bounds page-table walk during memory hot-remove - [arm64] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend - [arm64] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling - net: libwx: fix FDIR ATR queue mismatch for software VLAN packets - [arm64] octeontx2-pf: Set correct sequence for carrier off and tx queue stop - sched/deadline: Use revised wakeup rule only for running dl_server - qede: sync udp_tunnel ports outside qede_lock in the recovery path - ksmbd: return success for deferred final close - ksmbd: fix use-after-free in __close_file_table_ids() - pinctrl: devicetree: don't free uninitialized dev_name on error path - erofs: cap LZMA stream pool size - pinctrl: bm1880: add missing select GENERIC_PINCONF - fortify: Disable -Wstringop-overread in tests - mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() - mm/hugetlb: fix list corruption in allocate_file_region_entries() - mm/vmstat: fold stranded per-cpu node stats when a node comes online - tracing/probes: Reject $arg0 in meta argument expansion - [amd64] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active - [s390x] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled - [s390x] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure - [s390x] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages - sctp: validate Adaptation Indication parameter length - audit: fix potential integer overflow in audit_log_n_string() - audit: fix potential use-after-free in audit_del_rule() - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() - Bluetooth: mgmt: fix pending command UAF in EIR updates - Bluetooth: mgmt: fix UAF in pair command cancellation - Bluetooth: hci_sync: Fix advertising data UAFs - Bluetooth: HIDP: reject frames without a transaction header - Bluetooth: HIDP: validate numbered report payloads - bpf: lwt: Fix dst reference leak on reroute failure - ALSA: 6fire: Fix UAF at error handling during probe - ALSA: lx6464es: fix period byte count for 16-bit streams - ALSA: pcm: wake linked drain waiters on unlink - ALSA: seq: Fix division by zero in initialize_timer() - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes - ALSA: ump: fix double free of out_cvts on rawmidi error - ASoC: tas2562: fix DVC coefficient write order - ASoC: tas2562: fix broken entries in the volume lookup table - ata: libata-eh: Increase STANDBY IMMEDIATE timeout - ata: libata-sata: fix ata_scsi_lpm_supported() iteration - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() - ALSA: usb-audio: fix stack info leak in RME Digiface status - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set - ALSA: usb-audio: Clamp frame size in implicit-feedback mode - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ - e1000: fix memory leak in e1000_probe() - igbvf: Fix leak in TX DMA error cleanup - ipvs: do not propagate one-packet flag to synced conns - net/smc: fix socket use-after-free during link group termination - netfilter: ipset: do not update comments from kernel-side hash adds - tipc: avoid use-after-free in poll trace queue dumps - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames - binfmt_misc: reject a flag character as the field delimiter - binfmt_misc: don't let an 'F' entry pin its own instance - mm/page_reporting: use system_freezable_wq to fix UAF during suspend - mm: memcg: initialize *locked in memcg1_oom_prepare() stub - net: bridge: stop fast-leave after deleting a port group - net: ipv6: clear suppressed fib6 rule result - [powerpc*] ps3: Fix map failure path in dma_ioc0_map_pages() - veth: convert frag_list skbs before running XDP - vxlan: re-fetch eth header after route_shortcircuit() - vxlan: unclone skb head before modifying eth header in route_shortcircuit() - vxlan: use neigh_ha_snapshot() in route_shortcircuit() - vxlan: use pskb_network_may_pull() in route_shortcircuit() - ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() - tracing: Check return value of __register_event() in trace_module_add_events() - tracing/filters: Fix false positive match in regex_match_full() - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write - sctp: reject stale cookies with mismatched verification tags - sctp: prevent peer transport count overflow - hwmon: (npcm750-pwm-fan): stop fan timer on device detach - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client - i2c: amd-mp2: Unregister callback on adapter add failure - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() - cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized - power: supply: bq25890: fix the -10 C NTC lookup entry - power: supply: max17040: handle missing status supplier - [s390x] pci: Fix s390_pci_mmio_write syscall error return without MIO - [s390x] qeth: Check CAP_NET_ADMIN for private ioctls - [s390x] dasd: Fix potential NULL pointer dereference - [s390x] dasd: Fix undersized format-check buffer - [s390x] zcrypt: Fix wrong domain value verification with EP11 CPRBs - [s390x] zcrypt: Validate length for CCA AES cipher key requests - [s390x] zcrypt: Validate length for CCA ECC private key requests - [arm64] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask - [arm64] phy: zynqmp: use read-modify-write for SERDES scrambler bypass - [arm64] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB - net: openvswitch: fix potential UAF on meter attach failure - net: openvswitch: fix skb leak on flow key update failure during recirculation - net: openvswitch: fix skb leak on flow key update failure during ct - ice: wait for reset completion in ice_resume() - ice: fix memory leak in ice_lbtest_prepare_rings() - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock - i2c: iproc: reset bus after timeout if START_BUSY is stuck - i2c: imx: Fix slave registration race and error handling - i2c: imx: Cancel hrtimer before clearing slave pointer - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured - can: ems_usb: validate CPC message lengths - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents - can: softing: fw_parse(): validate firmware record spans - can: peak_usb: add bounds check for USB channel index - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error - can: peak_usb: validate uCAN receive record lengths - can: ctucanfd: add missing MODULE_DEVICE_TABLE() - can: ctucanfd: use self-test mode for PRESUME_ACK - can: ctucanfd: unmap BAR0 using base address - can: ctucanfd: handle bus error interrupts - can: ctucanfd: mark error-active controller status valid - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs - [arm*] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size - [arm*] drm/vc4: Zero the tile state data array before each BIN job - [arm64] drm/panthor: reject firmware sections with oversized data - [arm64] drm/panthor: validate firmware interface structure sizes - [arm64] drm/mediatek: ovl_adaptor: balance component registrations - drm/amdgpu: restore UMD profile pstate after runtime resume - drm/amdgpu: cap GTT size to physical RAM on APUs - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames - drm/amd/display: use proper context for logging - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE - drm/amdkfd: fix QID bit leak in pqm_create_queue() - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment - drm/amdkfd: Handle invalid event type in CRIU event restore - drm/amdkfd: hold event_mutex while checkpointing CRIU events - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size - drm/vmwgfx: reject DX_BIND_QUERY without a DX context - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division - drm/vmwgfx: bound DMA command body size against suffix pointer - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure - drm/vmwgfx: use check_add_overflow for shader size+offset bound - drm/vmwgfx: validate external BO copy bounds for both stride paths - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX - HID: logitech-dj: Fix maxfield check in DJ short report validation - ata: libahci_platform: Do not set mask_port_map when not needed - ata: ahci: Make ahci_ignore_port() handle empty mask_port_map - of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release - drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting - drm/xe: Introduce xe_gt_dbg_printer() - drm/xe: Apply whitelist to engine save-restore - drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267) - drm/xe/rtp: Maintain OA whitelists separately - drm/xe/rtp: Keep track of non-OA nonpriv slots - drm/xe/rtp: Generalize whitelist_apply_to_hwe - drm/xe/rtp: Save OA nonpriv registers to register save/restore lists - drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs - drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt - drm/xe/oa: (De-)whitelist OA registers on OA stream open/release - drm/xe/rtp: Ensure locking/ref counting for OA whitelists - mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios - lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() - mm/slab: prevent unbounded recursion in free path with new kmalloc type - gpio: pch: use raw_spinlock_t for the register lock - usb: gadget: f_tcm: synchronize delayed set_alt with teardown (CVE-2026-68367) - usb: typec: ucsi: split connector lock classes - usb: typec: ucsi: Fix race condition and ordering in port unregistration - media: i2c: imx219: Rename VTS to FRM_LENGTH - media: imx219: Fix maximum frame length in lines - media: chips-media: wave5: Support CBP profile - media: uapi: rkisp: Correct name version enum - wifi: brcmfmac: drain bus_reset work on device removal (CVE-2026-64586) - wifi: ath6kl: fix use-after-free in aggr_reset_state() (CVE-2026-68198) - wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change - mptcp: pm: avoid code duplication to lookup endp - mptcp: add mptcp_userspace_pm_lookup_addr helper - mptcp: pm: use addr entry for get_local_id - mptcp: pm: userspace: fix use-after-free in get_local_id (CVE-2026-68169) - drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions - drm/amdgpu: Fix context pstate override handling (CVE-2026-68273) - drm/sched: Store the drm client_id in drm_sched_fence - drm/amdgpu: give each kernel job a unique id - drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (CVE-2026-68276) - drm/fb-helper: Allocate and release fb_info in single place - drm/tegra: fbdev: Remove offset into framebuffer memory - drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] - drm/xe: Wait on external BO kernel fences in exec IOCTL - [arm64] drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() - [arm64] drm/i915/vrr: require valid min/max vfreq for VRR (CVE-2026-68254) - drm/xe: Rename ___xe_bo_create_locked() - drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266) - [arm64] drm/i915/hdcp: Move to using intel_display in intel_hdcp - [arm64] drm/i915/hdcp: require monotonically increasing seq_num_v - [arm64] drm/i915/hdcp: Skip inactive MST connectors when building stream list - [arm64] drm/i915/hdcp: check streams[] bounds before overflow (CVE-2026-68253) - drm/xe: Stub out new pagefault layer - drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (CVE-2026-68264) - rxrpc: Generate rtt_min - rxrpc: Adjust the rxrpc_rtt_rx tracepoint - rxrpc: Fix the calculation and use of RTO - rxrpc: Manage RTT per-call rather than per-peer - rxrpc: Fix irq-disabled in local_bh_enable() (CVE-2025-38525) - can: use skb hash instead of private variable in headroom - can: isotp: fix timer drain order, wakeup handling and tx_gen ordering - usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path - drm/fb-helper: Fix a locking bug in an error path - [arm64,armhf] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.104 - mount: honour SB_NOUSER in the new mount API - drm/amd/display: Add AV mute wait frames to dce110_set_avmute - drm/amd/display: Check for tg ops in dce110_set_avmute - [s390x] zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call - [arm64] dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer - drm/bridge: ps8640: propagate AUX transfer register errors - [arm64] net: hns3: fix speed configuration residue after driver reload - Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor - enic: fix tx_hang_reset use-after-free on device removal - net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock - pds_core: keep the health thread stopped during reset - pds_core: cancel pending PCI reset work on AER recovery - netfilter: ipset: switch ext_size to atomic64_t - ipvs: avoid out-of-bounds write in ip_vs_nat_icmp - ipvs: return the csum validation for forward hook - watchdog: bd96801_wdt: Fix timeout for enabled WDG - btrfs: fix memory leak in btrfs_do_encoded_write() - bpf: Preserve pointer state for commuted arithmetic - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() - net/sched: cls_route: fix fastmap use-after-free on filter - [arm64] net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete - devlink: fix net namespace reference leak in reload - net/mlx5: fw_tracer, return NULL on create error - counter: microchip-tcb-capture: Fix DT channel validation - bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch - bpf: tcp: Make sure iter->batch always contains a full bucket snapshot - bpf: tcp: Get rid of st_bucket_done - bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items - bpf: tcp: Avoid socket skips and repeats during iteration - bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() - vhost/vdpa: reject overflowing PA map page counts on 32-bit - vdpa/mlx5: Fix buffer length in create_direct_keys() - tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() - xsk: require at least 16 bytes of TX metadata - udp: fix potential use-after-free in tunnel segmentation - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter - net/openvswitch: check Ethernet header length in key_extract() - net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers - hwmon: (nzxt-smart2) Check return value of init_device() in probe - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations - bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() - bnxt_en: Determine and store default RX ring in vnic structure - bnxt_en: Refresh VNIC default ring on queue restart if needed - bnxt_en: Fix PTP PPS setting bug - sctp: fix addip_serial increment on ASCONF_ACK allocation failure - tcp: fix TFO max_qlen accounting across reuseport migration - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length - net: prestera: validate firmware header length - net: remove WARN_ON_ONCE() from sk_mc_loop() - net/smc: fix TOCTOU race between smc_listen_out() and listener close - [amd64] net: thunderbolt: Tear down DMA paths before stopping the rings - ata: pata_sl82c105: fix bridge revision use-after-free - net/atm: fix slab-out-of-bounds read in vcc_setsockopt() - sctp: clear control chunk transport if it is being removed - tls: don't abort the connection on signal-interrupted sends - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination - hwmon: (ads7828) Fix external VREF regulator handling - hwmon: (ltc4282) Avoid overflow in maximum power calculation - hwmon: (ltc4282) Clamp negative current limits - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt - mm/vmscan: wake up flushers conditionally to avoid cgroup OOM (Closes: #1143545) - net: fec: do not release NULL pages when RX buffer allocation fails - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers - mtd: spinand: fix direct mapping creation sizes - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails - mtd: spinand: repeat reading in regular mode if continuous reading fails - swapfile: call cond_resched() before locking si->lock - Input: evdev - sanitize event type index when fetching event masks - ALSA: usb-audio: fix OOB write on Type II inbound URBs - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() - [amd64] thunderbolt: icm: Preserve USB4 proxy data-valid bit - usb: cdnsp: fix incorrect endian conversions for APB timeout register - usb: gadget: f_ncm: Use unsigned int for ndp_index - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() - net: usb: ipheth: fix carrier_work UAF on disconnect - vt: add permission check for KDSKBMETA ioctl - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get - Input: evdev - fix information leak in evdev_pass_values() - ima: fix out-of-bounds read in xattr_verify() - ipvs: stop estimator after disabled calc phase - ipvs: add totalconns for dest - ipvs: properly update the overload flag on dest edit - ipvs: clear IPv4 options after rebasing tunnel ICMP errors - packet: use consistent hard_header_len in non-ring send paths - packet: use consistent hard_header_len in TX_RING send path - net/packet: reset the MAC header on the packet-socket transmit path - packet: synchronize pressure clearing with ring reconfiguration - net: fix skb length accounting after generic XDP frag adjustment - net: openvswitch: reallocate update replies for mismatched IDs - net/sched: reject overly deep qdisc hierarchies - net: octeontx2-pf: Fix UB in shift operation - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header - mac802154: fix netdev use-after-free in beacon worker - netfilter: ebt_nflog: pin the NFLOG backend - net: bridge: mrp: fix uninitialised bytes on the wire - [s390x] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (CVE-2026-74514) - [s390x] KVM: s390: pci: Fix missing error codes and memory unaccounting - [s390x] KVM: s390: pci: Fix resource leak on IRQ registration failure - [s390x] KVM: s390: pci: Fix aisb calculation - block: Reorder the request allocation code in blk_mq_submit_bio() - blk-mq: pop cached request if it is usable (CVE-2026-64017) - blk-mq: reinsert cached request to the list - dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk - [amd64] crypto: ccp - Add new SEV/SNP platform shutdown API - [amd64] KVM: SVM: Add support to initialize SEV/SNP functionality in KVM - [amd64] crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length - [amd64] crypto: ccp - Abort doing SEV INIT if SNP INIT fails - futex: Prevent robust futex exit race some more - kunit/fortify: Replace "volatile" with OPTIMIZER_HIDE_VAR() - kunit/fortify: Add back "volatile" for sizeof() constants - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops - ipv4: fix use-after-free in fib_nhc_update_mtu() - mei: pull kvfree out of spinlock - nvmem: layouts: Add fixed-layout driver - serial: qcom-geni: fix TX DMA buffer flush - serial: 8250_dma: Clear stale RX state on shutdown - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() - staging: rtl8723bs: fix OOB read in WMM_param_handler() - staging: rtl8723bs: fix missing shared-key auth challenge length check - staging: rtl8723bs: validate monitor transmit frame lengths - misc: fastrpc: fix channel ctx ref leak when session alloc fails - misc: fastrpc: Remove buffer from list prior to unmap operation - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free - ring-buffer: Fix crash passing ERR_PTR to kthread_stop() - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs - ALSA: usx2y: bound the hwdep mmap fault offset - tracing: Fix race between update_event_fields and, event_define_fields - fbdev: bitblit: bound-check glyph index in bit_cursor() - ring-buffer: Prevent subbuf order change when resizing is disabled - mm/huge_memory: fix huge_zero_pfn race - net: smc: fix splice entry lifetime imbalance in smc_rx_splice - ipv6: prevent in6_dev_get() from resurrecting inet6_dev - netfilter: bridge: release template ct on non-IP path - netfilter: nf_conntrack: defer invalid log until after unlock - net: atlantic: free stranded TX buffers on ring deinit - net: atlantic: free RX pages of consumed but not refilled buffers - net/sched: act_ct: fix sk_buff leak when the header checks reject a packet - net/sched: act_gact, act_police: range check the fallback control action - ovl: don't warn when the mount is completed from another user namespace - binfmt_misc: don't warn when the mount is completed from another user namespace - Revert "drm/amdgpu: fix aperture mapping leak" - xdp: reject clones that overrun skb_shared_info tailroom - vxlan: do not arm the ageing timer on a device that is down - vsock/virtio: read virtqueues under worker locks - vsock/virtio: avoid refilling the RX queue after teardown - veth: fix skb length accounting after XDP frag adjustment - vhost: reset the vring metadata cache on vring reconfiguration - tls: don't leave a full plaintext sk_msg ring unpushed - tipc: read le->link under the node lock in tipc_node_link_down() - smb: client: Fix use-after-free in cifs_try_adding_channels() - [amd64] KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page - eventfs: Fix use-after-free in eventfs_remove_rec() - Revert "thermal/drivers/hwmon: Cleanup coding style a bit" - ptp: ocp: Fix board ID over-read - ipv6: fix Route Information option length validation - ip6_tunnel: clear skb2->cb[] in ip6ip6_err() - fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() - sched/psi: Shut down rtpoll_timer in psi_cgroup_free() - ima: Instantiate file_truncate and path_truncate hooks - fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions - fsverity: Fix silent truncation in bpf_get_fsverity_digest() - bpf, sockmap: Fix sk_redir use-after-free in send verdict - scsi: scsi_debug: Negate wrapped memcmp() result - sctp: keep chunk->transport in step with the list it is queued on - sctp: fix use-after-free of cached ASCONF chunk - sctp: clear new_transport when removing a peer - [amd64] thunderbolt: Bound the DROM dual link port number before indexing sw->ports - [amd64] thunderbolt: Fix bandwidth group reservation indexing - bpf: tcp: fix double sock release on batch realloc https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.105 - block: stop the timeout timer when releasing a never added disk - bpf: Fix linked reg delta tracking when src_reg == dst_reg (CVE-2026-53092) - bpf: Clear delta when clearing reg id for non-{add,sub} ops - f2fs: fix UAF issue in f2fs_merge_page_bio() (CVE-2025-40054) - mtd: ubi: skip programming unused bits in ubi headers - ubi: fastmap: fix ubi->fm memory leak - mm/damon/ops-common: putback folios on invalid migrate nid (CVE-2026-74644) - mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} - igc: fix netdev not re-attached after resume if interface is down - ipvs: separate destination availability state - net: mana: Fix EQ leak in mana_remove on NULL port - [amd64] crypto: ccp: Add external API interface for PSP module initialization - [amd64] KVM: SVM: Ensure PSP module is initialized if KVM module is built-in - selinux: require every boolean value to be defined - selinux: reject a class permission count below its inherited common - selinux: do not cancel a policy conversion that never started - selinux: reject an unclaimed class value in security_get_classes() - mptcp: avoid combining some incoming suboptions - mptcp: options: reset DSS fields in case of unexpected size - mptcp: fastopen: only mark MPTFO subflows with SYN data - [s390x] qeth: validate user buffer length in SNMP and ARP query ioctls - [amd64] ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() - fbdev: core: Fix pointer desynchronization in fb_io_read() - drm/panthor: skip zero-sized firmware sections - drm/amdgpu: reject oversized IBs with per-ring packet limits - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 - drm/amdgpu: fix aperture iounmap skipped on device removal - [amd64] ASoC: SOF: topology: Use acpi mach from the machine driver - Input: xpad - add support for ZENAIM LEVERLESS - Input: cs40l50-vibra - validate custom data from user space - [powerpc*] pseries: pci - logic bug - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet - Input: psxpad-spi - set driver data before use - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard - Input: iforce - validate input packet lengths - [powerpc*] pseries: lparcfg - fix kbuf[] underflow - Input: synaptics-rmi4 - zero report size on F54 work error - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer - Input: synaptics-rmi4 - block s_input when F54 queue is busy - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue - Input: hynitron_cstxxx - validate touch count and finger IDs - [arm64] crypto: qce - fix error path in devm_qce_register_algs - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind - [arm64] pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 - libceph: fix multiple unsafe decodes in decode_locker() - ftrace: Protect direct_functions in ftrace_find_rec_direct - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() - Input: sur40 - fix input device registration ordering - Input: sur40 - fix V4L error path cleanup - libceph: Avoid using invalid osd indices from primary_temp - ceph: fix MDS random selection readiness predicate - libceph: tolerate addrvecs with multiple entries of the same type - [armhf] mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit - mmc: sdhci: unmap the bounce buffer before device release - mmc: sdhci: make tuning_err a signed int - drm/connector/hdmi: Fix out of bounds memory read - drm/xe: Order ring writes before ring tail updates - drm/radeon: fix autosuspend cleanup during teardown - [s390x] vfio_ccw: Free all memory if cp_init() fails - [s390x] vfio_ccw: Limit the number of channel program segments - [s390x] vfio_ccw: Cancel existing workqueues - [s390x] vfio_ccw: Ensure index for read/write regions are within range - [s390x] vfio_ccw: Ensure first IDAW remains constant - [s390x] vfio_ccw: Fix out of bounds check on CCW array - [s390x] vfio_ccw: Move cp cleanup out of not operational - [s390x] vfio_ccw: Selectively expand io_mutex - [s390x] vfio_ccw: Calculate idal length based on idaw type - [s390x] vfio_ccw: Implement a crw lock - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE - drm/amdgpu: Reject UVD message with invalid number of h265 refs - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional - drm/amdgpu: check ASPM on the dGPU host link - drm/amdgpu: validate GEM_CREATE domain combinations - drm/amdgpu: Reject UVD message with dimensions above 4096 - drm/amdgpu: Implement insert_end for VCE 3 - drm/amdgpu: Fix UVD min buffer sizes - drm/amdgpu: Fix UVD dpb min size calculation for H264 - drm/amdgpu: Fix UVD decode image min size calculation - drm/amdgpu: disallow multiple FENCE chunks in one submit - xfs: clear zapped attr fork state when bmap repair finds no attr fork - xfs: zero i_nlink before repair puts inode on unlinked list - xfs: only check mergeability of bnobt records - xfs: don't double-lock when deleting a self-referential directory - xfs: set the prev pointer when reinserting an inode on the unlinked list - xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers - xfs: nlink scrub must take IOLOCK before determining ILOCK state - xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev - xfs: fix ilock leak on error in xfs_dq_get_next_id - xfs: don't zap the attr fork on repair when there are queued pptr updates - xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair - xfs: fix allocated inodes that show up in the unlinked list - xfs: fix another iunlink infinite loop bug in online fsck - xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers - xfs: avoid UAF on sc->tempip in xrep_tempfile_create - xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN - xfs: don't swallow dquot recovery verification errors - xfs: check xfarray iteration errors when committing unlinked inode lists - xfs: check v5 superblock features early - ceph: Remove ceph_writepage() - ceph: Use a folio in ceph_page_mkwrite() - ceph: Convert ceph_find_incompatible() to take a folio - ceph: Convert writepage_nounlock() to write_folio_nounlock() - ceph: fix writeback_count leak in write_folio_nounlock() - ceph: avoid fs reclaim while using current->journal_info - ceph: fix hanging __ceph_get_caps() with stale mds_wanted - libceph: Amend checking to fix `make W=1` build breakage - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159) - mm/khugepaged: guard is_zero_pfn() calls with pte_present() - userfaultfd: prevent registration of special VMAs (CVE-2026-68166) - libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082) - net/sched: serialize qdisc_rtab_list against concurrent get/put (CVE-2026-68138) - super: remove pointless s_root checks - super: skip dying superblocks early - super: use a common iterator (Part 1) - super: use common iterator (Part 2) - fs/super: fix emergency thaw double-unlock of s_umount - super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132) - smb: move smb_version_values to common/smbglob.h - smb: move get_rfc1002_len() to common/smbglob.h - smb/server: rename include guard in smb_common.h - ksmbd: rename smb2_get_msg to smb_get_msg - smb/server: fix minimum SMB1 PDU size - smb/server: fix minimum SMB2 PDU size - ksmbd: validate minimum PDU size for transform requests (CVE-2026-68431) - eventpoll: pin files while checking reverse paths - tcp: Pass flags to __tcp_send_ack - tcp: fast path functions later - tcp: reorganize tcp_sock_write_txrx group for variables later - tcp: challenge ACK for non-exact RST in SYN-RECEIVED (CVE-2026-68118) - iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace - btrfs: add debug build only WARN - btrfs: add space_info argument to btrfs_chunk_alloc() - btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() - btrfs: zoned: fix missing chunk metadata reservation - [amd64] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (CVE-2026-74517) - [arm64] ASoC: tas2562: Validate values for volume writes - ata: libata-scsi: terminate deferred commands on time out - igc: remove napi_synchronize() in igc_down() - ksmbd: conn lock to serialize smb2 negotiate - ksmbd: reject repeated SMB2 NEGOTIATE requests (CVE-2026-74494) - net: pktgen: fix code style (WARNING: Block comments) - net: pktgen: fix proc entry use-after-free (CVE-2026-74479) - binfmt_misc: don't leak the user namespace when the mount fails (CVE-2026-74483) - fsnotify, lsm: Decouple fsnotify from lsm - fsnotify: opt-in for permission events at file open time - fs: don't block write during exec on pre-content watched files - binfmt_misc: restore write access when removing an entry (CVE-2026-74487) - vrf: Make pcpu_dstats update functions available to other modules. - vxlan: Handle stats using NETDEV_PCPU_STAT_DSTATS. - vxlan: use pskb_network_may_pull() for transmit path header pulls (CVE-2026-74474) - ice: fix VF interrupts cleanup - include/linux/fs.h: add inode_lock_killable() - smb: client: fix race with fallocate(2) and AIO+DIO - cifs: add fscache_resize_cookie() to cifs_setsize() - can: rcar_canfd: change the initializing flow for clocks and resets - drm/amd/pm: Use same metric table for APU - drm/amd/pm: Use macro to initialize metrics table - drm/amd/pm: fix torn gpu metrics reads - drm/amdgpu: remove unused function parameter - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini - drm/amd/pm: adjust the visibility of pp_table sysfs node - drm/amd/pm: fix pptable use-after-free (CVE-2026-74450) - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684) - drm/vmwgfx: take fman->lock around fence list mutation in fifo_down - ring-buffer: Simplify functions with __free(kfree) to free allocations - ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() (CVE-2026-74602) - mm/pagewalk: split walk_page_range_novma() into kernel/user parts - mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF (CVE-2026-74672) - mm/ptdump: always stabilise against page table freeing using init_mm (CVE-2026-74599) - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (CVE-2026-74607) - ring-buffer: Simplify ring_buffer_read_page() with guard() - ring-buffer: Make ring_buffer_{un}map() simpler with guard(mutex) - ring-buffer: Prevent resizing of persistent ring buffer - [amd64] x86/mce: Remove __mcheck_cpu_init_early() - [amd64] x86/mce: Set CR4.MCE last during init - [amd64] x86/mce: Set up the polling timer before CMCI discovery - [amd64] ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup - net/x25: fix use-after-free of the socket by its timers (CVE-2026-74628) - [arm64] tegra: Add EL2 virtual timer interrupt for Tegra194 - crypto: ccm - Set rfc4309 maxauthsize from child - netfilter: ipset: fix refcount race between list:set GC and swap - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path - netfilter: flowtable: publish GC-visible tuple last - netfilter: ipset: fix list type element drift bug - netfilter: ipset: let destroy callbacks adjust ext mem size - ipvlan: inherit needed_headroom and needed_tailroom from phy_dev - macvlan: inherit needed_headroom and needed_tailroom from lowerdev - veth: fix queue index used to wake the peer txq in veth_poll - tcp: fix icsk_ack.ato bitfield overflow - net: packet: fix wrong transport_header when sending VLAN-tagged frame - net/tls: Fail tls_sw_splice_read() after a failed async decrypt - af_packet: Don't send zero-byte data in tpacket_snd(). - net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain - net/sched: cls_u32: skip hash tables in u32_bind_class() - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG - net/sched: cls_bpf: reject dev-bound programs bound to a different device - drm/xe/oa: Fix sync entry leak on OA config emit failure - erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms - perf: Unify perf_event_free_task() / perf_event_exit_task_context() - perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637) - fs: unlock the superblock during iterate_supers_type - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone - net: harmonize tstats and dstats - ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS - ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() - ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601) - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r - net: ethernet: mtk_eth_soc: only use legacy mode on missing IRQ name - net: ethernet: mtk_eth_soc: improve support for named interrupts . [ Salvatore Bonaccorso ] * drivers/mmc/host: Enable MMC_ALCOR as module (Closes: #1142912) * drivers/misc/cardreader: Enable MISC_ALCOR_PCI as module (Closes: #1142912) linux-signed-amd64 (6.12.101+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.101-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.101 - [amd64] platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug - net: airoha: Move airoha_eth driver in a dedicated folder - net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() - bpf: Fix ld_{abs,ind} failure path analysis in subprogs (CVE-2026-53090) - netfilter: nft_counter: serialize reset with spinlock (CVE-2026-45897) - netfilter: nft_quota: use atomic64_xchg for reset - netfilter: nf_tables: revert commit_mutex usage in reset path (CVE-2026-45901) - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race - seqlock: Cure some more scoped_seqlock() optimization fails - seqlock: Allow KASAN to fail optimizing - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing - [amd64] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (CVE-2026-64561) - [amd64] KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN - [amd64] KVM: nVMX: Hide shadow VMCS right after VMCLEAR (CVE-2026-64562) - [amd64] KVM: x86/mmu: Fix use-after-free on vendor module reload - can: bcm: add locking when updating filter and timer values - can: bcm: fix CAN frame rx/tx statistics - can: bcm: extend bcm_tx_lock usage for data and timer updates - can: bcm: validate frame length in bcm_rx_setup() for RTR replies - can: bcm: add missing device refcount for CAN filter removal - can: bcm: fix stale rx/tx ops after device removal - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() - can: bcm: track a single source interface for ANYDEV timeout/throttle ops - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER - can: isotp: serialize TX state transitions under so->rx_lock - dmaengine: sh: rz-dmac: Move interrupt request after everything is set up - Revert "arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc" - [arm64,armhf] gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin - xprtrdma: Clear receive-side ownership pointers on release - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (CVE-2026-64565) - Input: ims-pcu - fix logic error in packet reset - [arm64] tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 - IB/mad: Drop unmatched RMPP responses before reassembly - mtd: mtdswap: remove debugfs stats file on teardown - mtd: nand: mtk-ecc: stop on ECC idle timeouts - btrfs: reject free space cache with more entries than pages - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() - RDMA/cma: Fix hardware address comparison length in netevent callback - RDMA/umem: Add pinned revocable dmabuf import interface - RDMA/irdma: Prevent rereg_mr for non-mem regions - RDMA/erdma: initialize ret for empty receive WR lists - [arm64] RDMA/hns: Fix potential integer overflow in mhop hem cleanup - RDMA/siw: publish QP after initialization - mtd: fix double free and WARN_ON in add_mtd_device() error paths - RDMA/irdma: Prevent overflows in memory contiguity checks - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert - wifi: cfg80211: cancel sched scan results work on unregister - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() - wifi: mac80211_hwsim: clamp virtio RX length before skb_put - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure - wifi: mac80211: fix fils_discovery double free on alloc failure - wifi: libertas: fix memory leak in helper_firmware_cb() - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() - wifi: cfg80211: pass net_device to .set_monitor_channel - wifi: cfg80211: define and use wiphy guard - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock - wifi: nl80211: free RNR data on MBSSID mismatch - wifi: cfg80211: derive S1G beacon TSF from S1G fields - wifi: nl80211: validate nested MBSSID IE blobs - wifi: cfg80211: validate PMSR measurement type data - wifi: cfg80211: validate PMSR FTM preamble range - wifi: cfg80211: reject unsupported PMSR FTM location requests - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock - wifi: brcmfmac: initialize SDIO data work before cleanup - wifi: cfg80211: bound element ID read when checking non-inheritance - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() - ASoC: cs42l43: Correct report for forced microphone jack - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup - [arm64] firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF - ipv4: fib: free fib_alias with kfree_rcu() on insert error path - net/iucv: take a reference on the socket found in afiucv_hs_rcv() - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() - scsi: core: wake eh reliably when using scsi_schedule_eh - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered - ata: sata_dwc_460ex: use platform_get_irq() - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning - [amd64] accel/ivpu: Fix wrong register read in LNL failure diagnostics - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC - Bluetooth: qca: fix NVM tag length underflow in TLV parser - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds - Bluetooth: hci_qca: Clear memdump state on invalid dump size - smb/client: handle overlapping allocated ranges in fallocate - [amd64] drm/i915/gt: use correct selftest config symbol - [powerpc*] 85xx: Add fsl,ifc to common device ids - [powerpc*] time: Prepare to stop elapsing in dynticks-idle - [powerpc*] vtime: Initialize starttime at boot for native accounting - bpf, sockmap: Reject unhashed UDP sockets on sockmap update - [s390x] checksum: Fix csum_partial() without vector facility - [riscv64] hwprobe: Avoid uninitialized read in hwprobe_get_cpus() - can: j1939: fix lockless local-destination check - drm/xe/wopcm: fix WOPCM size for LNL+ - smb: move some duplicate definitions to common/cifsglob.h - ksmbd: pin conn during async oplock break notification - ksmbd: validate compound request size before reading StructureSize2 - net/sched: act_tunnel_key: Defer dst_release to RCU callback - sctp: fix auth_hmacs array size in struct sctp_cookie - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n - usb: core: sysfs: add lock to bos_descriptors_read() - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() - usb: core: port: Deattach Type-C connector on component unbind - USB: storage: add NO_ATA_1X quirk for Longmai USB Key - usb: chipidea: fix usage_count leak when autosuspend_delay is negative - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback - usb: gadget: f_midi: cancel pending IN work before freeing the midi object - usb: gadget: printer: fix infinite loop in printer_read() - USB: gadget: snps-udc: fix device name leak on probe failure - USB: gadget: fsl-udc: fix device name leak on probe failure - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer - USB: serial: ftdi_sio: add support for E+H FXA291 - USB: serial: io_edgeport: cap received transmit credits - USB: serial: keyspan_pda: fix data loss on receive throttling - USB: serial: option: add TDTECH MT5710-CN - crypto: rsa-pkcs1pad: Don't WARN on an empty digest - Revert "drm/amd/display: Add missing kdoc for ALLM parameters" - [riscv64] KVM: Serialize virtual interrupt pending state updates - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - firewire: net: Fix fragmented datagram reassembly - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read - wifi: carl9170: fix OOB read from off-by-two in TX status handler - wifi: carl9170: fix buffer overflow in rx_stream failover path - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps - btrfs: free mapping node on duplicate reloc root insert - ASoC: tas2781: bound firmware description string parsing - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (CVE-2025-40098) - ALSA: hda: cs35l41: validate and free ACPI mute object - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI - ASoC: cs35l56: Don't use devres to unregister component - ASoC: cs35l56: Fix potential probe() deadlock - ASoC: cs35l56: Use complete_all() to signal init_completion - wifi: iwlwifi: mvm: validate SAR GEO response payload size - wifi: iwlwifi: mvm: fix read in wake packet notification handler - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC - hwmon: (asus-ec-sensors) fix EC read intervals - hwmon: (asus-ec-sensors) add missed handle for ENOMEM - smb: client: validate DFS referral PathConsumed - hwmon: occ: validate poll response sensor blocks - regulator: mt6358: use regmap helper to read fixed LDO calibration - Bluetooth: btusb: validate Realtek vendor event length - netlink: specs: rt-link: convert bridge port flag attributes to u8 - net/packet: avoid fanout hook re-registration after unregister - bonding: fix devconf_all NULL dereference when IPv6 is disabled - rds: drop incoming messages that cross network namespace boundaries - gtp: parse extension headers before reading inner protocol - [arm64] dpaa2-eth: put MAC endpoint device on disconnect - [amd64] iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() - wifi: mac80211: tear down new links on vif update error path - nfp: Check resource mutex allocation - wan: wanxl: Only reset hardware after BAR mapping - wifi: mwifiex: bound uAP association event IEs to the event buffer - [amd64] iommu/amd: Bound the early ACPI HID map - [amd64] iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() - wifi: mac80211: recalculate TIM when a station enters power save - pds_core: reject component parameter in legacy firmware update - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN - net: txgbe: fix FDIR filter leak on remove - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid - pds_core: fix deadlock between reset thread and remove - pds_core: fix use-after-free on workqueue during remove - pds_core: yield the CPU while waiting for the adminq to drain - pds_core: order completion reads after the ownership check - pds_core: fix auxiliary device add/del races - pds_core: check for workqueue allocation failure - sctp: validate stream count in sctp_process_strreset_inreq() - net: mctp i3c: clean up notifier and buses if driver register fails - tls: device: push pending open record on splice EOF - gtp: check skb_pull_data() return in gtp1u_send_echo_resp() - nexthop: initialize extack in nh_res_bucket_migrate() - tipc: fix infinite loop in __tipc_nl_compat_dumpit - wifi: mt76: mt7925: guard link STA in decap offload - wifi: mt76: mt7915: guard HE capability lookups - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() - wifi: mt76: mt7925: fix crash in reset link replay - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning - ovl: fix trusted xattr escape prefix matching - amt: re-read skb header pointers after every pull - amt: make the head writable before rewriting the L2 header - net: bridge: vlan: fix vlan range dumps starting with pvid - net: hsr: fix memory leak on slave unregistration by removing synced VLANs - net: dpaa: fix mode setting - sctp: auth: verify auth requirement when auth_chunk is NULL - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets - iomap: correct the range of a partial dirty clear - tipc: fix u16 MTU truncation in media and bearer MTU validation - net: stmmac: fix l3l4 filter rejecting unsupported offload requests - net: stmmac: reset residual action in L3L4 filters on delete - net: stmmac: enable the MAC on link up for all supported speeds - net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM - octeontx2-vf: set TC flower flag on MCAM entry allocation - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup - ppp: use IFF_NO_QUEUE in virtual interfaces - ppp: convert to percpu netstats - ppp: enable TX scatter-gather - ppp: annotate data races in ppp_generic - [amd64,arm64] hinic: remove unused ethtool RSS user configuration buffers - net: qrtr: restrict socket creation to the initial network namespace - dpll: add clock quality level attribute and op - net/mlx5: DPLL, Add clock quality level op implementation - net/mlx5: Remove newline at the end of a netlink error message - net/mlx5: Refactor EEPROM query error handling to return status separately - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule - net/mlx5e: Report zero bandwidth for non-ETS traffic classes - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation - octeontx2-pf: tc: fix egress ratelimiting - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV - ice: fix LAG recipe to profile association - rds: tcp: unregister sysctl before tearing down listen socket - net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() - [arm64] drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers - [arm64] drm/dp/mst: fix buffer overflows in sideband chunk accumulation - [arm64] drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 - drm/nouveau: fix reversed error cleanup order in ucopy functions - drm/displayid: fix Tiled Display Topology ID size - [amd64] drm/i915/gem: Add missing nospec on parallel submit slot - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() - drm/radeon: fix r100_copy_blit for large BOs - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds - drm/amdkfd: Use kvcalloc to allocate arrays - drm/amdkfd: Check bounds in allocate_event_notification_slot - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference - drm/virtio: bound EDID block reads to the response buffer - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() - [amd64] drm/i915: Return NULL on error in active_instance - [amd64] drm/i915/bios: range check LFP Data Block panel_type2 - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() - [amd64] drm/i915/gem: Do not leak siblings[] on proto context error - [amd64] drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU - drm/amd/pm: fix smu14 power limit range calculation - drm/gfx10: Program DB_RING_CONTROL - [arm64] drm/panthor: return error on truncated firmware - drm/amdgpu: Fix VFCT bus number matching with soft filter - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) - drm/amd/display: set new_stream to NULL after release - drm/amd/display: dce100: skip non-DP stream encoders for DP MST - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved - drm/vmwgfx: Validate vmw_surface_metadata::array_size - drm/vc4: Prevent shader BO mappings from becoming writable - media: airspy: Return queued buffers on start_streaming() failure - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure - media: cec: seco: unregister adapter on IR probe failure - media: cedrus: clean up media device on probe failure - media: cedrus: Fix missing cleanup in error path - media: cedrus: skip invalid H.264 reference list entries - media: chips-media: wave5: Move src_buf Removal to finish_encode - media: cx231xx: fix devres lifetime - media: cx23885: add ioremap return check and cleanup - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges - media: marvell-cam: fix missing pci_disable_device() on remove - media: meson: vdec: Fix memory leak in error path of vdec_open - media: msi2500: Return queued buffers on start_streaming() failure - media: nuvoton: npcm-video: fix error handling in npcm_video_init() - media: nuvoton: npcm-video: fix memory leaks in probe and remove - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path - media: nxp: imx8-isi: Fix potential out-of-bounds issues - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding - media: pci: dm1105: Free allocated workqueue - media: pwc: Drain fill_buf on start_streaming() failure - media: pwc: Return queued buffers on start_streaming() failure - media: qcom: camss: Fix RDI streaming for CSID GEN2 - media: radio-si476x: Unregister v4l2_device on probe failure - media: rtl2832: fix use-after-free in rtl2832_remove() - media: rtl2832_sdr: Return queued buffers on start_streaming() failure - media: saa7134: Fix a possible memory leak in saa7134_video_init1 - media: stm32: dcmi: unregister notifier on probe failure - media: sun4i-csi: Return queued buffers on start_streaming() failure - media: tegra-video: vi: fix invalid u32 return value in format lookup - media: ti: vpe: unwind v4l2 device registration on probe error - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() - media: v4l2-ctrls: validate HEVC active reference counts - media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely - media: vb2: use ssize_t for vb2_read/vb2_write - media: vidtv: fix reference leak on failed device registration - media: vimc: fix reference leak on failed device registration - media: vivid: add vivid_update_reduced_fps() - media: vivid: check for vb2_is_busy() when toggling caps - media: vivid: fix cleanup bugs in vivid_init() - media: vpif_capture: fix OF node reference imbalance - ALSA: seq: close a re-opened queue timer in the destructor - ALSA: timer: drain a slave's callback before its master detaches it - ALSA: timer: don't re-enter an instance callback that is still running - wifi: ath6kl: fix OOB access from firmware ADDBA window size - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper - wifi: wilc1000: validate assoc response length before subtracting header - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses - wifi: brcmfmac: make release_scratchbuffers idempotent - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() - staging: rtl8723bs: fix inverted HT40 secondary channel offset - Bluetooth: hci_sync: Protect UUID list traversal - Bluetooth: RFCOMM: Fix session UAF in set_termios - exec: fix unsigned loop counter wrap in transfer_args_to_stack() - binfmt_misc: set have_execfd only once the interpreter is opened - objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL - firmware: stratix10-svc: fix memory leaks and list corruption bugs - [amd64] x86/boot/compressed: Disable jump tables - [amd64] comedi: comedi_parport: deal with premature interrupt - uio_hv_generic: Bind to FCopy device by default - serial: sc16is7xx: implement gpio get_direction() callback - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Closes: #1143721) - mei: bus: access mei_device under device_lock on cleanup - [amd64] intel_th: fix MSC output device reference leak - misc: nsm: only unlock nsm_dev on post-lock error paths - misc: nsm: pin the module while the device is open - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev - tracing: Fix resource leak on mmiotrace trace_pipe close - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() - tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() - [arm64] syscall: Ensure saved x0 is kept in-sync with tracer updates - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" - mptcp: decrement subflows counter on failed passive join - mptcp: only set DATA_FIN when a mapping is present - sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564) - sctp: avoid auth_enable sysctl UAF during netns teardown - sctp: close UDP tunnel sockets during netns teardown - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() - ceph: fix refcount leak in ceph_readdir() - libceph: bound get_version reply decode to front len - libceph: Fix multiplication overflow in decode_new_up_state_weight() - libceph: guard missing CRUSH type name lookup - libceph: refresh auth->authorizer_buf{,_len} after authorizer update - libceph: Reject monmaps advertising zero monitors - libceph: reject zero bucket types in crush_decode - libceph: remove debugfs files before client teardown - amt: fix use-after-free in AMT delayed works - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP - binfmt_elf_fdpic: only honour the first PT_INTERP - fs: preserve ACL_DONT_CACHE state in forget_cached_acl() - fscrypt: Add missing superblock check in find_or_insert_direct_key() - ftrace: Add global mutex to serialize trace_parser access - iomap: fix out-of-bounds bitmap_set() with zero-length range - [amd64] iommu/vt-d: Disallow SVA if page walk is not coherent - phonet: pep: fix use-after-free in pep_get_sb() - vxlan: require CAP_NET_ADMIN in the device netns for changelink - net: slip: serialize receive against buffer reallocation - geneve: require CAP_NET_ADMIN in the device netns for changelink - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() - net/iucv: fix use-after-free of a severed iucv_path - net/mlx5e: Use sender devcom for MPV master-up - net/x25: fix use-after-free in x25_kill_by_neigh() - net: gro: fix double aggregation of flush-marked skbs - net: hip04: fix RX buffer leak on build_skb failure - proc: Fix broken error paths for namespace links - ice: fix PTP Call Trace during PTP release - rbd: Reset positive result codes to zero in object map update path - ksmbd: defer destroy_previous_session() until after NTLM authentication - ice: reject out-of-range ptype in ice_parser_profile_init - ice: use READ_ONCE() to access cached PHC time - ila: reload IPv6 header after pskb_may_pull in checksum adjust - mac802154: hold an interface reference across the scan worker - mac802154: llsec: reject frames shorter than the authentication tag - mctp: serial: handle zero-length frames to prevent rx buffer overflow - openvswitch: fix GSO userspace truncation underflow - pppoe: reload header pointer after dev_hard_header() - rtase: Workaround for TX hang caused by hardware packet parsing - tcp: initialize standalone TCP-AO response padding - tipc: clear sock->sk on the failed-insert path in tipc_sk_create() - vsock/virtio: collapse receive queue under memory pressure - vxlan: mdb: Fix source list corruption on a failed replace - drm/amd/pm: fix amdgpu_pm_info power display units - drm/amd/pm: make pp_features read-only when scpm is enabled - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx8: drop unecessary BUG_ON() - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/vce: fix integer overflow in image size - drm/amdgpu/vcn4: avoid rereading IB param length - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() - drm/amdgpu: fix division by zero with invalid uvd dimensions - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd - drm/amdgpu: fix aperture mapping leak - drm/amd/pm: fix smu13 power limit range calculation - bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (CVE-2026-53078) - net: qrtr: ns: Raise node count limit to 512 - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL - ksmbd: bound DACL dedup walk to copied ACEs - ksmbd: validate ACE size against SID sub-authorities - fscrypt: Avoid dynamic allocation in fscrypt_get_devices() - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources - io_uring/rw: fix missing ERESTARTSYS conversion in read paths - net: pcs: xpcs: fix SGMII state reading - gve: fix Rx queue stall on alloc failure - mm/damon/core: validate ranges in damon_set_regions() - mm/damon/core: disallow overlapping input ranges for damon_set_regions() - iommufd: Reject invalid read count in iommufd_fault_fops_read() - iommufd: Break the loop on failure in iommufd_fault_fops_read() (CVE-2026-64290) - iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (CVE-2026-64280) - i2c: davinci: Unregister cpufreq notifier on probe failure - VFS/audit: introduce kern_path_parent() for audit - audit: widen ino fields to u64 - audit: use 'unsigned int' instead of 'unsigned' - audit: fix recursive locking deadlock in audit_dupe_exe() - i2c: i801: fix hardware state machine corruption in error path (CVE-2026-64205) - ALSA: hda: conexant: Remove mic bias threshold override - ALSA: hda: Fix cached processing coefficient verbs - rxrpc: Pull out certain app callback funcs into an ops table - rxrpc: serialize kernel accept preallocation with socket teardown - xfs: factor out xfs_attr3_leaf_init - xfs: don't replace the wrong part of the cow fork - fbcon: Rename struct fbcon_ops to struct fbcon_par - fbcon: Use correct type for vc_resize() return value - rxrpc: Fix CPU time starvation in I/O thread - rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack - rxrpc: Use irq-disabling spinlocks between app and I/O thread - rxrpc: Fix notification vs call-release vs recvmsg - rxrpc: Fix socket notification race - tipc: restrict socket queue dumps in enqueue tracepoints - vduse: Use fixed 4KB bounce pages for non-4KB page size - vduse: remove unused vaddr parameter of vduse_domain_free_coherent - vduse: take out allocations from vduse_dev_alloc_coherent - VDUSE: avoid leaking information to userspace - octeontx2: Annotate mmio regions as __iomem - octeontx2-vf: clear stale mailbox IRQ state before request_irq() - octeontx2-pf: clear stale mailbox IRQ state before request_irq() - [arm64] dts: qcom: correct RBR opp entry - [arm64] dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable - ASoC: mediatek: mt8192: Check runtime resume during probe - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks - ASoC: mediatek: mt8183: Check runtime resume during probe - netfilter: nf_conntrack_sip: remove net variable shadowing - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it - netfilter: bitwise: rename some boolean operation functions - netfilter: nf_tables: Remove unused nft_reduce_is_readonly() - netfilter: nf_tables: remove register tracking infrastructure - netfilter: nft_fib: reject fib expression on the netdev egress hook - gpu: Move DRM buddy allocator one level up (part two) - gpu/buddy: bail out of try_harder when alignment cannot be honoured - NFSD: pass nfsd_file to nfsd_iter_read() - sunrpc: allocate a separate bvec array for socket sends - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow - remoteproc: xlnx: Check remote core state - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch - mm/sparse-vmemmap: fix vmemmap accounting underflow - landlock: Prepare to use credential instead of domain for fowner - landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages - mtd: maps: vmu-flash: fix fault in unaligned fixup - mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c - mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization - dma: dw-edma: Fix build warning in dw_edma_pcie_probe() - dmaengine: dw-edma: Fix confusing cleanup.h syntax - dmaengine: dw-edma-pcie: Reject devices without driver data - i2c: imx: separate atomic, dma and non-dma use case - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) - xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] - xfrm: nat_keepalive: avoid double free on send error - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect - tcp: Decrement tcp_md5_needed static branch - nvmet: Introduce nvmet_req_transfer_len() - nvmet-auth: reject short AUTH_RECEIVE buffers - ovl: use linked upper dentry in copy-up tmpfile - block: add helper add_disk_final() - block: remove redundant GD_NEED_PART_SCAN in add_disk_final() - dm-integrity: fix leaking uninitialized kernel memory - cleanup: add a scoped version of CLASS() - cleanup: fix scoped_class() - cred: add kernel_cred() helper - cred: add scoped_with_kernel_creds() - dm: avoid leaking the caller's thread keyring via the table device file - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() - net: mana: Validate the packet length reported by the NIC - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink - gve: fix header buffer corruption with header-split and HW-GRO - gpio: mt7621: avoid corruption of shared interrupt trigger state - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() - ipmi: fix refcount leak in i_ipmi_request() - net/mlx5: HWS, Rearrange to prevent forward declaration - net/mlx5: HWS, fix matcher leak on resize target setup failure - octeontx2-pf: fix SQB pointer leak on init failure - ata: libata-core: Reject an invalid concurrent positioning ranges count - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list - net: macb: drop in-flight Tx SKBs on close - net: ipa: fix SMEM state handle leaks in SMP2P init - Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections - Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately - afs: Improve server refcount/active count tracing - afs: Make afs_lookup_cell() take a trace note - afs: Drop the net parameter from afs_unuse_cell() - rxrpc: Allow the app to store private data on peer structs - afs: Use the per-peer app data provided by rxrpc - afs: Fix afs_server ref accounting - afs: Simplify cell record handling - afs: Fix dynamic lookup to fail on cell lookup failure - afs: Fix lack of locking around modifications of net->cells_dyn_ino - USB: gadget: Use str_enable_disable-like helpers - USB: gadget: fsl-udc: fix dev_printk() device - usb: musb: omap2430: clean up probe error handling - usb: musb: omap2430: Do not put borrowed of_node in probe - net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query - gpu: Fix uninitialized buddy for built-in drivers - rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link - rxrpc: Fix locking issues with the peer record hash - wifi: nl80211: fix nl80211_start_radar_detection return value - net: ethernet: Remove accidental duplication in Kconfig file - afs: Set vllist to NULL if addr parsing fails - dpll: fix clock quality level reporting - afs: Fix delayed allocation of a cell's anonymous key - afs: handle CB.InitCallBackState3 requests without a server record - Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK - Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() - afs: Fix uninit var in afs_alloc_anon_key() - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Add sparse annotation for RCU." (context changes) * rhashtable: clear stale iter->p on table restart (CVE-2026-64563) linux-signed-amd64 (6.12.100+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.100-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.97 - smb/server: do not require delete access for non-replacing links - [amd64] iommu/vt-d: Clear Present bit before tearing down context entry (CVE-2026-45944) - tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). - bpf: Support for hardening against JIT spraying (CVE-2026-64508) - [amd64] x86/bugs: Enable IBPB flush on BPF JIT allocation (CVE-2026-64507) - bpf: Restrict JIT predictor flush to cBPF - bpf: Skip redundant IBPB in pack allocator - bpf: Prefer packs that won't trigger an IBPB flush on allocation - bpf: Prefer dirty packs for eBPF allocations - sched/fair: Only update stats for allowed CPUs when looking for dst group - crypto: algif_skcipher - force synchronous processing - [arm64] KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287) - [arm64] KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (CVE-2026-64286) - iommu: Pass old domain to set_dev_pasid op - [amd64] iommu/vt-d: Cleanup intel_context_flush_present() - [amd64] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry - timekeeping: Register default clocksource before taking tk_core.lock - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534) - nvmet-tcp: Fix potential UAF when ddgst mismatch (CVE-2026-64535) - vsock/virtio: fix zerocopy completion for multi-skb sends (CVE-2026-53365) - vsock/virtio: bind uarg before filling zerocopy skb (CVE-2026-63970) - [armhf] crypto: sun4i-ss - Remove insecure and unused rng_alg - [amd64] iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 - [amd64] iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 - [amd64] x86/mm: Fix check/use ordering in switch_mm_irqs_off() - net: dropreason: Gather SOCKET_ drop reasons. - af_unix: Set drop reason in unix_release_sock(). - af_unix: Set drop reason in manage_oob(). - af_unix: Set drop reason in unix_stream_read_skb(). - af_unix/scm: fix whitespace errors - af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg(). - af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). - af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). - af_unix: Drop all SCM attributes for SOCKMAP. (CVE-2026-53005) - crypto: crypto4xx - Remove ahash-related code - crypto: crypto4xx - Remove insecure and unused rng_alg - crypto: hisi-trng - Remove crypto_rng interface - time/jiffies: Register jiffies clocksource before usage - time/jiffies: Change register_refined_jiffies() to void __init - media: uvcvideo: Use hw timestaming if the clock buffer is full - media: uvcvideo: Avoid partial metadata buffers - media: uvcvideo: Fix buffer sequence in frame gaps - media: uvcvideo: Fix dev_sof filtering in hw timestamp - media: uvcvideo: Do not add clock samples with small sof delta - media: uvcvideo: Relax the constrains for interpolating the hw clock - media: uvcvideo: Fix sequence number when no EOF - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties - dt-bindings: power: imx93: Add MIPI PHY power domain - serial: msm: Disable DMA for kernel console UART - serial: max310x: implement gpio_chip::get_direction() - serial: 8250_omap: clear rx_running on zero-length DMA completes - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) - afs: Fix netns teardown to cancel the preallocation charger - afs: fix NULL pointer dereference in afs_get_tree() - afs: Fix further netns teardown to cancel the preallocation charger - fbcon: fix NULL pointer dereference for a console without vc_data - clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() - drm/rockchip: Test for imported buffers with drm_gem_is_imported() - drm/tidss: Drop extra drm_mode_config_reset() call - drm/gpuvm: Do not prepare NULL objects - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() - drm/radeon: fix integer overflow in radeon_align_pitch() - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure - libbpf: Report error when a negative kprobe offset is specified - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro - Documentation: proc: fix section numbering in table of contents - [arm64] dts: rockchip: Fix gmac0 reset pin for NanoPi R5S - [arm64] dts: qcom: sc8180x: Fix phy simple_bus_reg warning - [arm64] dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning - wifi: cfg80211: fix grammar in MLO group key error message - [arm64] tegra: Fix Tegra234 MGBE PTP clock - dt-bindings: pinctrl: nvidia,tegra234: Add missing required block - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() - wifi: rtw89: Correct data type for scan index to avoid infinite loop - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer - kconfig: fix potential NULL pointer dereference in conf_askvalue - soc: xilinx: Shutdown and free rx mailbox channel - wifi: ath9k: fix OOB access from firmware tx status queue ID - [armhf] dts: am335x-sl50: Fix audio bitclock and frame master endpoint - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure - media: cedrus: Fix failure to clean up hardware on probe failure - media: v4l2-common: Add YUV24 format info - memory: tegra: Wire up system sleep PM ops - [amd64] crypto: qat - fix heartbeat error injection - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path - drm/gpuvm: take refcount on DRM device - [arm64] dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc - [arm64] dts: imx8x-colibri: Correct SODIMM PAD settings - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). - [amd64] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one - crypto: atmel-sha204a - fix blocking and non-blocking rng logic - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (CVE-2026-64544) - dlm: fix add msg handle in send_queue ordered - nilfs2: fix backing_dev_info reference leak - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite - [amd64] iommu/amd: Fix a stale comment about which legacy mode is user visible - [arm64] dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host - clk: scmi: Fix clock rate rounding - [arm64] dts: qcom: kodiak: Fix ICE reg size - [arm64] dts: qcom: sm8450: Fix ICE reg size - [arm64] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() - [arm64] drm/hisilicon/hibmc: use clock to look up the PLL value - evm: terminate and bound the evm_xattrs read buffer - thermal: hwmon: Fix critical temperature attribute removal - clk: scpi: Unregister child clock providers on remove - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() - crypto: ccp - Treat zero-length cert chain as query for blob lengths - spi: hisi-kunpeng: Use dev_err_probe() for host registration failure - net/sched: sch_htb: do not change sch->flags in htb_dump() - net/sched: sch_htb: annotate data-races (I) - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD - IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier - RDMA/hns: Fix arithmetic overflow in calc_hem_config() - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference - RDMA/srpt: fix integer overflow in immediate data length check - [arm64] RDMA/hns: Initialize seqfile before creating file - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() - media: atomisp: gc2235: fix UAF and memory leak - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() - firmware: arm_scmi: Read sensor config as 32-bit value - sysfs: clamp show() return value in sysfs_kf_read() - bitops: use common function parameter names - regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions - net/sched: sch_drr: annotate data-races around cl->deficit - media: rockchip: rga: fix too small buffer size - [arm64] firmware: arm_scmi: Fix OOB in scmi_power_name_get() - [arm64] dts: qcom: sc7180: Add power-domain and iface clk for ice node - [arm64] dts: qcom: kodiak: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8450: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8650: Add power-domain and iface clk for ice node - tracing: Bound synthetic-field strings with seq_buf - writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() - device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() - driver core: Use mod_delayed_work to prevent lost deferred probe work - Revert "treewide: Fix probing of devices in DT overlays" - cpufreq: Documentation: fix sampling_down_factor range - cpufreq: conservative: Simplify frequency limit handling - pwm: imx27: Fix variable truncation in .apply() - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed - bus: sunxi-rsb: Always check register address validity - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs - RDMA/rxe: Fix a use-after-free problem in rxe_mmap - IB/mlx4: Fix refcount leak in add_port() error path - [arm64] RDMA/hns: Fix warning in poll cq direct mode - [arm64] RDMA/hns: Fix log flood after cmd_mbox failure - RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup - PM: sleep: Use complete() in device_pm_sleep_init() - jiffies: Define secs_to_jiffies() - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() - driver core: Guard deferred probe timeout extension with delayed_work_pending() - mtd: spi-nor: Drop duplicate Kconfig dependency - ALSA: seq: midi: Serialize output teardown with event_input - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table - pinctrl: cs42l43: Fix polarity on debounce - nvmet-tcp: fix page fragment cache leak in error path - nvme-multipath: fix flex array size in struct nvme_ns_head - workqueue: drop spurious '*' from print_worker_info() fn declaration - ipv6: guard against possible NULL deref in __in6_dev_stats_get() - net/sched: cls_bpf: prevent unbounded recursion in offload rollback - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove - gpu: host1x: Allow entries in BO caches to be freed - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() - gpu: host1x: Fix iommu_map_sgtable() return value check - drm/tegra: Fix iommu_map_sgtable() return value check - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada - libbpf: Harden parse_vma_segs() path parsing - bpftool: Fix typo in struct_ops map FD generation for light skeleton - libbpf: Fix UAF in strset__add_str() - dax/kmem: account for partial discontiguous resource upon removal - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() - ocfs2: don't BUG_ON an invalid journal dinode - ocfs2: kill osb->system_file_mutex lock - crypto: hisilicon/qm - disable error report before flr - crypto: tegra - Fix dma_free_coherent size error - crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm - sched/deadline: Always stop dl-server before changing parameters - sched/deadline: Reject debugfs dl_server writes for offline CPUs - [arm64] drm/msm/dp: fix HPD state status bit shift value - [arm64] drm/msm/dp: Fix the ISR_* enum values - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info - RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe - RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path - media: qcom: venus: drop extra padding in NV12 raw size calculation - media: qcom: venus: relax encoder frame/blur dimension steps on v4 - media: qcom: venus: relax encoder frame/blur step size on v6 - amba: use generic driver_override infrastructure - cdx: use generic driver_override infrastructure - Drivers: hv: vmbus: use generic driver_override infrastructure - rpmsg: use generic driver_override infrastructure - md/raid10: reset read_slot when reusing r10bio for discard - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback - ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble - NFSD: Fix delegation reference leak in nfsd4_revoke_states - HID: wiimote: Fix table layout and whitespace errors - ata: libata: Fix ata_exec_internal() - nvdimm/btt: Handle preemption in BTT lane acquisition - scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" - scsi: pm8001: Fix error code in non_fatal_log_show() - scsi: ufs: Fix wrong value printed in unexpected UPIU response case - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs - mm/fake-numa: fix under-allocation detection in uniform split - ext2: fix ignored return value of generic_write_sync() - sched: restore timer_slack_ns when resetting RT policy on fork - driver core: Use system_percpu_wq instead of system_wq - tick/sched: Fix TOCTOU in nohz idle time fetch - configfs_lookup(): don't leave ->s_dentry dangling on failure - drm/amdgpu: set sub_block_index for mca ras sub-blocks - bpftool: Use libbpf error code for flow dissector query - vhost: fix vhost_get_avail_idx for a non empty ring - [amd64] perf/x86/amd/core: Always use the NMI latency mitigation - [amd64] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems - [amd64] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains - xfrm: fix NAT-related field inheritance in SA migration - drm/amdkfd: always resume_all after suspend_all - ocfs2: rebase copied fsdlm LVB pointers in locking_state - ocfs2: fix buffer head management in ocfs2_read_blocks() - ocfs2: reject FITRIM ranges shorter than a cluster - ocfs2/dlm: require a ref for locking_state debugfs open - ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures - netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - netfilter: synproxy: drop packets if timestamp adjustment fails - netfilter: synproxy: adjust duplicate timestamp options - netfilter: synproxy: fix unaligned memory access in timestamp adjustment - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock - netfilter: conntrack: revert ct extension genid infrastructure - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() - RDMA/irdma: Fix OOB read during CQ MR registration - RDMA/irdma: Initialize iwmr->access during MR registration - [arm64] dts: imx95: Correct PCIe outbound address space configuration - [arm64] dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well - RDMA/siw: Fix endpoint/socket association handling - bpf: Check tail zero of bpf_prog_info - bpf: Update transport_header when encapsulating UDP tunnel in lwt - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication - wifi: wcn36xx: fix OOB read from short trigger BA firmware response - ALSA: seq: Fix partial userptr event expansion - [riscv64] cpu_ops: Change return value type of cpu_is_stopped() to bool - [riscv64] stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe - ALSA: seq: Clear variable event pointer on read - ACPI: IPMI: Fix message kref handling on dead device - cpufreq: Documentation: fix conservative governor freq_step description - thermal: testing: reject missing command arguments - IB/mlx5: Don't take the rereg_mr fallback without a new translation - IB/mlx5: Properly support implicit ODP rereg_mr - spi: ep93xx: fix double-free of zeropage on DMA setup failure - [amd64] ASoC: amd: acp-sdw-sof: Bound DAI link iteration - firmware_loader: Fix recursive lock in device_cache_fw_images() - configfs: fix lockless traversals of ->s_children - watchdog: unregister PM notifier on watchdog unregister - scsi: target: Fix hexadecimal CHAP_I handling - scsi: target: Remove tcm_loop target reset handling - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() - hwspinlock: qcom: avoid uninitialized struct members - sched/fair: Fix cpu_util runnable_avg arithmetic - wifi: mt76: mt7925: clean up DMA on probe failure - wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links - wifi: mt76: mt7925: keep TX BA state in the primary WCID - wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX - wifi: mt76: fix argument to ieee80211_is_first_frag() - wifi: mt76: mt7915: fix potential tx_retries underflow - wifi: mt76: mt7921: fix potential tx_retries underflow - wifi: mt76: mt7925: fix potential tx_retries underflow - wifi: mt76: mt7996: fix potential tx_retries underflow - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() - fbdev: sm501fb: Fix buffer errors in OF binding code - hwmon: (it87) Clamp negative values to zero in set_fan() - btrfs: zoned: don't account data relocation space-info in statfs free space - btrfs: fix deadlock cloning inline extent when using flushoncommit - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified - NFSD: Handle layout stid in nfsd4_drop_revoked_stid() - spi: meson-spifc: fix runtime PM leak on remove - ASoC: codecs: aw88261: fix incorrect masks for boost regs - vduse: hold vduse_lock across IDR lookup in open path - vhost/vdpa: validate virtqueue index in mmap and fault paths - virtio_console: read size from config space during device init - vduse: Requeue failed read to send_list head - vhost/net: complete zerocopy ubufs only once - tools/virtio: check mmap return value in vringh_test - vdpa/octeon_ep: Fix PF->VF mailbox data address calculation - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails - bonding: 3ad: fix mux port state on oper down - ext4: fix kernel BUG in ext4_write_inline_data_end - ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT - of: cpu: add check in __of_find_n_match_cpu_property() - vfio/qat: fix f_pos race in qat_vf_resume_write() - bpf: Tighten cgroup storage cookie checks for prog arrays - ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() - [s390x] process: Fix kernel thread function pointer type - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (CVE-2026-64539) - Bluetooth: hci_core: Fix UAF in hci_unregister_dev() - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path - Bluetooth: hci: validate codec capability element length - Bluetooth: vhci: validate devcoredump state before side effects - fs: efs: remove unneeded debug prints - RDMA/mlx5: Remove DCT restrack tracking - RDMA/mlx5: Remove raw RSS QP restrack tracking - RDMA/mlx5: Fix undefined shift of user RQ WQE size - RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one - ASoC: codecs: hdac_hdmi: Validate written enum value - ASoC: fsl: fsl_audmix: Validate written enum values - ASoC: tegra: tegra210_ahub: Validate written enum value - net: dsa: qca8k: fix led devicename when using external mdio bus - net/sched: cls_flow: Dont expose folded kernel pointers - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). - bridge: cfm: reject invalid CCM interval at configuration time (CVE-2026-64537) - sctp: validate embedded address parameter length - net: pfcp: allocate per-cpu tstats for PFCP netdevs - net/sched: sch_hfsc: Don't make class passive twice - tipc: require net admin for TIPCv2 netlink mutators - tipc: prevent snt_unacked underflow on CONN_ACK - tipc: reject inverted service ranges from peer bindings - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index - crypto: cavium/cpt - fix DMA cleanup using wrong loop index - crypto: rng - Free default RNG on module exit - ALSA: seq: Fix kernel heap address leak in bounce_error_event() - spi: xilinx: use FIFO occupancy register to determine buffer size - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO - power: supply: core: fix supplied_from allocations - handshake: Require admin permission for DONE command - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net: mana: initialize gdma queue id to INVALID_QUEUE_ID - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check - net: ethernet: mtk_wed: fix loading WO firmware for MT7986 - bpf: Run generic devmap egress prog on private skb - net/mlx5: Check max_macs devlink param value against max capability - octeontx2-af: npc: Fix size of entry2cntr_map - net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() - net: wwan: t7xx: check skb_clone in control TX - dpll: add reference-sync netlink attribute - dpll: add reference sync get/set - dpll: Allow associating dpll pin with a firmware node - dpll: Add notifier chain for dpll events - dpll: Support dynamic pin index allocation - dpll: Enhance and consolidate reference counting logic - dpll: fix stale iteration in dpll_pin_on_pin_unregister() - dpll: send delete notification before unregister in on-pin rollback - dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() - dpll: guard sync-pair removal on full pin unregister - dpll: balance create/delete notifications in __dpll_pin_(un)register - landlock: Fix unmarked concurrent access to socket family - net: bcmgenet: Use weighted round-robin TX DMA arbitration - kcm: use WRITE_ONCE() when changing lower socket callbacks - netfilter: nf_conncount: callers must hold rcu read lock - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() - cifs: remove all cifs files before kill super - smb/client: always return a value for FS_IOC_GETFLAGS - bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket - udf: fix nls leak on udf_fill_super() failure - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check - [powerpc*] perf: fix preempt count underflow in fsl_emb_pmu_del - [powerpc*] powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down - [powerpc*] kexec: fix double get_cpu() imbalance in kexec_prepare_cpus - KEYS: Use acquire when reading state in keyring search - tipc: fix UAF in tipc_l2_send_msg() - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) - net: airoha: Introduce ndo_select_queue callback - net: airoha: Add sched ETS offload support - net: airoha: Fix always-true condition in PPE1 queue reservation loop - net: ethernet: oa_tc6: Remove FCS size in RX frame - ionic: Fix check in ionic_get_link_ext_stats - ksmbd: fix use-after-free in same_client_has_lease() - mfd: rsmu: Fix page register setup - mfd: cs42l43: Sanity check firmware size - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write - net/9p: fix race condition on rdma->state in trans_rdma.c - eventpoll: expand top-of-file overview / locking doc - eventpoll: rename attach_epitem() to ep_attach_file() - eventpoll: split ep_insert() into alloc + register stages - eventpoll: extract ep_deliver_event() from ep_send_events() - eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers - eventpoll: rename epi->next and txlist for clarity - eventpoll: Fix epoll_wait() report false negative - gpiolib: acpi: Only trigger ActiveBoth interrupts on boot - staging: nvec: fix use-after-free in nvec_rx_completed() - coresight: cti: Fix DT filter signals silently ignored - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore - PCI/ASPM: Don't reconfigure ASPM entering low-power state - PCI: Introduce named defines for PCI ROM - PCI: Check ROM header and data structure addr before accessing - [amd64] x86/platform/olpc: xo15: Drop wakeup source on driver removal - [amd64] platform/x86: xo15-ebook: Fix wakeup source and GPE handling - PCI: loongson: Do not ignore downstream devices on external bridges - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() - PCI: qcom: Set max OPP before DBI access during resume - phy: phy-can-transceiver: Check driver match and driver data against NULL - clk: at91: sam9x7: Fix gmac_gclk clock definition - coresight: Fix source not disabled on idr_alloc_u32 failure - mailbox: mtk-adsp: fix UAF during device teardown - staging: most: video: avoid double free on video register failure - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() - usb: host: max3421: Reject hub port requests for non-existent ports - char: tlclk: fix use-after-free in tlclk_cleanup() - PCI: qcom: Disable ASPM L0s for SA8775P - iio: light: si1133: reset counter to prevent race condition - iio: light: si1133: prevent race condition on timeout - iio: magnetometer: ak8975: fix potential kernel stack memory leak - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() - iio: tcs3472: power down chip on probe failure - clk: at91: keep securam node alive while mapping it - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter - fs/ntfs3: add bounds check to run_get_highest_vcn() - fs/ntfs3: fix mount failure on 64K page-size kernels - drm/amd/display: Add missing kdoc for ALLM parameters - [amd64] thunderbolt: debugfs: Fix margining error counter buffer leak - dmaengine: imx-sdma: Refine spba bus searching in probe - perf: Fix off-by-one stack buffer overflow in kallsyms__parse() - dmaengine: qcom: gpi: set DMA_PRIVATE capability - dmaengine: Fix possible use after free - dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor - clk: qcom: a53: Corrected frequency multiplier for 1152MHz - pNFS/filelayout: fix cheking if a layout is striped - xprtrdma: Avoid 250 ms delay on backlog wakeup - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot - xprtrdma: Post receive buffers after RPC completion - xprtrdma: Use sendctx DMA state for Send signaling - xprtrdma: Decouple req recycling from RPC completion - NFSv4/pnfs: defer return_range callbacks until after inode unlock - nfs: keep PG_UPTODATE clear after read errors in page groups - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write - nfs: use nfsi->rwsem to protect traversal of the file lock list - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro - PCI: meson: Propagate devm_add_action_or_reset() failure - PCI: meson: Add missing remove callback - fs/ntfs3: resize log->one_page_buf when adopting on-disk page size - PCI: rcar-host: Remove unused LIST_HEAD(res) - xprtrdma: Fix ep kref imbalance on ADDR_CHANGE - xprtrdma: Initialize re_id before removal registration - xprtrdma: Check frwr_wp_create() during connect - xprtrdma: Document and assert reply-handler invariants - xprtrdma: Resize reply buffers before reposting receives - xprtrdma: Fix bcall rep leak and unbounded peek - xprtrdma: Sanitize the reply credit grant after parsing - xprtrdma: Repost Receive buffers for malformed replies - xprtrdma: Return sendctx slot after Send preparation failure - tools lib api: Fix missing null termination in filename__read_int/ull() - tools lib api: Fix filename__write_int() writing uninitialized stack data - tools lib api: Fix mount_overload() snprintf truncation and toupper range - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() - PCI: mediatek: Use actual physical address instead of virt_to_phys() - Revert "PCI/MSI: Unmap MSI-X region on error" - security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() - apparmor: check label build before no_new_privs test - apparmor: aa_label_alloc use aa_label_free on alloc failure - apparmor: fix rawdata_f_data implicit flex array - apparmor: grab ns lock and refresh when looking up changehat child profiles - apparmor: fix potential UAF in aa_replace_profiles - apparmor: remove or add symlinks to rawdata according to export_binary - apparmor: aa_getprocattr free procattr leak on format failure - apparmor: put secmark label after secid lookup - workqueue: Add new WQ_PERCPU flag - i3c: master: add WQ_PERCPU to alloc_workqueue users - i3c: master: Make hot-join workqueue freezable to block hot-join during suspend - i3c: master: Prevent reuse of dynamic address on device add failure - apparmor: fix label can not be immediately before a declaration - gpio: mlxbf3: fail probe if gpiochip registration fails - [amd64] drm/i915: clear CRTC color blob pointers after dropping refs - spi: dw: fix wrong BAUDR setting after resume - xfrm: Fix xfrm state cache insertion race - xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] - xfrm: validate selector family and prefixlen during match - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm - drm/amdgpu: initialize irq.lock spinlock earlier - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown - net: psample: fix info leak in PSAMPLE_ATTR_DATA (CVE-2026-64553) - sctp: hold socket lock when dumping endpoints in sctp_diag - PCI: iproc: Restore .map_irq() for the platform bus driver - spi: rpc-if: Use correct device for hardware reinitialization on resume - virtio-net: fix len check in receive_big() (CVE-2026-64552) - dpaa2-switch: fix VLAN upper check not rejecting bridge join - devlink: Fix parent ref leak in devl_rate_node_create() - flow_dissector: check device type before reading ETH_ADDRS - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints - [arm64] hw_breakpoint: reject unaligned watchpoints that would truncate BAS - thermal: intel: Fix dangling resources on thermal_throttle_online() failure - ACPI: resource: Amend kernel-doc style - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() - ieee802154: fix kernel-infoleak in dgram_recvmsg() - mac802154: Prevent overwrite return code in mac802154_perform_association() - md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry - netfilter: ipset: Fix data race between add and dump in all hash types - netfilter: ipset: annotate "pos" for concurrent readers/writers - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() - netfilter: ipset: make sure gc is properly stopped - netfilter: nf_reject: skip iphdr options when looking for icmp header - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() - irqchip/crossbar: Fix parent domain resource leak - net: marvell: prestera: initialize err in prestera_port_sfp_bind - tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (CVE-2026-64543) - net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths - octeontx2-af: mcs: Fix unsupported secy stats read - octeontx2-pf: Clear stats of all resources when freeing resources - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown - net/sched: act_ct: fix nf_connlabels leak on two error paths - ipv6: ndisc: fix NULL deref in accept_untracked_na() (CVE-2026-64542) - dpaa2-switch: do not accept VLAN uppers while bridged - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 - bpf: Fix stack slot index in nospec checks - bpftool: Fix vmlinux BTF leak in cgroup commands - bpf: zero-initialize the fib lookup flow struct - bpf: Fix effective prog array index with BPF_F_PREORDER - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() - drm/edid: fix OOB read in drm_parse_tiled_block() (CVE-2026-64546) - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 - ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() - ice: fix AQ error code comparison in ice_set_pauseparam() - ice: call netif_keep_dst() once when entering switchdev mode - ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info - ice: dpll: fix memory leak in ice_dpll_init_info error paths - i40e: Fix i40e_debug() to use struct i40e_hw argument - rtc: msc313: fix NULL deref in shared IRQ handler at probe - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (CVE-2026-64538) - net: bnxt: use ethtool string helpers - eth: bnxt: gather and report HW-GRO stats - eth: bnxt: rename ring_err_stats -> ring_drv_stats - eth: bnxt: improve the timing of stats - ipv4: fib: Don't ignore error route in local/main tables. - md/raid5: use stripe state snapshot in break_stripe_batch_list() - md/raid5: avoid R5_Overlap races while breaking stripe batches - bpf: Disable xfrm_decode_session hook attachment - netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Closes: #1130336) - netfilter: nft_synproxy: stop bypassing the priv->info snapshot - netfilter: nft_compat: ebtables emulation must reject non-bridge targets - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure - NTB: epf: Make db_valid_mask cover only real doorbell bits - NTB: epf: Report 0-based doorbell vector via ntb_db_event() - NTB: epf: Fix doorbell bitmask and IRQ vector handling - net, bpf: check master for NULL in xdp_master_redirect() (CVE-2026-64545) - net: dsa: sja1105: round up PTP perout pin duration - veth: fix NAPI leak in XDP enable error path - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) - ipv6: fix error handling in disable_ipv6 sysctl - ipv6: fix error handling in ignore_routes_with_linkdown sysctl - ipv6: fix error handling in forwarding sysctl - ipv6: fix error handling in disable_policy sysctl - rtnetlink: Add per-netns RTNL. - rtnetlink: Add assertion helpers for per-netns RTNL. - rtnetlink: Define rtnl_net_trylock(). - ipv6: Add __in6_dev_get_rtnl_net(). - ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL. - ipv6: fix missing notification for ignore_routes_with_linkdown - thermal: testing: zone: Flush work items during cleanup - ACPI: processor_idle: Mark LPI enter functions as __cpuidle - smb/client: preserve errors from smb2_set_sparse() - rtc: ds1307: Fix off-by-one issue with wday for rx8130 - rtc: cmos: unregister HPET IRQ handler on probe failure - net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() - octeontx2-af: Validate NIX maximum LFs correctly - net: mvneta: re-enable percpu interrupt on resume - net: sungem: fix probe error cleanup - net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count - udp_tunnel: remove rtnl_lock dependency - net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync - dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback - [arm64] net: hisilicon: hns3: use ethtool string helpers - [arm64] net: hns3: use string choices helper - [arm64] net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: clear hns alarm: comparison of integer expressions of different signedness - [arm64] net: hns3: unify copper port ksettings configuration path - [arm64] net: hns3: refactor MAC autoneg and speed configuration - [arm64] net: hns3: fix permanent link down deadlock after reset - [arm64] net: hns3: differentiate autoneg default values between copper and fiber - tracing: probes: fix typo in a log message - spi: sh-msiof: abort transfers when reset times out - gpio: mvebu: fail probe if gpiochip registration fails - gpio: htc-egpio: use managed gpiochip registration - seg6: validate SRH length before reading fixed fields - qede: fix out-of-bounds check for cqe->len_list[] - net: enetc: check the number of BDs needed for xdp_frame - sctp: fix SCTP_RESET_STREAMS stream list length limit - MIPS: DEC: Ensure RTC platform device deregistration upon failure - ASoC: codecs: lpass-va-macro: add SM6115 compatible - ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 - hwmon: adm1275: Prevent reading uninitialized stack - hwmon: (pmbus) Fix passing events to regulator core - hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (CVE-2026-64540) - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy - net: gianfar: dispose irq mappings on probe failure and device removal - net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF - bridge: stp: Fix a potential use-after-free when deleting a bridge - [arm64] drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() - [arm64] drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() - [arm64] drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced - [arm64] drm/panthor: Interrupt group start/resumption if group_bind_locked() fails - tracing/events: Fix to check the simple_tsk_fn creation - tracing: eprobe: read the complete FILTER_PTR_STRING pointer - irqchip/gic-v3-its: Fix OF node reference leak - irqchip/ts4800: Fix missing chained handler cleanup on remove - virtio_net: disable cb when NAPI is busy-polled - cxgb4: Fix decode strings dump for T6 adapters - net/sched: act_bpf: use rcu_dereference_bh() to read the filter - ksmbd: reject undersized DACLs before parsing ACEs - ksmbd: fix use-after-free of fp->owner.name in durable handle owner check - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe - pinctrl: meson: restore non-sleeping GPIO access - net/sched: hhf: clear heavy-hitter state on reset - fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid - afs: Fix error code in afs_extract_vl_addrs() - afs: Fix double netfs initialisation in afs_root_iget() - afs: use kvfree() to free memory allocated by kvcalloc() - afs: Remove erroneous seq |= 1 in volume lookup loop - afs: Make /afs/. as well as /afs/ mountpoints - afs: Add rootcell checks - afs: Make /afs/@cell and /afs/.@cell symlinks - afs: Fix afs_atcell_get_link() to handle RCU pathwalk - afs: Remove the "autocell" mount option - afs: Change dynroot to create contents on demand - afs: Fix misplaced inc of net->cells_outstanding - afs: Fix callback service message parsers to pass through -EAGAIN - afs: Fix missing NULL pointer check in afs_break_some_callbacks() - afs: Fix vllist leak - afs: Fix the volume AFS_VOLUME_RM_TREE is set on - afs: Fix unchecked-length string display in debug statement - minix: avoid overflow in bitmap block count calculation - ovl: fix comment about locking order - netfs: Fix writeback error handling - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() - drm/xe/hw_engine: Fix double-free of managed BO in error path - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays - netfs: Drop the error arg from netfs_read_subreq_terminated() - cifs: Fix missing credit release on failure in cifs_issue_read() - ata: sata_gemini: unwind clocks on IDE pinctrl errors - ata: libata-scsi: limit simulated SCSI command copy to response length - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() - HID: core: Fix OOB read in hid_get_report for numbered reports - [arm64] mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() - HID: bpf: Fix hid_bpf_get_data() range check - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (CVE-2026-64547) - gue: validate REMCSUM private option length - netfilter: xt_u32: reject invalid shift counts - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop - netfilter: xt_connmark: reject invalid shift parameters - net/mlx5: LAG, MPESW, Fix missing complete() on devcom error - net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation - net/mlx5e: Fix HV VHCA stats agent registration race - net: microchip: vcap: fix races on the shared Super VCAP block - qede: fix off-by-one in BD ring consumption on build_skb failure - net: qualcomm: rmnet: validate MAP frame length before ingress parsing (CVE-2026-64550) - net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket - amt: fix size calculation in amt_get_size() - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control - Bluetooth: MGMT: Fix adv monitor add failure cleanup - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (CVE-2026-64549) - ring-buffer: Fix event length with forced 8-byte alignment - net/tls: Consume empty data records in tls_sw_read_sock() - net: usb: lan78xx: move functions to avoid forward definitions - net: usb: lan78xx: disable VLAN filter in promiscuous mode - [arm64] drm/v3d: Reject invalid indirect BO handle in indirect CSD setup - net/sched: cake: reject overhead values that underflow length - octeontx2-pf: check DMAC extraction support before filtering - [amd64] perf/x86/amd/core: Avoid enabling BRS from the SVM reload path - gpio: mvebu: free generic chips on unbind - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() - ipv6: mcast: Replace locking comments with lockdep annotations. - ipv6: mcast: Fix potential UAF in MLD delayed work - netfilter: nft_lookup: fix catchall element handling with inverted lookups - ipvs: pass parsed transport offset to state handlers - ipvs: use parsed transport offset in TCP state lookup - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors - ipvs: ensure inner headers in ICMP errors are in headroom - [s390x] zcrypt: Remove the empty file - cifs: validate DFS referral string offsets - SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED - SUNRPC: pin upper rpc_clnt across the TLS connect_worker - dm era: fix NULL pointer dereference in metadata_open() - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK - net/mlx5: Fix L3 tunnel entropy refcount leak - octeontx2-af: fix VF bringup affecting PF promiscuous state - drm/xe: remove duplicate include - smb: client: fix overflow in passthrough ioctl bounds check - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get - ASoC: SOF: topology: validate vendor array size before parsing - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() - net: atm: reject out-of-range traffic classes in QoS validation - net: ife: require ETH_HLEN to be pullable in ife_decode() - [arm64] fpsimd: Fix type mismatch in sve_{save,load}_state() - [arm64] dts: qcom: sdm630: describe adsp_mem region properly - [arm64] dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc - [arm64] dts: imx8ulp-evk: Correct Type-C int GPIO flags - [s390x] KVM: s390: pci: Fix GISC refcount leak on AIF enable failure - [arm64] KVM: arm64: vgic: Check the interrupt is still ours before migrating it - [s390x] KVM: s390: pci: Fix handling of AIF enable without AISB - [amd64] KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs - [amd64] KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs - [arm64] KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 - [arm64] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (CVE-2026-64555) - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() - fbdev: sm712: Fix operator precedence in big_swap macro - fbdev: efifb: fix memory leak in efifb_probe() - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() - fbdev: i740fb: fix potential memory leak in i740fb_probe() - fbdev: s3fb: fix potential memory leak in s3_pci_probe() - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() - fbdev: vesafb: fix memory leak in vesafb_probe() - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control - ASoC: mediatek: mt8192: Release reserved memory on cleanup - ASoC: mediatek: mt8183: Release reserved memory on cleanup - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read - netfilter: nfnl_cthelper: apply per-class values when updating policies - netfilter: xt_cluster: reject template conntracks in hash match - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst - netfilter: nft_set_pipapo: don't leak bad clone into future transaction - netfilter: nf_nat_sip: reload possible stale data pointer - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag - netfilter: nf_conncount: fix zone comparison in tuple dedup - netfilter: ecache: fix inverted time_after() check - netfilter: xt_nat: reject unsupported target families - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (CVE-2026-64554) - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy - soc: fsl: qe: panic on ioremap() failure in qe_reset() - selinux: check connect-related permissions on TCP Fast Open - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() - selinux: fix incorrect execmem checks on overlayfs - leds: uleds: Fix potential buffer overread - mfd: sm501: Fix reference leak on failed device registration - [amd64] tools/power/x86/intel-speed-select: Harden daemon pidfile open - [amd64] x86/boot: Validate console=uart8250 baud rate to fix early boot hang - [amd64] x86/boot: Reject too long acpi_rsdp= values - [amd64] perf/x86/amd/lbr: Fix kernel address leakage - cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() - [s390x] perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() - batman-adv: gw: acquire ethernet header only after skb realloc - batman-adv: access unicast_ttvn skb->data only after skb realloc - batman-adv: dat: acquire ARP hw source only after skb realloc - batman-adv: bla: reacquire gw address after skb realloc - batman-adv: dat: ensure accessible eth_hdr proto field - batman-adv: dat: fix tie-break for candidate selection - batman-adv: tt: avoid request storms during pending request - batman-adv: fix VLAN priority offset - batman-adv: frag: free unfragmentable packet - batman-adv: frag: fix primary_if leak on failed linearization - batman-adv: mcast: avoid OOB read of num_dests header - batman-adv: tt: prevent TVLV OOB check overflow - cifs: invalidate cfid on unlink/rename/rmdir - mfd: tps6586x: Fix OF node refcount - HID: playstation: validate num_touch_reports in DualShock 4 reports - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready - Bluetooth: SCO: hold sk properly in sco_conn_ready - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() - nvdimm/btt: Free arenas on btt_init() error paths - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback - sunrpc: wait for in-flight TLS handshake callback when cancel loses race - lockd: Plug nlm_file leak when nlm_do_fopen() fails - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing - remoteproc: qcom: Fix leak when custom dump_segments addition fails - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak - mm/memory_hotplug: fix incorrect altmap passing in error path - mm/damon/core: make charge_addr_from aware of end-address exclusivity - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length - fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off - fs/ntfs3: validate lcns_follow in log_replay conversion (CVE-2026-64533) - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow - fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (CVE-2026-64532) - ntfs3: cap RESTART_TABLE free-chain walker at rt->used - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head - ntfs3: validate split-point offset in indx_insert_into_buffer - ntfs3: fix out-of-bounds read in decompress_lznt - power: supply: charger-manager: fix refcount leak in is_full_charged() - [riscv64] cacheinfo: Fix node reference leak in populate_cache_leaves - mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() - mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error - fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() - fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() - proc: only bump parent nlink when registering directories - mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE - kcov: use WRITE_ONCE() for selftest mode stores - mtd: slram: remove failed entries from the device list - 9p: skip nlink update in cacheless mode to fix WARN_ON - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() - scsi: sas: Skip opt_sectors when DMA reports no real optimization hint - ocfs2: use kzalloc for quota recovery bitmap allocation - mtd: rawnand: pl353: fix probe resource allocation - net/9p: fix infinite loop in p9_client_rpc on fatal signal - mtd: rawnand: fix condition in 'nand_select_target()' - ocfs2: avoid moving extents to occupied clusters - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits - ocfs2: add journal NULL check in ocfs2_checkpoint_inode() - ocfs2: reject dinodes with non-canonical i_mode type - ocfs2: reject dinodes whose i_rdev disagrees with the file type - ocfs2: reject non-inline dinodes with i_size and zero i_clusters - fpga: dfl: add bounds check in dfh_get_param_size() - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path - net: thunderbolt: Fix frags[] overflow by bounding frame_count - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() - [s390x] pkey: Check length in PKEY_VERIFYPROTK ioctl - [s390x] pkey: Check length in pkey_pckmo handler implementation - mtd: spi-nor: swp: Improve locking user experience - mtd: spi-nor: spansion: use die erase for multi-die devices only - mtd: rawnand: Pause continuous reads at block boundaries - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization - taskstats: retain dead thread stats in TGID queries - irqchip/crossbar: Use correct index in crossbar_domain_free() - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() - tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt - dmaengine: tegra: Fix burst size calculation - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK - [amd64] platform/x86: dell-laptop: fix missing cleanups in init error path - [amd64] platform/x86/amd/pmc: Check for intermediate wakeup in function - [amd64] platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops - [amd64] platform/x86/amd/pmc: Add delay_suspend module parameter - [amd64] platform/x86/amd/pmc: Don't log during intermediate wakeups - pkey: Move keytype check from pkey api to handler - smb: client: use kvzalloc() for megabyte buffer in simple fallocate - ksmbd: fix integer overflow in set_file_allocation_info() - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig - hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig - i2c: mediatek: fix WRRD for SoCs without auto_restart option - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() - ice: fix ice_init_link() error return preventing probe - xen/gntdev: fix error handling in ioctl - xfrm: use compat translator only for u64 alignment mismatch - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink - tpm: fix event_size output in tpm1_binary_bios_measurements_show - tpm: Make the TPM character devices non-seekable - time: Fix off-by-one in compat settimeofday() usec validation - spi: uniphier: Fix completion initialization order before devm_request_irq() - sctp: validate STALE_COOKIE cause length before reading staleness (CVE-2026-64551) - NFS: Charge unstable writes by request size, not folio size - nvmet-rdma: handle inline data with a nonzero offset - netdev-genl: report NAPI thread PID in the caller's pid namespace - can: esd_usb: kill anchored URBs before freeing netdevs - can: isotp: use unconditional synchronize_rcu() in isotp_release() - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure - can: bcm: add missing rcu list annotations and operations - bpf,fork: wipe ->bpf_storage before bailouts that access it - bpf: Add missing access_ok call to copy_user_syms - block: fix race in blk_time_get_ns() returning 0 - net: sparx5: unregister blocking notifier on init failure - dm thin metadata: fix superblock refcount leak on snapshot shadow failure - dm thin metadata: fix metadata snapshot consistency on commit failure - dm era: fix out-of-bounds memory access for non-zero start sector - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard - dm-ioctl: fix a possible overflow in list_version_get_info - dm-log: fix a bitset_size overflow on 32bit machines - dm-stats: fix dm_jiffies_to_msec64 - dm-stats: fix merge accounting - dm_early_create: fix freeing used table on dm_resume failure - dm-integrity: fix a bug if the bio is out of limits - dm-integrity: don't increment hash_offset twice - dm-verity: avoid double increment of &use_bh_wq_enabled - dm-verity: fix a possible NULL pointer dereference - dm-verity: increase sprintf buffer size - dm-verity: make error counter atomic - [amd64] accel/ivpu: Reject firmware log with size smaller than header - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() - scsi: sg: Report request-table problems when any status is set - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path - scsi: xen: scsiback: Free unsubmitted command instead of double-putting it - scsi: target: Bound PR-OUT TransportID parsing to the received buffer - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() - scsi: elx: efct: Fix I/O leak on unsupported additional CDB - Input: ims-pcu - fix use-after-free and double-free in disconnect - Input: ims-pcu - only expose sysfs attributes on control interface - Input: ims-pcu - release data interface on disconnect - Input: ims-pcu - validate control endpoint type - Input: ims-pcu - add response length checks - Input: ims-pcu - fix DMA mapping violation in line setup - Input: ims-pcu - fix firmware leak in async update - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing - Input: ims-pcu - fix race condition in reset_device sysfs callback - Input: ims-pcu - fix type confusion in CDC union descriptor parsing - net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete - tracing/user_events: Fix use-after-free in user_event_mm_dup() - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() - cpu: hotplug: Preserve per instance callback errors - cpu: hotplug: Bound hotplug states sysfs output - gpio: tegra: do not call pinctrl for GPIO direction - gpio-f7188x: Add support for NCT6126D version B - gpios: palmas: add .get_direction() op - net: sit: require CAP_NET_ADMIN in the device netns for changelink - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure - net: ixp4xx_hss: fix duplicate HDLC netdev allocation - net/sched: act_ct: preserve tc_skb_cb across defragmentation - net: ena: clean up XDP TX queues when regular TX setup fails - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ipip: require CAP_NET_ADMIN in the device netns for changelink - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink - octeontx2-af: Free BPID bitmap on setup failure - ieee802154: admin-gate legacy LLSEC dump operations - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation - ieee802154: ca8210: fix cas_ctl leak on spi_async failure - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit - [amd64] platform/x86/amd/pmc: Avoid logging "(null)" for DMI values - net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants - [s390x] Revert support for DCACHE_WORD_ACCESS (CVE-2026-64369) - batman-adv: retrieve ethhdr after potential skb realloc on RX - batman-adv: ensure minimal ethernet header on TX - batman-adv: clean untagged VLAN on netdev registration failure - espintcp: use sk_msg_free_partial to fix partial send - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() - rtc: mpfs: fix counter upload completion condition - hwmon: (w83627hf) remove VID sysfs files on error and remove - hwmon: (w83793) remove vrm sysfs file on probe failure - net: liquidio: fix BAR resource leak on PF number failure - hwmon: (occ) unregister sysfs devices outside occ lock - fsl/fman: Free init resources on KeyGen failure in fman_init() - net: lan743x: Initialize eth_syslock spinlock before use - net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked - net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked - fhandle: reject detached mounts in capable_wrt_mount() - hwmon: (max1619) add missing 'select REGMAP' to Kconfig - tracing/probes: Fix double addition of offset for @+FOFFSET - orangefs: keep the readdir entry size 64-bit in fill_from_part() - ata: pata_pxa: Fix DMA channel leak on probe error - net: wwan: iosm: bound device offsets in the MUX downlink decoder - hwmon: (asus_atk0110) Check package count before accessing element - [riscv64] probes: save original sp in rethook trampoline - mm/compaction: handle free_pages_prepare() properly in compaction_free() - irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure - [s390x] monwriter: Reject buffer reuse with different data length - mac802154: remove interfaces with RCU list deletion - llc: fix SAP refcount leak in llc_ui_autobind() - ipvs: use parsed transport offset in SCTP state lookup - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new - macsec: don't read an unset MAC header in macsec_encrypt() - [arm64] smp: Fix hot-unplug tearing by forcing unregistration - ata: libata-core: Skip HPA resize for locked drives - drbd: reject data replies with an out-of-range payload size - [riscv64] Prevent NULL pointer dereference in machine_kexec_prepare() - tracing/osnoise: Call synchronize_rcu() when unregistering - [s390x] mm: Fix type mismatch in get_align_mask(). - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed - pmdomain: imx: Fix i.MX8MP power notifier - pmdomain: imx: Fix i.MX8MP VC8000E power up sequence - [powerpc*] pseries: fix memory leak on krealloc failure in papr_init - wifi: rt2x00: avoid full teardown before work setup in probe - wifi: mwifiex: fix roaming to different channel in host_mlme mode - wifi: mac80211: fix memory leak in ieee80211_register_hw() - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets - net: openvswitch: reject oversized nested action attrs (CVE-2026-64531) - Bluetooth: btrtl: validate firmware patch bounds - llc: fix SAP refcount leak when creating incoming sockets - macsec: fix promiscuity refcount leak in macsec_dev_open() - memstick: ms_block: reject a card that reports too many blocks - ipvs: fix more places with wrong ipv6 transport offsets - ipvs: reload ip header after head reallocation - reset: sunxi: fix memory region leak on ioremap failure - [powerpc*] spufs: fix out-of-bounds access in spufs_mem_mmap_access() - wifi: mac80211: free ack status frame on TX header build failure - wifi: mwifiex: fix permanently busy scans after multiple roam iterations - mtd: onenand: samsung: report DMA completion timeouts - mtd: mchp23k256: use SPI match data for chip caps - mmc: vub300: defer reset until cmd_mutex is unlocked - mtd: rawnand: fsl_ifc: return errors for failed page reads - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout - mmc: block: fix RPMB device unregister ordering - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method - ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup - ACPI: driver: Check ACPI_COMPANION() against NULL during probe - ACPI: bus: Introduce devm_acpi_install_notify_handler() - ACPI: NFIT: core: Use devm_acpi_install_notify_handler() - ACPI: NFIT: core: Fix possible deadlock and missing notifications - iio: hid-sensor-rotation: Fix stale or zero output when reading raw values - iio: adc: ad7380: select REGMAP - iio: pressure: Remove redundant pm_runtime_mark_last_busy() calls - iio: pressure: mpl115: fix runtime PM leak on read error (CVE-2026-64493) - ALSA: aoa: check snd_ctl_new1() return value - ALSA: hda/cs35l41: Fix firmware load work teardown (CVE-2026-64481) - ALSA: scarlett2: Allow selecting config_set by firmware version - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 - vfio/mlx5: Fix racy bitfields and tighten struct layout (CVE-2026-64472) - PCI: altera: Fix resource leaks on probe failure (CVE-2026-64462) - PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() - PCI: mediatek: Switch to msi_create_parent_irq_domain() - PCI: mediatek: Convert bool to single quirks entry and bitmap - PCI: mediatek: Use generic MACRO for TPVPERL delay - PCI: mediatek: Fix IRQ domain leak when port fails to enable (CVE-2026-64461) - PCI: Use pbus_select_window() during BAR resize - PCI: Prevent resource tree corruption when BAR resize fails - PCI: Free saved list without holding pci_bus_sem - PCI: Fix restoring BARs on BAR resize rollback path - PCI: Move Resizable BAR code to rebar.c - PCI: Skip Resizable BAR restore on read error - staging: rtl8723bs: core: move constants to right side in comparison - staging: rtl8723bs: fix spaces around binary operators - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() - [amd64] crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438) - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (CVE-2026-64434) - gpio: sch: use raw_spinlock_t in the irq startup path (CVE-2026-64428) - io_uring/rw: ensure reissue path is correctly handled for IOPOLL - io_uring/rw: preserve partial result for iopoll - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code - media: nxp: imx8-isi: Fix use-after-free on remove (CVE-2026-64421) - netfilter: ebtables: Use vmalloc_array() to improve code - netfilter: ebtables: zero chainstack array (CVE-2026-64413) - Bluetooth: L2CAP: Fix not tracking outstanding TX ident - Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (CVE-2026-64206) - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO - Bluetooth: separate CIS_LINK and BIS_LINK link types - Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() (CVE-2026-64405) - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() - mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (CVE-2026-64416) - smb: client: Improve unlocking of a mutex in cifs_get_swn_reg() - smb: client: resolve SWN tcon from live registrations (CVE-2026-64401) - ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name - vfs: make LAST_XXX private to fs/namei.c - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create - ksmbd: use opener credentials for FSCTL mutations - ksmbd: centralize ksmbd_conn final release to plug transport leak - ksmbd: track the connection owning a byte-range lock (CVE-2026-64390) - proc: rename proc_setattr to proc_nochmod_setattr - proc: protect ptrace_may_access() with exec_update_lock (FD links) - [amd64] perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box() - HID: add haptics page defines - HID: multitouch: fix out-of-bounds bit access on mt_io_flags (CVE-2026-64364) - seqlock: Introduce scoped_seqlock_read() - seqlock: Change do_task_stat() to use scoped_seqlock_read() - proc: protect ptrace_may_access() with exec_update_lock (part 1) - treewide: Switch/rename to timer_delete[_sync]() - HID: appleir: fix UAF on pending key_up_timer in remove() (CVE-2026-64363) - HID: pidff: Fix missing blank lines after declarations - HID: pidff: Add missing spaces - HID: pidff: Rework pidff_upload_effect - HID: pidff: Use correct effect type in effect update - hfs/hfsplus: prevent getting negative values of offset/length - hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (CVE-2026-64361) - bpf: Convert lpm_trie.c to rqspinlock - bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() - bpf: Consistently use bpf_rcu_lock_held() everywhere - bpf: Allow LPM map access from sleepable BPF programs (CVE-2026-64352) - usb: iowarrior: remove inherent race with minor number - USB: iowarrior: fix use-after-free on disconnect race (CVE-2026-64341) - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() - crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 - crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A - usb: gadget: f_fs: initialize reset_work at allocation time - crypto: atmel-sha204a - fail on hwrng registration error in probe path - usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile - btrfs: concentrate the error handling of submit_one_sector() - btrfs: replace for_each_set_bit() with for_each_set_bitmap() - btrfs: remove folio parameter from ordered io related functions - btrfs: remove the COW fixup mechanism - btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC - [amd64] crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown - [amd64] crypto: ccp - Reset TMR size at SNP Shutdown - [amd64] crypto: ccp - Register SNP panic notifier only if SNP is enabled - [amd64] crypto: ccp - Move SEV/SNP Platform initialization to KVM - [amd64] crypto: ccp - Fix a case where SNP_SHUTDOWN is missed - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) - [amd64] crypto: qat - fix restarting state leak on allocation failure - exfat: remove unnecessary read entry in __exfat_rename() - exfat: rename argument name for exfat_move_file and exfat_rename_file - exfat: add exfat_get_dentry_set_by_ei() helper - exfat: move exfat_chain_set() out of __exfat_resolve_path() - exfat: fix incorrect directory checksum after rename to shorter name - exfat: preserve benign secondary entries during rename and move - btrfs: fix false IO failure after falling back to buffered write - btrfs: fix incorrect buffered IO fallback for append direct writes - slab: Introduce kmalloc_obj() and family - slab: Introduce kmalloc_flex() and family - add default_gfp() helper macro and use it in the new *alloc_obj() helpers - default_gfp(): avoid using the "newfangled" __VA_OPT__ trick - slab: recognize @GFP parameter as optional in kernel-doc - fscrypt: Fix key setup in edge case with multiple data unit sizes - fscrypt: Replace mk_users keyring with simple list - mm/damon/core: always put unsuccessfully committed target pids - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers - [arm64] KVM: arm64: Ensure level is always initialized when relaxing perms - [arm64] KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (CVE-2026-64192) - [amd64] perf/x86/amd/brs: Fix kernel address leakage - dibs: loopback: validate offset and size in move_data() - seqlock: fix scoped_seqlock_read kernel-doc - ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd - rtnetlink: Make per-netns RTNL dereference helpers to macro. - net: airoha: Fix channel configuration for ETS Qdisc - jiffies: Cast to unsigned long in secs_to_jiffies() conversion - afs: Fix afs_atcell_get_link() to check if ws_cell is unset first - afs: Fix afs_dynroot_readdir() to not use the RCU read lock - [amd64] crypto: ccp - Fix __sev_snp_shutdown_locked - [amd64] crypto: ccp - Fix dereferencing uninitialized error pointer - [amd64] crypto: ccp - Fix SNP panic notifier unregistration - udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() - Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state - Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle - [amd64] crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() - i40e: drop udp_tunnel_get_rx_info() call from i40e_open() - ice: drop udp_tunnel_get_rx_info() call from ndo_open() - [amd64] crypto: ccp - Fix leaking the same page twice - Bluetooth: L2CAP: Fix regressions caused by reusing ident - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev - Bluetooth: L2CAP: fix tx ident leak for commands without a response - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() - tools/testing: add linux/args.h header and fix radix, VMA tests https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.98 - ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.99 - mm: refactor mm_access() to not return NULL https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.100 - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (CVE-2026-64560) linux-signed-amd64 (6.12.96+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.96-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.96 - [arm64] bpf, arm64: Reject out-of-range B.cond targets - nfsd: fix file change detection in CB_GETATTR - nfsd: release layout stid on setlease failure - userfaultfd: gate must_wait writability check on pte_present() - perf: Fix dangling cgroup pointer in cpuctx backport - bcachefs: avoid truncating fiemap extent length - drm/amd: Fix set but not used warnings - gpio: rockchip: change the GPIO version judgment logic - gpio: rockchip: teardown bugs and resource leaks - gpio: rockchip: fix generic IRQ chip leak on remove (CVE-2026-53226) - mm/vmalloc: take vmap_purge_lock in shrinker (CVE-2026-46093) - device property: initialize the remaining fields of fwnode_handle in fwnode_init() - f2fs: validate orphan inode entry count - f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes - f2fs: fix potential deadlock in f2fs_balance_fs() - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() - f2fs: fix listxattr handling of corrupted xattr entries - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() - nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations - nfs_common: rename functions that invalidate LOCALIO nfs_clients - NFSv4/flexfiles: Remove cred local variable dependency - NFSv4/flexfiles: Add data structure support for striped layouts - NFSv4/flexfiles: reject zero filehandle version count - locking/rtmutex: Make sure we wake anything on the wake_q when we release the lock->wait_lock - apparmor: advertise the tcp fast open fix is applied - nfsd: move name lookup out of nfsd4_list_rec_dir() - nfsd: change nfs4_client_to_reclaim() to allocate data - bonding: fix xfrm offload feature setup on active-backup mode - block: add a store_limit operations for sysfs entries - block: fix queue freeze vs limits lock order in sysfs store methods (CVE-2025-21807) - mm/khugepaged: write all dirty file folios when collapsing - perf trace beauty fcntl: Fix build with older kernel headers - ACPI: CPPC: Suppress UBSAN warning caused by field misuse - ACPI: NFIT: core: Fix possible NULL pointer dereference - [amd64] platform/x86: intel-hid: Protect ACPI notify handler against recursion - perf/core: Detach event groups during remove_on_exec - [amd64] drm/i915: ensure segment offset never exceeds allowed max - usb: gadget: function: rndis: add length check to response query - usb: gadget: function: rndis: add length check for header - iio: accel: bmc150: clamp the device-reported FIFO frame count - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error - iio: adc: lpc32xx: Initialize completion before requesting IRQ - iio: adc: spear: Initialize completion before requesting IRQ - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable - iio: adc: ti-ads124s08: Return reset GPIO lookup errors - iio: backend: fix uninitialized data in debugfs - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug - iio: common: st_sensors: honour channel endianness in read_axis_data - iio: event: Fix event FIFO reset race - iio: gyro: bmg160: bail out when bandwidth/filter is not in table - iio: gyro: bmg160: wait full startup time after mode change at probe - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ - iio: imu: inv_icm42600: fix timestamp clock period by using lower value - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading - iio: imu: st_lsm6dsx: deselect shub page before reading whoami - iio: light: al3010: fix incorrect scale for the highest gain range - iio: light: gp2ap002: fix runtime PM leak on read error - iio: light: opt3001: fix missing state reset on timeout - iio: light: tsl2591: return actual error from probe IRQ failure - iio: light: veml6030: fix channel type when pushing events - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call - iio: resolver: ad2s1210: notify trigger and clear state on fault read error - iio: temperature: Build mlx90635 with CONFIG_MLX90635 - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start - ALSA: virtio: Add missing 384 kHz PCM rate mapping - ALSA: virtio: Validate control metadata from the device - ALSA: ymfpci: check snd_ctl_new1() return value - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser - ALSA: cmipci: check snd_ctl_new1() return value - ALSA: es1938: check snd_ctl_new1() return value - ALSA: firewire: isight: bound the sample count to the packet payload - ALSA: gus: check snd_ctl_new1() return value - ALSA: ice1712: check snd_ctl_new1() return value - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() - ALSA: usb-audio: avoid kobject path lookup in DualSense match - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks - ALSA: usb-audio: Roll back quirk control caches on write errors - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes - vfio/pci: Use a private flag to prevent power state change with VFs - vfio/pci: Latch disable_idle_d3 per device - vfio/pci: Release the VGA arbiter client on register_device() failure - vfio/pci: Fix racy bitfields and tighten struct layout - vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc - vfio: Remove device debugfs before releasing devres - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB - Bluetooth: btusb: fix use-after-free on registration failure - Bluetooth: btusb: fix use-after-free on marvell probe failure - Bluetooth: btusb: fix wakeup source leak on probe failure - [arm*] binder: fix UAF in binder_thread_release() - [arm*] binder: fix UAF in binder_free_transaction() - usb: xhci: Fix sleep in atomic context in xhci_free_streams() - usb: typec: tcpci_rt1711h: unregister TCPCI port with devres - PCI: host-common: Request bus reassignment when not probe-only - [arm*] PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling - mm/damon/ops-common: handle extreme intervals in damon_hot_score() - netfilter: ipset: fix race between dump and ip_set_list resize - virtio_pci: fix vq info pointer lookup via wrong index - virtio-mmio: fix device release warning on module unload - hwrng: virtio: clamp device-reported used.len at copy_data() - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() - usb: dwc3: run gadget disconnect from sleepable suspend context - 6lowpan: fix NHC entry use-after-free on error path - tipc: fix out-of-bounds read in broadcast Gap ACK blocks - staging: vme_user: bound slave read/write to the kern_buf size - smb: client: restrict implied bcc[0] exemption to responses without data area - staging: vme_user: fix location monitor leak in fake bridge - staging: vme_user: fix location monitor leak in tsi148 bridge - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe - staging: media: atomisp: reduce load_primary_binaries() stack usage - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop - staging: rtl8723bs: fix OOB write in HT_caps_handler() - crypto: amlogic - avoid double cleanup in meson_crypto_probe() - ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL - net: af_key: initialize alg_key_len for IPComp states - audit: Fix data races of skb_queue_len() readers on audit_queue - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete - coresight: etb10: restore atomic_t for shared reading state - debugobjects: Plug race against a concurrent OOM disable - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns - NTB: epf: Avoid calling pci_irq_vector() from hardirq context - gpio: eic-sprd: use raw_spinlock_t in the irq startup path - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item - netpoll: fix a use-after-free on shutdown path - ipv4: igmp: remove multicast group from hash table on device destruction - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes - mfd: cros_ec: Delay dev_set_drvdata() until probe success - mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() - mm: shrinker: fix shrinker_info teardown race with expansion - mm: shrinker: fix NULL pointer dereference in debugfs - mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup - netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump - netfilter: handle unreadable frags - netfilter: ebtables: module names must be null-terminated - netfilter: ebtables: terminate table name before find_table_lock() - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() - Bluetooth: bnep: pin L2CAP connection during netdev registration - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() - Bluetooth: fix UAF in bt_accept_dequeue() - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() - Bluetooth: L2CAP: validate option length before reading conf opt value - fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr - fs/ntfs3: fsync files by syncing parent inodes - fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio() - fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() (CVE-2026-53027) - coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() - smb/client: Fix error code in smb2_aead_req_alloc() - ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE - ksmbd: add a permission check for FSCTL_SET_ZERO_DATA - ksmbd: serialize QUERY_DIRECTORY requests per file - ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation - ksmbd: require source read access for duplicate extents - ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY - ksmbd: run set info with opener credentials - ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION - ksmbd: add per-handle permission check to FILE_LINK_INFORMATION - ksmbd: use opener credentials for delete-on-close - ksmbd: use opener credentials for ADS I/O - smb: client: fix query directory replay double-free - smb: client: fix query_info() replay double-free - smb: client: fix double-free in SMB2_ioctl() replay - smb: client: fix change notify replay double-free - smb: client: fix double-free in SMB2_flush() replay - smb: client: fix double-free in SMB2_open() replay - smb: client: fix double-free in SMB2_close() replay - smb: client: Fix next buffer leak in receive_encrypted_standard() - smb: client: use unaligned reads in parse_posix_ctxt() - smb: client: harden POSIX SID length parsing - smb: client: fix atime clamp check in read completion - smb: client: mask server-provided mode to 07777 in modefromsid - writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() - cpufreq: qcom-cpufreq-hw: Fix possible double free - firmware_loader: fix device reference leak in firmware_upload_register() - [amd64] cpufreq: intel_pstate: Sync policy->cur during CPU offline - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT - cpufreq: Fix hotplug-suspend race during reboot - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path - clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances - X.509: Fix validation of ASN.1 certificate header - mm/slab: do not limit zeroing to orig_size when only red zoning is enabled - tools/mm/slabinfo: Fix trace disable logic inversion - tools/mm/slabinfo: fix total_objects attribute name - HID: hid-goodix-spi: validate report size to prevent stack buffer overflow - HID: wacom: stop hardware after post-start probe failures - HID: letsketch: fix UAF on inrange_timer at driver unbind - HID: lg-g15: cancel pending work on remove to fix a use-after-free - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers - media: mtk-jpeg: cancel workqueue on release for supported platforms only - serial: 8250_mid: Disable DMA for selected platforms - xfs: use null daddr for unset first bad log block - xfs: release dquot buffer after dqflush failure - xfs: fix unreachable BIGTIME check in dquot flush validation - xfs: fix pointer arithmetic error on 32-bit systems - xfs: fix exchmaps reservation limit check - bpf: Reject fragmented frames in devmap - bpf: Restore sysctl new-value from 1 to 0 - bpf: Validate BTF repeated field counts before expansion - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() - usb: cdc_acm: Add quirk for Uniden BC125AT scanner - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() - usb: free iso schedules on failed submit - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler - usb: gadget: udc: Fix use-after-free in gadget_match_driver - usb: gadget: f_printer: take kref only for successful open - USB: idmouse: fix use-after-free on disconnect race - USB: ldusb: fix use-after-free on disconnect race - USB: iowarrior: fix use-after-free on disconnect - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD - USB: legousbtower: fix use-after-free on disconnect race - usb: sl811-hcd: disable controller wakeup on remove - USB: storage: include US_FL_NO_SAME in quirks mask - USB: misc: uss720: unregister parport on probe failure - usb: mtu3: unmap request DMA on queue failure - USB: serial: keyspan_pda: fix information leak - USB: serial: option: add Telit Cinterion FE990D50 compositions - USB: serial: digi_acceleport: fix broken rx after throttle - USB: serial: digi_acceleport: fix hard lockup on disconnect - USB: serial: digi_acceleport: fix write buffer corruption - USB: ulpi: fix memory leak on registration failure - USB: usb-storage: ene_ub6250: restore media-ready check - usbip: tools: support SuperSpeedPlus devices - usbip: vudc: fix NULL deref in vep_dequeue() - usb: typec: anx7411: use devm_pm_runtime_enable() - usb: typec: class: drop PD lookup reference - usb: typec: tcpm: Fix VDM type for Enter Mode commands - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() - usb: typec: ucsi: Invert DisplayPort role assignment - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove - usb: typec: ucsi: cancel pending work on system suspend - usb: gadget: f_fs: Fix DMA fence leak - block: skip sync_blockdev() on surprise removal in bdev_mark_dead() - [amd64] x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled - PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining - udf: validate free block extents against the partition length - udf: validate VAT header length against the VAT inode size - udf: validate sparing table length as an entry count, not a byte count - hwrng: jh7110 - fix refcount leak in starfive_trng_read() - nvme: target: rdma: fix ndev refcount leak on queue connect - dm-ioctl: report an error if a device has no table - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page - nvmet-auth: validate reply message payload bounds against transfer length - btrfs: do not trim a device which is not writeable - partitions: aix: bound the pp_count scan to the ppe array - isofs: bound Rock Ridge symlink components to the SL record - crypto: af_alg - Remove zero-copy support from skcipher and aead - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps again - crypto: ecc - Fix carry overflow in vli multiplication - crypto: pcrypt - restore callback for non-parallel fallback - [amd64] crypto: ccp - Do not initialize SNP for SEV ioctls - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) - crypto: drbg - Fix returning success on failure in CTR_DRBG - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels - crypto: drbg - Fix the fips_enabled priority boost - [amd64] crypto: qat - keep VFs enabled during reset - [amd64] crypto: qat - notify fatal error before AER reset preparation - [amd64] crypto: qat - protect service table iterations with service_lock - [amd64] crypto: qat - validate RSA CRT component lengths - [arm64] fpsimd: Fix type mismatch in sme_{save,load}_state() - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path - EDAC/i10nm: Don't fail probing if ADXL is missing - watchdog: apple: Add "apple,t8103-wdt" compatible - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() - i2c: core: fix hang on adapter registration failure - tracing: Prevent out-of-bounds read in glob matching - audit: fix potential integer overflow in audit_log_n_hex() - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC - module: decompress: check return value of module_extend_max_pages() - exfat: bound uniname advance in exfat_find_dir_entry() - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() - riscv: mm: Unconditionally sfence.vma for spurious fault - mm: fix mmap errno value when MAP_DROPPABLE is not supported - mm: do file ownership checks with the proper mount idmap - [amd64] iommu/amd: Don't split flush for amd_iommu_domain_flush_all() - iommufd: Set upper bounds on cache invalidation entry_num and entry_len - [amd64] KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs - [amd64] KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits - [amd64] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode - udmabuf: fix DMA direction mismatch in release_udmabuf() - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning - i2c: core: fix irq domain leak on adapter registration failure - i2c: core: fix NULL-deref on adapter registration failure - i2c: core: fix adapter probe deferral loop - i2c: core: fix adapter debugfs creation - i2c: core: fix adapter deregistration race - i2c: mpc: Fix timeout calculations - i2c: stm32f7: truncate clock period instead of rounding it - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count - Input: elan_i2c - prevent division by zero and arithmetic underflow - Input: goodix - clamp the device-reported contact count - Input: iforce - bound the device-reported force-feedback effect index - Input: mms114 - fix touch indexing for MMS134S and MMS136 - Input: touchwin - reset the packet index on every complete packet - Input: mms114 - reject an oversized device packet size - Input: maplemouse - fix NULL pointer dereference in open() - Input: mms114 - fix multi-touch slot corruption - Input: maple_keyb - set driver data before registering input device - Input: maplemouse - set driver data before registering input device - Input: maplecontrol - set driver data before registering input device - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg - RDMA/siw: bound Read Response placement to the RREAD length - fuse: fix device node leak in cuse_process_init_reply() - fuse: re-lock request before returning from fuse_ref_folio() - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req - usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks - smb: client: reject overlapping data areas in SMB2 responses - xfs: fix null pointer dereference in tracepoint - xfs: fail recovery on a committed log item with no regions - xfs: resample the data fork mapping after cycling ILOCK - xfs: don't wrap around quota ids in dqiterate - xfs: set xfarray killable sort correctly - xfs: clamp timestamp nanoseconds correctly - xfs: fully check the parent handle when it points to the rootdir - xfs: don't zap bmbt forks if they are MAXLEVELS tall . [ Han Gao ] * [riscv64] set NR_CPUS to 128 (Closes: #1140651) . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." (context changes) linux-signed-amd64 (6.12.95+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.95-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95 - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain - wifi: mt76: mt7921: fix a potential scan no APs - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (CVE-2026-53101) - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167) - gpiolib: Extract gpiochip_choose_fwnode() for wider use - gpiolib: Remove redundant assignment of return variable - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (CVE-2026-31732) - io_uring/net: Avoid msghdr on op_connect/op_bind async data - drm/xe/display: fix oops in suspend/shutdown without display (CVE-2026-53142) - [arm64] drm/v3d: Store the active job inside the queue's state - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139) - eventpoll: use hlist_is_singular_node() in __ep_remove() - eventpoll: split __ep_remove() - eventpoll: kill __ep_remove() - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() - eventpoll: rename ep_remove_safe() back to ep_remove() - eventpoll: move epi_fget() up - eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355) - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216) - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP - debugobjects: Do not fill_pool() if pi_blocked_on - debugobjects: Dont call fill_pool() in early boot hardirq context - RDMA/bnxt_re: zero shared page before exposing to userspace - i2c: stub: Reject I2C block transfers with invalid length - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe() (CVE-2026-53325) - bpf: Reject sleepable kprobe_multi programs at attach time (CVE-2026-43010) - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() - regulator: core: fix locking in regulator_resolve_supply() error path - dlm: prevent NPD when writing a positive value to event_done (CVE-2025-23131) - xfs: remove the expr argument to XFS_TEST_ERROR - xfs: fix error returns in CoW fork repair - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()" - net: bonding: add broadcast_neighbor option for 802.3ad - bonding: add support for per-port LACP actor priority - bonding: print churn state via netlink - bonding: 3ad: implement proper RCU rules for port->aggregator (CVE-2026-52975) - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) - bonding: fix NULL pointer dereference in actor_port_prio setting - staging: rtl8723bs: fix buffer over-read in rtw_update_protection (CVE-2026-53179) - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (CVE-2026-53341) - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs - hv: utils: handle and propagate errors in kvp_register - locking/mutex: Remove wakeups from under mutex::wait_lock - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued - phonet: Pass ifindex to fill_addr(). - phonet: Pass net and ifindex to phonet_address_notify(). - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157) - rxrpc: Fix the ACK parser to extract the SACK table for parsing (CVE-2026-53151) - fuse: re-lock request before replacing page cache folio - ftrace: Update the mcount_loc check of skipped entries - ftrace: Have ftrace pages output reflect freed pages - ftrace: Do not over-allocate ftrace memory - ftrace: Test mcount_loc addr before calling ftrace_call_addr() - ftrace: Check against is_kernel_text() instead of kaslr_offset() - net: ipv6: Make udp_tunnel6_xmit_skb() void - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070) - iio: light: veml6075: add bounds check to veml6075_it_ms index - iio: adc: ti-ads1298: add bounds check to pga_settings index - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero - ksmbd: reject non-VALID session in compound request branch - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si - virtiofs: fix UAF on submount umount - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support" - [amd64] KVM: SEV: Ignore MMIO requests of length '0' - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ - [amd64] KVM: SEV: Ignore Port I/O requests of length '0' - batman-adv: tp_meter: keep unacked list in ascending ordered - batman-adv: tp_meter: initialize dup_acks explicitly - batman-adv: tp_meter: initialize dec_cwnd explicitly - batman-adv: tp_meter: avoid window underflow - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd - batman-adv: tp_meter: fix fast recovery precondition - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection - batman-adv: tp_meter: add only finished tp_vars to lists - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE - batman-adv: prevent ELP transmission interval underflow - batman-adv: tp_meter: initialize last_recv_time during init - batman-adv: ensure bcast is writable before modifying TTL - batman-adv: fix (m|b)cast csum after decrementing TTL - batman-adv: frag: ensure fragment is writable before modifying TTL - batman-adv: frag: avoid underflow of TTL - batman-adv: v: prevent OGM aggregation on disabled hardif - batman-adv: tp_meter: restrict number of unacked list entries - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE - batman-adv: tp_meter: prevent parallel modifications of last_recv - batman-adv: tp_meter: handle overlapping packets - batman-adv: tt: don't merge change entries with different VIDs - batman-adv: tt: track roam count per VID - batman-adv: dat: prevent false sharing between VLANs - batman-adv: tvlv: enforce 2-byte alignment - batman-adv: tvlv: avoid race of cifsnotfound handler state - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362) - fs: constify file ptr in backing_file accessor helpers - lsm: add backing_file LSM hooks - selinux: fix overlayfs mmap() and mprotect() access checks - inet: add indirect call wrapper for getfrag() calls - ipv4: account for fraggap on the paged allocation path - ntfs3: reject direct userspace writes to reserved $LX* xattrs - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361) - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g - mac802154: llsec: add skb_cow_data() before in-place crypto - net: skmsg: preserve sg.copy across SG transforms - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink - apparmor: mediate the implicit connect of TCP fast open sendmsg - apparmor: fix use-after-free in rawdata dedup loop - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR - fbdev: fix use-after-free in store_modes() - kernel/fork: clear PF_BLOCK_TS in copy_process() - block: invalidate cached plug timestamp after task switch - err.h: use __always_inline on all error pointer helpers - KEYS: fix overflow in keyctl_pkey_params_get_2() - keys: Pin request_key_auth payload in instantiate paths - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer - wifi: ath11k: fix warning when unbinding - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor - wifi: rtw88: increase TX report timeout to fix race condition - wifi: rtw88: usb: fix memory leaks on USB write failures - wifi: iwlwifi: mvm: fix race condition in PTP removal - f2fs: validate compress cache inode only when enabled - f2fs: fix to round down start offset of fallocate for pin file - f2fs: validate ACL entry sizes in f2fs_acl_from_disk() - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() - f2fs: keep atomic write retry from zeroing original data - block: Avoid mounting the bdev pseudo-filesystem in userspace - bpf: use kvfree() for replaced sysctl write buffer - exfat: fix potential use-after-free in exfat_find_dir_entry() - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() - gfs2: fix use-after-free in gfs2_qd_dealloc - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() - hdlc_ppp: sync per-proto timers before freeing hdlc state - blk-cgroup: fix UAF in __blkcg_rstat_flush() - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done - pNFS: Fix use-after-free in pnfs_update_layout() - fpga: region: fix use-after-free in child_regions_with_firmware() - rpmsg: char: Fix use-after-free on probe error path - ocfs2: reject oversized group bitmap descriptors - 9p: avoid putting oldfid in p9_client_walk() error path - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() - [riscv64] mm: Extract helper mark_new_valid_map() - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect() - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var - fbdev: modedb: fix a possible UAF in fb_find_mode() - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode - i2c: core: fix adapter registration race - NFSD: Fix SECINFO_NO_NAME decode error cleanup - nfsd: fix posix_acl leak on SETACL decode failure - nfsd: check get_user() return when reading princhashlen - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race - nfsd: reset write verifier on deferred writeback errors - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr - NFS: Prevent resource leak in nfs_alloc_server() - ksmbd: fix out-of-bounds read in smb_check_perm_dacl() - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails - drivers/base/memory: set mem->altmap after successful device registration - Documentation: ioctl-number: Fix linuxppc-dev mailto link - Documentation: ioctl-number: Extend "Include File" column width - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources - [amd64] crypto: qat - remove unused character device and IOCTLs - net/tcp-ao: fix use-after-free of key in del_async path - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex - net: bonding: update the slave array for broadcast mode - bonding: annotate data-races arcound churn variables - bonding: do not set usable_slaves for broadcast mode . [ Salvatore Bonaccorso ] * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686) * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." . [ Uwe Kleine-König ] * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly (Closes: #1136179) linux-signed-amd64 (6.12.95+1~bpo12+1) bookworm-backports; urgency=medium . * Sign kernel from linux 6.12.95-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-arm64 (6.12.107+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.107-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.106 - PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept - ALSA: scarlett2: Use a private URB for the notification endpoint - rndis_host: add overflow check in rndis_rx_fixup() - gpio: ml-ioh: use raw_spinlock_t for the register lock (CVE-2026-80562) - gve: fix zero-length skb frag with header-split - hwmon: (ltc4286) Fix symbol namespace of MODULE_IMPORT_NS() - netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() (CVE-2026-64216) - inet: frags: add inet_frag_putn() helper - ipv4: frags: remove ipq_put() - inet: frags: change inet_frag_kill() to defer refcount updates - inet: frags: save a pair of atomic operations in reassembly - inet: frags: publish queues before arming timer (CVE-2026-74662) - serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx (CVE-2026-74653) - NTB: ntb_netdev: Preserve RX queue depth on allocation failure (CVE-2026-74626) - serial: amba-pl011: synchronize DMA teardown - serial: sc16is7xx: rename EFR mutex with generic name - serial: sc16is7xx: use guards for simple mutex locks - serial: sc16is7xx: enable THRI before filling TX FIFO - xfs: namespace the maximum length/refcount symbols - xfs: don't use a xfs_log_iovec for ri_buf in log recovery - xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536) - xfs: hoist per-bucket unlinked list check to helper - xfs: don't livelock in scrub on a circular unlinked list - ALSA: dummy: Check card index validity at probe - ocfs2: fix missing metadata reservation for large xattrs - null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows - kcov: fix data corruption and race conditions on PREEMPT_RT - ext4: stop retrying saturated xattr cache entries - ext4: clear error before retrying inode xattr space fallback - ext4: propagate errors from fast commit range replay - xfs: validate attr entry pointer before field access - libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557) - nfc: digital: clamp SENSF_RES length to the destination buffer - nfc: fdp: bound the device-reported read length and fix an skb leak - nfc: microread: validate target discovery payload lengths - nfc: llcp: bound the connect_sn TLV walk to the skb - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers - nfc: llcp: reject PDUs shorter than the LLCP header - nfc: pn533: purge fragmented skbs during cleanup - nfc: st21nfca: validate ATR_REQ length against the received frame - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers - nfc: nci: free destination parameters when closing a connection - ndisc: ndisc_send_redirect() cleanup - Input: byd - synchronize timer deletion before freeing private data (CVE-2026-80572) - ipv4: reject undersized MTUs in ip_do_fragment() - ipv6: fix use-after-free in ip6_finish_output2() - nvmet-auth: zero the AUTH_RECEIVE response buffer - nvmet-fc: fix invalid free in LS IOD error path - nvmet-tcp: bound SGL data length before allocating command buffers - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations - mptcp: pm: fix data race in add_addr timer callback - [arm64] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (CVE-2026-80583) - drm/xe: Fix DPT allocation paths. - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C - HID: magicmouse: re-enable multitouch after reset-resume - HID: magicmouse: do not keep a stale msc->input if no input is claimed - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID - HID: core: fix OOB read of field->usage in hid_set_field() - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ - xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (CVE-2026-64581) - ipv4: start using dst_dev_rcu() (CVE-2025-40074) - mptcp: pm: fix memory leak from alloc-during-teardown race - Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard - Input: atkbd - skip deactivate for HONOR ZQC-P - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() - HID: nintendo: register input device after capabilities are set - HID: nintendo: stop device IO before hid_hw_stop on probe failure - HID: core: fix number/pointer type confusion on long items - HID: sensor: custom: Fix use-after-free in enable_sensor - HID: hyperv: validate initial device info bounds - Bluetooth: hci_event: fix LE list UAF on reset - Bluetooth: hci_event: validate LE Set CIG Parameters response - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync - Bluetooth: hci_aml: validate firmware segment lengths - net: gro: properly validate BIG TCP aggregation criteria https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.107 - inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590) linux-signed-arm64 (6.12.105+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.105-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.102 - [amd64] x86/bugs: Make Safe-RET robust against interrupt injection (CVE-2026-68480) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.103 - netfilter: nf_conntrack_expect: restore helper propagation via expectation - netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() - net: mpls: initialize rtm_tos in mpls_getroute() - HID: logitech-dj: Standardise hid_report_enum variable nomenclature - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report - bpf: Reset register bounds before narrowing retval range in check_mem_access() - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197) - [amd64] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect - [arm64] pinctrl: qcom: Unconditionally mark gpio as wakeup enable - [arm64] pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA - [amd64] dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() - ata: sata_mv: accept 1 or 2 resources in platform probe - ata: libahci_platform: support non-consecutive port numbers - ahci: Introduce ahci_ignore_port() helper - ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup - of: reserved_mem: Add code to dynamically allocate reserved_mem array - of: reserved_mem: prevent OOB when too many dynamic regions are defined - btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag - btrfs: zoned: fix deadlock between metadata writeback and transaction commit - [arm64] phy-zynqmp: Postpone getting clock rate until actually needed - [arm64] phy: zynqmp: fix clock error handling in xpsgtr_phy_init() - [arm64] phy: zynqmp: fix runtime PM leak on probe allocation failure - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() - [arm64] drm/mediatek: Check CRTC state before freeing - Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation - KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type - keys: fix out-of-bounds read in keyring_get_key_chunk() - keys: make keyring key-chunk byte order agree with keyring_diff_objects() - assoc_array: trim the final shortcut word using the current chunk end - netfilter: nf_tables: make nft_object rhltable per table - netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH - ipvs: fix the checksum validations - ipvs: fix places with wrong packet offsets - ipvs: do not mangle ICMP replies for non-first fragments - netfilter: nft_payload: fix mask build for partial field offload - rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (CVE-2026-68322) - rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() - [amd64,arm64] pinctrl-amd: Don't clear S4 wake bits at probe - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer - scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race - smb: client: fix buffer leaks in SMB1 read and write - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 - hwmon: (ina2xx) Add support for has_alerts configuration flag - hwmon: (ina2xx) Add support for INA260 - hwmon: (ina226) Add support for SY24655 - hwmon: (ina2xx) Make it easier to add more devices - hwmon: (ina2xx) Add support for INA234 - hwmon: (ina2xx) Shift INA234 shunt and current registers - hwmon: (ina2xx) Fix various overflow issues - hwmon: (ltc4282) Fix reading the minimum alarm voltage - hwmon: (sht3x) Fix unaligned accesses - hwmon: (lm90) Only report alarms if driver is ready - hwmon: (nzxt-smart2) DMA-align output buffer - net: do not send ICMP/NDISC Redirects when peer allocation fails - hwmon: (nct6775-core) Prevent access to unsupported weight registers - net: bridge: mrp: fix Option TLV length in MRP_Test frames - forcedeth: fix UAF of txrx_stats in nv_remove - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors - hwmon: (adt7470) Fix cache updated before hardware write on I2C error - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks - hwmon: (adt7470) Use cached PWM frequency value - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read - hwmon: (adt7470) Fix PWM auto temp state array and bounds check - rtase: fix double free of multi-frag skb on DMA map failure - [powerpc*] boot: Fix simpleboot CPU node lookup check - [powerpc*] boot: Fix treeboot-currituck CPU node lookup check - [powerpc*] boot: Fix treeboot-akebono CPU node lookup check - net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() - wifi: mac80211: validate individual TWT params before driver setup - net: ethernet: mtk_eth_soc: support named IRQs - net: ethernet: mtk_eth_soc: add consts for irq index - net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() - [amd64,arm64] idpf: adjust TxQ ring count minimum - [amd64,arm64] idpf: Fix mailbox IRQ name leak on request failure - Bluetooth: ISO: clear iso_data always when detaching conn from hcon - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() - Bluetooth: ISO: fix leaking sk after socket release - Bluetooth: ISO: avoid deadlocks in iso_sock_timeout - Bluetooth: btintel: Validate length before parsing diagnostics TLV - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() - Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync - net: phylink: put link_gpio if phylink_create fails - scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE - scsi: ufs: core: Cancel RTC work in active-active suspend - scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req - scsi: target: Clear cmd_cnt when initial counter enrollment fails - net: sxgbe: free TX rings on RX allocation failure - net: sxgbe: check descriptor ring allocation failures - can: isotp: check register_netdevice_notifier() error in module init - tracing/mmiotrace: Reset dropped_count in mmio_reset_data() - tracing: Remove TRACE_EVENT_FL_FILTERED logic - tracing/mmiotrace: Remove reference to unused per CPU data pointer - tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions - [riscv64] mm: Fix out-of-bounds page-table walk during memory hot-remove - [arm64] net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend - [arm64] net: dsa: mt7530: error out on failed reads in MT7531 PHY polling - net: libwx: fix FDIR ATR queue mismatch for software VLAN packets - [arm64] octeontx2-pf: Set correct sequence for carrier off and tx queue stop - sched/deadline: Use revised wakeup rule only for running dl_server - qede: sync udp_tunnel ports outside qede_lock in the recovery path - ksmbd: return success for deferred final close - ksmbd: fix use-after-free in __close_file_table_ids() - pinctrl: devicetree: don't free uninitialized dev_name on error path - erofs: cap LZMA stream pool size - pinctrl: bm1880: add missing select GENERIC_PINCONF - fortify: Disable -Wstringop-overread in tests - mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() - mm/hugetlb: fix list corruption in allocate_file_region_entries() - mm/vmstat: fold stranded per-cpu node stats when a node comes online - tracing/probes: Reject $arg0 in meta argument expansion - [amd64] KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active - [s390x] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled - [s390x] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure - [s390x] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages - sctp: validate Adaptation Indication parameter length - audit: fix potential integer overflow in audit_log_n_string() - audit: fix potential use-after-free in audit_del_rule() - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() - Bluetooth: mgmt: fix pending command UAF in EIR updates - Bluetooth: mgmt: fix UAF in pair command cancellation - Bluetooth: hci_sync: Fix advertising data UAFs - Bluetooth: HIDP: reject frames without a transaction header - Bluetooth: HIDP: validate numbered report payloads - bpf: lwt: Fix dst reference leak on reroute failure - ALSA: 6fire: Fix UAF at error handling during probe - ALSA: lx6464es: fix period byte count for 16-bit streams - ALSA: pcm: wake linked drain waiters on unlink - ALSA: seq: Fix division by zero in initialize_timer() - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes - ALSA: ump: fix double free of out_cvts on rawmidi error - ASoC: tas2562: fix DVC coefficient write order - ASoC: tas2562: fix broken entries in the volume lookup table - ata: libata-eh: Increase STANDBY IMMEDIATE timeout - ata: libata-sata: fix ata_scsi_lpm_supported() iteration - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() - ALSA: usb-audio: fix stack info leak in RME Digiface status - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set - ALSA: usb-audio: Clamp frame size in implicit-feedback mode - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ - e1000: fix memory leak in e1000_probe() - igbvf: Fix leak in TX DMA error cleanup - ipvs: do not propagate one-packet flag to synced conns - net/smc: fix socket use-after-free during link group termination - netfilter: ipset: do not update comments from kernel-side hash adds - tipc: avoid use-after-free in poll trace queue dumps - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames - binfmt_misc: reject a flag character as the field delimiter - binfmt_misc: don't let an 'F' entry pin its own instance - mm/page_reporting: use system_freezable_wq to fix UAF during suspend - mm: memcg: initialize *locked in memcg1_oom_prepare() stub - net: bridge: stop fast-leave after deleting a port group - net: ipv6: clear suppressed fib6 rule result - [powerpc*] ps3: Fix map failure path in dma_ioc0_map_pages() - veth: convert frag_list skbs before running XDP - vxlan: re-fetch eth header after route_shortcircuit() - vxlan: unclone skb head before modifying eth header in route_shortcircuit() - vxlan: use neigh_ha_snapshot() in route_shortcircuit() - vxlan: use pskb_network_may_pull() in route_shortcircuit() - ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() - tracing: Check return value of __register_event() in trace_module_add_events() - tracing/filters: Fix false positive match in regex_match_full() - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write - sctp: reject stale cookies with mismatched verification tags - sctp: prevent peer transport count overflow - hwmon: (npcm750-pwm-fan): stop fan timer on device detach - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client - i2c: amd-mp2: Unregister callback on adapter add failure - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() - cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized - power: supply: bq25890: fix the -10 C NTC lookup entry - power: supply: max17040: handle missing status supplier - [s390x] pci: Fix s390_pci_mmio_write syscall error return without MIO - [s390x] qeth: Check CAP_NET_ADMIN for private ioctls - [s390x] dasd: Fix potential NULL pointer dereference - [s390x] dasd: Fix undersized format-check buffer - [s390x] zcrypt: Fix wrong domain value verification with EP11 CPRBs - [s390x] zcrypt: Validate length for CCA AES cipher key requests - [s390x] zcrypt: Validate length for CCA ECC private key requests - [arm64] phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask - [arm64] phy: zynqmp: use read-modify-write for SERDES scrambler bypass - [arm64] phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB - net: openvswitch: fix potential UAF on meter attach failure - net: openvswitch: fix skb leak on flow key update failure during recirculation - net: openvswitch: fix skb leak on flow key update failure during ct - ice: wait for reset completion in ice_resume() - ice: fix memory leak in ice_lbtest_prepare_rings() - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock - i2c: iproc: reset bus after timeout if START_BUSY is stuck - i2c: imx: Fix slave registration race and error handling - i2c: imx: Cancel hrtimer before clearing slave pointer - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured - can: ems_usb: validate CPC message lengths - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents - can: softing: fw_parse(): validate firmware record spans - can: peak_usb: add bounds check for USB channel index - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error - can: peak_usb: validate uCAN receive record lengths - can: ctucanfd: add missing MODULE_DEVICE_TABLE() - can: ctucanfd: use self-test mode for PRESUME_ACK - can: ctucanfd: unmap BAR0 using base address - can: ctucanfd: handle bus error interrupts - can: ctucanfd: mark error-active controller status valid - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs - [arm*] drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size - [arm*] drm/vc4: Zero the tile state data array before each BIN job - [arm64] drm/panthor: reject firmware sections with oversized data - [arm64] drm/panthor: validate firmware interface structure sizes - [arm64] drm/mediatek: ovl_adaptor: balance component registrations - drm/amdgpu: restore UMD profile pstate after runtime resume - drm/amdgpu: cap GTT size to physical RAM on APUs - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames - drm/amd/display: use proper context for logging - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE - drm/amdkfd: fix QID bit leak in pqm_create_queue() - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment - drm/amdkfd: Handle invalid event type in CRIU event restore - drm/amdkfd: hold event_mutex while checkpointing CRIU events - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size - drm/vmwgfx: reject DX_BIND_QUERY without a DX context - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division - drm/vmwgfx: bound DMA command body size against suffix pointer - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure - drm/vmwgfx: use check_add_overflow for shader size+offset bound - drm/vmwgfx: validate external BO copy bounds for both stride paths - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX - HID: logitech-dj: Fix maxfield check in DJ short report validation - ata: libahci_platform: Do not set mask_port_map when not needed - ata: ahci: Make ahci_ignore_port() handle empty mask_port_map - of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release - drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting - drm/xe: Introduce xe_gt_dbg_printer() - drm/xe: Apply whitelist to engine save-restore - drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267) - drm/xe/rtp: Maintain OA whitelists separately - drm/xe/rtp: Keep track of non-OA nonpriv slots - drm/xe/rtp: Generalize whitelist_apply_to_hwe - drm/xe/rtp: Save OA nonpriv registers to register save/restore lists - drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs - drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt - drm/xe/oa: (De-)whitelist OA registers on OA stream open/release - drm/xe/rtp: Ensure locking/ref counting for OA whitelists - mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios - lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() - mm/slab: prevent unbounded recursion in free path with new kmalloc type - gpio: pch: use raw_spinlock_t for the register lock - usb: gadget: f_tcm: synchronize delayed set_alt with teardown (CVE-2026-68367) - usb: typec: ucsi: split connector lock classes - usb: typec: ucsi: Fix race condition and ordering in port unregistration - media: i2c: imx219: Rename VTS to FRM_LENGTH - media: imx219: Fix maximum frame length in lines - media: chips-media: wave5: Support CBP profile - media: uapi: rkisp: Correct name version enum - wifi: brcmfmac: drain bus_reset work on device removal (CVE-2026-64586) - wifi: ath6kl: fix use-after-free in aggr_reset_state() (CVE-2026-68198) - wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change - mptcp: pm: avoid code duplication to lookup endp - mptcp: add mptcp_userspace_pm_lookup_addr helper - mptcp: pm: use addr entry for get_local_id - mptcp: pm: userspace: fix use-after-free in get_local_id (CVE-2026-68169) - drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions - drm/amdgpu: Fix context pstate override handling (CVE-2026-68273) - drm/sched: Store the drm client_id in drm_sched_fence - drm/amdgpu: give each kernel job a unique id - drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (CVE-2026-68276) - drm/fb-helper: Allocate and release fb_info in single place - drm/tegra: fbdev: Remove offset into framebuffer memory - drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] - drm/xe: Wait on external BO kernel fences in exec IOCTL - [arm64] drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() - [arm64] drm/i915/vrr: require valid min/max vfreq for VRR (CVE-2026-68254) - drm/xe: Rename ___xe_bo_create_locked() - drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266) - [arm64] drm/i915/hdcp: Move to using intel_display in intel_hdcp - [arm64] drm/i915/hdcp: require monotonically increasing seq_num_v - [arm64] drm/i915/hdcp: Skip inactive MST connectors when building stream list - [arm64] drm/i915/hdcp: check streams[] bounds before overflow (CVE-2026-68253) - drm/xe: Stub out new pagefault layer - drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (CVE-2026-68264) - rxrpc: Generate rtt_min - rxrpc: Adjust the rxrpc_rtt_rx tracepoint - rxrpc: Fix the calculation and use of RTO - rxrpc: Manage RTT per-call rather than per-peer - rxrpc: Fix irq-disabled in local_bh_enable() (CVE-2025-38525) - can: use skb hash instead of private variable in headroom - can: isotp: fix timer drain order, wakeup handling and tx_gen ordering - usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path - drm/fb-helper: Fix a locking bug in an error path - [arm64,armhf] drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.104 - mount: honour SB_NOUSER in the new mount API - drm/amd/display: Add AV mute wait frames to dce110_set_avmute - drm/amd/display: Check for tg ops in dce110_set_avmute - [s390x] zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call - [arm64] dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer - drm/bridge: ps8640: propagate AUX transfer register errors - [arm64] net: hns3: fix speed configuration residue after driver reload - Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor - enic: fix tx_hang_reset use-after-free on device removal - net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock - pds_core: keep the health thread stopped during reset - pds_core: cancel pending PCI reset work on AER recovery - netfilter: ipset: switch ext_size to atomic64_t - ipvs: avoid out-of-bounds write in ip_vs_nat_icmp - ipvs: return the csum validation for forward hook - watchdog: bd96801_wdt: Fix timeout for enabled WDG - btrfs: fix memory leak in btrfs_do_encoded_write() - bpf: Preserve pointer state for commuted arithmetic - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() - net/sched: cls_route: fix fastmap use-after-free on filter - [arm64] net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete - devlink: fix net namespace reference leak in reload - net/mlx5: fw_tracer, return NULL on create error - counter: microchip-tcb-capture: Fix DT channel validation - bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch - bpf: tcp: Make sure iter->batch always contains a full bucket snapshot - bpf: tcp: Get rid of st_bucket_done - bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items - bpf: tcp: Avoid socket skips and repeats during iteration - bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() - vhost/vdpa: reject overflowing PA map page counts on 32-bit - vdpa/mlx5: Fix buffer length in create_direct_keys() - tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() - xsk: require at least 16 bytes of TX metadata - udp: fix potential use-after-free in tunnel segmentation - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter - net/openvswitch: check Ethernet header length in key_extract() - net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers - hwmon: (nzxt-smart2) Check return value of init_device() in probe - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations - bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() - bnxt_en: Determine and store default RX ring in vnic structure - bnxt_en: Refresh VNIC default ring on queue restart if needed - bnxt_en: Fix PTP PPS setting bug - sctp: fix addip_serial increment on ASCONF_ACK allocation failure - tcp: fix TFO max_qlen accounting across reuseport migration - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length - net: prestera: validate firmware header length - net: remove WARN_ON_ONCE() from sk_mc_loop() - net/smc: fix TOCTOU race between smc_listen_out() and listener close - [amd64] net: thunderbolt: Tear down DMA paths before stopping the rings - ata: pata_sl82c105: fix bridge revision use-after-free - net/atm: fix slab-out-of-bounds read in vcc_setsockopt() - sctp: clear control chunk transport if it is being removed - tls: don't abort the connection on signal-interrupted sends - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination - hwmon: (ads7828) Fix external VREF regulator handling - hwmon: (ltc4282) Avoid overflow in maximum power calculation - hwmon: (ltc4282) Clamp negative current limits - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt - mm/vmscan: wake up flushers conditionally to avoid cgroup OOM (Closes: #1143545) - net: fec: do not release NULL pages when RX buffer allocation fails - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers - mtd: spinand: fix direct mapping creation sizes - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails - mtd: spinand: repeat reading in regular mode if continuous reading fails - swapfile: call cond_resched() before locking si->lock - Input: evdev - sanitize event type index when fetching event masks - ALSA: usb-audio: fix OOB write on Type II inbound URBs - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() - [amd64] thunderbolt: icm: Preserve USB4 proxy data-valid bit - usb: cdnsp: fix incorrect endian conversions for APB timeout register - usb: gadget: f_ncm: Use unsigned int for ndp_index - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() - net: usb: ipheth: fix carrier_work UAF on disconnect - vt: add permission check for KDSKBMETA ioctl - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get - Input: evdev - fix information leak in evdev_pass_values() - ima: fix out-of-bounds read in xattr_verify() - ipvs: stop estimator after disabled calc phase - ipvs: add totalconns for dest - ipvs: properly update the overload flag on dest edit - ipvs: clear IPv4 options after rebasing tunnel ICMP errors - packet: use consistent hard_header_len in non-ring send paths - packet: use consistent hard_header_len in TX_RING send path - net/packet: reset the MAC header on the packet-socket transmit path - packet: synchronize pressure clearing with ring reconfiguration - net: fix skb length accounting after generic XDP frag adjustment - net: openvswitch: reallocate update replies for mismatched IDs - net/sched: reject overly deep qdisc hierarchies - net: octeontx2-pf: Fix UB in shift operation - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header - mac802154: fix netdev use-after-free in beacon worker - netfilter: ebt_nflog: pin the NFLOG backend - net: bridge: mrp: fix uninitialised bytes on the wire - [s390x] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (CVE-2026-74514) - [s390x] KVM: s390: pci: Fix missing error codes and memory unaccounting - [s390x] KVM: s390: pci: Fix resource leak on IRQ registration failure - [s390x] KVM: s390: pci: Fix aisb calculation - block: Reorder the request allocation code in blk_mq_submit_bio() - blk-mq: pop cached request if it is usable (CVE-2026-64017) - blk-mq: reinsert cached request to the list - dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk - [amd64] crypto: ccp - Add new SEV/SNP platform shutdown API - [amd64] KVM: SVM: Add support to initialize SEV/SNP functionality in KVM - [amd64] crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length - [amd64] crypto: ccp - Abort doing SEV INIT if SNP INIT fails - futex: Prevent robust futex exit race some more - kunit/fortify: Replace "volatile" with OPTIMIZER_HIDE_VAR() - kunit/fortify: Add back "volatile" for sizeof() constants - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops - ipv4: fix use-after-free in fib_nhc_update_mtu() - mei: pull kvfree out of spinlock - nvmem: layouts: Add fixed-layout driver - serial: qcom-geni: fix TX DMA buffer flush - serial: 8250_dma: Clear stale RX state on shutdown - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() - staging: rtl8723bs: fix OOB read in WMM_param_handler() - staging: rtl8723bs: fix missing shared-key auth challenge length check - staging: rtl8723bs: validate monitor transmit frame lengths - misc: fastrpc: fix channel ctx ref leak when session alloc fails - misc: fastrpc: Remove buffer from list prior to unmap operation - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free - ring-buffer: Fix crash passing ERR_PTR to kthread_stop() - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs - ALSA: usx2y: bound the hwdep mmap fault offset - tracing: Fix race between update_event_fields and, event_define_fields - fbdev: bitblit: bound-check glyph index in bit_cursor() - ring-buffer: Prevent subbuf order change when resizing is disabled - mm/huge_memory: fix huge_zero_pfn race - net: smc: fix splice entry lifetime imbalance in smc_rx_splice - ipv6: prevent in6_dev_get() from resurrecting inet6_dev - netfilter: bridge: release template ct on non-IP path - netfilter: nf_conntrack: defer invalid log until after unlock - net: atlantic: free stranded TX buffers on ring deinit - net: atlantic: free RX pages of consumed but not refilled buffers - net/sched: act_ct: fix sk_buff leak when the header checks reject a packet - net/sched: act_gact, act_police: range check the fallback control action - ovl: don't warn when the mount is completed from another user namespace - binfmt_misc: don't warn when the mount is completed from another user namespace - Revert "drm/amdgpu: fix aperture mapping leak" - xdp: reject clones that overrun skb_shared_info tailroom - vxlan: do not arm the ageing timer on a device that is down - vsock/virtio: read virtqueues under worker locks - vsock/virtio: avoid refilling the RX queue after teardown - veth: fix skb length accounting after XDP frag adjustment - vhost: reset the vring metadata cache on vring reconfiguration - tls: don't leave a full plaintext sk_msg ring unpushed - tipc: read le->link under the node lock in tipc_node_link_down() - smb: client: Fix use-after-free in cifs_try_adding_channels() - [amd64] KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page - eventfs: Fix use-after-free in eventfs_remove_rec() - Revert "thermal/drivers/hwmon: Cleanup coding style a bit" - ptp: ocp: Fix board ID over-read - ipv6: fix Route Information option length validation - ip6_tunnel: clear skb2->cb[] in ip6ip6_err() - fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() - sched/psi: Shut down rtpoll_timer in psi_cgroup_free() - ima: Instantiate file_truncate and path_truncate hooks - fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions - fsverity: Fix silent truncation in bpf_get_fsverity_digest() - bpf, sockmap: Fix sk_redir use-after-free in send verdict - scsi: scsi_debug: Negate wrapped memcmp() result - sctp: keep chunk->transport in step with the list it is queued on - sctp: fix use-after-free of cached ASCONF chunk - sctp: clear new_transport when removing a peer - [amd64] thunderbolt: Bound the DROM dual link port number before indexing sw->ports - [amd64] thunderbolt: Fix bandwidth group reservation indexing - bpf: tcp: fix double sock release on batch realloc https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.105 - block: stop the timeout timer when releasing a never added disk - bpf: Fix linked reg delta tracking when src_reg == dst_reg (CVE-2026-53092) - bpf: Clear delta when clearing reg id for non-{add,sub} ops - f2fs: fix UAF issue in f2fs_merge_page_bio() (CVE-2025-40054) - mtd: ubi: skip programming unused bits in ubi headers - ubi: fastmap: fix ubi->fm memory leak - mm/damon/ops-common: putback folios on invalid migrate nid (CVE-2026-74644) - mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} - igc: fix netdev not re-attached after resume if interface is down - ipvs: separate destination availability state - net: mana: Fix EQ leak in mana_remove on NULL port - [amd64] crypto: ccp: Add external API interface for PSP module initialization - [amd64] KVM: SVM: Ensure PSP module is initialized if KVM module is built-in - selinux: require every boolean value to be defined - selinux: reject a class permission count below its inherited common - selinux: do not cancel a policy conversion that never started - selinux: reject an unclaimed class value in security_get_classes() - mptcp: avoid combining some incoming suboptions - mptcp: options: reset DSS fields in case of unexpected size - mptcp: fastopen: only mark MPTFO subflows with SYN data - [s390x] qeth: validate user buffer length in SNMP and ARP query ioctls - [amd64] ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() - fbdev: core: Fix pointer desynchronization in fb_io_read() - drm/panthor: skip zero-sized firmware sections - drm/amdgpu: reject oversized IBs with per-ring packet limits - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 - drm/amdgpu: fix aperture iounmap skipped on device removal - [amd64] ASoC: SOF: topology: Use acpi mach from the machine driver - Input: xpad - add support for ZENAIM LEVERLESS - Input: cs40l50-vibra - validate custom data from user space - [powerpc*] pseries: pci - logic bug - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet - Input: psxpad-spi - set driver data before use - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard - Input: iforce - validate input packet lengths - [powerpc*] pseries: lparcfg - fix kbuf[] underflow - Input: synaptics-rmi4 - zero report size on F54 work error - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer - Input: synaptics-rmi4 - block s_input when F54 queue is busy - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue - Input: hynitron_cstxxx - validate touch count and finger IDs - [arm64] crypto: qce - fix error path in devm_qce_register_algs - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind - [arm64] pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 - libceph: fix multiple unsafe decodes in decode_locker() - ftrace: Protect direct_functions in ftrace_find_rec_direct - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() - Input: sur40 - fix input device registration ordering - Input: sur40 - fix V4L error path cleanup - libceph: Avoid using invalid osd indices from primary_temp - ceph: fix MDS random selection readiness predicate - libceph: tolerate addrvecs with multiple entries of the same type - [armhf] mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit - mmc: sdhci: unmap the bounce buffer before device release - mmc: sdhci: make tuning_err a signed int - drm/connector/hdmi: Fix out of bounds memory read - drm/xe: Order ring writes before ring tail updates - drm/radeon: fix autosuspend cleanup during teardown - [s390x] vfio_ccw: Free all memory if cp_init() fails - [s390x] vfio_ccw: Limit the number of channel program segments - [s390x] vfio_ccw: Cancel existing workqueues - [s390x] vfio_ccw: Ensure index for read/write regions are within range - [s390x] vfio_ccw: Ensure first IDAW remains constant - [s390x] vfio_ccw: Fix out of bounds check on CCW array - [s390x] vfio_ccw: Move cp cleanup out of not operational - [s390x] vfio_ccw: Selectively expand io_mutex - [s390x] vfio_ccw: Calculate idal length based on idaw type - [s390x] vfio_ccw: Implement a crw lock - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE - drm/amdgpu: Reject UVD message with invalid number of h265 refs - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional - drm/amdgpu: check ASPM on the dGPU host link - drm/amdgpu: validate GEM_CREATE domain combinations - drm/amdgpu: Reject UVD message with dimensions above 4096 - drm/amdgpu: Implement insert_end for VCE 3 - drm/amdgpu: Fix UVD min buffer sizes - drm/amdgpu: Fix UVD dpb min size calculation for H264 - drm/amdgpu: Fix UVD decode image min size calculation - drm/amdgpu: disallow multiple FENCE chunks in one submit - xfs: clear zapped attr fork state when bmap repair finds no attr fork - xfs: zero i_nlink before repair puts inode on unlinked list - xfs: only check mergeability of bnobt records - xfs: don't double-lock when deleting a self-referential directory - xfs: set the prev pointer when reinserting an inode on the unlinked list - xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers - xfs: nlink scrub must take IOLOCK before determining ILOCK state - xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev - xfs: fix ilock leak on error in xfs_dq_get_next_id - xfs: don't zap the attr fork on repair when there are queued pptr updates - xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair - xfs: fix allocated inodes that show up in the unlinked list - xfs: fix another iunlink infinite loop bug in online fsck - xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers - xfs: avoid UAF on sc->tempip in xrep_tempfile_create - xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN - xfs: don't swallow dquot recovery verification errors - xfs: check xfarray iteration errors when committing unlinked inode lists - xfs: check v5 superblock features early - ceph: Remove ceph_writepage() - ceph: Use a folio in ceph_page_mkwrite() - ceph: Convert ceph_find_incompatible() to take a folio - ceph: Convert writepage_nounlock() to write_folio_nounlock() - ceph: fix writeback_count leak in write_folio_nounlock() - ceph: avoid fs reclaim while using current->journal_info - ceph: fix hanging __ceph_get_caps() with stale mds_wanted - libceph: Amend checking to fix `make W=1` build breakage - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159) - mm/khugepaged: guard is_zero_pfn() calls with pte_present() - userfaultfd: prevent registration of special VMAs (CVE-2026-68166) - libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082) - net/sched: serialize qdisc_rtab_list against concurrent get/put (CVE-2026-68138) - super: remove pointless s_root checks - super: skip dying superblocks early - super: use a common iterator (Part 1) - super: use common iterator (Part 2) - fs/super: fix emergency thaw double-unlock of s_umount - super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132) - smb: move smb_version_values to common/smbglob.h - smb: move get_rfc1002_len() to common/smbglob.h - smb/server: rename include guard in smb_common.h - ksmbd: rename smb2_get_msg to smb_get_msg - smb/server: fix minimum SMB1 PDU size - smb/server: fix minimum SMB2 PDU size - ksmbd: validate minimum PDU size for transform requests (CVE-2026-68431) - eventpoll: pin files while checking reverse paths - tcp: Pass flags to __tcp_send_ack - tcp: fast path functions later - tcp: reorganize tcp_sock_write_txrx group for variables later - tcp: challenge ACK for non-exact RST in SYN-RECEIVED (CVE-2026-68118) - iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace - btrfs: add debug build only WARN - btrfs: add space_info argument to btrfs_chunk_alloc() - btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() - btrfs: zoned: fix missing chunk metadata reservation - [amd64] KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (CVE-2026-74517) - [arm64] ASoC: tas2562: Validate values for volume writes - ata: libata-scsi: terminate deferred commands on time out - igc: remove napi_synchronize() in igc_down() - ksmbd: conn lock to serialize smb2 negotiate - ksmbd: reject repeated SMB2 NEGOTIATE requests (CVE-2026-74494) - net: pktgen: fix code style (WARNING: Block comments) - net: pktgen: fix proc entry use-after-free (CVE-2026-74479) - binfmt_misc: don't leak the user namespace when the mount fails (CVE-2026-74483) - fsnotify, lsm: Decouple fsnotify from lsm - fsnotify: opt-in for permission events at file open time - fs: don't block write during exec on pre-content watched files - binfmt_misc: restore write access when removing an entry (CVE-2026-74487) - vrf: Make pcpu_dstats update functions available to other modules. - vxlan: Handle stats using NETDEV_PCPU_STAT_DSTATS. - vxlan: use pskb_network_may_pull() for transmit path header pulls (CVE-2026-74474) - ice: fix VF interrupts cleanup - include/linux/fs.h: add inode_lock_killable() - smb: client: fix race with fallocate(2) and AIO+DIO - cifs: add fscache_resize_cookie() to cifs_setsize() - can: rcar_canfd: change the initializing flow for clocks and resets - drm/amd/pm: Use same metric table for APU - drm/amd/pm: Use macro to initialize metrics table - drm/amd/pm: fix torn gpu metrics reads - drm/amdgpu: remove unused function parameter - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini - drm/amd/pm: adjust the visibility of pp_table sysfs node - drm/amd/pm: fix pptable use-after-free (CVE-2026-74450) - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684) - drm/vmwgfx: take fman->lock around fence list mutation in fifo_down - ring-buffer: Simplify functions with __free(kfree) to free allocations - ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() (CVE-2026-74602) - mm/pagewalk: split walk_page_range_novma() into kernel/user parts - mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF (CVE-2026-74672) - mm/ptdump: always stabilise against page table freeing using init_mm (CVE-2026-74599) - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (CVE-2026-74607) - ring-buffer: Simplify ring_buffer_read_page() with guard() - ring-buffer: Make ring_buffer_{un}map() simpler with guard(mutex) - ring-buffer: Prevent resizing of persistent ring buffer - [amd64] x86/mce: Remove __mcheck_cpu_init_early() - [amd64] x86/mce: Set CR4.MCE last during init - [amd64] x86/mce: Set up the polling timer before CMCI discovery - [amd64] ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup - net/x25: fix use-after-free of the socket by its timers (CVE-2026-74628) - [arm64] tegra: Add EL2 virtual timer interrupt for Tegra194 - crypto: ccm - Set rfc4309 maxauthsize from child - netfilter: ipset: fix refcount race between list:set GC and swap - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path - netfilter: flowtable: publish GC-visible tuple last - netfilter: ipset: fix list type element drift bug - netfilter: ipset: let destroy callbacks adjust ext mem size - ipvlan: inherit needed_headroom and needed_tailroom from phy_dev - macvlan: inherit needed_headroom and needed_tailroom from lowerdev - veth: fix queue index used to wake the peer txq in veth_poll - tcp: fix icsk_ack.ato bitfield overflow - net: packet: fix wrong transport_header when sending VLAN-tagged frame - net/tls: Fail tls_sw_splice_read() after a failed async decrypt - af_packet: Don't send zero-byte data in tpacket_snd(). - net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain - net/sched: cls_u32: skip hash tables in u32_bind_class() - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG - net/sched: cls_bpf: reject dev-bound programs bound to a different device - drm/xe/oa: Fix sync entry leak on OA config emit failure - erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms - perf: Unify perf_event_free_task() / perf_event_exit_task_context() - perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637) - fs: unlock the superblock during iterate_supers_type - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone - net: harmonize tstats and dstats - ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS - ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() - ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601) - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r - net: ethernet: mtk_eth_soc: only use legacy mode on missing IRQ name - net: ethernet: mtk_eth_soc: improve support for named interrupts . [ Salvatore Bonaccorso ] * drivers/mmc/host: Enable MMC_ALCOR as module (Closes: #1142912) * drivers/misc/cardreader: Enable MISC_ALCOR_PCI as module (Closes: #1142912) linux-signed-arm64 (6.12.101+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.101-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.101 - [amd64] platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug - net: airoha: Move airoha_eth driver in a dedicated folder - net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() - bpf: Fix ld_{abs,ind} failure path analysis in subprogs (CVE-2026-53090) - netfilter: nft_counter: serialize reset with spinlock (CVE-2026-45897) - netfilter: nft_quota: use atomic64_xchg for reset - netfilter: nf_tables: revert commit_mutex usage in reset path (CVE-2026-45901) - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race - seqlock: Cure some more scoped_seqlock() optimization fails - seqlock: Allow KASAN to fail optimizing - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing - [amd64] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (CVE-2026-64561) - [amd64] KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN - [amd64] KVM: nVMX: Hide shadow VMCS right after VMCLEAR (CVE-2026-64562) - [amd64] KVM: x86/mmu: Fix use-after-free on vendor module reload - can: bcm: add locking when updating filter and timer values - can: bcm: fix CAN frame rx/tx statistics - can: bcm: extend bcm_tx_lock usage for data and timer updates - can: bcm: validate frame length in bcm_rx_setup() for RTR replies - can: bcm: add missing device refcount for CAN filter removal - can: bcm: fix stale rx/tx ops after device removal - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() - can: bcm: track a single source interface for ANYDEV timeout/throttle ops - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER - can: isotp: serialize TX state transitions under so->rx_lock - dmaengine: sh: rz-dmac: Move interrupt request after everything is set up - Revert "arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc" - [arm64,armhf] gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin - xprtrdma: Clear receive-side ownership pointers on release - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (CVE-2026-64565) - Input: ims-pcu - fix logic error in packet reset - [arm64] tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 - IB/mad: Drop unmatched RMPP responses before reassembly - mtd: mtdswap: remove debugfs stats file on teardown - mtd: nand: mtk-ecc: stop on ECC idle timeouts - btrfs: reject free space cache with more entries than pages - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() - RDMA/cma: Fix hardware address comparison length in netevent callback - RDMA/umem: Add pinned revocable dmabuf import interface - RDMA/irdma: Prevent rereg_mr for non-mem regions - RDMA/erdma: initialize ret for empty receive WR lists - [arm64] RDMA/hns: Fix potential integer overflow in mhop hem cleanup - RDMA/siw: publish QP after initialization - mtd: fix double free and WARN_ON in add_mtd_device() error paths - RDMA/irdma: Prevent overflows in memory contiguity checks - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert - wifi: cfg80211: cancel sched scan results work on unregister - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() - wifi: mac80211_hwsim: clamp virtio RX length before skb_put - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure - wifi: mac80211: fix fils_discovery double free on alloc failure - wifi: libertas: fix memory leak in helper_firmware_cb() - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() - wifi: cfg80211: pass net_device to .set_monitor_channel - wifi: cfg80211: define and use wiphy guard - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock - wifi: nl80211: free RNR data on MBSSID mismatch - wifi: cfg80211: derive S1G beacon TSF from S1G fields - wifi: nl80211: validate nested MBSSID IE blobs - wifi: cfg80211: validate PMSR measurement type data - wifi: cfg80211: validate PMSR FTM preamble range - wifi: cfg80211: reject unsupported PMSR FTM location requests - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock - wifi: brcmfmac: initialize SDIO data work before cleanup - wifi: cfg80211: bound element ID read when checking non-inheritance - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() - ASoC: cs42l43: Correct report for forced microphone jack - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup - [arm64] firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF - ipv4: fib: free fib_alias with kfree_rcu() on insert error path - net/iucv: take a reference on the socket found in afiucv_hs_rcv() - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() - scsi: core: wake eh reliably when using scsi_schedule_eh - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered - ata: sata_dwc_460ex: use platform_get_irq() - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning - [amd64] accel/ivpu: Fix wrong register read in LNL failure diagnostics - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC - Bluetooth: qca: fix NVM tag length underflow in TLV parser - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds - Bluetooth: hci_qca: Clear memdump state on invalid dump size - smb/client: handle overlapping allocated ranges in fallocate - [amd64] drm/i915/gt: use correct selftest config symbol - [powerpc*] 85xx: Add fsl,ifc to common device ids - [powerpc*] time: Prepare to stop elapsing in dynticks-idle - [powerpc*] vtime: Initialize starttime at boot for native accounting - bpf, sockmap: Reject unhashed UDP sockets on sockmap update - [s390x] checksum: Fix csum_partial() without vector facility - [riscv64] hwprobe: Avoid uninitialized read in hwprobe_get_cpus() - can: j1939: fix lockless local-destination check - drm/xe/wopcm: fix WOPCM size for LNL+ - smb: move some duplicate definitions to common/cifsglob.h - ksmbd: pin conn during async oplock break notification - ksmbd: validate compound request size before reading StructureSize2 - net/sched: act_tunnel_key: Defer dst_release to RCU callback - sctp: fix auth_hmacs array size in struct sctp_cookie - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n - usb: core: sysfs: add lock to bos_descriptors_read() - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() - usb: core: port: Deattach Type-C connector on component unbind - USB: storage: add NO_ATA_1X quirk for Longmai USB Key - usb: chipidea: fix usage_count leak when autosuspend_delay is negative - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback - usb: gadget: f_midi: cancel pending IN work before freeing the midi object - usb: gadget: printer: fix infinite loop in printer_read() - USB: gadget: snps-udc: fix device name leak on probe failure - USB: gadget: fsl-udc: fix device name leak on probe failure - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer - USB: serial: ftdi_sio: add support for E+H FXA291 - USB: serial: io_edgeport: cap received transmit credits - USB: serial: keyspan_pda: fix data loss on receive throttling - USB: serial: option: add TDTECH MT5710-CN - crypto: rsa-pkcs1pad: Don't WARN on an empty digest - Revert "drm/amd/display: Add missing kdoc for ALLM parameters" - [riscv64] KVM: Serialize virtual interrupt pending state updates - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET - firewire: net: Fix fragmented datagram reassembly - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read - wifi: carl9170: fix OOB read from off-by-two in TX status handler - wifi: carl9170: fix buffer overflow in rx_stream failover path - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps - btrfs: free mapping node on duplicate reloc root insert - ASoC: tas2781: bound firmware description string parsing - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (CVE-2025-40098) - ALSA: hda: cs35l41: validate and free ACPI mute object - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI - ASoC: cs35l56: Don't use devres to unregister component - ASoC: cs35l56: Fix potential probe() deadlock - ASoC: cs35l56: Use complete_all() to signal init_completion - wifi: iwlwifi: mvm: validate SAR GEO response payload size - wifi: iwlwifi: mvm: fix read in wake packet notification handler - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC - hwmon: (asus-ec-sensors) fix EC read intervals - hwmon: (asus-ec-sensors) add missed handle for ENOMEM - smb: client: validate DFS referral PathConsumed - hwmon: occ: validate poll response sensor blocks - regulator: mt6358: use regmap helper to read fixed LDO calibration - Bluetooth: btusb: validate Realtek vendor event length - netlink: specs: rt-link: convert bridge port flag attributes to u8 - net/packet: avoid fanout hook re-registration after unregister - bonding: fix devconf_all NULL dereference when IPv6 is disabled - rds: drop incoming messages that cross network namespace boundaries - gtp: parse extension headers before reading inner protocol - [arm64] dpaa2-eth: put MAC endpoint device on disconnect - [amd64] iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() - wifi: mac80211: tear down new links on vif update error path - nfp: Check resource mutex allocation - wan: wanxl: Only reset hardware after BAR mapping - wifi: mwifiex: bound uAP association event IEs to the event buffer - [amd64] iommu/amd: Bound the early ACPI HID map - [amd64] iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() - wifi: mac80211: recalculate TIM when a station enters power save - pds_core: reject component parameter in legacy firmware update - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN - net: txgbe: fix FDIR filter leak on remove - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid - pds_core: fix deadlock between reset thread and remove - pds_core: fix use-after-free on workqueue during remove - pds_core: yield the CPU while waiting for the adminq to drain - pds_core: order completion reads after the ownership check - pds_core: fix auxiliary device add/del races - pds_core: check for workqueue allocation failure - sctp: validate stream count in sctp_process_strreset_inreq() - net: mctp i3c: clean up notifier and buses if driver register fails - tls: device: push pending open record on splice EOF - gtp: check skb_pull_data() return in gtp1u_send_echo_resp() - nexthop: initialize extack in nh_res_bucket_migrate() - tipc: fix infinite loop in __tipc_nl_compat_dumpit - wifi: mt76: mt7925: guard link STA in decap offload - wifi: mt76: mt7915: guard HE capability lookups - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() - wifi: mt76: mt7925: fix crash in reset link replay - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning - ovl: fix trusted xattr escape prefix matching - amt: re-read skb header pointers after every pull - amt: make the head writable before rewriting the L2 header - net: bridge: vlan: fix vlan range dumps starting with pvid - net: hsr: fix memory leak on slave unregistration by removing synced VLANs - net: dpaa: fix mode setting - sctp: auth: verify auth requirement when auth_chunk is NULL - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets - iomap: correct the range of a partial dirty clear - tipc: fix u16 MTU truncation in media and bearer MTU validation - net: stmmac: fix l3l4 filter rejecting unsupported offload requests - net: stmmac: reset residual action in L3L4 filters on delete - net: stmmac: enable the MAC on link up for all supported speeds - net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM - octeontx2-vf: set TC flower flag on MCAM entry allocation - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup - ppp: use IFF_NO_QUEUE in virtual interfaces - ppp: convert to percpu netstats - ppp: enable TX scatter-gather - ppp: annotate data races in ppp_generic - [amd64,arm64] hinic: remove unused ethtool RSS user configuration buffers - net: qrtr: restrict socket creation to the initial network namespace - dpll: add clock quality level attribute and op - net/mlx5: DPLL, Add clock quality level op implementation - net/mlx5: Remove newline at the end of a netlink error message - net/mlx5: Refactor EEPROM query error handling to return status separately - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule - net/mlx5e: Report zero bandwidth for non-ETS traffic classes - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation - octeontx2-pf: tc: fix egress ratelimiting - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV - ice: fix LAG recipe to profile association - rds: tcp: unregister sysctl before tearing down listen socket - net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() - [arm64] drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers - [arm64] drm/dp/mst: fix buffer overflows in sideband chunk accumulation - [arm64] drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 - drm/nouveau: fix reversed error cleanup order in ucopy functions - drm/displayid: fix Tiled Display Topology ID size - [amd64] drm/i915/gem: Add missing nospec on parallel submit slot - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() - drm/radeon: fix r100_copy_blit for large BOs - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds - drm/amdkfd: Use kvcalloc to allocate arrays - drm/amdkfd: Check bounds in allocate_event_notification_slot - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference - drm/virtio: bound EDID block reads to the response buffer - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() - [amd64] drm/i915: Return NULL on error in active_instance - [amd64] drm/i915/bios: range check LFP Data Block panel_type2 - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() - [amd64] drm/i915/gem: Do not leak siblings[] on proto context error - [amd64] drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU - drm/amd/pm: fix smu14 power limit range calculation - drm/gfx10: Program DB_RING_CONTROL - [arm64] drm/panthor: return error on truncated firmware - drm/amdgpu: Fix VFCT bus number matching with soft filter - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) - drm/amd/display: set new_stream to NULL after release - drm/amd/display: dce100: skip non-DP stream encoders for DP MST - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved - drm/vmwgfx: Validate vmw_surface_metadata::array_size - drm/vc4: Prevent shader BO mappings from becoming writable - media: airspy: Return queued buffers on start_streaming() failure - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure - media: cec: seco: unregister adapter on IR probe failure - media: cedrus: clean up media device on probe failure - media: cedrus: Fix missing cleanup in error path - media: cedrus: skip invalid H.264 reference list entries - media: chips-media: wave5: Move src_buf Removal to finish_encode - media: cx231xx: fix devres lifetime - media: cx23885: add ioremap return check and cleanup - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges - media: marvell-cam: fix missing pci_disable_device() on remove - media: meson: vdec: Fix memory leak in error path of vdec_open - media: msi2500: Return queued buffers on start_streaming() failure - media: nuvoton: npcm-video: fix error handling in npcm_video_init() - media: nuvoton: npcm-video: fix memory leaks in probe and remove - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path - media: nxp: imx8-isi: Fix potential out-of-bounds issues - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding - media: pci: dm1105: Free allocated workqueue - media: pwc: Drain fill_buf on start_streaming() failure - media: pwc: Return queued buffers on start_streaming() failure - media: qcom: camss: Fix RDI streaming for CSID GEN2 - media: radio-si476x: Unregister v4l2_device on probe failure - media: rtl2832: fix use-after-free in rtl2832_remove() - media: rtl2832_sdr: Return queued buffers on start_streaming() failure - media: saa7134: Fix a possible memory leak in saa7134_video_init1 - media: stm32: dcmi: unregister notifier on probe failure - media: sun4i-csi: Return queued buffers on start_streaming() failure - media: tegra-video: vi: fix invalid u32 return value in format lookup - media: ti: vpe: unwind v4l2 device registration on probe error - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() - media: v4l2-ctrls: validate HEVC active reference counts - media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely - media: vb2: use ssize_t for vb2_read/vb2_write - media: vidtv: fix reference leak on failed device registration - media: vimc: fix reference leak on failed device registration - media: vivid: add vivid_update_reduced_fps() - media: vivid: check for vb2_is_busy() when toggling caps - media: vivid: fix cleanup bugs in vivid_init() - media: vpif_capture: fix OF node reference imbalance - ALSA: seq: close a re-opened queue timer in the destructor - ALSA: timer: drain a slave's callback before its master detaches it - ALSA: timer: don't re-enter an instance callback that is still running - wifi: ath6kl: fix OOB access from firmware ADDBA window size - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper - wifi: wilc1000: validate assoc response length before subtracting header - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses - wifi: brcmfmac: make release_scratchbuffers idempotent - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() - staging: rtl8723bs: fix inverted HT40 secondary channel offset - Bluetooth: hci_sync: Protect UUID list traversal - Bluetooth: RFCOMM: Fix session UAF in set_termios - exec: fix unsigned loop counter wrap in transfer_args_to_stack() - binfmt_misc: set have_execfd only once the interpreter is opened - objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL - firmware: stratix10-svc: fix memory leaks and list corruption bugs - [amd64] x86/boot/compressed: Disable jump tables - [amd64] comedi: comedi_parport: deal with premature interrupt - uio_hv_generic: Bind to FCopy device by default - serial: sc16is7xx: implement gpio get_direction() callback - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Closes: #1143721) - mei: bus: access mei_device under device_lock on cleanup - [amd64] intel_th: fix MSC output device reference leak - misc: nsm: only unlock nsm_dev on post-lock error paths - misc: nsm: pin the module while the device is open - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev - tracing: Fix resource leak on mmiotrace trace_pipe close - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() - tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() - [arm64] syscall: Ensure saved x0 is kept in-sync with tracer updates - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" - mptcp: decrement subflows counter on failed passive join - mptcp: only set DATA_FIN when a mapping is present - sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564) - sctp: avoid auth_enable sysctl UAF during netns teardown - sctp: close UDP tunnel sockets during netns teardown - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() - ceph: fix refcount leak in ceph_readdir() - libceph: bound get_version reply decode to front len - libceph: Fix multiplication overflow in decode_new_up_state_weight() - libceph: guard missing CRUSH type name lookup - libceph: refresh auth->authorizer_buf{,_len} after authorizer update - libceph: Reject monmaps advertising zero monitors - libceph: reject zero bucket types in crush_decode - libceph: remove debugfs files before client teardown - amt: fix use-after-free in AMT delayed works - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP - binfmt_elf_fdpic: only honour the first PT_INTERP - fs: preserve ACL_DONT_CACHE state in forget_cached_acl() - fscrypt: Add missing superblock check in find_or_insert_direct_key() - ftrace: Add global mutex to serialize trace_parser access - iomap: fix out-of-bounds bitmap_set() with zero-length range - [amd64] iommu/vt-d: Disallow SVA if page walk is not coherent - phonet: pep: fix use-after-free in pep_get_sb() - vxlan: require CAP_NET_ADMIN in the device netns for changelink - net: slip: serialize receive against buffer reallocation - geneve: require CAP_NET_ADMIN in the device netns for changelink - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() - net/iucv: fix use-after-free of a severed iucv_path - net/mlx5e: Use sender devcom for MPV master-up - net/x25: fix use-after-free in x25_kill_by_neigh() - net: gro: fix double aggregation of flush-marked skbs - net: hip04: fix RX buffer leak on build_skb failure - proc: Fix broken error paths for namespace links - ice: fix PTP Call Trace during PTP release - rbd: Reset positive result codes to zero in object map update path - ksmbd: defer destroy_previous_session() until after NTLM authentication - ice: reject out-of-range ptype in ice_parser_profile_init - ice: use READ_ONCE() to access cached PHC time - ila: reload IPv6 header after pskb_may_pull in checksum adjust - mac802154: hold an interface reference across the scan worker - mac802154: llsec: reject frames shorter than the authentication tag - mctp: serial: handle zero-length frames to prevent rx buffer overflow - openvswitch: fix GSO userspace truncation underflow - pppoe: reload header pointer after dev_hard_header() - rtase: Workaround for TX hang caused by hardware packet parsing - tcp: initialize standalone TCP-AO response padding - tipc: clear sock->sk on the failed-insert path in tipc_sk_create() - vsock/virtio: collapse receive queue under memory pressure - vxlan: mdb: Fix source list corruption on a failed replace - drm/amd/pm: fix amdgpu_pm_info power display units - drm/amd/pm: make pp_features read-only when scpm is enabled - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx8: drop unecessary BUG_ON() - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() - drm/amdgpu/vce: fix integer overflow in image size - drm/amdgpu/vcn4: avoid rereading IB param length - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() - drm/amdgpu: fix division by zero with invalid uvd dimensions - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd - drm/amdgpu: fix aperture mapping leak - drm/amd/pm: fix smu13 power limit range calculation - bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (CVE-2026-53078) - net: qrtr: ns: Raise node count limit to 512 - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL - ksmbd: bound DACL dedup walk to copied ACEs - ksmbd: validate ACE size against SID sub-authorities - fscrypt: Avoid dynamic allocation in fscrypt_get_devices() - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources - io_uring/rw: fix missing ERESTARTSYS conversion in read paths - net: pcs: xpcs: fix SGMII state reading - gve: fix Rx queue stall on alloc failure - mm/damon/core: validate ranges in damon_set_regions() - mm/damon/core: disallow overlapping input ranges for damon_set_regions() - iommufd: Reject invalid read count in iommufd_fault_fops_read() - iommufd: Break the loop on failure in iommufd_fault_fops_read() (CVE-2026-64290) - iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (CVE-2026-64280) - i2c: davinci: Unregister cpufreq notifier on probe failure - VFS/audit: introduce kern_path_parent() for audit - audit: widen ino fields to u64 - audit: use 'unsigned int' instead of 'unsigned' - audit: fix recursive locking deadlock in audit_dupe_exe() - i2c: i801: fix hardware state machine corruption in error path (CVE-2026-64205) - ALSA: hda: conexant: Remove mic bias threshold override - ALSA: hda: Fix cached processing coefficient verbs - rxrpc: Pull out certain app callback funcs into an ops table - rxrpc: serialize kernel accept preallocation with socket teardown - xfs: factor out xfs_attr3_leaf_init - xfs: don't replace the wrong part of the cow fork - fbcon: Rename struct fbcon_ops to struct fbcon_par - fbcon: Use correct type for vc_resize() return value - rxrpc: Fix CPU time starvation in I/O thread - rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack - rxrpc: Use irq-disabling spinlocks between app and I/O thread - rxrpc: Fix notification vs call-release vs recvmsg - rxrpc: Fix socket notification race - tipc: restrict socket queue dumps in enqueue tracepoints - vduse: Use fixed 4KB bounce pages for non-4KB page size - vduse: remove unused vaddr parameter of vduse_domain_free_coherent - vduse: take out allocations from vduse_dev_alloc_coherent - VDUSE: avoid leaking information to userspace - octeontx2: Annotate mmio regions as __iomem - octeontx2-vf: clear stale mailbox IRQ state before request_irq() - octeontx2-pf: clear stale mailbox IRQ state before request_irq() - [arm64] dts: qcom: correct RBR opp entry - [arm64] dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable - ASoC: mediatek: mt8192: Check runtime resume during probe - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks - ASoC: mediatek: mt8183: Check runtime resume during probe - netfilter: nf_conntrack_sip: remove net variable shadowing - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it - netfilter: bitwise: rename some boolean operation functions - netfilter: nf_tables: Remove unused nft_reduce_is_readonly() - netfilter: nf_tables: remove register tracking infrastructure - netfilter: nft_fib: reject fib expression on the netdev egress hook - gpu: Move DRM buddy allocator one level up (part two) - gpu/buddy: bail out of try_harder when alignment cannot be honoured - NFSD: pass nfsd_file to nfsd_iter_read() - sunrpc: allocate a separate bvec array for socket sends - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow - remoteproc: xlnx: Check remote core state - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch - mm/sparse-vmemmap: fix vmemmap accounting underflow - landlock: Prepare to use credential instead of domain for fowner - landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages - mtd: maps: vmu-flash: fix fault in unaligned fixup - mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c - mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization - dma: dw-edma: Fix build warning in dw_edma_pcie_probe() - dmaengine: dw-edma: Fix confusing cleanup.h syntax - dmaengine: dw-edma-pcie: Reject devices without driver data - i2c: imx: separate atomic, dma and non-dma use case - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) - xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] - xfrm: nat_keepalive: avoid double free on send error - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect - tcp: Decrement tcp_md5_needed static branch - nvmet: Introduce nvmet_req_transfer_len() - nvmet-auth: reject short AUTH_RECEIVE buffers - ovl: use linked upper dentry in copy-up tmpfile - block: add helper add_disk_final() - block: remove redundant GD_NEED_PART_SCAN in add_disk_final() - dm-integrity: fix leaking uninitialized kernel memory - cleanup: add a scoped version of CLASS() - cleanup: fix scoped_class() - cred: add kernel_cred() helper - cred: add scoped_with_kernel_creds() - dm: avoid leaking the caller's thread keyring via the table device file - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() - net: mana: Validate the packet length reported by the NIC - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink - gve: fix header buffer corruption with header-split and HW-GRO - gpio: mt7621: avoid corruption of shared interrupt trigger state - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() - ipmi: fix refcount leak in i_ipmi_request() - net/mlx5: HWS, Rearrange to prevent forward declaration - net/mlx5: HWS, fix matcher leak on resize target setup failure - octeontx2-pf: fix SQB pointer leak on init failure - ata: libata-core: Reject an invalid concurrent positioning ranges count - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list - net: macb: drop in-flight Tx SKBs on close - net: ipa: fix SMEM state handle leaks in SMP2P init - Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections - Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately - afs: Improve server refcount/active count tracing - afs: Make afs_lookup_cell() take a trace note - afs: Drop the net parameter from afs_unuse_cell() - rxrpc: Allow the app to store private data on peer structs - afs: Use the per-peer app data provided by rxrpc - afs: Fix afs_server ref accounting - afs: Simplify cell record handling - afs: Fix dynamic lookup to fail on cell lookup failure - afs: Fix lack of locking around modifications of net->cells_dyn_ino - USB: gadget: Use str_enable_disable-like helpers - USB: gadget: fsl-udc: fix dev_printk() device - usb: musb: omap2430: clean up probe error handling - usb: musb: omap2430: Do not put borrowed of_node in probe - net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query - gpu: Fix uninitialized buddy for built-in drivers - rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link - rxrpc: Fix locking issues with the peer record hash - wifi: nl80211: fix nl80211_start_radar_detection return value - net: ethernet: Remove accidental duplication in Kconfig file - afs: Set vllist to NULL if addr parsing fails - dpll: fix clock quality level reporting - afs: Fix delayed allocation of a cell's anonymous key - afs: handle CB.InitCallBackState3 requests without a server record - Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK - Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() - afs: Fix uninit var in afs_alloc_anon_key() - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Add sparse annotation for RCU." (context changes) * rhashtable: clear stale iter->p on table restart (CVE-2026-64563) linux-signed-arm64 (6.12.100+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.100-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.97 - smb/server: do not require delete access for non-replacing links - [amd64] iommu/vt-d: Clear Present bit before tearing down context entry (CVE-2026-45944) - tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). - bpf: Support for hardening against JIT spraying (CVE-2026-64508) - [amd64] x86/bugs: Enable IBPB flush on BPF JIT allocation (CVE-2026-64507) - bpf: Restrict JIT predictor flush to cBPF - bpf: Skip redundant IBPB in pack allocator - bpf: Prefer packs that won't trigger an IBPB flush on allocation - bpf: Prefer dirty packs for eBPF allocations - sched/fair: Only update stats for allowed CPUs when looking for dst group - crypto: algif_skcipher - force synchronous processing - [arm64] KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287) - [arm64] KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (CVE-2026-64286) - iommu: Pass old domain to set_dev_pasid op - [amd64] iommu/vt-d: Cleanup intel_context_flush_present() - [amd64] iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry - timekeeping: Register default clocksource before taking tk_core.lock - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534) - nvmet-tcp: Fix potential UAF when ddgst mismatch (CVE-2026-64535) - vsock/virtio: fix zerocopy completion for multi-skb sends (CVE-2026-53365) - vsock/virtio: bind uarg before filling zerocopy skb (CVE-2026-63970) - [armhf] crypto: sun4i-ss - Remove insecure and unused rng_alg - [amd64] iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 - [amd64] iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 - [amd64] x86/mm: Fix check/use ordering in switch_mm_irqs_off() - net: dropreason: Gather SOCKET_ drop reasons. - af_unix: Set drop reason in unix_release_sock(). - af_unix: Set drop reason in manage_oob(). - af_unix: Set drop reason in unix_stream_read_skb(). - af_unix/scm: fix whitespace errors - af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg(). - af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). - af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). - af_unix: Drop all SCM attributes for SOCKMAP. (CVE-2026-53005) - crypto: crypto4xx - Remove ahash-related code - crypto: crypto4xx - Remove insecure and unused rng_alg - crypto: hisi-trng - Remove crypto_rng interface - time/jiffies: Register jiffies clocksource before usage - time/jiffies: Change register_refined_jiffies() to void __init - media: uvcvideo: Use hw timestaming if the clock buffer is full - media: uvcvideo: Avoid partial metadata buffers - media: uvcvideo: Fix buffer sequence in frame gaps - media: uvcvideo: Fix dev_sof filtering in hw timestamp - media: uvcvideo: Do not add clock samples with small sof delta - media: uvcvideo: Relax the constrains for interpolating the hw clock - media: uvcvideo: Fix sequence number when no EOF - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties - dt-bindings: power: imx93: Add MIPI PHY power domain - serial: msm: Disable DMA for kernel console UART - serial: max310x: implement gpio_chip::get_direction() - serial: 8250_omap: clear rx_running on zero-length DMA completes - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) - afs: Fix netns teardown to cancel the preallocation charger - afs: fix NULL pointer dereference in afs_get_tree() - afs: Fix further netns teardown to cancel the preallocation charger - fbcon: fix NULL pointer dereference for a console without vc_data - clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() - drm/rockchip: Test for imported buffers with drm_gem_is_imported() - drm/tidss: Drop extra drm_mode_config_reset() call - drm/gpuvm: Do not prepare NULL objects - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() - drm/radeon: fix integer overflow in radeon_align_pitch() - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure - libbpf: Report error when a negative kprobe offset is specified - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro - Documentation: proc: fix section numbering in table of contents - [arm64] dts: rockchip: Fix gmac0 reset pin for NanoPi R5S - [arm64] dts: qcom: sc8180x: Fix phy simple_bus_reg warning - [arm64] dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning - wifi: cfg80211: fix grammar in MLO group key error message - [arm64] tegra: Fix Tegra234 MGBE PTP clock - dt-bindings: pinctrl: nvidia,tegra234: Add missing required block - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() - wifi: rtw89: Correct data type for scan index to avoid infinite loop - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer - kconfig: fix potential NULL pointer dereference in conf_askvalue - soc: xilinx: Shutdown and free rx mailbox channel - wifi: ath9k: fix OOB access from firmware tx status queue ID - [armhf] dts: am335x-sl50: Fix audio bitclock and frame master endpoint - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure - media: cedrus: Fix failure to clean up hardware on probe failure - media: v4l2-common: Add YUV24 format info - memory: tegra: Wire up system sleep PM ops - [amd64] crypto: qat - fix heartbeat error injection - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path - drm/gpuvm: take refcount on DRM device - [arm64] dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc - [arm64] dts: imx8x-colibri: Correct SODIMM PAD settings - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). - [amd64] crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one - crypto: atmel-sha204a - fix blocking and non-blocking rng logic - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (CVE-2026-64544) - dlm: fix add msg handle in send_queue ordered - nilfs2: fix backing_dev_info reference leak - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite - [amd64] iommu/amd: Fix a stale comment about which legacy mode is user visible - [arm64] dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host - clk: scmi: Fix clock rate rounding - [arm64] dts: qcom: kodiak: Fix ICE reg size - [arm64] dts: qcom: sm8450: Fix ICE reg size - [arm64] drm/hisilicon/hibmc: move display contrl config to hibmc_probe() - [arm64] drm/hisilicon/hibmc: use clock to look up the PLL value - evm: terminate and bound the evm_xattrs read buffer - thermal: hwmon: Fix critical temperature attribute removal - clk: scpi: Unregister child clock providers on remove - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() - crypto: ccp - Treat zero-length cert chain as query for blob lengths - spi: hisi-kunpeng: Use dev_err_probe() for host registration failure - net/sched: sch_htb: do not change sch->flags in htb_dump() - net/sched: sch_htb: annotate data-races (I) - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD - IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier - RDMA/hns: Fix arithmetic overflow in calc_hem_config() - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference - RDMA/srpt: fix integer overflow in immediate data length check - [arm64] RDMA/hns: Initialize seqfile before creating file - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() - media: atomisp: gc2235: fix UAF and memory leak - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() - firmware: arm_scmi: Read sensor config as 32-bit value - sysfs: clamp show() return value in sysfs_kf_read() - bitops: use common function parameter names - regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions - net/sched: sch_drr: annotate data-races around cl->deficit - media: rockchip: rga: fix too small buffer size - [arm64] firmware: arm_scmi: Fix OOB in scmi_power_name_get() - [arm64] dts: qcom: sc7180: Add power-domain and iface clk for ice node - [arm64] dts: qcom: kodiak: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8450: Add power-domain and iface clk for ice node - [arm64] dts: qcom: sm8650: Add power-domain and iface clk for ice node - tracing: Bound synthetic-field strings with seq_buf - writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() - device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() - driver core: Use mod_delayed_work to prevent lost deferred probe work - Revert "treewide: Fix probing of devices in DT overlays" - cpufreq: Documentation: fix sampling_down_factor range - cpufreq: conservative: Simplify frequency limit handling - pwm: imx27: Fix variable truncation in .apply() - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed - bus: sunxi-rsb: Always check register address validity - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs - RDMA/rxe: Fix a use-after-free problem in rxe_mmap - IB/mlx4: Fix refcount leak in add_port() error path - [arm64] RDMA/hns: Fix warning in poll cq direct mode - [arm64] RDMA/hns: Fix log flood after cmd_mbox failure - RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup - PM: sleep: Use complete() in device_pm_sleep_init() - jiffies: Define secs_to_jiffies() - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() - driver core: Guard deferred probe timeout extension with delayed_work_pending() - mtd: spi-nor: Drop duplicate Kconfig dependency - ALSA: seq: midi: Serialize output teardown with event_input - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table - pinctrl: cs42l43: Fix polarity on debounce - nvmet-tcp: fix page fragment cache leak in error path - nvme-multipath: fix flex array size in struct nvme_ns_head - workqueue: drop spurious '*' from print_worker_info() fn declaration - ipv6: guard against possible NULL deref in __in6_dev_stats_get() - net/sched: cls_bpf: prevent unbounded recursion in offload rollback - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove - gpu: host1x: Allow entries in BO caches to be freed - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() - gpu: host1x: Fix iommu_map_sgtable() return value check - drm/tegra: Fix iommu_map_sgtable() return value check - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada - libbpf: Harden parse_vma_segs() path parsing - bpftool: Fix typo in struct_ops map FD generation for light skeleton - libbpf: Fix UAF in strset__add_str() - dax/kmem: account for partial discontiguous resource upon removal - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() - ocfs2: don't BUG_ON an invalid journal dinode - ocfs2: kill osb->system_file_mutex lock - crypto: hisilicon/qm - disable error report before flr - crypto: tegra - Fix dma_free_coherent size error - crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm - sched/deadline: Always stop dl-server before changing parameters - sched/deadline: Reject debugfs dl_server writes for offline CPUs - [arm64] drm/msm/dp: fix HPD state status bit shift value - [arm64] drm/msm/dp: Fix the ISR_* enum values - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info - RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe - RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path - media: qcom: venus: drop extra padding in NV12 raw size calculation - media: qcom: venus: relax encoder frame/blur dimension steps on v4 - media: qcom: venus: relax encoder frame/blur step size on v6 - amba: use generic driver_override infrastructure - cdx: use generic driver_override infrastructure - Drivers: hv: vmbus: use generic driver_override infrastructure - rpmsg: use generic driver_override infrastructure - md/raid10: reset read_slot when reusing r10bio for discard - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback - ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble - NFSD: Fix delegation reference leak in nfsd4_revoke_states - HID: wiimote: Fix table layout and whitespace errors - ata: libata: Fix ata_exec_internal() - nvdimm/btt: Handle preemption in BTT lane acquisition - scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" - scsi: pm8001: Fix error code in non_fatal_log_show() - scsi: ufs: Fix wrong value printed in unexpected UPIU response case - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs - mm/fake-numa: fix under-allocation detection in uniform split - ext2: fix ignored return value of generic_write_sync() - sched: restore timer_slack_ns when resetting RT policy on fork - driver core: Use system_percpu_wq instead of system_wq - tick/sched: Fix TOCTOU in nohz idle time fetch - configfs_lookup(): don't leave ->s_dentry dangling on failure - drm/amdgpu: set sub_block_index for mca ras sub-blocks - bpftool: Use libbpf error code for flow dissector query - vhost: fix vhost_get_avail_idx for a non empty ring - [amd64] perf/x86/amd/core: Always use the NMI latency mitigation - [amd64] perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems - [amd64] perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains - xfrm: fix NAT-related field inheritance in SA migration - drm/amdkfd: always resume_all after suspend_all - ocfs2: rebase copied fsdlm LVB pointers in locking_state - ocfs2: fix buffer head management in ocfs2_read_blocks() - ocfs2: reject FITRIM ranges shorter than a cluster - ocfs2/dlm: require a ref for locking_state debugfs open - ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures - netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags - netfilter: synproxy: drop packets if timestamp adjustment fails - netfilter: synproxy: adjust duplicate timestamp options - netfilter: synproxy: fix unaligned memory access in timestamp adjustment - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock - netfilter: conntrack: revert ct extension genid infrastructure - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() - RDMA/irdma: Fix OOB read during CQ MR registration - RDMA/irdma: Initialize iwmr->access during MR registration - [arm64] dts: imx95: Correct PCIe outbound address space configuration - [arm64] dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well - RDMA/siw: Fix endpoint/socket association handling - bpf: Check tail zero of bpf_prog_info - bpf: Update transport_header when encapsulating UDP tunnel in lwt - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication - wifi: wcn36xx: fix OOB read from short trigger BA firmware response - ALSA: seq: Fix partial userptr event expansion - [riscv64] cpu_ops: Change return value type of cpu_is_stopped() to bool - [riscv64] stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe - ALSA: seq: Clear variable event pointer on read - ACPI: IPMI: Fix message kref handling on dead device - cpufreq: Documentation: fix conservative governor freq_step description - thermal: testing: reject missing command arguments - IB/mlx5: Don't take the rereg_mr fallback without a new translation - IB/mlx5: Properly support implicit ODP rereg_mr - spi: ep93xx: fix double-free of zeropage on DMA setup failure - [amd64] ASoC: amd: acp-sdw-sof: Bound DAI link iteration - firmware_loader: Fix recursive lock in device_cache_fw_images() - configfs: fix lockless traversals of ->s_children - watchdog: unregister PM notifier on watchdog unregister - scsi: target: Fix hexadecimal CHAP_I handling - scsi: target: Remove tcm_loop target reset handling - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() - hwspinlock: qcom: avoid uninitialized struct members - sched/fair: Fix cpu_util runnable_avg arithmetic - wifi: mt76: mt7925: clean up DMA on probe failure - wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links - wifi: mt76: mt7925: keep TX BA state in the primary WCID - wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX - wifi: mt76: fix argument to ieee80211_is_first_frag() - wifi: mt76: mt7915: fix potential tx_retries underflow - wifi: mt76: mt7921: fix potential tx_retries underflow - wifi: mt76: mt7925: fix potential tx_retries underflow - wifi: mt76: mt7996: fix potential tx_retries underflow - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() - fbdev: sm501fb: Fix buffer errors in OF binding code - hwmon: (it87) Clamp negative values to zero in set_fan() - btrfs: zoned: don't account data relocation space-info in statfs free space - btrfs: fix deadlock cloning inline extent when using flushoncommit - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified - NFSD: Handle layout stid in nfsd4_drop_revoked_stid() - spi: meson-spifc: fix runtime PM leak on remove - ASoC: codecs: aw88261: fix incorrect masks for boost regs - vduse: hold vduse_lock across IDR lookup in open path - vhost/vdpa: validate virtqueue index in mmap and fault paths - virtio_console: read size from config space during device init - vduse: Requeue failed read to send_list head - vhost/net: complete zerocopy ubufs only once - tools/virtio: check mmap return value in vringh_test - vdpa/octeon_ep: Fix PF->VF mailbox data address calculation - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails - bonding: 3ad: fix mux port state on oper down - ext4: fix kernel BUG in ext4_write_inline_data_end - ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT - of: cpu: add check in __of_find_n_match_cpu_property() - vfio/qat: fix f_pos race in qat_vf_resume_write() - bpf: Tighten cgroup storage cookie checks for prog arrays - ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() - [s390x] process: Fix kernel thread function pointer type - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (CVE-2026-64539) - Bluetooth: hci_core: Fix UAF in hci_unregister_dev() - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path - Bluetooth: hci: validate codec capability element length - Bluetooth: vhci: validate devcoredump state before side effects - fs: efs: remove unneeded debug prints - RDMA/mlx5: Remove DCT restrack tracking - RDMA/mlx5: Remove raw RSS QP restrack tracking - RDMA/mlx5: Fix undefined shift of user RQ WQE size - RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one - ASoC: codecs: hdac_hdmi: Validate written enum value - ASoC: fsl: fsl_audmix: Validate written enum values - ASoC: tegra: tegra210_ahub: Validate written enum value - net: dsa: qca8k: fix led devicename when using external mdio bus - net/sched: cls_flow: Dont expose folded kernel pointers - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). - bridge: cfm: reject invalid CCM interval at configuration time (CVE-2026-64537) - sctp: validate embedded address parameter length - net: pfcp: allocate per-cpu tstats for PFCP netdevs - net/sched: sch_hfsc: Don't make class passive twice - tipc: require net admin for TIPCv2 netlink mutators - tipc: prevent snt_unacked underflow on CONN_ACK - tipc: reject inverted service ranges from peer bindings - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index - crypto: cavium/cpt - fix DMA cleanup using wrong loop index - crypto: rng - Free default RNG on module exit - ALSA: seq: Fix kernel heap address leak in bounce_error_event() - spi: xilinx: use FIFO occupancy register to determine buffer size - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO - power: supply: core: fix supplied_from allocations - handshake: Require admin permission for DONE command - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen - net: mana: initialize gdma queue id to INVALID_QUEUE_ID - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check - net: ethernet: mtk_wed: fix loading WO firmware for MT7986 - bpf: Run generic devmap egress prog on private skb - net/mlx5: Check max_macs devlink param value against max capability - octeontx2-af: npc: Fix size of entry2cntr_map - net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() - net: wwan: t7xx: check skb_clone in control TX - dpll: add reference-sync netlink attribute - dpll: add reference sync get/set - dpll: Allow associating dpll pin with a firmware node - dpll: Add notifier chain for dpll events - dpll: Support dynamic pin index allocation - dpll: Enhance and consolidate reference counting logic - dpll: fix stale iteration in dpll_pin_on_pin_unregister() - dpll: send delete notification before unregister in on-pin rollback - dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() - dpll: guard sync-pair removal on full pin unregister - dpll: balance create/delete notifications in __dpll_pin_(un)register - landlock: Fix unmarked concurrent access to socket family - net: bcmgenet: Use weighted round-robin TX DMA arbitration - kcm: use WRITE_ONCE() when changing lower socket callbacks - netfilter: nf_conncount: callers must hold rcu read lock - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() - cifs: remove all cifs files before kill super - smb/client: always return a value for FS_IOC_GETFLAGS - bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket - udf: fix nls leak on udf_fill_super() failure - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check - [powerpc*] perf: fix preempt count underflow in fsl_emb_pmu_del - [powerpc*] powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down - [powerpc*] kexec: fix double get_cpu() imbalance in kexec_prepare_cpus - KEYS: Use acquire when reading state in keyring search - tipc: fix UAF in tipc_l2_send_msg() - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) - net: airoha: Introduce ndo_select_queue callback - net: airoha: Add sched ETS offload support - net: airoha: Fix always-true condition in PPE1 queue reservation loop - net: ethernet: oa_tc6: Remove FCS size in RX frame - ionic: Fix check in ionic_get_link_ext_stats - ksmbd: fix use-after-free in same_client_has_lease() - mfd: rsmu: Fix page register setup - mfd: cs42l43: Sanity check firmware size - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write - net/9p: fix race condition on rdma->state in trans_rdma.c - eventpoll: expand top-of-file overview / locking doc - eventpoll: rename attach_epitem() to ep_attach_file() - eventpoll: split ep_insert() into alloc + register stages - eventpoll: extract ep_deliver_event() from ep_send_events() - eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers - eventpoll: rename epi->next and txlist for clarity - eventpoll: Fix epoll_wait() report false negative - gpiolib: acpi: Only trigger ActiveBoth interrupts on boot - staging: nvec: fix use-after-free in nvec_rx_completed() - coresight: cti: Fix DT filter signals silently ignored - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore - PCI/ASPM: Don't reconfigure ASPM entering low-power state - PCI: Introduce named defines for PCI ROM - PCI: Check ROM header and data structure addr before accessing - [amd64] x86/platform/olpc: xo15: Drop wakeup source on driver removal - [amd64] platform/x86: xo15-ebook: Fix wakeup source and GPE handling - PCI: loongson: Do not ignore downstream devices on external bridges - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() - PCI: qcom: Set max OPP before DBI access during resume - phy: phy-can-transceiver: Check driver match and driver data against NULL - clk: at91: sam9x7: Fix gmac_gclk clock definition - coresight: Fix source not disabled on idr_alloc_u32 failure - mailbox: mtk-adsp: fix UAF during device teardown - staging: most: video: avoid double free on video register failure - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() - usb: host: max3421: Reject hub port requests for non-existent ports - char: tlclk: fix use-after-free in tlclk_cleanup() - PCI: qcom: Disable ASPM L0s for SA8775P - iio: light: si1133: reset counter to prevent race condition - iio: light: si1133: prevent race condition on timeout - iio: magnetometer: ak8975: fix potential kernel stack memory leak - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() - iio: tcs3472: power down chip on probe failure - clk: at91: keep securam node alive while mapping it - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter - fs/ntfs3: add bounds check to run_get_highest_vcn() - fs/ntfs3: fix mount failure on 64K page-size kernels - drm/amd/display: Add missing kdoc for ALLM parameters - [amd64] thunderbolt: debugfs: Fix margining error counter buffer leak - dmaengine: imx-sdma: Refine spba bus searching in probe - perf: Fix off-by-one stack buffer overflow in kallsyms__parse() - dmaengine: qcom: gpi: set DMA_PRIVATE capability - dmaengine: Fix possible use after free - dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor - clk: qcom: a53: Corrected frequency multiplier for 1152MHz - pNFS/filelayout: fix cheking if a layout is striped - xprtrdma: Avoid 250 ms delay on backlog wakeup - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot - xprtrdma: Post receive buffers after RPC completion - xprtrdma: Use sendctx DMA state for Send signaling - xprtrdma: Decouple req recycling from RPC completion - NFSv4/pnfs: defer return_range callbacks until after inode unlock - nfs: keep PG_UPTODATE clear after read errors in page groups - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write - nfs: use nfsi->rwsem to protect traversal of the file lock list - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro - PCI: meson: Propagate devm_add_action_or_reset() failure - PCI: meson: Add missing remove callback - fs/ntfs3: resize log->one_page_buf when adopting on-disk page size - PCI: rcar-host: Remove unused LIST_HEAD(res) - xprtrdma: Fix ep kref imbalance on ADDR_CHANGE - xprtrdma: Initialize re_id before removal registration - xprtrdma: Check frwr_wp_create() during connect - xprtrdma: Document and assert reply-handler invariants - xprtrdma: Resize reply buffers before reposting receives - xprtrdma: Fix bcall rep leak and unbounded peek - xprtrdma: Sanitize the reply credit grant after parsing - xprtrdma: Repost Receive buffers for malformed replies - xprtrdma: Return sendctx slot after Send preparation failure - tools lib api: Fix missing null termination in filename__read_int/ull() - tools lib api: Fix filename__write_int() writing uninitialized stack data - tools lib api: Fix mount_overload() snprintf truncation and toupper range - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() - PCI: mediatek: Use actual physical address instead of virt_to_phys() - Revert "PCI/MSI: Unmap MSI-X region on error" - security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() - apparmor: check label build before no_new_privs test - apparmor: aa_label_alloc use aa_label_free on alloc failure - apparmor: fix rawdata_f_data implicit flex array - apparmor: grab ns lock and refresh when looking up changehat child profiles - apparmor: fix potential UAF in aa_replace_profiles - apparmor: remove or add symlinks to rawdata according to export_binary - apparmor: aa_getprocattr free procattr leak on format failure - apparmor: put secmark label after secid lookup - workqueue: Add new WQ_PERCPU flag - i3c: master: add WQ_PERCPU to alloc_workqueue users - i3c: master: Make hot-join workqueue freezable to block hot-join during suspend - i3c: master: Prevent reuse of dynamic address on device add failure - apparmor: fix label can not be immediately before a declaration - gpio: mlxbf3: fail probe if gpiochip registration fails - [amd64] drm/i915: clear CRTC color blob pointers after dropping refs - spi: dw: fix wrong BAUDR setting after resume - xfrm: Fix xfrm state cache insertion race - xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] - xfrm: validate selector family and prefixlen during match - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm - drm/amdgpu: initialize irq.lock spinlock earlier - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown - net: psample: fix info leak in PSAMPLE_ATTR_DATA (CVE-2026-64553) - sctp: hold socket lock when dumping endpoints in sctp_diag - PCI: iproc: Restore .map_irq() for the platform bus driver - spi: rpc-if: Use correct device for hardware reinitialization on resume - virtio-net: fix len check in receive_big() (CVE-2026-64552) - dpaa2-switch: fix VLAN upper check not rejecting bridge join - devlink: Fix parent ref leak in devl_rate_node_create() - flow_dissector: check device type before reading ETH_ADDRS - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints - [arm64] hw_breakpoint: reject unaligned watchpoints that would truncate BAS - thermal: intel: Fix dangling resources on thermal_throttle_online() failure - ACPI: resource: Amend kernel-doc style - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() - ieee802154: fix kernel-infoleak in dgram_recvmsg() - mac802154: Prevent overwrite return code in mac802154_perform_association() - md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry - netfilter: ipset: Fix data race between add and dump in all hash types - netfilter: ipset: annotate "pos" for concurrent readers/writers - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() - netfilter: ipset: make sure gc is properly stopped - netfilter: nf_reject: skip iphdr options when looking for icmp header - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() - irqchip/crossbar: Fix parent domain resource leak - net: marvell: prestera: initialize err in prestera_port_sfp_bind - tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (CVE-2026-64543) - net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths - octeontx2-af: mcs: Fix unsupported secy stats read - octeontx2-pf: Clear stats of all resources when freeing resources - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown - net/sched: act_ct: fix nf_connlabels leak on two error paths - ipv6: ndisc: fix NULL deref in accept_untracked_na() (CVE-2026-64542) - dpaa2-switch: do not accept VLAN uppers while bridged - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 - bpf: Fix stack slot index in nospec checks - bpftool: Fix vmlinux BTF leak in cgroup commands - bpf: zero-initialize the fib lookup flow struct - bpf: Fix effective prog array index with BPF_F_PREORDER - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() - drm/edid: fix OOB read in drm_parse_tiled_block() (CVE-2026-64546) - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 - ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() - ice: fix AQ error code comparison in ice_set_pauseparam() - ice: call netif_keep_dst() once when entering switchdev mode - ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info - ice: dpll: fix memory leak in ice_dpll_init_info error paths - i40e: Fix i40e_debug() to use struct i40e_hw argument - rtc: msc313: fix NULL deref in shared IRQ handler at probe - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (CVE-2026-64538) - net: bnxt: use ethtool string helpers - eth: bnxt: gather and report HW-GRO stats - eth: bnxt: rename ring_err_stats -> ring_drv_stats - eth: bnxt: improve the timing of stats - ipv4: fib: Don't ignore error route in local/main tables. - md/raid5: use stripe state snapshot in break_stripe_batch_list() - md/raid5: avoid R5_Overlap races while breaking stripe batches - bpf: Disable xfrm_decode_session hook attachment - netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Closes: #1130336) - netfilter: nft_synproxy: stop bypassing the priv->info snapshot - netfilter: nft_compat: ebtables emulation must reject non-bridge targets - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure - NTB: epf: Make db_valid_mask cover only real doorbell bits - NTB: epf: Report 0-based doorbell vector via ntb_db_event() - NTB: epf: Fix doorbell bitmask and IRQ vector handling - net, bpf: check master for NULL in xdp_master_redirect() (CVE-2026-64545) - net: dsa: sja1105: round up PTP perout pin duration - veth: fix NAPI leak in XDP enable error path - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) - ipv6: fix error handling in disable_ipv6 sysctl - ipv6: fix error handling in ignore_routes_with_linkdown sysctl - ipv6: fix error handling in forwarding sysctl - ipv6: fix error handling in disable_policy sysctl - rtnetlink: Add per-netns RTNL. - rtnetlink: Add assertion helpers for per-netns RTNL. - rtnetlink: Define rtnl_net_trylock(). - ipv6: Add __in6_dev_get_rtnl_net(). - ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL. - ipv6: fix missing notification for ignore_routes_with_linkdown - thermal: testing: zone: Flush work items during cleanup - ACPI: processor_idle: Mark LPI enter functions as __cpuidle - smb/client: preserve errors from smb2_set_sparse() - rtc: ds1307: Fix off-by-one issue with wday for rx8130 - rtc: cmos: unregister HPET IRQ handler on probe failure - net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() - octeontx2-af: Validate NIX maximum LFs correctly - net: mvneta: re-enable percpu interrupt on resume - net: sungem: fix probe error cleanup - net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count - udp_tunnel: remove rtnl_lock dependency - net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync - dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback - [arm64] net: hisilicon: hns3: use ethtool string helpers - [arm64] net: hns3: use string choices helper - [arm64] net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle layer conversion - [arm64] net: hns3: clear hns alarm: comparison of integer expressions of different signedness - [arm64] net: hns3: unify copper port ksettings configuration path - [arm64] net: hns3: refactor MAC autoneg and speed configuration - [arm64] net: hns3: fix permanent link down deadlock after reset - [arm64] net: hns3: differentiate autoneg default values between copper and fiber - tracing: probes: fix typo in a log message - spi: sh-msiof: abort transfers when reset times out - gpio: mvebu: fail probe if gpiochip registration fails - gpio: htc-egpio: use managed gpiochip registration - seg6: validate SRH length before reading fixed fields - qede: fix out-of-bounds check for cqe->len_list[] - net: enetc: check the number of BDs needed for xdp_frame - sctp: fix SCTP_RESET_STREAMS stream list length limit - MIPS: DEC: Ensure RTC platform device deregistration upon failure - ASoC: codecs: lpass-va-macro: add SM6115 compatible - ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 - hwmon: adm1275: Prevent reading uninitialized stack - hwmon: (pmbus) Fix passing events to regulator core - hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (CVE-2026-64540) - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy - net: gianfar: dispose irq mappings on probe failure and device removal - net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF - bridge: stp: Fix a potential use-after-free when deleting a bridge - [arm64] drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() - [arm64] drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() - [arm64] drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced - [arm64] drm/panthor: Interrupt group start/resumption if group_bind_locked() fails - tracing/events: Fix to check the simple_tsk_fn creation - tracing: eprobe: read the complete FILTER_PTR_STRING pointer - irqchip/gic-v3-its: Fix OF node reference leak - irqchip/ts4800: Fix missing chained handler cleanup on remove - virtio_net: disable cb when NAPI is busy-polled - cxgb4: Fix decode strings dump for T6 adapters - net/sched: act_bpf: use rcu_dereference_bh() to read the filter - ksmbd: reject undersized DACLs before parsing ACEs - ksmbd: fix use-after-free of fp->owner.name in durable handle owner check - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe - pinctrl: meson: restore non-sleeping GPIO access - net/sched: hhf: clear heavy-hitter state on reset - fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid - afs: Fix error code in afs_extract_vl_addrs() - afs: Fix double netfs initialisation in afs_root_iget() - afs: use kvfree() to free memory allocated by kvcalloc() - afs: Remove erroneous seq |= 1 in volume lookup loop - afs: Make /afs/. as well as /afs/ mountpoints - afs: Add rootcell checks - afs: Make /afs/@cell and /afs/.@cell symlinks - afs: Fix afs_atcell_get_link() to handle RCU pathwalk - afs: Remove the "autocell" mount option - afs: Change dynroot to create contents on demand - afs: Fix misplaced inc of net->cells_outstanding - afs: Fix callback service message parsers to pass through -EAGAIN - afs: Fix missing NULL pointer check in afs_break_some_callbacks() - afs: Fix vllist leak - afs: Fix the volume AFS_VOLUME_RM_TREE is set on - afs: Fix unchecked-length string display in debug statement - minix: avoid overflow in bitmap block count calculation - ovl: fix comment about locking order - netfs: Fix writeback error handling - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() - drm/xe/hw_engine: Fix double-free of managed BO in error path - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays - netfs: Drop the error arg from netfs_read_subreq_terminated() - cifs: Fix missing credit release on failure in cifs_issue_read() - ata: sata_gemini: unwind clocks on IDE pinctrl errors - ata: libata-scsi: limit simulated SCSI command copy to response length - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() - HID: core: Fix OOB read in hid_get_report for numbered reports - [arm64] mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() - HID: bpf: Fix hid_bpf_get_data() range check - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (CVE-2026-64547) - gue: validate REMCSUM private option length - netfilter: xt_u32: reject invalid shift counts - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop - netfilter: xt_connmark: reject invalid shift parameters - net/mlx5: LAG, MPESW, Fix missing complete() on devcom error - net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation - net/mlx5e: Fix HV VHCA stats agent registration race - net: microchip: vcap: fix races on the shared Super VCAP block - qede: fix off-by-one in BD ring consumption on build_skb failure - net: qualcomm: rmnet: validate MAP frame length before ingress parsing (CVE-2026-64550) - net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket - amt: fix size calculation in amt_get_size() - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control - Bluetooth: MGMT: Fix adv monitor add failure cleanup - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (CVE-2026-64549) - ring-buffer: Fix event length with forced 8-byte alignment - net/tls: Consume empty data records in tls_sw_read_sock() - net: usb: lan78xx: move functions to avoid forward definitions - net: usb: lan78xx: disable VLAN filter in promiscuous mode - [arm64] drm/v3d: Reject invalid indirect BO handle in indirect CSD setup - net/sched: cake: reject overhead values that underflow length - octeontx2-pf: check DMAC extraction support before filtering - [amd64] perf/x86/amd/core: Avoid enabling BRS from the SVM reload path - gpio: mvebu: free generic chips on unbind - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() - ipv6: mcast: Replace locking comments with lockdep annotations. - ipv6: mcast: Fix potential UAF in MLD delayed work - netfilter: nft_lookup: fix catchall element handling with inverted lookups - ipvs: pass parsed transport offset to state handlers - ipvs: use parsed transport offset in TCP state lookup - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors - ipvs: ensure inner headers in ICMP errors are in headroom - [s390x] zcrypt: Remove the empty file - cifs: validate DFS referral string offsets - SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED - SUNRPC: pin upper rpc_clnt across the TLS connect_worker - dm era: fix NULL pointer dereference in metadata_open() - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK - net/mlx5: Fix L3 tunnel entropy refcount leak - octeontx2-af: fix VF bringup affecting PF promiscuous state - drm/xe: remove duplicate include - smb: client: fix overflow in passthrough ioctl bounds check - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get - ASoC: SOF: topology: validate vendor array size before parsing - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() - net: atm: reject out-of-range traffic classes in QoS validation - net: ife: require ETH_HLEN to be pullable in ife_decode() - [arm64] fpsimd: Fix type mismatch in sve_{save,load}_state() - [arm64] dts: qcom: sdm630: describe adsp_mem region properly - [arm64] dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc - [arm64] dts: imx8ulp-evk: Correct Type-C int GPIO flags - [s390x] KVM: s390: pci: Fix GISC refcount leak on AIF enable failure - [arm64] KVM: arm64: vgic: Check the interrupt is still ours before migrating it - [s390x] KVM: s390: pci: Fix handling of AIF enable without AISB - [amd64] KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs - [amd64] KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs - [arm64] KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 - [arm64] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (CVE-2026-64555) - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() - fbdev: sm712: Fix operator precedence in big_swap macro - fbdev: efifb: fix memory leak in efifb_probe() - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() - fbdev: i740fb: fix potential memory leak in i740fb_probe() - fbdev: s3fb: fix potential memory leak in s3_pci_probe() - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() - fbdev: vesafb: fix memory leak in vesafb_probe() - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control - ASoC: mediatek: mt8192: Release reserved memory on cleanup - ASoC: mediatek: mt8183: Release reserved memory on cleanup - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read - netfilter: nfnl_cthelper: apply per-class values when updating policies - netfilter: xt_cluster: reject template conntracks in hash match - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst - netfilter: nft_set_pipapo: don't leak bad clone into future transaction - netfilter: nf_nat_sip: reload possible stale data pointer - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag - netfilter: nf_conncount: fix zone comparison in tuple dedup - netfilter: ecache: fix inverted time_after() check - netfilter: xt_nat: reject unsupported target families - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (CVE-2026-64554) - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy - soc: fsl: qe: panic on ioremap() failure in qe_reset() - selinux: check connect-related permissions on TCP Fast Open - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() - selinux: fix incorrect execmem checks on overlayfs - leds: uleds: Fix potential buffer overread - mfd: sm501: Fix reference leak on failed device registration - [amd64] tools/power/x86/intel-speed-select: Harden daemon pidfile open - [amd64] x86/boot: Validate console=uart8250 baud rate to fix early boot hang - [amd64] x86/boot: Reject too long acpi_rsdp= values - [amd64] perf/x86/amd/lbr: Fix kernel address leakage - cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() - [s390x] perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() - batman-adv: gw: acquire ethernet header only after skb realloc - batman-adv: access unicast_ttvn skb->data only after skb realloc - batman-adv: dat: acquire ARP hw source only after skb realloc - batman-adv: bla: reacquire gw address after skb realloc - batman-adv: dat: ensure accessible eth_hdr proto field - batman-adv: dat: fix tie-break for candidate selection - batman-adv: tt: avoid request storms during pending request - batman-adv: fix VLAN priority offset - batman-adv: frag: free unfragmentable packet - batman-adv: frag: fix primary_if leak on failed linearization - batman-adv: mcast: avoid OOB read of num_dests header - batman-adv: tt: prevent TVLV OOB check overflow - cifs: invalidate cfid on unlink/rename/rmdir - mfd: tps6586x: Fix OF node refcount - HID: playstation: validate num_touch_reports in DualShock 4 reports - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready - Bluetooth: SCO: hold sk properly in sco_conn_ready - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() - nvdimm/btt: Free arenas on btt_init() error paths - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback - sunrpc: wait for in-flight TLS handshake callback when cancel loses race - lockd: Plug nlm_file leak when nlm_do_fopen() fails - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing - remoteproc: qcom: Fix leak when custom dump_segments addition fails - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak - mm/memory_hotplug: fix incorrect altmap passing in error path - mm/damon/core: make charge_addr_from aware of end-address exclusivity - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length - fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off - fs/ntfs3: validate lcns_follow in log_replay conversion (CVE-2026-64533) - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow - fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (CVE-2026-64532) - ntfs3: cap RESTART_TABLE free-chain walker at rt->used - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head - ntfs3: validate split-point offset in indx_insert_into_buffer - ntfs3: fix out-of-bounds read in decompress_lznt - power: supply: charger-manager: fix refcount leak in is_full_charged() - [riscv64] cacheinfo: Fix node reference leak in populate_cache_leaves - mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() - mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error - fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() - fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() - proc: only bump parent nlink when registering directories - mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE - kcov: use WRITE_ONCE() for selftest mode stores - mtd: slram: remove failed entries from the device list - 9p: skip nlink update in cacheless mode to fix WARN_ON - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() - scsi: sas: Skip opt_sectors when DMA reports no real optimization hint - ocfs2: use kzalloc for quota recovery bitmap allocation - mtd: rawnand: pl353: fix probe resource allocation - net/9p: fix infinite loop in p9_client_rpc on fatal signal - mtd: rawnand: fix condition in 'nand_select_target()' - ocfs2: avoid moving extents to occupied clusters - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits - ocfs2: add journal NULL check in ocfs2_checkpoint_inode() - ocfs2: reject dinodes with non-canonical i_mode type - ocfs2: reject dinodes whose i_rdev disagrees with the file type - ocfs2: reject non-inline dinodes with i_size and zero i_clusters - fpga: dfl: add bounds check in dfh_get_param_size() - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path - net: thunderbolt: Fix frags[] overflow by bounding frame_count - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() - [s390x] pkey: Check length in PKEY_VERIFYPROTK ioctl - [s390x] pkey: Check length in pkey_pckmo handler implementation - mtd: spi-nor: swp: Improve locking user experience - mtd: spi-nor: spansion: use die erase for multi-die devices only - mtd: rawnand: Pause continuous reads at block boundaries - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization - taskstats: retain dead thread stats in TGID queries - irqchip/crossbar: Use correct index in crossbar_domain_free() - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() - tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt - dmaengine: tegra: Fix burst size calculation - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK - [amd64] platform/x86: dell-laptop: fix missing cleanups in init error path - [amd64] platform/x86/amd/pmc: Check for intermediate wakeup in function - [amd64] platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops - [amd64] platform/x86/amd/pmc: Add delay_suspend module parameter - [amd64] platform/x86/amd/pmc: Don't log during intermediate wakeups - pkey: Move keytype check from pkey api to handler - smb: client: use kvzalloc() for megabyte buffer in simple fallocate - ksmbd: fix integer overflow in set_file_allocation_info() - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig - hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig - i2c: mediatek: fix WRRD for SoCs without auto_restart option - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() - ice: fix ice_init_link() error return preventing probe - xen/gntdev: fix error handling in ioctl - xfrm: use compat translator only for u64 alignment mismatch - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink - tpm: fix event_size output in tpm1_binary_bios_measurements_show - tpm: Make the TPM character devices non-seekable - time: Fix off-by-one in compat settimeofday() usec validation - spi: uniphier: Fix completion initialization order before devm_request_irq() - sctp: validate STALE_COOKIE cause length before reading staleness (CVE-2026-64551) - NFS: Charge unstable writes by request size, not folio size - nvmet-rdma: handle inline data with a nonzero offset - netdev-genl: report NAPI thread PID in the caller's pid namespace - can: esd_usb: kill anchored URBs before freeing netdevs - can: isotp: use unconditional synchronize_rcu() in isotp_release() - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure - can: bcm: add missing rcu list annotations and operations - bpf,fork: wipe ->bpf_storage before bailouts that access it - bpf: Add missing access_ok call to copy_user_syms - block: fix race in blk_time_get_ns() returning 0 - net: sparx5: unregister blocking notifier on init failure - dm thin metadata: fix superblock refcount leak on snapshot shadow failure - dm thin metadata: fix metadata snapshot consistency on commit failure - dm era: fix out-of-bounds memory access for non-zero start sector - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard - dm-ioctl: fix a possible overflow in list_version_get_info - dm-log: fix a bitset_size overflow on 32bit machines - dm-stats: fix dm_jiffies_to_msec64 - dm-stats: fix merge accounting - dm_early_create: fix freeing used table on dm_resume failure - dm-integrity: fix a bug if the bio is out of limits - dm-integrity: don't increment hash_offset twice - dm-verity: avoid double increment of &use_bh_wq_enabled - dm-verity: fix a possible NULL pointer dereference - dm-verity: increase sprintf buffer size - dm-verity: make error counter atomic - [amd64] accel/ivpu: Reject firmware log with size smaller than header - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() - scsi: sg: Report request-table problems when any status is set - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path - scsi: xen: scsiback: Free unsubmitted command instead of double-putting it - scsi: target: Bound PR-OUT TransportID parsing to the received buffer - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() - scsi: elx: efct: Fix I/O leak on unsupported additional CDB - Input: ims-pcu - fix use-after-free and double-free in disconnect - Input: ims-pcu - only expose sysfs attributes on control interface - Input: ims-pcu - release data interface on disconnect - Input: ims-pcu - validate control endpoint type - Input: ims-pcu - add response length checks - Input: ims-pcu - fix DMA mapping violation in line setup - Input: ims-pcu - fix firmware leak in async update - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing - Input: ims-pcu - fix race condition in reset_device sysfs callback - Input: ims-pcu - fix type confusion in CDC union descriptor parsing - net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete - tracing/user_events: Fix use-after-free in user_event_mm_dup() - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() - cpu: hotplug: Preserve per instance callback errors - cpu: hotplug: Bound hotplug states sysfs output - gpio: tegra: do not call pinctrl for GPIO direction - gpio-f7188x: Add support for NCT6126D version B - gpios: palmas: add .get_direction() op - net: sit: require CAP_NET_ADMIN in the device netns for changelink - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure - net: ixp4xx_hss: fix duplicate HDLC netdev allocation - net/sched: act_ct: preserve tc_skb_cb across defragmentation - net: ena: clean up XDP TX queues when regular TX setup fails - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink - net: ipip: require CAP_NET_ADMIN in the device netns for changelink - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink - octeontx2-af: Free BPID bitmap on setup failure - ieee802154: admin-gate legacy LLSEC dump operations - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation - ieee802154: ca8210: fix cas_ctl leak on spi_async failure - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit - [amd64] platform/x86/amd/pmc: Avoid logging "(null)" for DMI values - net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants - [s390x] Revert support for DCACHE_WORD_ACCESS (CVE-2026-64369) - batman-adv: retrieve ethhdr after potential skb realloc on RX - batman-adv: ensure minimal ethernet header on TX - batman-adv: clean untagged VLAN on netdev registration failure - espintcp: use sk_msg_free_partial to fix partial send - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() - rtc: mpfs: fix counter upload completion condition - hwmon: (w83627hf) remove VID sysfs files on error and remove - hwmon: (w83793) remove vrm sysfs file on probe failure - net: liquidio: fix BAR resource leak on PF number failure - hwmon: (occ) unregister sysfs devices outside occ lock - fsl/fman: Free init resources on KeyGen failure in fman_init() - net: lan743x: Initialize eth_syslock spinlock before use - net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked - net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked - fhandle: reject detached mounts in capable_wrt_mount() - hwmon: (max1619) add missing 'select REGMAP' to Kconfig - tracing/probes: Fix double addition of offset for @+FOFFSET - orangefs: keep the readdir entry size 64-bit in fill_from_part() - ata: pata_pxa: Fix DMA channel leak on probe error - net: wwan: iosm: bound device offsets in the MUX downlink decoder - hwmon: (asus_atk0110) Check package count before accessing element - [riscv64] probes: save original sp in rethook trampoline - mm/compaction: handle free_pages_prepare() properly in compaction_free() - irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure - [s390x] monwriter: Reject buffer reuse with different data length - mac802154: remove interfaces with RCU list deletion - llc: fix SAP refcount leak in llc_ui_autobind() - ipvs: use parsed transport offset in SCTP state lookup - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new - macsec: don't read an unset MAC header in macsec_encrypt() - [arm64] smp: Fix hot-unplug tearing by forcing unregistration - ata: libata-core: Skip HPA resize for locked drives - drbd: reject data replies with an out-of-range payload size - [riscv64] Prevent NULL pointer dereference in machine_kexec_prepare() - tracing/osnoise: Call synchronize_rcu() when unregistering - [s390x] mm: Fix type mismatch in get_align_mask(). - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed - pmdomain: imx: Fix i.MX8MP power notifier - pmdomain: imx: Fix i.MX8MP VC8000E power up sequence - [powerpc*] pseries: fix memory leak on krealloc failure in papr_init - wifi: rt2x00: avoid full teardown before work setup in probe - wifi: mwifiex: fix roaming to different channel in host_mlme mode - wifi: mac80211: fix memory leak in ieee80211_register_hw() - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets - net: openvswitch: reject oversized nested action attrs (CVE-2026-64531) - Bluetooth: btrtl: validate firmware patch bounds - llc: fix SAP refcount leak when creating incoming sockets - macsec: fix promiscuity refcount leak in macsec_dev_open() - memstick: ms_block: reject a card that reports too many blocks - ipvs: fix more places with wrong ipv6 transport offsets - ipvs: reload ip header after head reallocation - reset: sunxi: fix memory region leak on ioremap failure - [powerpc*] spufs: fix out-of-bounds access in spufs_mem_mmap_access() - wifi: mac80211: free ack status frame on TX header build failure - wifi: mwifiex: fix permanently busy scans after multiple roam iterations - mtd: onenand: samsung: report DMA completion timeouts - mtd: mchp23k256: use SPI match data for chip caps - mmc: vub300: defer reset until cmd_mutex is unlocked - mtd: rawnand: fsl_ifc: return errors for failed page reads - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout - mmc: block: fix RPMB device unregister ordering - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method - ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup - ACPI: driver: Check ACPI_COMPANION() against NULL during probe - ACPI: bus: Introduce devm_acpi_install_notify_handler() - ACPI: NFIT: core: Use devm_acpi_install_notify_handler() - ACPI: NFIT: core: Fix possible deadlock and missing notifications - iio: hid-sensor-rotation: Fix stale or zero output when reading raw values - iio: adc: ad7380: select REGMAP - iio: pressure: Remove redundant pm_runtime_mark_last_busy() calls - iio: pressure: mpl115: fix runtime PM leak on read error (CVE-2026-64493) - ALSA: aoa: check snd_ctl_new1() return value - ALSA: hda/cs35l41: Fix firmware load work teardown (CVE-2026-64481) - ALSA: scarlett2: Allow selecting config_set by firmware version - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 - vfio/mlx5: Fix racy bitfields and tighten struct layout (CVE-2026-64472) - PCI: altera: Fix resource leaks on probe failure (CVE-2026-64462) - PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() - PCI: mediatek: Switch to msi_create_parent_irq_domain() - PCI: mediatek: Convert bool to single quirks entry and bitmap - PCI: mediatek: Use generic MACRO for TPVPERL delay - PCI: mediatek: Fix IRQ domain leak when port fails to enable (CVE-2026-64461) - PCI: Use pbus_select_window() during BAR resize - PCI: Prevent resource tree corruption when BAR resize fails - PCI: Free saved list without holding pci_bus_sem - PCI: Fix restoring BARs on BAR resize rollback path - PCI: Move Resizable BAR code to rebar.c - PCI: Skip Resizable BAR restore on read error - staging: rtl8723bs: core: move constants to right side in comparison - staging: rtl8723bs: fix spaces around binary operators - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() - [amd64] crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438) - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (CVE-2026-64434) - gpio: sch: use raw_spinlock_t in the irq startup path (CVE-2026-64428) - io_uring/rw: ensure reissue path is correctly handled for IOPOLL - io_uring/rw: preserve partial result for iopoll - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code - media: nxp: imx8-isi: Fix use-after-free on remove (CVE-2026-64421) - netfilter: ebtables: Use vmalloc_array() to improve code - netfilter: ebtables: zero chainstack array (CVE-2026-64413) - Bluetooth: L2CAP: Fix not tracking outstanding TX ident - Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (CVE-2026-64206) - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO - Bluetooth: separate CIS_LINK and BIS_LINK link types - Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() (CVE-2026-64405) - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() - mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (CVE-2026-64416) - smb: client: Improve unlocking of a mutex in cifs_get_swn_reg() - smb: client: resolve SWN tcon from live registrations (CVE-2026-64401) - ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name - vfs: make LAST_XXX private to fs/namei.c - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create - ksmbd: use opener credentials for FSCTL mutations - ksmbd: centralize ksmbd_conn final release to plug transport leak - ksmbd: track the connection owning a byte-range lock (CVE-2026-64390) - proc: rename proc_setattr to proc_nochmod_setattr - proc: protect ptrace_may_access() with exec_update_lock (FD links) - [amd64] perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box() - HID: add haptics page defines - HID: multitouch: fix out-of-bounds bit access on mt_io_flags (CVE-2026-64364) - seqlock: Introduce scoped_seqlock_read() - seqlock: Change do_task_stat() to use scoped_seqlock_read() - proc: protect ptrace_may_access() with exec_update_lock (part 1) - treewide: Switch/rename to timer_delete[_sync]() - HID: appleir: fix UAF on pending key_up_timer in remove() (CVE-2026-64363) - HID: pidff: Fix missing blank lines after declarations - HID: pidff: Add missing spaces - HID: pidff: Rework pidff_upload_effect - HID: pidff: Use correct effect type in effect update - hfs/hfsplus: prevent getting negative values of offset/length - hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (CVE-2026-64361) - bpf: Convert lpm_trie.c to rqspinlock - bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() - bpf: Consistently use bpf_rcu_lock_held() everywhere - bpf: Allow LPM map access from sleepable BPF programs (CVE-2026-64352) - usb: iowarrior: remove inherent race with minor number - USB: iowarrior: fix use-after-free on disconnect race (CVE-2026-64341) - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() - crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 - crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A - usb: gadget: f_fs: initialize reset_work at allocation time - crypto: atmel-sha204a - fail on hwrng registration error in probe path - usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile - btrfs: concentrate the error handling of submit_one_sector() - btrfs: replace for_each_set_bit() with for_each_set_bitmap() - btrfs: remove folio parameter from ordered io related functions - btrfs: remove the COW fixup mechanism - btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC - [amd64] crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown - [amd64] crypto: ccp - Reset TMR size at SNP Shutdown - [amd64] crypto: ccp - Register SNP panic notifier only if SNP is enabled - [amd64] crypto: ccp - Move SEV/SNP Platform initialization to KVM - [amd64] crypto: ccp - Fix a case where SNP_SHUTDOWN is missed - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) - [amd64] crypto: qat - fix restarting state leak on allocation failure - exfat: remove unnecessary read entry in __exfat_rename() - exfat: rename argument name for exfat_move_file and exfat_rename_file - exfat: add exfat_get_dentry_set_by_ei() helper - exfat: move exfat_chain_set() out of __exfat_resolve_path() - exfat: fix incorrect directory checksum after rename to shorter name - exfat: preserve benign secondary entries during rename and move - btrfs: fix false IO failure after falling back to buffered write - btrfs: fix incorrect buffered IO fallback for append direct writes - slab: Introduce kmalloc_obj() and family - slab: Introduce kmalloc_flex() and family - add default_gfp() helper macro and use it in the new *alloc_obj() helpers - default_gfp(): avoid using the "newfangled" __VA_OPT__ trick - slab: recognize @GFP parameter as optional in kernel-doc - fscrypt: Fix key setup in edge case with multiple data unit sizes - fscrypt: Replace mk_users keyring with simple list - mm/damon/core: always put unsuccessfully committed target pids - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers - [arm64] KVM: arm64: Ensure level is always initialized when relaxing perms - [arm64] KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (CVE-2026-64192) - [amd64] perf/x86/amd/brs: Fix kernel address leakage - dibs: loopback: validate offset and size in move_data() - seqlock: fix scoped_seqlock_read kernel-doc - ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd - rtnetlink: Make per-netns RTNL dereference helpers to macro. - net: airoha: Fix channel configuration for ETS Qdisc - jiffies: Cast to unsigned long in secs_to_jiffies() conversion - afs: Fix afs_atcell_get_link() to check if ws_cell is unset first - afs: Fix afs_dynroot_readdir() to not use the RCU read lock - [amd64] crypto: ccp - Fix __sev_snp_shutdown_locked - [amd64] crypto: ccp - Fix dereferencing uninitialized error pointer - [amd64] crypto: ccp - Fix SNP panic notifier unregistration - udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() - Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state - Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle - [amd64] crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() - i40e: drop udp_tunnel_get_rx_info() call from i40e_open() - ice: drop udp_tunnel_get_rx_info() call from ndo_open() - [amd64] crypto: ccp - Fix leaking the same page twice - Bluetooth: L2CAP: Fix regressions caused by reusing ident - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev - Bluetooth: L2CAP: fix tx ident leak for commands without a response - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() - tools/testing: add linux/args.h header and fix radix, VMA tests https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.98 - ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.99 - mm: refactor mm_access() to not return NULL https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.100 - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (CVE-2026-64560) linux-signed-arm64 (6.12.96+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.96-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.96 - [arm64] bpf, arm64: Reject out-of-range B.cond targets - nfsd: fix file change detection in CB_GETATTR - nfsd: release layout stid on setlease failure - userfaultfd: gate must_wait writability check on pte_present() - perf: Fix dangling cgroup pointer in cpuctx backport - bcachefs: avoid truncating fiemap extent length - drm/amd: Fix set but not used warnings - gpio: rockchip: change the GPIO version judgment logic - gpio: rockchip: teardown bugs and resource leaks - gpio: rockchip: fix generic IRQ chip leak on remove (CVE-2026-53226) - mm/vmalloc: take vmap_purge_lock in shrinker (CVE-2026-46093) - device property: initialize the remaining fields of fwnode_handle in fwnode_init() - f2fs: validate orphan inode entry count - f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes - f2fs: fix potential deadlock in f2fs_balance_fs() - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() - f2fs: fix listxattr handling of corrupted xattr entries - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() - nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations - nfs_common: rename functions that invalidate LOCALIO nfs_clients - NFSv4/flexfiles: Remove cred local variable dependency - NFSv4/flexfiles: Add data structure support for striped layouts - NFSv4/flexfiles: reject zero filehandle version count - locking/rtmutex: Make sure we wake anything on the wake_q when we release the lock->wait_lock - apparmor: advertise the tcp fast open fix is applied - nfsd: move name lookup out of nfsd4_list_rec_dir() - nfsd: change nfs4_client_to_reclaim() to allocate data - bonding: fix xfrm offload feature setup on active-backup mode - block: add a store_limit operations for sysfs entries - block: fix queue freeze vs limits lock order in sysfs store methods (CVE-2025-21807) - mm/khugepaged: write all dirty file folios when collapsing - perf trace beauty fcntl: Fix build with older kernel headers - ACPI: CPPC: Suppress UBSAN warning caused by field misuse - ACPI: NFIT: core: Fix possible NULL pointer dereference - [amd64] platform/x86: intel-hid: Protect ACPI notify handler against recursion - perf/core: Detach event groups during remove_on_exec - [amd64] drm/i915: ensure segment offset never exceeds allowed max - usb: gadget: function: rndis: add length check to response query - usb: gadget: function: rndis: add length check for header - iio: accel: bmc150: clamp the device-reported FIFO frame count - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error - iio: adc: lpc32xx: Initialize completion before requesting IRQ - iio: adc: spear: Initialize completion before requesting IRQ - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable - iio: adc: ti-ads124s08: Return reset GPIO lookup errors - iio: backend: fix uninitialized data in debugfs - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug - iio: common: st_sensors: honour channel endianness in read_axis_data - iio: event: Fix event FIFO reset race - iio: gyro: bmg160: bail out when bandwidth/filter is not in table - iio: gyro: bmg160: wait full startup time after mode change at probe - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ - iio: imu: inv_icm42600: fix timestamp clock period by using lower value - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading - iio: imu: st_lsm6dsx: deselect shub page before reading whoami - iio: light: al3010: fix incorrect scale for the highest gain range - iio: light: gp2ap002: fix runtime PM leak on read error - iio: light: opt3001: fix missing state reset on timeout - iio: light: tsl2591: return actual error from probe IRQ failure - iio: light: veml6030: fix channel type when pushing events - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call - iio: resolver: ad2s1210: notify trigger and clear state on fault read error - iio: temperature: Build mlx90635 with CONFIG_MLX90635 - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start - ALSA: virtio: Add missing 384 kHz PCM rate mapping - ALSA: virtio: Validate control metadata from the device - ALSA: ymfpci: check snd_ctl_new1() return value - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser - ALSA: cmipci: check snd_ctl_new1() return value - ALSA: es1938: check snd_ctl_new1() return value - ALSA: firewire: isight: bound the sample count to the packet payload - ALSA: gus: check snd_ctl_new1() return value - ALSA: ice1712: check snd_ctl_new1() return value - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() - ALSA: usb-audio: avoid kobject path lookup in DualSense match - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks - ALSA: usb-audio: Roll back quirk control caches on write errors - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes - vfio/pci: Use a private flag to prevent power state change with VFs - vfio/pci: Latch disable_idle_d3 per device - vfio/pci: Release the VGA arbiter client on register_device() failure - vfio/pci: Fix racy bitfields and tighten struct layout - vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc - vfio: Remove device debugfs before releasing devres - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB - Bluetooth: btusb: fix use-after-free on registration failure - Bluetooth: btusb: fix use-after-free on marvell probe failure - Bluetooth: btusb: fix wakeup source leak on probe failure - [arm*] binder: fix UAF in binder_thread_release() - [arm*] binder: fix UAF in binder_free_transaction() - usb: xhci: Fix sleep in atomic context in xhci_free_streams() - usb: typec: tcpci_rt1711h: unregister TCPCI port with devres - PCI: host-common: Request bus reassignment when not probe-only - [arm*] PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling - mm/damon/ops-common: handle extreme intervals in damon_hot_score() - netfilter: ipset: fix race between dump and ip_set_list resize - virtio_pci: fix vq info pointer lookup via wrong index - virtio-mmio: fix device release warning on module unload - hwrng: virtio: clamp device-reported used.len at copy_data() - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() - usb: dwc3: run gadget disconnect from sleepable suspend context - 6lowpan: fix NHC entry use-after-free on error path - tipc: fix out-of-bounds read in broadcast Gap ACK blocks - staging: vme_user: bound slave read/write to the kern_buf size - smb: client: restrict implied bcc[0] exemption to responses without data area - staging: vme_user: fix location monitor leak in fake bridge - staging: vme_user: fix location monitor leak in tsi148 bridge - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe - staging: media: atomisp: reduce load_primary_binaries() stack usage - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop - staging: rtl8723bs: fix OOB write in HT_caps_handler() - crypto: amlogic - avoid double cleanup in meson_crypto_probe() - ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL - net: af_key: initialize alg_key_len for IPComp states - audit: Fix data races of skb_queue_len() readers on audit_queue - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete - coresight: etb10: restore atomic_t for shared reading state - debugobjects: Plug race against a concurrent OOM disable - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns - NTB: epf: Avoid calling pci_irq_vector() from hardirq context - gpio: eic-sprd: use raw_spinlock_t in the irq startup path - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item - netpoll: fix a use-after-free on shutdown path - ipv4: igmp: remove multicast group from hash table on device destruction - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes - mfd: cros_ec: Delay dev_set_drvdata() until probe success - mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() - mm: shrinker: fix shrinker_info teardown race with expansion - mm: shrinker: fix NULL pointer dereference in debugfs - mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup - netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump - netfilter: handle unreadable frags - netfilter: ebtables: module names must be null-terminated - netfilter: ebtables: terminate table name before find_table_lock() - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() - Bluetooth: bnep: pin L2CAP connection during netdev registration - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() - Bluetooth: fix UAF in bt_accept_dequeue() - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() - Bluetooth: L2CAP: validate option length before reading conf opt value - fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr - fs/ntfs3: fsync files by syncing parent inodes - fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio() - fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() (CVE-2026-53027) - coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() - smb/client: Fix error code in smb2_aead_req_alloc() - ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE - ksmbd: add a permission check for FSCTL_SET_ZERO_DATA - ksmbd: serialize QUERY_DIRECTORY requests per file - ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation - ksmbd: require source read access for duplicate extents - ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY - ksmbd: run set info with opener credentials - ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION - ksmbd: add per-handle permission check to FILE_LINK_INFORMATION - ksmbd: use opener credentials for delete-on-close - ksmbd: use opener credentials for ADS I/O - smb: client: fix query directory replay double-free - smb: client: fix query_info() replay double-free - smb: client: fix double-free in SMB2_ioctl() replay - smb: client: fix change notify replay double-free - smb: client: fix double-free in SMB2_flush() replay - smb: client: fix double-free in SMB2_open() replay - smb: client: fix double-free in SMB2_close() replay - smb: client: Fix next buffer leak in receive_encrypted_standard() - smb: client: use unaligned reads in parse_posix_ctxt() - smb: client: harden POSIX SID length parsing - smb: client: fix atime clamp check in read completion - smb: client: mask server-provided mode to 07777 in modefromsid - writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() - cpufreq: qcom-cpufreq-hw: Fix possible double free - firmware_loader: fix device reference leak in firmware_upload_register() - [amd64] cpufreq: intel_pstate: Sync policy->cur during CPU offline - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT - cpufreq: Fix hotplug-suspend race during reboot - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path - clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances - X.509: Fix validation of ASN.1 certificate header - mm/slab: do not limit zeroing to orig_size when only red zoning is enabled - tools/mm/slabinfo: Fix trace disable logic inversion - tools/mm/slabinfo: fix total_objects attribute name - HID: hid-goodix-spi: validate report size to prevent stack buffer overflow - HID: wacom: stop hardware after post-start probe failures - HID: letsketch: fix UAF on inrange_timer at driver unbind - HID: lg-g15: cancel pending work on remove to fix a use-after-free - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers - media: mtk-jpeg: cancel workqueue on release for supported platforms only - serial: 8250_mid: Disable DMA for selected platforms - xfs: use null daddr for unset first bad log block - xfs: release dquot buffer after dqflush failure - xfs: fix unreachable BIGTIME check in dquot flush validation - xfs: fix pointer arithmetic error on 32-bit systems - xfs: fix exchmaps reservation limit check - bpf: Reject fragmented frames in devmap - bpf: Restore sysctl new-value from 1 to 0 - bpf: Validate BTF repeated field counts before expansion - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() - usb: cdc_acm: Add quirk for Uniden BC125AT scanner - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() - usb: free iso schedules on failed submit - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler - usb: gadget: udc: Fix use-after-free in gadget_match_driver - usb: gadget: f_printer: take kref only for successful open - USB: idmouse: fix use-after-free on disconnect race - USB: ldusb: fix use-after-free on disconnect race - USB: iowarrior: fix use-after-free on disconnect - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD - USB: legousbtower: fix use-after-free on disconnect race - usb: sl811-hcd: disable controller wakeup on remove - USB: storage: include US_FL_NO_SAME in quirks mask - USB: misc: uss720: unregister parport on probe failure - usb: mtu3: unmap request DMA on queue failure - USB: serial: keyspan_pda: fix information leak - USB: serial: option: add Telit Cinterion FE990D50 compositions - USB: serial: digi_acceleport: fix broken rx after throttle - USB: serial: digi_acceleport: fix hard lockup on disconnect - USB: serial: digi_acceleport: fix write buffer corruption - USB: ulpi: fix memory leak on registration failure - USB: usb-storage: ene_ub6250: restore media-ready check - usbip: tools: support SuperSpeedPlus devices - usbip: vudc: fix NULL deref in vep_dequeue() - usb: typec: anx7411: use devm_pm_runtime_enable() - usb: typec: class: drop PD lookup reference - usb: typec: tcpm: Fix VDM type for Enter Mode commands - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() - usb: typec: ucsi: Invert DisplayPort role assignment - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove - usb: typec: ucsi: cancel pending work on system suspend - usb: gadget: f_fs: Fix DMA fence leak - block: skip sync_blockdev() on surprise removal in bdev_mark_dead() - [amd64] x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled - PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining - udf: validate free block extents against the partition length - udf: validate VAT header length against the VAT inode size - udf: validate sparing table length as an entry count, not a byte count - hwrng: jh7110 - fix refcount leak in starfive_trng_read() - nvme: target: rdma: fix ndev refcount leak on queue connect - dm-ioctl: report an error if a device has no table - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page - nvmet-auth: validate reply message payload bounds against transfer length - btrfs: do not trim a device which is not writeable - partitions: aix: bound the pp_count scan to the ppe array - isofs: bound Rock Ridge symlink components to the SL record - crypto: af_alg - Remove zero-copy support from skcipher and aead - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps again - crypto: ecc - Fix carry overflow in vli multiplication - crypto: pcrypt - restore callback for non-parallel fallback - [amd64] crypto: ccp - Do not initialize SNP for SEV ioctls - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) - crypto: drbg - Fix returning success on failure in CTR_DRBG - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels - crypto: drbg - Fix the fips_enabled priority boost - [amd64] crypto: qat - keep VFs enabled during reset - [amd64] crypto: qat - notify fatal error before AER reset preparation - [amd64] crypto: qat - protect service table iterations with service_lock - [amd64] crypto: qat - validate RSA CRT component lengths - [arm64] fpsimd: Fix type mismatch in sme_{save,load}_state() - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path - EDAC/i10nm: Don't fail probing if ADXL is missing - watchdog: apple: Add "apple,t8103-wdt" compatible - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() - i2c: core: fix hang on adapter registration failure - tracing: Prevent out-of-bounds read in glob matching - audit: fix potential integer overflow in audit_log_n_hex() - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC - module: decompress: check return value of module_extend_max_pages() - exfat: bound uniname advance in exfat_find_dir_entry() - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() - riscv: mm: Unconditionally sfence.vma for spurious fault - mm: fix mmap errno value when MAP_DROPPABLE is not supported - mm: do file ownership checks with the proper mount idmap - [amd64] iommu/amd: Don't split flush for amd_iommu_domain_flush_all() - iommufd: Set upper bounds on cache invalidation entry_num and entry_len - [amd64] KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs - [amd64] KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits - [amd64] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode - udmabuf: fix DMA direction mismatch in release_udmabuf() - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning - i2c: core: fix irq domain leak on adapter registration failure - i2c: core: fix NULL-deref on adapter registration failure - i2c: core: fix adapter probe deferral loop - i2c: core: fix adapter debugfs creation - i2c: core: fix adapter deregistration race - i2c: mpc: Fix timeout calculations - i2c: stm32f7: truncate clock period instead of rounding it - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count - Input: elan_i2c - prevent division by zero and arithmetic underflow - Input: goodix - clamp the device-reported contact count - Input: iforce - bound the device-reported force-feedback effect index - Input: mms114 - fix touch indexing for MMS134S and MMS136 - Input: touchwin - reset the packet index on every complete packet - Input: mms114 - reject an oversized device packet size - Input: maplemouse - fix NULL pointer dereference in open() - Input: mms114 - fix multi-touch slot corruption - Input: maple_keyb - set driver data before registering input device - Input: maplemouse - set driver data before registering input device - Input: maplecontrol - set driver data before registering input device - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg - RDMA/siw: bound Read Response placement to the RREAD length - fuse: fix device node leak in cuse_process_init_reply() - fuse: re-lock request before returning from fuse_ref_folio() - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req - usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks - smb: client: reject overlapping data areas in SMB2 responses - xfs: fix null pointer dereference in tracepoint - xfs: fail recovery on a committed log item with no regions - xfs: resample the data fork mapping after cycling ILOCK - xfs: don't wrap around quota ids in dqiterate - xfs: set xfarray killable sort correctly - xfs: clamp timestamp nanoseconds correctly - xfs: fully check the parent handle when it points to the rootdir - xfs: don't zap bmbt forks if they are MAXLEVELS tall . [ Han Gao ] * [riscv64] set NR_CPUS to 128 (Closes: #1140651) . [ Salvatore Bonaccorso ] * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." (context changes) linux-signed-arm64 (6.12.95+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.95-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95 - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain - wifi: mt76: mt7921: fix a potential scan no APs - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (CVE-2026-53101) - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167) - gpiolib: Extract gpiochip_choose_fwnode() for wider use - gpiolib: Remove redundant assignment of return variable - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (CVE-2026-31732) - io_uring/net: Avoid msghdr on op_connect/op_bind async data - drm/xe/display: fix oops in suspend/shutdown without display (CVE-2026-53142) - [arm64] drm/v3d: Store the active job inside the queue's state - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139) - eventpoll: use hlist_is_singular_node() in __ep_remove() - eventpoll: split __ep_remove() - eventpoll: kill __ep_remove() - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() - eventpoll: rename ep_remove_safe() back to ep_remove() - eventpoll: move epi_fget() up - eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355) - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216) - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP - debugobjects: Do not fill_pool() if pi_blocked_on - debugobjects: Dont call fill_pool() in early boot hardirq context - RDMA/bnxt_re: zero shared page before exposing to userspace - i2c: stub: Reject I2C block transfers with invalid length - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe() (CVE-2026-53325) - bpf: Reject sleepable kprobe_multi programs at attach time (CVE-2026-43010) - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() - regulator: core: fix locking in regulator_resolve_supply() error path - dlm: prevent NPD when writing a positive value to event_done (CVE-2025-23131) - xfs: remove the expr argument to XFS_TEST_ERROR - xfs: fix error returns in CoW fork repair - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()" - net: bonding: add broadcast_neighbor option for 802.3ad - bonding: add support for per-port LACP actor priority - bonding: print churn state via netlink - bonding: 3ad: implement proper RCU rules for port->aggregator (CVE-2026-52975) - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419) - bonding: fix NULL pointer dereference in actor_port_prio setting - staging: rtl8723bs: fix buffer over-read in rtw_update_protection (CVE-2026-53179) - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (CVE-2026-53341) - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs - hv: utils: handle and propagate errors in kvp_register - locking/mutex: Remove wakeups from under mutex::wait_lock - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued - phonet: Pass ifindex to fill_addr(). - phonet: Pass net and ifindex to phonet_address_notify(). - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157) - rxrpc: Fix the ACK parser to extract the SACK table for parsing (CVE-2026-53151) - fuse: re-lock request before replacing page cache folio - ftrace: Update the mcount_loc check of skipped entries - ftrace: Have ftrace pages output reflect freed pages - ftrace: Do not over-allocate ftrace memory - ftrace: Test mcount_loc addr before calling ftrace_call_addr() - ftrace: Check against is_kernel_text() instead of kaslr_offset() - net: ipv6: Make udp_tunnel6_xmit_skb() void - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070) - iio: light: veml6075: add bounds check to veml6075_it_ms index - iio: adc: ti-ads1298: add bounds check to pga_settings index - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero - ksmbd: reject non-VALID session in compound request branch - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si - virtiofs: fix UAF on submount umount - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support" - [amd64] KVM: SEV: Ignore MMIO requests of length '0' - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ - [amd64] KVM: SEV: Ignore Port I/O requests of length '0' - batman-adv: tp_meter: keep unacked list in ascending ordered - batman-adv: tp_meter: initialize dup_acks explicitly - batman-adv: tp_meter: initialize dec_cwnd explicitly - batman-adv: tp_meter: avoid window underflow - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd - batman-adv: tp_meter: fix fast recovery precondition - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection - batman-adv: tp_meter: add only finished tp_vars to lists - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE - batman-adv: prevent ELP transmission interval underflow - batman-adv: tp_meter: initialize last_recv_time during init - batman-adv: ensure bcast is writable before modifying TTL - batman-adv: fix (m|b)cast csum after decrementing TTL - batman-adv: frag: ensure fragment is writable before modifying TTL - batman-adv: frag: avoid underflow of TTL - batman-adv: v: prevent OGM aggregation on disabled hardif - batman-adv: tp_meter: restrict number of unacked list entries - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE - batman-adv: tp_meter: prevent parallel modifications of last_recv - batman-adv: tp_meter: handle overlapping packets - batman-adv: tt: don't merge change entries with different VIDs - batman-adv: tt: track roam count per VID - batman-adv: dat: prevent false sharing between VLANs - batman-adv: tvlv: enforce 2-byte alignment - batman-adv: tvlv: avoid race of cifsnotfound handler state - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362) - fs: constify file ptr in backing_file accessor helpers - lsm: add backing_file LSM hooks - selinux: fix overlayfs mmap() and mprotect() access checks - inet: add indirect call wrapper for getfrag() calls - ipv4: account for fraggap on the paged allocation path - ntfs3: reject direct userspace writes to reserved $LX* xattrs - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361) - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g - mac802154: llsec: add skb_cow_data() before in-place crypto - net: skmsg: preserve sg.copy across SG transforms - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink - apparmor: mediate the implicit connect of TCP fast open sendmsg - apparmor: fix use-after-free in rawdata dedup loop - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR - fbdev: fix use-after-free in store_modes() - kernel/fork: clear PF_BLOCK_TS in copy_process() - block: invalidate cached plug timestamp after task switch - err.h: use __always_inline on all error pointer helpers - KEYS: fix overflow in keyctl_pkey_params_get_2() - keys: Pin request_key_auth payload in instantiate paths - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer - wifi: ath11k: fix warning when unbinding - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor - wifi: rtw88: increase TX report timeout to fix race condition - wifi: rtw88: usb: fix memory leaks on USB write failures - wifi: iwlwifi: mvm: fix race condition in PTP removal - f2fs: validate compress cache inode only when enabled - f2fs: fix to round down start offset of fallocate for pin file - f2fs: validate ACL entry sizes in f2fs_acl_from_disk() - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() - f2fs: keep atomic write retry from zeroing original data - block: Avoid mounting the bdev pseudo-filesystem in userspace - bpf: use kvfree() for replaced sysctl write buffer - exfat: fix potential use-after-free in exfat_find_dir_entry() - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() - gfs2: fix use-after-free in gfs2_qd_dealloc - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() - hdlc_ppp: sync per-proto timers before freeing hdlc state - blk-cgroup: fix UAF in __blkcg_rstat_flush() - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done - pNFS: Fix use-after-free in pnfs_update_layout() - fpga: region: fix use-after-free in child_regions_with_firmware() - rpmsg: char: Fix use-after-free on probe error path - ocfs2: reject oversized group bitmap descriptors - 9p: avoid putting oldfid in p9_client_walk() error path - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() - [riscv64] mm: Extract helper mark_new_valid_map() - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect() - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var - fbdev: modedb: fix a possible UAF in fb_find_mode() - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode - i2c: core: fix adapter registration race - NFSD: Fix SECINFO_NO_NAME decode error cleanup - nfsd: fix posix_acl leak on SETACL decode failure - nfsd: check get_user() return when reading princhashlen - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race - nfsd: reset write verifier on deferred writeback errors - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr - NFS: Prevent resource leak in nfs_alloc_server() - ksmbd: fix out-of-bounds read in smb_check_perm_dacl() - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails - drivers/base/memory: set mem->altmap after successful device registration - Documentation: ioctl-number: Fix linuxppc-dev mailto link - Documentation: ioctl-number: Extend "Include File" column width - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources - [amd64] crypto: qat - remove unused character device and IOCTLs - net/tcp-ao: fix use-after-free of key in del_async path - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex - net: bonding: update the slave array for broadcast mode - bonding: annotate data-races arcound churn variables - bonding: do not set usable_slaves for broadcast mode . [ Salvatore Bonaccorso ] * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686) * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse." . [ Uwe Kleine-König ] * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly (Closes: #1136179) linux-signed-arm64 (6.12.95+1~bpo12+1) bookworm-backports; urgency=medium . * Sign kernel from linux 6.12.95-1~bpo12+1 . * Rebuild for bookworm-backports llvm-toolchain-22 (1:22.1.8-1~deb13u4) trixie; urgency=medium . * d/rules: - Disable OMP on i386, trixie's llvm-toolchain-19 doesn't have it. - Disable LIBUNWIND on s390x, trixie's llvm-toolchain-19 doesn't have it. - Disable OFFLOAD on ppc64el, it FTBFS. - Fix architecture list generation for libunwind build-dep (which was broken due to matching against llvm-libunwind1 instead of libunwind-19). llvm-toolchain-22 (1:22.1.8-1~deb13u3) trixie; urgency=medium . * d/patches/x86-fix-incorrect-load-combining-causing-oob-reads.patch: Pull in upstream fix for llvm's tendency to miscompile rustc; see https://salsa.debian.org/pkg-llvm-team/llvm-toolchain/-/merge_requests/224 . llvm-toolchain-22 (1:22.1.8-1~deb13u2) trixie; urgency=medium . * Update d/rules to liboffload depend on llvm 19's libomp. . llvm-toolchain-22 (1:22.1.8-1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. * Change build-dep from sid's llvm-spirv-22 to trixie's llvm-spirv-19. * Add s390x to g++-multilib build-dep. * Set SKIP_COMMON_PACKAGES=yes in d/rules to skip building the non-versioned library packages. Set the NEW_LLVM_VERSION to 19 (instead of 23; not what the maintainers intended, but it works). * Regenerate d/control, dropping libc++1, libc++abi1, llvm-libunwind1, and libomp5 binary packages, and also adding build-deps on trixie's libc++1-19, libc++abi1-19, libomp5-19, libunwind-19, and libllvm19. * Add depends for the various -dev packages to those -19 shared lib packages, but also note in package descriptions that dynamic linking is unsupported. It *will* fail, as -22-dev headers include symbols that -19 doesn't have. llvm-toolchain-22 (1:22.1.8-1~deb13u2) trixie; urgency=medium . * Update d/rules to liboffload depend on llvm 19's libomp. . llvm-toolchain-22 (1:22.1.8-1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. * Change build-dep from sid's llvm-spirv-22 to trixie's llvm-spirv-19. * Add s390x to g++-multilib build-dep. * Set SKIP_COMMON_PACKAGES=yes in d/rules to skip building the non-versioned library packages. Set the NEW_LLVM_VERSION to 19 (instead of 23; not what the maintainers intended, but it works). * Regenerate d/control, dropping libc++1, libc++abi1, llvm-libunwind1, and libomp5 binary packages, and also adding build-deps on trixie's libc++1-19, libc++abi1-19, libomp5-19, libunwind-19, and libllvm19. * Add depends for the various -dev packages to those -19 shared lib packages, but also note in package descriptions that dynamic linking is unsupported. It *will* fail, as -22-dev headers include symbols that -19 doesn't have. llvm-toolchain-22 (1:22.1.8-1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. * Change build-dep from sid's llvm-spirv-22 to trixie's llvm-spirv-19. * Add s390x to g++-multilib build-dep. * Set SKIP_COMMON_PACKAGES=yes in d/rules to skip building the non-versioned library packages. Set the NEW_LLVM_VERSION to 19 (instead of 23; not what the maintainers intended, but it works). * Regenerate d/control, dropping libc++1, libc++abi1, llvm-libunwind1, and libomp5 binary packages, and also adding build-deps on trixie's libc++1-19, libc++abi1-19, libomp5-19, libunwind-19, and libllvm19. * Add depends for the various -dev packages to those -19 shared lib packages, but also note in package descriptions that dynamic linking is unsupported. It *will* fail, as -22-dev headers include symbols that -19 doesn't have. llvm-toolchain-22 (1:22.1.8-1~deb12u1) bookworm-security; urgency=medium . * Non-maintainer upload by the LTS Team. * Rebuild for bookworm. * Clean up leftover changelog.dch file. * Build with bookworm's llvm-spirv-14. * Disable omp on i386. * Disable offload on ppc64el, it FTBFS. llvm-toolchain-22 (1:22.1.7-1) unstable; urgency=medium . * experimental New snapshot release * enable PRIF (coarray) support thanks to Alastair McKinstry (Closes: #1136346) llvm-toolchain-22 (1:22.1.6-1) unstable; urgency=medium . [ Matthias Klose ] * Make stonking a known Ubuntu series. * Build OCaml for stonking. . [ Sylvestre Ledru ] * New upstream release llvm-toolchain-22 (1:22.1.5-1) unstable; urgency=medium . * New upstream release * d/rules: Fail the build if debian/control is regenerated, except for apt.llvm.org snapshot builds where the substitutions legitimately differ between snapshots. Modifying debian/control during the build is forbidden by Debian policy and breaks reproducibility. (Closes: #1130335) * d/rules, d/control.in: Replace the post-substitution sed that rewrote the libc++/libomp/libunwind move version cap on apt.llvm.org snapshot builds with a @LIBCXX_MOVE_VERSION@ placeholder substituted in the same loop as the other variables. Removes one more in-build mutation of debian/control. * d/rules: Extend the regenerate-vs-fail check to debian/watch, debian/packages.ocaml and debian/packages.libclc. These three files are also tracked in git, kept by override_dh_auto_clean and rewritten in place by the substitution loop, so they have the same drift risk as debian/control. * d/source-integrity.mk: Move the source-package integrity logic (APT_LLVM_ORG, GENERATED_TRACKED_FILES and the snapshot/verify canned recipes) into a dedicated include file. Keeps debian/rules focused on the build itself. * d/tests.mk: Move the override_dh_auto_test definition (the whole ifeq RUN_TEST block, ARCH_LLVM_TEST_OK and the lcov coverage tail) into a dedicated include file. Pure relocation, no behavioural change. * d/build-wasm-mingw.mk: Move the wasm32/wasm64 + mingw-w64 compiler-rt and libcxx pattern rules, the STAGE_2_WASM_C(XX)FLAGS filters and the stamps/debian-{wasm,mingw}-build aggregators into a dedicated include file. Pure relocation, no behavioural change. * Fix the autopkgtest for Polly. Thanks to Adrian Bunk for the fix (Closes: #1130893) llvm-toolchain-22 (1:22.1.4-1) unstable; urgency=medium . [ Samuel Thibault ] * d/patches/hurd/hurd_orc_pathmax.diff: Update to version that does not need sys::fs::readlink. * patches/fix-readlink-not-in-fs-namespace.diff: Drop . [ Matthias Klose ] * d/rules, d/python3-lldb-X.Y.links.in: Fix location for extension. . [ Sylvestre Ledru ] * New upstream release llvm-toolchain-22 (1:22.1.3-1) unstable; urgency=medium . [ Samuel Thibault ] * d/patches/hurd/hurd_orc_pathmax.diff: Fix GNU/Hurd build. . [ Sylvestre Ledru ] * new upstream release * patches/fix-readlink-not-in-fs-namespace.diff: Fix build issue #190659 llvm-toolchain-22 (1:22.1.2-1) unstable; urgency=medium . * New upstream release llvm-toolchain-22 (1:22.1.1-1) unstable; urgency=medium . [ Matthias Klose ] * d/rules: Only disable Z3 support for Ubuntu when it is in main. * Install a lit binary. Addresses: #1122910. * llvm-tools: Don't install the lit tests. Addresses: #1122909. * d/rules: For Ubuntu, don't include i386 for CLANG_GRPC_ARCHS, not built on i386. * Update libc++1, libc++abi1 and libomp5 symbols files. * d/rules: Stop ignoring failure for dh_shlibdeps call. . [ Sylvestre Ledru ] * New upstream release * Add hello fallback for lld build dependency. For bullseye and jammy s390x backport in particular * Fix autopkgtests for Polly: Update to use LLVM 22's new pass manager syntax (-passes=polly-canonicalize instead of -polly-canonicalize). (Closes: #1130893) * Adjust the path to lit llvm-toolchain-22 (1:22.1.0-2) unstable; urgency=medium . [ Matthias Klose ] * d/rules: Don't use lld for backport build, when not available. * d/rules: Add safety check for enablement of the RVA23 baseline. . [ Sylvestre Ledru ] * lldb: support global config file, thanks to Nobert Lange * Don't fallback to llvm-spirv-(N-1) when llvm-spirv-N isn't available. LLVM 22 bitcode contains new attributes that llvm-spirv-21 can't read, causing libclc build failures on full builds (not -B/binary-arch since libclc is arch=all): "Unknown attribute kind (105) (Producer: 'LLVM22.1.0' Reader: 'LLVM 21.1.8')" Update build-dep to llvm-spirv-22. (Closes: #1128822) llvm-toolchain-22 (1:22.1.0-1) unstable; urgency=medium . * New upstream release llvm-toolchain-22 (1:22.1.0~+rc3-1~exp1) experimental; urgency=medium . [ Matthias Klose ] * d/rules: Fix self-referencing macro. . [ Sylvestre Ledru ] * New rc release * Fix autopkgtest failure with CMake 4. thanks to Adrian Bunk * d/rules: Simplify and clean up: - Remove empty hurd-i386 conditional block - Fix inverted LLVM_LIBC_ENABLE and LTO_ENABLE info message conditions - Consolidate duplicate mips64el architecture handling - Factor out common sparc/sparc64 PARALLEL_LINK_JOBS setting - Consolidate sed commands for CMake export files - Consolidate wasm install commands into a loop - Simplify jquery/underscore symlink replacement - Consolidate Python cleanup commands llvm-toolchain-22 (1:22.1.0~+rc2-1~exp1) experimental; urgency=medium . [ Matthias Klose ] * Enable libunwind on s390x (Michael R. Crusoe). Addresses: #1126263. . [ Sylvestre Ledru ] * New rc release * Dedup the flags declarations * Implement terse option in DEB_BUILD_OPTIONS to reduce build verbosity * Break the build if DEB_BUILD_OPTIONS contains a comma llvm-toolchain-22 (1:22.1.0~+rc1-1~exp1) experimental; urgency=medium . [ Sylvestre Ledru ] * new rc release * grep is interpreting -Bno-symbolic as a context option. * Workaround the replaces/breaks on apt.llvm.org (upstream 167538) * flang: also ignore -fstack-protector-strong (happens on focal) * Rename ign_fail => ignore_if_fail * Fix file location for lintian source override. * mingw-w64 cross compilation is broken on focal, disable it . [ Fabian Grünbichler ] * workaround cmake 4 . [ Matthias Klose ] * d/rules: Mark usage of SLOPPY_BUILD to ease searching in the build log. * Update watch file, use with --force-download to fetch the integration testsuite. * Introduce an OMPD_ARCHS macro and use it. * Add a llvm.noclang build profile (not enabled by default). * Bump llvm-spirv build dependency to 21 again. * Introduce an LLVM_SPIRV_ARCHS macro and use it. * Don't run the omp autopkg test on i386. Closes: #1118644. * d/tests/control.in: Add test dependency on g++-multilib. Closes: #1118643. * d/debian-llvm-testsuite.bats: Skip test. Closes: #1118641. The test "pthread_cancel with libunwind compatibility" is wrong. * d/tests/control.in: Add test dependency on binutils-gold. Closes: #1118646. * Introduce CLANG_GRPC_ARCHS macro and use it. * Also use the grpc bits for clang on i386. * Add the alternate hello b-d for grpc related build dependencies. * Add profile to ocaml build dependencies. * Re(?)-enable omp on i386. * d/control: Only use one build profile per binary package for now. The ORing of build profiles seems to be not working. * Rename build profiles from llvm.* to pkg.llvm.*. * Fix some lintian warnings, override some more. * Clarify the libunwind package descriptions, that it is not compatible with glibc. * Only run the flang autopkg tests where flang is available. * Rename the LIBC_ARCHS macro to LLVM_LIBC_ARCHS, and only run the libllvmlibc autopkg tests where the package is available. * Fix removing *.pyc files and __pycache__ dirs during installation. * Fix some lintian warnings, override some more. * Copy libc++1, libc++abi1 and libomp5 symbols files from 21. * Build and install libflang_rt.runtime. Addresses: #1117534. * Fix liborc install on hurd-amd64. * Also call dh_python for the llvm-X.Y-tools package. * libunwind-X.Y-dev: Stop providing libunwind-dev. As updated in the package description, the unwinder is incompatible with glibc. * d/rules, d/*.{install,links,lintian-overrides}.in: Use a macro LLVM_LIBDIR. * Fix one more libclang1 lintian override. * Fix one more libc++-22-dev-wasm32 lintian override. * Update symbols files from the buildd logs, including i386. * Fix syntax for OR-ed build profiles. * clang-22-tools, llvm-22-tools: Use dh_python3 substvars. * liblldb-22: Move the .so symlink to the liblldb-22-dev package. * d/rules: Remove unnecessary use of the CURDIR macro. * Enable offloading on riscv64 (Aurelian Jarno). * Manually fix the python3 shebangs. dh_python3 can only handle one private directory. Also install lit first in the dh_override_install target, fix it there, and move it to the package from there. * Add build conflicts on llvm-22-runtime and clang-22, or else the wasm build picks up stuff from the installed llvm-22 and fails. * Stop building multilibs on s390x. Closes: #1125254. * Still build-depend on spirv-21. * d/llvm-X.Y-tools.bcep.in: Fix Python 3.14 byte compilation by adding an exception for shtest-encoding.py test file containing non-UTF-8 characters (Igor Luppi). LP: #2138890. * d/rules: Remove some invalid CLC targets. * Allow to build without CLC packages. * d/llvm-libunwind1.symbols: Update for 22. lua-geoip (0.2-3+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Fix FTBFS after the geoip-database downgrade. (Closes: #1142063) lwip (2.2.1+dfsg1-1+deb13u1) trixie; urgency=medium . * Fix CVE-2026-8836: snmpv3: fix handling packets with invalid msgAuthenticationParameters length * A remote attacker can send a crafted msgAuthenticationParameters field to overflow a stack buffer in snmp_parse_inbound_frame(). * Re-enables the bounds check on msgAuthenticationParameters length in snmp_parse_inbound_frame() and clamps the copy length to SNMP_V3_MAX_AUTH_PARAM_LENGTH instead of using the attacker-controlled TLV value length * https://savannah.nongnu.org/bugs/?68194 lxc (1:6.0.4-4+deb13u4) trixie; urgency=medium . * Cherry-pick fix to properly free libcap-allocated memory * Cherry-pick fix for running nested containers using current versions of runc (ie, Docker) (Closes: #1146472) mbedtls (3.6.6-0.1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . mbedtls (3.6.6-0.1) unstable; urgency=medium . * Non-maintainer upload. * New upstream release. - CVE-2026-25834: Signature Algorithm Injection - CVE-2026-25835: PSA random generator cloning - CVE-2026-34872: FFDH: improper input validation - CVE-2026-34873: Client impersonation resuming a TLS 1.3 session - CVE-2026-34874: Null pointer dereference setting a distinguished name - CVE-2026-34875: Buffer overflow in FFDH public key export - CVE-2026-34876: CCM multipart finish tag-length validation bypass (Closes: #1133841, #1132577) mbedtls (3.6.5-0.1) unstable; urgency=medium . * Non-maintainer upload. * New upstream release. - CVE-2025-54764: Side channel in RSA key generation and operations (Closes: #1118750) - CVE-2025-59438: Padding oracle through timing of cipher error reporting (Closes: #1118752) milib (2.2.0+dfsg-1+deb13u1) trixie; urgency=medium . * Patching code to catch IOException (Closes: #1139472) mongo-c-driver (1.30.4-1+deb13u3) trixie; urgency=medium . * Fix CVE-2026-81524: validate db and collection names mrtg (2.17.10-13+deb13u2) trixie; urgency=medium . * debian/patches/110_fix-CVE-2026-72694: created to fix a symlink-following chown of pid file in daemon mode. Thanks to Tobias Oetiker . This patch fixes CVE-2026-72694. (Closes: #1144393) neutron (2:26.0.3-0+deb13u3) trixie-security; urgency=medium . * CVE-2026-55707: subnetpool onboarding cross-project subnet mutation. Applied upstream fix: CVE-2026-55707-stable-2025.1.patch. (Closes: #1143170). * OSSN-0102: sub-resource APIs do not verify parent ownership. Applied upstream patches (Closes: #1142937): - "Fix PF GET/PUT parent floating IP validation". - "Fix cross-project access to router conntrack helpers" node-lodash (4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1) trixie; urgency=high . * Non-maintainer upload by the LTS team. * Add patch to prevent prototype pollution on baseUnset function. (Fixes: CVE-2025-13465) (Closes: #1126265) * Add patch to block prototype pollution in baseUnset via constructor/prototype traversal (array-wrapped path bypass of the CVE-2025-13465 fix). (Fixes: CVE-2026-2950) * Add patch to validate imports keys in _.template, preventing code injection via the Function() sink. (Fixes: CVE-2026-4800) * Add patch to update lodash-cli dependency map so the regenerated lodash.template module requires assignWith/arrayEach; without it the module throws "assignWith is not defined" at runtime (caught by the node-gulp-util autopkgtest). (Related: CVE-2026-4800) nss (2:3.110-1+deb13u4) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * guard against integer overflow in CERT_Hexify (CVE-2026-16389) ntfs-3g (1:2022.10.3-5+deb13u2) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix multiple vulnerabilities (CVE-2026-42616, CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572, CVE-2026-56135, CVE-2026-56136) onionshare (2.6.3-1+deb13u2) trixie; urgency=medium . * Use CVE identifiers. . onionshare (2.6.3-1+deb13u1) trixie; urgency=medium . * Update debian branch in gbp.conf. * Fixes CVE-2026-54707. (Closes: #1139716) Backport upstream patches from 2.6.4: - a090e97193efc91fbeac9dace7793ea568b83cf5 - e4ed559908b55cf41b993ed3d02052911025785b - 1d76494f5d819adc4c69f08f3842d564a425aa89 * Fixes CVE-2026-54706. (Closes: #1139717) Backport upstream patches from 2.6.4: - 48f31cfac077fcc9c04c67c2a6dbf87d956f5eec - 96827bdd0580bd34b921a7b269198f65434178d8 - d0697fa3d05a193138c6052422c313612301d98a opam (2.3.0-1+deb13u2) trixie-security; urgency=medium . * Backport upstream patches (Closes: CVE-2026-57825) opencryptoki (3.23.0+dfsg-0.3+deb13u1) trixie; urgency=medium . * CVE-2026-40253 (Closes: #1136019) * CVE-2026-23893 (Closes: #1126268) openjdk-21 (21.0.12.1+1-1~deb13u1) trixie-security; urgency=medium . * Rebuild for trixie openjdk-21 (21.0.12+8-2) unstable; urgency=medium . [ Vladimir Petko ] * d/t/jtreg-autopkgtest.in: Do not fail tests if ulimit can not be set. * d/t/problems.csv: Add test exclusions. * d/rules: Enable S390x C2 compiler. * d/rules: Collect hotspot error and replay logs after jtreg tests. * d/copyright-generator: Fix license SPDX identifiers. . [ Matthias Klose ] * Build using GCC 16 on development releases. openjdk-21 (21.0.12+8-1) unstable; urgency=medium . * OpenJDK 21.0.12 release, build 8. - CVEs: + CVE-2026-46968 + CVE-2026-46917 + CVE-2026-47010 + CVE-2026-47021 + CVE-2026-47027 + CVE-2026-60147 + CVE-2026-47059 + CVE-2026-47063 + CVE-2026-41254 - Release notes: https://bit.ly/openjdk2112 openjdk-21 (21.0.12+8-1~deb13u1) trixie-security; urgency=medium . * Rebuild for trixie openjdk-21 (21.0.12~7ea-1) unstable; urgency=medium . * OpenJDK 21.0.12 early access, build 7. * d/copyright: Regenerate. * d/p/jdk-8387580.diff: Apply upstream patch to resolve S390x ftbfs (JDK-8387580). * d/t/problems.csv: Drop obsolete versions, add openjdk-28, add new exclusions. openjdk-21 (21.0.12~5ea-1) unstable; urgency=medium . * OpenJDK 21.0.12 early access, build 5. * d/rules: Do not perform copyright validation for old releases. * d/rules: Check DEB_BUILD_PROFILES in addition to DEB_BUILD_OPTIONS to set up with_check variable. Do not check control files if with_check is disabled (Closes: #1137499). * d/control.in: Add myself to uploaders. * Regenerate files. * d/JB-jre-{headless,zero}.overrides.in: Drop exit-in-shared-library override. openjdk-21 (21.0.11+10-1) unstable; urgency=medium . * OpenJDK 21.0.11 release, build 10. - CVEs: + CVE-2026-22016: 8370529: Enhance Path Factories Redux + CVE-2026-34282: 8374557: Enhance TLS connection handling + CVE-2026-22021: 8371830: Enhance certificate chain validation + CVE-2026-22013: 8370615: Improve Kerberos credentialing + CVE-2026-23865: 8379158: Update FreeType to 2.14.2 + CVE-2026-22018: 8370986: Enhance Zip file reading + CVE-2026-22007: 8369575: Enhance crypto algorithm support + CVE-2026-34268: 8371935: Enhance key generation * d/rules: Check generated files only on amd64. This resolves riscv64 ftbfs, as some architectures change with_check flag. * d/t/problems.csv: Fix typo in loong64 excluded tests lists. * Add common GPL and Apache license headers to copyright generator. * d/copyright: Regenerate. openssl (3.5.7-1~deb13u2) trixie-security; urgency=medium . * CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing INITIAL Packet") * CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping") * CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted protectionAlg") * CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate") * CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future Epoch") * CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response Validation") * CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts") * CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory Exhaustion") * CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()") (Closes: #1145172) * CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel Queue") (Closes: #1144615) openssl (3.5.7-1~deb13u1) trixie; urgency=medium . * Import 3.5.7 openvpn-dco-dkms (0.0+git20241121-1+deb13u1) trixie; urgency=medium . * Add debian/gbp.conf for debian/trixie branch * Cherry-Pick upstream patches to fix NULL deref in ovpn_netlink_notify_del_peer (Closes: #1140548) org-roam (2.3.1-1+deb13u1) trixie; urgency=medium . * Team upload. * Resolve undeclared mandatory dependency. Org-roam does not function without emacsql-sqlite.el. In trixie this library is provided by elpa-emacsql-sqlite, and this dependency must be declared (Closes: #1144053). patool (4.0.0-1+deb13u1) trixie; urgency=medium . * Fix CVE-2026-29509: a path traversal vulnerability in the safe_extract() function. d/patches/CVE-2026-29509.patch pcre2 (10.46-1~deb13u2) trixie; urgency=high . * Use upstream backports of security fixes from 10.48 pdns (4.9.17-0+deb13u1) trixie-security; urgency=medium . * New upstream version 4.9.17, fixing security issue CVE-2026-52682 pdns-recursor (5.2.13-0+deb13u1) trixie-security; urgency=medium . * New upstream version 5.2.13, fixing security issue CVE-2026-52682 pdns-recursor (5.2.12-0+deb13u1) trixie-security; urgency=medium . * New upstream version 5.2.12, fixing security issues CVE-2026-52686, CVE-2026-52688. perl (5.40.1-6+deb13u1) trixie; urgency=medium . * [SECURITY] various upstream fixes: + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects. (Closes: #1141639) + CVE-2026-42496: Archive::Tar symlink extraction. (Closes: #1138860) + CVE-2026-42497: Archive::Tar hardlink extraction. (Closes: #1138859) + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read. (Closes: #1140152) + CVE-2026-13221: silently incorrect regular expression matches. (Closes: #1142037) + CVE-2025-15649: header parsing in IO::Uncompress::Unzip. (Closes: #1138863) + CVE-2026-7010: CRLF-validation in HTTP::Tiny. (Closes: #1138858) + CVE-2026-8376: Buffer overflow in Perl_study_chunk. (Closes: #1137345) + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip. (Closes: #1138856) + CVE-2026-48961: crash in zipdetails. (Closes: #1138855) + CVE-2026-48962: code execution in IO-Compress via output globs. (Closes: #1138854) + CVE-2026-57432: out of bound heap reads in pack() and unpack(). (Closes: #1138905) + CVE-2026-57433: signed integer overflow in Storable. (Closes: #1138906) pgextwlist (1.19-1+deb13u1) trixie-security; urgency=medium . * Reject substituting extension schemas or owners matching ["$'\]. . The extwlist.custom_path script mechanism was vulnerable to SQL injection via crafted schema and user names. The same problem was fixed in August 2023 in PostgreSQL (cd5f2a3570), and is now fixed in pgextwlist as well. Substitutions that attempt to insert any of "$'\ are now simply rejected. (We don't try to quote the values as we don't know which quoting context we are in.) . CVE-2023-39417 php-guzzlehttp-psr7 (2.7.1-1+deb13u2) trixie; urgency=medium . * Reject CR/LF in HTTP method, protocol version, and reason phrase (GHSA-vm85-hxw5-5432) [CVE-2026-55766] php8.4 (8.4.24-1~deb13u1) trixie-security; urgency=high . * New upstream version 8.4.24 (Closes: #1143153) + [CVE-2026-17544]: Out-of-bounds write in bccomp() + [CVE-2026-17543]: SQL injection via E'...' backslash breakout + [CVE-2026-7260]: Crash via recursive symlinks php8.4 (8.4.23-1) unstable; urgency=medium . * New upstream version 8.4.23 postfix (3.10.13-0+deb13u1) trixie-security; urgency=medium . * new upstream stable/bugfix/security release From the release announcement by Wietse Wenema at https://www.postfix.org/announcements/postfix-3.11.6.html : . These defects were found by Qualys assisted by Claude Mythos Preview, and by OpenAI Security; more than half date from 20 or more years ago. When I implemented Postfix, I knew that there were going to be mistakes. That is the reason why Postfix has its architecture and safety nets. The number of defects may seem large, but considering that they were found in a code base of over 150 thousand lines, the error rate is still lower than what I designed for. . o Policy bypass: . - Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server resets of MAIL FROM and RCPT TO command state after smtpd_end_of_data_restrictions rejected a message. This resulted in SMTP protocol state desynchronization between the remote SMTP client and the Postfix SMTP server. . - A crafted remote SMTP client could then send RCPT TO and DATA without MAIL FROM, and deliver a second message. Then, smtpd_end_of_data_restrictions skipped check_recipient_access constraints, because a recipient counter was > 1. . - The failure to reset MAIL FROM and RCPT TO state also affected Milter support (added in Postfix 2.3). Here, after a Milter replied with "accept this message" based on the message envelope, and smtpd_end_of_data_restrictions rejected the message, the Postfix SMTP server as before accepted RCPT TO and DATA without MAIL FROM, and smtpd_end_of_data_restrictions as before skipped check_recipient_access constraints for the second message. Under these conditions, the Postfix Milter client remained in the "accept this message" state, skipping Milter policy enforcement for the second message. . o Denial of service: . - Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server command history memory exhaustion with a large number of very small BDAT requests. . - Bug (defect introduced: Postfix 1.1, date: 20021116): address verification cache poisoning. A local user could use the postdrop command to submit an address verification probe with envelope or message content that Postfix rejected later, resulting in a negative address verification cache entry for that address. On systems that enable address verification, the negative address verification cache entry would force the Postfix SMTP server to reject a message that it should accept (denial of service). . o Server crashes and panic()s: . - Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server reset of RCPT TO state, after a BDAT command error. A crafted remote SMTP client could then send a DATA command without MAIL FROM or RCPT TO, and crash a Postfix SMTP daemon process with a null pointer read error. . - Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read crash while parsing a malformed Dovecot AUTH server response. . o Read after free, uninitialized read, under/over read: . - Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free in the PSC_CALL_BACK_NOTIFY() macro. This had no effect on program execution, because myfree() wiped memory, and that memory was not yet reused. . - Read after free (no privilege escalation) in debug logging (defect introduced: Postfix 2.2, date: 20050117). . - Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized memory read in postscreen HaProxy client after remote I/O exception, causing garbage to be logged. . - Latent bug (defect introduced: Postfix 2.7, date: 20090618): uninitialized memory read after dnsblog(8) returns a string that is not an IPv4 address. . - Bug (defect introduced: before Postfix alpha, date 19970424): the DNS client could read up to two bytes past the end of an MX record, before discovering that the record was too short. This behavior was later copied with SRV records, potentially over-reading up to six bytes. . - Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper command under-read or over-read a very short queue filename. No crash, information leak, or privilege escalation. . o Other code hygiene: . - Bug (defect introduced: before Postfix alpha, date: 19971106): 'int' over-shift, in the queue file record-length parser. Postfix programs do not generate such records, but an attacker could cause postdrop to reject input or panic(). . - Bug (defect introduced: Postfix 2.2, date: 20050117): non-transitive comparison of IPv4 addresses. . - Bug (defect introduced: Postfix 1.0, date: 20000928): the fast flush server, used by the SMTP command "ETRN", and by the commands "postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1) equivalents), used the wrong duplicate suppression API, resulting in unnecessary queue scans by the queue manager. . - Queue hygiene: the postdrop command accepted the null record type which the rest of Postfix ignores. postfix (3.10.12-0+deb13u2) trixie-security; urgency=medium . * fix previous changelog entry (remove item which is not relevant for 3.10.x) * re-upload to trixie-security postgresql-17 (17.11-0+deb13u1) trixie-security; urgency=medium . * New upstream version 17.11. . + Restrict logical decoding output plugins to the set specified by a new server parameter `output_plugin_libraries` (Jacob Champion) . Previously, a replication user could select any loadable library for logical decoding, allowing exploits of various sorts. To allow locking this down without breaking setups that worked before, introduce a whitelist of allowed output plugins. . By default, only the output plugins shipped as part of PostgreSQL (`pgoutput` and `test_decoding`) are included in `output_plugin_libraries`. Installations that rely on other output plugins must add them after updating the server, for example . output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder' . Additionally, pg_upgrade --check will fail if the `output_plugin_libraries` parameter on the new cluster does not permit the plugins of logical replication slots on the old cluster, when migrating from versions 17 and later. Make necessary additions to the new cluster's setting before performing pg_upgrade. . The PostgreSQL Project thanks Vladimir Tokarev and Yu Kunpeng for reporting this problem. (CVE-2026-6471) . + Fix contrib/pgcrypto's PGP encryption to detect unsupported ciphers (Daniel Gustafsson) . Previously, if OpenSSL rejected the requested cipher (for example, because it is running in FIPS mode, or the legacy provider hasn't been loaded), pgcrypto failed to notice the failure and simply XOR'd the non-encrypted block with the plaintext, rendering the "encryption" trivially breakable. This will typically occur with deprecated or non-FIPS cipher algorithms (cipher-algo=blowfish/bf, twofish, cast5, or 3des). . By default, pgcrypto will now fail to decrypt any messages that were affected in this way. To allow retrieval of such data, a new option `ignore-cipher-failure` has been added to pgp_pub_decrypt() and pgp_sym_decrypt(). Setting `ignore-cipher-failure=1` will restore their previous behavior, allowing the faulty encryption wrapper to be stripped off: . pgp_sym_decrypt(encrypted_column, any key, 'ignore-cipher-failure=1') . Once the affected messages are identified and stripped of their wrappers, they can then be re-encrypted with a modern algorithm. It is important however that the behavior of OpenSSL be the same as it was when the faulty messages were created: if the set of unsupported algorithms is not the same, this approach will not work. See the documentation for `ignore-cipher-failure`. . The PostgreSQL Project thanks Shishir Sharma for reporting this problem. (CVE-2026-14663) . + Fix psql to skip in-line data following a scripted COPY ... FROM STDIN command, even if the COPY fails before sending `PGRES_COPY_IN` (Tom Lane) . Previously, if a `COPY` command failed at startup (for instance, because the target table doesn't exist) psql would not realize that and would proceed to read the following in-line data as SQL commands. In the best case that's wrong and in the worst case it's a SQL-injection hazard. Teach psql to recognize syntactically-valid COPY ... FROM STDIN commands and to skip data on its own authority if the server doesn't respond with `PGRES_COPY_IN`. . While this fix is unlikely to affect any production SQL scripts, test scripts might intentionally exercise failing COPY ... FROM STDIN commands. Those will need to gain a `\.` data terminator line after each such command. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2026-6464) . + Cross-check the output row type of a portal running EXECUTE or FETCH (Robert Haas) . EXECUTE and FETCH use two portals: an outer one for the statement itself, and an inner one running the query being executed on its behalf. It was previously possible to make the declared row types of the two portals diverge, leading to server memory disclosure and arbitrary code execution. . The PostgreSQL Project thanks Ben Morris (in collaboration with Claude and Anthropic Research) and Peter Geoghegan for reporting this problem. (CVE-2026-16239) . + Fix buffer overrun with long time zone abbreviation in to_char() (Tom Lane) . This can easily crash the server, and exploits leading to arbitrary code execution have been reported. . The PostgreSQL Project thanks Hcamael, Amjad Shahzad, Tan Zhen of AntAISecurityLab, Tomer Fichman, Zheng Yu, Amy Burnett (OpenAI Codex Security), Rick de Jager, Heewon Song, Sylvie Mayer, Aleksander Alekseev, and Hillai Ben Sasson for reporting this problem. (CVE-2026-14669) . + Fix buffer overrun in regexp match/split functions (Masahiko Sawada) . If passed invalidly-encoded data, these functions could write past the end of their conversion buffer. . The PostgreSQL Project thanks Francesco Verardi for reporting this problem. (CVE-2026-14664) . + Harden the ascii() function against invalid input (Michael Paquier) . By supplying invalidly-encoded input, this function could be coaxed to read and return a few bytes of data that it shouldn't. In assert-enabled builds, its assertions could be triggered too. . The PostgreSQL Project thanks Hcamael for reporting this problem. (CVE-2026-18024) . + Fix multirange type handling in pg_restore_attribute_stats() (OpenAI Security Research Team) . pg_restore_attribute_stats() treated multirange types just like their underlying range type. This works correctly for the bounds histogram, but it was wrong for all the other statistics kinds. . The PostgreSQL Project thanks Amy Burnett (OpenAI Codex Security) for reporting this problem. (CVE-2026-16238) . + Make scalarineqsel() check that a constant it expects to be of type tid actually is (Tom Lane) . This expectation will hold for all the built-in operators that use this estimator, but a maliciously-constructed operator could violate it, leading to a crash or server memory disclosure. . The PostgreSQL Project thanks Hcamael for reporting this problem. (CVE-2026-14668) . + Harden tsvector and tsquery code against overly long values (both individual lexemes and total vector/query length) (Tom Lane) . The documented limits were not enforced in all code paths. . The PostgreSQL Project thanks Yuhang Wu, Zhenpeng Lin, Zheng Yu, and Hcamael for reporting these problems. (CVE-2026-14662) . + Fix various places that mistakenly assumed they would not have to deal with more than `FUNC_MAX_ARGS` function arguments (Tom Lane) . Notably, the server's actual limit on the number of arguments to an aggregate function is `FUNC_MAX_ARGS - 1`, but the parser failed to enforce that, creating hazards downstream. . The PostgreSQL Project thanks Zheng Yu, ylwangtju, and Masahiko Sawada for reporting these problems. (CVE-2026-14679) . + Reject calls from SQL to functions that take or return type internal (Tom Lane) . The existing defenses against doing this have been shown to be insufficient, so add more explicit checks. . The PostgreSQL Project thanks Amy Burnett (OpenAI Codex Security) for reporting this problem. (CVE-2026-14680) . + Preserve the ownership of extended statistics objects when they are rebuilt by ALTER TABLE (Masahiko Sawada) . Previously, the role running ALTER TABLE gained ownership of such objects, but that seems inappropriate. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2026-6469) . + When deparsing an EXTRACT() function call, quote the field name if needed (Nathan Bossart) . The parser accepts any string literal as a field name in EXTRACT(), deferring validation to execution. If the call is stored and deparsed (for example during pg_dump), the string body was regurgitated verbatim, allowing SQL injection. . The PostgreSQL Project thanks Ben Morris (in collaboration with Claude and Anthropic Research) for reporting this problem. (CVE-2026-15741) . + Check for `USAGE` privilege on data types in places that formerly failed to check that (Nathan Bossart) . CREATE TYPE AS RANGE did not check, nor did ALTER TABLE OF, nor did commands that create stored expressions. These omissions allowed roles without `USAGE` privilege to nonetheless create objects depending on the type, possibly blocking the type's owner from changing the type later. . The PostgreSQL Project thanks Jingzhou Fu for reporting this problem. (CVE-2026-6470) . + Invalidate role-dependent cached plans after role changes (Ilya Staroverov, Shinya Kato, Nathan Bossart) . Role membership, role attribute, and database ownership changes may impact the expected behavior of row-level security policies, but previously we'd continue to use cached plans that were made according to the old state of affairs. . The PostgreSQL Project thanks Ilya Staroverov and Shinya Kato for reporting this problem. (CVE-2026-14666) . + Reject GSSEncRequest after direct SSL connection (Michael Paquier) . After establishing a TLS-encrypted connection, the server would still accept a request for GSSAPI encryption. If that succeeded, the connection would proceed using TLS encryption, but it would look like a GSS connection to the pg_hba rules. Thus, a pg_hba policy intending to disallow TLS would not be enforced correctly. . The PostgreSQL Project thanks p4p3r for reporting this problem. (CVE-2026-14681) . + Make mock SCRAM authentication secrets more plausible (Nathan Bossart) . If a SCRAM login is attempted against a role that doesn't exist or doesn't have a SCRAM secret, we generate a mock secret and carry out the authentication handshake anyway, to avoid revealing these facts to an attacker. But the mock secret was made with a fixed iteration count, which in itself can be an observable response discrepancy. Use the configuration setting `scram_iterations` instead, to make the mock secret look more like the installation's real secrets. . The PostgreSQL Project thanks Radim Marek for reporting this problem. (CVE-2026-14672) . + Fix out-of-bounds writes in ecpg applications caused by invalid bytea data received from the server (Michael Paquier) . ecpg assumed without checking that any bytea value must begin with `\x`. A broken or malicious server might send a string shorter than 2 bytes, resulting in memory clobber in the application. . The PostgreSQL Project thanks ylwangtju for reporting this problem. (CVE-2026-16241) . + Do not do backquote expansion on the argument of psql's \unrestrict command (Nathan Bossart) . This oversight in the fix for CVE-2025-8714 allows a malicious server to inject shell commands into plain-text dump output that will be run at restore time on the machine running psql, the exact scenario that CVE-2025-8714 intended to prevent. . The PostgreSQL Project thanks Lucas Velgus, Filip Janus, and Daniel Bakker for reporting this problem. (CVE-2026-18408) . + Remove pg_dump's assumption that pg_proc.protrftypes cannot have more than `FUNC_MAX_ARGS` entries (Tom Lane) . Since there could be entries for both input and output arguments, it's feasible for this array's length to exceed `FUNC_MAX_ARGS` (which constrains only input arguments). Even if that were not so, pg_dump cannot assume that the server was built with the same value of `FUNC_MAX_ARGS` that it has. An overrun would lead to a memory clobber inside pg_dump. . The PostgreSQL Project thanks Masahiko Sawada for reporting this problem. (CVE-2026-19385) . + Harden PL/Perl against "tied" Perl arrays and hashes (Tom Lane) . A tied object that doesn't behave like a regular one could lead to memory overwrite, or to constructing a corrupt result array (which would likely cause problems later). . The PostgreSQL Project thanks Hcamael for reporting this problem. (CVE-2026-14670) . + Fix integer overflows in memory-allocation calculations in PL/Perl and PL/Tcl (Heikki Linnakangas) . This is the same type of problem as CVE-2026-6473, just in a different part of the code, and is fixed in the same way. . The PostgreSQL Project thanks the Tulya Project (Team Dhiutsa, Bitecope Technologies Private Ltd) for reporting this problem. (CVE-2026-14677) . + Ensure that contrib/amcheck functions restrict `search_path` before executing index expressions (Noah Misch) . Because amcheck will run such index expressions as the owner of their tables, a caller could potentially hijack `search_path`-dependent functions to run arbitrary code as the table owner. By default this is not a vulnerability because only superusers are allowed to call amcheck functions; but if that privilege was granted out, it created a larger hazard than the documentation suggests. . The PostgreSQL Project thanks Yuelin Wang and Jacob Brazeal for reporting this problem. (CVE-2026-14673) . + Fix integer overflows in contrib/fuzzystrmatch's levenshtein() and levenshtein_less_equal() functions (Nathan Bossart) . Passing large cost values to these functions could cause integer overflows, thereby producing nonsensical results, and even causing out-of-bounds writes in some cases. . The PostgreSQL Project thanks Ben Morris (in collaboration with Claude and Anthropic Research) for reporting this problem. (CVE-2026-15742) . + Fix buffer overrun in contrib/pg_stat_statements (Álvaro Herrera) . Query normalization didn't accurately account for the amount of space the normalized string would require. . The PostgreSQL Project thanks Sajeeb Lohani (with TrendAI Zero Day Initiative) and Yuelin Wang for reporting this problem. (CVE-2026-14676) . + Fix datatype error in contrib/pg_trgm's GiST picksplit function (Heikki Linnakangas) . This mistake resulted in reading past the end of the buffer, typically causing bad split decisions; but a crash could ensue if you're very unlucky. . The PostgreSQL Project thanks Mehmet D. Ince for reporting this problem. (CVE-2026-14678) . + Remove the plan cache in contrib/refint (Ayush Tiwari) . This caching behavior has several serious bugs, notably that check_foreign_key() embeds the new key values in its cascade-UPDATE queries, so a cached plan reuses the originally-needed values rather than the key values that should be used. The simplest solution is to remove it. . The PostgreSQL Project thanks Hcamael for reporting this problem. (CVE-2026-14671) . * Fix psql -c 'truncate/create table; copy from stdin'. proftpd-dfsg (1.3.8.c+dfsg-4+deb13u3) trixie; urgency=medium . * Add patch for CVE-2026-44331 (Closes: #1135840). * Add patch for CVE-2026-53994. * Add patch for CVE-2026-63091. * Add patch for CVE-2026-63090. pyasn1 (0.6.1-1+deb13u3) trixie; urgency=high . * Team upload. * CVE-2026-59886: uncontrolled resource consumption when converting decoded real values. univ.Real convertedts mantissa, base, exponens to a Python float using exact big-integer exponentiation, so a real value only a few bytes long could carry a very large exponent. * CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long-form tag IDs. The BER decoder accumulated tag continuation octets without an upper bound, so a crafted substrate could force construction of an arbitrarily large integer with quadratic CPU cost (Closes: #1142388). * CVE-2026-59885: fix quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID decoding and encoding, which allowed denial of service via a small payload with many arcs. python-ecdsa (0.19.1-1+deb13u1) trixie; urgency=medium . * Team upload. * d/patches: (Closes: #1132164) - CVE-2026-33936: Import upstream patch - Fix-tests-with-new-Python: Import upstream patch (Tests fails with python 3.13) python-httplib2 (0.22.0-1+deb13u1) trixie-security; urgency=medium . * CVE-2026-59939: The httplib2 HTTP client library performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate. This is a classic decompression bomb (zip bomb) attack against the HTTP client. python3.13 (3.13.5-2+deb13u5) trixie; urgency=medium . * CVE-2026-6879 * CVE-2026-0864 (Closes: #1141524) * CVE-2026-4360 (Closes: #1141531) * CVE-2026-11940 (Closes: #1141533) * CVE-2026-11972 (Closes: #1141534) python3.13 (3.13.5-2+deb13u4) trixie; urgency=medium . * Patch: Fix use-after-free in dict.clear() with embedded values. Resolves a regression in 3.13.5-2+deb13u3. (Closes: #1141977) qemu (1:10.0.13+ds-0+deb13u1) trixie; urgency=medium . * new upstream stable/bugfix release, including multiple security fixes: - Update version for 10.0.13 release - target/riscv/tcg: sret in virtual user mode raises virtual instruction exception https://gitlab.com/qemu-project/qemu/-/work_items/3622 - target/riscv: enforce even register constraints for Zdinx fcvt pairs https://gitlab.com/qemu-project/qemu/-/work_items/4109 - target/riscv: reject FMV.X.W/FMV.W.X under Zfinx https://gitlab.com/qemu-project/qemu/-/work_items/4108 - target/riscv: honor zicbo* envcfg gating in linux-user mode https://gitlab.com/qemu-project/qemu/-/work_items/4107 - disas/riscv: Fix typo in th.lbib format - disas/riscv: Fix isa decoding of rev8 - disas/riscv: Fix rv32 encoding of zext.h - target/riscv: allow menvcfg/henvcfg LPE and SSE bits on RV32 https://gitlab.com/qemu-project/qemu/-/work_items/4045 - hw/riscv/riscv-iommu: preserve requested perm in spa_fetch() - hw/riscv/riscv-iommu: fix U-bit check to apply only to leaf S/VS-stage PTEs - disas/riscv: Decode unsigned vector immediates as unsigned - disas/riscv: Use signed type for vector immediates - disas/riscv: Fix 6-bit immediate extraction - disas/riscv: Fix th.srri decoding - target/riscv: use SXL instead of MXL for read_sstatus - target/riscv: Fix PC sync in trans_sspopchk for CFI exception handling https://gitlab.com/qemu-project/qemu/-/work_items/4118 - hw/watchdog: Add lower bound check for watchdogNumber https://gitlab.com/qemu-project/qemu/-/work_items/3600 - tcg: Export tcg_gen_ussub_i{32,64,tl} - tcg: Defer tb_flush when initial thread region alloc fails https://gitlab.com/qemu-project/qemu/-/work_items/2984 - tcg: Return success from tcg_region_alloc - tcg: Return success from tcg_region_alloc__locked - target/loongarch: check FPE before reading fcc in bceqz/bcnez https://gitlab.com/qemu-project/qemu/-/work_items/4209 - meson: make linker warnings non-fatal on Linux - serial: clear transmit retry callback on unrealize https://gitlab.com/qemu-project/qemu/-/work_items/4125 - target/i386: decode opcode extensions group 3 /1 as TEST https://gitlab.com/qemu-project/qemu/-/work_items/3580 - target/i386: allow transition to virtual-8086 mode only if CPL == 0 and CPU is not in long mode https://gitlab.com/qemu-project/qemu/-/work_items/3583 - target/i386: fix long mode segment override prefix decoding https://gitlab.com/qemu-project/qemu/-/work_items/3391 - target/i386: fix incorrect decoding of EXTRQ_i https://gitlab.com/qemu-project/qemu/-/work_items/3611 - target/i386: Clear OF, SF, and AF for fcomi/fucomi https://gitlab.com/qemu-project/qemu/-/work_items/4133 - target/i386: Use correct type for get_float_exception_flags() values - tcg/optimize: Fix s_mask computation for shifts - tcg/optimize: INDEX_op_mul is commutative - hw/elf_ops: defend against weird elf headers - hw/nvme: add SPDM_SOCKET Kconfig dependency - hw/block/pflash_cfi01: Restore ROMD mode after migration https://gitlab.com/qemu-project/qemu/-/work_items/4042 - hw/net/rtl8139: Send whole of vlan-tagged packet when doing loopback - hw/net/rtl8139: Fix handling of VLAN tags on incoming short packets https://gitlab.com/qemu-project/qemu/-/work_items/3518 - tests/qtest/ahci: regression test for ATAPI read vs. drain - hw/ide/atapi: read the whole elementary transfer asynchronously - tests/qtest/ahci: cover raw (2352-byte) ATAPI CD reads - tests/qtest/libqos/ahci: support raw (2352-byte) READ CD - tests/qtest/ide-test: cover raw (2352-byte) ATAPI CD reads - tests/qtest/ide-test: add a multi-sector ATAPI DMA read test - tests/qtest/ide-test: parametrize the ATAPI CD-ROM read test - hw/net/vmxnet3: Do not abort if guest provides bad interrupt numbers https://gitlab.com/qemu-project/qemu/-/work_items/539 - hw/usb/dev-uas: Don't abort if guest provided an undersized buffer for status https://gitlab.com/qemu-project/qemu/-/work_items/3900 - hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq https://gitlab.com/qemu-project/qemu/-/work_items/4114 - migration/multifd: Replace assert() with error_setg() in recv paths - migration/multifd: Validate next_packet_size in zlib/zstd recv https://gitlab.com/qemu-project/qemu/-/work_items/3737 - tests/tcg/s390x: Test STCKF condition code on a faulting store - target/s390x/tcg: Set STCK/STCKF condition code after the store - pc-bios/s390-ccw.img: update s390x bios - pc-bios/s390-ccw: bound zipl menu strlen and replace VLA in zipl_print_entry - pc-bios/s390-ccw: bounds-check zipl menu entry index before array write - pc-bios/s390-ccw: fix out-of-bounds read in iso_get_file_size() - s390x/ipl: validate num_comp against iplb length before iterating - hw/char/sclpconsole-lm: avoid guest triggerable assert - tests/tcg/s390x: Test DR overflow (INT64_MIN / -1) - target/s390x: Fix DR/D INT64_MIN / -1 host crash - tests/tcg/s390x: Test PRNO TRNG interruptibility - target/s390x: Make PRNO TRNG interruptible - target/s390x: Have MSA helper pass a mmu_idx argument - hw/arm/aspeed: Add missing Kconfig dependencies on required components - linux-user: implement mount_setattr(2) - linux-user/sh4: Fix crashes on signal delivery in conditional delay slot - linux-user/sh4: Initialize the FPSCR register on signal - linux-user/sh4: Deliver SIGILL on invalid instruction - gitlab: disable provenance attestations to work around CI bug - hw/nvme: fix leak on copy ranges - hw/nvme: cancel inflight requests on controller reset https://gitlab.com/qemu-project/qemu/-/work_items/3398 https://gitlab.com/qemu-project/qemu/-/work_items/3883 https://gitlab.com/qemu-project/qemu/-/work_items/4068 https://gitlab.com/qemu-project/qemu/-/work_items/4072 - hw/nvme: factor out nvme_sq_cancel_inflight() - hw/nvme: drop AER requests without aiocb in nvme_del_sq() - hw/display/virtio-gpu: Unmap DMA regions on reset https://gitlab.com/qemu-project/qemu/-/work_items/3467 - hw/display/virtio-gpu: Always reject invalid scanout bounds - virtio-gpu: reject requests with short/truncated control headers Closes: CVE-2026-18054 - hw/display/virtio-gpu: fix offset wraparound in scanout_blob_to_fb - vhost-user-gpu: fix integer overflow in buffer allocation Closes: CVE-2026-15264 - hw/display/vga: fix panning_buf OOB after text/graphics switch https://gitlab.com/qemu-project/qemu/-/work_items/4085 Closes: CVE-2026-17516 - hw/display/virtio-gpu: validate blob iov size https://gitlab.com/qemu-project/qemu/-/work_items/3945 Closes: CVE-2026-66021 - coroutine: fix lost wakeup in qemu_co_sleep_wake() - iotests: run the test pool with the 'fork' start method - qcow2: do not try to clear the dirty bit on a read-only node - dmg: reject inconsistent UDRW chunk sector count and length https://gitlab.com/qemu-project/qemu/-/work_items/3846 Closes: CVE-2026-65928 - dmg: refuse to open files with no chunks https://gitlab.com/qemu-project/qemu/-/work_items/4021 - dmg: fix out-of-bounds load in search_chunk() https://gitlab.com/qemu-project/qemu/-/work_items/3844 Closes: CVE-2026-65929 - tests/unit: add reproducer for BlockAcctStats histogram locking race - block/qapi: take stats->lock when reading BlockAcctStats for query-blockstats - block/accounting: take stats->lock in latency histogram setters - block: Fix crash after setting latency historygram with single bin - block/cloop: fix integer overflow in total_sectors calculation - linux-user: fix incorrect msg_l[sr]pid members of target_msqid_ds - linux-user: Fix msqid_ds struct wrt 32-bit big endian architectures - hw/nvme: fix assertion failure on subregion removal - hw/nvme: fix unintentional integer overflow in shift - hw/nvme: fix cross-namespace copy dif buffer overflow - virtio-mmio: fix QUEUE_NUM_MAX https://gitlab.com/qemu-project/qemu/-/work_items/3882 Closes: CVE-2026-50626 - hw/display/exynos4210_fimd: Clamp windows to screen size https://gitlab.com/qemu-project/qemu/-/work_items/3795 - hw/display/exynos4210_fimd: Pass width to draw_line functions - hw/display/exynos4210_fimd: Factor out finding screen width/height - hw/i2c/bcm2835_i2c: Correct CLKT register offset - linux-user/sh4: allow full 32-bit address space - target/sparc: set reg window data structures currently after vmstate load - hw/net/igb: recalculate rx_desc_len on migration load - hw/net/e1000e: recalculate rx_desc_len on migration load - linux-user: fix guards for the fsmount(2) syscall series - hw/net/xilinx_axienet: Don't write checksums off end of packet - linux-user: Guard local FUTEX_CMD_MASK definition - virtio: avoid packed vring virtio_queue_empty() infinite loops https://gitlab.com/qemu-project/qemu/-/work_items/3968 Closes: CVE-2026-16457 - backends/rng: cap request size to avoid oversized allocation https://gitlab.com/qemu-project/qemu/-/work_items/3983 - hw/virtio-rng: Fix host use-after-free https://gitlab.com/qemu-project/qemu/-/work_items/3917 Closes: CVE-2026-50624 - hw/net/virtio-net: Protect from DMA re-entrancy bugs https://gitlab.com/qemu-project/qemu/-/work_items/4073 Closes: CVE-2026-66022 (again) - intel_iommu: Check address mask before using it in pasid-based iotlb invalidation https://gitlab.com/qemu-project/qemu/-/work_items/3619 - hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle - hw/virtio/vdpa-dev: pass set_config buffer to vhost backend - hw/pci-host/q35.c: Avoid early return in mch_write_config() - hw/pci-host/q35.c: Factor out creation of SMRAM MRs - hw/pci-host/q35.c: Always initialize smram-region even if SMM disabled - virtio-iommu: fix OOM due to unbounded call_rcu - libvduse: validate vq size https://gitlab.com/qemu-project/qemu/-/work_items/3652 Closes: CVE-2026-61402 - libvhost-user: fix heap overflow in vu_check_queue_inflights https://gitlab.com/qemu-project/qemu/-/work_items/3974 Closes: CVE-2026-63110 - libvhost-user: validate last_batch_head in vu_check_queue_inflights https://gitlab.com/qemu-project/qemu/-/work_items/3974 - virtio-pmem: wait for flush requests on unrealize https://gitlab.com/qemu-project/qemu/-/work_items/3938 Closes: CVE-2026-63323 - vhost-user: assert nregions within limit https://gitlab.com/qemu-project/qemu/-/work_items/3910 - virtio: fail early on bad config_len in migration https://gitlab.com/qemu-project/qemu/-/work_items/3891 - virtio-scsi: fix SCSIRequest leak on a bad request https://gitlab.com/qemu-project/qemu/-/work_items/3875 Closes: CVE-2026-61476 - vhost: do not crash on ring map failure https://gitlab.com/qemu-project/qemu/-/work_items/3783 - hw/virtio: reject zero-length packed indirect descriptor table https://gitlab.com/qemu-project/qemu/-/work_items/3984 - libvhost-user: protect against OOB vring queue access https://gitlab.com/qemu-project/qemu/-/work_items/3741 - libvhost-user: protect against OOB writes in vu_set_inflight_fd https://gitlab.com/qemu-project/qemu/-/work_items/3740 - virtio-net: fix short frame OOB read in receive_filter() https://gitlab.com/qemu-project/qemu/-/work_items/3626 Closes: CVE-2026-63320 - virtio-net: fix OOB read in RSC receive path https://gitlab.com/qemu-project/qemu/-/work_items/3623 Closes: CVE-2026-63321 - hw/display/virtio-gpu: Block Rutabaga migration - rutabaga: improve error handling, fix potential crash during init - hw/display/virtio-gpu: Initialize blob mapping for ATTACH_BACKING - hw/display/virtio-gpu: Fix empty blob discrimination - virtio-gpu: fix NULL deref in rutabaga set_scanout https://gitlab.com/qemu-project/qemu/-/work_items/3897 - target/i386/sev: fix MemoryRegion reference leaks in gpa2hva callers - net/colo: fix g_hash_table_destroy assertion on uninitialized filter - hw/display/qxl: unregister vm_change_state handler and BHs https://gitlab.com/qemu-project/qemu/-/work_items/3607 Closes: CVE-2026-63322 - ui/vnc: remove redundant rows computation - hw/display/vhost-user-gpu: validate message payload sizes https://gitlab.com/qemu-project/qemu/-/work_items/3866 - hw/display/virtio-gpu: Remove the bytes_pp field - hw/display/virtio-gpu: reject strides exceeding INT_MAX - hw/display/virtio-gpu: validate stride against width on scanout https://gitlab.com/qemu-project/qemu/-/work_items/3989 Closes: CVE-2026-63109 - hw/usb/hcd-xhci: Check return value of xhci_xfer_create_sgl() for errors https://gitlab.com/qemu-project/qemu/-/work_items/3786 - hw/usb/core: Avoid possible assert() in do_parameter() --> usb_packet_copy() https://gitlab.com/qemu-project/qemu/-/work_items/3746 - hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync() https://gitlab.com/qemu-project/qemu/-/work_items/905 https://gitlab.com/qemu-project/qemu/-/work_items/4052 - hw/usb/dev-uas: Fix guest-triggerable heap OOB access https://gitlab.com/qemu-project/qemu/-/work_items/3612 https://gitlab.com/qemu-project/qemu/-/work_items/3986 - hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect - hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize https://gitlab.com/qemu-project/qemu/-/work_items/3937 - hw/9pfs: fix O_TRUNC bypass on read-only export https://gitlab.com/qemu-project/qemu/-/work_items/4000 Closes: CVE-2026-63318 - hw/display/vmware_vga: Don't allow guest to trigger long running loop in host https://gitlab.com/qemu-project/qemu/-/work_items/3782 https://gitlab.com/qemu-project/qemu/-/work_items/4026 https://gitlab.com/qemu-project/qemu/-/work_items/4076 - hw/ide: replace assert with proper error handling https://gitlab.com/qemu-project/qemu/-/work_items/2777 - scsi-disk: fix off by one in assertion - scsi-disk: protect against guest sending truncated data for MODE SELECT commands https://gitlab.com/qemu-project/qemu/-/work_items/4051 - target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU https://gitlab.com/qemu-project/qemu/-/work_items/3223 - vfio/pci: reject invalid PCI_INTERRUPT_PIN values - vfio/pci: don't narrow a failed config read to a plausible value - vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time https://gitlab.com/qemu-project/qemu/-/work_items/3093 - vfio/pci: Initialize rom_read_failed in vfio_pci_load_rom() - hw/uefi: make SetupMode read-only https://gitlab.com/qemu-project/qemu/-/work_items/4039 Closes: CVE-2026-16288 - hw/uefi: add post_load checks https://gitlab.com/qemu-project/qemu/-/work_items/3837 https://gitlab.com/qemu-project/qemu/-/work_items/3838 https://gitlab.com/qemu-project/qemu/-/work_items/3839 https://gitlab.com/qemu-project/qemu/-/work_items/3885 Closes: CVE-2026-61404 - hw/uefi: account variable policy entries against storage size https://gitlab.com/qemu-project/qemu/-/work_items/3890 Closes: CVE-2026-61405 - hw/uefi: check lower limit for signature list size https://gitlab.com/qemu-project/qemu/-/work_items/3899 Closes: CVE-2026-61406 - hw/uefi: remove debug function https://gitlab.com/qemu-project/qemu/-/work_items/3615 Closes: CVE-2026-58582 - hw/uefi: add sanity check https://gitlab.com/qemu-project/qemu/-/work_items/3614 Closes: CVE-2026-58581 refpolicy (2:2.20250213-13~deb13u1) trixie; urgency=medium . * Fixes for Trixie stable update refpolicy (2:2.20250213-12) unstable; urgency=medium . [ Russell Coker ] * Fix for usbguard * Label /var/lib/dbconfig-common/sqlite3/sympa/sympa * Allow pam sessions to create wtmp.db-journal refpolicy (2:2.20250213-11) unstable; urgency=medium . * Added usbguard policy * Allow chromium to stat xattr filesystems, read xkb libs, and give fifo files to the window manager (to stop it crashing on paste) * Allow pulseaudio_client domains (including the $1_wm_t domains) to mmap the tmpfs files related to pulseaudio (for Chrome mostly) * Allow systemd_passwd_agent_t to watch user runtime dirs for systemd daemon restart * Allow dhcpd_t to execute ntpd_exec_t in ntpd_t for dhcp scripts and start generic units * Allow systemd-nspawn to use user terminal devices for directly running by sysadmin and allow managing mnt_t files roundcube (1.6.18+dfsg-0+deb13u1) trixie-security; urgency=high . * New upstream security and bugfix release (closes: #1144059). + Fix CVE-2026-74998: Content proxied by the css proxy is not validated validation. + Fix CVE-2026-75006: SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 subnets. + Fix CVE-2026-75006: SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading `is_local_url()` check. + Fix CVE-2026-75003: Remote content blocking bypass via unclosed `url()` in a FuncIRI attribute. + Fix CVE-2026-75007: LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`. + Fix CVE-2026-75004: Arbitrary sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`. + Fix CVE-2026-74997: RCE in the `cmd_learn` driver of markasjunk plugin. + Fix CVE-2026-75002: IMAP command injection via mail search and LITERAL+ byte-count desynchronization. + Fix CVE-2026-75010: The modoboa driver of the passwd plugin leaks an authentication token to a user-controlled host. + Fix CVE-2026-74999: Stored XSS in "Add to address book" action. + Fix CVE-2026-75000: HTML/CSS sanitization bypass via SVG animate `by` attribute. * Refresh d/patches. * Cherry-pick follow-up change to fix PHP warning in markasjunk's cmd_learn.php. roundcube (1.6.17+dfsg-1) unstable; urgency=high . * New upstream security and bugfix release (closes: #1141495). + Fix infinite loop in TNEF (winmail.dat) decoder. + Fix various vulnerabilities in the password plugin using session-injected username. + Fix CVE-2026-54432: Stored XSS via unescaped attachment MIME type on the attachment-validation warning page. + Fix SSRF bypass via specific local address URLs. + Fix CVE-2026-54433: Zero-click stored XSS in plain-text rendering. + Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file. + Enigma: Add support for automatic public key lookup (import) using HKP v1 protocol. + Enigma: Add support for Kolab's Web Of Anti-Trust (WOAT) feature. * d/p/Avoid-dependency-on-new-package-mlocati-ip-lib.patch: Improve patch and drop type annotations to restore compatibility with PHP<8 (closes: #1138086). roundcube (1.6.17+dfsg-0+deb13u1) trixie-security; urgency=high . * New upstream security and bugfix release (closes: #1141495). + Fix CVE-2026-62642: Infinite loop in TNEF (winmail.dat) decoder. + Fix CVE-2026-62644: Various vulnerabilities in the password plugin using session-injected username. + Fix CVE-2026-54432: Stored XSS via unescaped attachment MIME type on the attachment-validation warning page. + Fix CVE-2026-62643: SSRF bypass via specific local address URLs. + Fix CVE-2026-54433: Zero-click stored XSS in plain-text rendering. + Fix CVE-2026-62641: DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file. + Enigma: Add support for automatic public key lookup (import) using HKP v1 protocol. + Enigma: Add support for Kolab's Web Of Anti-Trust (WOAT) feature. * d/p/Avoid-dependency-on-new-package-mlocati-ip-lib.patch: Improve patch and drop type annotations to restore compatibility with PHP<8 (closes: #1138086). * Refresh d/patches. roundcube (1.6.16+dfsg-1) unstable; urgency=medium . * New upstream security and bugfix release (closes: #1137507). + Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog. + Fix CSS injection bypass in HTML sanitizer via SVG . + Fix pre-auth SQL injection in `virtuser_query plugin` via `preg_replace()` backslash escape bypass. + Fix SSRF bypass via specific local address URLs. + Fix local/private URL fetch bypass when remote resources were not allowed. + Fix bypass of remote image blocking via CSS `var()`. + Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass. + Code injection vulnerability via code evaluation support in LDAP autovalues option. Code evaluation support has been removed. * Refresh d/patches. * d/p/Avoid-dependency-on-new-package-mlocati-ip-lib.patch: Add support for non quad-dotted IPs and non-decimal fields to match the upstream behavior. * Update Standards-Version to 4.7.4 (no changes necessary). rsyslog (8.2504.0-1+deb13u2) trixie; urgency=medium . * rainerscript: Avoid heap buffer overflow in replace() function. Patch cherry-picked from upstream Git. (CVE-2026-78002, Closes: #1145980) * mmpstrucdata: Fix stack buffer overflow with oversized RFC5424 structured data. Patch backported from upstream Git. (CVE-2026-61548) rsyslog (8.2504.0-1+deb13u1) trixie; urgency=medium . * omfwd regression fix: avoid false active target change log message. Patch backported from upstream Git. (Closes: #1141981) * imptcp: reject invalid regex-framing recovery transitions. (CVE-2026-19654, Closes: #1144616) rust-cbindgen-web (0.29.4+dfsg-1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Backport to trixie as rust-cbindgen-web. * Only build the cbindgen binary. Since we're vendoring the dependencies, we can't easily ship a librust-cbindgen-web-dev package as its dependencies won't be available. * Vendor dependencies, they are not available in trixie. rust-cbindgen-web (0.27.0-1~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Backport to bookworm as rust-cbindgen-web. Since we're vendoring the dependencies, we can't easily ship a librust-cbindgen-dev package as it's dependencies won't be available, and there are build-rdeps for that binary now so we can't just disable it. * Vendor dependencies, they are not available in bookworm. * Only build the cbindgen binary. Since we're vendoring the dependencies, we can't easily ship a librust-cbindgen-web-dev package as its dependencies won't be available. * Build with rustc-web. rust-cbindgen-web (0.26.0-3~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Backport to bookworm as rust-cbindgen-web. Since we're vendoring the dependencies, we can't easily ship a librust-cbindgen-dev package as it's dependencies won't be available, and there are build-rdeps for that binary now so we can't just disable it. * Vendor dependencies, they are not available in bookworm. * Only build the cbindgen binary. * Build with rustc-web. rust-cbindgen-web (0.26.0-3~deb11u1) bullseye; urgency=medium . * Backport to bullseye. * Lower dh-cargo requirement to 24. * Build with cargo-mozilla. rustc (1.85.1+dfsg1-1+deb13u1) trixie; urgency=medium . * New upstream point release 1.85.1 (Closes: #1135220) - fix doctest merging with edition 2024 - fix rustdoc on 32-bit ARM * backport tar CVE-2026-33055/CVE-2026-33056 fixes (Closes: #1135225) * cherry-pick cargo CVE-2026-5222/CVE-2026-5223 fixes rustc-web (1.96.0+dfsg1-1~deb13u1) trixie; urgency=medium . [ Fabian Grünbichler ] * downgrade git2 for trixie . [ Emilio Pozuelo Monfort ] * Don't build wasm. * Rename to rustc-web. * Add missing provides. rustc-web (1.96.0+dfsg1-1~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm. * Lower libgit2-dev requirement to 1.5. * Drop build-dep on node-fortawesome-fontawesome-free, not available on bookworm. * Don't build -doc packages, they require the above font. rustc-web (1.85.0+dfsg3-1~deb12u3) bookworm; urgency=medium . * Non-maintainer upload. * Remove hardcoded x86_64 string in debian/not-installed to fix non-amd64 builds. rustc-web (1.85.0+dfsg3-1~deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * Fix rustfmt-web to properly depend on libstd-rust-web-*. rustc-web (1.85.0+dfsg3-1~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Backport to bookworm, as required by newer firefox & chromium. * Rename rustc & friends to rustc-web or similar. * Generate & include bootstrap compilers via orig-stage0.tar.xz. * Disable wasm, -all, and -llvm packages. * Vendor libgit2 dependency, switching from llhttp/builtin to the (debian package) http-parser. * Increase allowed test failures up to 15 to work around random fails. * Add 'Provides: cargo' for cargo-web (closes: #1084926). . rustc (1.85.0+dfsg3-1) unstable; urgency=medium . * backport fix for gix-features CVE-2025-31130 * rust-lldb: fix lldb version (Closes: #1100950) * cherry-pick fix for crossbeam-channel RUSTSEC-2025-0024 . rustc (1.85.0+dfsg2-3) unstable; urgency=medium . * baseline: enable SSE2 for i386 build (Closes: #1095862) . rustc (1.85.0+dfsg2-2) unstable; urgency=medium . * Upload to unstable . rustc (1.85.0+dfsg2-1) experimental; urgency=medium . * d/control: bump libgit2-dev version * vendor git2, git2-curl and libgit2-sys bindings for libgit2 1.9 * cargo: bump git2* dependencies . rustc (1.85.0+dfsg1-1) unstable; urgency=medium . * New (stable) upstream release. . rustc (1.85.0~beta.9+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release 1.85.0~beta999 * build docs with -j1 to make them reproducible * build: make windows libstd build opt-in . rustc (1.84.0+dfsg1-2) unstable; urgency=medium . * revert upstream commit breaking cross builds * rust-llvm: ship symlink to llvm-objcopy instead of copy of binary . rustc (1.84.0+dfsg1-1) unstable; urgency=medium . * rust-analyzer: fix build on mips64el * fix hurd build (Closes: #1093125) * d/control: add Conflicts with rustup (Closes: #1093031) . rustc (1.84.0+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release. * Stop building wasm32-wasi target * Build rust-analyzer (Closes: #1052319) * rust-llvm: ship rust-objcopy helper * rust-all: add rust-llvm and rust-analyzer packages . rustc (1.83.0+dfsg1-1) unstable; urgency=medium . * upload to unstable * fix/ignore some test failures . rustc (1.83.0+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release * config: disable downloading LLVM from CI * blake3: adapt build.rs to skip bundled C code * remove libstd shared library . rustc (1.82.0+dfsg1-2) unstable; urgency=medium . * build: re-enable clang-rt on armel/armhf * build: drop workaround for riscv64/loong64 . rustc (1.82.0+dfsg1-1) unstable; urgency=medium . * rust-src: ship original Cargo.lock file to fix rust-analyzer for libstd, and allow `-Z build-std` * build: disable profiler support on armel/armhf * build: extend riscv64 workaround to loong64 * cargo wrapper: fix LTO position in argument lists (Closes: #1086025) . rustc (1.82.0+dfsg1-1~exp3) experimental; urgency=medium . * conditonalize riscv64 workaround * fix or disable more broken tests . rustc (1.82.0+dfsg1-1~exp2) experimental; urgency=medium . * fix some test breakage * riscv64: unbreak compiler_builtin build . rustc (1.82.0+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release * New wasi-libc version 0.0~git20240708.3f43ea9 * switch to LLVM 19 * set LLVM profiler RT path via config * update bootstrap git commit info patch * re-instate bootstrap test config patch * make rust-src cleanup more robust . rustc (1.81.0+dfsg1-2) unstable; urgency=medium . * use system libz-sys even when cross-building (Closes: #1084754) * drop no longer needed loongarch64 patch * add temporary Breaks to force migration of libgit2 . rustc (1.81.0+dfsg1-1) unstable; urgency=medium . * Upload to unstable . rustc (1.81.0+dfsg1-1~exp2) experimental; urgency=medium . * source: duplicate lintian overrides to make ftp-masters happy * cargo wrapper: fix LTO handling (Closes: #1079071) . rustc (1.81.0+dfsg1-1~exp1) experimental; urgency=medium . [ Fabian Grünbichler ] * New upstream release * switch to LLVM 18 * bump libgit2 to 1.8.1 * build and install wasm-component-ld for wasm-wasip2 * make rust-llvm arch:any . [ Samuel Thibault ] * add hurd-amd64 support . rustc (1.80.1+dfsg1-1) unstable; urgency=medium . * upload to unstable . rustc (1.80.1+dfsg1-1~exp1) experimental; urgency=medium . * New upstream point release . rustc (1.80.0+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release * Build wasi-p2 target * Use packaged libonig * Update lintian overrides * d/control: drop Build-Conflicts on gdb-minimal . rustc (1.79.0+dfsg1-2) unstable; urgency=medium . [ Fabian Grünbichler ] * build: remove more cache files (Closes: #1074373) * d/control: update Standards-Version to 4.7.0 . [ Samuel Thibault ] * Avoid hurd-stuck test . rustc (1.79.0+dfsg1-1) unstable; urgency=medium . * cargo wrapper: switch to config.toml * cargo wrapper: ensure debug symbols are not stripped * add missing rustfmt dependency (Closes: #1074290) . rustc (1.79.0+dfsg1-1~exp1) experimental; urgency=medium . * New upstream release * New wasi-libc version (SDK 22) * config: adapt to new change tracking mechanism rustc-web (1.78.0+dfsg1-2~deb12u3) bookworm; urgency=medium . * Depend on cargo-web for the autopkgtest. * Add missing conflicts (closes: #1079744, #1079653, #1076683). rustc-web (1.78.0+dfsg1-2~deb12u2) bookworm; urgency=medium . * Also rename rustfmt to rustfmt-web. rustc-web (1.78.0+dfsg1-2~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Backport rustc 1.78, as required by newer firefox and chromium. * Rename rustc backport to rustc-web. * Use LLVM 16. * Disable wasm, -all, -llvm packages. * Vendor libgit2 dependency. rustc-web (1.78.0+dfsg1-2~deb11u3) bullseye; urgency=medium . * Depend on cargo-web for the autopkgtest. * Add missing conflicts (closes: #1079744, #1079653, #1076683). rustc-web (1.78.0+dfsg1-2~deb11u2) bullseye; urgency=medium . * Also rename rustfmt to rustfmt-web. rustc-web (1.78.0+dfsg1-2~deb11u1) bullseye; urgency=medium . * Backport to bullseye. * Switch pkgconf build-dependency to pkg-config, pkgconf in bullseye doesn't provide `triplet`-pkgconf binaries. rustc-web (1.70.0+dfsg1-7~deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * Increase allowed test failures on armhf and ppc64el to fix FTBFS. * Provide Conflicts/Replaces for rust*-mozilla*, which could still be installed from oldstable (closes: #1064562). * Add Provides/Conflicts/Replaces for libstd-rust-1.70 (closes: #1064563). rustc-web (1.70.0+dfsg1-7~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Rename rustc backport to rustc-web, intended to be used for browsers. * Generate & include bootstrap compilers via an orig-stage0.tar.xz. * Add mipsel bootstrap compiler back, as mipsel is still in bookworm. * Disable profiler on mipsel, as it likely doesn't work either. * Disable wasm. * Drop -all virtual package, which doesn't make sense for us. rustc-web (1.70.0+dfsg1-7~deb11u1) bullseye; urgency=medium . * Non-maintainer upload. * Backport to bullseye. sabnzbdplus (4.5.0+dfsg-1+deb13u1) trixie-security; urgency=high . * Patches: add 11, backport of an upstream security fix for an authentication bypass in the web interface. samba (2:4.22.11+dfsg-0+deb13u1) trixie; urgency=medium . * switch to actual new upstream release, dropping the security patchset (it is included into the upstream tarball now). . Besides all the security fixes, there's an addtional fix in this release (which was queued before the security fixes): . o libsecurity: Fix security_acl_dup()'s talloc hierarchy Bug: https://bugzilla.samba.org/show_bug.cgi?id=16095 samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium . * 2026-jul-sec-update-bug-16039-v4-22-combined.patch: Jul-2026 samba security update addresses the following defects: . CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083 TSIG packet with crafted name compression can crash internal DNS server . CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085 CTDB: heap OOB read via unchecked packet length fields . CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087 kpasswd service: 6-byte heap OOB read in packet parser . CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115 DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes . CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147 authenticated LDAP access to internal LDB special DNs permits domain takeover . CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148 LDAP Compare filter injection and trusted-request confusion disclose protected attributes sbsigntool (0.9.4-3.2+deb13u1) trixie; urgency=medium . * Backport the "certificate validation with intermediates" fix for trixie. Closes: #1141851 sg3-utils (1.48-3~deb13u1) trixie; urgency=medium . * Rebuild for trixie. . sg3-utils (1.48-3) unstable; urgency=medium . * Add fix for missing output fields in sg_inq (Closes: #1109923) socat (1.8.0.3-1+deb13u1) trixie; urgency=medium . * CVE-2026-56123 spip (4.4.21+dfsg-0+deb13u1) trixie-security; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.21 spip (4.4.20+dfsg-1) unstable; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.20 . [ David Prévot ] * Use debhelper-compat = 14 spip (4.4.20+dfsg-0+deb13u1) trixie-security; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.20 spip (4.4.19+dfsg-1) unstable; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.19 spip (4.4.19+dfsg-0+deb13u1) trixie-security; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.19 + Fix code injection [CVE-2026-66738] . [ David Prévot ] * Don’t install ecs, rector nor phplint files spip (4.4.18+dfsg-1) unstable; urgency=medium . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.18 + Fix code injection [CVE-2026-66738] . [ David Prévot ] * Don’t install ecs, rector nor phplint files * Document lintian-overrides spip (4.4.16+dfsg-1) unstable; urgency=medium . [ b_b ] * security: interdire l'accès aux fichiers PHP dans IMG et local . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.16 . [ David Prévot ] * Document CVE in previous changelog entry * Update mutualisation spip (4.4.16+dfsg-0+deb13u1) trixie; urgency=medium . [ b_b ] * security: interdire l'accès aux fichiers PHP dans IMG et local . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.16 . [ David Prévot ] * Document CVE in previous changelog entry spip (4.4.15+dfsg-1) unstable; urgency=medium . [ David Prévot ] * Document CVEs in previouss changelog entry * debian/watch: Update Source URL . [ Matthieu Marcillaud ] * build: up dependencies * build: Version 4.4.15 sqlite3 (3.46.1-7+deb13u2) trixie; urgency=medium . * Backport upstream security fix for CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension. * Backport upstream security fix for CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension. squid (6.13-2+deb13u3) trixie; urgency=medium . * CVE-2026-33515 srt (1.5.4-1+deb13u1) trixie-security; urgency=medium . * [4136a38] d/patches/CVE-2026-55869.patch: added from upstream. Fix KMREQ/KMRSP Stack-Based Buffer Overflow (CVE-2026-55869, GHSA-6xg9-784j-24rm), when used together with the patch for CVE-2026-55868 / GHSA-4mc6-qmpp-g7gw. * [76b1e2d] d/patches/CVE-2026-55868.patch: added from upstream. Fix Encryption State Machine Downgrade (CVE-2026-55868, GHSA-4mc6-qmpp-g7gw), and fix KMREQ/KMRSP Stack-Based Buffer Overflow (CVE-2026-55869, GHSA-6xg9-784j-24rm). starlette (0.46.1-3+deb13u3) trixie-security; urgency=medium . * Team upload. * d/patches: (Closes: #1140631, #1140632) - CVE-2026-48817: Import and backport upstream patch (Prevent unintended HTTPEndpoint method dispatch) - CVE-2026-54282: Import upstream patch (Validate request paths to prevent host confusion) - CVE-2026-54283: Import and backport upstream patch (Enforce max_fields and max_part_size limits) suricata-update (1.3.4-1+deb13u1) trixie-security; urgency=medium . * Fix CVE-2026-63347 in 1.3.4. Cherry-Picked from fae50697dff60364d6f0638908c6762eec3b421c. swift (2.35.1-0+deb13u3) trixie-security; urgency=medium . * CVE-2026-71191 / OSSA-2026-030: Swift S3API header authorization bypass. Applied upstream patch: - "s3api: require signing of sensitive SigV4 x-amz headers" - "s3api: drop native Swift control headers from client requests" (Closes: #1142972). * CVE-2026-71192 / OSSA-2026-031: proxy denial of service via Accept header. Applied upstream patch: - "swob: avoid excessive backtracking in Accept parser" (Closes: #1142973). * CVE-2026-50221: Swift proxy-server SSRF via internal update header injection: applied upstream patch: Block internal update headers at the gatekeeper (Closes: #1140678). tiff (4.7.0-3+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Address heap-based buffer overflow in pixarlog (CVE-2026-12912) (Closes: #1141320) - pixarlog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 - pixarlog: add comment explaining 4-byte advance in ABGR decode - pixarlog: complete ABGR bounds check for multi-row strip decoding - pixarlog: error out on invalid ABGR output buffer sizes transmission (4.1.0~beta2+dfsg-3+deb13u2) trixie; urgency=medium . * CVE-2026-38978 tryton-modules-company (7.0.2-1+deb13u1) trixie-security; urgency=high . * Add 01_manage_ModelAccessProxy.patch. This patch is part of the required patch adding ModelAccessProxy https://foss.heptapod.net/tryton/tryton/-/merge_requests/3431 needed for From https://discuss.tryton.org/t/security-release-for-issue-14907: Cédric Krier has discovered that access is not enforced when browsing record instances in templates. tryton-modules-marketing-automation (7.0.1-1deb13u1) trixie-security; urgency=high . * Add 01_enforce_access_rights_on_the_email_template_record_of_marketing _automation.patch. . From https://discuss.tryton.org/t/security-release-for-issue-14907: Cédric Krier has discovered that access is not enforced when browsing record instances in templates. This patch also neeeds ModelAccessProxy https://foss.heptapod.net/tryton/tryton/-/merge_requests/3431 tryton-modules-marketing-email (7.0.0-3deb13u1) trixie-security; urgency=high . * Add 01_enforce_access_rights_on_the_email_template_record_of_marketing _email.patch. Enforce access rights on email template records From https://discuss.tryton.org/t/security-release-for-issue-14907: Cédric Krier has discovered that access is not enforced when browsing record instances in templates. This patch also neeeds ModelAccessProxy https://foss.heptapod.net/tryton/tryton/-/merge_requests/3431 tryton-server (7.0.30-1+deb13u2) trixie-security; urgency=high . * Add 06_restrict_genshi_evaluation.patch. From https://discuss.tryton.org/t/security-release-for-issue-5160-and-14869: Security Release for issue #5160 and #14869 The user titou has discovered that the administrator group can execute Python code on the server which is hidden inside an uploaded report template. And Dan Shallom has discovered that the same can also be accomplished by the marketing group when uploading marketing email templates. This patch also contains the subsequent fixes from https://bugs.tryton.org/14928, https://bugs.tryton.org/14932 * Add 07_enforce_access_right_on_email_template_records.patch. From https://discuss.tryton.org/t/security-release-for-issue-14907: Cédric Krier has discovered that access is not enforced when browsing record instances in templates. This patch also contains the required patch adding ModelAccessProxy https://foss.heptapod.net/tryton/tryton/-/merge_requests/3431 * Add 08_restrict_weasyprint_protocol.patch. From https://discuss.tryton.org/t/security-release-for-issue-14947: Cédric Krier has discovered that Tryton does not prevent weasyprint to access local files when rendering HTML report to PDF. https://foss.heptapod.net/tryton/tryton/-/work_items/14947 The weasyprint documentation states that it can be used to access local files. tzdata (2026c-0+deb13u1) trixie; urgency=medium . * New upstream version 2026c: - Alberta moved to permanent -06 on 2026-06-18, so it will not fall back from -06 to -07 on 2026-11-01. - Morocco moves to permanent +00 on 2026-09-20. - No leap second on 2026-12-31. tzdata (2026b-1) unstable; urgency=medium . * New upstream version 2026b: - British Columbia moved to permanent -07 on 2026-03-09, so it will not fall back from -07 to -08 on 2026-11-01. * Add autopkgtest test case for 2026b release u-boot (2025.01-3+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2024-42040: buffer overread vulnerability in the DHCP implementation. (Closes: #1081557) * CVE-2026-46728: mishandles use of unit addresses in a FIT. (Closes: #1136954) udisks2 (2.10.1-12.1+deb13u2) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix local privilege escalation via 'as-user' mount spoofing (CVE-2026-7867). Patches cherry-picked from the upstream 2.10.x-branch. unixodbc (2.3.12-2+deb13u1) trixie; urgency=medium . * debian/libodbcinst2.symbols: Add inst_logClose@Base. * debian/patches: Clear cached allocations on dlclose() in libodbcinst2 (Closes: #1136221). unzip (6.0-29+deb13u1) trixie-security; urgency=high . * Apply upstream fix for CAN-2026-2034440. Closes: #1142904. (heap out-of-bounds read in EF_IZUNIX3 extra field handler) * Apply upstream fix for CAN-2026-2034443. Closes: #1142905. (stack out-of-bounds NUL write in EF_SMARTZIP handler) * Apply upstream fix for CAN-2026-2034442. Closes: #1142906. (heap buffer overflow WRITE in memextract() STORED path) util-linux (2.41.5-0+deb13u1) trixie-security; urgency=medium . * New upstream version 2.41.5, fixing CVE-2026-53612, CVE-2026-53613, CVE-2026-53614. (Closes: #1140194, #1140195, #1140196) * Drop patches from upstream which came from the stable release branch. * Pick upstream patch from stable release branch: loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file Fixes CVE-2026-27456. * Pick upstream patch: libmount: restrict source path canonicalization for non-root users * Avoid installing new bash-completions. * d/gbp.conf: setup for trixie. util-linux (2.41.3-4) unstable; urgency=medium . [ Chris Hofstaedtler ] * Follow libselinux1-dev to libselinux-dev rename (Closes: #1124751) * uuid-runtime: stop removing /var/run/uuidd on purge /run is a tmpfs, it will be cleaned up anyway. Lets us drop the postrm maintscript. . [ Luca Boccassi ] * uuid-runtime: drop manual scripting in postinst and rely on sysusers.d util-linux (2.41.3-3) unstable; urgency=medium . * d/libsmartcols1.symbols: drop terminal crap * d/rules: make dpkg-gensymbols more strict * lintian: ignore groff-message tags * lintian: ignore groff-message tags in remaining packages * Add upstream patches * unshare: fix user namespace bind mounts * unshare: remove get_mnt_ino() check in bind_ns_files_from_child() * unshare: add --owner to set user namespace owner uid and gid * libfdisk: modernize ZFS GPT type description util-linux (2.41.3-2) unstable; urgency=medium . [ Luca Boccassi ] * util-linux: do not fail postinst/prerm if update-alternatives is missing util-linux (2.41.3-1) unstable; urgency=medium . * Stop installing lastlog2-import.service * New upstream release, fixing CVE-2025-14104. (Closes: #1122058) util-linux (2.41.2-4) unstable; urgency=medium . * Install pivot_root into util-linux-extra. Thanks to Antonio Ospite (Closes: #1117538) * Ensure /var/lib/lastlog exists for pam_lastlog2. Previously this was created by lastlog2-tmpfiles.conf, installed by the lastlog2 package. But lastlog2 itself is optional and not stricly necessary for libpam-lastlog2 to function. Install lastlog2-tmpfiles.conf into libpam-lastlog2, and also have dpkg create the directory. Thanks to Joachim Jautz (Closes: #1117725) * Break older dracut for moved switch_root util-linux (2.41.2-3) unstable; urgency=medium . * Revive switch_root for dracut, in util-linux-extra (Closes: #1116629) util-linux (2.41.2-2) unstable; urgency=medium . * Reduce Installed-Size of util-linux: * Move lslogins from util-linux to util-linux-extra * Move rev from util-linux to bsdextrautils * Move blkzone, chcpu, chmem, lsmem from util-linux to util-linux-extra * Move isosize from util-linux to util-linux-extra * Move wdctl from util-linux to util-linux-extra * Move rename.ul from util-linux to util-linux-extra * Move ldattach from util-linux to util-linux-extra * Stop installing pivot_root, switch_root. Apparently unused on Debian. * util-linux-extra: Remove protectice diversions for usrmerge util-linux (2.41.2-1) unstable; urgency=medium . * New upstream release. * Drop upstream-applied patches. * Release to unstable. . Includes from upstream: . [ Sam Fink ] * libblkid: Fix probe_ioctl_tp assigning BLKGETDISKSEQ as physical sector size (Closes: #1115590) util-linux (2.41.1-4) experimental; urgency=medium . * d/copyright: remove (old) FSF address * fdisk-udeb: remove old lintian overrides * Ignore lintian warning about dh-exec-script-without-dh-exec-features * util-linux.README.Debian: fstrim is enabled by default (Closes: #1115239) * Install isosize into upstream-determined /usr/bin (Closes: #1025819) * Install chmem into upstream-determined /usr/bin * Install addpart,delpart into util-linux-extra (Closes: #1115193) * Fix enosys bash completion using upstream patches (Closes: #1108317) * Move newgrp, sg from login to util-linux-extra (Closes: #1111747) * Install ll2_rename_user.3 into util-linux-locales * Move logger to util-linux * Drop Essential: yes from bsdutils util-linux (2.41.1-3) unstable; urgency=medium . [ Niels Thykier ] * Replace ad-hoc maintscripts substitution with `dh_installdeb` feature . [ Thomas Weißschuh ] * Install lsclocks into util-linux-extra . [ Chris Hofstaedtler ] * Install lsclocks bash completion and translated man pages util-linux (2.41.1-2) unstable; urgency=medium . * Mark uuid_time64 symbol linux-only. Thanks to Samuel Thibault (Closes: #1108994) * Install PAM configuration for login "remote" (Closes: #1103923) * Add patches from upstream util-linux (2.41.1-1) unstable; urgency=medium . * New upstream release. * Drop upstream signing-key for the time being * d/README.source: update tag fetch instructions for current git * Rebase patches * d/README.source: update for current repo layout * login: drop Protected: yes. Bug #1099445. webkit2gtk (2.52.6-1~deb13u1) trixie-security; urgency=medium . * Rebuild for trixie-security. * Re-enable libmanette in i386. * Enable the transitional packages. * Use the default clang on armhf since trixie uses clang-19 and is not affected by WebKit bug #290167. * Add the 'Priority: optional' field. webkit2gtk (2.52.5-1) unstable; urgency=high . * New upstream release. * The WebKitGTK security advisory WSA-2026-0004 lists the following security fixes in the latest versions of WebKitGTK: - CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745 (fixed in 2.52.5). * Drop fix-ftbfs-system-malloc.patch. webkit2gtk (2.52.5-1~deb13u1) trixie-security; urgency=medium . * Rebuild for trixie-security. * Re-enable libmanette in i386. * Enable the transitional packages. * Use the default clang on armhf since trixie uses clang-19 and is not affected by WebKit bug #290167. * Add the 'Priority: optional' field. webkit2gtk (2.52.4-1) unstable; urgency=medium . * New upstream release. * Drop fix-atomics-detection.patch and fix-big-endian-string.patch. * fix-ftbfs-system-malloc.patch: - Fix FTBFS when USE_SYSTEM_MALLOC is enabled (for example i386). * Use clang-22 on armhf instead of gcc: - debian/control.in: add build dependency. - debian/rules: don't use -no-integrated-cpp as it causes build failures with clang due to missing includes. webkit2gtk (2.52.3-2) unstable; urgency=medium . * debian/rules: - Use --param ggc-min-expand=10 on hppa, m68k and sh4 in order to reduce the memory usage during compilation (Closes: #1134391) (thanks, John Paul Adrian Glaubitz). * Refresh upstream signing keys with the expiration dates. * debian/control.in: - Update Standards-Version to 4.7.4. * fix-atomics-detection.patch: - Improve detection of whether libatomic is required. This was failing in some architectures (armhf, armel) with some versions of clang. * fix-big-endian-string.patch: - Use the native byte order when converting from utf8 to utf16. This fixes strings in big-endian machines (Closes: #1132818). wireshark (4.4.18-0+deb13u1) trixie-security; urgency=medium . * Team upload. * New upstream version 4.4.18 (Closes: #1142268, #1144924) - CVE-2026-15163: Multiple loops in dissectors, allows DoS - CVE-2026-15164: Crash in ciscodump, allows DoS - CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS - CVE-2026-15167: DBS Etherwatch parser crash, allows DoS - CVE-2026-15168: BLF parser, allows information disclosure - CVE-2026-15169: UMTS FP dissector crash, allows DoS - CVE-2026-15170: Z39.50 dissector crash, allows DoS - CVE-2026-15171: SSH dissector crash, allows DoS - CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS - CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS - CVE-2026-76879: C12.22 dissector crash, allows DoS - CVE-2026-76880: RRC dissector crash, allows DoS - CVE-2026-76881: CMS dissector crash, allows DoS - CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS - CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS - CVE-2026-76884: ERF parser crash, allows DoS - CVE-2026-76885: Tektronix K12xx parser crash, allows DoS - CVE-2026-76886: C12.22 dissector crash, allows DoS - CVE-2026-76887: Dissection engine crash, allows DoS - CVE-2026-76888: RDP dissector crash, allows DoS - CVE-2026-76889: UMTS FP dissector crash, allows DoS - CVE-2026-76890: Crash in sharkd, allows DoS - CVE-2026-76891: Crash in sharkd, allows DoS - CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS - CVE-2026-76918: SSH dissector crash, allows DoS - CVE-2026-76919: ESS dissector crash, allows DoS - CVE-2026-76920: 3gpp phone log parser crash, allows DoS - CVE-2026-76921: CMS dissector crash, allows DoS - CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS - CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS - CVE-2026-76924: Kerberos dissector crash, allows DoS - CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS - CVE-2026-76927: H.245 dissector crash, allows DoS - CVE-2026-76928: X.509IF dissector crash, allows DoS - CVE-2026-76929: Pcapng parser crash, allows DoS wolfssl (5.7.2-0.1+deb13u2) trixie; urgency=high . * Backport upstream security fixes. (See #1140765, #1140815) * CVE-2026-5194: require certificate signature OID to match issuer key OID. * CVE-2026-55960: validate negotiated certificate type for raw public keys. * CVE-2026-55961: reject degenerate certs-only PKCS#7 in PKCS7_verify. * CVE-2026-55962: require client cert on outstanding TLS 1.3 post- handshake auth. * CVE-2026-55967: reject AES-GCM cumulative size overflow in streaming update. * CVE-2026-6092: enforce Encrypt-then-MAC on the TLS resumption path. * CVE-2026-6094: bound encrypted content size in PKCS7 EnvelopedData. * CVE-2026-6325: bound index in SetSuitesHashSigAlgo to prevent OOB write. * CVE-2026-6329: reject PKCS#12 MAC length mismatch. * CVE-2026-6331: require exact HMAC tag length in EVP_DigestVerifyFinal. * CVE-2026-6450: reject CRLs with unrecognized critical extensions. * CVE-2026-6678: fix integer underflow in wc_PKCS7_DecryptOri. * CVE-2026-6681: respect caller output buffer size in PKCS7 decode. * CVE-2026-6731: apply DNS name constraints to Subject CN when no SAN. * CVE-2026-7511: report the verifying cert as the PKCS#7 signer. wordpress (6.8.7+dfsg1-0+deb13u1) trixie-security; urgency=medium . * New upstream security release CVE-2026-64638 fix XSS in login that leads to RCE Closes: #1143843 wordpress (6.8.6+dfsg1-0+deb13u1) trixie-security; urgency=medium . * New upstream security release 6.8.6 * CVE-2026-60137 fix facilitated SQL injection Closes: #1142510 * Includes release 6.8.4 and 6.8.5 updates - Check permissions on edit notes CVE-2026-3906 (not vulnerable) wordpress (6.8.3+dfsg1-1) unstable; urgency=medium . * New upstream security release Closes: #1117047 Fixes the following CVEs: - Stored XSS in nav menus CVE-2025-58674 - Data exposure CVE-2025-58246 * Update copyright files to use download links xapian-core (1.4.29-3+deb13u1) trixie; urgency=medium . * Cherry-pick fix for missed corner case of CVE-2018-0499. New patch: cve-2018-0499-mset-snippet-escaping-no-highlighting-1.4.x.patch (Closes: #1144490) xdg-dbus-proxy (0.1.6-1+deb13u2) trixie-security; urgency=high . * d/p/GHSA-r7hp-698j-2h6c/*.patch: Fix a vulnerability in access control for receiving broadcasts. In 0.1.6 and 0.1.7, a malicious or compromised Flatpak app could receive any broadcast D-Bus message on the session bus or the AT-SPI bus, leading to unintended information disclosure. * d/p/tests/*.patch: Add automated test coverage for message filtering xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=medium . * Update to new upstream version 4.20.3+127-gc42374a105, which also contains security fixes for the following issues: (Closes: #1129037) - Use after free of paging structures in EPT XSA-480 CVE-2026-23554 - Xenstored DoS by unprivileged domain XSA-481 CVE-2026-23555 - oxenstored keeps quota related use counts across domain destruction XSA-483 CVE-2026-23556 - Xenstored DoS via XS_RESET_WATCHES command XSA-484 CVE-2026-23557 - grant table v2 race in status page mapping XSA-486 CVE-2026-23558 - x86: Floating Point Divider State Sampling XSA-488 CVE-2025-54505 - x86: CPU Opcode Cache corruption XSA-490 CVE-2025-54518 - x86 HVM I/O port list traversal XSA-491 CVE-2026-42487 - domctl lock open to abuse XSA-492 CVE-2026-42489 CVE-2026-42490 - Arm: Completion of memory accesses not guaranteed by completion of a TLBI XSA-493 CVE-2025-10263 - x86: mismatched mapcache metadata XSA-494 CVE-2026-42488 - x86 shadow paging is deprecated XSA-495 CVE-2026-42493 - buffer overruns in libfsimage iso9660 handling XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 - sysctl and platform-op locks open to abuse XSA-499 CVE-2026-62426 CVE-2026-62427 - grant-table: type confusion in grant-copy XSA-500 CVE-2026-62428 - grant-table: version change racing with other operations XSA-501 CVE-2026-62435 CVE-2026-62436 - vNUMA domain cleanup may race other operations XSA-502 CVE-2026-62429 - x86: Out-of-bounds read in vRTC emulation XSA-503 CVE-2026-62430 - Viridian STIMER division by zero XSA-504 CVE-2026-62431 - evtchn: Race between FIFO expand and reset XSA-505 CVE-2026-62432 - correct buffer checks for DM_OP hypercalls XSA-506 CVE-2026-62433 - PoD: Don't try to reclaim special pages XSA-507 CVE-2026-62434 - pygrub: security-supported only when run de-privileged XSA-508 * Drop the following patches which are now included upstream: - ARM: Drop ThumbEE support - xen/arm: Set ThumbEE as not present in PFR0 * Note that the following XSA are not listed, because... - XSA-482 has patches for the Linux kernel - XSA-485 has patches for the Linux kernel - XSA-487 has patches for the Linux kernel - XSA-489 applies to XAPI which is not included in Debian - XSA-496 only applies to Xen 4.21 and later - XSA-498 applies to XAPI which is not included in Debian . xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=medium . * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains security fixes for the following issues: - x86: buffer overrun with shadow paging + tracing XSA-477 CVE-2025-58150 - x86: incomplete IBPB for vCPU isolation XSA-479 CVE-2026-23553 * Note that the following XSA are not listed, because... - XSA-478 applies to XAPI which is not included in Debian xen (4.20.2+37-g61ff35323e-1) unstable; urgency=medium . * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains security fixes for the following issues: - x86: buffer overrun with shadow paging + tracing XSA-477 CVE-2025-58150 - x86: incomplete IBPB for vCPU isolation XSA-479 CVE-2026-23553 * Note that the following XSA are not listed, because... - XSA-478 applies to XAPI which is not included in Debian * Pick upstream commit 1ecb5946bd ("xen/arm: Set ThumbEE as not present in PFR0") which is an additional fix for the ThumbEE commit picked in previous upload. xfsprogs (6.13.0-2+deb13u1) trixie; urgency=medium . * xfs_scrub_fail: reduce security lockdowns to avoid postfix problems (Closes: #1116595) xrdp (0.10.1-3.1+deb13u2) trixie-security; urgency=high . * Non-maintainer upload. * CVE-CVE-2026-32105: modify encrypted traffic in transit without detection (Closes: #1134339) * CVE-2026-32107: improper privilege management allow attacker to escalate privileges to root and execute arbitrary code. * CVE-2026-32623: heap-based buffer overflow vulnerability * CVE-2026-32624: heap-based buffer overflow vulnerability * CVE-2026-33145: authenticated remote user to execute arbitrary commands * CVE-2026-33516: out-of-bounds read vulnerability * CVE-2026-33689: out-of-bounds read vulnerability * CVE-2026-35512: a heap-based buffer overflow * CVE-2026-41252: missing bounds check in xrdp, which allows a heap-based buffer overflow * CVE-2026-41521: nteger overflow vulnerability * CVE-2026-42218: a timing side-channel vulnerability in the login interface * CVE-2026-44178: heap-based buffer overflow vulnerability * CVE-2026-44978: heap out-of-bounds read vulnerability * CVE-2026-54538: sending a specially crafted packet that forces the process into an infinite, CPU-bound loop * CVE-2026-55238: Denial of Service * CVE-2026-55639: exploit by specially crafted RDP malformed data and read out-of-bound data block. * CVE-2026-55645: out-of-bounds memory reads zfs-linux (2.3.9-0+deb13u1) trixie-security; urgency=medium . * New upstream stable point release 2.3.9, fix open zpool manipulation and escapes via unprivileged userns. * d/patches: drop patches that are now included, refresh remaining. * d/zfsutils-linux.install: add zfs-mount@.service and zfs-rewrite.8 * d/*.symbols: update. * d/rules: fix dkms build by retaining more fields in configure.ac. * d/rules: install scripts/objtool-wrapper.in into dkms tree. zfs-linux (2.3.5-2) unstable; urgency=medium . [ Shengqi Chen ] * d/watch: switch to version 5 . [ Aron Xu ] * d/patches: resync with Ubuntu, changes - Enable ubuntu/4100-disable-bpool-upgrade.patch - Enable Linux 6.18 cherry-picks * Revert "d/patches: remove not used patch" * d/patches/bump-Linux-Minimum.patch: refresh * d/patches: enable-linux-experimental to allow building with 6.18 * d/upstream/signing-key.asc: add 6AD860EED4598027 * d/libzpool6linux.symbols: update * d/source/lintian-overrides: drop unused ones, add python test ones * d/control*: std-ver 4.7.2, no change required * d/pyzfs-doc.lintian-overrides: removed * d/control: remove redundant "Rules-Requires-Root: no" zfs-linux (2.3.5-2~bpo13+1) trixie-backports; urgency=medium . * Rebuild for trixie-backports. zfs-linux (2.3.5-1) unstable; urgency=medium . * New upstream version 2.3.5 (Closes: #1119915) * d/patch: remove not used patch zfs-linux (2.3.4-1) unstable; urgency=medium . * New upstream version 2.3.4 (closes: #1111252). * d/symbols: add new symbols for libzpool6linux. * d/install: install new zfs-mount@.service in zfsutils-linux. zfs-linux (2.3.4-1~bpo13+1) trixie-backports; urgency=medium . * Rebuild for trixie-backports. zfs-linux (2.3.4~git20250812.3b64a96-1) experimental; urgency=medium . [ Shengqi Chen ] * New upstream version 2.3.4~git20250812.3b64a96 (from zfs-2.3.4-staging). * d/patches: further patch pyzfs to fix error on debian pre-release version. * d/install: add new manpage for zfs-rewrite in zfsutils-linux. * d/symbols: remove missing symbol for libzpool6linux. * d/rules: install scripts/objtool-wrapper.in into dkms tree. . [ Attila Fülöp ] * d/rules: fix dkms build by retaining more fields in configure.ac. zfs-linux (2.3.3-1) unstable; urgency=medium . * New upstream version 2.3.3 (closes: #1106035, #1106556). * d/patches: refresh existing patches. * d/symbols: add symbols in new version, remove vanished ones. * d/copyright: remove deprecated FSF physical addresses. zfs-linux (2.3.3-1~bpo13+1) trixie-backports; urgency=medium . * Rebuild for trixie-backports. zip (3.0-15+deb13u1) trixie-security; urgency=high . * Fix command injection issue. Closes: #1143866. ======================================= Sat, 11 Jul 2026 - Debian 13.6 released ======================================= apache2 (2.4.68-1~deb13u1) trixie; urgency=medium . * New upstream version (Closes: CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913) * Drop CVE-2026-49975_*, now included in upstream * Update debian/convert_docs * Update test framework apache2 (2.4.68-1~deb12u1) bookworm; urgency=medium . * New upstream version (Closes: CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975) * Drop CVE-2026-49975_1.patch, now included in upstream * Drop CVE-2026-49975_2.patch, now included in upstream * Update debian/convert_docs * Update test framewaork apache2 (2.4.67-2) unstable; urgency=medium . * Fix a typo in NEWS file (Closes: #1135096) * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. apache2 (2.4.67-1) unstable; urgency=medium . * New upstream release (Closes: #1135737, CVE-2026-23918, CVE-2026-24072, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059) * Refresh patches apache2 (2.4.67-1~deb13u3) trixie-security; urgency=medium . * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. archlinux-keyring (0~20260420-1~deb13u1) trixie; urgency=medium . * gbp.conf: set branch to debian/trixie * salsa-ci.yml: set release to trixie . archlinux-keyring (0~20260420-1) unstable; urgency=medium . * Update standards version to 4.7.4 * Fix version mangling in debian/watch * New upstream version 0~20260420 . archlinux-keyring (0~20251116-1) unstable; urgency=medium . * New upstream version 0~20251116 * Fix debian/watch to also set dversionmangle and upgrade to v5 . archlinux-keyring (0~20250716-1) unstable; urgency=medium . * Add gbp.conf * New upstream version 0~20250716 archlinux-keyring (0~20251116-1) unstable; urgency=medium . * New upstream version 0~20251116 * Fix debian/watch to also set dversionmangle and upgrade to v5 archlinux-keyring (0~20250716-1) unstable; urgency=medium . * Add gbp.conf * New upstream version 0~20250716 atril (1.26.2-4+deb13u1) trixie-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2026-46529: command line argument injection (Closes: #1139874) awstats (7.9-1+deb13u2) trixie; urgency=medium . * Add upstream patch to fix freeze on keyword stat (Closes: #1135203) base-files (13.8+deb13u6) trixie; urgency=medium . * Update debian_version and os-release for Debian 13.6 point release. beets (2.2.0-3+deb13u1) trixie; urgency=medium . * Add patch to fix xss vulnerability CVE-2026-42052 in web ui (Closes: #1135779) * Add patch with test for unsafe web ui input bind9 (1:9.20.23-1~deb13u1) trixie-security; urgency=high . * New upstream version 9.20.23 + [CVE-2026-3592]: Limit resolver server list size. + [CVE-2026-3039]: Fix GSS-API resource leak. + [CVE-2026-5946]: Disable recursion, UPDATE, and NOTIFY for non-IN views. + [CVE-2026-5950]: Avoid unbounded recursion loop. + [CVE-2026-5947]: Fix crash in resolver when SIG(0)-signed responses are received under load. + [CVE-2026-3593]: Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. bind9 (1:9.20.23-1~deb13u1~bpo12+1) bookworm-backports; urgency=medium . * Rebuild for bookworm-backports. bind9 (1:9.20.22-1) unstable; urgency=medium . * New upstream version 9.20.22 bind9 (1:9.20.21-1) unstable; urgency=high . * New upstream version 9.20.21 - [CVE-2026-1519]: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. - [CVE-2026-3104]: Fix memory leaks in code preparing DNSSEC proofs of non-existence. - [CVE-2026-3119]: Prevent a crash in code processing queries containing a TKEY record. - [CVE-2026-3591]: Fix a stack use-after-return flaw in SIG(0) handling code. bird2 (2.17.5-0+deb13u1) trixie-security; urgency=medium . * New upstream release. bird2 (2.17.3-2) unstable; urgency=medium . * bird.service: fix the Environment directive. (Closes: #1123567) bird2 (2.17.3-1) unstable; urgency=medium . * New upstream release. * New maintainer. * Use Restart=on-abnormal instead of on-abort. (Closes: #1099513) * Do not install an example /etc/bird/bird.conf anymore, because there is no useful BIRD configuration that can be enabled by default. * Create /etc/bird/ with standard permissions: the local admin can use appropriate permission for bird.conf if access to it needs to be restricted. * Create the bird user with no home directory for added security. bird2 (2.17.2-1) unstable; urgency=medium . * New upstream version 2.17.2 * Update debian/watch for new BIRD download URL bird3 (3.1.7-0+deb13u1) trixie-security; urgency=medium . * New upstream release. bird3 (3.1.5-2) unstable; urgency=medium . * bird.service: fix the Environment directive. bird3 (3.1.5-1) unstable; urgency=medium . * New upstream release. * New maintainer. * Use Restart=on-abnormal instead of on-abort. (Closes: #1099513) * Do not install an example /etc/bird/bird.conf anymore, because there is no useful BIRD configuration that can be enabled by default. * Create /etc/bird/ with standard permissions: the local admin can use appropriate permission for bird.conf if access to it needs to be restricted. * Create the bird user with no home directory for added security. bird3 (3.1.4-1) unstable; urgency=medium . * New upstream version * Update debian/watch for new BIRD download URL calibre (8.5.0+ds-1+deb13u3) trixie; urgency=medium . * Fix security vulnerabilities and code quality issues (Closes: #1135543) * CVE-2026-30853: RB Input: Ensure files are extracted within container dir * CVE-2026-33205 (1/2): E-book viewer: prevent reading background images from outside the config dir * CVE-2026-33205 (2/2): E-book viewer: Disallow background images from the internet. This was an unused feature anyway * CVE-2026-33206: TXT Input: Ensure resource files are read only from book contents ceph (18.2.7+ds-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * mgr/alerts: enforce ssl context to SMTP_SSL (CVE-2024-31884) (Closes: #1126573) * Check if `HTTP_X_AMZ_COPY_SOURCE` header is empty (CVE-2024-47866) (Closes: #1120797) chromium (150.0.7871.100-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE list still to be announced. * debian/patches/ungoogled/remove-navigation-source-param.patch: fix crash related to the previous version's resynch. Thanks to plmaneo for the suggested patch (closes: #1141488). chromium (150.0.7871.100-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE list still to be announced. * debian/patches/ungoogled/remove-navigation-source-param.patch: fix crash related to the previous version's resynch. Thanks to plmaneo for the suggested patch (closes: #1141488). chromium (150.0.7871.46-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-13774: Use after free in Extensions. Reported by Google. - CVE-2026-13775: Use after free in GPU. Reported by Google. - CVE-2026-14398: Use after free in ANGLE. Reported by Google. - CVE-2026-13776: Type Confusion in Dawn. Reported by Google. - CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. Reported by Google. - CVE-2026-13778: Use after free in WebUSB. Reported by Google. - CVE-2026-13779: Use after free in Chromoting. Reported by Google. - CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13781: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14417: Use after free in Dawn. Reported by Google. - CVE-2026-13782: Use after free in Browser. Reported by Google. - CVE-2026-13783: Use after free in Views. Reported by Google. - CVE-2026-13784: Use after free in Views. Reported by Google. - CVE-2026-14419: Use after free in Skia. Reported by Google. - CVE-2026-13785: Use after free in Bluetooth. Reported by Google. - CVE-2026-14420: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-13786: Use after free in Ozone. Reported by Google. - CVE-2026-14427: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-13787: Use after free in Chromoting. Reported by Google. - CVE-2026-13788: Use after free in Fullscreen. Reported by Google. - CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous. - CVE-2026-13790: Side-channel information leakage in Scroll. Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer. - CVE-2026-14385: Heap buffer overflow in ANGLE. Reported by Thomas Guillem . - CVE-2026-13791: Insufficient validation of untrusted input in Downloads. Reported by Ron Masas (Imperva). - CVE-2026-13792: Use after free in Touchbar. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-13793: Insufficient policy enforcement in SVG. Reported by pakhunov.anton.n@gmail.com. - CVE-2026-14392: Out of bounds write in Tint. Reported by FastPL Group, Imperial College London. - CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. Reported by Daniel Rodríguez. - CVE-2026-14422: Out of bounds read and write in Tint. Reported by Michal Andryskowski. - CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. Reported by maitai. - CVE-2026-14426: Use after free in V8. Reported by ywatanabee. - CVE-2026-13796: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-14386: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13798: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-13799: Use after free in QUIC. Reported by Google. - CVE-2026-13800: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-13801: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13802: Use after free in Views. Reported by Google. - CVE-2026-13803: Type Confusion in Chrome Tabs. Reported by Google. - CVE-2026-13804: Use after free in Chromecast. Reported by Google. - CVE-2026-13805: Use after free in GFX. Reported by Google. - CVE-2026-14390: Use after free in ANGLE. Reported by Google. - CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. Reported by Google. - CVE-2026-13807: Use after free in Import. Reported by Google. - CVE-2026-13808: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-13809: Side-channel information leakage in Safe Browsing. Reported by Google. - CVE-2026-13810: Inappropriate implementation in Input. Reported by dilipsc03@gmail.com. - CVE-2026-13811: Use after free in IME. Reported by Google. - CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13814: Use after free in Views. Reported by Google. - CVE-2026-13815: Use after free in Blink. Reported by Google. - CVE-2026-13816: Insufficient validation of untrusted input in File Input. Reported by Google. - CVE-2026-14396: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13817: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-13818: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13819: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13820: Out of bounds read in Skia. Reported by Google. - CVE-2026-14400: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14401: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14402: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13821: Use after free in Canvas. Reported by Google. - CVE-2026-13822: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-13823: Use after free in Glic. Reported by Google. - CVE-2026-13824: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13825: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13826: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13827: Use after free in Updater. Reported by Google. - CVE-2026-13828: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-13829: Insufficient validation of untrusted input in Settings. Reported by Google. - CVE-2026-13830: Use after free in Chromoting. Reported by Google. - CVE-2026-13831: Use after free in GPU. Reported by Google. - CVE-2026-13832: Use after free in Headless. Reported by Google. - CVE-2026-14411: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13833: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14412: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14413: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13835: Inappropriate implementation in XML. Reported by Google. - CVE-2026-13836: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13837: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13838: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13839: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13840: Insufficient policy enforcement in Canvas. Reported by Binglin Song. - CVE-2026-13841: Integer overflow in Skia. Reported by Google. - CVE-2026-13842: Incorrect security UI in Chrome for iOS. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-14418: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13844: Use after free in Updater. Reported by Google. - CVE-2026-13845: Use after free in DOM. Reported by Google. - CVE-2026-13846: Use after free in USB. Reported by Google. - CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13848: Use after free in Forms. Reported by Google. - CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14423: Type Confusion in Tint. Reported by Google. - CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14424: Use after free in Dawn. Reported by Google. - CVE-2026-14425: Use after free in ANGLE. Reported by Google. - CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14428: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14429: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14430: Integer overflow in V8. Reported by Google. - CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13853: Use after free in Journeys. Reported by Google. - CVE-2026-13854: Use after free in Ozone. Reported by Google. - CVE-2026-14431: Type Confusion in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-13855: Use after free in Ozone. Reported by Google. - CVE-2026-13856: Insufficient validation of untrusted input in Speech. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-13857: Inappropriate implementation in Geometry. Reported by Luan Herrera (@lbherrera_). - CVE-2026-13858: Out of bounds read in FFmpeg. Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube). - CVE-2026-13859: Inappropriate implementation in ANGLE. Reported by Jason Villaluna. - CVE-2026-14391: Integer overflow in ANGLE. Reported by Quac Tran. - CVE-2026-13860: Incorrect security UI in Autofill. Reported by Khalil Zhani. - CVE-2026-14408: Uninitialized Use in Dawn. Reported by Chrovus. - CVE-2026-14381: Incorrect security UI in WebAppInstalls. Reported by Hafiizh. - CVE-2026-14383: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13861: Use after free in Core. Reported by Google. - CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys). Reported by Google. - CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13864: Insufficient policy enforcement in WebHID. Reported by Google. - CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13866: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-13867: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-13868: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14384: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13869: Use after free in Device. Reported by Google. - CVE-2026-13870: Use after free in WebView. Reported by Google. - CVE-2026-13871: Insufficient data validation in GuestView. Reported by Google. - CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13873: Out of bounds memory access in Layout. Reported by Google. - CVE-2026-13874: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13875: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-13876: Inappropriate implementation in Network. Reported by Google. - CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13878: Use after free in Bluetooth. Reported by Google. - CVE-2026-13879: Use after free in Bluetooth. Reported by Google. - CVE-2026-13880: Use after free in USB. Reported by Google. - CVE-2026-13881: Insufficient data validation in WebAppInstalls. Reported by Google. - CVE-2026-13882: Inappropriate implementation in USB. Reported by Google - CVE-2026-13883: Type Confusion in ANGLE. Reported by Google. - CVE-2026-13884: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-14387: Integer overflow in Skia. Reported by Google. - CVE-2026-13885: Use after free in Skia. Reported by Google. - CVE-2026-13886: Policy bypass in Isolated Web Apps. Reported by Google. - CVE-2026-14388: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-14389: Integer overflow in Skia. Reported by Google. - CVE-2026-13887: Insufficient policy enforcement in NFC. Reported by Google. - CVE-2026-13888: Use after free in Extensions. Reported by Google. - CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-13890: Out of bounds read in Chromecast. Reported by Google. - CVE-2026-13891: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13892: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13893: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-13894: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-13895: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13896: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-13897: Insufficient policy enforcement in Chromecast. Reported by Google. - CVE-2026-13898: Use after free in Cast Receiver. Reported by Google. - CVE-2026-13899: Use after free in HTML. Reported by Google. - CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-13901: Insufficient validation of untrusted input in Serial. Reported by Google. - CVE-2026-13902: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13903: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-13904: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13905: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13906: Out of bounds read in Codecs. Reported by Google. - CVE-2026-13907: Inappropriate implementation in iOSWeb. Reported by Google. - CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-13909: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-13910: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-13911: Insufficient data validation in Spellcheck. Reported by Google. - CVE-2026-13912: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13913: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-13914: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13915: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13916: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13918: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13919: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-14393: Use after free in V8. Reported by Google. - CVE-2026-13920: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-13922: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-13923: Uninitialized Use in GPU. Reported by Google. - CVE-2026-14397: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-13924: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-13925: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-13926: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-13927: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13929: Insufficient validation of untrusted input in DevTools. Reported by LegioSec. - CVE-2026-13930: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-13931: Inappropriate implementation in Media. Reported by Google. - CVE-2026-13932: Inappropriate implementation in Sharing. Reported by Google. - CVE-2026-13933: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13934: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14399: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13935: Side-channel information leakage in ComputePressure. Reported by Google. - CVE-2026-13936: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13937: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13938: Integer overflow in Fonts. Reported by Google. - CVE-2026-13939: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-13940: Uninitialized Use in Cast. Reported by Google. - CVE-2026-13941: Inappropriate implementation in SiteSettings. Reported by Google. - CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. Reported by Google. - CVE-2026-13943: Uninitialized Use in CSS. Reported by Google. - CVE-2026-13944: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13945: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13946: Inappropriate implementation in ScriptInjections. Reported by Google. - CVE-2026-13947: Uninitialized Use in XR. Reported by Google. - CVE-2026-13948: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13949: Insufficient policy enforcement in Payments. Reported by Google. - CVE-2026-14404: Inappropriate implementation in PDFium. Reported by Google. - CVE-2026-13950: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13951: Policy bypass in USB. Reported by Google. - CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. Reported by Google. - CVE-2026-14406: Out of bounds read in V8. Reported by Google. - CVE-2026-13953: Inappropriate implementation in SplitView. Reported by Google. - CVE-2026-13954: Insufficient policy enforcement in XML. Reported by Google. - CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13956: Incorrect security UI in PageInfo. Reported by Google. - CVE-2026-13957: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13958: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14407: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13959: Insufficient validation of untrusted input in Blink. Reported by Google. - CVE-2026-13960: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13961: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13962: Insufficient data validation in PDF. Reported by Google - CVE-2026-13963: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-13964: Insufficient policy enforcement in WebView. Reported by Google. - CVE-2026-13965: Use after free in Oilpan. Reported by Google. - CVE-2026-13966: Inappropriate implementation in History. Reported by Google. - CVE-2026-13967: Type Confusion in V8. Reported by Google. - CVE-2026-13968: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13969: Uninitialized Use in UI. Reported by Google. - CVE-2026-13970: Uninitialized Use in Media. Reported by Google. - CVE-2026-13971: Uninitialized Use in Skia. Reported by Google. - CVE-2026-13972: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13973: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13974: Integer overflow in Safe Browsing. Reported by Google. - CVE-2026-13975: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13976: Heap buffer overflow in Storage. Reported by Google. - CVE-2026-13977: Inappropriate implementation in HTMLParser. Reported by Google. - CVE-2026-13978: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-14414: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-13979: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13980: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13981: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13982: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-13983: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13984: Incorrect security UI in TabStrip. Reported by Google. - CVE-2026-13985: Inappropriate implementation in MediaCapture. Reported by Google. - CVE-2026-13986: Inappropriate implementation in Media UI. Reported by Google. - CVE-2026-13987: Incorrect security UI in Mobile. Reported by Google. - CVE-2026-13988: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13989: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13992: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13993: Incorrect security UI in WebAppInstalls. Reported by Google. - CVE-2026-13994: Inappropriate implementation in Credential Management. Reported by Google. - CVE-2026-13995: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-13996: Incorrect security UI in Permissions. Reported by Google. - CVE-2026-13997: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13998: Incorrect security UI in File Input. Reported by Google - CVE-2026-13999: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14000: Inappropriate implementation in XML. Reported by Google - CVE-2026-14001: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14002: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-14003: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14004: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14005: Use after free in Omnibox. Reported by Google. - CVE-2026-14006: Use after free in Navigation. Reported by Google. - CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. Reported by Google. - CVE-2026-14008: Uninitialized Use in WebXR. Reported by Google. - CVE-2026-14009: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-14010: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14011: Out of bounds read in SurfaceCapture. Reported by Google. - CVE-2026-14421: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-14012: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14013: Inappropriate implementation in SVG. Reported by Google - CVE-2026-14014: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-14015: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-14016: Insufficient policy enforcement in SVG. Reported by Google. - CVE-2026-14017: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-14018: Use after free in Updater. Reported by Google. - CVE-2026-14019: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-14020: Insufficient validation of untrusted input in WebXR. Reported by Google. - CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. Reported by Google. - CVE-2026-14022: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. Reported by Google. - CVE-2026-14024: Use after free in Ozone. Reported by Google. - CVE-2026-14432: Use after free in V8. Reported by Google. - CVE-2026-14025: Use after free in Views. Reported by asjidkalam. - CVE-2026-14026: Incorrect security UI in SplitView. Reported by adisahilna35@gmail.com. - CVE-2026-14027: Use after free in SignIn. Reported by Sven Dysthe (@svn-dys). - CVE-2026-14028: Incorrect security UI in Chrome for iOS. Reported by Ameen Basha M K. - CVE-2026-14030: Incorrect security UI in SplitView. Reported by Khalil Zhani. - CVE-2026-14031: Incorrect security UI in File Input. Reported by Google - CVE-2026-14032: Use after free in Bluetooth. Reported by Google. - CVE-2026-14033: Insufficient policy enforcement in Media. Reported by Google. - CVE-2026-14034: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14035: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14036: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14037: Insufficient policy enforcement in GPU. Reported by Google. - CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. Reported by Google. - CVE-2026-14040: Use after free in BrowserTag. Reported by Google. - CVE-2026-14041: Insufficient policy enforcement in Serial. Reported by Google. - CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-14043: Use after free in GetUserMedia. Reported by Google. - CVE-2026-14044: Use after free in ANGLE. Reported by Google. - CVE-2026-14045: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14046: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-14047: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14048: Use after free in Chromecast. Reported by Google. - CVE-2026-14049: Inappropriate implementation in GPU. Reported by Google - CVE-2026-14050: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-14051: Uninitialized Use in GamepadAPI. Reported by Google. - CVE-2026-14052: Insufficient policy enforcement in FileSystem. Reported by Google. - CVE-2026-14053: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14054: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. Reported by Google. - CVE-2026-14056: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-14057: Insufficient policy enforcement in FedCM. Reported by Google. - CVE-2026-14058: Policy bypass in Parser. Reported by Google. - CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. Reported by Google. - CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14061: Inappropriate implementation in Dawn. Reported by Google. - CVE-2026-14062: Inappropriate implementation in Views. Reported by Google. - CVE-2026-14063: Out of bounds memory access in Chromecast. Reported by Google. - CVE-2026-14064: Use after free in PageInfo. Reported by Google. - CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. Reported by Google. - CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14067: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14068: Inappropriate implementation in Omnibox. Reported by Google. - CVE-2026-14069: Integer overflow in WebNN. Reported by Google. - CVE-2026-14070: Uninitialized Use in WebNN. Reported by Google. - CVE-2026-14071: Side-channel information leakage in WebAudio. Reported by Google. - CVE-2026-14072: Incorrect security UI in SplitView. Reported by FARISSAL B. - CVE-2026-14073: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-14394: Use after free in V8. Reported by Google. - CVE-2026-14395: Out of bounds write in V8. Reported by Google. - CVE-2026-14074: Side-channel information leakage in WebAuthentication. Reported by Google. - CVE-2026-14075: Policy bypass in Chrome for iOS. Reported by Google. - CVE-2026-14076: Policy bypass in Network. Reported by Google. - CVE-2026-14077: Incorrect security UI in Select. Reported by pwn.ai. - CVE-2026-14078: Policy bypass in WebRTC. Reported by Google. - CVE-2026-14079: Policy bypass in Network. Reported by Google. - CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. Reported by Google. - CVE-2026-14081: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-14082: Race in Storage. Reported by Google. - CVE-2026-14083: Insufficient validation of untrusted input in HTML. Reported by Google. - CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14085: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14086: Insufficient policy enforcement in HID. Reported by Google. - CVE-2026-14087: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-14088: Uninitialized Use in Canvas. Reported by Google. - CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. Reported by Google. - CVE-2026-14090: Out of bounds read in CameraCapture. Reported by Google - CVE-2026-14091: Use after free in DevTools. Reported by Google. - CVE-2026-14092: Insufficient policy enforcement in Privacy. Reported by Google. - CVE-2026-14093: Use after free in Cast. Reported by Google. - CVE-2026-14094: Use after free in Installer. Reported by Google. - CVE-2026-14095: Insufficient validation of untrusted input in Browser. Reported by Google. - CVE-2026-14403: Use after free in V8. Reported by Google. - CVE-2026-14096: Object lifecycle issue in Input. Reported by Google. - CVE-2026-14097: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14098: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14405: Uninitialized Use in V8. Reported by Google. - CVE-2026-14099: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14100: Insufficient data validation in NetworkCache. Reported by Google. - CVE-2026-14101: Insufficient policy enforcement in Sandbox. Reported by Google. - CVE-2026-14102: Use after free in Passwords. Reported by Google. - CVE-2026-14103: Use after free in SSL. Reported by Google. - CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14105: Insufficient policy enforcement in Speech. Reported by Google. - CVE-2026-14106: Insufficient validation of untrusted input in Text. Reported by Google. - CVE-2026-14107: Use after free in Scheduling. Reported by Google. - CVE-2026-14108: Use after free in PDFium. Reported by Google. - CVE-2026-14109: Insufficient policy enforcement in Mojo. Reported by Google. - CVE-2026-14110: Inappropriate implementation in DarkMode. Reported by Google. - CVE-2026-14111: Use after free in WebProtect. Reported by Google. - CVE-2026-14112: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-14113: Use after free in Updater. Reported by Google. - CVE-2026-14114: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14115: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-14116: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14117: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14118: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-14119: Type Confusion in Bluetooth. Reported by Google. - CVE-2026-14120: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14121: Use after free in Chromoting. Reported by Google. - CVE-2026-14409: Inappropriate implementation in V8. Reported by Yuntao You (@GraVity0) of Bytedance Wuheng Lab. - CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14410: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-14123: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14124: Inappropriate implementation in CredentialProvider. Reported by Google. - CVE-2026-14125: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14126: Incorrect security UI in UI. Reported by Google. - CVE-2026-14127: Inappropriate implementation in Printing. Reported by Google. - CVE-2026-14128: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-14129: Incorrect security UI in PreviewTab. Reported by Google - CVE-2026-14130: Incorrect security UI in Omnibox. Reported by Google. - CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14132: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14133: Race in History Embeddings. Reported by Google. - CVE-2026-14134: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-14135: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14136: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14138: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14139: Inappropriate implementation in TabStrip. Reported by Google. - CVE-2026-14140: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. Reported by Google. - CVE-2026-14142: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14143: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-14144: Incorrect security UI in Views. Reported by Google. - CVE-2026-14145: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14146: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14147: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14415: Inappropriate implementation in V8. Reported by Google. - CVE-2026-14148: Type Confusion in CSS. Reported by Google. - CVE-2026-14149: Use after free in Audio. Reported by Google. - CVE-2026-14416: Out of bounds read in Dawn. Reported by Google. - CVE-2026-14150: Insufficient validation of untrusted input in Speech. Reported by Google. - CVE-2026-14151: Inappropriate implementation in AI. Reported by Google. - CVE-2026-14152: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14153: Inappropriate implementation in Glic. Reported by Google. - CVE-2026-14154: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. Reported by Google. - CVE-2026-14156: Policy bypass in StorageAccessAPI. Reported by Google. - CVE-2026-13281: Integer overflow in Mojo. Reported by Google. - CVE-2026-13282: Use after free in Payments. Reported by Google. - CVE-2026-13283: Use after free in AdFilter. Reported by Google. * d/copyright: - delete third_party/webpagereplay/. - delete tsgo (typescript compiler in Go) binary. * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: drop, merged upstream. - disable/android.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/libcpp-headers.patch: rework parts of the patch due to upstream changes. - disable/catapult.patch: refresh. - disable/tests.patch: refresh. - llvm-19/clang19.patch: refresh. - trixie/gn-expand-dir-allowlist.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - i386/support-i386.patch: refresh. - upstream/sysroot.patch: add a new build fix pulled from upstream. - upstream/ar-path1.patch, upstream/ar-path2.patch: add two more vendoring-related build fixes from upstream. - trixie/gn-additional-outputs.patch: add patch to partially revert usage of a newer generate-ninja feature. - llvm-19/i18n-builder-enum.patch: add a workaround for clang-19 being confused between a class declaration (with default template parameter) and definition. - llvm-19/00*-revert-v8-libm.patch: add 9 patches backing out usage of internal libc++/libm symbols; this requires a newer llvm than we have. - llvm-19/value-or.patch: work around more places where value_or() can't figure out the type of a passed init value. - trixie/node20-compat.patch: break out part of Daniel's node18-compat.patch (below) into one for trixie that also fixes nodejs 20 issues [trixie, bookworm]. - rust-1.85/std-from-utf8.patch: add workaround for str::from_utf8 added in 1.87 [trixie, bookworm]. - trixie/bindgen-boringssl.patch: add workaround for older bindgen [trixie, bookworm]. . [ Daniel Richard G. ] * d/patches: - bookworm/gn-absl.patch: Refresh [bookworm]. - bookworm/gn-funcs.patch: Zap new usage of filter_labels_include() [bookworm]. - bookworm/node18-compat.patch: Fix more cases of nodejs v18 breakage [bookworm]. - trixie/gn-module-name.patch: add more spots where the workaround is needed [trixie, bookworm]. . [ Jianfeng Liu ] * d/patches: - upstream/libyuv-loongarch-fix-row_lsx.cc-and-row_lasx.cc.patch: Fix build for libyuv loongarch64. - loongarch64/0015-ffmpeg-support-for-loongarch.patch: Refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - fixes/fix-rust-linking.patch: refresh for upstream changes - fixes/fix-breakpad-compile.patch: refresh for upstream changes - third_party/dawn-fix-ppc64le-detection.patch: refresh for upstream changes - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes chromium (150.0.7871.46-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-13774: Use after free in Extensions. Reported by Google. - CVE-2026-13775: Use after free in GPU. Reported by Google. - CVE-2026-14398: Use after free in ANGLE. Reported by Google. - CVE-2026-13776: Type Confusion in Dawn. Reported by Google. - CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. Reported by Google. - CVE-2026-13778: Use after free in WebUSB. Reported by Google. - CVE-2026-13779: Use after free in Chromoting. Reported by Google. - CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13781: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14417: Use after free in Dawn. Reported by Google. - CVE-2026-13782: Use after free in Browser. Reported by Google. - CVE-2026-13783: Use after free in Views. Reported by Google. - CVE-2026-13784: Use after free in Views. Reported by Google. - CVE-2026-14419: Use after free in Skia. Reported by Google. - CVE-2026-13785: Use after free in Bluetooth. Reported by Google. - CVE-2026-14420: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-13786: Use after free in Ozone. Reported by Google. - CVE-2026-14427: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-13787: Use after free in Chromoting. Reported by Google. - CVE-2026-13788: Use after free in Fullscreen. Reported by Google. - CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous. - CVE-2026-13790: Side-channel information leakage in Scroll. Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer. - CVE-2026-14385: Heap buffer overflow in ANGLE. Reported by Thomas Guillem . - CVE-2026-13791: Insufficient validation of untrusted input in Downloads. Reported by Ron Masas (Imperva). - CVE-2026-13792: Use after free in Touchbar. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-13793: Insufficient policy enforcement in SVG. Reported by pakhunov.anton.n@gmail.com. - CVE-2026-14392: Out of bounds write in Tint. Reported by FastPL Group, Imperial College London. - CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. Reported by Daniel Rodríguez. - CVE-2026-14422: Out of bounds read and write in Tint. Reported by Michal Andryskowski. - CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. Reported by maitai. - CVE-2026-14426: Use after free in V8. Reported by ywatanabee. - CVE-2026-13796: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-14386: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13798: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-13799: Use after free in QUIC. Reported by Google. - CVE-2026-13800: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-13801: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13802: Use after free in Views. Reported by Google. - CVE-2026-13803: Type Confusion in Chrome Tabs. Reported by Google. - CVE-2026-13804: Use after free in Chromecast. Reported by Google. - CVE-2026-13805: Use after free in GFX. Reported by Google. - CVE-2026-14390: Use after free in ANGLE. Reported by Google. - CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. Reported by Google. - CVE-2026-13807: Use after free in Import. Reported by Google. - CVE-2026-13808: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-13809: Side-channel information leakage in Safe Browsing. Reported by Google. - CVE-2026-13810: Inappropriate implementation in Input. Reported by dilipsc03@gmail.com. - CVE-2026-13811: Use after free in IME. Reported by Google. - CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13814: Use after free in Views. Reported by Google. - CVE-2026-13815: Use after free in Blink. Reported by Google. - CVE-2026-13816: Insufficient validation of untrusted input in File Input. Reported by Google. - CVE-2026-14396: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13817: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-13818: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13819: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13820: Out of bounds read in Skia. Reported by Google. - CVE-2026-14400: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14401: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14402: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13821: Use after free in Canvas. Reported by Google. - CVE-2026-13822: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-13823: Use after free in Glic. Reported by Google. - CVE-2026-13824: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13825: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13826: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13827: Use after free in Updater. Reported by Google. - CVE-2026-13828: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-13829: Insufficient validation of untrusted input in Settings. Reported by Google. - CVE-2026-13830: Use after free in Chromoting. Reported by Google. - CVE-2026-13831: Use after free in GPU. Reported by Google. - CVE-2026-13832: Use after free in Headless. Reported by Google. - CVE-2026-14411: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13833: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14412: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14413: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13835: Inappropriate implementation in XML. Reported by Google. - CVE-2026-13836: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13837: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13838: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13839: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13840: Insufficient policy enforcement in Canvas. Reported by Binglin Song. - CVE-2026-13841: Integer overflow in Skia. Reported by Google. - CVE-2026-13842: Incorrect security UI in Chrome for iOS. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-14418: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13844: Use after free in Updater. Reported by Google. - CVE-2026-13845: Use after free in DOM. Reported by Google. - CVE-2026-13846: Use after free in USB. Reported by Google. - CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13848: Use after free in Forms. Reported by Google. - CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14423: Type Confusion in Tint. Reported by Google. - CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14424: Use after free in Dawn. Reported by Google. - CVE-2026-14425: Use after free in ANGLE. Reported by Google. - CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14428: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14429: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14430: Integer overflow in V8. Reported by Google. - CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13853: Use after free in Journeys. Reported by Google. - CVE-2026-13854: Use after free in Ozone. Reported by Google. - CVE-2026-14431: Type Confusion in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-13855: Use after free in Ozone. Reported by Google. - CVE-2026-13856: Insufficient validation of untrusted input in Speech. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-13857: Inappropriate implementation in Geometry. Reported by Luan Herrera (@lbherrera_). - CVE-2026-13858: Out of bounds read in FFmpeg. Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube). - CVE-2026-13859: Inappropriate implementation in ANGLE. Reported by Jason Villaluna. - CVE-2026-14391: Integer overflow in ANGLE. Reported by Quac Tran. - CVE-2026-13860: Incorrect security UI in Autofill. Reported by Khalil Zhani. - CVE-2026-14408: Uninitialized Use in Dawn. Reported by Chrovus. - CVE-2026-14381: Incorrect security UI in WebAppInstalls. Reported by Hafiizh. - CVE-2026-14383: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13861: Use after free in Core. Reported by Google. - CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys). Reported by Google. - CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13864: Insufficient policy enforcement in WebHID. Reported by Google. - CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13866: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-13867: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-13868: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14384: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13869: Use after free in Device. Reported by Google. - CVE-2026-13870: Use after free in WebView. Reported by Google. - CVE-2026-13871: Insufficient data validation in GuestView. Reported by Google. - CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13873: Out of bounds memory access in Layout. Reported by Google. - CVE-2026-13874: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13875: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-13876: Inappropriate implementation in Network. Reported by Google. - CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13878: Use after free in Bluetooth. Reported by Google. - CVE-2026-13879: Use after free in Bluetooth. Reported by Google. - CVE-2026-13880: Use after free in USB. Reported by Google. - CVE-2026-13881: Insufficient data validation in WebAppInstalls. Reported by Google. - CVE-2026-13882: Inappropriate implementation in USB. Reported by Google - CVE-2026-13883: Type Confusion in ANGLE. Reported by Google. - CVE-2026-13884: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-14387: Integer overflow in Skia. Reported by Google. - CVE-2026-13885: Use after free in Skia. Reported by Google. - CVE-2026-13886: Policy bypass in Isolated Web Apps. Reported by Google. - CVE-2026-14388: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-14389: Integer overflow in Skia. Reported by Google. - CVE-2026-13887: Insufficient policy enforcement in NFC. Reported by Google. - CVE-2026-13888: Use after free in Extensions. Reported by Google. - CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-13890: Out of bounds read in Chromecast. Reported by Google. - CVE-2026-13891: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13892: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13893: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-13894: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-13895: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13896: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-13897: Insufficient policy enforcement in Chromecast. Reported by Google. - CVE-2026-13898: Use after free in Cast Receiver. Reported by Google. - CVE-2026-13899: Use after free in HTML. Reported by Google. - CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-13901: Insufficient validation of untrusted input in Serial. Reported by Google. - CVE-2026-13902: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13903: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-13904: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13905: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13906: Out of bounds read in Codecs. Reported by Google. - CVE-2026-13907: Inappropriate implementation in iOSWeb. Reported by Google. - CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-13909: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-13910: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-13911: Insufficient data validation in Spellcheck. Reported by Google. - CVE-2026-13912: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13913: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-13914: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13915: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13916: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13918: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13919: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-14393: Use after free in V8. Reported by Google. - CVE-2026-13920: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-13922: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-13923: Uninitialized Use in GPU. Reported by Google. - CVE-2026-14397: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-13924: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-13925: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-13926: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-13927: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13929: Insufficient validation of untrusted input in DevTools. Reported by LegioSec. - CVE-2026-13930: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-13931: Inappropriate implementation in Media. Reported by Google. - CVE-2026-13932: Inappropriate implementation in Sharing. Reported by Google. - CVE-2026-13933: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13934: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14399: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13935: Side-channel information leakage in ComputePressure. Reported by Google. - CVE-2026-13936: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13937: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13938: Integer overflow in Fonts. Reported by Google. - CVE-2026-13939: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-13940: Uninitialized Use in Cast. Reported by Google. - CVE-2026-13941: Inappropriate implementation in SiteSettings. Reported by Google. - CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. Reported by Google. - CVE-2026-13943: Uninitialized Use in CSS. Reported by Google. - CVE-2026-13944: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13945: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13946: Inappropriate implementation in ScriptInjections. Reported by Google. - CVE-2026-13947: Uninitialized Use in XR. Reported by Google. - CVE-2026-13948: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13949: Insufficient policy enforcement in Payments. Reported by Google. - CVE-2026-14404: Inappropriate implementation in PDFium. Reported by Google. - CVE-2026-13950: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13951: Policy bypass in USB. Reported by Google. - CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. Reported by Google. - CVE-2026-14406: Out of bounds read in V8. Reported by Google. - CVE-2026-13953: Inappropriate implementation in SplitView. Reported by Google. - CVE-2026-13954: Insufficient policy enforcement in XML. Reported by Google. - CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13956: Incorrect security UI in PageInfo. Reported by Google. - CVE-2026-13957: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13958: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14407: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13959: Insufficient validation of untrusted input in Blink. Reported by Google. - CVE-2026-13960: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13961: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13962: Insufficient data validation in PDF. Reported by Google - CVE-2026-13963: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-13964: Insufficient policy enforcement in WebView. Reported by Google. - CVE-2026-13965: Use after free in Oilpan. Reported by Google. - CVE-2026-13966: Inappropriate implementation in History. Reported by Google. - CVE-2026-13967: Type Confusion in V8. Reported by Google. - CVE-2026-13968: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13969: Uninitialized Use in UI. Reported by Google. - CVE-2026-13970: Uninitialized Use in Media. Reported by Google. - CVE-2026-13971: Uninitialized Use in Skia. Reported by Google. - CVE-2026-13972: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13973: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13974: Integer overflow in Safe Browsing. Reported by Google. - CVE-2026-13975: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13976: Heap buffer overflow in Storage. Reported by Google. - CVE-2026-13977: Inappropriate implementation in HTMLParser. Reported by Google. - CVE-2026-13978: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-14414: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-13979: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13980: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13981: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13982: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-13983: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13984: Incorrect security UI in TabStrip. Reported by Google. - CVE-2026-13985: Inappropriate implementation in MediaCapture. Reported by Google. - CVE-2026-13986: Inappropriate implementation in Media UI. Reported by Google. - CVE-2026-13987: Incorrect security UI in Mobile. Reported by Google. - CVE-2026-13988: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13989: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13992: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13993: Incorrect security UI in WebAppInstalls. Reported by Google. - CVE-2026-13994: Inappropriate implementation in Credential Management. Reported by Google. - CVE-2026-13995: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-13996: Incorrect security UI in Permissions. Reported by Google. - CVE-2026-13997: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13998: Incorrect security UI in File Input. Reported by Google - CVE-2026-13999: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14000: Inappropriate implementation in XML. Reported by Google - CVE-2026-14001: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14002: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-14003: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14004: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14005: Use after free in Omnibox. Reported by Google. - CVE-2026-14006: Use after free in Navigation. Reported by Google. - CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. Reported by Google. - CVE-2026-14008: Uninitialized Use in WebXR. Reported by Google. - CVE-2026-14009: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-14010: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14011: Out of bounds read in SurfaceCapture. Reported by Google. - CVE-2026-14421: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-14012: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14013: Inappropriate implementation in SVG. Reported by Google - CVE-2026-14014: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-14015: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-14016: Insufficient policy enforcement in SVG. Reported by Google. - CVE-2026-14017: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-14018: Use after free in Updater. Reported by Google. - CVE-2026-14019: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-14020: Insufficient validation of untrusted input in WebXR. Reported by Google. - CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. Reported by Google. - CVE-2026-14022: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. Reported by Google. - CVE-2026-14024: Use after free in Ozone. Reported by Google. - CVE-2026-14432: Use after free in V8. Reported by Google. - CVE-2026-14025: Use after free in Views. Reported by asjidkalam. - CVE-2026-14026: Incorrect security UI in SplitView. Reported by adisahilna35@gmail.com. - CVE-2026-14027: Use after free in SignIn. Reported by Sven Dysthe (@svn-dys). - CVE-2026-14028: Incorrect security UI in Chrome for iOS. Reported by Ameen Basha M K. - CVE-2026-14030: Incorrect security UI in SplitView. Reported by Khalil Zhani. - CVE-2026-14031: Incorrect security UI in File Input. Reported by Google - CVE-2026-14032: Use after free in Bluetooth. Reported by Google. - CVE-2026-14033: Insufficient policy enforcement in Media. Reported by Google. - CVE-2026-14034: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14035: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14036: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14037: Insufficient policy enforcement in GPU. Reported by Google. - CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. Reported by Google. - CVE-2026-14040: Use after free in BrowserTag. Reported by Google. - CVE-2026-14041: Insufficient policy enforcement in Serial. Reported by Google. - CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-14043: Use after free in GetUserMedia. Reported by Google. - CVE-2026-14044: Use after free in ANGLE. Reported by Google. - CVE-2026-14045: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14046: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-14047: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14048: Use after free in Chromecast. Reported by Google. - CVE-2026-14049: Inappropriate implementation in GPU. Reported by Google - CVE-2026-14050: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-14051: Uninitialized Use in GamepadAPI. Reported by Google. - CVE-2026-14052: Insufficient policy enforcement in FileSystem. Reported by Google. - CVE-2026-14053: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14054: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. Reported by Google. - CVE-2026-14056: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-14057: Insufficient policy enforcement in FedCM. Reported by Google. - CVE-2026-14058: Policy bypass in Parser. Reported by Google. - CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. Reported by Google. - CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14061: Inappropriate implementation in Dawn. Reported by Google. - CVE-2026-14062: Inappropriate implementation in Views. Reported by Google. - CVE-2026-14063: Out of bounds memory access in Chromecast. Reported by Google. - CVE-2026-14064: Use after free in PageInfo. Reported by Google. - CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. Reported by Google. - CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14067: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14068: Inappropriate implementation in Omnibox. Reported by Google. - CVE-2026-14069: Integer overflow in WebNN. Reported by Google. - CVE-2026-14070: Uninitialized Use in WebNN. Reported by Google. - CVE-2026-14071: Side-channel information leakage in WebAudio. Reported by Google. - CVE-2026-14072: Incorrect security UI in SplitView. Reported by FARISSAL B. - CVE-2026-14073: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-14394: Use after free in V8. Reported by Google. - CVE-2026-14395: Out of bounds write in V8. Reported by Google. - CVE-2026-14074: Side-channel information leakage in WebAuthentication. Reported by Google. - CVE-2026-14075: Policy bypass in Chrome for iOS. Reported by Google. - CVE-2026-14076: Policy bypass in Network. Reported by Google. - CVE-2026-14077: Incorrect security UI in Select. Reported by pwn.ai. - CVE-2026-14078: Policy bypass in WebRTC. Reported by Google. - CVE-2026-14079: Policy bypass in Network. Reported by Google. - CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. Reported by Google. - CVE-2026-14081: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-14082: Race in Storage. Reported by Google. - CVE-2026-14083: Insufficient validation of untrusted input in HTML. Reported by Google. - CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14085: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14086: Insufficient policy enforcement in HID. Reported by Google. - CVE-2026-14087: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-14088: Uninitialized Use in Canvas. Reported by Google. - CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. Reported by Google. - CVE-2026-14090: Out of bounds read in CameraCapture. Reported by Google - CVE-2026-14091: Use after free in DevTools. Reported by Google. - CVE-2026-14092: Insufficient policy enforcement in Privacy. Reported by Google. - CVE-2026-14093: Use after free in Cast. Reported by Google. - CVE-2026-14094: Use after free in Installer. Reported by Google. - CVE-2026-14095: Insufficient validation of untrusted input in Browser. Reported by Google. - CVE-2026-14403: Use after free in V8. Reported by Google. - CVE-2026-14096: Object lifecycle issue in Input. Reported by Google. - CVE-2026-14097: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14098: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14405: Uninitialized Use in V8. Reported by Google. - CVE-2026-14099: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14100: Insufficient data validation in NetworkCache. Reported by Google. - CVE-2026-14101: Insufficient policy enforcement in Sandbox. Reported by Google. - CVE-2026-14102: Use after free in Passwords. Reported by Google. - CVE-2026-14103: Use after free in SSL. Reported by Google. - CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14105: Insufficient policy enforcement in Speech. Reported by Google. - CVE-2026-14106: Insufficient validation of untrusted input in Text. Reported by Google. - CVE-2026-14107: Use after free in Scheduling. Reported by Google. - CVE-2026-14108: Use after free in PDFium. Reported by Google. - CVE-2026-14109: Insufficient policy enforcement in Mojo. Reported by Google. - CVE-2026-14110: Inappropriate implementation in DarkMode. Reported by Google. - CVE-2026-14111: Use after free in WebProtect. Reported by Google. - CVE-2026-14112: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-14113: Use after free in Updater. Reported by Google. - CVE-2026-14114: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14115: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-14116: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14117: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14118: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-14119: Type Confusion in Bluetooth. Reported by Google. - CVE-2026-14120: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14121: Use after free in Chromoting. Reported by Google. - CVE-2026-14409: Inappropriate implementation in V8. Reported by Yuntao You (@GraVity0) of Bytedance Wuheng Lab. - CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14410: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-14123: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14124: Inappropriate implementation in CredentialProvider. Reported by Google. - CVE-2026-14125: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14126: Incorrect security UI in UI. Reported by Google. - CVE-2026-14127: Inappropriate implementation in Printing. Reported by Google. - CVE-2026-14128: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-14129: Incorrect security UI in PreviewTab. Reported by Google - CVE-2026-14130: Incorrect security UI in Omnibox. Reported by Google. - CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14132: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14133: Race in History Embeddings. Reported by Google. - CVE-2026-14134: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-14135: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14136: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14138: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14139: Inappropriate implementation in TabStrip. Reported by Google. - CVE-2026-14140: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. Reported by Google. - CVE-2026-14142: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14143: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-14144: Incorrect security UI in Views. Reported by Google. - CVE-2026-14145: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14146: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14147: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14415: Inappropriate implementation in V8. Reported by Google. - CVE-2026-14148: Type Confusion in CSS. Reported by Google. - CVE-2026-14149: Use after free in Audio. Reported by Google. - CVE-2026-14416: Out of bounds read in Dawn. Reported by Google. - CVE-2026-14150: Insufficient validation of untrusted input in Speech. Reported by Google. - CVE-2026-14151: Inappropriate implementation in AI. Reported by Google. - CVE-2026-14152: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14153: Inappropriate implementation in Glic. Reported by Google. - CVE-2026-14154: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. Reported by Google. - CVE-2026-14156: Policy bypass in StorageAccessAPI. Reported by Google. - CVE-2026-13281: Integer overflow in Mojo. Reported by Google. - CVE-2026-13282: Use after free in Payments. Reported by Google. - CVE-2026-13283: Use after free in AdFilter. Reported by Google. * d/copyright: - delete third_party/webpagereplay/. - delete tsgo (typescript compiler in Go) binary. * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: drop, merged upstream. - disable/android.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/libcpp-headers.patch: rework parts of the patch due to upstream changes. - disable/catapult.patch: refresh. - disable/tests.patch: refresh. - llvm-19/clang19.patch: refresh. - trixie/gn-expand-dir-allowlist.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - i386/support-i386.patch: refresh. - upstream/sysroot.patch: add a new build fix pulled from upstream. - upstream/ar-path1.patch, upstream/ar-path2.patch: add two more vendoring-related build fixes from upstream. - trixie/gn-additional-outputs.patch: add patch to partially revert usage of a newer generate-ninja feature. - llvm-19/i18n-builder-enum.patch: add a workaround for clang-19 being confused between a class declaration (with default template parameter) and definition. - llvm-19/00*-revert-v8-libm.patch: add 9 patches backing out usage of internal libc++/libm symbols; this requires a newer llvm than we have. - llvm-19/value-or.patch: work around more places where value_or() can't figure out the type of a passed init value. - trixie/node20-compat.patch: break out part of Daniel's node18-compat.patch (below) into one for trixie that also fixes nodejs 20 issues [trixie, bookworm]. - rust-1.85/std-from-utf8.patch: add workaround for str::from_utf8 added in 1.87 [trixie, bookworm]. - trixie/bindgen-boringssl.patch: add workaround for older bindgen [trixie, bookworm]. . [ Daniel Richard G. ] * d/patches: - bookworm/gn-absl.patch: Refresh [bookworm]. - bookworm/gn-funcs.patch: Zap new usage of filter_labels_include() [bookworm]. - bookworm/node18-compat.patch: Fix more cases of nodejs v18 breakage [bookworm]. - trixie/gn-module-name.patch: add more spots where the workaround is needed [trixie, bookworm]. . [ Jianfeng Liu ] * d/patches: - upstream/libyuv-loongarch-fix-row_lsx.cc-and-row_lasx.cc.patch: Fix build for libyuv loongarch64. - loongarch64/0015-ffmpeg-support-for-loongarch.patch: Refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - fixes/fix-rust-linking.patch: refresh for upstream changes - fixes/fix-breakpad-compile.patch: refresh for upstream changes - third_party/dawn-fix-ppc64le-detection.patch: refresh for upstream changes - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes chromium (150.0.7871.46-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-13774: Use after free in Extensions. Reported by Google. - CVE-2026-13775: Use after free in GPU. Reported by Google. - CVE-2026-14398: Use after free in ANGLE. Reported by Google. - CVE-2026-13776: Type Confusion in Dawn. Reported by Google. - CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. Reported by Google. - CVE-2026-13778: Use after free in WebUSB. Reported by Google. - CVE-2026-13779: Use after free in Chromoting. Reported by Google. - CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13781: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14417: Use after free in Dawn. Reported by Google. - CVE-2026-13782: Use after free in Browser. Reported by Google. - CVE-2026-13783: Use after free in Views. Reported by Google. - CVE-2026-13784: Use after free in Views. Reported by Google. - CVE-2026-14419: Use after free in Skia. Reported by Google. - CVE-2026-13785: Use after free in Bluetooth. Reported by Google. - CVE-2026-14420: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-13786: Use after free in Ozone. Reported by Google. - CVE-2026-14427: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-13787: Use after free in Chromoting. Reported by Google. - CVE-2026-13788: Use after free in Fullscreen. Reported by Google. - CVE-2026-14382: Insufficient validation of untrusted input in ANGLE. Reported by anonymous. - CVE-2026-13790: Side-channel information leakage in Scroll. Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer. - CVE-2026-14385: Heap buffer overflow in ANGLE. Reported by Thomas Guillem . - CVE-2026-13791: Insufficient validation of untrusted input in Downloads. Reported by Ron Masas (Imperva). - CVE-2026-13792: Use after free in Touchbar. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-13793: Insufficient policy enforcement in SVG. Reported by pakhunov.anton.n@gmail.com. - CVE-2026-14392: Out of bounds write in Tint. Reported by FastPL Group, Imperial College London. - CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. Reported by Daniel Rodríguez. - CVE-2026-14422: Out of bounds read and write in Tint. Reported by Michal Andryskowski. - CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. Reported by maitai. - CVE-2026-14426: Use after free in V8. Reported by ywatanabee. - CVE-2026-13796: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-14386: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13798: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-13799: Use after free in QUIC. Reported by Google. - CVE-2026-13800: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-13801: Integer overflow in Chromecast. Reported by Google. - CVE-2026-13802: Use after free in Views. Reported by Google. - CVE-2026-13803: Type Confusion in Chrome Tabs. Reported by Google. - CVE-2026-13804: Use after free in Chromecast. Reported by Google. - CVE-2026-13805: Use after free in GFX. Reported by Google. - CVE-2026-14390: Use after free in ANGLE. Reported by Google. - CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. Reported by Google. - CVE-2026-13807: Use after free in Import. Reported by Google. - CVE-2026-13808: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-13809: Side-channel information leakage in Safe Browsing. Reported by Google. - CVE-2026-13810: Inappropriate implementation in Input. Reported by dilipsc03@gmail.com. - CVE-2026-13811: Use after free in IME. Reported by Google. - CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13814: Use after free in Views. Reported by Google. - CVE-2026-13815: Use after free in Blink. Reported by Google. - CVE-2026-13816: Insufficient validation of untrusted input in File Input. Reported by Google. - CVE-2026-14396: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13817: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-13818: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13819: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13820: Out of bounds read in Skia. Reported by Google. - CVE-2026-14400: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14401: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14402: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13821: Use after free in Canvas. Reported by Google. - CVE-2026-13822: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-13823: Use after free in Glic. Reported by Google. - CVE-2026-13824: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13825: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13826: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13827: Use after free in Updater. Reported by Google. - CVE-2026-13828: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-13829: Insufficient validation of untrusted input in Settings. Reported by Google. - CVE-2026-13830: Use after free in Chromoting. Reported by Google. - CVE-2026-13831: Use after free in GPU. Reported by Google. - CVE-2026-13832: Use after free in Headless. Reported by Google. - CVE-2026-14411: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13833: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14412: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-14413: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13835: Inappropriate implementation in XML. Reported by Google. - CVE-2026-13836: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13837: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13838: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13839: Inappropriate implementation in CSS. Reported by Google. - CVE-2026-13840: Insufficient policy enforcement in Canvas. Reported by Binglin Song. - CVE-2026-13841: Integer overflow in Skia. Reported by Google. - CVE-2026-13842: Incorrect security UI in Chrome for iOS. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-14418: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13844: Use after free in Updater. Reported by Google. - CVE-2026-13845: Use after free in DOM. Reported by Google. - CVE-2026-13846: Use after free in USB. Reported by Google. - CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13848: Use after free in Forms. Reported by Google. - CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14423: Type Confusion in Tint. Reported by Google. - CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14424: Use after free in Dawn. Reported by Google. - CVE-2026-14425: Use after free in ANGLE. Reported by Google. - CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14428: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14429: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-14430: Integer overflow in V8. Reported by Google. - CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13853: Use after free in Journeys. Reported by Google. - CVE-2026-13854: Use after free in Ozone. Reported by Google. - CVE-2026-14431: Type Confusion in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-13855: Use after free in Ozone. Reported by Google. - CVE-2026-13856: Insufficient validation of untrusted input in Speech. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-13857: Inappropriate implementation in Geometry. Reported by Luan Herrera (@lbherrera_). - CVE-2026-13858: Out of bounds read in FFmpeg. Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube). - CVE-2026-13859: Inappropriate implementation in ANGLE. Reported by Jason Villaluna. - CVE-2026-14391: Integer overflow in ANGLE. Reported by Quac Tran. - CVE-2026-13860: Incorrect security UI in Autofill. Reported by Khalil Zhani. - CVE-2026-14408: Uninitialized Use in Dawn. Reported by Chrovus. - CVE-2026-14381: Incorrect security UI in WebAppInstalls. Reported by Hafiizh. - CVE-2026-14383: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13861: Use after free in Core. Reported by Google. - CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys). Reported by Google. - CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13864: Insufficient policy enforcement in WebHID. Reported by Google. - CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13866: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-13867: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-13868: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14384: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13869: Use after free in Device. Reported by Google. - CVE-2026-13870: Use after free in WebView. Reported by Google. - CVE-2026-13871: Insufficient data validation in GuestView. Reported by Google. - CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-13873: Out of bounds memory access in Layout. Reported by Google. - CVE-2026-13874: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13875: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-13876: Inappropriate implementation in Network. Reported by Google. - CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-13878: Use after free in Bluetooth. Reported by Google. - CVE-2026-13879: Use after free in Bluetooth. Reported by Google. - CVE-2026-13880: Use after free in USB. Reported by Google. - CVE-2026-13881: Insufficient data validation in WebAppInstalls. Reported by Google. - CVE-2026-13882: Inappropriate implementation in USB. Reported by Google - CVE-2026-13883: Type Confusion in ANGLE. Reported by Google. - CVE-2026-13884: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-14387: Integer overflow in Skia. Reported by Google. - CVE-2026-13885: Use after free in Skia. Reported by Google. - CVE-2026-13886: Policy bypass in Isolated Web Apps. Reported by Google. - CVE-2026-14388: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-14389: Integer overflow in Skia. Reported by Google. - CVE-2026-13887: Insufficient policy enforcement in NFC. Reported by Google. - CVE-2026-13888: Use after free in Extensions. Reported by Google. - CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-13890: Out of bounds read in Chromecast. Reported by Google. - CVE-2026-13891: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-13892: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13893: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-13894: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-13895: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13896: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-13897: Insufficient policy enforcement in Chromecast. Reported by Google. - CVE-2026-13898: Use after free in Cast Receiver. Reported by Google. - CVE-2026-13899: Use after free in HTML. Reported by Google. - CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-13901: Insufficient validation of untrusted input in Serial. Reported by Google. - CVE-2026-13902: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13903: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-13904: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13905: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13906: Out of bounds read in Codecs. Reported by Google. - CVE-2026-13907: Inappropriate implementation in iOSWeb. Reported by Google. - CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-13909: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-13910: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-13911: Insufficient data validation in Spellcheck. Reported by Google. - CVE-2026-13912: Incorrect security UI in Safe Browsing. Reported by Google. - CVE-2026-13913: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-13914: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13915: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13916: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13918: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-13919: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-14393: Use after free in V8. Reported by Google. - CVE-2026-13920: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-13922: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-13923: Uninitialized Use in GPU. Reported by Google. - CVE-2026-14397: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-13924: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-13925: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-13926: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-13927: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. Reported by Google. - CVE-2026-13929: Insufficient validation of untrusted input in DevTools. Reported by LegioSec. - CVE-2026-13930: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-13931: Inappropriate implementation in Media. Reported by Google. - CVE-2026-13932: Inappropriate implementation in Sharing. Reported by Google. - CVE-2026-13933: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13934: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-14399: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-13935: Side-channel information leakage in ComputePressure. Reported by Google. - CVE-2026-13936: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13937: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-13938: Integer overflow in Fonts. Reported by Google. - CVE-2026-13939: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-13940: Uninitialized Use in Cast. Reported by Google. - CVE-2026-13941: Inappropriate implementation in SiteSettings. Reported by Google. - CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. Reported by Google. - CVE-2026-13943: Uninitialized Use in CSS. Reported by Google. - CVE-2026-13944: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-13945: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13946: Inappropriate implementation in ScriptInjections. Reported by Google. - CVE-2026-13947: Uninitialized Use in XR. Reported by Google. - CVE-2026-13948: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-13949: Insufficient policy enforcement in Payments. Reported by Google. - CVE-2026-14404: Inappropriate implementation in PDFium. Reported by Google. - CVE-2026-13950: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13951: Policy bypass in USB. Reported by Google. - CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. Reported by Google. - CVE-2026-14406: Out of bounds read in V8. Reported by Google. - CVE-2026-13953: Inappropriate implementation in SplitView. Reported by Google. - CVE-2026-13954: Insufficient policy enforcement in XML. Reported by Google. - CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. Reported by Google. - CVE-2026-13956: Incorrect security UI in PageInfo. Reported by Google. - CVE-2026-13957: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13958: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14407: Inappropriate implementation in V8. Reported by Google. - CVE-2026-13959: Insufficient validation of untrusted input in Blink. Reported by Google. - CVE-2026-13960: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13961: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13962: Insufficient data validation in PDF. Reported by Google - CVE-2026-13963: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-13964: Insufficient policy enforcement in WebView. Reported by Google. - CVE-2026-13965: Use after free in Oilpan. Reported by Google. - CVE-2026-13966: Inappropriate implementation in History. Reported by Google. - CVE-2026-13967: Type Confusion in V8. Reported by Google. - CVE-2026-13968: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13969: Uninitialized Use in UI. Reported by Google. - CVE-2026-13970: Uninitialized Use in Media. Reported by Google. - CVE-2026-13971: Uninitialized Use in Skia. Reported by Google. - CVE-2026-13972: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13973: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13974: Integer overflow in Safe Browsing. Reported by Google. - CVE-2026-13975: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-13976: Heap buffer overflow in Storage. Reported by Google. - CVE-2026-13977: Inappropriate implementation in HTMLParser. Reported by Google. - CVE-2026-13978: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-14414: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-13979: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13980: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13981: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-13982: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-13983: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-13984: Incorrect security UI in TabStrip. Reported by Google. - CVE-2026-13985: Inappropriate implementation in MediaCapture. Reported by Google. - CVE-2026-13986: Inappropriate implementation in Media UI. Reported by Google. - CVE-2026-13987: Incorrect security UI in Mobile. Reported by Google. - CVE-2026-13988: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-13989: Insufficient policy enforcement in PageInfo. Reported by Google. - CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-13992: Inappropriate implementation in UI. Reported by Google. - CVE-2026-13993: Incorrect security UI in WebAppInstalls. Reported by Google. - CVE-2026-13994: Inappropriate implementation in Credential Management. Reported by Google. - CVE-2026-13995: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-13996: Incorrect security UI in Permissions. Reported by Google. - CVE-2026-13997: Incorrect security UI in Extensions. Reported by Google - CVE-2026-13998: Incorrect security UI in File Input. Reported by Google - CVE-2026-13999: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14000: Inappropriate implementation in XML. Reported by Google - CVE-2026-14001: Inappropriate implementation in Network. Reported by Google. - CVE-2026-14002: Inappropriate implementation in Geolocation. Reported by Google. - CVE-2026-14003: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14004: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14005: Use after free in Omnibox. Reported by Google. - CVE-2026-14006: Use after free in Navigation. Reported by Google. - CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. Reported by Google. - CVE-2026-14008: Uninitialized Use in WebXR. Reported by Google. - CVE-2026-14009: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-14010: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-14011: Out of bounds read in SurfaceCapture. Reported by Google. - CVE-2026-14421: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-14012: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14013: Inappropriate implementation in SVG. Reported by Google - CVE-2026-14014: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-14015: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-14016: Insufficient policy enforcement in SVG. Reported by Google. - CVE-2026-14017: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-14018: Use after free in Updater. Reported by Google. - CVE-2026-14019: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-14020: Insufficient validation of untrusted input in WebXR. Reported by Google. - CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. Reported by Google. - CVE-2026-14022: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. Reported by Google. - CVE-2026-14024: Use after free in Ozone. Reported by Google. - CVE-2026-14432: Use after free in V8. Reported by Google. - CVE-2026-14025: Use after free in Views. Reported by asjidkalam. - CVE-2026-14026: Incorrect security UI in SplitView. Reported by adisahilna35@gmail.com. - CVE-2026-14027: Use after free in SignIn. Reported by Sven Dysthe (@svn-dys). - CVE-2026-14028: Incorrect security UI in Chrome for iOS. Reported by Ameen Basha M K. - CVE-2026-14030: Incorrect security UI in SplitView. Reported by Khalil Zhani. - CVE-2026-14031: Incorrect security UI in File Input. Reported by Google - CVE-2026-14032: Use after free in Bluetooth. Reported by Google. - CVE-2026-14033: Insufficient policy enforcement in Media. Reported by Google. - CVE-2026-14034: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14035: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14036: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-14037: Insufficient policy enforcement in GPU. Reported by Google. - CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. Reported by Google. - CVE-2026-14040: Use after free in BrowserTag. Reported by Google. - CVE-2026-14041: Insufficient policy enforcement in Serial. Reported by Google. - CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-14043: Use after free in GetUserMedia. Reported by Google. - CVE-2026-14044: Use after free in ANGLE. Reported by Google. - CVE-2026-14045: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14046: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-14047: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14048: Use after free in Chromecast. Reported by Google. - CVE-2026-14049: Inappropriate implementation in GPU. Reported by Google - CVE-2026-14050: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-14051: Uninitialized Use in GamepadAPI. Reported by Google. - CVE-2026-14052: Insufficient policy enforcement in FileSystem. Reported by Google. - CVE-2026-14053: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-14054: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. Reported by Google. - CVE-2026-14056: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-14057: Insufficient policy enforcement in FedCM. Reported by Google. - CVE-2026-14058: Policy bypass in Parser. Reported by Google. - CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. Reported by Google. - CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14061: Inappropriate implementation in Dawn. Reported by Google. - CVE-2026-14062: Inappropriate implementation in Views. Reported by Google. - CVE-2026-14063: Out of bounds memory access in Chromecast. Reported by Google. - CVE-2026-14064: Use after free in PageInfo. Reported by Google. - CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. Reported by Google. - CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14067: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14068: Inappropriate implementation in Omnibox. Reported by Google. - CVE-2026-14069: Integer overflow in WebNN. Reported by Google. - CVE-2026-14070: Uninitialized Use in WebNN. Reported by Google. - CVE-2026-14071: Side-channel information leakage in WebAudio. Reported by Google. - CVE-2026-14072: Incorrect security UI in SplitView. Reported by FARISSAL B. - CVE-2026-14073: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-14394: Use after free in V8. Reported by Google. - CVE-2026-14395: Out of bounds write in V8. Reported by Google. - CVE-2026-14074: Side-channel information leakage in WebAuthentication. Reported by Google. - CVE-2026-14075: Policy bypass in Chrome for iOS. Reported by Google. - CVE-2026-14076: Policy bypass in Network. Reported by Google. - CVE-2026-14077: Incorrect security UI in Select. Reported by pwn.ai. - CVE-2026-14078: Policy bypass in WebRTC. Reported by Google. - CVE-2026-14079: Policy bypass in Network. Reported by Google. - CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. Reported by Google. - CVE-2026-14081: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-14082: Race in Storage. Reported by Google. - CVE-2026-14083: Insufficient validation of untrusted input in HTML. Reported by Google. - CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-14085: Side-channel information leakage in CSS. Reported by Google. - CVE-2026-14086: Insufficient policy enforcement in HID. Reported by Google. - CVE-2026-14087: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-14088: Uninitialized Use in Canvas. Reported by Google. - CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. Reported by Google. - CVE-2026-14090: Out of bounds read in CameraCapture. Reported by Google - CVE-2026-14091: Use after free in DevTools. Reported by Google. - CVE-2026-14092: Insufficient policy enforcement in Privacy. Reported by Google. - CVE-2026-14093: Use after free in Cast. Reported by Google. - CVE-2026-14094: Use after free in Installer. Reported by Google. - CVE-2026-14095: Insufficient validation of untrusted input in Browser. Reported by Google. - CVE-2026-14403: Use after free in V8. Reported by Google. - CVE-2026-14096: Object lifecycle issue in Input. Reported by Google. - CVE-2026-14097: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14098: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14405: Uninitialized Use in V8. Reported by Google. - CVE-2026-14099: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-14100: Insufficient data validation in NetworkCache. Reported by Google. - CVE-2026-14101: Insufficient policy enforcement in Sandbox. Reported by Google. - CVE-2026-14102: Use after free in Passwords. Reported by Google. - CVE-2026-14103: Use after free in SSL. Reported by Google. - CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14105: Insufficient policy enforcement in Speech. Reported by Google. - CVE-2026-14106: Insufficient validation of untrusted input in Text. Reported by Google. - CVE-2026-14107: Use after free in Scheduling. Reported by Google. - CVE-2026-14108: Use after free in PDFium. Reported by Google. - CVE-2026-14109: Insufficient policy enforcement in Mojo. Reported by Google. - CVE-2026-14110: Inappropriate implementation in DarkMode. Reported by Google. - CVE-2026-14111: Use after free in WebProtect. Reported by Google. - CVE-2026-14112: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-14113: Use after free in Updater. Reported by Google. - CVE-2026-14114: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14115: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-14116: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14117: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-14118: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-14119: Type Confusion in Bluetooth. Reported by Google. - CVE-2026-14120: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14121: Use after free in Chromoting. Reported by Google. - CVE-2026-14409: Inappropriate implementation in V8. Reported by Yuntao You (@GraVity0) of Bytedance Wuheng Lab. - CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14410: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-14123: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14124: Inappropriate implementation in CredentialProvider. Reported by Google. - CVE-2026-14125: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-14126: Incorrect security UI in UI. Reported by Google. - CVE-2026-14127: Inappropriate implementation in Printing. Reported by Google. - CVE-2026-14128: Insufficient data validation in Chrome for iOS. Reported by Google. - CVE-2026-14129: Incorrect security UI in PreviewTab. Reported by Google - CVE-2026-14130: Incorrect security UI in Omnibox. Reported by Google. - CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-14132: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-14133: Race in History Embeddings. Reported by Google. - CVE-2026-14134: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-14135: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-14136: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-14138: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-14139: Inappropriate implementation in TabStrip. Reported by Google. - CVE-2026-14140: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. Reported by Google. - CVE-2026-14142: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-14143: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-14144: Incorrect security UI in Views. Reported by Google. - CVE-2026-14145: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14146: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14147: Inappropriate implementation in CSS. Reported by Google - CVE-2026-14415: Inappropriate implementation in V8. Reported by Google. - CVE-2026-14148: Type Confusion in CSS. Reported by Google. - CVE-2026-14149: Use after free in Audio. Reported by Google. - CVE-2026-14416: Out of bounds read in Dawn. Reported by Google. - CVE-2026-14150: Insufficient validation of untrusted input in Speech. Reported by Google. - CVE-2026-14151: Inappropriate implementation in AI. Reported by Google. - CVE-2026-14152: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-14153: Inappropriate implementation in Glic. Reported by Google. - CVE-2026-14154: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. Reported by Google. - CVE-2026-14156: Policy bypass in StorageAccessAPI. Reported by Google. - CVE-2026-13281: Integer overflow in Mojo. Reported by Google. - CVE-2026-13282: Use after free in Payments. Reported by Google. - CVE-2026-13283: Use after free in AdFilter. Reported by Google. * d/copyright: - delete third_party/webpagereplay/. - delete tsgo (typescript compiler in Go) binary. * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: drop, merged upstream. - disable/android.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/libcpp-headers.patch: rework parts of the patch due to upstream changes. - disable/catapult.patch: refresh. - disable/tests.patch: refresh. - llvm-19/clang19.patch: refresh. - trixie/gn-expand-dir-allowlist.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - i386/support-i386.patch: refresh. - upstream/sysroot.patch: add a new build fix pulled from upstream. - upstream/ar-path1.patch, upstream/ar-path2.patch: add two more vendoring-related build fixes from upstream. - trixie/gn-additional-outputs.patch: add patch to partially revert usage of a newer generate-ninja feature. - llvm-19/i18n-builder-enum.patch: add a workaround for clang-19 being confused between a class declaration (with default template parameter) and definition. - llvm-19/00*-revert-v8-libm.patch: add 9 patches backing out usage of internal libc++/libm symbols; this requires a newer llvm than we have. - llvm-19/value-or.patch: work around more places where value_or() can't figure out the type of a passed init value. - trixie/node20-compat.patch: break out part of Daniel's node18-compat.patch (below) into one for trixie that also fixes nodejs 20 issues [trixie, bookworm]. - rust-1.85/std-from-utf8.patch: add workaround for str::from_utf8 added in 1.87 [trixie, bookworm]. - trixie/bindgen-boringssl.patch: add workaround for older bindgen [trixie, bookworm]. . [ Daniel Richard G. ] * d/patches: - bookworm/gn-absl.patch: Refresh [bookworm]. - bookworm/gn-funcs.patch: Zap new usage of filter_labels_include() [bookworm]. - bookworm/node18-compat.patch: Fix more cases of nodejs v18 breakage [bookworm]. - trixie/gn-module-name.patch: add more spots where the workaround is needed [trixie, bookworm]. . [ Jianfeng Liu ] * d/patches: - upstream/libyuv-loongarch-fix-row_lsx.cc-and-row_lasx.cc.patch: Fix build for libyuv loongarch64. - loongarch64/0015-ffmpeg-support-for-loongarch.patch: Refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - fixes/fix-rust-linking.patch: refresh for upstream changes - fixes/fix-breakpad-compile.patch: refresh for upstream changes - third_party/dawn-fix-ppc64le-detection.patch: refresh for upstream changes - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes chromium (149.0.7827.196-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. chromium (149.0.7827.196-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-13028: Use after free in WebGL. Reported by anonymous. - CVE-2026-13032: Use after free in WebGL. Reported by Google. - CVE-2026-13033: Out of bounds read in Blink>InterestGroups. Reported by Google. - CVE-2026-13038: Use after free in Autofill. Reported by Google. - CVE-2026-13021: Inappropriate implementation in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-13022: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13023: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13024: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-13025: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13026: Use after free in Digital Credentials. Reported by Google. - CVE-2026-13027: Use after free in FileSystem. Reported by Google. - CVE-2026-13029: Use after free in Web Authentication. Reported by Google - CVE-2026-13030: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13031: Use after free in Blink. Reported by Google. - CVE-2026-13034: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13035: Use after free in Bluetooth. Reported by Google. - CVE-2026-13036: Use after free in Blink. Reported by Google. - CVE-2026-13037: Use after free in WebView. Reported by Google. chromium (149.0.7827.196-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-13028: Use after free in WebGL. Reported by anonymous. - CVE-2026-13032: Use after free in WebGL. Reported by Google. - CVE-2026-13033: Out of bounds read in Blink>InterestGroups. Reported by Google. - CVE-2026-13038: Use after free in Autofill. Reported by Google. - CVE-2026-13021: Inappropriate implementation in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-13022: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-13023: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13024: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-13025: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-13026: Use after free in Digital Credentials. Reported by Google. - CVE-2026-13027: Use after free in FileSystem. Reported by Google. - CVE-2026-13029: Use after free in Web Authentication. Reported by Google - CVE-2026-13030: Uninitialized Use in GPU. Reported by Google. - CVE-2026-13031: Use after free in Blink. Reported by Google. - CVE-2026-13034: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-13035: Use after free in Bluetooth. Reported by Google. - CVE-2026-13036: Use after free in Blink. Reported by Google. - CVE-2026-13037: Use after free in WebView. Reported by Google. chromium (149.0.7827.155-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. chromium (149.0.7827.155-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. chromium (149.0.7827.155-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. chromium (149.0.7827.114-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. . [ Jianfeng Liu ] * d/patches/loongarch64/0024-fix-libyuv-lsx.patch: drop due to upstream reverting to version of libyuv that doesn't have lsx issue. chromium (149.0.7827.114-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. . [ Jianfeng Liu ] * d/patches/loongarch64/0024-fix-libyuv-lsx.patch: drop due to upstream reverting to version of libyuv that doesn't have lsx issue. chromium (149.0.7827.114-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. chromium (149.0.7827.102-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-11628: Use after free in Ozone. Reported by Google. - CVE-2026-11629: Use after free in Ozone. Reported by Google. - CVE-2026-11630: Use after free in File Input. Reported by Google. - CVE-2026-11631: Use after free in Aura. Reported by Google. - CVE-2026-11632: Use after free in TabStrip. Reported by Google. - CVE-2026-11633: Use after free in Bluetooth. Reported by Google. - CVE-2026-11634: Use after free in Gamepad. Reported by Google. - CVE-2026-11635: Use after free in Bluetooth. Reported by Google. - CVE-2026-11636: Use after free in Autofill. Reported by Google. - CVE-2026-11637: Use after free in Views. Reported by Google. - CVE-2026-11638: Use after free in Printing. Reported by Google. - CVE-2026-11639: Use after free in Compositing. Reported by Google. - CVE-2026-11640: Integer overflow in libyuv. Reported by Google. - CVE-2026-11641: Use after free in Bluetooth. Reported by Google. - CVE-2026-11642: Use after free in Web Apps. Reported by Google. - CVE-2026-11643: Use after free in Proxy. Reported by Google. - CVE-2026-11644: Use after free in Views. Reported by Google. - CVE-2026-11645: Out of bounds memory access in V8. Reported by 303f06e3 - CVE-2026-11646: Use after free in ViewTransitions. Reported by Quac Tran. - CVE-2026-11647: Use after free in Printing. Reported by Google. - CVE-2026-11648: Use after free in FullScreen. Reported by Mihnea Nicolau. - CVE-2026-11649: Use after free in V8. Reported by Google. - CVE-2026-11650: Use after free in V8. Reported by Google. - CVE-2026-11651: Use after free in Network. Reported by Google. - CVE-2026-11652: Use after free in Extensions. Reported by Google. - CVE-2026-11653: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11654: Use after free in CameraCapture. Reported by Google. - CVE-2026-11655: Integer overflow in Media. Reported by Google. - CVE-2026-11656: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11657: Use after free in Payments. Reported by Google. - CVE-2026-11658: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11659: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11661: Use after free in Views. Reported by Google. - CVE-2026-11662: Type Confusion in Bindings. Reported by Google. - CVE-2026-11663: Use after free in Skia. Reported by Google. - CVE-2026-11664: Use after free in Payments. Reported by Google. - CVE-2026-11665: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11666: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-11667: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11668: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-11669: Integer overflow in Media. Reported by Google. - CVE-2026-11670: Use after free in PDF. Reported by Google. - CVE-2026-11671: Use after free in Navigation. Reported by Google. - CVE-2026-11672: Out of bounds write in GPU. Reported by Google. - CVE-2026-11673: Use after free in InterestGroups. Reported by Google. - CVE-2026-11674: Use after free in Guest View. Reported by Google. - CVE-2026-11675: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11676: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11677: Race in Network. Reported by Google. - CVE-2026-11678: Integer overflow in libyuv. Reported by Google. - CVE-2026-11679: Use after free in Codecs. Reported by Google. - CVE-2026-11680: Use after free in Media. Reported by Google. - CVE-2026-11681: Use after free in Ozone. Reported by Google. - CVE-2026-11682: Insufficient validation of untrusted input in Views. Reported by Google. - CVE-2026-11683: Use after free in WebCodecs. Reported by Google. - CVE-2026-11684: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-11685: Insufficient data validation in MediaCapture. Reported by Google. - CVE-2026-11686: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11687: Use after free in Dawn. Reported by Google. - CVE-2026-11688: Object lifecycle issue in SVG. Reported by Google. - CVE-2026-11689: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-11690: Out of bounds read and write in Media. Reported by Google. - CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11692: Use after free in Read Anything. Reported by Google. - CVE-2026-11693: Inappropriate implementation in Plugins. Reported by Google. - CVE-2026-11694: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11695: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11696: Uninitialized Use in Video. Reported by Google. - CVE-2026-11697: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11698: Use after free in Bluetooth. Reported by Google. - CVE-2026-11699: Use after free in Bluetooth. Reported by Google. - CVE-2026-11700: Use after free in Tracing. Reported by Google. - CVE-2026-11701: Insufficient validation of untrusted input in Guest View. Reported by Google. * d/patches: - fixes/arm-logging.patch: add patch to hopefully fix build failure on arm*. - loongarch64/0024-fix-libyuv-lsx.patch: refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes - core/baseline-isa-3-0.patch: refresh chromium (149.0.7827.102-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-11628: Use after free in Ozone. Reported by Google. - CVE-2026-11629: Use after free in Ozone. Reported by Google. - CVE-2026-11630: Use after free in File Input. Reported by Google. - CVE-2026-11631: Use after free in Aura. Reported by Google. - CVE-2026-11632: Use after free in TabStrip. Reported by Google. - CVE-2026-11633: Use after free in Bluetooth. Reported by Google. - CVE-2026-11634: Use after free in Gamepad. Reported by Google. - CVE-2026-11635: Use after free in Bluetooth. Reported by Google. - CVE-2026-11636: Use after free in Autofill. Reported by Google. - CVE-2026-11637: Use after free in Views. Reported by Google. - CVE-2026-11638: Use after free in Printing. Reported by Google. - CVE-2026-11639: Use after free in Compositing. Reported by Google. - CVE-2026-11640: Integer overflow in libyuv. Reported by Google. - CVE-2026-11641: Use after free in Bluetooth. Reported by Google. - CVE-2026-11642: Use after free in Web Apps. Reported by Google. - CVE-2026-11643: Use after free in Proxy. Reported by Google. - CVE-2026-11644: Use after free in Views. Reported by Google. - CVE-2026-11645: Out of bounds memory access in V8. Reported by 303f06e3 - CVE-2026-11646: Use after free in ViewTransitions. Reported by Quac Tran. - CVE-2026-11647: Use after free in Printing. Reported by Google. - CVE-2026-11648: Use after free in FullScreen. Reported by Mihnea Nicolau. - CVE-2026-11649: Use after free in V8. Reported by Google. - CVE-2026-11650: Use after free in V8. Reported by Google. - CVE-2026-11651: Use after free in Network. Reported by Google. - CVE-2026-11652: Use after free in Extensions. Reported by Google. - CVE-2026-11653: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11654: Use after free in CameraCapture. Reported by Google. - CVE-2026-11655: Integer overflow in Media. Reported by Google. - CVE-2026-11656: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11657: Use after free in Payments. Reported by Google. - CVE-2026-11658: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11659: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11661: Use after free in Views. Reported by Google. - CVE-2026-11662: Type Confusion in Bindings. Reported by Google. - CVE-2026-11663: Use after free in Skia. Reported by Google. - CVE-2026-11664: Use after free in Payments. Reported by Google. - CVE-2026-11665: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11666: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-11667: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11668: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-11669: Integer overflow in Media. Reported by Google. - CVE-2026-11670: Use after free in PDF. Reported by Google. - CVE-2026-11671: Use after free in Navigation. Reported by Google. - CVE-2026-11672: Out of bounds write in GPU. Reported by Google. - CVE-2026-11673: Use after free in InterestGroups. Reported by Google. - CVE-2026-11674: Use after free in Guest View. Reported by Google. - CVE-2026-11675: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11676: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11677: Race in Network. Reported by Google. - CVE-2026-11678: Integer overflow in libyuv. Reported by Google. - CVE-2026-11679: Use after free in Codecs. Reported by Google. - CVE-2026-11680: Use after free in Media. Reported by Google. - CVE-2026-11681: Use after free in Ozone. Reported by Google. - CVE-2026-11682: Insufficient validation of untrusted input in Views. Reported by Google. - CVE-2026-11683: Use after free in WebCodecs. Reported by Google. - CVE-2026-11684: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-11685: Insufficient data validation in MediaCapture. Reported by Google. - CVE-2026-11686: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11687: Use after free in Dawn. Reported by Google. - CVE-2026-11688: Object lifecycle issue in SVG. Reported by Google. - CVE-2026-11689: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-11690: Out of bounds read and write in Media. Reported by Google. - CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11692: Use after free in Read Anything. Reported by Google. - CVE-2026-11693: Inappropriate implementation in Plugins. Reported by Google. - CVE-2026-11694: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11695: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11696: Uninitialized Use in Video. Reported by Google. - CVE-2026-11697: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11698: Use after free in Bluetooth. Reported by Google. - CVE-2026-11699: Use after free in Bluetooth. Reported by Google. - CVE-2026-11700: Use after free in Tracing. Reported by Google. - CVE-2026-11701: Insufficient validation of untrusted input in Guest View. Reported by Google. * d/patches: - fixes/arm-logging.patch: add patch to hopefully fix build failure on arm*. - loongarch64/0024-fix-libyuv-lsx.patch: refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes - core/baseline-isa-3-0.patch: refresh chromium (149.0.7827.102-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-11628: Use after free in Ozone. Reported by Google. - CVE-2026-11629: Use after free in Ozone. Reported by Google. - CVE-2026-11630: Use after free in File Input. Reported by Google. - CVE-2026-11631: Use after free in Aura. Reported by Google. - CVE-2026-11632: Use after free in TabStrip. Reported by Google. - CVE-2026-11633: Use after free in Bluetooth. Reported by Google. - CVE-2026-11634: Use after free in Gamepad. Reported by Google. - CVE-2026-11635: Use after free in Bluetooth. Reported by Google. - CVE-2026-11636: Use after free in Autofill. Reported by Google. - CVE-2026-11637: Use after free in Views. Reported by Google. - CVE-2026-11638: Use after free in Printing. Reported by Google. - CVE-2026-11639: Use after free in Compositing. Reported by Google. - CVE-2026-11640: Integer overflow in libyuv. Reported by Google. - CVE-2026-11641: Use after free in Bluetooth. Reported by Google. - CVE-2026-11642: Use after free in Web Apps. Reported by Google. - CVE-2026-11643: Use after free in Proxy. Reported by Google. - CVE-2026-11644: Use after free in Views. Reported by Google. - CVE-2026-11645: Out of bounds memory access in V8. Reported by 303f06e3 - CVE-2026-11646: Use after free in ViewTransitions. Reported by Quac Tran. - CVE-2026-11647: Use after free in Printing. Reported by Google. - CVE-2026-11648: Use after free in FullScreen. Reported by Mihnea Nicolau. - CVE-2026-11649: Use after free in V8. Reported by Google. - CVE-2026-11650: Use after free in V8. Reported by Google. - CVE-2026-11651: Use after free in Network. Reported by Google. - CVE-2026-11652: Use after free in Extensions. Reported by Google. - CVE-2026-11653: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11654: Use after free in CameraCapture. Reported by Google. - CVE-2026-11655: Integer overflow in Media. Reported by Google. - CVE-2026-11656: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11657: Use after free in Payments. Reported by Google. - CVE-2026-11658: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11659: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11661: Use after free in Views. Reported by Google. - CVE-2026-11662: Type Confusion in Bindings. Reported by Google. - CVE-2026-11663: Use after free in Skia. Reported by Google. - CVE-2026-11664: Use after free in Payments. Reported by Google. - CVE-2026-11665: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11666: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-11667: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11668: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-11669: Integer overflow in Media. Reported by Google. - CVE-2026-11670: Use after free in PDF. Reported by Google. - CVE-2026-11671: Use after free in Navigation. Reported by Google. - CVE-2026-11672: Out of bounds write in GPU. Reported by Google. - CVE-2026-11673: Use after free in InterestGroups. Reported by Google. - CVE-2026-11674: Use after free in Guest View. Reported by Google. - CVE-2026-11675: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11676: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11677: Race in Network. Reported by Google. - CVE-2026-11678: Integer overflow in libyuv. Reported by Google. - CVE-2026-11679: Use after free in Codecs. Reported by Google. - CVE-2026-11680: Use after free in Media. Reported by Google. - CVE-2026-11681: Use after free in Ozone. Reported by Google. - CVE-2026-11682: Insufficient validation of untrusted input in Views. Reported by Google. - CVE-2026-11683: Use after free in WebCodecs. Reported by Google. - CVE-2026-11684: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-11685: Insufficient data validation in MediaCapture. Reported by Google. - CVE-2026-11686: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11687: Use after free in Dawn. Reported by Google. - CVE-2026-11688: Object lifecycle issue in SVG. Reported by Google. - CVE-2026-11689: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-11690: Out of bounds read and write in Media. Reported by Google. - CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page. Reported by Google. - CVE-2026-11692: Use after free in Read Anything. Reported by Google. - CVE-2026-11693: Inappropriate implementation in Plugins. Reported by Google. - CVE-2026-11694: Use after free in ServiceWorker. Reported by Google. - CVE-2026-11695: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11696: Uninitialized Use in Video. Reported by Google. - CVE-2026-11697: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-11698: Use after free in Bluetooth. Reported by Google. - CVE-2026-11699: Use after free in Bluetooth. Reported by Google. - CVE-2026-11700: Use after free in Tracing. Reported by Google. - CVE-2026-11701: Insufficient validation of untrusted input in Guest View. Reported by Google. * d/patches: - fixes/arm-logging.patch: add patch to hopefully fix build failure on arm*. - loongarch64/0024-fix-libyuv-lsx.patch: refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes - core/baseline-isa-3-0.patch: refresh chromium (149.0.7827.53-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-10881: Out of bounds read and write in ANGLE. Reported by Anonymous. - CVE-2026-10882: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10883: Out of bounds write in ANGLE. Reported by Maher Azzouzi. - CVE-2026-10884: Use after free in Chromecast. Reported by Google. - CVE-2026-10885: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10886: Use after free in FileSystem. Reported by Andrew Boni. - CVE-2026-10887: Use after free in Chromoting. Reported by Google. - CVE-2026-10888: Use after free in Cast Streaming. Reported by Google. - CVE-2026-10889: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10890: Use after free in Cast. Reported by Google. - CVE-2026-10891: Use after free in GFX. Reported by Google. - CVE-2026-10892: Out of bounds write in GPU. Reported by Google. - CVE-2026-10893: Use after free in Chromoting. Reported by Google. - CVE-2026-10894: Use after free in Printing. Reported by Google. - CVE-2026-10895: Use after free in Ozone. Reported by Google. - CVE-2026-10896: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10897: Out of bounds write in GPU. Reported by Google. - CVE-2026-10898: Stack buffer overflow in GPU. Reported by Google. - CVE-2026-10899: Use after free in Ozone. Reported by Google. - CVE-2026-10900: Use after free in Passwords. Reported by Google. - CVE-2026-10901: Use after free in Passwords. Reported by Google. - CVE-2026-10902: Use after free in Ozone. Reported by Google. - CVE-2026-10903: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10904: Inappropriate implementation in V8. Reported by 303f06e3 - CVE-2026-10905: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10906: Use after free in WebAuthentication. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10907: Out of bounds write in ANGLE. Reported by sweetchip. - CVE-2026-10908: Use after free in FullScreen. Reported by Mihnea Nicolau - CVE-2026-10909: Use after free in Dawn. Reported by whiter@xuanyusec. - CVE-2026-10910: Type Confusion in V8. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10911: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10912: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-10913: Use after free in ANGLE. Reported by Google. - CVE-2026-10914: Use after free in ANGLE. Reported by Google. - CVE-2026-10915: Use after free in Core. Reported by Google. - CVE-2026-10916: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10917: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10918: Use after free in Viz. Reported by Google. - CVE-2026-10919: Use after free in ANGLE. Reported by Google. - CVE-2026-10920: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-10921: Integer overflow in Dawn. Reported by Google. - CVE-2026-10922: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10923: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10924: Integer overflow in Chromecast. Reported by Google. - CVE-2026-10925: Out of bounds write in Skia. Reported by Google. - CVE-2026-10926: Use after free in Cast. Reported by Google. - CVE-2026-10927: Out of bounds read in Dawn. Reported by Google. - CVE-2026-10928: Script injection in Headless. Reported by Google. - CVE-2026-10929: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-10930: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10931: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-10932: Use after free in UI. Reported by Google. - CVE-2026-10933: Use after free in Audio. Reported by Google. - CVE-2026-10934: Use after free in Autofill. Reported by Google. - CVE-2026-10935: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10936: Type Confusion in V8. Reported by Google. - CVE-2026-10937: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-10938: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-10939: Use after free in WebRTC. Reported by Google. - CVE-2026-10940: Race in Codecs. Reported by Google. - CVE-2026-10941: Out of bounds memory access in Skia. Reported by Google. - CVE-2026-10942: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-10943: Use after free in WebRTC. Reported by Rayyan Kadar. - CVE-2026-10944: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10945: Use after free in PDF. Reported by Google. - CVE-2026-10946: Heap buffer overflow in Media. Reported by Google. - CVE-2026-10947: Use after free in WebRTC. Reported by Google. - CVE-2026-10948: Use after free in WebRTC. Reported by Google. - CVE-2026-10949: Heap buffer overflow in Video. Reported by Google. - CVE-2026-10950: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10951: Use after free in Autofill. Reported by Google. - CVE-2026-10952: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10953: Use after free in Core. Reported by Google. - CVE-2026-10954: Use after free in Actor. Reported by Google. - CVE-2026-10955: Type Confusion in ANGLE. Reported by Google. - CVE-2026-10956: Use after free in MimeHandlerView. Reported by Google. - CVE-2026-10957: Use after free in Glic. Reported by Google. - CVE-2026-10958: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10959: Use after free in Input. Reported by Google. - CVE-2026-10960: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-10961: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10962: Type Confusion in Media. Reported by Google. - CVE-2026-10963: Integer overflow in V8. Reported by Google. - CVE-2026-10964: Integer overflow in V8. Reported by Google. - CVE-2026-10965: Integer overflow in DevTools. Reported by Google. - CVE-2026-10966: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10967: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-10968: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10969: Insufficient validation of untrusted input in Extensions Reported by Google. - CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups. Reported by Google. - CVE-2026-10971: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-10972: Use after free in Ozone. Reported by Google. - CVE-2026-10973: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10974: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-10975: Use after free in WebRTC. Reported by Google. - CVE-2026-10976: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10977: Uninitialized Use in Skia. Reported by Google. - CVE-2026-10978: Use after free in Chromoting. Reported by Google. - CVE-2026-10979: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10980: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10981: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10982: Use after free in WebXR. Reported by Google. - CVE-2026-10983: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10984: Inappropriate implementation in Accessibility. Reported by Google. - CVE-2026-10985: Out of bounds read in Skia. Reported by Google. - CVE-2026-10986: Integer overflow in Media. Reported by Google. - CVE-2026-10987: Integer overflow in V8. Reported by Google. - CVE-2026-10988: Use after free in Views. Reported by Google. - CVE-2026-10989: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10990: Use after free in Glic. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10991: Use after free in V8. Reported by Alisa Esage (@alisaesage). - CVE-2026-10992: Insufficient data validation in Animation. Reported by heapracer (@heapracer). - CVE-2026-10993: Heap buffer overflow in Skia. Reported by M. Fauzan Wijaya (Gh05t666nero). - CVE-2026-10994: Uninitialized Use in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10995: Heap buffer overflow in TabStrip. Reported by Sven Dysthe (@svn-dys). - CVE-2026-10996: Inappropriate implementation in Workers. Reported by Jayateertha Guruprasad. - CVE-2026-10997: Insufficient policy enforcement in Extensions. Reported by djallalakira@gmail.com. - CVE-2026-10998: Out of bounds read in Media. Reported by Ameen Basha M K - CVE-2026-10999: Out of bounds memory access in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11000: Use after free in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11001: Incorrect security UI in Payments. Reported by Google. - CVE-2026-11002: Use after free in Autofill. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11003: Use after free in WebRTC. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-11004: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11005: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11006: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11007: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11009: Use after free in USB. Reported by Google. - CVE-2026-11010: Use after free in WebShare. Reported by David Sievers. - CVE-2026-11011: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11012: Use after free in Serial. Reported by Google. - CVE-2026-11013: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11014: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11015: Out of bounds read in WebGPU. Reported by Yuma Takeuchi. - CVE-2026-11016: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11017: Inappropriate implementation in Link Preview. Reported by Google. - CVE-2026-11018: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11019: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11020: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11021: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11022: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11024: Stack buffer overflow in Skia. Reported by Google. - CVE-2026-11025: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-11026: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11027: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-11028: Use after free in Media. Reported by Google. - CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop. Reported by Google. - CVE-2026-11030: Use after free in Network. Reported by Google. - CVE-2026-11031: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11032: Insufficient data validation in Password Manager. Reported by Google. - CVE-2026-11033: Uninitialized Use in WebML. Reported by Google. - CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync. Reported by Google. - CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs. Reported by Google. - CVE-2026-11036: Inappropriate implementation in DOM. Reported by Google - CVE-2026-11037: Out of bounds write in Codecs. Reported by Google. - CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity. Reported by Google. - CVE-2026-11039: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11040: Use after free in ANGLE. Reported by Google. - CVE-2026-11041: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11042: Use after free in Views. Reported by Google. - CVE-2026-11043: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-11044: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11045: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11046: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11047: Insufficient validation of untrusted input in Base. Reported by Google. - CVE-2026-11048: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11049: Use after free in Password Manager. Reported by Google. - CVE-2026-11050: Use after free in V8. Reported by Google. - CVE-2026-11051: Out of bounds read in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11052: Type Confusion in GPU. Reported by Google. - CVE-2026-11053: VULNERABILITY in WebRTC. Reported by Google. - CVE-2026-11054: Use after free in WebRTC. Reported by Google. - CVE-2026-11055: Use after free in ANGLE. Reported by Google. - CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-11057: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11058: Integer overflow in CredentialProvider. Reported by Google. - CVE-2026-11059: Use after free in Blink. Reported by Google. - CVE-2026-11060: Use after free in Media. Reported by Google. - CVE-2026-11061: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11062: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11063: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-11064: Uninitialized Use in GPU. Reported by Google. - CVE-2026-11065: Use after free in ANGLE. Reported by Google. - CVE-2026-11066: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11067: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11068: Use after free in WebSockets. Reported by Google. - CVE-2026-11069: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11070: Insufficient validation of untrusted input in Chromoting Reported by Google. - CVE-2026-11071: Use after free in Base. Reported by Google. - CVE-2026-11072: Use after free in WebView. Reported by Google. - CVE-2026-11073: Use after free in WebGL. Reported by Google. - CVE-2026-11074: Use after free in WebRTC. Reported by boboliverfrancishoward@gmail.com. - CVE-2026-11075: Out of bounds read in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-11076: Type Confusion in CSS. Reported by Google. - CVE-2026-11077: Out of bounds read in Dawn. Reported by Anonymous. - CVE-2026-11078: Insufficient validation of untrusted input in FileSystem. Reported by Eran Rom of Palo Alto Networks. - CVE-2026-11079: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11080: Use after free in WebView. Reported by Google. - CVE-2026-11081: Policy bypass in Canvas. Reported by Google. - CVE-2026-11082: Use after free in GPU. Reported by Google. - CVE-2026-11083: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11084: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11085: Integer overflow in GPU. Reported by Google. - CVE-2026-11086: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11087: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11088: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11089: Uninitialized Use in Media. Reported by Google. - CVE-2026-11090: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11091: Inappropriate implementation in Dawn. Reported by Google - CVE-2026-11092: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11093: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-11094: Use after free in Codecs. Reported by Google. - CVE-2026-11095: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11096: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11097: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11098: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11099: Vulnerability in Skia. Reported by Google. - CVE-2026-11100: Use after free in File Input. Reported by Google. - CVE-2026-11101: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11102: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-11103: Inappropriate implementation in Installer. Reported by Google. - CVE-2026-11104: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11105: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-11106: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11107: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-11108: Inappropriate implementation in NFC. Reported by Google - CVE-2026-11109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11110: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11111: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11112: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11113: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11114: Use after free in Device Trust. Reported by Google. - CVE-2026-11115: Use after free in Updater. Reported by Google. - CVE-2026-11116: Use after free in Chromoting. Reported by Google. - CVE-2026-11117: Use after free in Views. Reported by Google. - CVE-2026-11118: Use after free in WebRTC. Reported by Google. - CVE-2026-11119: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting. Reported by Google. - CVE-2026-11121: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11122: Inappropriate implementation in Keyboard. Reported by Google. - CVE-2026-11123: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11124: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-11125: Use after free in Compositing. Reported by Google. - CVE-2026-11126: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11127: Inappropriate implementation in WebAPKs. Reported by Google. - CVE-2026-11128: Insufficient validation of untrusted input in Web Share. Reported by Google. - CVE-2026-11129: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11130: Use after free in Media. Reported by Google. - CVE-2026-11131: Use after free in Autofill. Reported by Google. - CVE-2026-11132: Policy bypass in Paint. Reported by Google. - CVE-2026-11133: Insufficient policy enforcement in Paint. Reported by Google. - CVE-2026-11134: Insufficient data validation in Media. Reported by Google. - CVE-2026-11135: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-11136: Use after free in Canvas. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-11137: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11138: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11139: Policy bypass in Paint. Reported by Google. - CVE-2026-11140: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-11141: Uninitialized Use in Audio. Reported by Google. - CVE-2026-11142: Policy bypass in Paint. Reported by Google. - CVE-2026-11143: Heap buffer overflow in Extensions. Reported by Google. - CVE-2026-11144: Use after free in Media. Reported by Google. - CVE-2026-11145: Race in Geolocation. Reported by Google. - CVE-2026-11146: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11147: Use after free in WebML. Reported by Google. - CVE-2026-11148: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11149: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11150: Inappropriate implementation in XML. Reported by Google - CVE-2026-11151: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11152: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-11153: Side-channel information leakage in Forms. Reported by Google. - CVE-2026-11154: Use after free in Dawn. Reported by Google. - CVE-2026-11155: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11156: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11157: Script injection in Accessibility. Reported by Google. - CVE-2026-11158: Insufficient validation of untrusted input in Downloads. Reported by Google. - CVE-2026-11159: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11160: Out of bounds read in Input. Reported by Google. - CVE-2026-11161: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-11162: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11163: Use after free in Messages. Reported by Google. - CVE-2026-11164: Use after free in Blink. Reported by Google. - CVE-2026-11165: Use after free in WebMIDI. Reported by Google. - CVE-2026-11166: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11167: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11168: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11169: Inappropriate implementation in XML. Reported by Google - CVE-2026-11170: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-11171: Integer overflow in Blink. Reported by Google. - CVE-2026-11172: Incorrect security UI in Contact Picker. Reported by mochazril.ti@gmail.com. - CVE-2026-11173: Out of bounds write in V8. Reported by Google. - CVE-2026-11174: Insufficient policy enforcement in Site Isolation. Reported by Google. - CVE-2026-11175: Incorrect security UI in Messages. Reported by Google. - CVE-2026-11176: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11177: Use after free in Omnibox. Reported by gevakun. - CVE-2026-11178: Policy bypass in WebView. Reported by Google. - CVE-2026-11179: Inappropriate implementation in ORB. Reported by Google - CVE-2026-11180: Policy bypass in SVG. Reported by Google. - CVE-2026-11181: Inappropriate implementation in Media Session. Reported by Google. - CVE-2026-11182: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11183: Out of bounds read in GWP-ASan. Reported by Google. - CVE-2026-11184: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11185: Use after free in V8. Reported by Google. - CVE-2026-11186: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11187: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-11188: Use after free in USB. Reported by Google. - CVE-2026-11189: Insufficient validation of untrusted input in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-11190: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11191: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-11192: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11193: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11194: Inappropriate implementation in Network. Reported by Google. - CVE-2026-11195: Inappropriate implementation in MHTML. Reported by Google. - CVE-2026-11196: Type Confusion in XML. Reported by Google. - CVE-2026-11197: Insufficient policy enforcement in Workers. Reported by VEZEKA. - CVE-2026-11198: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11199: Insufficient validation of untrusted input in WebRTC. Reported by Google. - CVE-2026-11200: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-11201: Use after free in ServiceWorker. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11203: Policy bypass in GPU. Reported by Google. - CVE-2026-11204: Inappropriate implementation in Signin. Reported by Google. - CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11206: Policy bypass in ServiceWorker. Reported by David Bors, Catalin Iovita. - CVE-2026-11207: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-11208: Use after free in Codecs. Reported by Google. - CVE-2026-11209: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-11210: Insufficient policy enforcement in Safe Browsing. Reported by Google. - CVE-2026-11211: Integer overflow in V8. Reported by Google. - CVE-2026-11212: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode. Reported by Google. - CVE-2026-11214: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-11215: Inappropriate implementation in Cronet. Reported by Google. - CVE-2026-11216: Incorrect security UI in File Input. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-11217: Insufficient policy enforcement in Fenced Frames. Reported by Tianyi Hu. - CVE-2026-11218: Inappropriate implementation in PlatformIntegration. Reported by Han Liu (Xi’an Jiaotong University, School of Cyber Science and Engineering). - CVE-2026-11219: Insufficient data validation in Navigation. Reported by Bharat (mrnoob) . - CVE-2026-11220: Insufficient validation of untrusted input in Navigation. Reported by Tianyi Hu. - CVE-2026-11221: Insufficient validation of untrusted input in PointerLock. Reported by mihalis.haatainen@bountyy.fi. - CVE-2026-11222: Incorrect security UI in Tab Strip. Reported by Hafiizh - CVE-2026-11223: Insufficient validation of untrusted input in Network. Reported by Tianyi Hu. - CVE-2026-11224: Use after free in Chromoting. Reported by David Bors, Catalin Iovita. - CVE-2026-11225: Incorrect security UI in WebUI. Reported by Tareq Ahamed - itztrq. - CVE-2026-11226: Insufficient policy enforcement in PreviewTab. Reported by Google. - CVE-2026-11227: Incorrect security UI in Tab Hover Cards. Reported by Hafiizh. - CVE-2026-11228: Incorrect security UI in File Input. Reported by Umar Farooq . - CVE-2026-11229: Insufficient policy enforcement in Enterprise. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-11230: Use after free in Extensions. Reported by Google. - CVE-2026-11231: Inappropriate implementation in Safe Browsing. Reported by Google. - CVE-2026-11232: Inappropriate implementation in TabGroups. Reported by Google. - CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs. Reported by Google. - CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs. Reported by Google. - CVE-2026-11235: Insufficient validation of untrusted input in Compositing. Reported by Google. - CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth. Reported by Google. - CVE-2026-11237: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11238: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11239: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11240: Insufficient validation of untrusted input in Loader. Reported by Google. - CVE-2026-11241: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11242: Insufficient validation of untrusted input in Plugins. Reported by Google. - CVE-2026-11243: Incorrect security UI in Downloads. Reported by Google. - CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-11245: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB. Reported by Google. - CVE-2026-11247: Insufficient policy enforcement in CustomTabs. Reported by Google. - CVE-2026-11248: Policy bypass in Google Lens. Reported by Google. - CVE-2026-11249: Use after free in Network. Reported by Google. - CVE-2026-11250: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11251: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11252: Policy bypass in Content Settings. Reported by Google. - CVE-2026-11253: Race in Permissions. Reported by Google. - CVE-2026-11254: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API. Reported by Google. - CVE-2026-11256: Out of bounds read in GPU. Reported by Google. - CVE-2026-11257: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-11258: Inappropriate implementation in File System Access. Reported by Google. - CVE-2026-11259: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11260: Policy bypass in Permissions. Reported by Google. - CVE-2026-11261: Insufficient validation of untrusted input in PDF. Reported by Google. - CVE-2026-11262: Use after free in TabStrip. Reported by Google. - CVE-2026-11263: Insufficient policy enforcement in WebAuthentication. Reported by Google. - CVE-2026-11264: Policy bypass in Content Security Policy. Reported by Google. - CVE-2026-11265: Insufficient data validation in Autofill. Reported by Google. - CVE-2026-11266: Policy bypass in SafeBrowsing. Reported by Google. - CVE-2026-11267: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11268: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11269: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11270: Inappropriate implementation in UI. Reported by Google. - CVE-2026-11271: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-11272: Insufficient validation of untrusted input in Reading List. Reported by Google. - CVE-2026-11273: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-11274: Inappropriate implementation in DOM Distiller. Reported by Google. - CVE-2026-11275: Insufficient policy enforcement in Page Info. Reported by Google. - CVE-2026-11276: Inappropriate implementation in Cast. Reported by Google - CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11278: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-11279: Out of bounds read in DevTools. Reported by Google. - CVE-2026-11280: Insufficient validation of untrusted input in Signin. Reported by Google. - CVE-2026-11281: Integer overflow in Chromoting. Reported by Google. - CVE-2026-11282: Policy bypass in Sandbox. Reported by Google. - CVE-2026-11283: Policy bypass in Shortcuts. Reported by Google. - CVE-2026-11284: Side-channel information leakage in PerformanceAPIs. Reported by Google. - CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11286: Insufficient validation of untrusted input in Wallet. Reported by Google. - CVE-2026-11287: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-11288: Policy bypass in CSS. Reported by Google. - CVE-2026-11289: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-11290: Integer overflow in WebView. Reported by Google. - CVE-2026-11291: Policy bypass in Android Autofill. Reported by Google. - CVE-2026-11292: Policy bypass in Blink. Reported by Google. - CVE-2026-11293: Use after free in Input. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11294: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11295: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11296: Inappropriate implementation in ImageCapture. Reported by Google. - CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode. Reported by Google. - CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11299: Out of bounds read in Fonts. Reported by sharadboni@gmail.com. - CVE-2026-11300: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11301: Out of bounds read in LiveCaption. Reported by Google. - CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11303: Use after free in PDFium. Reported by Google. - CVE-2026-11304: Use after free in PDFium. Reported by Google. - CVE-2026-11305: Use after free in PDFium. Reported by Google. - CVE-2026-11306: Use after free in PDFium. Reported by Google. - CVE-2026-11307: Use after free in PDFium. Reported by Google. - CVE-2026-11308: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11309: Insufficient policy enforcement in History. Reported by Google. * d/patches: - upstream/turboshaft.patch: drop, merged upstream. - fixes/enable-widevine-on-arm64-linux-platform.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/armhf-icf.patch: refresh. - disable/catapult.patch: refresh. - llvm-19/clang19.patch: add more bits to drop unsupported warning and diagnostic flags. - trixie/gn-inputs.patch: drop portion of patch due to upstream changes. - trixie/gn-inputs2.patch: refresh. - bookworm/bindgen.patch: drop due to upgraded bindgen [sid, trixie]. - bookworm/gn-allowlist.patch: drop due to upgraded generate-ninja [sid, trixie]. - llvm-22/ignore-for-ubsan.patch: update for upstream reworking. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - trixie/gn-expand-dir-allowlist.patch: add new patch to work around older generate-ninja. - fixes/libcpp-headers.patch: update for upstream changes reworking how this was done. - disable/libei.patch: add patch to fix build failure due to libei removal. - llvm-19/value-or.patch: add another clang-19 build workaround. - llvm-19/const-profile.patch: add patch to work around const-related clang-19 build failure. - rust-1.85/file_as_c_str.patch: rework patch due to upstream changes [trixie, bookworm]. - rust-1.85/zip8.patch: refresh [trixie, bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. * d/copyright: properly delete harfbuzz (due to harfbuzz-ng rename). . [ Daniel Richard G. ] * d/patches: - bookworm/bindgen.patch: Refresh [bookworm]. - bookworm/gn-absl.patch: Update absl_source_set("no_destructor") with visibility directive, and refresh [bookworm]. - rust-1.85/mojo-features.patch: Add feature to new Rust source file [trixie, bookworm]. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/0005-blink-add-audio-vector-support.patch: refresh for upstream changes - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: regenerate - third_party/0003-third_party-libvpx-Add-ppc64-generated-config.patch: regenerate - third_party/0001-third_party-libvpx-Disable-vsx-on-ppc64.patch: ensure VSX is disabled until VP9 artifacting can be fixed upstream . [ Jianfeng Liu ] * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: This is a patch aleady merged to v150 to fix build on loongarch64. - loongarch64/0024-fix-libyuv-lsx.patch: Upstream has bumped the version of libyuv and it has broken build with lsx enabled on loongarch64. Add a patch to fix the build first. chromium (149.0.7827.53-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-10881: Out of bounds read and write in ANGLE. Reported by Anonymous. - CVE-2026-10882: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10883: Out of bounds write in ANGLE. Reported by Maher Azzouzi. - CVE-2026-10884: Use after free in Chromecast. Reported by Google. - CVE-2026-10885: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10886: Use after free in FileSystem. Reported by Andrew Boni. - CVE-2026-10887: Use after free in Chromoting. Reported by Google. - CVE-2026-10888: Use after free in Cast Streaming. Reported by Google. - CVE-2026-10889: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10890: Use after free in Cast. Reported by Google. - CVE-2026-10891: Use after free in GFX. Reported by Google. - CVE-2026-10892: Out of bounds write in GPU. Reported by Google. - CVE-2026-10893: Use after free in Chromoting. Reported by Google. - CVE-2026-10894: Use after free in Printing. Reported by Google. - CVE-2026-10895: Use after free in Ozone. Reported by Google. - CVE-2026-10896: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10897: Out of bounds write in GPU. Reported by Google. - CVE-2026-10898: Stack buffer overflow in GPU. Reported by Google. - CVE-2026-10899: Use after free in Ozone. Reported by Google. - CVE-2026-10900: Use after free in Passwords. Reported by Google. - CVE-2026-10901: Use after free in Passwords. Reported by Google. - CVE-2026-10902: Use after free in Ozone. Reported by Google. - CVE-2026-10903: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10904: Inappropriate implementation in V8. Reported by 303f06e3 - CVE-2026-10905: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10906: Use after free in WebAuthentication. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10907: Out of bounds write in ANGLE. Reported by sweetchip. - CVE-2026-10908: Use after free in FullScreen. Reported by Mihnea Nicolau - CVE-2026-10909: Use after free in Dawn. Reported by whiter@xuanyusec. - CVE-2026-10910: Type Confusion in V8. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10911: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10912: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-10913: Use after free in ANGLE. Reported by Google. - CVE-2026-10914: Use after free in ANGLE. Reported by Google. - CVE-2026-10915: Use after free in Core. Reported by Google. - CVE-2026-10916: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10917: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10918: Use after free in Viz. Reported by Google. - CVE-2026-10919: Use after free in ANGLE. Reported by Google. - CVE-2026-10920: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-10921: Integer overflow in Dawn. Reported by Google. - CVE-2026-10922: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10923: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10924: Integer overflow in Chromecast. Reported by Google. - CVE-2026-10925: Out of bounds write in Skia. Reported by Google. - CVE-2026-10926: Use after free in Cast. Reported by Google. - CVE-2026-10927: Out of bounds read in Dawn. Reported by Google. - CVE-2026-10928: Script injection in Headless. Reported by Google. - CVE-2026-10929: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-10930: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10931: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-10932: Use after free in UI. Reported by Google. - CVE-2026-10933: Use after free in Audio. Reported by Google. - CVE-2026-10934: Use after free in Autofill. Reported by Google. - CVE-2026-10935: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10936: Type Confusion in V8. Reported by Google. - CVE-2026-10937: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-10938: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-10939: Use after free in WebRTC. Reported by Google. - CVE-2026-10940: Race in Codecs. Reported by Google. - CVE-2026-10941: Out of bounds memory access in Skia. Reported by Google. - CVE-2026-10942: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-10943: Use after free in WebRTC. Reported by Rayyan Kadar. - CVE-2026-10944: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10945: Use after free in PDF. Reported by Google. - CVE-2026-10946: Heap buffer overflow in Media. Reported by Google. - CVE-2026-10947: Use after free in WebRTC. Reported by Google. - CVE-2026-10948: Use after free in WebRTC. Reported by Google. - CVE-2026-10949: Heap buffer overflow in Video. Reported by Google. - CVE-2026-10950: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10951: Use after free in Autofill. Reported by Google. - CVE-2026-10952: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10953: Use after free in Core. Reported by Google. - CVE-2026-10954: Use after free in Actor. Reported by Google. - CVE-2026-10955: Type Confusion in ANGLE. Reported by Google. - CVE-2026-10956: Use after free in MimeHandlerView. Reported by Google. - CVE-2026-10957: Use after free in Glic. Reported by Google. - CVE-2026-10958: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10959: Use after free in Input. Reported by Google. - CVE-2026-10960: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-10961: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10962: Type Confusion in Media. Reported by Google. - CVE-2026-10963: Integer overflow in V8. Reported by Google. - CVE-2026-10964: Integer overflow in V8. Reported by Google. - CVE-2026-10965: Integer overflow in DevTools. Reported by Google. - CVE-2026-10966: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10967: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-10968: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10969: Insufficient validation of untrusted input in Extensions Reported by Google. - CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups. Reported by Google. - CVE-2026-10971: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-10972: Use after free in Ozone. Reported by Google. - CVE-2026-10973: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10974: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-10975: Use after free in WebRTC. Reported by Google. - CVE-2026-10976: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10977: Uninitialized Use in Skia. Reported by Google. - CVE-2026-10978: Use after free in Chromoting. Reported by Google. - CVE-2026-10979: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10980: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10981: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10982: Use after free in WebXR. Reported by Google. - CVE-2026-10983: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10984: Inappropriate implementation in Accessibility. Reported by Google. - CVE-2026-10985: Out of bounds read in Skia. Reported by Google. - CVE-2026-10986: Integer overflow in Media. Reported by Google. - CVE-2026-10987: Integer overflow in V8. Reported by Google. - CVE-2026-10988: Use after free in Views. Reported by Google. - CVE-2026-10989: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10990: Use after free in Glic. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10991: Use after free in V8. Reported by Alisa Esage (@alisaesage). - CVE-2026-10992: Insufficient data validation in Animation. Reported by heapracer (@heapracer). - CVE-2026-10993: Heap buffer overflow in Skia. Reported by M. Fauzan Wijaya (Gh05t666nero). - CVE-2026-10994: Uninitialized Use in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10995: Heap buffer overflow in TabStrip. Reported by Sven Dysthe (@svn-dys). - CVE-2026-10996: Inappropriate implementation in Workers. Reported by Jayateertha Guruprasad. - CVE-2026-10997: Insufficient policy enforcement in Extensions. Reported by djallalakira@gmail.com. - CVE-2026-10998: Out of bounds read in Media. Reported by Ameen Basha M K - CVE-2026-10999: Out of bounds memory access in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11000: Use after free in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11001: Incorrect security UI in Payments. Reported by Google. - CVE-2026-11002: Use after free in Autofill. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11003: Use after free in WebRTC. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-11004: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11005: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11006: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11007: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11009: Use after free in USB. Reported by Google. - CVE-2026-11010: Use after free in WebShare. Reported by David Sievers. - CVE-2026-11011: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11012: Use after free in Serial. Reported by Google. - CVE-2026-11013: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11014: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11015: Out of bounds read in WebGPU. Reported by Yuma Takeuchi. - CVE-2026-11016: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11017: Inappropriate implementation in Link Preview. Reported by Google. - CVE-2026-11018: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11019: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11020: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11021: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11022: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11024: Stack buffer overflow in Skia. Reported by Google. - CVE-2026-11025: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-11026: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11027: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-11028: Use after free in Media. Reported by Google. - CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop. Reported by Google. - CVE-2026-11030: Use after free in Network. Reported by Google. - CVE-2026-11031: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11032: Insufficient data validation in Password Manager. Reported by Google. - CVE-2026-11033: Uninitialized Use in WebML. Reported by Google. - CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync. Reported by Google. - CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs. Reported by Google. - CVE-2026-11036: Inappropriate implementation in DOM. Reported by Google - CVE-2026-11037: Out of bounds write in Codecs. Reported by Google. - CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity. Reported by Google. - CVE-2026-11039: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11040: Use after free in ANGLE. Reported by Google. - CVE-2026-11041: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11042: Use after free in Views. Reported by Google. - CVE-2026-11043: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-11044: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11045: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11046: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11047: Insufficient validation of untrusted input in Base. Reported by Google. - CVE-2026-11048: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11049: Use after free in Password Manager. Reported by Google. - CVE-2026-11050: Use after free in V8. Reported by Google. - CVE-2026-11051: Out of bounds read in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11052: Type Confusion in GPU. Reported by Google. - CVE-2026-11053: VULNERABILITY in WebRTC. Reported by Google. - CVE-2026-11054: Use after free in WebRTC. Reported by Google. - CVE-2026-11055: Use after free in ANGLE. Reported by Google. - CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-11057: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11058: Integer overflow in CredentialProvider. Reported by Google. - CVE-2026-11059: Use after free in Blink. Reported by Google. - CVE-2026-11060: Use after free in Media. Reported by Google. - CVE-2026-11061: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11062: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11063: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-11064: Uninitialized Use in GPU. Reported by Google. - CVE-2026-11065: Use after free in ANGLE. Reported by Google. - CVE-2026-11066: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11067: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11068: Use after free in WebSockets. Reported by Google. - CVE-2026-11069: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11070: Insufficient validation of untrusted input in Chromoting Reported by Google. - CVE-2026-11071: Use after free in Base. Reported by Google. - CVE-2026-11072: Use after free in WebView. Reported by Google. - CVE-2026-11073: Use after free in WebGL. Reported by Google. - CVE-2026-11074: Use after free in WebRTC. Reported by boboliverfrancishoward@gmail.com. - CVE-2026-11075: Out of bounds read in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-11076: Type Confusion in CSS. Reported by Google. - CVE-2026-11077: Out of bounds read in Dawn. Reported by Anonymous. - CVE-2026-11078: Insufficient validation of untrusted input in FileSystem. Reported by Eran Rom of Palo Alto Networks. - CVE-2026-11079: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11080: Use after free in WebView. Reported by Google. - CVE-2026-11081: Policy bypass in Canvas. Reported by Google. - CVE-2026-11082: Use after free in GPU. Reported by Google. - CVE-2026-11083: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11084: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11085: Integer overflow in GPU. Reported by Google. - CVE-2026-11086: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11087: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11088: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11089: Uninitialized Use in Media. Reported by Google. - CVE-2026-11090: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11091: Inappropriate implementation in Dawn. Reported by Google - CVE-2026-11092: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11093: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-11094: Use after free in Codecs. Reported by Google. - CVE-2026-11095: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11096: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11097: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11098: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11099: Vulnerability in Skia. Reported by Google. - CVE-2026-11100: Use after free in File Input. Reported by Google. - CVE-2026-11101: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11102: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-11103: Inappropriate implementation in Installer. Reported by Google. - CVE-2026-11104: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11105: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-11106: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11107: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-11108: Inappropriate implementation in NFC. Reported by Google - CVE-2026-11109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11110: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11111: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11112: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11113: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11114: Use after free in Device Trust. Reported by Google. - CVE-2026-11115: Use after free in Updater. Reported by Google. - CVE-2026-11116: Use after free in Chromoting. Reported by Google. - CVE-2026-11117: Use after free in Views. Reported by Google. - CVE-2026-11118: Use after free in WebRTC. Reported by Google. - CVE-2026-11119: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting. Reported by Google. - CVE-2026-11121: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11122: Inappropriate implementation in Keyboard. Reported by Google. - CVE-2026-11123: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11124: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-11125: Use after free in Compositing. Reported by Google. - CVE-2026-11126: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11127: Inappropriate implementation in WebAPKs. Reported by Google. - CVE-2026-11128: Insufficient validation of untrusted input in Web Share. Reported by Google. - CVE-2026-11129: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11130: Use after free in Media. Reported by Google. - CVE-2026-11131: Use after free in Autofill. Reported by Google. - CVE-2026-11132: Policy bypass in Paint. Reported by Google. - CVE-2026-11133: Insufficient policy enforcement in Paint. Reported by Google. - CVE-2026-11134: Insufficient data validation in Media. Reported by Google. - CVE-2026-11135: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-11136: Use after free in Canvas. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-11137: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11138: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11139: Policy bypass in Paint. Reported by Google. - CVE-2026-11140: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-11141: Uninitialized Use in Audio. Reported by Google. - CVE-2026-11142: Policy bypass in Paint. Reported by Google. - CVE-2026-11143: Heap buffer overflow in Extensions. Reported by Google. - CVE-2026-11144: Use after free in Media. Reported by Google. - CVE-2026-11145: Race in Geolocation. Reported by Google. - CVE-2026-11146: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11147: Use after free in WebML. Reported by Google. - CVE-2026-11148: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11149: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11150: Inappropriate implementation in XML. Reported by Google - CVE-2026-11151: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11152: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-11153: Side-channel information leakage in Forms. Reported by Google. - CVE-2026-11154: Use after free in Dawn. Reported by Google. - CVE-2026-11155: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11156: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11157: Script injection in Accessibility. Reported by Google. - CVE-2026-11158: Insufficient validation of untrusted input in Downloads. Reported by Google. - CVE-2026-11159: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11160: Out of bounds read in Input. Reported by Google. - CVE-2026-11161: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-11162: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11163: Use after free in Messages. Reported by Google. - CVE-2026-11164: Use after free in Blink. Reported by Google. - CVE-2026-11165: Use after free in WebMIDI. Reported by Google. - CVE-2026-11166: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11167: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11168: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11169: Inappropriate implementation in XML. Reported by Google - CVE-2026-11170: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-11171: Integer overflow in Blink. Reported by Google. - CVE-2026-11172: Incorrect security UI in Contact Picker. Reported by mochazril.ti@gmail.com. - CVE-2026-11173: Out of bounds write in V8. Reported by Google. - CVE-2026-11174: Insufficient policy enforcement in Site Isolation. Reported by Google. - CVE-2026-11175: Incorrect security UI in Messages. Reported by Google. - CVE-2026-11176: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11177: Use after free in Omnibox. Reported by gevakun. - CVE-2026-11178: Policy bypass in WebView. Reported by Google. - CVE-2026-11179: Inappropriate implementation in ORB. Reported by Google - CVE-2026-11180: Policy bypass in SVG. Reported by Google. - CVE-2026-11181: Inappropriate implementation in Media Session. Reported by Google. - CVE-2026-11182: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11183: Out of bounds read in GWP-ASan. Reported by Google. - CVE-2026-11184: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11185: Use after free in V8. Reported by Google. - CVE-2026-11186: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11187: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-11188: Use after free in USB. Reported by Google. - CVE-2026-11189: Insufficient validation of untrusted input in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-11190: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11191: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-11192: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11193: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11194: Inappropriate implementation in Network. Reported by Google. - CVE-2026-11195: Inappropriate implementation in MHTML. Reported by Google. - CVE-2026-11196: Type Confusion in XML. Reported by Google. - CVE-2026-11197: Insufficient policy enforcement in Workers. Reported by VEZEKA. - CVE-2026-11198: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11199: Insufficient validation of untrusted input in WebRTC. Reported by Google. - CVE-2026-11200: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-11201: Use after free in ServiceWorker. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11203: Policy bypass in GPU. Reported by Google. - CVE-2026-11204: Inappropriate implementation in Signin. Reported by Google. - CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11206: Policy bypass in ServiceWorker. Reported by David Bors, Catalin Iovita. - CVE-2026-11207: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-11208: Use after free in Codecs. Reported by Google. - CVE-2026-11209: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-11210: Insufficient policy enforcement in Safe Browsing. Reported by Google. - CVE-2026-11211: Integer overflow in V8. Reported by Google. - CVE-2026-11212: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode. Reported by Google. - CVE-2026-11214: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-11215: Inappropriate implementation in Cronet. Reported by Google. - CVE-2026-11216: Incorrect security UI in File Input. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-11217: Insufficient policy enforcement in Fenced Frames. Reported by Tianyi Hu. - CVE-2026-11218: Inappropriate implementation in PlatformIntegration. Reported by Han Liu (Xi’an Jiaotong University, School of Cyber Science and Engineering). - CVE-2026-11219: Insufficient data validation in Navigation. Reported by Bharat (mrnoob) . - CVE-2026-11220: Insufficient validation of untrusted input in Navigation. Reported by Tianyi Hu. - CVE-2026-11221: Insufficient validation of untrusted input in PointerLock. Reported by mihalis.haatainen@bountyy.fi. - CVE-2026-11222: Incorrect security UI in Tab Strip. Reported by Hafiizh - CVE-2026-11223: Insufficient validation of untrusted input in Network. Reported by Tianyi Hu. - CVE-2026-11224: Use after free in Chromoting. Reported by David Bors, Catalin Iovita. - CVE-2026-11225: Incorrect security UI in WebUI. Reported by Tareq Ahamed - itztrq. - CVE-2026-11226: Insufficient policy enforcement in PreviewTab. Reported by Google. - CVE-2026-11227: Incorrect security UI in Tab Hover Cards. Reported by Hafiizh. - CVE-2026-11228: Incorrect security UI in File Input. Reported by Umar Farooq . - CVE-2026-11229: Insufficient policy enforcement in Enterprise. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-11230: Use after free in Extensions. Reported by Google. - CVE-2026-11231: Inappropriate implementation in Safe Browsing. Reported by Google. - CVE-2026-11232: Inappropriate implementation in TabGroups. Reported by Google. - CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs. Reported by Google. - CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs. Reported by Google. - CVE-2026-11235: Insufficient validation of untrusted input in Compositing. Reported by Google. - CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth. Reported by Google. - CVE-2026-11237: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11238: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11239: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11240: Insufficient validation of untrusted input in Loader. Reported by Google. - CVE-2026-11241: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11242: Insufficient validation of untrusted input in Plugins. Reported by Google. - CVE-2026-11243: Incorrect security UI in Downloads. Reported by Google. - CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-11245: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB. Reported by Google. - CVE-2026-11247: Insufficient policy enforcement in CustomTabs. Reported by Google. - CVE-2026-11248: Policy bypass in Google Lens. Reported by Google. - CVE-2026-11249: Use after free in Network. Reported by Google. - CVE-2026-11250: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11251: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11252: Policy bypass in Content Settings. Reported by Google. - CVE-2026-11253: Race in Permissions. Reported by Google. - CVE-2026-11254: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API. Reported by Google. - CVE-2026-11256: Out of bounds read in GPU. Reported by Google. - CVE-2026-11257: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-11258: Inappropriate implementation in File System Access. Reported by Google. - CVE-2026-11259: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11260: Policy bypass in Permissions. Reported by Google. - CVE-2026-11261: Insufficient validation of untrusted input in PDF. Reported by Google. - CVE-2026-11262: Use after free in TabStrip. Reported by Google. - CVE-2026-11263: Insufficient policy enforcement in WebAuthentication. Reported by Google. - CVE-2026-11264: Policy bypass in Content Security Policy. Reported by Google. - CVE-2026-11265: Insufficient data validation in Autofill. Reported by Google. - CVE-2026-11266: Policy bypass in SafeBrowsing. Reported by Google. - CVE-2026-11267: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11268: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11269: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11270: Inappropriate implementation in UI. Reported by Google. - CVE-2026-11271: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-11272: Insufficient validation of untrusted input in Reading List. Reported by Google. - CVE-2026-11273: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-11274: Inappropriate implementation in DOM Distiller. Reported by Google. - CVE-2026-11275: Insufficient policy enforcement in Page Info. Reported by Google. - CVE-2026-11276: Inappropriate implementation in Cast. Reported by Google - CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11278: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-11279: Out of bounds read in DevTools. Reported by Google. - CVE-2026-11280: Insufficient validation of untrusted input in Signin. Reported by Google. - CVE-2026-11281: Integer overflow in Chromoting. Reported by Google. - CVE-2026-11282: Policy bypass in Sandbox. Reported by Google. - CVE-2026-11283: Policy bypass in Shortcuts. Reported by Google. - CVE-2026-11284: Side-channel information leakage in PerformanceAPIs. Reported by Google. - CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11286: Insufficient validation of untrusted input in Wallet. Reported by Google. - CVE-2026-11287: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-11288: Policy bypass in CSS. Reported by Google. - CVE-2026-11289: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-11290: Integer overflow in WebView. Reported by Google. - CVE-2026-11291: Policy bypass in Android Autofill. Reported by Google. - CVE-2026-11292: Policy bypass in Blink. Reported by Google. - CVE-2026-11293: Use after free in Input. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11294: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11295: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11296: Inappropriate implementation in ImageCapture. Reported by Google. - CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode. Reported by Google. - CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11299: Out of bounds read in Fonts. Reported by sharadboni@gmail.com. - CVE-2026-11300: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11301: Out of bounds read in LiveCaption. Reported by Google. - CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11303: Use after free in PDFium. Reported by Google. - CVE-2026-11304: Use after free in PDFium. Reported by Google. - CVE-2026-11305: Use after free in PDFium. Reported by Google. - CVE-2026-11306: Use after free in PDFium. Reported by Google. - CVE-2026-11307: Use after free in PDFium. Reported by Google. - CVE-2026-11308: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11309: Insufficient policy enforcement in History. Reported by Google. * d/patches: - upstream/turboshaft.patch: drop, merged upstream. - fixes/enable-widevine-on-arm64-linux-platform.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/armhf-icf.patch: refresh. - disable/catapult.patch: refresh. - llvm-19/clang19.patch: add more bits to drop unsupported warning and diagnostic flags. - trixie/gn-inputs.patch: drop portion of patch due to upstream changes. - trixie/gn-inputs2.patch: refresh. - bookworm/bindgen.patch: drop due to upgraded bindgen [sid, trixie]. - bookworm/gn-allowlist.patch: drop due to upgraded generate-ninja [sid, trixie]. - llvm-22/ignore-for-ubsan.patch: update for upstream reworking. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - trixie/gn-expand-dir-allowlist.patch: add new patch to work around older generate-ninja. - fixes/libcpp-headers.patch: update for upstream changes reworking how this was done. - disable/libei.patch: add patch to fix build failure due to libei removal. - llvm-19/value-or.patch: add another clang-19 build workaround. - llvm-19/const-profile.patch: add patch to work around const-related clang-19 build failure. - rust-1.85/file_as_c_str.patch: rework patch due to upstream changes [trixie, bookworm]. - rust-1.85/zip8.patch: refresh [trixie, bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. * d/copyright: properly delete harfbuzz (due to harfbuzz-ng rename). . [ Daniel Richard G. ] * d/patches: - bookworm/bindgen.patch: Refresh [bookworm]. - bookworm/gn-absl.patch: Update absl_source_set("no_destructor") with visibility directive, and refresh [bookworm]. - rust-1.85/mojo-features.patch: Add feature to new Rust source file [trixie, bookworm]. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/0005-blink-add-audio-vector-support.patch: refresh for upstream changes - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: regenerate - third_party/0003-third_party-libvpx-Add-ppc64-generated-config.patch: regenerate - third_party/0001-third_party-libvpx-Disable-vsx-on-ppc64.patch: ensure VSX is disabled until VP9 artifacting can be fixed upstream . [ Jianfeng Liu ] * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: This is a patch aleady merged to v150 to fix build on loongarch64. - loongarch64/0024-fix-libyuv-lsx.patch: Upstream has bumped the version of libyuv and it has broken build with lsx enabled on loongarch64. Add a patch to fix the build first. chromium (149.0.7827.53-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-10881: Out of bounds read and write in ANGLE. Reported by Anonymous. - CVE-2026-10882: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10883: Out of bounds write in ANGLE. Reported by Maher Azzouzi. - CVE-2026-10884: Use after free in Chromecast. Reported by Google. - CVE-2026-10885: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10886: Use after free in FileSystem. Reported by Andrew Boni. - CVE-2026-10887: Use after free in Chromoting. Reported by Google. - CVE-2026-10888: Use after free in Cast Streaming. Reported by Google. - CVE-2026-10889: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10890: Use after free in Cast. Reported by Google. - CVE-2026-10891: Use after free in GFX. Reported by Google. - CVE-2026-10892: Out of bounds write in GPU. Reported by Google. - CVE-2026-10893: Use after free in Chromoting. Reported by Google. - CVE-2026-10894: Use after free in Printing. Reported by Google. - CVE-2026-10895: Use after free in Ozone. Reported by Google. - CVE-2026-10896: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10897: Out of bounds write in GPU. Reported by Google. - CVE-2026-10898: Stack buffer overflow in GPU. Reported by Google. - CVE-2026-10899: Use after free in Ozone. Reported by Google. - CVE-2026-10900: Use after free in Passwords. Reported by Google. - CVE-2026-10901: Use after free in Passwords. Reported by Google. - CVE-2026-10902: Use after free in Ozone. Reported by Google. - CVE-2026-10903: Use after free in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10904: Inappropriate implementation in V8. Reported by 303f06e3 - CVE-2026-10905: Use after free in Network. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10906: Use after free in WebAuthentication. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10907: Out of bounds write in ANGLE. Reported by sweetchip. - CVE-2026-10908: Use after free in FullScreen. Reported by Mihnea Nicolau - CVE-2026-10909: Use after free in Dawn. Reported by whiter@xuanyusec. - CVE-2026-10910: Type Confusion in V8. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10911: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10912: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-10913: Use after free in ANGLE. Reported by Google. - CVE-2026-10914: Use after free in ANGLE. Reported by Google. - CVE-2026-10915: Use after free in Core. Reported by Google. - CVE-2026-10916: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10917: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-10918: Use after free in Viz. Reported by Google. - CVE-2026-10919: Use after free in ANGLE. Reported by Google. - CVE-2026-10920: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-10921: Integer overflow in Dawn. Reported by Google. - CVE-2026-10922: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10923: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10924: Integer overflow in Chromecast. Reported by Google. - CVE-2026-10925: Out of bounds write in Skia. Reported by Google. - CVE-2026-10926: Use after free in Cast. Reported by Google. - CVE-2026-10927: Out of bounds read in Dawn. Reported by Google. - CVE-2026-10928: Script injection in Headless. Reported by Google. - CVE-2026-10929: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-10930: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10931: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-10932: Use after free in UI. Reported by Google. - CVE-2026-10933: Use after free in Audio. Reported by Google. - CVE-2026-10934: Use after free in Autofill. Reported by Google. - CVE-2026-10935: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10936: Type Confusion in V8. Reported by Google. - CVE-2026-10937: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-10938: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-10939: Use after free in WebRTC. Reported by Google. - CVE-2026-10940: Race in Codecs. Reported by Google. - CVE-2026-10941: Out of bounds memory access in Skia. Reported by Google. - CVE-2026-10942: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-10943: Use after free in WebRTC. Reported by Rayyan Kadar. - CVE-2026-10944: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10945: Use after free in PDF. Reported by Google. - CVE-2026-10946: Heap buffer overflow in Media. Reported by Google. - CVE-2026-10947: Use after free in WebRTC. Reported by Google. - CVE-2026-10948: Use after free in WebRTC. Reported by Google. - CVE-2026-10949: Heap buffer overflow in Video. Reported by Google. - CVE-2026-10950: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-10951: Use after free in Autofill. Reported by Google. - CVE-2026-10952: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10953: Use after free in Core. Reported by Google. - CVE-2026-10954: Use after free in Actor. Reported by Google. - CVE-2026-10955: Type Confusion in ANGLE. Reported by Google. - CVE-2026-10956: Use after free in MimeHandlerView. Reported by Google. - CVE-2026-10957: Use after free in Glic. Reported by Google. - CVE-2026-10958: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10959: Use after free in Input. Reported by Google. - CVE-2026-10960: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-10961: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-10962: Type Confusion in Media. Reported by Google. - CVE-2026-10963: Integer overflow in V8. Reported by Google. - CVE-2026-10964: Integer overflow in V8. Reported by Google. - CVE-2026-10965: Integer overflow in DevTools. Reported by Google. - CVE-2026-10966: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10967: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-10968: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10969: Insufficient validation of untrusted input in Extensions Reported by Google. - CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups. Reported by Google. - CVE-2026-10971: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-10972: Use after free in Ozone. Reported by Google. - CVE-2026-10973: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10974: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-10975: Use after free in WebRTC. Reported by Google. - CVE-2026-10976: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-10977: Uninitialized Use in Skia. Reported by Google. - CVE-2026-10978: Use after free in Chromoting. Reported by Google. - CVE-2026-10979: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-10980: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-10981: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-10982: Use after free in WebXR. Reported by Google. - CVE-2026-10983: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-10984: Inappropriate implementation in Accessibility. Reported by Google. - CVE-2026-10985: Out of bounds read in Skia. Reported by Google. - CVE-2026-10986: Integer overflow in Media. Reported by Google. - CVE-2026-10987: Integer overflow in V8. Reported by Google. - CVE-2026-10988: Use after free in Views. Reported by Google. - CVE-2026-10989: Inappropriate implementation in V8. Reported by Google. - CVE-2026-10990: Use after free in Glic. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-10991: Use after free in V8. Reported by Alisa Esage (@alisaesage). - CVE-2026-10992: Insufficient data validation in Animation. Reported by heapracer (@heapracer). - CVE-2026-10993: Heap buffer overflow in Skia. Reported by M. Fauzan Wijaya (Gh05t666nero). - CVE-2026-10994: Uninitialized Use in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10995: Heap buffer overflow in TabStrip. Reported by Sven Dysthe (@svn-dys). - CVE-2026-10996: Inappropriate implementation in Workers. Reported by Jayateertha Guruprasad. - CVE-2026-10997: Insufficient policy enforcement in Extensions. Reported by djallalakira@gmail.com. - CVE-2026-10998: Out of bounds read in Media. Reported by Ameen Basha M K - CVE-2026-10999: Out of bounds memory access in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11000: Use after free in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11001: Incorrect security UI in Payments. Reported by Google. - CVE-2026-11002: Use after free in Autofill. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11003: Use after free in WebRTC. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. - CVE-2026-11004: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11005: Out of bounds read in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-11006: Out of bounds read in Dawn. Reported by Google. - CVE-2026-11007: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11009: Use after free in USB. Reported by Google. - CVE-2026-11010: Use after free in WebShare. Reported by David Sievers. - CVE-2026-11011: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11012: Use after free in Serial. Reported by Google. - CVE-2026-11013: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11014: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11015: Out of bounds read in WebGPU. Reported by Yuma Takeuchi. - CVE-2026-11016: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-11017: Inappropriate implementation in Link Preview. Reported by Google. - CVE-2026-11018: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11019: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11020: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11021: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11022: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-11024: Stack buffer overflow in Skia. Reported by Google. - CVE-2026-11025: Insufficient policy enforcement in Navigation. Reported by Google. - CVE-2026-11026: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11027: Insufficient validation of untrusted input in Glic. Reported by Google. - CVE-2026-11028: Use after free in Media. Reported by Google. - CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop. Reported by Google. - CVE-2026-11030: Use after free in Network. Reported by Google. - CVE-2026-11031: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11032: Insufficient data validation in Password Manager. Reported by Google. - CVE-2026-11033: Uninitialized Use in WebML. Reported by Google. - CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync. Reported by Google. - CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs. Reported by Google. - CVE-2026-11036: Inappropriate implementation in DOM. Reported by Google - CVE-2026-11037: Out of bounds write in Codecs. Reported by Google. - CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity. Reported by Google. - CVE-2026-11039: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11040: Use after free in ANGLE. Reported by Google. - CVE-2026-11041: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11042: Use after free in Views. Reported by Google. - CVE-2026-11043: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-11044: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11045: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11046: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11047: Insufficient validation of untrusted input in Base. Reported by Google. - CVE-2026-11048: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11049: Use after free in Password Manager. Reported by Google. - CVE-2026-11050: Use after free in V8. Reported by Google. - CVE-2026-11051: Out of bounds read in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-11052: Type Confusion in GPU. Reported by Google. - CVE-2026-11053: VULNERABILITY in WebRTC. Reported by Google. - CVE-2026-11054: Use after free in WebRTC. Reported by Google. - CVE-2026-11055: Use after free in ANGLE. Reported by Google. - CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-11057: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11058: Integer overflow in CredentialProvider. Reported by Google. - CVE-2026-11059: Use after free in Blink. Reported by Google. - CVE-2026-11060: Use after free in Media. Reported by Google. - CVE-2026-11061: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11062: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11063: Insufficient validation of untrusted input in WebNN. Reported by Google. - CVE-2026-11064: Uninitialized Use in GPU. Reported by Google. - CVE-2026-11065: Use after free in ANGLE. Reported by Google. - CVE-2026-11066: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11067: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11068: Use after free in WebSockets. Reported by Google. - CVE-2026-11069: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11070: Insufficient validation of untrusted input in Chromoting Reported by Google. - CVE-2026-11071: Use after free in Base. Reported by Google. - CVE-2026-11072: Use after free in WebView. Reported by Google. - CVE-2026-11073: Use after free in WebGL. Reported by Google. - CVE-2026-11074: Use after free in WebRTC. Reported by boboliverfrancishoward@gmail.com. - CVE-2026-11075: Out of bounds read in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-11076: Type Confusion in CSS. Reported by Google. - CVE-2026-11077: Out of bounds read in Dawn. Reported by Anonymous. - CVE-2026-11078: Insufficient validation of untrusted input in FileSystem. Reported by Eran Rom of Palo Alto Networks. - CVE-2026-11079: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11080: Use after free in WebView. Reported by Google. - CVE-2026-11081: Policy bypass in Canvas. Reported by Google. - CVE-2026-11082: Use after free in GPU. Reported by Google. - CVE-2026-11083: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11084: Inappropriate implementation in Password Manager. Reported by Google. - CVE-2026-11085: Integer overflow in GPU. Reported by Google. - CVE-2026-11086: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-11087: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11088: Integer overflow in ANGLE. Reported by Google. - CVE-2026-11089: Uninitialized Use in Media. Reported by Google. - CVE-2026-11090: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11091: Inappropriate implementation in Dawn. Reported by Google - CVE-2026-11092: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11093: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-11094: Use after free in Codecs. Reported by Google. - CVE-2026-11095: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11096: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-11097: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11098: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11099: Vulnerability in Skia. Reported by Google. - CVE-2026-11100: Use after free in File Input. Reported by Google. - CVE-2026-11101: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-11102: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-11103: Inappropriate implementation in Installer. Reported by Google. - CVE-2026-11104: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11105: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-11106: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11107: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-11108: Inappropriate implementation in NFC. Reported by Google - CVE-2026-11109: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11110: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11111: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-11112: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11113: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-11114: Use after free in Device Trust. Reported by Google. - CVE-2026-11115: Use after free in Updater. Reported by Google. - CVE-2026-11116: Use after free in Chromoting. Reported by Google. - CVE-2026-11117: Use after free in Views. Reported by Google. - CVE-2026-11118: Use after free in WebRTC. Reported by Google. - CVE-2026-11119: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting. Reported by Google. - CVE-2026-11121: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-11122: Inappropriate implementation in Keyboard. Reported by Google. - CVE-2026-11123: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11124: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-11125: Use after free in Compositing. Reported by Google. - CVE-2026-11126: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-11127: Inappropriate implementation in WebAPKs. Reported by Google. - CVE-2026-11128: Insufficient validation of untrusted input in Web Share. Reported by Google. - CVE-2026-11129: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11130: Use after free in Media. Reported by Google. - CVE-2026-11131: Use after free in Autofill. Reported by Google. - CVE-2026-11132: Policy bypass in Paint. Reported by Google. - CVE-2026-11133: Insufficient policy enforcement in Paint. Reported by Google. - CVE-2026-11134: Insufficient data validation in Media. Reported by Google. - CVE-2026-11135: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-11136: Use after free in Canvas. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-11137: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11138: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11139: Policy bypass in Paint. Reported by Google. - CVE-2026-11140: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-11141: Uninitialized Use in Audio. Reported by Google. - CVE-2026-11142: Policy bypass in Paint. Reported by Google. - CVE-2026-11143: Heap buffer overflow in Extensions. Reported by Google. - CVE-2026-11144: Use after free in Media. Reported by Google. - CVE-2026-11145: Race in Geolocation. Reported by Google. - CVE-2026-11146: Insufficient validation of untrusted input in Chromoting. Reported by Google. - CVE-2026-11147: Use after free in WebML. Reported by Google. - CVE-2026-11148: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11149: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11150: Inappropriate implementation in XML. Reported by Google - CVE-2026-11151: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11152: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-11153: Side-channel information leakage in Forms. Reported by Google. - CVE-2026-11154: Use after free in Dawn. Reported by Google. - CVE-2026-11155: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11156: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11157: Script injection in Accessibility. Reported by Google. - CVE-2026-11158: Insufficient validation of untrusted input in Downloads. Reported by Google. - CVE-2026-11159: Uninitialized Use in Skia. Reported by Google. - CVE-2026-11160: Out of bounds read in Input. Reported by Google. - CVE-2026-11161: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-11162: Insufficient policy enforcement in CSS. Reported by Google. - CVE-2026-11163: Use after free in Messages. Reported by Google. - CVE-2026-11164: Use after free in Blink. Reported by Google. - CVE-2026-11165: Use after free in WebMIDI. Reported by Google. - CVE-2026-11166: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11167: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11168: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11169: Inappropriate implementation in XML. Reported by Google - CVE-2026-11170: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-11171: Integer overflow in Blink. Reported by Google. - CVE-2026-11172: Incorrect security UI in Contact Picker. Reported by mochazril.ti@gmail.com. - CVE-2026-11173: Out of bounds write in V8. Reported by Google. - CVE-2026-11174: Insufficient policy enforcement in Site Isolation. Reported by Google. - CVE-2026-11175: Incorrect security UI in Messages. Reported by Google. - CVE-2026-11176: Inappropriate implementation in Media. Reported by Google. - CVE-2026-11177: Use after free in Omnibox. Reported by gevakun. - CVE-2026-11178: Policy bypass in WebView. Reported by Google. - CVE-2026-11179: Inappropriate implementation in ORB. Reported by Google - CVE-2026-11180: Policy bypass in SVG. Reported by Google. - CVE-2026-11181: Inappropriate implementation in Media Session. Reported by Google. - CVE-2026-11182: Inappropriate implementation in SVG. Reported by Google - CVE-2026-11183: Out of bounds read in GWP-ASan. Reported by Google. - CVE-2026-11184: Insufficient policy enforcement in Actor. Reported by Google. - CVE-2026-11185: Use after free in V8. Reported by Google. - CVE-2026-11186: Inappropriate implementation in CSS. Reported by Google - CVE-2026-11187: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-11188: Use after free in USB. Reported by Google. - CVE-2026-11189: Insufficient validation of untrusted input in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-11190: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11191: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-11192: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11193: Insufficient policy enforcement in Password Manager. Reported by Google. - CVE-2026-11194: Inappropriate implementation in Network. Reported by Google. - CVE-2026-11195: Inappropriate implementation in MHTML. Reported by Google. - CVE-2026-11196: Type Confusion in XML. Reported by Google. - CVE-2026-11197: Insufficient policy enforcement in Workers. Reported by VEZEKA. - CVE-2026-11198: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-11199: Insufficient validation of untrusted input in WebRTC. Reported by Google. - CVE-2026-11200: Inappropriate implementation in WebRTC. Reported by Google. - CVE-2026-11201: Use after free in ServiceWorker. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11203: Policy bypass in GPU. Reported by Google. - CVE-2026-11204: Inappropriate implementation in Signin. Reported by Google. - CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-11206: Policy bypass in ServiceWorker. Reported by David Bors, Catalin Iovita. - CVE-2026-11207: Insufficient validation of untrusted input in Autofill. Reported by Google. - CVE-2026-11208: Use after free in Codecs. Reported by Google. - CVE-2026-11209: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-11210: Insufficient policy enforcement in Safe Browsing. Reported by Google. - CVE-2026-11211: Integer overflow in V8. Reported by Google. - CVE-2026-11212: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode. Reported by Google. - CVE-2026-11214: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-11215: Inappropriate implementation in Cronet. Reported by Google. - CVE-2026-11216: Incorrect security UI in File Input. Reported by Azza Tegar Naufal Ataullah. - CVE-2026-11217: Insufficient policy enforcement in Fenced Frames. Reported by Tianyi Hu. - CVE-2026-11218: Inappropriate implementation in PlatformIntegration. Reported by Han Liu (Xi’an Jiaotong University, School of Cyber Science and Engineering). - CVE-2026-11219: Insufficient data validation in Navigation. Reported by Bharat (mrnoob) . - CVE-2026-11220: Insufficient validation of untrusted input in Navigation. Reported by Tianyi Hu. - CVE-2026-11221: Insufficient validation of untrusted input in PointerLock. Reported by mihalis.haatainen@bountyy.fi. - CVE-2026-11222: Incorrect security UI in Tab Strip. Reported by Hafiizh - CVE-2026-11223: Insufficient validation of untrusted input in Network. Reported by Tianyi Hu. - CVE-2026-11224: Use after free in Chromoting. Reported by David Bors, Catalin Iovita. - CVE-2026-11225: Incorrect security UI in WebUI. Reported by Tareq Ahamed - itztrq. - CVE-2026-11226: Insufficient policy enforcement in PreviewTab. Reported by Google. - CVE-2026-11227: Incorrect security UI in Tab Hover Cards. Reported by Hafiizh. - CVE-2026-11228: Incorrect security UI in File Input. Reported by Umar Farooq . - CVE-2026-11229: Insufficient policy enforcement in Enterprise. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-11230: Use after free in Extensions. Reported by Google. - CVE-2026-11231: Inappropriate implementation in Safe Browsing. Reported by Google. - CVE-2026-11232: Inappropriate implementation in TabGroups. Reported by Google. - CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs. Reported by Google. - CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs. Reported by Google. - CVE-2026-11235: Insufficient validation of untrusted input in Compositing. Reported by Google. - CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth. Reported by Google. - CVE-2026-11237: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-11238: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11239: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-11240: Insufficient validation of untrusted input in Loader. Reported by Google. - CVE-2026-11241: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11242: Insufficient validation of untrusted input in Plugins. Reported by Google. - CVE-2026-11243: Incorrect security UI in Downloads. Reported by Google. - CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication. Reported by Google. - CVE-2026-11245: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB. Reported by Google. - CVE-2026-11247: Insufficient policy enforcement in CustomTabs. Reported by Google. - CVE-2026-11248: Policy bypass in Google Lens. Reported by Google. - CVE-2026-11249: Use after free in Network. Reported by Google. - CVE-2026-11250: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-11251: Insufficient validation of untrusted input in Password Manager. Reported by Google. - CVE-2026-11252: Policy bypass in Content Settings. Reported by Google. - CVE-2026-11253: Race in Permissions. Reported by Google. - CVE-2026-11254: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API. Reported by Google. - CVE-2026-11256: Out of bounds read in GPU. Reported by Google. - CVE-2026-11257: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-11258: Inappropriate implementation in File System Access. Reported by Google. - CVE-2026-11259: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-11260: Policy bypass in Permissions. Reported by Google. - CVE-2026-11261: Insufficient validation of untrusted input in PDF. Reported by Google. - CVE-2026-11262: Use after free in TabStrip. Reported by Google. - CVE-2026-11263: Insufficient policy enforcement in WebAuthentication. Reported by Google. - CVE-2026-11264: Policy bypass in Content Security Policy. Reported by Google. - CVE-2026-11265: Insufficient data validation in Autofill. Reported by Google. - CVE-2026-11266: Policy bypass in SafeBrowsing. Reported by Google. - CVE-2026-11267: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-11268: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-11269: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11270: Inappropriate implementation in UI. Reported by Google. - CVE-2026-11271: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-11272: Insufficient validation of untrusted input in Reading List. Reported by Google. - CVE-2026-11273: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-11274: Inappropriate implementation in DOM Distiller. Reported by Google. - CVE-2026-11275: Insufficient policy enforcement in Page Info. Reported by Google. - CVE-2026-11276: Inappropriate implementation in Cast. Reported by Google - CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11278: Inappropriate implementation in CustomTabs. Reported by Google. - CVE-2026-11279: Out of bounds read in DevTools. Reported by Google. - CVE-2026-11280: Insufficient validation of untrusted input in Signin. Reported by Google. - CVE-2026-11281: Integer overflow in Chromoting. Reported by Google. - CVE-2026-11282: Policy bypass in Sandbox. Reported by Google. - CVE-2026-11283: Policy bypass in Shortcuts. Reported by Google. - CVE-2026-11284: Side-channel information leakage in PerformanceAPIs. Reported by Google. - CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11286: Insufficient validation of untrusted input in Wallet. Reported by Google. - CVE-2026-11287: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-11288: Policy bypass in CSS. Reported by Google. - CVE-2026-11289: Side-channel information leakage in Paint. Reported by Google. - CVE-2026-11290: Integer overflow in WebView. Reported by Google. - CVE-2026-11291: Policy bypass in Android Autofill. Reported by Google. - CVE-2026-11292: Policy bypass in Blink. Reported by Google. - CVE-2026-11293: Use after free in Input. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2026-11294: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-11295: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-11296: Inappropriate implementation in ImageCapture. Reported by Google. - CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode. Reported by Google. - CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11299: Out of bounds read in Fonts. Reported by sharadboni@gmail.com. - CVE-2026-11300: Inappropriate implementation in Permissions. Reported by Google. - CVE-2026-11301: Out of bounds read in LiveCaption. Reported by Google. - CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-11303: Use after free in PDFium. Reported by Google. - CVE-2026-11304: Use after free in PDFium. Reported by Google. - CVE-2026-11305: Use after free in PDFium. Reported by Google. - CVE-2026-11306: Use after free in PDFium. Reported by Google. - CVE-2026-11307: Use after free in PDFium. Reported by Google. - CVE-2026-11308: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-11309: Insufficient policy enforcement in History. Reported by Google. * d/patches: - upstream/turboshaft.patch: drop, merged upstream. - fixes/enable-widevine-on-arm64-linux-platform.patch: drop, merged upstream. - debianization/clang-version.patch: refresh. - fixes/armhf-icf.patch: refresh. - disable/catapult.patch: refresh. - llvm-19/clang19.patch: add more bits to drop unsupported warning and diagnostic flags. - trixie/gn-inputs.patch: drop portion of patch due to upstream changes. - trixie/gn-inputs2.patch: refresh. - bookworm/bindgen.patch: drop due to upgraded bindgen [sid, trixie]. - bookworm/gn-allowlist.patch: drop due to upgraded generate-ninja [sid, trixie]. - llvm-22/ignore-for-ubsan.patch: update for upstream reworking. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - ungoogled/remove-navigation-source-param.patch: sync from u-c. - trixie/gn-expand-dir-allowlist.patch: add new patch to work around older generate-ninja. - fixes/libcpp-headers.patch: update for upstream changes reworking how this was done. - disable/libei.patch: add patch to fix build failure due to libei removal. - llvm-19/value-or.patch: add another clang-19 build workaround. - llvm-19/const-profile.patch: add patch to work around const-related clang-19 build failure. - rust-1.85/file_as_c_str.patch: rework patch due to upstream changes [trixie, bookworm]. - rust-1.85/zip8.patch: refresh [trixie, bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. * d/copyright: properly delete harfbuzz (due to harfbuzz-ng rename). . [ Daniel Richard G. ] * d/patches: - bookworm/bindgen.patch: Refresh [bookworm]. - bookworm/gn-absl.patch: Update absl_source_set("no_destructor") with visibility directive, and refresh [bookworm]. - rust-1.85/mojo-features.patch: Add feature to new Rust source file [trixie, bookworm]. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/0005-blink-add-audio-vector-support.patch: refresh for upstream changes - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: regenerate - third_party/0003-third_party-libvpx-Add-ppc64-generated-config.patch: regenerate - third_party/0001-third_party-libvpx-Disable-vsx-on-ppc64.patch: ensure VSX is disabled until VP9 artifacting can be fixed upstream . [ Jianfeng Liu ] * d/patches: - upstream/0001-Fix-build-for-CPU-yield-on-LoongArch.patch: This is a patch aleady merged to v150 to fix build on loongarch64. - loongarch64/0024-fix-libyuv-lsx.patch: Upstream has bumped the version of libyuv and it has broken build with lsx enabled on loongarch64. Add a patch to fix the build first. chromium (148.0.7778.215-2) unstable; urgency=high . [ Juan Manuel Méndez Rey ] * Team upload. * d/patches/fixes/bytemuck.patch: select bytemuck's core::simd impls by rust version rather than date, fixing FTBFS with rustc 1.95 (which removed core::simd::LaneCount) while still building on rust < 1.95 (trixie/bookworm). Affects the default chromium build too. chromium (148.0.7778.215-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-9872: Out of bounds write in GPU. Reported by cinzinga. - CVE-2026-9873: Use after free in Network. Reported by cinzinga. - CVE-2026-9874: Use after free in Dawn. Reported by Anonymous. - CVE-2026-9875: Out of bounds read in WebGL. Reported by Anonymous. - CVE-2026-9876: Use after free in WebGL. Reported by happy2me. - CVE-2026-9877: Use after free in ANGLE. Reported by Google. - CVE-2026-9878: Use after free in ANGLE. Reported by Google. - CVE-2026-9879: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9880: Insufficient validation of untrusted input in WebGL. Reported by Google. - CVE-2026-9881: Use after free in Bluetooth. Reported by Google. - CVE-2026-9882: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9883: Use after free in Base. Reported by Google. - CVE-2026-9884: Use after free in Browser. Reported by Google. - CVE-2026-9885: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-9886: Use after free in Base. Reported by Google. - CVE-2026-9887: Use after free in Proxy. Reported by Google. - CVE-2026-9888: Use after free in WebView. Reported by Google. - CVE-2026-9889: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-9890: Use after free in XR. Reported by Google. - CVE-2026-9891: Use after free in Extensions. Reported by Google. - CVE-2026-9892: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9893: Use after free in Skia. Reported by Google. - CVE-2026-9894: Use after free in GPU. Reported by tohafrit. - CVE-2026-9895: Out of bounds read in GPU. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-9896: Out of bounds write in V8. Reported by 303f06e3. - CVE-2026-9897: Use after free in DOM. Reported by Google. - CVE-2026-9898: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-9899: Use after free in ANGLE. Reported by Google. - CVE-2026-9900: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9901: Use after free in ANGLE. Reported by Google. - CVE-2026-9902: Use after free in Accessibility. Reported by Google. - CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation. Reported by Google. - CVE-2026-9904: Use after free in ANGLE. Reported by Google. - CVE-2026-9905: Use after free in Accessibility. Reported by Google. - CVE-2026-9906: Out of bounds write in GPU. Reported by Google. - CVE-2026-9907: Out of bounds read in Dawn. Reported by Google. - CVE-2026-9908: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9909: Integer overflow in Skia. Reported by Google. - CVE-2026-9910: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-9911: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9912: Inappropriate implementation in GPU. Reported by Google. - CVE-2026-9913: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-9914: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9915: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9916: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9917: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9918: Inappropriate implementation in Tint. Reported by Google. - CVE-2026-9919: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9920: Uninitialized Use in GPU. Reported by Google. - CVE-2026-9921: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9922: Use after free in GPU. Reported by Google. - CVE-2026-9923: Use after free in Skia. Reported by Google. - CVE-2026-9924: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9925: Use after free in ANGLE. Reported by Google. - CVE-2026-9926: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9927: Use after free in ANGLE. Reported by Google. - CVE-2026-9928: Out of bounds read in ANGLE. Reported by Jeff Muizelaar - Mozilla. - CVE-2026-9929: Inappropriate implementation in WebGL. Reported by Google - CVE-2026-9930: Out of bounds write in Dawn. Reported by Google. - CVE-2026-9931: Use after free in GPU. Reported by Google. - CVE-2026-9932: Use after free in ANGLE. Reported by Google. - CVE-2026-9933: Use after free in Input. Reported by Google. - CVE-2026-9934: Use after free in Aura. Reported by Google. - CVE-2026-9935: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9936: Use after free in GFX. Reported by Google. - CVE-2026-9937: Use after free in UI. Reported by Google. - CVE-2026-9938: Inappropriate implementation in V8. Reported by Google. - CVE-2026-9939: Heap buffer overflow in WebCodecs. Reported by Google. - CVE-2026-9940: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9941: Use after free in ANGLE. Reported by Google. - CVE-2026-9942: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9943: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9944: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9945: Use after free in Media. Reported by Google. - CVE-2026-9946: Use after free in ANGLE. Reported by Google. - CVE-2026-9947: Use after free in XML. Reported by Google. - CVE-2026-9948: Use after free in Views. Reported by Google. - CVE-2026-9949: Use after free in Core. Reported by Google. - CVE-2026-9950: Insufficient validation of untrusted input in iOS. Reported by Google. - CVE-2026-9951: Use after free in UI. Reported by Google. - CVE-2026-9952: Use after free in WebAudio. Reported by Google. - CVE-2026-9953: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9954: Use after free in TabStrip. Reported by yueliu of Microsoft. - CVE-2026-9955: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9956: Use after free in iOS. Reported by Google. - CVE-2026-9957: Use after free in PDF. Reported by Google. - CVE-2026-9958: Use after free in PDFium. Reported by Google. - CVE-2026-9959: Race in WebRTC. Reported by Google. - CVE-2026-9960: Integer overflow in PDFium. Reported by Google. - CVE-2026-9961: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-9962: Use after free in WebRTC. Reported by Google. - CVE-2026-9963: Uninitialized Use in iOS. Reported by Google. - CVE-2026-9964: Use after free in Bluetooth. Reported by Google. - CVE-2026-9965: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9966: Integer overflow in XML. Reported by Google. - CVE-2026-9967: Out of bounds write in GPU. Reported by Google. - CVE-2026-9968: Integer overflow in V8. Reported by Google. - CVE-2026-9969: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9970: Use after free in WebGL. Reported by TFGC. - CVE-2026-9971: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9972: Uninitialized Use in Gamepad. Reported by Google. - CVE-2026-9973: Out of bounds write in V8. Reported by amyb of OpenAI. - CVE-2026-9974: Out of bounds write in GPU. Reported by Google. - CVE-2026-9975: Out of bounds read and write in ANGLE. Reported by Google - CVE-2026-9976: Inappropriate implementation in USB. Reported by Google. - CVE-2026-9977: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-9978: Use after free in Glic. Reported by Google. - CVE-2026-9979: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-9980: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-9981: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9982: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9983: Type Confusion in Skia. Reported by Google. - CVE-2026-9984: Use after free in UI. Reported by Google. - CVE-2026-9985: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide. Reported by Google. - CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-9988: Use after free in WebRTC. Reported by Google. - CVE-2026-9989: Inappropriate implementation in Media. Reported by Google - CVE-2026-9990: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-9991: Inappropriate implementation in Media. Reported by Google - CVE-2026-9992: Use after free in Network. Reported by Google. - CVE-2026-9993: Use after free in Views. Reported by Google. - CVE-2026-9994: Use after free in Core. Reported by Google. - CVE-2026-9995: Use after free in WebXR. Reported by Google. - CVE-2026-9996: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-9997: Use after free in Input. Reported by Google. - CVE-2026-9998: Integer overflow in Skia. Reported by Google. - CVE-2026-9999: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-10000: Use after free in Passwords. Reported by Google. - CVE-2026-10001: Use after free in PerformanceManager. Reported by Google - CVE-2026-10002: Use after free in PDFium. Reported by Google. - CVE-2026-10003: Use after free in Views. Reported by Google. - CVE-2026-10004: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-10005: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10006: Race in WebAudio. Reported by Google. - CVE-2026-10007: Use after free in SVG. Reported by Google. - CVE-2026-10008: Uninitialized Use in GPU. Reported by Google. - CVE-2026-10009: Integer overflow in Skia. Reported by Google. - CVE-2026-10010: Inappropriate implementation in Input. Reported by Google. - CVE-2026-10011: Inappropriate implementation in Skia. Reported by Google - CVE-2026-10012: Use after free in Skia. Reported by Google. - CVE-2026-10013: Use after free in WebCodecs. Reported by Google. - CVE-2026-10014: Use after free in WebMIDI. Reported by Google. - CVE-2026-10015: Integer overflow in WTF. Reported by Google. - CVE-2026-10016: Use after free in DOM. Reported by pwn2addr. - CVE-2026-10017: Out of bounds read in Headless. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10018: Integer overflow in ANGLE. Reported by Rahul Raj. - CVE-2026-10019: Integer overflow in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10020: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-10021: Insufficient validation of untrusted input in USB. Reported by Google. - CVE-2026-10022: Type Confusion in V8. Reported by ggwhyp. chromium (148.0.7778.215-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-9872: Out of bounds write in GPU. Reported by cinzinga. - CVE-2026-9873: Use after free in Network. Reported by cinzinga. - CVE-2026-9874: Use after free in Dawn. Reported by Anonymous. - CVE-2026-9875: Out of bounds read in WebGL. Reported by Anonymous. - CVE-2026-9876: Use after free in WebGL. Reported by happy2me. - CVE-2026-9877: Use after free in ANGLE. Reported by Google. - CVE-2026-9878: Use after free in ANGLE. Reported by Google. - CVE-2026-9879: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9880: Insufficient validation of untrusted input in WebGL. Reported by Google. - CVE-2026-9881: Use after free in Bluetooth. Reported by Google. - CVE-2026-9882: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9883: Use after free in Base. Reported by Google. - CVE-2026-9884: Use after free in Browser. Reported by Google. - CVE-2026-9885: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-9886: Use after free in Base. Reported by Google. - CVE-2026-9887: Use after free in Proxy. Reported by Google. - CVE-2026-9888: Use after free in WebView. Reported by Google. - CVE-2026-9889: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-9890: Use after free in XR. Reported by Google. - CVE-2026-9891: Use after free in Extensions. Reported by Google. - CVE-2026-9892: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9893: Use after free in Skia. Reported by Google. - CVE-2026-9894: Use after free in GPU. Reported by tohafrit. - CVE-2026-9895: Out of bounds read in GPU. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-9896: Out of bounds write in V8. Reported by 303f06e3. - CVE-2026-9897: Use after free in DOM. Reported by Google. - CVE-2026-9898: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-9899: Use after free in ANGLE. Reported by Google. - CVE-2026-9900: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9901: Use after free in ANGLE. Reported by Google. - CVE-2026-9902: Use after free in Accessibility. Reported by Google. - CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation. Reported by Google. - CVE-2026-9904: Use after free in ANGLE. Reported by Google. - CVE-2026-9905: Use after free in Accessibility. Reported by Google. - CVE-2026-9906: Out of bounds write in GPU. Reported by Google. - CVE-2026-9907: Out of bounds read in Dawn. Reported by Google. - CVE-2026-9908: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9909: Integer overflow in Skia. Reported by Google. - CVE-2026-9910: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-9911: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9912: Inappropriate implementation in GPU. Reported by Google. - CVE-2026-9913: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-9914: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9915: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9916: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9917: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9918: Inappropriate implementation in Tint. Reported by Google. - CVE-2026-9919: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9920: Uninitialized Use in GPU. Reported by Google. - CVE-2026-9921: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9922: Use after free in GPU. Reported by Google. - CVE-2026-9923: Use after free in Skia. Reported by Google. - CVE-2026-9924: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9925: Use after free in ANGLE. Reported by Google. - CVE-2026-9926: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9927: Use after free in ANGLE. Reported by Google. - CVE-2026-9928: Out of bounds read in ANGLE. Reported by Jeff Muizelaar - Mozilla. - CVE-2026-9929: Inappropriate implementation in WebGL. Reported by Google - CVE-2026-9930: Out of bounds write in Dawn. Reported by Google. - CVE-2026-9931: Use after free in GPU. Reported by Google. - CVE-2026-9932: Use after free in ANGLE. Reported by Google. - CVE-2026-9933: Use after free in Input. Reported by Google. - CVE-2026-9934: Use after free in Aura. Reported by Google. - CVE-2026-9935: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9936: Use after free in GFX. Reported by Google. - CVE-2026-9937: Use after free in UI. Reported by Google. - CVE-2026-9938: Inappropriate implementation in V8. Reported by Google. - CVE-2026-9939: Heap buffer overflow in WebCodecs. Reported by Google. - CVE-2026-9940: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9941: Use after free in ANGLE. Reported by Google. - CVE-2026-9942: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9943: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9944: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9945: Use after free in Media. Reported by Google. - CVE-2026-9946: Use after free in ANGLE. Reported by Google. - CVE-2026-9947: Use after free in XML. Reported by Google. - CVE-2026-9948: Use after free in Views. Reported by Google. - CVE-2026-9949: Use after free in Core. Reported by Google. - CVE-2026-9950: Insufficient validation of untrusted input in iOS. Reported by Google. - CVE-2026-9951: Use after free in UI. Reported by Google. - CVE-2026-9952: Use after free in WebAudio. Reported by Google. - CVE-2026-9953: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9954: Use after free in TabStrip. Reported by yueliu of Microsoft. - CVE-2026-9955: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9956: Use after free in iOS. Reported by Google. - CVE-2026-9957: Use after free in PDF. Reported by Google. - CVE-2026-9958: Use after free in PDFium. Reported by Google. - CVE-2026-9959: Race in WebRTC. Reported by Google. - CVE-2026-9960: Integer overflow in PDFium. Reported by Google. - CVE-2026-9961: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-9962: Use after free in WebRTC. Reported by Google. - CVE-2026-9963: Uninitialized Use in iOS. Reported by Google. - CVE-2026-9964: Use after free in Bluetooth. Reported by Google. - CVE-2026-9965: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9966: Integer overflow in XML. Reported by Google. - CVE-2026-9967: Out of bounds write in GPU. Reported by Google. - CVE-2026-9968: Integer overflow in V8. Reported by Google. - CVE-2026-9969: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9970: Use after free in WebGL. Reported by TFGC. - CVE-2026-9971: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9972: Uninitialized Use in Gamepad. Reported by Google. - CVE-2026-9973: Out of bounds write in V8. Reported by amyb of OpenAI. - CVE-2026-9974: Out of bounds write in GPU. Reported by Google. - CVE-2026-9975: Out of bounds read and write in ANGLE. Reported by Google - CVE-2026-9976: Inappropriate implementation in USB. Reported by Google. - CVE-2026-9977: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-9978: Use after free in Glic. Reported by Google. - CVE-2026-9979: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-9980: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-9981: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9982: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9983: Type Confusion in Skia. Reported by Google. - CVE-2026-9984: Use after free in UI. Reported by Google. - CVE-2026-9985: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide. Reported by Google. - CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-9988: Use after free in WebRTC. Reported by Google. - CVE-2026-9989: Inappropriate implementation in Media. Reported by Google - CVE-2026-9990: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-9991: Inappropriate implementation in Media. Reported by Google - CVE-2026-9992: Use after free in Network. Reported by Google. - CVE-2026-9993: Use after free in Views. Reported by Google. - CVE-2026-9994: Use after free in Core. Reported by Google. - CVE-2026-9995: Use after free in WebXR. Reported by Google. - CVE-2026-9996: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-9997: Use after free in Input. Reported by Google. - CVE-2026-9998: Integer overflow in Skia. Reported by Google. - CVE-2026-9999: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-10000: Use after free in Passwords. Reported by Google. - CVE-2026-10001: Use after free in PerformanceManager. Reported by Google - CVE-2026-10002: Use after free in PDFium. Reported by Google. - CVE-2026-10003: Use after free in Views. Reported by Google. - CVE-2026-10004: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-10005: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10006: Race in WebAudio. Reported by Google. - CVE-2026-10007: Use after free in SVG. Reported by Google. - CVE-2026-10008: Uninitialized Use in GPU. Reported by Google. - CVE-2026-10009: Integer overflow in Skia. Reported by Google. - CVE-2026-10010: Inappropriate implementation in Input. Reported by Google. - CVE-2026-10011: Inappropriate implementation in Skia. Reported by Google - CVE-2026-10012: Use after free in Skia. Reported by Google. - CVE-2026-10013: Use after free in WebCodecs. Reported by Google. - CVE-2026-10014: Use after free in WebMIDI. Reported by Google. - CVE-2026-10015: Integer overflow in WTF. Reported by Google. - CVE-2026-10016: Use after free in DOM. Reported by pwn2addr. - CVE-2026-10017: Out of bounds read in Headless. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10018: Integer overflow in ANGLE. Reported by Rahul Raj. - CVE-2026-10019: Integer overflow in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10020: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-10021: Insufficient validation of untrusted input in USB. Reported by Google. - CVE-2026-10022: Type Confusion in V8. Reported by ggwhyp. chromium (148.0.7778.215-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-9872: Out of bounds write in GPU. Reported by cinzinga. - CVE-2026-9873: Use after free in Network. Reported by cinzinga. - CVE-2026-9874: Use after free in Dawn. Reported by Anonymous. - CVE-2026-9875: Out of bounds read in WebGL. Reported by Anonymous. - CVE-2026-9876: Use after free in WebGL. Reported by happy2me. - CVE-2026-9877: Use after free in ANGLE. Reported by Google. - CVE-2026-9878: Use after free in ANGLE. Reported by Google. - CVE-2026-9879: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9880: Insufficient validation of untrusted input in WebGL. Reported by Google. - CVE-2026-9881: Use after free in Bluetooth. Reported by Google. - CVE-2026-9882: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9883: Use after free in Base. Reported by Google. - CVE-2026-9884: Use after free in Browser. Reported by Google. - CVE-2026-9885: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-9886: Use after free in Base. Reported by Google. - CVE-2026-9887: Use after free in Proxy. Reported by Google. - CVE-2026-9888: Use after free in WebView. Reported by Google. - CVE-2026-9889: Out of bounds read and write in Dawn. Reported by Google. - CVE-2026-9890: Use after free in XR. Reported by Google. - CVE-2026-9891: Use after free in Extensions. Reported by Google. - CVE-2026-9892: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9893: Use after free in Skia. Reported by Google. - CVE-2026-9894: Use after free in GPU. Reported by tohafrit. - CVE-2026-9895: Out of bounds read in GPU. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-9896: Out of bounds write in V8. Reported by 303f06e3. - CVE-2026-9897: Use after free in DOM. Reported by Google. - CVE-2026-9898: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-9899: Use after free in ANGLE. Reported by Google. - CVE-2026-9900: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9901: Use after free in ANGLE. Reported by Google. - CVE-2026-9902: Use after free in Accessibility. Reported by Google. - CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation. Reported by Google. - CVE-2026-9904: Use after free in ANGLE. Reported by Google. - CVE-2026-9905: Use after free in Accessibility. Reported by Google. - CVE-2026-9906: Out of bounds write in GPU. Reported by Google. - CVE-2026-9907: Out of bounds read in Dawn. Reported by Google. - CVE-2026-9908: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9909: Integer overflow in Skia. Reported by Google. - CVE-2026-9910: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-9911: Integer overflow in ANGLE. Reported by Google. - CVE-2026-9912: Inappropriate implementation in GPU. Reported by Google. - CVE-2026-9913: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-9914: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9915: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9916: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9917: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9918: Inappropriate implementation in Tint. Reported by Google. - CVE-2026-9919: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9920: Uninitialized Use in GPU. Reported by Google. - CVE-2026-9921: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-9922: Use after free in GPU. Reported by Google. - CVE-2026-9923: Use after free in Skia. Reported by Google. - CVE-2026-9924: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9925: Use after free in ANGLE. Reported by Google. - CVE-2026-9926: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9927: Use after free in ANGLE. Reported by Google. - CVE-2026-9928: Out of bounds read in ANGLE. Reported by Jeff Muizelaar - Mozilla. - CVE-2026-9929: Inappropriate implementation in WebGL. Reported by Google - CVE-2026-9930: Out of bounds write in Dawn. Reported by Google. - CVE-2026-9931: Use after free in GPU. Reported by Google. - CVE-2026-9932: Use after free in ANGLE. Reported by Google. - CVE-2026-9933: Use after free in Input. Reported by Google. - CVE-2026-9934: Use after free in Aura. Reported by Google. - CVE-2026-9935: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9936: Use after free in GFX. Reported by Google. - CVE-2026-9937: Use after free in UI. Reported by Google. - CVE-2026-9938: Inappropriate implementation in V8. Reported by Google. - CVE-2026-9939: Heap buffer overflow in WebCodecs. Reported by Google. - CVE-2026-9940: Heap buffer overflow in ANGLE. Reported by Google. - CVE-2026-9941: Use after free in ANGLE. Reported by Google. - CVE-2026-9942: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9943: Out of bounds read in WebGL. Reported by Google. - CVE-2026-9944: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-9945: Use after free in Media. Reported by Google. - CVE-2026-9946: Use after free in ANGLE. Reported by Google. - CVE-2026-9947: Use after free in XML. Reported by Google. - CVE-2026-9948: Use after free in Views. Reported by Google. - CVE-2026-9949: Use after free in Core. Reported by Google. - CVE-2026-9950: Insufficient validation of untrusted input in iOS. Reported by Google. - CVE-2026-9951: Use after free in UI. Reported by Google. - CVE-2026-9952: Use after free in WebAudio. Reported by Google. - CVE-2026-9953: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-9954: Use after free in TabStrip. Reported by yueliu of Microsoft. - CVE-2026-9955: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9956: Use after free in iOS. Reported by Google. - CVE-2026-9957: Use after free in PDF. Reported by Google. - CVE-2026-9958: Use after free in PDFium. Reported by Google. - CVE-2026-9959: Race in WebRTC. Reported by Google. - CVE-2026-9960: Integer overflow in PDFium. Reported by Google. - CVE-2026-9961: Use after free in SurfaceCapture. Reported by Google. - CVE-2026-9962: Use after free in WebRTC. Reported by Google. - CVE-2026-9963: Uninitialized Use in iOS. Reported by Google. - CVE-2026-9964: Use after free in Bluetooth. Reported by Google. - CVE-2026-9965: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-9966: Integer overflow in XML. Reported by Google. - CVE-2026-9967: Out of bounds write in GPU. Reported by Google. - CVE-2026-9968: Integer overflow in V8. Reported by Google. - CVE-2026-9969: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9970: Use after free in WebGL. Reported by TFGC. - CVE-2026-9971: Inappropriate implementation in iOS. Reported by Google. - CVE-2026-9972: Uninitialized Use in Gamepad. Reported by Google. - CVE-2026-9973: Out of bounds write in V8. Reported by amyb of OpenAI. - CVE-2026-9974: Out of bounds write in GPU. Reported by Google. - CVE-2026-9975: Out of bounds read and write in ANGLE. Reported by Google - CVE-2026-9976: Inappropriate implementation in USB. Reported by Google. - CVE-2026-9977: Insufficient validation of untrusted input in WebShare. Reported by Google. - CVE-2026-9978: Use after free in Glic. Reported by Google. - CVE-2026-9979: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-9980: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-9981: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-9982: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-9983: Type Confusion in Skia. Reported by Google. - CVE-2026-9984: Use after free in UI. Reported by Google. - CVE-2026-9985: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide. Reported by Google. - CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google. - CVE-2026-9988: Use after free in WebRTC. Reported by Google. - CVE-2026-9989: Inappropriate implementation in Media. Reported by Google - CVE-2026-9990: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-9991: Inappropriate implementation in Media. Reported by Google - CVE-2026-9992: Use after free in Network. Reported by Google. - CVE-2026-9993: Use after free in Views. Reported by Google. - CVE-2026-9994: Use after free in Core. Reported by Google. - CVE-2026-9995: Use after free in WebXR. Reported by Google. - CVE-2026-9996: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-9997: Use after free in Input. Reported by Google. - CVE-2026-9998: Integer overflow in Skia. Reported by Google. - CVE-2026-9999: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-10000: Use after free in Passwords. Reported by Google. - CVE-2026-10001: Use after free in PerformanceManager. Reported by Google - CVE-2026-10002: Use after free in PDFium. Reported by Google. - CVE-2026-10003: Use after free in Views. Reported by Google. - CVE-2026-10004: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-10005: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-10006: Race in WebAudio. Reported by Google. - CVE-2026-10007: Use after free in SVG. Reported by Google. - CVE-2026-10008: Uninitialized Use in GPU. Reported by Google. - CVE-2026-10009: Integer overflow in Skia. Reported by Google. - CVE-2026-10010: Inappropriate implementation in Input. Reported by Google. - CVE-2026-10011: Inappropriate implementation in Skia. Reported by Google - CVE-2026-10012: Use after free in Skia. Reported by Google. - CVE-2026-10013: Use after free in WebCodecs. Reported by Google. - CVE-2026-10014: Use after free in WebMIDI. Reported by Google. - CVE-2026-10015: Integer overflow in WTF. Reported by Google. - CVE-2026-10016: Use after free in DOM. Reported by pwn2addr. - CVE-2026-10017: Out of bounds read in Headless. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-10018: Integer overflow in ANGLE. Reported by Rahul Raj. - CVE-2026-10019: Integer overflow in ANGLE. Reported by Mufeed VH from Winfunc Research (winfunc.com). - CVE-2026-10020: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-10021: Insufficient validation of untrusted input in USB. Reported by Google. - CVE-2026-10022: Type Confusion in V8. Reported by ggwhyp. chromium (148.0.7778.178-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. chromium (148.0.7778.178-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-9111: Use after free in WebRTC. Reported by Google. - CVE-2026-9110: Inappropriate implementation in UI. Reported by Google. - CVE-2026-9112: Use after free in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9113: Out of bounds read in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9114: Use after free in QUIC. Reported by Google. - CVE-2026-9115: Insufficient policy enforcement in Service Worker. Reported by Google. - CVE-2026-9116: Insufficient policy enforcement in ServiceWorker. Reported by Google. - CVE-2026-9117: Type Confusion in GFX. Reported by Google. - CVE-2026-9118: Use after free in XR. Reported by Google. - CVE-2026-9119: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-9120: Use after free in WebRTC. Reported by Google. - CVE-2026-9126: Use after free in DOM. Reported by Google. - CVE-2026-9121: Out of bounds read in GPU. Reported by David Korczynski (Adalogics) . - CVE-2026-9122: Out of bounds read in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9123: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-9124: Insufficient validation of untrusted input in Input. Reported by Google. chromium (148.0.7778.178-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-9111: Use after free in WebRTC. Reported by Google. - CVE-2026-9110: Inappropriate implementation in UI. Reported by Google. - CVE-2026-9112: Use after free in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9113: Out of bounds read in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9114: Use after free in QUIC. Reported by Google. - CVE-2026-9115: Insufficient policy enforcement in Service Worker. Reported by Google. - CVE-2026-9116: Insufficient policy enforcement in ServiceWorker. Reported by Google. - CVE-2026-9117: Type Confusion in GFX. Reported by Google. - CVE-2026-9118: Use after free in XR. Reported by Google. - CVE-2026-9119: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-9120: Use after free in WebRTC. Reported by Google. - CVE-2026-9126: Use after free in DOM. Reported by Google. - CVE-2026-9121: Out of bounds read in GPU. Reported by David Korczynski (Adalogics) . - CVE-2026-9122: Out of bounds read in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-9123: Heap buffer overflow in Chromecast. Reported by Google. - CVE-2026-9124: Insufficient validation of untrusted input in Input. Reported by Google. chromium (148.0.7778.167-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-8509: Heap buffer overflow in WebML. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8510: Integer overflow in Skia. Reported by q@calif.io. - CVE-2026-8511: Use after free in UI. Reported by Google. - CVE-2026-8512: Use after free in FileSystem. Reported by Google. - CVE-2026-8513: Use after free in Input. Reported by Google. - CVE-2026-8514: Use after free in Aura. Reported by Google. - CVE-2026-8515: Use after free in HID. Reported by Google. - CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google. - CVE-2026-8518: Use after free in Blink. Reported by Google. - CVE-2026-8519: Integer overflow in ANGLE. Reported by Google. - CVE-2026-8520: Race in Payments. Reported by Google. - CVE-2026-8521: Use after free in Tab Groups. Reported by Google. - CVE-2026-8522: Use after free in Downloads. Reported by Google. - CVE-2026-8523: Use after free in Mojo. Reported by Paul Seekamp / nullenc0de. - CVE-2026-8558: Out of bounds write in Fonts. Reported by Matej Smycka. - CVE-2026-8524: Out of bounds write in WebAudio. Reported by Brendan Dolan-Gavitt, XBOW. - CVE-2026-8525: Heap buffer overflow in ANGLE. Reported by Nathaniel Oh (@calysteon). - CVE-2026-8526: Out of bounds write in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8527: Insufficient validation of untrusted input in Downloads. Reported by rachmat.abdul.ro. - CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8529: Heap buffer overflow in Codecs. Reported by Google. - CVE-2026-8530: Use after free in Network. Reported by Google. - CVE-2026-8531: Heap buffer overflow in WebML. Reported by Syn4pse. - CVE-2026-8532: Integer overflow in XML. Reported by Google. - CVE-2026-8533: Use after free in Accessibility. Reported by Google. - CVE-2026-8534: Integer overflow in GPU. Reported by Google. - CVE-2026-8535: Out of bounds read in Media. Reported by Google. - CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode. Reported by Google. - CVE-2026-8537: Insufficient policy enforcement in ViewTransitions. Reported by Google. - CVE-2026-8538: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-8539: Script injection in SanitizerAPI. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-8540: Type Confusion in V8. Reported by Google. - CVE-2026-8541: Out of bounds read in UI. Reported by Google. - CVE-2026-8542: Use after free in Core. Reported by Google. - CVE-2026-8543: Out of bounds read in FileSystem. Reported by Google. - CVE-2026-8544: Use after free in Media. Reported by Google. - CVE-2026-8545: Object corruption in Compositing. Reported by Google. - CVE-2026-8546: Out of bounds read in GPU. Reported by Google. - CVE-2026-8547: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-8548: Out of bounds write in Media. Reported by Google. - CVE-2026-8549: Use after free in Media. Reported by Google. - CVE-2026-8550: Use after free in Google Lens. Reported by Google. - CVE-2026-8551: Use after free in Downloads. Reported by Google. - CVE-2026-8552: Heap buffer overflow in GPU. Reported by Google. - CVE-2026-8553: Use after free in GPU. Reported by Google. - CVE-2026-8554: Type Confusion in ANGLE. Reported by Google. - CVE-2026-8555: Use after free in GTK. Reported by Google. - CVE-2026-8556: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-8557: Use after free in Accessibility. Reported by Google. - CVE-2026-8559: Integer overflow in Internationalization. Reported by Google. - CVE-2026-8560: Heap buffer overflow in SwiftShader. Reported by Cassidy Kim(@cassidy6564). - CVE-2026-8561: Incorrect security UI in Fullscreen. Reported by Wolfgang Ettlinger (aff. Certitude Consulting GmbH) Alexander Hurbean (aff. Certitude Consulting GmbH). - CVE-2026-8562: Side-channel information leakage in Navigation. Reported by Google. - CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox. Reported by Luan Herrera (@lbherrera_). - CVE-2026-8564: Incorrect security UI in Downloads. Reported by Alesandro Ortiz https://AlesandroOrtiz.com. - CVE-2026-8565: Inappropriate implementation in Downloads. Reported by Farras Givari. - CVE-2026-8566: Insufficient policy enforcement in Payments. Reported by Jorian Woltjer. - CVE-2026-8567: Integer overflow in ANGLE. Reported by cinzinga. - CVE-2026-8568: Insufficient policy enforcement in AI. Reported by Tianyi Hu. - CVE-2026-8569: Out of bounds write in Codecs. Reported by Google. - CVE-2026-8570: Type Confusion in V8. Reported by Google. - CVE-2026-8571: Insufficient policy enforcement in GPU. Reported by Mark Blaszczyk. - CVE-2026-8572: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-8573: Integer overflow in Codecs. Reported by Google. - CVE-2026-8574: Use after free in Core. Reported by Google. - CVE-2026-8575: Use after free in UI. Reported by Google. - CVE-2026-8576: Inappropriate implementation in CORS. Reported by Google - CVE-2026-8577: Integer overflow in Fonts. Reported by Google. - CVE-2026-8578: Out of bounds read in GPU. Reported by Google. - CVE-2026-8579: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-8580: Use after free in Mojo. Reported by Google. - CVE-2026-8581: Use after free in GPU. Reported by Google. - CVE-2026-8582: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-8583: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-8584: Inappropriate implementation in Views. Reported by Google - CVE-2026-8585: Inappropriate implementation in Media. Reported by Google - CVE-2026-8586: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-8587: Use after free in Extensions. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. * rust-1.85/file_as_c_str.patch: fix build on non-x86 archs, as char* signed-ness is apparently different there versus arm & ppc64 [trixie, bookworm]. chromium (148.0.7778.167-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-8509: Heap buffer overflow in WebML. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8510: Integer overflow in Skia. Reported by q@calif.io. - CVE-2026-8511: Use after free in UI. Reported by Google. - CVE-2026-8512: Use after free in FileSystem. Reported by Google. - CVE-2026-8513: Use after free in Input. Reported by Google. - CVE-2026-8514: Use after free in Aura. Reported by Google. - CVE-2026-8515: Use after free in HID. Reported by Google. - CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google. - CVE-2026-8518: Use after free in Blink. Reported by Google. - CVE-2026-8519: Integer overflow in ANGLE. Reported by Google. - CVE-2026-8520: Race in Payments. Reported by Google. - CVE-2026-8521: Use after free in Tab Groups. Reported by Google. - CVE-2026-8522: Use after free in Downloads. Reported by Google. - CVE-2026-8523: Use after free in Mojo. Reported by Paul Seekamp / nullenc0de. - CVE-2026-8558: Out of bounds write in Fonts. Reported by Matej Smycka. - CVE-2026-8524: Out of bounds write in WebAudio. Reported by Brendan Dolan-Gavitt, XBOW. - CVE-2026-8525: Heap buffer overflow in ANGLE. Reported by Nathaniel Oh (@calysteon). - CVE-2026-8526: Out of bounds write in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8527: Insufficient validation of untrusted input in Downloads. Reported by rachmat.abdul.ro. - CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8529: Heap buffer overflow in Codecs. Reported by Google. - CVE-2026-8530: Use after free in Network. Reported by Google. - CVE-2026-8531: Heap buffer overflow in WebML. Reported by Syn4pse. - CVE-2026-8532: Integer overflow in XML. Reported by Google. - CVE-2026-8533: Use after free in Accessibility. Reported by Google. - CVE-2026-8534: Integer overflow in GPU. Reported by Google. - CVE-2026-8535: Out of bounds read in Media. Reported by Google. - CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode. Reported by Google. - CVE-2026-8537: Insufficient policy enforcement in ViewTransitions. Reported by Google. - CVE-2026-8538: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-8539: Script injection in SanitizerAPI. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-8540: Type Confusion in V8. Reported by Google. - CVE-2026-8541: Out of bounds read in UI. Reported by Google. - CVE-2026-8542: Use after free in Core. Reported by Google. - CVE-2026-8543: Out of bounds read in FileSystem. Reported by Google. - CVE-2026-8544: Use after free in Media. Reported by Google. - CVE-2026-8545: Object corruption in Compositing. Reported by Google. - CVE-2026-8546: Out of bounds read in GPU. Reported by Google. - CVE-2026-8547: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-8548: Out of bounds write in Media. Reported by Google. - CVE-2026-8549: Use after free in Media. Reported by Google. - CVE-2026-8550: Use after free in Google Lens. Reported by Google. - CVE-2026-8551: Use after free in Downloads. Reported by Google. - CVE-2026-8552: Heap buffer overflow in GPU. Reported by Google. - CVE-2026-8553: Use after free in GPU. Reported by Google. - CVE-2026-8554: Type Confusion in ANGLE. Reported by Google. - CVE-2026-8555: Use after free in GTK. Reported by Google. - CVE-2026-8556: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-8557: Use after free in Accessibility. Reported by Google. - CVE-2026-8559: Integer overflow in Internationalization. Reported by Google. - CVE-2026-8560: Heap buffer overflow in SwiftShader. Reported by Cassidy Kim(@cassidy6564). - CVE-2026-8561: Incorrect security UI in Fullscreen. Reported by Wolfgang Ettlinger (aff. Certitude Consulting GmbH) Alexander Hurbean (aff. Certitude Consulting GmbH). - CVE-2026-8562: Side-channel information leakage in Navigation. Reported by Google. - CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox. Reported by Luan Herrera (@lbherrera_). - CVE-2026-8564: Incorrect security UI in Downloads. Reported by Alesandro Ortiz https://AlesandroOrtiz.com. - CVE-2026-8565: Inappropriate implementation in Downloads. Reported by Farras Givari. - CVE-2026-8566: Insufficient policy enforcement in Payments. Reported by Jorian Woltjer. - CVE-2026-8567: Integer overflow in ANGLE. Reported by cinzinga. - CVE-2026-8568: Insufficient policy enforcement in AI. Reported by Tianyi Hu. - CVE-2026-8569: Out of bounds write in Codecs. Reported by Google. - CVE-2026-8570: Type Confusion in V8. Reported by Google. - CVE-2026-8571: Insufficient policy enforcement in GPU. Reported by Mark Blaszczyk. - CVE-2026-8572: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-8573: Integer overflow in Codecs. Reported by Google. - CVE-2026-8574: Use after free in Core. Reported by Google. - CVE-2026-8575: Use after free in UI. Reported by Google. - CVE-2026-8576: Inappropriate implementation in CORS. Reported by Google - CVE-2026-8577: Integer overflow in Fonts. Reported by Google. - CVE-2026-8578: Out of bounds read in GPU. Reported by Google. - CVE-2026-8579: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-8580: Use after free in Mojo. Reported by Google. - CVE-2026-8581: Use after free in GPU. Reported by Google. - CVE-2026-8582: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-8583: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-8584: Inappropriate implementation in Views. Reported by Google - CVE-2026-8585: Inappropriate implementation in Media. Reported by Google - CVE-2026-8586: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-8587: Use after free in Extensions. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. * rust-1.85/file_as_c_str.patch: fix build on non-x86 archs, as char* signed-ness is apparently different there versus arm & ppc64 [trixie, bookworm]. chromium (148.0.7778.167-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-8509: Heap buffer overflow in WebML. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8510: Integer overflow in Skia. Reported by q@calif.io. - CVE-2026-8511: Use after free in UI. Reported by Google. - CVE-2026-8512: Use after free in FileSystem. Reported by Google. - CVE-2026-8513: Use after free in Input. Reported by Google. - CVE-2026-8514: Use after free in Aura. Reported by Google. - CVE-2026-8515: Use after free in HID. Reported by Google. - CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer. Reported by Google. - CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google. - CVE-2026-8518: Use after free in Blink. Reported by Google. - CVE-2026-8519: Integer overflow in ANGLE. Reported by Google. - CVE-2026-8520: Race in Payments. Reported by Google. - CVE-2026-8521: Use after free in Tab Groups. Reported by Google. - CVE-2026-8522: Use after free in Downloads. Reported by Google. - CVE-2026-8523: Use after free in Mojo. Reported by Paul Seekamp / nullenc0de. - CVE-2026-8558: Out of bounds write in Fonts. Reported by Matej Smycka. - CVE-2026-8524: Out of bounds write in WebAudio. Reported by Brendan Dolan-Gavitt, XBOW. - CVE-2026-8525: Heap buffer overflow in ANGLE. Reported by Nathaniel Oh (@calysteon). - CVE-2026-8526: Out of bounds write in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8527: Insufficient validation of untrusted input in Downloads. Reported by rachmat.abdul.ro. - CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8529: Heap buffer overflow in Codecs. Reported by Google. - CVE-2026-8530: Use after free in Network. Reported by Google. - CVE-2026-8531: Heap buffer overflow in WebML. Reported by Syn4pse. - CVE-2026-8532: Integer overflow in XML. Reported by Google. - CVE-2026-8533: Use after free in Accessibility. Reported by Google. - CVE-2026-8534: Integer overflow in GPU. Reported by Google. - CVE-2026-8535: Out of bounds read in Media. Reported by Google. - CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode. Reported by Google. - CVE-2026-8537: Insufficient policy enforcement in ViewTransitions. Reported by Google. - CVE-2026-8538: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-8539: Script injection in SanitizerAPI. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-8540: Type Confusion in V8. Reported by Google. - CVE-2026-8541: Out of bounds read in UI. Reported by Google. - CVE-2026-8542: Use after free in Core. Reported by Google. - CVE-2026-8543: Out of bounds read in FileSystem. Reported by Google. - CVE-2026-8544: Use after free in Media. Reported by Google. - CVE-2026-8545: Object corruption in Compositing. Reported by Google. - CVE-2026-8546: Out of bounds read in GPU. Reported by Google. - CVE-2026-8547: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-8548: Out of bounds write in Media. Reported by Google. - CVE-2026-8549: Use after free in Media. Reported by Google. - CVE-2026-8550: Use after free in Google Lens. Reported by Google. - CVE-2026-8551: Use after free in Downloads. Reported by Google. - CVE-2026-8552: Heap buffer overflow in GPU. Reported by Google. - CVE-2026-8553: Use after free in GPU. Reported by Google. - CVE-2026-8554: Type Confusion in ANGLE. Reported by Google. - CVE-2026-8555: Use after free in GTK. Reported by Google. - CVE-2026-8556: Inappropriate implementation in ANGLE. Reported by Google - CVE-2026-8557: Use after free in Accessibility. Reported by Google. - CVE-2026-8559: Integer overflow in Internationalization. Reported by Google. - CVE-2026-8560: Heap buffer overflow in SwiftShader. Reported by Cassidy Kim(@cassidy6564). - CVE-2026-8561: Incorrect security UI in Fullscreen. Reported by Wolfgang Ettlinger (aff. Certitude Consulting GmbH) Alexander Hurbean (aff. Certitude Consulting GmbH). - CVE-2026-8562: Side-channel information leakage in Navigation. Reported by Google. - CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox. Reported by Luan Herrera (@lbherrera_). - CVE-2026-8564: Incorrect security UI in Downloads. Reported by Alesandro Ortiz https://AlesandroOrtiz.com. - CVE-2026-8565: Inappropriate implementation in Downloads. Reported by Farras Givari. - CVE-2026-8566: Insufficient policy enforcement in Payments. Reported by Jorian Woltjer. - CVE-2026-8567: Integer overflow in ANGLE. Reported by cinzinga. - CVE-2026-8568: Insufficient policy enforcement in AI. Reported by Tianyi Hu. - CVE-2026-8569: Out of bounds write in Codecs. Reported by Google. - CVE-2026-8570: Type Confusion in V8. Reported by Google. - CVE-2026-8571: Insufficient policy enforcement in GPU. Reported by Mark Blaszczyk. - CVE-2026-8572: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-8573: Integer overflow in Codecs. Reported by Google. - CVE-2026-8574: Use after free in Core. Reported by Google. - CVE-2026-8575: Use after free in UI. Reported by Google. - CVE-2026-8576: Inappropriate implementation in CORS. Reported by Google - CVE-2026-8577: Integer overflow in Fonts. Reported by Google. - CVE-2026-8578: Out of bounds read in GPU. Reported by Google. - CVE-2026-8579: Insufficient validation of untrusted input in Skia. Reported by Google. - CVE-2026-8580: Use after free in Mojo. Reported by Google. - CVE-2026-8581: Use after free in GPU. Reported by Google. - CVE-2026-8582: Object lifecycle issue in Dawn. Reported by Google. - CVE-2026-8583: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-8584: Inappropriate implementation in Views. Reported by Google - CVE-2026-8585: Inappropriate implementation in Media. Reported by Google - CVE-2026-8586: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-8587: Use after free in Extensions. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab. * rust-1.85/file_as_c_str.patch: fix build on non-x86 archs, as char* signed-ness is apparently different there versus arm & ppc64 [trixie, bookworm]. chromium (148.0.7778.96-3) unstable; urgency=high . [ Andres Salomon ] * d/control: switch to hardcoding esbuild-wasm build-dep, since buildds aren't smart enough to handle OR build-deps. chromium (148.0.7778.96-2) unstable; urgency=high . [ Andres Salomon ] * d/rules: update for new script path in debian's esbuild package (maintaining backwards compatibility with older esbuild packages). * d/control: add build-dep on esbuild-wasm for sid but not older distributions. chromium (148.0.7778.96-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-7896: Integer overflow in Blink. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7897: Use after free in Mobile. Reported by Google. - CVE-2026-7898: Use after free in Chromoting. Reported by Google. - CVE-2026-7899: Out of bounds read and write in V8. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-7900: Heap buffer overflow in ANGLE. Reported by Anonymous. - CVE-2026-7901: Use after free in ANGLE. Reported by Syn4pse (@ret2happy) - CVE-2026-7902: Out of bounds memory access in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-7903: Integer overflow in ANGLE. Reported by heesun. - CVE-2026-7904: Out of bounds read in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7905: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-7906: Use after free in SVG. Reported by Google. - CVE-2026-7907: Use after free in DOM. Reported by Google. - CVE-2026-7908: Use after free in Fullscreen. Reported by Google. - CVE-2026-7909: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7910: Use after free in Views. Reported by Google. - CVE-2026-7911: Use after free in Aura. Reported by Google. - CVE-2026-7912: Integer overflow in GPU. Reported by Google. - CVE-2026-7913: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-7914: Type Confusion in Accessibility. Reported by Google. - CVE-2026-7915: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-7916: Insufficient data validation in InterestGroups. Reported by Google. - CVE-2026-7917: Use after free in Fullscreen. Reported by Google. - CVE-2026-7918: Use after free in GPU. Reported by Google. - CVE-2026-7919: Use after free in Aura. Reported by Google. - CVE-2026-7920: Use after free in Skia. Reported by Google. - CVE-2026-7921: Use after free in Passwords. Reported by Google. - CVE-2026-7922: Use after free in ServiceWorker. Reported by Google. - CVE-2026-7923: Out of bounds write in Skia. Reported by Google. - CVE-2026-7924: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-7925: Use after free in Chromoting. Reported by Google. - CVE-2026-7926: Use after free in PresentationAPI. Reported by anonymous - CVE-2026-7927: Type Confusion in Runtime. Reported by Google. - CVE-2026-7928: Use after free in WebRTC. Reported by Google. - CVE-2026-7929: Use after free in MediaRecording. Reported by Google. - CVE-2026-7930: Insufficient validation of untrusted input in Cookies. Reported by Satoki. - CVE-2026-7931: Insufficient validation of untrusted input in iOS. Reported by Qadhafy Muhammad Tera. - CVE-2026-7932: Insufficient policy enforcement in Downloads. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-7933: Out of bounds read in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker. Reported by Google. - CVE-2026-7935: Inappropriate implementation in Speech. Reported by Qadhafy Muhammad Tera. - CVE-2026-7936: Object lifecycle issue in V8. Reported by Christian Holler. - CVE-2026-7937: Insufficient policy enforcement in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-7938: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7939: Inappropriate implementation in SanitizerAPI. Reported by s3zer0. - CVE-2026-7940: Use after free in V8. Reported by sakana. - CVE-2026-7941: Insufficient validation of untrusted input in Mobile. Reported by Adithya Kotian. - CVE-2026-7942: Integer overflow in ANGLE. Reported by Google. - CVE-2026-7943: Insufficient validation of untrusted input in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache. Reported by Google. - CVE-2026-7945: Insufficient validation of untrusted input in COOP. Reported by Google. - CVE-2026-7946: Insufficient policy enforcement in WebUI. Reported by Google. - CVE-2026-7947: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-7948: Race in Chromoting. Reported by Google. - CVE-2026-7949: Out of bounds read in Skia. Reported by Google. - CVE-2026-7950: Out of bounds read and write in GFX. Reported by Google. - CVE-2026-7951: Out of bounds write in WebRTC. Reported by soft.connect.fr. - CVE-2026-7952: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-7953: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-7954: Race in Shared Storage. Reported by Google. - CVE-2026-7955: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7956: Use after free in Navigation. Reported by Google. - CVE-2026-7957: Out of bounds write in Media. Reported by Google. - CVE-2026-7958: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7959: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-7960: Race in Speech. Reported by Google. - CVE-2026-7961: Insufficient validation of untrusted input in Permissions Reported by Google. - CVE-2026-7962: Insufficient policy enforcement in DirectSockets. Reported by Google. - CVE-2026-7963: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7964: Insufficient validation of untrusted input in FileSystem. Reported by Google. - CVE-2026-7965: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-7967: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-7968: Insufficient validation of untrusted input in CORS. Reported by Google. - CVE-2026-7969: Integer overflow in Network. Reported by Google. - CVE-2026-7970: Use after free in TopChrome. Reported by Google. - CVE-2026-7971: Inappropriate implementation in ORB. Reported by Google. - CVE-2026-7972: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7973: Integer overflow in Dawn. Reported by Google. - CVE-2026-7974: Use after free in Blink. Reported by Google. - CVE-2026-7975: Use after free in DevTools. Reported by Google. - CVE-2026-7976: Use after free in Views. Reported by Google. - CVE-2026-7977: Inappropriate implementation in Canvas. Reported by Google. - CVE-2026-7978: Inappropriate implementation in Companion. Reported by Google. - CVE-2026-7979: Inappropriate implementation in Media. Reported by Google - CVE-2026-7980: Use after free in WebAudio. Reported by Google. - CVE-2026-7981: Out of bounds read in Codecs. Reported by Google. - CVE-2026-7982: Uninitialized Use in WebCodecs. Reported by Google. - CVE-2026-7983: Out of bounds read in Dawn. Reported by Google. - CVE-2026-7984: Use after free in ReadingMode. Reported by Google. - CVE-2026-7985: Use after free in GPU. Reported by Google. - CVE-2026-7986: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-7987: Use after free in WebRTC. Reported by Google. - CVE-2026-7988: Type Confusion in WebRTC. Reported by Google. - CVE-2026-7989: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-7990: Insufficient validation of untrusted input in Updater. Reported by Google. - CVE-2026-7991: Use after free in UI. Reported by Google. - CVE-2026-7992: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-7993: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-7994: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-7995: Out of bounds read in AdFilter. Reported by Google. - CVE-2026-7996: Insufficient validation of untrusted input in SSL. Reported by heesun. - CVE-2026-7997: Insufficient validation of untrusted input in Updater. Reported by ochkofficial. - CVE-2026-7998: Insufficient validation of untrusted input in Dialog. Reported by Tianyi Hu. - CVE-2026-7999: Inappropriate implementation in V8. Reported by Taisic Yun (@taisic) of Theori. - CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver. Reported by Ryan Jupp - HAAO. - CVE-2026-8001: Use after free in Printing. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8002: Use after free in Audio. Reported by Google. - CVE-2026-8003: Insufficient validation of untrusted input in TabGroups. Reported by Google. - CVE-2026-8004: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8005: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8006: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8007: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8008: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-8009: Inappropriate implementation in Cast. Reported by Google. - CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8011: Insufficient policy enforcement in Search. Reported by Google. - CVE-2026-8012: Inappropriate implementation in MHTML. Reported by Google - CVE-2026-8013: Insufficient validation of untrusted input in FedCM. Reported by Google. - CVE-2026-8014: Inappropriate implementation in Preload. Reported by Google. - CVE-2026-8015: Inappropriate implementation in Media. Reported by Google - CVE-2026-8016: Use after free in WebRTC. Reported by Google. - CVE-2026-8017: Side-channel information leakage in Media. Reported by Google. - CVE-2026-8018: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8019: Insufficient policy enforcement in WebApp. Reported by Google. - CVE-2026-8020: Uninitialized Use in GPU. Reported by Google. - CVE-2026-8021: Script injection in UI. Reported by Google. - CVE-2026-8022: Inappropriate implementation in MHTML. Reported by Google * d/copyright: - drop gperf binary that upstream now includes. - update for dropping of "khronos" from opengl paths. * d/rules: - copy gperf binary from /usr/bin into build tree. - set webnn_use_litert=false. * d/clean: - update for harfbuzz-ng to harfbuzz rename. * d/patches: - upstream/Fix-GL-native-pixmap-import-support-reset-in-GpuInit.patch: drop, merged upstream. - disable/lint.patch: refresh. - trixie/nodejs-set-intersection.patch: refresh for file rename. - ungoogled/disable-ai.patch: sync from u-c. - trixie/gn-inputs.patch, trixie/gn-inputs2.patch: add patches to revert gn "inputs" usage, which isn't supported by our older generate-ninja package. - llvm-22/ignore-for-ubsan.patch: add another bit to remove the same unsupported compiler flag. - llvm-19/iota.patch: add build fix for missing std::ranges::iota(). - upstream/turboshaft.patch: add build fix pulled from (v8) upstream for value_or() type ambiguity. - trixie/revert-v8-sanitize.patch: add patch to revert v8 gn-related changes that cause the build to fail w/ older gn. - llvm-19/raw-ref-map-find.patch: add patch to work around older clang-19 std::map::find() limitation. - rust-1.85/jxl-features.patch: refresh for new version [trixie, bookworm]. - rust-1.85/jxl-simd-avx512.patch: refresh for new version, and also drop large portions of this patch that add unsafe{} to macro calls (since I already added an unsafe block in the macro definition). And mark more functions as unsafe [trixie, bookworm]. - trixie/adler1.patch: refresh [trixie, bookworm]. - trixie/rust-is-multiple-of.patch: refresh & move to rust-1.85/ directory [trixie, bookworm]. - rust-1.85/file_as_c_str.patch: add patch to work around lack of std::panic::file_as_c_str() [trixie, bookworm]. - rust-1.85/mojo-features.patch: add patch to enable some newer rust features in mojom parser [trixie, bookworm]. - rust-1.85/zip8.patch: add patch to enable some newer rust features in zip [trixie, bookworm]. - bookworm/constexpr.patch: refresh for moved file [bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. - bookworm/eslint.patch: drop, no longer needed [bookworm]. - ungoogled/remove-navigation-source-param.patch: add patch from u-c to drop the "&source=chrome.ob" that shows up when you search for something via omnibox. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch refresh for upstream changes - third_party/skia-vsx-instructions.patch: refresh for upstream changes - fixes/fix-different-data-layouts.patch: refresh for upstream changes . [ Jianfeng Liu ] * d/patches/loongarch64: - 0004-loong64-sandbox-sandbox-linux-Update-syscall-helpers.patch: Refresh for upstream changes - 0024-disable-BROTLI_MODEL-macro-for-some-targets.patch: Drop, merged upstream . [ Daniel Richard G. ] * d/patches/llvm-19/clang19.patch: Also drop -Wlifetime-safety-permissive flag from v8 build, as clang-19 (and 20) doesn't recognize it. chromium (148.0.7778.96-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-7896: Integer overflow in Blink. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7897: Use after free in Mobile. Reported by Google. - CVE-2026-7898: Use after free in Chromoting. Reported by Google. - CVE-2026-7899: Out of bounds read and write in V8. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-7900: Heap buffer overflow in ANGLE. Reported by Anonymous. - CVE-2026-7901: Use after free in ANGLE. Reported by Syn4pse (@ret2happy) - CVE-2026-7902: Out of bounds memory access in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-7903: Integer overflow in ANGLE. Reported by heesun. - CVE-2026-7904: Out of bounds read in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7905: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-7906: Use after free in SVG. Reported by Google. - CVE-2026-7907: Use after free in DOM. Reported by Google. - CVE-2026-7908: Use after free in Fullscreen. Reported by Google. - CVE-2026-7909: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7910: Use after free in Views. Reported by Google. - CVE-2026-7911: Use after free in Aura. Reported by Google. - CVE-2026-7912: Integer overflow in GPU. Reported by Google. - CVE-2026-7913: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-7914: Type Confusion in Accessibility. Reported by Google. - CVE-2026-7915: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-7916: Insufficient data validation in InterestGroups. Reported by Google. - CVE-2026-7917: Use after free in Fullscreen. Reported by Google. - CVE-2026-7918: Use after free in GPU. Reported by Google. - CVE-2026-7919: Use after free in Aura. Reported by Google. - CVE-2026-7920: Use after free in Skia. Reported by Google. - CVE-2026-7921: Use after free in Passwords. Reported by Google. - CVE-2026-7922: Use after free in ServiceWorker. Reported by Google. - CVE-2026-7923: Out of bounds write in Skia. Reported by Google. - CVE-2026-7924: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-7925: Use after free in Chromoting. Reported by Google. - CVE-2026-7926: Use after free in PresentationAPI. Reported by anonymous - CVE-2026-7927: Type Confusion in Runtime. Reported by Google. - CVE-2026-7928: Use after free in WebRTC. Reported by Google. - CVE-2026-7929: Use after free in MediaRecording. Reported by Google. - CVE-2026-7930: Insufficient validation of untrusted input in Cookies. Reported by Satoki. - CVE-2026-7931: Insufficient validation of untrusted input in iOS. Reported by Qadhafy Muhammad Tera. - CVE-2026-7932: Insufficient policy enforcement in Downloads. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-7933: Out of bounds read in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker. Reported by Google. - CVE-2026-7935: Inappropriate implementation in Speech. Reported by Qadhafy Muhammad Tera. - CVE-2026-7936: Object lifecycle issue in V8. Reported by Christian Holler. - CVE-2026-7937: Insufficient policy enforcement in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-7938: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7939: Inappropriate implementation in SanitizerAPI. Reported by s3zer0. - CVE-2026-7940: Use after free in V8. Reported by sakana. - CVE-2026-7941: Insufficient validation of untrusted input in Mobile. Reported by Adithya Kotian. - CVE-2026-7942: Integer overflow in ANGLE. Reported by Google. - CVE-2026-7943: Insufficient validation of untrusted input in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache. Reported by Google. - CVE-2026-7945: Insufficient validation of untrusted input in COOP. Reported by Google. - CVE-2026-7946: Insufficient policy enforcement in WebUI. Reported by Google. - CVE-2026-7947: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-7948: Race in Chromoting. Reported by Google. - CVE-2026-7949: Out of bounds read in Skia. Reported by Google. - CVE-2026-7950: Out of bounds read and write in GFX. Reported by Google. - CVE-2026-7951: Out of bounds write in WebRTC. Reported by soft.connect.fr. - CVE-2026-7952: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-7953: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-7954: Race in Shared Storage. Reported by Google. - CVE-2026-7955: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7956: Use after free in Navigation. Reported by Google. - CVE-2026-7957: Out of bounds write in Media. Reported by Google. - CVE-2026-7958: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7959: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-7960: Race in Speech. Reported by Google. - CVE-2026-7961: Insufficient validation of untrusted input in Permissions Reported by Google. - CVE-2026-7962: Insufficient policy enforcement in DirectSockets. Reported by Google. - CVE-2026-7963: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7964: Insufficient validation of untrusted input in FileSystem. Reported by Google. - CVE-2026-7965: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-7967: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-7968: Insufficient validation of untrusted input in CORS. Reported by Google. - CVE-2026-7969: Integer overflow in Network. Reported by Google. - CVE-2026-7970: Use after free in TopChrome. Reported by Google. - CVE-2026-7971: Inappropriate implementation in ORB. Reported by Google. - CVE-2026-7972: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7973: Integer overflow in Dawn. Reported by Google. - CVE-2026-7974: Use after free in Blink. Reported by Google. - CVE-2026-7975: Use after free in DevTools. Reported by Google. - CVE-2026-7976: Use after free in Views. Reported by Google. - CVE-2026-7977: Inappropriate implementation in Canvas. Reported by Google. - CVE-2026-7978: Inappropriate implementation in Companion. Reported by Google. - CVE-2026-7979: Inappropriate implementation in Media. Reported by Google - CVE-2026-7980: Use after free in WebAudio. Reported by Google. - CVE-2026-7981: Out of bounds read in Codecs. Reported by Google. - CVE-2026-7982: Uninitialized Use in WebCodecs. Reported by Google. - CVE-2026-7983: Out of bounds read in Dawn. Reported by Google. - CVE-2026-7984: Use after free in ReadingMode. Reported by Google. - CVE-2026-7985: Use after free in GPU. Reported by Google. - CVE-2026-7986: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-7987: Use after free in WebRTC. Reported by Google. - CVE-2026-7988: Type Confusion in WebRTC. Reported by Google. - CVE-2026-7989: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-7990: Insufficient validation of untrusted input in Updater. Reported by Google. - CVE-2026-7991: Use after free in UI. Reported by Google. - CVE-2026-7992: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-7993: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-7994: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-7995: Out of bounds read in AdFilter. Reported by Google. - CVE-2026-7996: Insufficient validation of untrusted input in SSL. Reported by heesun. - CVE-2026-7997: Insufficient validation of untrusted input in Updater. Reported by ochkofficial. - CVE-2026-7998: Insufficient validation of untrusted input in Dialog. Reported by Tianyi Hu. - CVE-2026-7999: Inappropriate implementation in V8. Reported by Taisic Yun (@taisic) of Theori. - CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver. Reported by Ryan Jupp - HAAO. - CVE-2026-8001: Use after free in Printing. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8002: Use after free in Audio. Reported by Google. - CVE-2026-8003: Insufficient validation of untrusted input in TabGroups. Reported by Google. - CVE-2026-8004: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8005: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8006: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8007: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8008: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-8009: Inappropriate implementation in Cast. Reported by Google. - CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8011: Insufficient policy enforcement in Search. Reported by Google. - CVE-2026-8012: Inappropriate implementation in MHTML. Reported by Google - CVE-2026-8013: Insufficient validation of untrusted input in FedCM. Reported by Google. - CVE-2026-8014: Inappropriate implementation in Preload. Reported by Google. - CVE-2026-8015: Inappropriate implementation in Media. Reported by Google - CVE-2026-8016: Use after free in WebRTC. Reported by Google. - CVE-2026-8017: Side-channel information leakage in Media. Reported by Google. - CVE-2026-8018: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8019: Insufficient policy enforcement in WebApp. Reported by Google. - CVE-2026-8020: Uninitialized Use in GPU. Reported by Google. - CVE-2026-8021: Script injection in UI. Reported by Google. - CVE-2026-8022: Inappropriate implementation in MHTML. Reported by Google * d/copyright: - drop gperf binary that upstream now includes. - update for dropping of "khronos" from opengl paths. * d/rules: - copy gperf binary from /usr/bin into build tree. - set webnn_use_litert=false. * d/clean: - update for harfbuzz-ng to harfbuzz rename. * d/patches: - upstream/Fix-GL-native-pixmap-import-support-reset-in-GpuInit.patch: drop, merged upstream. - disable/lint.patch: refresh. - trixie/nodejs-set-intersection.patch: refresh for file rename. - ungoogled/disable-ai.patch: sync from u-c. - trixie/gn-inputs.patch, trixie/gn-inputs2.patch: add patches to revert gn "inputs" usage, which isn't supported by our older generate-ninja package. - llvm-22/ignore-for-ubsan.patch: add another bit to remove the same unsupported compiler flag. - llvm-19/iota.patch: add build fix for missing std::ranges::iota(). - upstream/turboshaft.patch: add build fix pulled from (v8) upstream for value_or() type ambiguity. - trixie/revert-v8-sanitize.patch: add patch to revert v8 gn-related changes that cause the build to fail w/ older gn. - llvm-19/raw-ref-map-find.patch: add patch to work around older clang-19 std::map::find() limitation. - rust-1.85/jxl-features.patch: refresh for new version [trixie, bookworm]. - rust-1.85/jxl-simd-avx512.patch: refresh for new version, and also drop large portions of this patch that add unsafe{} to macro calls (since I already added an unsafe block in the macro definition). And mark more functions as unsafe [trixie, bookworm]. - trixie/adler1.patch: refresh [trixie, bookworm]. - trixie/rust-is-multiple-of.patch: refresh & move to rust-1.85/ directory [trixie, bookworm]. - rust-1.85/file_as_c_str.patch: add patch to work around lack of std::panic::file_as_c_str() [trixie, bookworm]. - rust-1.85/mojo-features.patch: add patch to enable some newer rust features in mojom parser [trixie, bookworm]. - rust-1.85/zip8.patch: add patch to enable some newer rust features in zip [trixie, bookworm]. - bookworm/constexpr.patch: refresh for moved file [bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. - bookworm/eslint.patch: drop, no longer needed [bookworm]. - ungoogled/remove-navigation-source-param.patch: add patch from u-c to drop the "&source=chrome.ob" that shows up when you search for something via omnibox. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch refresh for upstream changes - third_party/skia-vsx-instructions.patch: refresh for upstream changes - fixes/fix-different-data-layouts.patch: refresh for upstream changes . [ Jianfeng Liu ] * d/patches/loongarch64: - 0004-loong64-sandbox-sandbox-linux-Update-syscall-helpers.patch: Refresh for upstream changes - 0024-disable-BROTLI_MODEL-macro-for-some-targets.patch: Drop, merged upstream . [ Daniel Richard G. ] * d/patches/llvm-19/clang19.patch: Also drop -Wlifetime-safety-permissive flag from v8 build, as clang-19 (and 20) doesn't recognize it. chromium (148.0.7778.96-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-7896: Integer overflow in Blink. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7897: Use after free in Mobile. Reported by Google. - CVE-2026-7898: Use after free in Chromoting. Reported by Google. - CVE-2026-7899: Out of bounds read and write in V8. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-7900: Heap buffer overflow in ANGLE. Reported by Anonymous. - CVE-2026-7901: Use after free in ANGLE. Reported by Syn4pse (@ret2happy) - CVE-2026-7902: Out of bounds memory access in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-7903: Integer overflow in ANGLE. Reported by heesun. - CVE-2026-7904: Out of bounds read in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7905: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-7906: Use after free in SVG. Reported by Google. - CVE-2026-7907: Use after free in DOM. Reported by Google. - CVE-2026-7908: Use after free in Fullscreen. Reported by Google. - CVE-2026-7909: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7910: Use after free in Views. Reported by Google. - CVE-2026-7911: Use after free in Aura. Reported by Google. - CVE-2026-7912: Integer overflow in GPU. Reported by Google. - CVE-2026-7913: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-7914: Type Confusion in Accessibility. Reported by Google. - CVE-2026-7915: Insufficient data validation in DevTools. Reported by Google. - CVE-2026-7916: Insufficient data validation in InterestGroups. Reported by Google. - CVE-2026-7917: Use after free in Fullscreen. Reported by Google. - CVE-2026-7918: Use after free in GPU. Reported by Google. - CVE-2026-7919: Use after free in Aura. Reported by Google. - CVE-2026-7920: Use after free in Skia. Reported by Google. - CVE-2026-7921: Use after free in Passwords. Reported by Google. - CVE-2026-7922: Use after free in ServiceWorker. Reported by Google. - CVE-2026-7923: Out of bounds write in Skia. Reported by Google. - CVE-2026-7924: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-7925: Use after free in Chromoting. Reported by Google. - CVE-2026-7926: Use after free in PresentationAPI. Reported by anonymous - CVE-2026-7927: Type Confusion in Runtime. Reported by Google. - CVE-2026-7928: Use after free in WebRTC. Reported by Google. - CVE-2026-7929: Use after free in MediaRecording. Reported by Google. - CVE-2026-7930: Insufficient validation of untrusted input in Cookies. Reported by Satoki. - CVE-2026-7931: Insufficient validation of untrusted input in iOS. Reported by Qadhafy Muhammad Tera. - CVE-2026-7932: Insufficient policy enforcement in Downloads. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-7933: Out of bounds read in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker. Reported by Google. - CVE-2026-7935: Inappropriate implementation in Speech. Reported by Qadhafy Muhammad Tera. - CVE-2026-7936: Object lifecycle issue in V8. Reported by Christian Holler. - CVE-2026-7937: Insufficient policy enforcement in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-7938: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7939: Inappropriate implementation in SanitizerAPI. Reported by s3zer0. - CVE-2026-7940: Use after free in V8. Reported by sakana. - CVE-2026-7941: Insufficient validation of untrusted input in Mobile. Reported by Adithya Kotian. - CVE-2026-7942: Integer overflow in ANGLE. Reported by Google. - CVE-2026-7943: Insufficient validation of untrusted input in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache. Reported by Google. - CVE-2026-7945: Insufficient validation of untrusted input in COOP. Reported by Google. - CVE-2026-7946: Insufficient policy enforcement in WebUI. Reported by Google. - CVE-2026-7947: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-7948: Race in Chromoting. Reported by Google. - CVE-2026-7949: Out of bounds read in Skia. Reported by Google. - CVE-2026-7950: Out of bounds read and write in GFX. Reported by Google. - CVE-2026-7951: Out of bounds write in WebRTC. Reported by soft.connect.fr. - CVE-2026-7952: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-7953: Insufficient validation of untrusted input in Omnibox. Reported by Google. - CVE-2026-7954: Race in Shared Storage. Reported by Google. - CVE-2026-7955: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7956: Use after free in Navigation. Reported by Google. - CVE-2026-7957: Out of bounds write in Media. Reported by Google. - CVE-2026-7958: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7959: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-7960: Race in Speech. Reported by Google. - CVE-2026-7961: Insufficient validation of untrusted input in Permissions Reported by Google. - CVE-2026-7962: Insufficient policy enforcement in DirectSockets. Reported by Google. - CVE-2026-7963: Inappropriate implementation in ServiceWorker. Reported by Google. - CVE-2026-7964: Insufficient validation of untrusted input in FileSystem. Reported by Google. - CVE-2026-7965: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-7967: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-7968: Insufficient validation of untrusted input in CORS. Reported by Google. - CVE-2026-7969: Integer overflow in Network. Reported by Google. - CVE-2026-7970: Use after free in TopChrome. Reported by Google. - CVE-2026-7971: Inappropriate implementation in ORB. Reported by Google. - CVE-2026-7972: Uninitialized Use in GPU. Reported by Google. - CVE-2026-7973: Integer overflow in Dawn. Reported by Google. - CVE-2026-7974: Use after free in Blink. Reported by Google. - CVE-2026-7975: Use after free in DevTools. Reported by Google. - CVE-2026-7976: Use after free in Views. Reported by Google. - CVE-2026-7977: Inappropriate implementation in Canvas. Reported by Google. - CVE-2026-7978: Inappropriate implementation in Companion. Reported by Google. - CVE-2026-7979: Inappropriate implementation in Media. Reported by Google - CVE-2026-7980: Use after free in WebAudio. Reported by Google. - CVE-2026-7981: Out of bounds read in Codecs. Reported by Google. - CVE-2026-7982: Uninitialized Use in WebCodecs. Reported by Google. - CVE-2026-7983: Out of bounds read in Dawn. Reported by Google. - CVE-2026-7984: Use after free in ReadingMode. Reported by Google. - CVE-2026-7985: Use after free in GPU. Reported by Google. - CVE-2026-7986: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-7987: Use after free in WebRTC. Reported by Google. - CVE-2026-7988: Type Confusion in WebRTC. Reported by Google. - CVE-2026-7989: Insufficient data validation in DataTransfer. Reported by Google. - CVE-2026-7990: Insufficient validation of untrusted input in Updater. Reported by Google. - CVE-2026-7991: Use after free in UI. Reported by Google. - CVE-2026-7992: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-7993: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-7994: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-7995: Out of bounds read in AdFilter. Reported by Google. - CVE-2026-7996: Insufficient validation of untrusted input in SSL. Reported by heesun. - CVE-2026-7997: Insufficient validation of untrusted input in Updater. Reported by ochkofficial. - CVE-2026-7998: Insufficient validation of untrusted input in Dialog. Reported by Tianyi Hu. - CVE-2026-7999: Inappropriate implementation in V8. Reported by Taisic Yun (@taisic) of Theori. - CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver. Reported by Ryan Jupp - HAAO. - CVE-2026-8001: Use after free in Printing. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-8002: Use after free in Audio. Reported by Google. - CVE-2026-8003: Insufficient validation of untrusted input in TabGroups. Reported by Google. - CVE-2026-8004: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8005: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8006: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8007: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-8008: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-8009: Inappropriate implementation in Cast. Reported by Google. - CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation. Reported by Google. - CVE-2026-8011: Insufficient policy enforcement in Search. Reported by Google. - CVE-2026-8012: Inappropriate implementation in MHTML. Reported by Google - CVE-2026-8013: Insufficient validation of untrusted input in FedCM. Reported by Google. - CVE-2026-8014: Inappropriate implementation in Preload. Reported by Google. - CVE-2026-8015: Inappropriate implementation in Media. Reported by Google - CVE-2026-8016: Use after free in WebRTC. Reported by Google. - CVE-2026-8017: Side-channel information leakage in Media. Reported by Google. - CVE-2026-8018: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-8019: Insufficient policy enforcement in WebApp. Reported by Google. - CVE-2026-8020: Uninitialized Use in GPU. Reported by Google. - CVE-2026-8021: Script injection in UI. Reported by Google. - CVE-2026-8022: Inappropriate implementation in MHTML. Reported by Google * d/copyright: - drop gperf binary that upstream now includes. - update for dropping of "khronos" from opengl paths. * d/rules: - copy gperf binary from /usr/bin into build tree. - set webnn_use_litert=false. * d/clean: - update for harfbuzz-ng to harfbuzz rename. * d/patches: - upstream/Fix-GL-native-pixmap-import-support-reset-in-GpuInit.patch: drop, merged upstream. - disable/lint.patch: refresh. - trixie/nodejs-set-intersection.patch: refresh for file rename. - ungoogled/disable-ai.patch: sync from u-c. - trixie/gn-inputs.patch, trixie/gn-inputs2.patch: add patches to revert gn "inputs" usage, which isn't supported by our older generate-ninja package. - llvm-22/ignore-for-ubsan.patch: add another bit to remove the same unsupported compiler flag. - llvm-19/iota.patch: add build fix for missing std::ranges::iota(). - upstream/turboshaft.patch: add build fix pulled from (v8) upstream for value_or() type ambiguity. - trixie/revert-v8-sanitize.patch: add patch to revert v8 gn-related changes that cause the build to fail w/ older gn. - llvm-19/raw-ref-map-find.patch: add patch to work around older clang-19 std::map::find() limitation. - rust-1.85/jxl-features.patch: refresh for new version [trixie, bookworm]. - rust-1.85/jxl-simd-avx512.patch: refresh for new version, and also drop large portions of this patch that add unsafe{} to macro calls (since I already added an unsafe block in the macro definition). And mark more functions as unsafe [trixie, bookworm]. - trixie/adler1.patch: refresh [trixie, bookworm]. - trixie/rust-is-multiple-of.patch: refresh & move to rust-1.85/ directory [trixie, bookworm]. - rust-1.85/file_as_c_str.patch: add patch to work around lack of std::panic::file_as_c_str() [trixie, bookworm]. - rust-1.85/mojo-features.patch: add patch to enable some newer rust features in mojom parser [trixie, bookworm]. - rust-1.85/zip8.patch: add patch to enable some newer rust features in zip [trixie, bookworm]. - bookworm/constexpr.patch: refresh for moved file [bookworm]. - bookworm/dav1d-drop-hdr.patch: refresh [bookworm]. - bookworm/eslint.patch: drop, no longer needed [bookworm]. - ungoogled/remove-navigation-source-param.patch: add patch from u-c to drop the "&source=chrome.ob" that shows up when you search for something via omnibox. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch refresh for upstream changes - third_party/skia-vsx-instructions.patch: refresh for upstream changes - fixes/fix-different-data-layouts.patch: refresh for upstream changes . [ Jianfeng Liu ] * d/patches/loongarch64: - 0004-loong64-sandbox-sandbox-linux-Update-syscall-helpers.patch: Refresh for upstream changes - 0024-disable-BROTLI_MODEL-macro-for-some-targets.patch: Drop, merged upstream . [ Daniel Richard G. ] * d/patches/llvm-19/clang19.patch: Also drop -Wlifetime-safety-permissive flag from v8 build, as clang-19 (and 20) doesn't recognize it. chromium (147.0.7727.137-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-7363: Use after free in Canvas. Reported by heapracer. - CVE-2026-7361: Use after free in iOS. Reported by Google. - CVE-2026-7344: Use after free in Accessibility. Reported by Google. - CVE-2026-7343: Use after free in Views. Reported by Google. - CVE-2026-7333: Use after free in GPU. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7360: Insufficient validation of untrusted input in Compositing. Reported by Google. - CVE-2026-7359: Use after free in ANGLE. Reported by Google. - CVE-2026-7358: Use after free in Animation. Reported by Google. - CVE-2026-7334: Use after free in Views. Reported by Batuhan Eşref KOÇ. - CVE-2026-7357: Use after free in GPU. Reported by Google. - CVE-2026-7356: Use after free in Navigation. Reported by Google. - CVE-2026-7354: Out of bounds read and write in Angle. Reported by Google. - CVE-2026-7353: Heap buffer overflow in Skia. Reported by Google. - CVE-2026-7352: Use after free in Media. Reported by Google. - CVE-2026-7351: Race in MHTML. Reported by Google. - CVE-2026-7350: Use after free in WebMIDI. Reported by Google. - CVE-2026-7349: Use after free in Cast. Reported by Google. - CVE-2026-7348: Use after free in Codecs. Reported by Google. - CVE-2026-7335: Use after free in media. Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po). - CVE-2026-7336: Use after free in WebRTC. Reported by Mozilla. - CVE-2026-7337: Type Confusion in V8. Reported by q@calif.io. - CVE-2026-7347: Use after free in Chromoting. Reported by Google. - CVE-2026-7346: Inappropriate implementation in Tint. Reported by Google. - CVE-2026-7345: Insufficient validation of untrusted input in Feedback. Reported by Google. - CVE-2026-7338: Use after free in Cast. Reported by Krace. - CVE-2026-7342: Use after free in WebView. Reported by Google. - CVE-2026-7341: Use after free in WebRTC. Reported by Google. - CVE-2026-7339: Heap buffer overflow in WebRTC. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-7340: Integer overflow in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-7355: Use after free in Media. Reported by Google. . [ Jianfeng Liu ] * d/patches: - upstream/Fix-GL-native-pixmap-import-support-reset-in-GpuInit.patch: Fixes upstream issue https://crbug.com/501115509. This issue is introduced in v147, and unfortunately the fix won't get into v147. This issue affects both vaapi and v4l2 decoding under ozone wayland. - fixes/enable-widevine-on-arm64-linux-platform.patch: Enable widevine support on arm64. There is no official support for widevine on arm64 linux while there are libwidevine binaries extracted from chromeos, which can work on linux (closes: #1052440). chrony (4.6.1-3+deb13u2) trixie; urgency=medium . * debian/chrony.if-{post-down,up}: - Adjust the if-up and if-down hook scripts so that they always exit successfully. (Closes: #1011533) ckermit (416~beta12-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. . [ John Goerzen ] * CVE-2025-68920: Block remote control of the local kermit by default. Closes: #1123025 * Permanently disable OpenSSL version check. Closes: #1118629. composer (2.8.8-1+deb13u3) trixie; urgency=medium . * Fix regexp to support new GitHub installation tokens format (GHSA-f9f8-rm49-7jv2) [CVE-2026-45793] courier (1.4.1-3+deb13u2) trixie; urgency=medium . * Add debian/patches/adjust-webadmin-scripts.patch, thanks Jean Louis (closes: #1132026). curl (8.14.1-2+deb13u4) trixie; urgency=medium . * Import upstream patches for 13 CVE fixes: - CVE-2025-14524 - CVE-2025-14819 - CVE-2026-1965 - CVE-2026-3783 - CVE-2026-3784 - CVE-2026-3805 - CVE-2026-4873 - CVE-2026-5545 - CVE-2026-5773 - CVE-2026-6253 - CVE-2026-6276 - CVE-2026-6429 - CVE-2026-7168 * d/p/CVE-2025-10148.patch: drop format-patch artefacts * d/p/CVE-2025-13034.patch: refresh after gbp pq round-trip * d/p: refresh patch series after gbp pq round-trip cyborg (14.0.0-3+deb13u1) trixie-security; urgency=medium . * CVE-2026-40213: Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC. CVE-2026-40214: The Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service. Applied upstream patches: - Use_common_checks.check_policy_json_from_oslo.upgradecheck.patch - Fix_cyborg-status_upgrade_check_tests.patch - Fix_rule-allow_policy_bypass_on_device_deployable_attribute_APIs.patch - Set_project_id_on_ARQ_creation_and_binding.patch - Refactor_session_handling_and_align_test_contexts.patch - Add_project_id_backfill_for_existing_ARQs.patch - Enforce_project-scoped_access_for_ARQs.patch - Require_service_token_for_bound_ARQ_operations.patch (Closes: #1136006). dcmtk (3.6.9-5+deb13u2) trixie; urgency=medium . * Team upload. * CVE-2026-12805.patch: new: fix CVE-2026-12805. This patch fixes a risk of buffer overflow by ensuring negative error codes in XMLNode::parseFile are properly handled, as well a NULL values. (Closes: #1140562) . dcmtk (3.6.9-5+deb13u1) trixie; urgency=medium . * Team upload * d/patches/*-CVE-2025-9732.patch: new. These changes pulled from dcmtk upstream address CVE-2025-9732. (Closes: #1113993) * 0015-CVE-2025-14607.patch: new: fix CVE-2025-14607. (Closes: #1122926) * 0016-CVE-2026-5663.patch: new: fix CVE-2026-5663. (Closes: #1133001) * 0017-CVE-2025-14841.patch: new: fix CVE-2025-14841. (Closes: #1123584) * 0018-CVE-2026-10194.patch: new: fix CVE-2026-10194. (Closes: #1139181) dcmtk (3.6.9-5+deb13u1) trixie; urgency=medium . * Team upload * d/patches/*-CVE-2025-9732.patch: new. These changes pulled from dcmtk upstream address CVE-2025-9732. (Closes: #1113993) * 0015-CVE-2025-14607.patch: new: fix CVE-2025-14607. (Closes: #1122926) * 0016-CVE-2026-5663.patch: new: fix CVE-2026-5663. (Closes: #1133001) * 0017-CVE-2025-14841.patch: new: fix CVE-2025-14841. (Closes: #1123584) * 0018-CVE-2026-10194.patch: new: fix CVE-2026-10194. (Closes: #1139181) debian-installer (20250803+deb13u6) trixie; urgency=medium . * Bump Linux kernel ABI to 6.12.94+deb13. * Adjust linux-image build-deps accordingly. debian-installer-netboot-images (20250803+deb13u6) trixie; urgency=medium . * Update to 20250803+deb13u6, from trixie-proposed-updates. debusine (0.11.3+deb13u1) trixie; urgency=medium . * Security update for stable: - Enforce permissions on the file body upload endpoint. - CVE-2026-11852: Restrict artifact relation creation and deletion. - Sbuild task: harden against shell injection. - CVE-2026-11853: Reject .dsc/.changes checksum filenames with multiple path components. deepdiff (8.1.1-4+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-58367: Class Pollution in Delta class * CVE-2026-33155: Memory Exhaustion DoS through SAFE_TO_IMPORT (Closes: #1131472) dhcpcd (1:10.1.0-11+deb13u3) trixie; urgency=medium . * [patches] (Closes: #1140767) + Cherry-pick upstream fix for CVE-2025-70102 (commit 117742d). + Cherry-pick upstream fix for CVE-2026-56113 (commit 5733d3c). + Cherry-pick upstream fix for CVE-2026-56114 (commit 2f00c7b). + Cherry-pick upstream fix for CVE-2026-56116 (commit 708b4a5). + Cherry-pick upstream fix for CVE-2026-56117 (commit 78ea09e). dnsdist (1.9.15-0+deb13u1) trixie-security; urgency=medium . * New upstream version 1.9.15, fixing security issues CVE-2026-40011, CVE-2026-42004, CVE-2026-42005, CVE-2026-40208, CVE-2026-40209, CVE-2026-40210, CVE-2026-40211 dolphin (4:25.04.3-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-41525: Sandbox escape dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium . * Security update (Closes: #1136444) * [76ceed4] CVE-2026-27851: lib-var-expand: Reset safe state when transfer is unset * [4af6fb3] CVE-2026-40016: lib-sieve: Enforce CPU time limit within :contains and :matches matcher loops * [366ef61] CVE-2026-33603: login-common: Only accept base64 in sasl * [26bd41e] CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * [b6f5bac] CVE-2026-42006: imap-login: Excessive memory usage DoS errands (46.2.8-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-71063: TLS certificates for CalDAV servers were not verified (Closes: #1123738) evince (48.1-3+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * shell: quote strings in arguments used when calling ev_spawn (CVE-2026-46529) execnet (2.1.1-1+deb13u1) trixie; urgency=medium . * Team upload. * Mark several tests as flaky. Closes: #854494. exim4 (4.98.2-1+deb13u3) trixie-security; urgency=high . * Cherry-pick fix for EXIM-Security-2026-05-19.1 from 4.99.4. Security: PROXYv2 parser: reject PROXY frames whose declared payload length is too short for the claimed address family (12 bytes for TCPv4/0x11, 36 bytes for TCPv6/0x21). Previously a frame with family=0x21 and len=0 caused 16 bytes of uninitialized stack to be formatted as the sender's IPv6 address and disclosed in the SMTP greeting banner. Affects configurations with SUPPORT_PROXY and `hosts_proxy` set. Reported by Warisjeet Singh (sin99xx). fastnetmon (1.2.9-0+deb13u1) trixie-security; urgency=high . * New upstream release. - This release fixes various security issues: CVE-2026-48689, CVE-2026-48688, CVE-2026-48696, CVE-2026-48695, CVE-2026-48694, CVE-2026-48691, CVE-2026-48690, CVE-2026-48687, CVE-2026-48686, CVE-2026-48685, CVE-2026-48684 and CVE-2026-48683. Closes: #1138646 * Revert for trixie: Remove dh_movetousr sequence and manually set the systemd servicedir. fastnetmon (1.2.8+git20250911-2) unstable; urgency=medium . * Bump Standards-Version to 4.7.3 (Remove priority field). * Remove dh_movetousr sequence and manually set the systemd servicedir. Closes: #1122752 * Update years in debian/copyright. * Remove Rules-Requires-Root control field. * Update debian/watch to version 5. * Remove libboost-system-dev Build-Depends. Closes: #1127190 fastnetmon (1.2.8+git20250911-1) unstable; urgency=medium . * New upstream git snapshot. - Fixes build with mongo-c-driver 2.0. Closes: #1111777, #1110574, #1112881 - Remove merged patch 01-spelling-error. * Bump Standards-Version to 4.7.2. * Merge 1.2.4-2+deb12u1 changelog. * Fix old-fsf-address-in-copyright-file. ffmpeg (7:7.1.5-0+deb13u1) trixie-security; urgency=high . * New upstream version 7.1.5 - Fixes CVE-2026-8461 ffmpeg (7:7.1.4-0+deb13u1) trixie-security; urgency=medium . * New upstream version 7.1.4 * debian/libavfilter10.symbols.in: Add new symbol ffmpeg (7:7.1.3-1) unstable; urgency=medium . * New upstream version 7.1.3 * debian/patches: Unbreak build with glslang 16 (Closes: #1120579) firefox-esr (140.12.0esr-1~deb13u1) trixie-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-58, also known as: CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12292, CVE-2026-12294, CVE-2026-12295, CVE-2026-12298, CVE-2026-12296, CVE-2026-12297, CVE-2026-12299, CVE-2026-12329, CVE-2026-12302, CVE-2026-12304, CVE-2026-12305, CVE-2026-12306, CVE-2026-12307, CVE-2026-12308, CVE-2026-12309, CVE-2026-12310, CVE-2026-12311, CVE-2026-12312, CVE-2026-12313, CVE-2026-12314, CVE-2026-12315, CVE-2026-12330, CVE-2026-12324, CVE-2026-12325, CVE-2026-12327, CVE-2026-12328. firefox-esr (140.12.0esr-1~deb12u1) bookworm-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-58, also known as: CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12292, CVE-2026-12294, CVE-2026-12295, CVE-2026-12298, CVE-2026-12296, CVE-2026-12297, CVE-2026-12299, CVE-2026-12329, CVE-2026-12302, CVE-2026-12304, CVE-2026-12305, CVE-2026-12306, CVE-2026-12307, CVE-2026-12308, CVE-2026-12309, CVE-2026-12310, CVE-2026-12311, CVE-2026-12312, CVE-2026-12313, CVE-2026-12314, CVE-2026-12315, CVE-2026-12330, CVE-2026-12324, CVE-2026-12325, CVE-2026-12327, CVE-2026-12328. firefox-esr (140.11.0esr-1) unstable; urgency=medium . * New upstream release. * Fixes for mfsa2026-48, also known as: CVE-2026-8946, CVE-2026-8388, CVE-2026-8947, CVE-2026-8391, CVE-2026-8401, CVE-2026-8950, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955, CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8961, CVE-2026-8962, CVE-2026-8968, CVE-2026-8970, CVE-2026-8974, CVE-2026-8975. firefox-esr (140.11.0esr-1~deb13u1) trixie-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-48, also known as: CVE-2026-8946, CVE-2026-8388, CVE-2026-8947, CVE-2026-8391, CVE-2026-8401, CVE-2026-8950, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955, CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8961, CVE-2026-8962, CVE-2026-8968, CVE-2026-8970, CVE-2026-8974, CVE-2026-8975. firefox-esr (140.11.0esr-1~deb12u1) bookworm-security; urgency=medium . * New upstream release. * Fixes for mfsa2026-48, also known as: CVE-2026-8946, CVE-2026-8388, CVE-2026-8947, CVE-2026-8391, CVE-2026-8401, CVE-2026-8950, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955, CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8961, CVE-2026-8962, CVE-2026-8968, CVE-2026-8970, CVE-2026-8974, CVE-2026-8975. firefox-esr (140.10.2esr-1) unstable; urgency=medium . * New upstream release. * Fixes for mfsa2026-41, also known as: CVE-2026-8090, CVE-2026-8094, CVE-2026-8092. fldigi (4.2.06-1+deb13u1) trixie; urgency=medium . * Team upload. * Force LC_NUMERIC=C.UTF-8 to use proper decimal separator in API and ADIF log files. (Closes: #1114613) freecad (1.0.0+dfsg-8+deb13u2) trixie; urgency=medium . * Maintaner approvided upload. * Backport patch 1040-fix-cmake-race.patch to fix FTBFS on arm64. freecad (1.0.0+dfsg-8+deb13u1) trixie; urgency=medium . * Maintaner approvided upload. * Get fanuc post processor working (Closes: #1117850). frr (10.3-3+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Backport upstream fixes for several BGP/OSPF parsing vulnerabilities: - CVE-2026-37457: off-by-one out-of-bounds write in the BGP FlowSpec operator decoder (bgp_flowspec_op_decode). - CVE-2026-28532: out-of-bounds read in OSPF TE/SR Opaque LSA TLV parsing caused by a truncated uint16_t length accumulator. - CVE-2026-5107: missing length validation when parsing EVPN Type-2/3/4 and ENCAP/VNC NLRIs. - CVE-2026-37458: missing martian next-hop validation in MP_REACH_NLRI. - CVE-2025-61099, CVE-2025-61100, CVE-2025-61101, CVE-2025-61102, CVE-2025-61103, CVE-2025-61104, CVE-2025-61105, CVE-2025-61106, CVE-2025-61107: NULL pointer dereference in ospfd when dumping Opaque LSAs while OSPF packet debugging is enabled. fwupd (2.0.20-1~deb13u1) stable-updates; urgency=medium . * Release to stable updates to enable updating UEFI CA. (Closes: #1138871) * Note: Fix deploying the thunderbolt controller on the X280 is now part of the upstream release and the patch is dropped. fwupd (2.0.20-1~deb12u2) bookworm; urgency=medium . * No change rebuild for source upload. fwupd (2.0.20-1~deb12u1) bookworm; urgency=medium . * Release to oldstable updates to enable updating UEFI CA. * d/control: Refresh b-d against bookworm * d/rules: disable modem manager * d/patches: Add patches to allow building on bookworm fwupd (2.0.20-1~bpo13+1) trixie-backports; urgency=medium . * Backport to trixie * Disable passim support fwupd (2.0.19-1) unstable; urgency=medium . * New upstream version (2.0.19) fwupd (2.0.18-1) unstable; urgency=medium . * New upstream version (2.0.18) * Drop upstream patches fwupd (2.0.17-6) unstable; urgency=medium . * Backport a patch to fix x86 32 bit installed tests fwupd (2.0.17-5) unstable; urgency=medium . * d/tests/control: depends on fwupd-tests instead of fwupd fwupd (2.0.17-4) unstable; urgency=medium . * d/t/control: Explicitly add fwupd to depends fwupd (2.0.17-3) unstable; urgency=medium . * d/t/control: Add missing depends for autopkgtest fwupd (2.0.17-2) unstable; urgency=medium . * Backport a fix for installed tests failures with mtdram fwupd (2.0.17-1) unstable; urgency=medium . * New upstream version (2.0.17) fwupd (2.0.16-4) unstable; urgency=medium . * Enable passim support in Debian (disabled in Ubuntu right now). fwupd (2.0.16-3) unstable; urgency=medium . * d/rules: Explicitly set efi_os_dir (Closes: #1105176) (Closes: #1112464) * d/control: Drop b-d on python3-typogrify (Closes: #1105777) * Changes for build-dependency on libgirepository1.0-dev (Closes: #1118817) * Backport a patch to fix a segfault with flashrom (Closes: #1118449) fwupd (2.0.16-2) unstable; urgency=medium . * Backport a patch from upstream to drop python3-toml b-d * d/copyright, d/control: refresh against dependencies.xml (Closes: #1110022) fwupd (2.0.16-1) unstable; urgency=medium . * New upstream version (2.0.16) fwupd (2.0.15-1) unstable; urgency=medium . * New upstream version (2.0.15) fwupd (2.0.14-1) unstable; urgency=medium . * New upstream version (2.0.14) fwupd (2.0.13-2) unstable; urgency=medium . * Upload to unstable fwupd (2.0.13-1) experimental; urgency=medium . * New upstream version. fwupd (2.0.12-1) experimental; urgency=medium . * New upstream version. fwupd (2.0.10-1) experimental; urgency=medium . * New upstream version. * d/control: Update my email fwupd (2.0.9-1) experimental; urgency=medium . * New upstream version (2.0.9) - Drop all upstream patches. gambas3 (3.20.2-1+deb13u1) trixie; urgency=medium . * Team upload * Fix qt6 component trying to load non-existing qt5 dependency (Closes: #1136260) gdown (5.2.0+dfsg-2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-40491: Arbitrary File Write via Path Traversal geoip (1.6.12-11.2~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . geoip (1.6.12-11.2) unstable; urgency=medium . * Non-maintainer upload. * Restore the generator scripts for geoip-database. geoip-database (20250401+really20191224-0+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Revert to the last version before the license change. (Closes: #1134158) * Build depend on geoip with support for the old version restored. giflib (5.2.2-1+deb13u1) trixie; urgency=medium . * CVE-2026-23868 (Closes: #1130495) * CVE-2026-26740 (Closes: #1131368) gimp (3.0.4-3+deb13u9) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-4154: XPM parsing integer overflow * CVE-2026-40915: FITS parsing integer overflow gnustep-sqlclient (1.9.0-6+deb13u1) trixie; urgency=medium . * debian/control (libsqlclient-dev): Remove "Multi-Arch: same" field to avoid file conflicts (Closes: #1133733). gnutls28 (3.8.9-3+deb13u4) trixie-security; urgency=high . * Add 3.8.13 patchset from CentOS 10 security release. Fixes CVE-2026-33846 CVE-2026-42009 CVE-2026-33845 CVE-2026-42010 CVE-2026-3833 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-5260 CVE-2026-42015 CVE-2026-3832 CVE-2026-5419 and also adds a couple of fixes for issues without CVEs assigned. (For Debian base64-encode a testfile, quilt does not support git binary patches.) Closes: #1135319 * Drop patches irrelevant for 3.8.9 from the CentOS patchset. The PKCS#11 [provider] feature was only added in 3.8.10. * Cherry-pick another patch to add a mising declaration. graphite2 (1.3.14-2+deb13u1) trixie; urgency=medium . * debian/patches/ad78c6b7319909e1540c1b134e115ced03417866.patch: fix CVE-2026-50593 gsasl (2.2.2-1.1+deb13u2) trixie-security; urgency=medium . * NTLM client: Avoid use-of-unitialized-value inside libntlm gsasl (2.2.2-1.1+deb13u1) trixie-security; urgency=medium . * Fix NULL pointer dereference in DIGEST-MD5 parser gst-libav1.0 (1.26.2-1+deb13u1) trixie-security; urgency=medium . * CVE-2026-52717 gst-plugins-bad1.0 (1.26.2-3+deb13u2) trixie-security; urgency=medium . * CVE-2026-52718 * CVE-2026-52719 * CVE-2026-53701 gst-plugins-good1.0 (1.26.2-1+deb13u2) trixie-security; urgency=medium . * CVE-2026-39043 * CVE-2026-39044 * CVE-2026-1940 * CVE-2026-3083 * CVE-2026-3085 gst-plugins-good1.0 (1.26.2-1+deb13u1) trixie-security; urgency=medium . * CVE-2026-5056 * CVE-2026-46469 * CVE-2026-46470 haproxy (3.0.11-1+deb13u3) trixie-security; urgency=high . [ Salvatore Bonaccorso ] * BUG/MAJOR: h3: check body size with content-length on empty FIN (CVE-2026-33555) . [ Vincent Bernat ] * BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well * BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based normalization * BUG/MAJOR: mux-h1: Deal with true 64-bits integer to emit chunks size * BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in h2c_dec_hdrs() * BUG/MAJOR: slz: always make sure to limit fixed output to less than worst case literals * BUG/MAJOR: http: forbid comma character in authority value * BUG/MEDIUM: h1: Skip all h2c values from Upgrade headers during parsing haveged (1.9.19-12+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix privilege escalation via command socket (CVE-2026-41054) (Closes: #1137096) * Check peer credentials before reading command (CVE-2026-41054) horizon (3:25.3.0-3+deb13u1) trixie; urgency=medium . * OSSN-0097: Horizon RC file generation does not escape special characters in project. Applied upstream patch: "Escape $ character in shellfilter, and use it consistently" (Closes: #1138845). imagemagick (8:7.1.1.43+dfsg1-1+deb13u10) trixie-security; urgency=high . * Fix CVE-2026-48724: When using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write * Fix CVE-2026-48734: A crafted MVG file could result in a stack overflow due to a missing depth or visited-set check * Fix CVE-2026-48994: A missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. * Fix CVE-2026-49218: A missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. * Fix CVE-2026-49219: An incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink * Backport policy from 7.1.2.25 * Fix CVE-2026-53460: A missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. * Fix CVE-2026-53461: An incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. * Fix CVE-2026-53463: When passing incorrect arguments in the distort operation a null pointer deference will occur. * Fix CVE-2026-53464: When providing invalid options to the wand option parser a small memory leak will occur. * Harden debian policy in case of custom recompilation (Closes: #1140176) imagemagick (8:7.1.1.43+dfsg1-1+deb13u9) trixie-security; urgency=high . * Fix CVE-2026-33901 regression: Previous fix breaks rendering of some MVG files. * Fix CVE-2026-42050: A malicious MIFF file could trigger an overflow when a user opens it in the he display tool and right-clicks a tile to invoke the Load/Update menu item. * Fix CVE-2026-42326: Heap Buffer Over-Read in IPTC encoder * Fix CVE-2026-45031: Policy Bypass in PSD decoder. Due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. * Fix CVE-2026-45358: Heap Buffer Over-Read of a single byte in meta encoder. An of by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder. * Fix CVE-2026-45359: Heap Buffer Over-Read in connected components when the user supplies an invalid keep-top define. An invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. * Fix CVE-2026-45624: Heap Buffer Over-Read of 24 bytes in distort operation. When performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. * Fix CVE-2026-45664: Policy Bypass in MNG decoder Because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. * Fix CVE-2026-46520: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions When reading multiple images with different dimensions an out of bounds heap write can occur. * Fix CVE-2026-46521: Heap Buffer Over-Write in MIFF encoder when using LZMA compression. When using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check * Fix CVE-2026-46522: Infinite Loop in the MIFF decoder can lead to CPU exhaustion. Due to a missing check in the MIFF decoder a crafted file could cause an infinite loop resulting in CPU exhaustion. * Fix CVE-2026-46523: Use-After-Free in MSL decoder. A crafted MSL image can trigger a heap-use-after-free. * Fix CVE-2026-46557: Stack overflow in fx operation. Due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. * Fix CVE-2026-46559: Heap Buffer Over-Write of a single byte in the JP2 encoder. An incorrect check in the JP2 will result in an heap buffer over write of a single byte when specifying certain options. * Fix CVE-2026-46692: Heap Buffer Over-Write in distributed pixel cache server An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. * Fix CVE-2026-46693: Race Condition in distributed pixel cache server can result in file descriptor hijacking An attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. * Fix CVE-2026-47165: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model. The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation. * Fix CVE-2026-47166: Heap Buffer Over-Read in distributed pixel cache server. An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. incus (6.0.4-2+deb13u8) trixie-security; urgency=high . * Cherry-pick fixes for the following security issues: - CVE-2026-48749 / GHSA-2q3f-q5pq-g8wv - CVE-2026-48750 / GHSA-73hr-m85f-64v9 - CVE-2026-48751 / GHSA-48q5-w887-33wv - CVE-2026-48752 / GHSA-vxp5-584q-c479 - CVE-2026-48755 / GHSA-v6mj-8pf4-hhw4 - CVE-2026-48756 / GHSA-xhqx-mgh3-3h7q - CVE-2026-48769 / GHSA-f6m5-xw2g-xc4x - CVE-2026-55621 / GHSA-64f3-v33m-w89f - CVE-2026-55622 / GHSA-c9f5-j9c3-mhrg ironic (1:29.0.5-0+deb13u2) trixie-security; urgency=medium . * CVE-2026-44917: Ironic does not validate the location of node.driver_info[pxe_template], allowing a user who can set it to expose arbitrary files on an internal Ironic network, such as the servicing, provisioning, or cleaning networks. Applied upstream patch: - CVE-2026-44917_disable-driver_info-level-pxe_template-override.patch * CVE-2026-46447: A user with access to add or modify node.driver_info or node.instance_info can create a crafted value to enable iPXE script execution during the boot process. Applied upstream patch: - CVE-2026-46447_Sanitize-kernel_append_parms.patch * CVE-2026-48681: A maliciously crafted ISO image can cause Ironic to perform path traversal and overwrite files on a conductor's disk. Applied upstream patch: - CVE-2026-48681-directory_transversal_ISO9660_support.patch (Closes: #1138842) ironic (1:29.0.5-0+deb13u1) trixie; urgency=medium . * New upstream release. Include fix for: - CVE-2026-42997 / OSSA-2026-010: Credential Forwarding to Arbitrary Endpoints via Ironic’s idrac Configuration molds Feature (Closes: #1135898). - CVE-2026-42510 / OSSA-2026-008: Command Injection in Ironic IPMI Console Implementations. Applied upstream patch: "Shell-quote console command passed to socat" (Closes: #1135255). * CVE-2026-44916: instance_info['ks_template'] is rendered without sandboxing. An attacker with sufficient access, an ironic deployment with the anaconda deploy interface, a node with the anaconda deployment interface set by an admin, and a malicious template could result in conductor internal data being rendered and if the infrastucture operator is allowing traffic egress for the provisioning network, could have sensitive internal data exfiled out of the environment. Applied upstream patch: - CVE-2026-44916_Use_sandbox_rendering_for_jinja2.patch (Closes: #1136005). * CVE-2026-44919: during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. Add upstream patch: move_file_url_validation_up_into_deploy_utils_main_path.patch. (Closes: #1136655). isc-kea (2.6.3-1+deb13u1) trixie; urgency=medium . * CVE-2026-3608 isenkram (0.69+deb13u1) trixie; urgency=medium . * Adjusted update-fw-list to handle / -> /usr migration (Closes: #1133426). * Updated generated firmware lists. jackson-core (2.14.1-2~deb13u1) trixie-security; urgency=medium . * Team upload. * Backport 2.14.1 to trixie. * Fix CVE-2025-52999 and CVE-2025-49128. jackson-core (2.14.1-2~deb12u1) bookworm-security; urgency=medium . * Team upload. * Backport 2.14.1 to bookworm. * Fix CVE-2025-52999 and CVE-2025-49128. jackson-databind (2.14.0+ds-1+deb13u1) trixie-security; urgency=medium . [ Otto Kekäläinen ] * Enable Salsa CI to help avoid testable regressions before upload to Debian * Fix broken Homepage link and add current upstream metadata. The site wiki.fasterxml.com no longer exists. Replace it with link to the current wiki location. Also add a metadata file following DEP-12, so it is easier for both maintainers to find the correct upstream websites, as well as for `git-buildpackage --add-upstreamvcs` feature to work. * Define Debian packaging repository conventions in gbp.conf. Add a git-buildpackage config file to show explicitly what conventions this Debian source package repository uses. This way it is easier for current maintainer to do e.g. new upstream version imports, as there are less arguments that need to be passed to `gbp` commands, and also for any future maintainer/contributor there is less guesswork. . [ Markus Koschany ] * Add CVE-2025-52999.patch and fix a FBTFS due to changes in jackson-core. (Closes: #1135410) jackson-dataformat-smile (2.7.8-5+deb13u1) trixie-security; urgency=medium . * Team upload. * Fix FTBFS with jackson-core and restore the compatibility. jackson-dataformat-smile (2.7.8-5+deb12u1) bookworm-security; urgency=medium . * Team upload. * Fix FTBFS with jackson-core and restore the compatibility. jpeg-xl (0.11.2-0.1~deb13u2) trixie-security; urgency=medium . * CVE-2025-70103 (Closes: #1138575) kdenlive (24.12.3-2+deb13u1) trixie-security; urgency=high . * Add patch 02-CVE-2026-45184: Dangerous proxy parameters, when an attacker-controlled project file is used. Closes: #1136172 keystone (2:27.0.0-3+deb13u4) trixie-security; urgency=medium . * Multiple vulnerabilities in Keystone's delegated authentication allow an authenticated user to escalate privileges to cloud admin. The most severe (CVE-2026-42999) requires only a valid token: - CVE-2026-42999: An attacker can inject RBAC policy targets via the JSON request body, bypassing authorization on any policy-protected endpoint. Allows reading all credential secrets, creating credentials for arbitrary users, and granting admin across domains. (LP#2148398, reported by Boris Bobrov, SAP SE). - CVE-2026-42998: Application credential authentication does not verify the caller owns the credential, allowing user impersonation within a shared project. (LP#2148477, reported by Boris Bobrov, SAP SE). - CVE-2026-43000: The impersonation from CVE-2026-42998 can be chained with trusts to escalate from member to admin. The resulting trust persists independently of the original credential. (LP#2148477, reported by Boris Bobrov, SAP SE) - CVE-2026-43001: Application credentials scoped to one project can create EC2 credentials for a different project. A fix for the creation-time path is already merged; this patch extends the check to the auth-time path. (LP#2149775, reported by Tim Shepherd, roiai.ca) - CVE-2026-44394: Federated users can maintain access indefinitely by repeatedly rescoping tokens before expiry. Each rescope issues a fresh full-TTL token instead of inheriting the original expiry. Only SAML2/OIDC deployments are affected. (LP#2150379, reported by Erichen, Institute of Computing Technology, Chinese Academy of Sciences). . The patch also addresses three related issues found during investigation: trust-scoped tokens accessing credentials outside the delegated project (LP#2149789), trust-scoped tokens creating persistent application credentials for impersonated users (LP#2150089), and a latent query-string parameter injection in policy enforcement and lack of scope boundary enforcement in the delegated token logic (LP#2150089). These were reported by Tim Shepherd (roiai.ca) and Artem Goncharov (SysEleven GmbH). . Applied the proposed upstream patches: - 0001-Add-tests-for-restricted-app-cred-guard.patch - 0002-Block-restricted-app-creds-from-creating-EC2-credent.patch - 0003-Block-app-cred-tokens-from-authorizing-OAuth1-reques.patch - 0004-Enforce-app-cred-project-boundary-on-EC2-credential-.patch - CVE-2026-43001-keystone-backport-stable-2025.1.patch . Please also note that the fix for CVE-2026-42999 (LP#2148398) modifies the trust policy structure. If this policy is customized by the provider, failure to update it may result in issues with image upload, heat service functionality and potentially more. * Note that all the above CVE are combined into this one: CVE-2026-43001. (Closes: #1135645). keystone (2:27.0.0-3+deb13u3) trixie; urgency=medium . * CVE-2026-40683 / OSSA-2026-007: LDAP identity backend does not convert enabled attribute to boolean. When the user_enabled_invert configuration option was False (the default), Keystone did not correctly interpret the LDAP enabled attribute, causing users disabled in LDAP to be treated as enabled and allowed to authenticate. Deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected. Applied upstream patch: - OSSA-2026-007-fix_ldap_enabled_setting_not_interpreted_as_boolean.patch (Closes: #1133884). * CVE-2026-33551 / OSSA-2026-005: Restricted application credentials can create EC2 credentials. Applied upstream patch "Prevent unauthorized EC2 credential creation and deletion" (Closes: #1133118). kitty (0.41.1-2+deb13u1) trixie-security; urgency=medium . * Add patches to fix CVE-2026-33642 and CVE-2026-33633 Closes: #1137210 krb5 (1.21.3-5+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) (Closes: #1135317) libapache-session-browseable-perl (1.3.16-1+deb13u1) trixie; urgency=medium . * Improve Apache::Session::Generate::SHA256 entropy (Closes: CVE-2026-8503) libass (1:0.17.3-1+deb13u1) trixie; urgency=medium . [ Oneric ] * Backport security fixes from 0.15.5 to 0.17.3 - Out-of-bounds read and write in wrap_lines_measure (GHSA-pjjp-65r7-ppgm) libbytes-random-secure-perl (0.29-4~deb13u1) trixie; urgency=medium . * Rebuild for trixie . libbytes-random-secure-perl (0.29-4) unstable; urgency=medium . * Team upload. * Fix incorrect usage of seed in PRNG (CVE-2026-11625) libbytes-random-secure-perl (0.29-4~deb13u1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm . libbytes-random-secure-perl (0.29-4~deb13u1) trixie; urgency=medium . * Rebuild for trixie . libbytes-random-secure-perl (0.29-4) unstable; urgency=medium . * Team upload. * Fix incorrect usage of seed in PRNG (CVE-2026-11625) libcaca (0.99.beta20-5+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Prevent undefined behaviour in overflow check (CVE-2026-42046) (Closes: #1136952) libconfig-inifiles-perl (3.000003-3+deb13u1) trixie-security; urgency=high . * Team upload. * Add fix for CVE-2026-11527 (uses 2-arg open() in _make_filehandle) libcrypt-pbkdf2-perl (0.261630-1~deb13u1) trixie; urgency=medium . * Rebuild for trixie * Revert "Annotate test-only build dependencies with ." * Revert "Remove «Priority: optional», which is the current default." * Revert "Declare compliance with Debian Policy 4.7.4." . libcrypt-pbkdf2-perl (0.261630-1) unstable; urgency=medium . * Team upload. * Import upstream version 0.261630. - Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000 (CVE-2026-9641). - Generate salts using Crypt::URandom instead of perl's builtin `rand()` (CVE-2026-9638). - Use a constant-time comparison in `validate` to avoid timing attacks (CVE-2017-20240). Closes: #1139867 * Update debian/upstream/metadata. * Update years of upstream copyright. * debian/control: update build/test/runtime dependencies. * Declare compliance with Debian Policy 4.7.4. * Remove «Priority: optional», which is the current default. * Annotate test-only build dependencies with . libcrypt-pbkdf2-perl (0.261630-1~deb13u1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm . libcrypt-pbkdf2-perl (0.261630-1~deb13u1) trixie; urgency=medium . * Rebuild for trixie * Revert "Annotate test-only build dependencies with ." * Revert "Remove «Priority: optional», which is the current default." * Revert "Declare compliance with Debian Policy 4.7.4." . libcrypt-pbkdf2-perl (0.261630-1) unstable; urgency=medium . * Team upload. * Import upstream version 0.261630. - Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000 (CVE-2026-9641). - Generate salts using Crypt::URandom instead of perl's builtin `rand()` (CVE-2026-9638). - Use a constant-time comparison in `validate` to avoid timing attacks (CVE-2017-20240). Closes: #1139867 * Update debian/upstream/metadata. * Update years of upstream copyright. * debian/control: update build/test/runtime dependencies. * Declare compliance with Debian Policy 4.7.4. * Remove «Priority: optional», which is the current default. * Annotate test-only build dependencies with . libcrypt-urandom-perl (0.54-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-2474: heap buffer overflow in crypt_urandom_getrandom() libdbi-perl (1.647-1+deb13u1) trixie-security; urgency=high . * Team upload. * Fix possible stack overflow (CVE-2026-9698) * Replacing `?` with `:p#` in `preparse ()` with more than 9 `?` causes buffer overflow (CVE-2026-10879) libgcrypt20 (1.11.0-7+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * cipher:ecc: Fix decoding a point on Montgomery curve. (CVE-2026-41989) libgd-perl (2.78-1+deb13u1) trixie-security; urgency=high . * Team upload. * Fix CVE-2026-11526: command injection via 2-arg open() in _make_filehandle libhtml-parser-perl (3.83-2~deb13u1) trixie; urgency=medium . * Rebuild for trixie . libhtml-parser-perl (3.83-2) unstable; urgency=medium . * Fix heap-use-after-free in _decode_entities (CVE-2026-8829) libhttp-daemon-perl (6.16-1+deb13u1) trixie-security; urgency=high . * Team upload. * Fix CVE-2026-8450: send_file() honoured 2-arg open() shell-magic (Closes: #1138050) * Add regression test for send_file() shell-magic refusal libhttp-daemon-perl (6.16-1+deb13u1~deb12u1) bookworm-security; urgency=high . * Team upload. * Rebuild for bookworm-security . libhttp-daemon-perl (6.16-1+deb13u1) trixie-security; urgency=high . * Team upload. * Fix CVE-2026-8450: send_file() honoured 2-arg open() shell-magic (Closes: #1138050) * Add regression test for send_file() shell-magic refusal libinput (1.28.1-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * util: don't call function in macro argument * util: sanitize control characters in str_sanitize() * libinput-device-group: sanitize phys before printing it (CVE-2026-50292) libnet-cidr-lite-perl (0.22-3~deb13u2) trixie; urgency=medium . * Team upload. * CVE-2026-45190: Reject Unicode digits and trailing newlines in parsers * CVE-2026-45190: Add tests * CVE-2026-45191: Reject zero-padded CIDR masks * CVE-2026-45191: Add tests librabbitmq (0.15.0-1+deb13u1) trixie-security; urgency=medium . * [b57bf8d] d/patches/CVE-2026-44235.patch: added from upstream. Fix out-of-bounds read via undersized frames in amqp_handle_input (GHSA-9mmv-r8g3-qp46, CVE-2026-44235) * [890d6c5] d/patches/CVE-2026-44236.patch: added from upstream. Fix client crash when server negotiates frame_max below the AMQP protocol minimum (GHSA-jh48-qjf5-fx5v, CVE-2026-44236) libreoffice (4:25.2.3-2+deb13u6) trixie; urgency=medium . * debian/patches/check-for-hb_shape_full-failure.diff: add patch from libreoffice-26-2 branch to gracefully handle hb_shape_full failure, as can happen after the fix for CVE-2026-50593 in graphite2 libreoffice (4:25.2.3-2+deb13u5) trixie-security; urgency=medium . * debian/patches/CVE-2026-*.diff: fix - CVE-2026-6039 DXF heap-buffer-overflow in DrawLWPolyLineEntity - CVE-2026-6040 ODT use-after-free in lcl_InsertBlankWidthChars - CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read - CVE-2026-8356 ANT-2026-01882: Stack Buffer Overflow in `SdrEscherImport::RecolorGraphic()` - CVE-2026-8357 ANT-2026-03093: Off-by-one heap-buffer-overflow in LibreOffice Calc formula compiler - CVE-2026-8358 ANT-2026-03238: Heap-buffer-overflow in LibreOffice Calc FODS tracked-changes importer via duplicate action ID libreoffice (4:25.2.3-2+deb13u5~bpo12+1) bookworm-backports; urgency=medium . * rebuild for bookworm-backports . * revert t64 rename for bookworm-backports . * debian/source/include-binaries, tarballs/*: include tarballs/frozen-1.2.0.tar.gz tarballs/mdds-2.1.1.tar.xz tarballs/liborcus-0.19.2.tar.xz tarballs/libcmis-0.6.2.tar.xz . libreoffice (4:25.2.3-2+deb13u5) trixie-security; urgency=medium . * debian/patches/CVE-2026-*.diff: fix - CVE-2026-6039 DXF heap-buffer-overflow in DrawLWPolyLineEntity - CVE-2026-6040 ODT use-after-free in lcl_InsertBlankWidthChars - CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read - CVE-2026-8356 ANT-2026-01882: Stack Buffer Overflow in `SdrEscherImport::RecolorGraphic()` - CVE-2026-8357 ANT-2026-03093: Off-by-one heap-buffer-overflow in LibreOffice Calc formula compiler - CVE-2026-8358 ANT-2026-03238: Heap-buffer-overflow in LibreOffice Calc FODS tracked-changes importer via duplicate action ID . libreoffice (4:25.2.3-2+deb13u4) trixie-security; urgency=medium . * debian/patches/Conform-AlignEngine-parsing-to-spec.diff: as name says; from libreoffice-26-2 branch; fixes CVE-2026-4430 libslirp (4.8.0-1+deb13u1) trixie; urgency=medium . * d/gbp.conf: switch to debian/trixie branch * oob-cap-urgent-data-to-what-is-available-CVE-2026-9539.patch patch from upstream to fix CVE-2026-9539 (oob heap read and integer underflow allowing reading sensitive host-process memory) libssh2 (1.11.1-1+deb13u1) trixie-security; urgency=medium . * CVE-2026-7598 (Closes: #1135647) * CVE-2025-15661 / CVE-2026-55199 / CVE-2026-55200 (Closes: #1140401) libtasn1-6 (4.20.0-2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-13151: Stack-based buffer overflow in asn1_expand_octet_string() (Closes: #1125063) libvncserver (0.9.15+dfsg-1+deb13u2) trixie; urgency=medium . * Team upload. * debian/patches: + CVE-2026-44988: Add 0003_CVE-2026-44988.patch fixing Tight gradient decoding overflow (Closes: #1138174). + CVE-2026-50538: Add 0004_CVE-2026-50538.patch fixing attacker-controlled heap out-of-bounds write (Closes: #1138253). libxml-libxml-perl (2.0207+dfsg+really+2.0134-5+deb13u1) trixie; urgency=medium . * Team upload. * fix: replace domParseChar with xmlValidateName to prevent OOB UTF-8 read (CVE-2026-8177) (Closes: #1136300) libxml2 (2.12.7+dfsg+really2.9.14-2.1+deb13u3) trixie; urgency=high . * Non-maintainer upload. * Fix CVE-2026-0989: Specially crafted or overly complex schemas can cause excessive recursion during parsing, which may lead to stack exhaustion and application crashes. The parser now enforces a limit on inclusion depth when resolving nested `` directives; the limit defaults to 1000 and can be modified at runtime with the env variable `RNG_INCLUDE_LIMIT`. (Closes: #1125691) * Fix CVE-2026-0990: `xmlCatalogXMLResolveURI()` will recurse infinitely if a catalog has a URI delegate referencing itself, eventually resulting in a call stack overflow. (Closes: #1125695) * Fix CVE-2026-0992: Denial of Service vulnerability due to uncontrolled resource consumption when processing XML catalogs containing repeated `` elements pointing to the same downstream catalog. (Closes: #1125696) * Fix CVE-2025-8732: When a catalog file contains a CATALOG directive pointing to itself, `xmlExpandCatalog()` and `xmlParseSGMLCatalog()` recursively call each other without bounds until stack overflow. * Fix CVE-2026-1757: Memory leak issue in the command parsing logic of the xmllint interactive shell. * Fix unit tests for CVE-2025-49794 and -49796. * Backport some more upstream changes from v2.15.2: + Fix memory leak of prefix in `xmlTextWriterStartElementNS()`. + Mitigate use-after-free issue in `xmlRelaxNGValidateValue()`. + Fix memory leak in `xmlTextWriterStartAttributeNS()`. + Schematron: Fix additional memory leaks on error paths. + Catalog: Fix stack overflow from self-referencing SGML CATALOG entries. * Add d/salsa-ci.yml for Salsa CI. libxpm (1:3.5.17-1+deb13u1) trixie; urgency=medium . * CVE-2026-4367 (Closes: #1134690) linux (6.12.94-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.91 - io_uring/kbuf: use mem_is_zero() - blk-cgroup: wait for blkcg cleanup before initializing new disk - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START - fs/mbcache: cancel shrink work before destroying the cache - md/raid1: fix the comparing region of interval tree - drbd: Balance RCU calls in drbd_adm_dump_devices() - loop: fix partition scan race between udev and loop_reread_partitions() - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() - blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() - pstore/ram: fix resource leak when ioremap() fails - md: wake raid456 reshape waiters before suspend - btrfs: pass struct btrfs_inode to clone_copy_inline_extent() - btrfs: fix deadlock between reflink and transaction commit when using flushoncommit - [amd64] ACPI: x86: cmos_rtc: Clean up address space handler driver - [amd64] ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver - devres: fix missing node debug info in devm_krealloc() - thermal/drivers/spear: Fix error condition for reading st,thermal-flags - debugfs: check for NULL pointer in debugfs_create_str() - debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() - soundwire: debugfs: initialize firmware_file to empty string - PCI: use generic driver_override infrastructure - platform/wmi: use generic driver_override infrastructure - [s390x] cio: use generic driver_override infrastructure - bus: fsl-mc: use generic driver_override infrastructure - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter - hrtimers: Update the return type of enqueue_hrtimer() - hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() - hrtimer: Reduce trace noise in hrtimer_start() - locking: Fix rwlock support in - firmware: dmi: Correct an indexing error in dmi.h - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet - bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n - [s390x] bpf: Zero-extend bpf prog return values and kfunc arguments - params: Replace __modinit with __init_or_module - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() - wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control - wifi: mt76: mt7615: fix use_cts_prot support - wifi: mt76: mt7915: fix use_cts_prot support - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() - wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor - wifi: mt76: mt7921: Place upper limit on station AID - [arm64] cpufeature: Make PMUVer and PerfMon unsigned - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() - wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() - wifi: mt76: mt7921: fix 6GHz regulatory update on connection - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path - bpf: Fix variable length stack write over spilled pointers - bpf,arc_jit: Fix missing newline in pr_err messages - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() - r8152: fix incorrect register write to USB_UPHY_XTAL - [powerpc*] crash: fix backup region offset update to elfcorehdr - [powerpc*] crash: Update backup region offset in elfcorehdr on memory hotplug - macvlan: annotate data-races around port->bc_queue_len_used - bpf: fix end-of-list detection in cgroup_storage_get_next_key() - bpf: Fix stale offload->prog pointer after constant blinding - wifi: brcmfmac: Fix error pointer dereference - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() - wifi: ath10k: fix station lookup failure during disconnect - ACPI: AGDI: fix missing newline in error message - [arm64] kexec: Remove duplicate allocation for trans_pgd - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb - net: bcmgenet: add bcmgenet_has_* helpers - net: bcmgenet: move DESC_INDEX flow to ring 0 - net: bcmgenet: support reclaiming unsent Tx packets - net: bcmgenet: switch to use 64bit statistics - net: bcmgenet: fix racing timeout handler - eth: fbnic: Use wake instead of start - netfilter: xt_socket: enable defrag after all other checks - netfilter: nft_fwd_netdev: check ttl/hl before forwarding - bpf: fix mm lifecycle in open-coded task_vma iterator - bpf: switch task_vma iterator from mmap_lock to per-VMA locks - bpf: return VMA snapshot from task_vma iterator - bpf: Fix RCU stall in bpf_fd_array_map_clear() - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf - bpf: Relax scalar id equivalence for state pruning - bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars - net/sched: act_ct: Only release RCU read lock after ct_ft - net: airoha: Implement BQL support - net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() - bpf: Allow instructions with arena source and non-arena dest registers - net/rds: Optimize rds_ib_laddr_check - net/rds: Restrict use of RDS/IB to the initial network namespace - bpf: Fix OOB in pcpu_init_value - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls - net: ipa: Fix programming of QTIME_TIMESTAMP_CFG - net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ - dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 - net: phy: fix a return path in get_phy_c45_ids() - net/mlx5e: Fix features not applied during netdev registration - net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp - Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec - net: phy: qcom: at803x: Use the correct bit to disable extended next page - ipv4: udp: fix typos in comments - ipv6: udp: fix typos in comments - udp: Force compute_score to always inline - tcp: Don't set treq->req_usec_ts in cookie_tcp_reqsk_init(). - sctp: fix missing encap_port propagation for GSO fragments - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master - drm/komeda: fix integer overflow in AFBC framebuffer size check - ASoC: SOF: ipc3: Use standard dev_dbg API - ASoC: add symmetric_ prefix for dai->rate/channels/sample_bits - ASoC: soc-compress: use function to clear symmetric params - drm/sun4i: backend: fix error pointer dereference - ASoC: sti: Return errors from regmap_field_alloc() - ASoC: sti: use managed regmap_field allocations - dm cache: fix null-deref with concurrent writes in passthrough mode - dm cache: fix write path cache coherency in passthrough mode - dm cache: fix write hang in passthrough mode - dm cache policy smq: fix missing locks in invalidating cache blocks - dm cache: fix concurrent write failure in passthrough mode - dm cache: support shrinking the origin device - dm cache: fix dirty mapping checking in passthrough mode switching - platform/chrome: chromeos_tbmc: Drop wakeup source on remove - PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding - PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() - dm cache metadata: fix memory leak on metadata abort retry - dm log: fix out-of-bounds write due to region_count overflow - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check - spi: spi-nxp-fspi: enable runtime pm for fspi - spi: nxp-fspi: Use reinit_completion() for repeated operations - spi: fsl-qspi: Use reinit_completion() for repeated operations - media: i2c: og01a1b: Replace client->dev usage - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe - drm/v3d: Handle error from drm_sched_entity_init() - drm/sun4i: Fix resource leaks - drm/amdgpu: Add default case in DVI mode validation - dm init: ensure device probing has finished in dm-mod.waitfor= - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break - crypto: tegra - finalize crypto req on error - crypto: tegra - Transfer HASH init function to crypto engine - crypto: tegra - Reserve keyslots to allocate dynamically - crypto: tegra - Disable softirqs before finalizing request - crypto: atmel - Use unregister_{aeads,ahashes,skciphers} - crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs - padata: Remove cpu online check from cpu add and removal - padata: Put CPU offline callback in ONLINE section to allow failure - PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation - drm/amdgpu/gfx10: look at the right prop for gfx queue priority - drm/amdgpu/gfx11: look at the right prop for gfx queue priority - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo - drm/imagination: Switch reset_reason fields from enum to u32 - iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() - [arm64] drm/msm/dpu: fix mismatch between power and frequency - [arm64] drm/msm/dsi: add the missing parameter description - [arm64] drm/msm/dsi: fix bits_per_pclk - [arm64] drm/msm/dsi: fix hdisplay calculation for CMD mode panel - [arm64] drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first - drm/panel: simple: Correct G190EAN01 prepare timing - PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support - ALSA: core: Validate compress device numbers without dynamic minors - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels - drm/amd/pm/ci: Fill DW8 fields from SMC - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board - drm/amdgpu: add amdgpu_device reference in ip block - drm/amdgpu: update the handle ptr in dump_ip_state - drm/amdgpu: update the handle ptr in early_init - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled - hwmon: Switch back to struct platform_driver::remove() - hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') - [amd64] ASoC: SOF: Intel: hda: Place check before dereference - [arm64] drm/msm/a6xx: Fix HLSQ register dumping - [arm64] drm/msm/shrinker: Fix can_block() logic - [arm64] drm/msm/a6xx: Fix dumping A650+ debugbus blocks - [arm64] drm/msm/a6xx: Use barriers while updating HFI Q headers - pmdomain: ti: omap_prm: Fix a reference leak on device node - pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() - PM: domains: De-constify fields in struct dev_pm_domain_attach_data - ASoC: fsl_micfil: Add access property for "VAD Detected" - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() - ASoC: fsl_easrc: Change the type for iec958 channel status controls - [amd64] iommu/amd: Remove protection_domain.dev_cnt variable - [amd64] iommu/amd: xarray to track protection_domain->iommu list - [amd64] iommu/amd: Do not detach devices in domain free path - [amd64] iommu/amd: Reduce domain lock scope in attach device path - [amd64] iommu/amd: Rearrange attach device code - [amd64] iommu/amd: Convert dev_data lock from spinlock to mutex - [amd64] iommu/amd: Introduce helper function to update 256-bit DTE - [amd64] iommu/amd: Introduce helper function get_dte256() - [amd64] iommu/amd: Fix clone_alias() to use the original device's devid - [arm64] ASoC: qcom: qdsp6: topology: check widget type before accessing data - crypto: qat - introduce fuse array - crypto: qat - disable 4xxx AE cluster when lead engine is fused off - crypto: qat - disable 420xx AE cluster when lead engine is fused off - crypto: qat - fix type mismatch in RAS sysfs show functions - crypto: qat - use swab32 macro - ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] - PCI: Enable AtomicOps only if Root Port supports them - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found - Documentation: fix a hugetlbfs reservation statement - ALSA: scarlett2: Add missing sentinel initializer field - ASoC: SOF: compress: return the configured codec from get_params - PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports - PCI: tegra194: Fix polling delay for L2 state - PCI: tegra194: Increase LTSSM poll time on surprise link down - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down - PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() - PCI: tegra194: Don't force the device into the D0 state before L2 - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" - PCI: tegra194: Disable direct speed change for Endpoint mode - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode - PCI: tegra194: Allow system suspend when the Endpoint link is not up - PCI: tegra194: Free up Endpoint resources during remove() - PCI: tegra194: Use DWC IP core version - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well - PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback - ALSA: sc6000: Keep the programmed board state in card-private data - dm cache: fix missing return in invalidate_committed's error path - crypto: jitterentropy - replace long-held spinlock with mutex - ALSA: hda/realtek - fixed speaker no sound update - gfs2: Call unlock_new_inode before d_instantiate - net/socket.c: switch to CLASS(fd) - fdget(), trivial conversions - fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() - quota: Fix race of dquot_scan_active() with quota deactivation - gfs2: add some missing log locking - gfs2: prevent NULL pointer dereference during unmount - efi/capsule-loader: fix incorrect sizeof in phys array reallocation - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine - [arm64] dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon - memory: tegra124-emc: Fix dll_change check - memory: tegra30-emc: Fix dll_change check - [arm64] dts: imx8-apalis: Fix LEDs name collision - [arm64] dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config - [arm64] dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) - iommufd: vfio compatibility extension check for noiommu mode - [arm64] dts: mediatek: mt6795: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7981b: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7986a: Fix gpio-ranges pin count - [arm64] dts: qcom: msm8953-xiaomi-vince: correct wled ovp value - [arm64] dts: qcom: msm8953-xiaomi-daisy: fix backlight - [arm64] dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi - [arm64] dts: rockchip: Correct Fan Supply for Gameforce Ace - [arm64] dts: rockchip: Correct Joystick Axes on Gameforce Ace - [arm64] soc: qcom: ocmem: make the core clock optional - [arm64] soc: qcom: ocmem: register reasons for probe deferrals - [arm64] soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available - bus: rifsc: fix RIF configuration check for peripherals - [arm64] dts: qcom: sm8450: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix GIC_ITS range length - [arm64] dts: qcom: sm8650: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix xo clock supply of platform SD host controller - [arm64] dts: qcom: sm8650: Fix xo clock supply of SD host controller - [arm64] dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl - [arm64] dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot - [arm64] dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins - [arm64] dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins - [arm64] dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label - [arm64] dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing - [arm64] dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit - [arm64] dts: lx2160a: remove duplicate pinmux nodes - [arm64] dts: lx2160a: rename pinmux nodes for readability - [arm64] dts: lx2160a: add sda gpio references for i2c bus recovery - [arm64] dts: lx2160a: change zeros to hexadecimal in pinmux nodes - [arm64] dts: lx2160a: complete pinmux for rcwsr12 configuration word - [arm64] dts: imx8qm-mek: switch Type-C connector power-role to dual - [arm64] dts: imx8qxp-mek: switch Type-C connector power-role to dual - soc/tegra: cbb: Set ERD on resume for err interrupt - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure - ocfs2/dlm: validate qr_numregions in dlm_match_regions() - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison - soc: qcom: llcc: fix v1 SB syndrome register offset - [arm64] soc: qcom: aoss: compare against normalized cooling state - [arm64] dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP - [arm64] xor: fix conflicting attributes for xor_block_template - firmware: arm_ffa: Use the correct buffer size during RXTX_MAP - ocfs2: fix listxattr handling when the buffer is full - ocfs2: validate bg_bits during freefrag scan - ocfs2: validate group add input before caching - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() - soundwire: cadence: Clear message complete before signaling waiting thread - tracing: Rebuild full_name on each hist_field_name() call - hte: tegra194: remove Kconfig dependency on Tegra194 SoC - remoteproc: xlnx: Fix sram property parsing - ima: check return value of crypto_shash_final() in boot aggregate - HID: asus: make asus_resume adhere to linux kernel coding standards - HID: asus: do not abort probe when not necessary - mtd: physmap_of_gemini: Fix disabled pinctrl state check - ima_fs: don't bother with removal of files in directory we'll be removing - ima_fs: get rid of lookup-by-dentry stuff - ima_fs: Correctly create securityfs files for unsupported hash algos - dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations - mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook - mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook - mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions - cxl/pci: Check memdev driver binding status in cxl_reset_done() - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob - HID: usbhid: fix deadlock in hid_post_reset() - ext4: fix possible null-ptr-deref in mbt_kunit_exit() - [arm64] bpf, arm64: Fix off-by-one in check_imm signed range check - bpf, sockmap: Fix af_unix iter deadlock - bpf, sockmap: Fix af_unix null-ptr-deref in proto update - bpf, sockmap: Take state lock for af_unix iter - bpf: Fix precedence bug in convert_bpf_ld_abs alignment check - bpf: Fix NULL deref in map_kptr_match_type for scalar regs - bpf: allow UTF-8 literals in bpf_bprintf_prepare() - bpf: Validate node_id in arena_alloc_pages() - bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT - pinctrl: pinctrl-pic32: Fix resource leak - pinctrl: cy8c95x0: remove duplicate error message - pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() - pinctrl: cy8c95x0: Avoid returning positive values to user space - perf branch: Avoid incrementing NULL - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace - pinctrl: realtek: Fix function signature for config argument - pinctrl: abx500: Fix type of 'argument' variable - pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers - perf lock: Fix option value type in parse_max_stack - perf stat: Fix opt->value type for parse_cache_level - perf tools: Fix module symbol resolution for non-zero .text sh_addr - perf expr: Return -EINVAL for syntax error in expr__find_ids() - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure - ipmi: ssif_bmc: fix message desynchronization after truncated response - ipmi: ssif_bmc: change log level to dbg in irq callback - perf evsel: Add alternate_hw_config and use in evsel__match - perf tool_pmu: Factor tool events into their own PMU - perf python: Add parse_events function - perf cgroup: Update metric leader in evlist__expand_cgroup - perf maps: Fix copy_from that can break sorted by name order - perf util: Kill die() prototype, dead for a long time - reset: replace boolean parameters with flags parameter - reset: Add devres helpers to request pre-deasserted reset controls - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() - platform/surface: surfacepro3_button: Drop wakeup source on remove - leds: lgm-sso: Remove duplicate assignments for priv->mmap - tty: hvc_iucv: fix off-by-one in number of supported devices - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() - nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist() - [amd64] platform/x86: asus-wmi: adjust screenpad power/brightness handling - [amd64] platform/x86: asus-wmi: fix screenpad brightness range - tty: serial: ip22zilog: Fix section mispatch warning - fs/ntfs3: terminate the cached volume label after UTF-8 conversion - [amd64] platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() - [amd64] platform/x86: dell-wmi-sysman: bound enumeration string aggregation - RDMA/core: Prefer NLA_NUL_STRING - clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source - scsi: sg: Fix sysctl sg-big-buff register during sg_init() - scsi: sg: Resolve soft lockup issue when opening /dev/sgX - clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers - clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting - scsi: target: core: Fix integer overflow in UNMAP bounds check - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Use retention for USB power domains - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() - clk: imx8mq: Correct the CSI PHY sels - [amd64] x86/um/vdso: Drop VDSO64-y from Makefile - clk: qoriq: avoid format string warning - clk: xgene: Fix mapping leak in xgene_pllclk_init() - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets - clk: qcom: dispcc-sc7180: Add missing MDSS resets - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() - clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON - clk: visconti: pll: initialize clk_init_data to zero - f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() - [amd64] drm/i915: Relocate the SKL wm sanitation code - [amd64] drm/i915/wm: Verify the correct plane DDB entry - crypto: sa2ul - Fix AEAD fallback algorithm names - crypto: ccp - copy IV using skcipher ivsize - erofs: add encoded extent on-disk definition - erofs: do sanity check on m->type in z_erofs_load_compact_lcluster() - erofs: avoid infinite loops due to corrupted subpage compact indexes (CVE-2025-68251) - erofs: unify lcn as u64 for 32-bit platforms - [arm64] dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT - PCMCIA: Fix garbled log messages for KERN_CONT - [arm64] dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT - [arm64] dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names - net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir - macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF - net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys - nexthop: fix IPv6 route referencing IPv4 nexthop - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch - tcp: add data-race annotations around tp->data_segs_out and tp->total_retrans - tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE - tcp: annotate data-races around tp->bytes_sent - tcp: annotate data-races around tp->bytes_retrans - tcp: annotate data-races around tp->dsack_dups - tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) - tcp: annotate data-races around tp->plb_rehash - ice: update PCS latency settings for E825 10G/25Gb modes - ice: Remove jumbo_remove step from TX path - ice: fix double-free of tx_buf skb - ice: fix ICE_AQ_LINK_SPEED_M for 200G - i40e: don't advertise IFF_SUPP_NOFCS - e1000e: Unroll PTP in probe error handling - ipv6: fix possible UAF in icmpv6_rcv() - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks - pppoe: drop PFC frames - net/mlx5: Fix HCA caps leak on notifier init failure - openvswitch: cap upcall PID array size and pre-size vport replies - netfilter: nft_osf: restrict it to ipv4 - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO - netfilter: conntrack: remove sprintf usage - netfilter: xtables: restrict several matches to inet family - ipvs: fix MTU check for GSO packets in tunnel mode - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check - slip: reject VJ receive packets on instances with no rstate array - slip: bound decode() reads against the compressed packet length - [arm64] dts: meson-gxl-p230: fix ethernet PHY interrupt number - pwm: atmel-tcb: Cache clock rates and mark chip as atomic - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() - ksmbd: destroy async_ida in ksmbd_conn_free() - ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open - ksmbd: scope conn->binding slowpath to bound sessions only - net/rds: zero per-item info buffer before handing it to visitors - ice: fix timestamp interrupt configuration for E825C - ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() - net/sched: sch_pie: annotate data-races in pie_dump_stats() - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() - net/sched: sch_red: annotate data-races in red_dump_stats() - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() - net: dsa: realtek: rtl8365mb: fix mode mask calculation - net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() - virtio_net: Split struct virtio_net_rss_config - virtio_net: Fix endian with virtio_net_ctrl_rss - virtio_net: Use new RSS config structs - virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls - tipc: fix double-free in tipc_buf_append() - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() - fs/adfs: validate nzones in adfs_validate_bblk() - rtc: abx80x: Disable alarm feature if no interrupt attached - kbuild: builddeb - avoid recompiles for non-cross-compiles - fbdev: offb: fix PCI device reference leak on probe failure - mailbox: mtk-cmdq: Fix CURR and END addr for task insert case - mailbox: mailbox-test: free channels on probe error - cgroup/rdma: fix integer overflow in rdmacg_try_charge() - mailbox: add sanity check for channel array - mailbox: mailbox-test: don't free the reused channel - mailbox: mailbox-test: initialize struct earlier - mailbox: mailbox-test: make data_ready a per-instance variable - fsnotify: fix inode reference leak in fsnotify_recalc_mask() - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() - cgroup: Increment nr_dying_subsys_* from rmdir context - tracing: branch: Fix inverted check on stat tracer registration - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers - netfilter: arp_tables: fix IEEE1394 ARP payload parsing - nvme-pci: fix missed admin queue sq doorbell write - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG - drm/amdgpu: fix spelling typos - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) - netfilter: xt_policy: fix strict mode inbound policy matching - netfilter: nf_conntrack_sip: don't use simple_strtoul - [amd64] ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ - drm/sysfb: ofdrm: fix PCI device reference leaks - arm64/scs: Fix potential sign extension issue of advance_loc4 - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() - netdevsim: zero initialize struct iphdr in dummy sk_buff - net/sched: netem: fix probability gaps in 4-state loss model - net/sched: netem: fix queue limit check to include reordered packets - net/sched: netem: only reseed PRNG when seed is explicitly provided - net/sched: netem: validate slot configuration - net/sched: netem: fix slot delay calculation overflow - net/sched: netem: check for negative latency and jitter - net/sched: sch_choke: annotate data-races in choke_dump_stats() - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() - vrf: Fix a potential NPD when removing a port from a VRF - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit - NFC: trf7970a: Ignore antenna noise when checking for RF field - net/sched: taprio: fix NULL pointer dereference in class dump - neigh: let neigh_xmit take skb ownership - tcp: make probe0 timer handle expired user timeout - net, treewide: define and use MAC_ADDR_STR_LEN - netconsole: allow selection of egress interface via MAC address - netpoll: Extract carrier wait function - netpoll: extract IPv4 address retrieval into helper function - netpoll: fix IPv6 local-address corruption - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams - sched/fair: Clear rel_deadline when initializing forked entities - net: mctp i2c: check length before marking flow active - net: phy: dp83869: fix setting CLK_O_SEL field. - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring - ASoC: codecs: ab8500: Fix casting of private data - netfilter: skip recording stale or retransmitted INIT - sctp: discard stale INIT after handshake completion - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) - netconsole: propagate device name truncation in dev_name_store() - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 - ALSA: hda/conexant: Fix missing error check for jack detection - ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup - drm/amd/display: Allow DCE link encoder without AUX registers - drm/amd/display: Read EDID from VBIOS embedded panel info - drm/xe/debugfs: Correct printing of register whitelist ranges - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() - page_pool: Set `dma_sync` to false for devmem memory provider - net: page_pool: create hooks for custom memory providers - page_pool: fix memory-provider leak in page_pool_create_percpu() error path - iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING - iavf: stop removing VLAN filters from PF on interface down - iavf: wait for PF confirmation before removing VLAN filters - iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler - ice: fix NULL pointer dereference in ice_reset_all_vfs() - net: tls: fix strparser anchor skb leak on offload RX setup failure - sfc: fix error code in efx_devlink_info_running_versions() - net/sched: cls_flower: revert unintended changes - [arm64] Reserve an extra page for early kernel mapping - smb: client: correctly handle ErrorContextData as a flexible array - smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) - LoongArch: KVM: Compile switch.S directly into the kernel - ntfs: ->d_compare() must not block - PCI: Initialize temporary device in new_id_store() - net: bcmgenet: Initialize u64 stats seq counter - net: bcmgenet: fix leaking free_bds - [amd64] iommu/amd: Reorder attach device code - [amd64] iommu/amd: Put list_add/del(dev_data) back under the domain->lock - perf tool_pmu: Fix aggregation on duration_time - net/sched: sch_pie: annotate more data-races in pie_dump_stats() - netpoll: Extract IPv6 address retrieval function - netpoll: pass buffer size to egress_dev() to avoid MAC truncation - page_pool: fix incorrect mp_ops error handling - crypto: af_alg - Cap AEAD AD length to 0x80000000 - i40e: Cleanup PTP pins on probe failure - workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path - netfilter: nf_conntrack_sip: get helper before allocating expectation - audit: fix incorrect inheritable capability in CAPSET records - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" - netfilter: nft_ct: fix missing expect put in obj eval - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() - [s390x] KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic - [amd64] KVM: x86: Fix Xen hypercall tracepoint argument assignment - netfilter: nf_tables: unconditionally bump set->nelems before insertion (CVE-2026-23272) - ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands - smb/client: fix possible infinite loop and oob read in symlink_data() - [amd64] drm/i915/dp: Fix VSC dynamic range signaling for RGB formats - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans - ALSA: usb-audio: Bound MIDI endpoint descriptor scans - ceph: fix a buffer leak in __ceph_setxattr() - ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size - io-wq: check that the predecessor is hashed in io_wq_remove_pending() - [powerpc*] warp: Fix error handling in pika_dtm_thread - netfs: fix error handling in netfs_extract_user_iter() - irqchip/riscv-imsic: Clear interrupt move state during CPU offlining - libceph: Fix potential out-of-bounds access in osdmap_decode() - libceph: Fix potential null-ptr-deref in decode_choose_args() - libceph: Fix potential out-of-bounds access in crush_decode() - libceph: handle rbtree insertion error in decode_choose_args() - [amd64] iommu/vt-d: Disable DMAR for Intel Q35 IGFX - [amd64] drm/i915: skip __i915_request_skip() for already signaled requests - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() - drm/xe/dma-buf: handle empty bo and UAF races - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup - drm/gma500/oaktrail_lvds: fix hang on init failure - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init - iommufd: Fix return value of iommufd_fault_fops_write() - eventfs: Use list_add_tail_rcu() for SRCU-protected children list - drm/v3d: Reject empty multisync extension to prevent infinite loop - btrfs: use inode already stored in local variable at btrfs_rmdir() - btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() - btrfs: fix missing last_unlink_trans update when removing a directory - smb: client: Use FullSessionKey for AES-256 encryption key derivation - btrfs: do not mark inode incompressible after inline attempt fails - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() - sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new - mptcp: pm: prio: skip closed subflows - mptcp: drop __mptcp_fastopen_gen_msk_ackseq() - mptcp: fix rx timestamp corruption on fastopen - f2fs: fix incorrect file address mapping when inline inode is unwritten - f2fs: fix false alarm of lockdep on cp_global_sem lock - spi: sifive: Simplify clock handling with devm_clk_get_enabled() - spi: sifive: fix controller deregistration - mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 - mptcp: pm: ADD_ADDR rtx: fix potential data-race - mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker - netfs: Fix potential uninitialised var in netfs_extract_user_iter() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.92 - mptcp: sync the msk->sndbuf at accept() time - mptcp: pm: ADD_ADDR rtx: allow ID 0 - mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (CVE-2026-46158) - mptcp: pm: ADD_ADDR rtx: free sk if last (CVE-2026-46170) - ksmbd: validate owner of durable handle on reconnect (CVE-2026-31717) - drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (CVE-2026-46216) - [s390x] debug: Reject zero-length input before trimming a newline - Revert "perf cgroup: Update metric leader in evlist__expand_cgroup" - Revert "perf tool_pmu: Fix aggregation on duration_time" - Revert "perf python: Add parse_events function" - Revert "perf tool_pmu: Factor tool events into their own PMU" - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420) - spi: spi-dw-dma: fix print error log when wait finish transaction (CVE-2026-31560) - Revert "x86/vdso: Fix output operand size of RDPID" - sched/deadline: Less agressive dl_server handling - sched/deadline: Fix dl_server_stopped() - sched/deadline: Fix dl_server getting stuck - sched/deadline: Fix dl_server behaviour - sched/deadline: Stop dl_server before CPU goes offline - ksmbd: close durable scavenger races against m_fp_list lookups - af_unix: Give up GC if MSG_PEEK intervened. (CVE-2026-23394) - drm/imagination: Synchronize interrupts before suspending the GPU (CVE-2026-23469) - ata: libata-scsi: improve readability of ata_scsi_qc_issue() - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS - perf parse-events: Expose/rename config_term_name - Revert "ice: fix double-free of tx_buf skb" - Revert "ice: Remove jumbo_remove step from TX path" - tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 - net/mlx5e: Trigger neighbor resolution for unresolved destinations - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init - [amd64] x86/fgraph: Fix return_to_handler regs.rsp value - [amd64] iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set - [riscv64] fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends on HAVE_DYNAMIC_FTRACE_WITH_ARGS - [riscv64] fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (CVE-2025-22069) - hwmon: (pmbus/core) Protect regulator operations with mutex - [arm64] Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL - sysfs: don't remove existing directory on update failure - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() - ksmbd: fix null pointer dereference in compare_guid_key() - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow - ksmbd: validate SID in parent security descriptor during ACL inheritance - smb: client: require net admin for CIFS SWN netlink - smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() - smb: client: use data_len for SMB2 READ encrypted folioq copy - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX - ALSA: ua101: Reject too-short USB descriptors - ALSA: pcm: Don't setup bogus iov_iter for silencing - ALSA: asihpi: Fix potential OOB array access at reading cache - efi: Allocate runtime workqueue before ACPI init - io_uring/waitid: clear waitid info before copying it to userspace - drivers/base/memory: fix memory block reference leak in poison accounting - ipv6: ioam: refresh hdr pointer before ioam6_event() - mm/memory_hotplug: fix memory block reference leak on remove - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START - Bluetooth: bnep: Fix UAF read of dev->name - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer - Bluetooth: MGMT: validate Add Extended Advertising Data length - Bluetooth: serialize accept_q access - phonet/pep: disable BH around forwarded sk_receive_skb() - net: bcmgenet: keep RBUF EEE/PM disabled - net: ifb: report ethtool stats over num_tx_queues - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() - netfilter: ip6t_hbh: reject oversized option lists - netfilter: nf_queue: hold bridge skb->dev while queued - netfilter: ipset: stop hash:* range iteration at end - netfilter: nft_inner: Fix IPv6 inner_thoff desync - sched_ext: Fix missing warning in scx_set_task_state() default case - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path - cgroup/cpuset: Reset DL migration state on can_attach() failure - fs/ntfs3: handle attr_set_size() errors when truncating files - l2tp: use list_del_rcu in l2tp_session_unhash - qed: fix double free in qed_cxt_tables_alloc() - ring-buffer: Fix reporting of missed events in iterator - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() - vsock/vmci: fix UAF when peer resets connection during handshake - vsock/virtio: reset connection on receiving queue overflow - wifi: ath11k: clear shared SRNG pointer state on restart - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 - ixgbevf: fix use-after-free in VEPA multicast source pruning - rbd: eliminate a race in lock_dwork draining on unmap - lsm: hold cred_guard_mutex for lsm_set_self_attr() - [arm64] octeontx2-af: CGX: add bounds check to cgx_speed_mbps index - ice: fix setting promisc mode while adding VID filter - ice: restore PTP Rx timestamp config after ethtool set-channels - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() - af_unix: Fix UAF read of tail->len in unix_stream_data_wait() - wifi: mac80211: consume only present negotiated TTLM maps - cifs: Fix busy dentry used after unmounting - tracing: Do not call map->ops->elt_free() if elt_alloc() fails - [arm64] probes: Handle probes on hinted conditional branch instructions - [arm64] KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits - [arm64] KVM: arm64: vgic: Free private_irqs when init fails after allocation - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe - spi: qup: fix error pointer deref after DMA setup failure - [arm64] phy: tegra: xusb: Fix per-pad high-speed termination calibration - scsi: isci: Fix use-after-free in device removal path - spi: ep93xx: fix error pointer deref after DMA setup failure - spi: sprd: fix error pointer deref after DMA setup failure - spi: ti-qspi: fix use-after-free after DMA setup failure - RDMA/siw: Reject MPA FPDU length underflow before signed receive math - device property: set fwnode->secondary to NULL in fwnode_init() - drm/virtio: use uninterruptible resv lock for plane updates - drm/amdgpu/vpe: Force collaborate sync after TRAP - drm/bridge: it66121: acquire reset GPIO in probe - drm/bridge: megachips: remove bridge when irq request fails - drm/amd/display: Fix integer overflow in bios_get_image() - drm/amd/display: Validate GPIO pin LUT table size before iterating - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async - batman-adv: mcast: fix use-after-free in orig_node RCU release - batman-adv: clear current gateway during teardown - batman-adv: dat: handle forward allocation error - batman-adv: fix fragment reassembly length accounting - batman-adv: fix tp_meter counter underflow during shutdown - batman-adv: frag: disallow unicast fragment in fragment - batman-adv: bla: fix report_work leak on backbone_gw purge - batman-adv: tp_meter: avoid use of uninit sender vars - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown - batman-adv: tp_meter: fix race condition in send error reporting - batman-adv: tt: fix negative last_changeset_len - batman-adv: tt: fix negative tt_buff_len - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock - hwmon: (pmbus/adm1266) reject implausible blackbox record_count - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors - [arm64] pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume - HID: uclogic: Fix regression of input name assignment - [riscv64] mm: Fixup no5lvl failure when vaddr is invalid - [arm64] pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 - ALSA: hda: cs35l56: Put ACPI device after setting companion - ALSA: hda: cs35l41: Put ACPI device on missing physical node - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() - netfilter: x_tables: unregister the templates first - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() - tcp: Fix imbalanced icsk_accept_queue count. - ice: fix setting RSS VSI hash for E830 - ice: fix locking in ice_dcb_rebuild() - net: lan966x: avoid unregistering netdev on register failure - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access - NFSD: Fix infinite loop in layout state revocation - irqchip/ath79-cpu: Remove unused function - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation - nsfs: fix wrong error code returned for pidns ioctls - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT - zonefs: handle integer overflow in zonefs_fname_to_fno - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). - [powerpc*] fix dead default for GUEST_STATE_BUFFER_TEST - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call - netfs: Fix overrun check in netfs_extract_user_iter() - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone - netfs: Defer the emission of trace_netfs_folio() - netfs: Fix streaming write being overwritten - netfs: Fix potential deadlock in write-through mode - netfs: Fix write streaming disablement if fd open O_RDWR - netfs: Fix early put of sink folio in netfs_read_gaps() - netfs: Fix partial invalidation of streaming-write folio - netfs: Fix a few minor bugs in netfs_page_mkwrite() - netfs: Remove unnecessary references to pages - netfs: Fix folio->private handling in netfs_perform_write() - net: ethernet: cortina: Make RX SKB per-port - net: ethernet: cortina: Drop half-assembled SKB - net: ethernet: cortina: Carry over frag counter - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference - wifi: ath11k: fix error path leaks in some WMI WOW calls - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() - wifi: ath10k: skip WMI and beacon transmission when device is wedged - blk-integrity: remove seed for user mapped buffers - block: don't overwrite bip_vcnt in bio_integrity_copy_user() - block: recompute nr_integrity_segments in blk_insert_cloned_request - HID: quirks: really enable the intended work around for appledisplay - block: modify bio_integrity_map_user to accept iov_iter as argument - block: drop direction param from bio_integrity_copy_user() - blk-integrity: use simpler alignment check - blk-integrity: enable p2p source and destination - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() - accel/qaic: Add overflow check to remap_pfn_range during mmap - net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics - [arm64] drm/msm/dsi: don't dump registers past the mapped region - [arm64] drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN - [powerpc*] time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring - net: tls: prevent chain-after-chain in plain text SG - net: phy: DP83TC811: add reading of abilities - [amd64] x86/xen: Fix xen_e820_swap_entry_with_ram() - tls: Preserve sk_err across recvmsg() when data has been copied - net/mlx5: Do not restore destination-less TC rules - scsi: sd: Fix return code handling in sd_spinup_disk() - ALSA: scarlett2: Add missing error check when initialise Autogain Status - io_uring/net: punt IORING_OP_BIND async if it needs file create - btrfs: fix squota accounting during enable generation - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() - [arm64] drm/msm/snapshot: fix dumping of the unaligned regions - drm/xe/gsc: Fix double-free of managed BO in error path - drm/xe/vf: Fix signature of print functions - drm/xe/pf: Fix CFI failure in debugfs access - wifi: ath11k: fix peer resolution on rx path when peer_id=0 - ice: ptp: serialize E825 PHY timer start with PTP lock - [amd64] drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP - [arm64] net: dsa: mt7530: fix FDB entries not aging out with short timeout - [arm64] net: dsa: mt7530: preserve VLAN tags on trapped link-local frames - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 - [amd64] platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: hp_accel: Check ACPI_COMPANION() against NULL - [amd64] platform/x86: intel-hid: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL - RDMA/rtrs: Fix use-after-free in path file creation cleanup - net: bridge: Flush multicast groups when snooping is disabled - bridge: mcast: Fix a possible use-after-free when removing a bridge port - pds_core: fix error handling in pdsc_devcmd_wait - pds_core: fix debugfs_lookup dentry leak and error handling - wifi: mac80211: fix MLE defragmentation - ALSA: seq: Serialize UMP output teardown with event_input - tracing: Avoid NULL return from hist_field_name() on truncation - Bluetooth: btmtk: fix urb->setup_packet leak in error paths - net: ag71xx: check error for platform_get_irq - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() - drm/xe/oa: Fix exec_queue leak on width check in stream open - [arm64] octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs - net: mana: validate rx_req_idx to prevent out-of-bounds array access - pds_core: ensure null-termination for firmware version strings - net: gro: don't merge zcopy skbs - landlock: Fix TCP handling of short AF_UNSPEC addresses - block: make bio_integrity_map_user() static inline - security/keys: fix missed RCU read section on lookup https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.93 - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size - [arm64] drm/v3d: Fix use-after-free of CPU job query arrays on error path - [arm64] drm/v3d: Release indirect CSD GEM reference on CPU job free - net/sched: cls_fw: fix NULL dereference of "old" filters before change() - net: mctp: ensure our nlmsg responses are initialised (CVE-2026-45930) - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit - net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked - bcache: fix uninitialized closure object - net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (CVE-2026-43219) - [arm64] Introduce esr_is_ubsan_brk() - [arm64] debug: clean up single_step_handler logic - [arm64] refactor aarch32_break_handler() - [arm64] debug: call software breakpoint handlers statically - [arm64] debug: call step handlers statically - [arm64] debug: remove break/step handler registration infrastructure - [arm64] entry: Add entry and exit functions for debug exceptions - [arm64] debug: split hardware breakpoint exception entry - [arm64] debug: refactor reinstall_suspended_bps() - [arm64] debug: split single stepping exception entry - [arm64] debug: split hardware watchpoint exception entry - [arm64] debug: split brk64 exception entry - [arm64] debug: split bkpt32 exception entry - [arm64] debug: remove debug exception registration infrastructure - [arm64] debug: always unmask interrupts in el0_softstp() - nfc: llcp: Fix use-after-free in llcp_sock_release() - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() - xfrm: Check for underflow in xfrm_state_mtu - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems - netfilter: synproxy: refresh tcphdr after skb_ensure_writable - netfilter: xt_cpu: prefer raw_smp_processor_id - netfilter: ebtables: fix OOB read in compat_mtw_from_user - tun: free page on short-frame rejection in tun_xdp_one() (CVE-2026-46321) - tun: free page on build_skb failure in tun_xdp_one() (CVE-2026-46322) - vsock: keep poll shutdown state consistent - net: netlink: fix sending unassigned nsid after assigned one - net: netlink: don't set nsid on local notifications - net/smc: Do not re-initialize smc hashtables - [s390x] net/iucv: fix locking in .getsockopt - scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues - ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() - ALSA: pcm: oss: Fix setup list UAF on proc write error - [amd64] ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors - net: hsr: fix potential OOB access in supervision frame handling - [amd64] accel/ivpu: prevent uninitialized data bug in debugfs - gpio: mxc: fix irq_high handling - net: Avoid checksumming unreadable skb tail on trim - ethtool: rss: fix hkey leak when indir_size is 0 - ethtool: module: avoid leaking a netdev ref on module flash errors - ethtool: module: check fw_flash_in_progress under rtnl_lock - ethtool: module: fix cleanup if socket used for flashing multiple devices - ethtool: cmis: require exact CDB reply length - ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl - net: ethtool: Add new parameters and a function to support EPL - net: ethtool: Add support for writing firmware blocks using EPL payload - ethtool: cmis: validate start_cmd_payload_size from module - ethtool: cmis: validate fw->size against start_cmd_payload_size - tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() - ASoC: codecs: simple-mux: Fix enum control bounds check - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() - bonding: refuse to enslave CAN devices - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES - ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error - ethtool: pse-pd: fix missing ethnl_ops_complete() - ethtool: strset: fix header attribute index in ethnl_req_get_phydev() - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback - ethtool: eeprom: add more safeties to EEPROM Netlink fallback - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() - net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" - net/sched: fix packet loop on netem when duplicate is on - net/sched: act_mirred: Move the recursion counter struct netdev_xmit - net/sched: act_mirred: add loop detection - net: Introduce skb tc depth field to track packet loops - net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop - net/sched: act_mirred: Fix return code in early mirred redirect error paths - net/handshake: Use spin_lock_bh for hn_lock - nvme-tcp: store negative errno in queue->tls_err - net/handshake: Pass negative errno through handshake_complete() - remove pointless includes of - net/handshake: Take a long-lived file reference at submit - net/handshake: Drain pending requests at net namespace exit - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close - [arm64,armhf] gpio: rockchip: convert bank->clk to devm_clk_get_enabled() - [amd64,arm64] net: mana: Add NULL guards in teardown path to prevent panic on attach failure - sctp: fix race between sctp_wait_for_connect and peeloff - ipv6: fix possible infinite loop in rt6_fill_node() - ipv6: fix possible infinite loop in fib6_select_path() - net: skbuff: fix pskb_carve leaking zcopy pages - perf: Fix dangling cgroup pointer in cpuctx - batman-adv: v: stop OGMv2 on disabled interface - batman-adv: tvlv: abort OGM send on tvlv append failure - batman-adv: tt: reject oversized local TVLV buffers - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface - batman-adv: tvlv: reject oversized TVLV packets - batman-adv: iv: recover OGM scheduling after forward packet error - batman-adv: tp_meter: avoid role confusion in tp_list - [s390x] cio: Restore GFP_DMA for CHSC allocation - batman-adv: tp_meter: directly shut down timer on cleanup - batman-adv: tt: fix TOCTOU race for reported vlans - batman-adv: tt: avoid empty VLAN responses - batman-adv: bla: avoid double decrement of bla.num_requests - mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303) - media: rc: fix race between unregister and urb/irq callbacks - media: rc: ttusbir: fix inverted error logic - inet: frags: add inet_frag_queue_flush() - inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) - HID: core: Add printk_ratelimited variants to hid_warn() etc - HID: pass the buffer size to hid_report_raw_event - HID: core: introduce hid_safe_input_report() - HID: core: Fix size_t specifier in hid_report_raw_event() - [amd64] drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register - [amd64] drm/i915/psr: Read Intel DPCD workaround register - drm/dp: Add eDP 1.5 bit definition - [amd64] drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used - [arm64] io: Rename ioremap_prot() to __ioremap_prot() - [arm64] io: Extract user memory type in ioremap_prot() (CVE-2026-23346) - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X - batman-adv: tt: prevent TVLV entry number overflow - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer - usb: typec: ucsi: ccg: reject firmware images without a ':' record header - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers - usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO - usb: typec: altmodes/displayport: validate count before reading Status Update VDO - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT - usb: typec: ucsi: validate connector number in ucsi_connector_change() - USB: serial: safe_serial: fix memory corruption with small endpoint - media: rc: igorplugusb: fix control request setup packet - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse - Bluetooth: btusb: Allow firmware re-download when version matches - hpfs: fix a crash if hpfs_map_dnode_bitmap fails - ipc: limit next_id allocation to the valid ID range - auxdisplay: line-display: fix OOB read on zero-length message_store() - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn - Bluetooth: HIDP: fix missing length checks in hidp_input_report() - Bluetooth: ISO: fix UAF in iso_recv_frame - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync - Input: xpad - fix out-of-bounds access for Share button - parport: Fix race between port and client registration (Closes: #1130365) - USB: cdc-acm: Fix bit overlap and move quirk definitions to header - [arm64] KVM: arm64: PMU: Preserve AArch32 counter low bits - [amd64] KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC - [amd64] KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use - [amd64] KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests - [amd64] KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 - [amd64] KVM: SEV: Compute the correct max length of the in-GHCB scratch area - [amd64] KVM: SEV: Check PSC request indices against the actual size of the buffer - [amd64] KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer - [amd64] KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux - iio: adc: npcm: fix unbalanced clk_disable_unprepare() - iio: dac: max5821: fix return value check in powerdown sync - iio: dac: ad5686: fix input raw value check - iio: dac: ad5686: acquire lock when doing powerdown control - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw - iio: gyro: itg3200: fix i2c read into the wrong stack location - iio: gyro: adis16260: fix division by zero in write_raw - iio: ssp_sensors: cancel delayed work_refresh on remove - iio: temperature: tsys01: fix broken PROM checksum validation - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL - iio: light: cm3323: fix reg_conf not being initialized correctly - iio: buffer: hw-consumer: fix use-after-free in error path - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() - USB: serial: omninet: fix memory corruption with small endpoint - usb: cdns3: gadget: fix request skipping after clearing halt - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles - usb: dwc2: Fix use after free in debug code - Input: elan_i2c - validate firmware size before use - wireguard: send: append trailer after expanding head - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data - macsec: fix replay protection at XPN lower-PN wrap - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() - [arm64] ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params - ipv6: exthdrs: refresh nh after handling HAO option - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). - ipv6: validate extension header length before copying to cmsg - xfrm: input: hold netns during deferred transport reinjection - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname - ip6: vti: Use ip6_tnl.net in vti6_changelink(). - net: skbuff: fix missing zerocopy reference in pskb_carve helpers - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() - nfc: hci: fix out-of-bounds read in HCP header parsing - xfrm: route MIGRATE notifications to caller's netns - xfrm: ah: use skb_to_full_sk in async output callbacks - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - [arm64] ASoC: qcom: q6asm-dai: close stream only when running - [arm64] ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks - xfrm: esp: restore combined single-frag length gate - Input: xpad - add "Nova 2 Lite" from GameSir - Input: xpad - add support for ASUS ROG RAIKIRI II - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 - [amd64] comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() - [amd64] comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() - counter: Fix refcount leak in counter_alloc() error path - tty: serial: pch_uart: add check for dma_alloc_coherent() - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers - usb: chipidea: core: convert ci_role_switch to local variable - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers - usb: storage: Add quirks for PNY Elite Portable SSD - usbip: vudc: Fix use after free bug in vudc_remove due to race condition - usb: usbtmc: check URB actual_length for interrupt-IN notifications - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize - usb: typec: tcpm: improve handling of DISCOVER_MODES failures - USB: serial: option: add MeiG SRM813Q - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL - USB: serial: belkin_sa: validate interrupt status length - USB: serial: cypress_m8: validate interrupt packet headers - USB: serial: keyspan: fix missing indat transfer sanity check - USB: serial: mxuport: fix memory corruption with small endpoint - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind - usb: gadget: net2280: Fix double free in probe error path - usb: gadget: f_hid: fix device reference leak in hidg_alloc() - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports - usb: gadget: f_fs: copy only received bytes on short ep0 read - usb: gadget: f_fs: serialize DMABUF cancel against request completion - [amd64] thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() - [amd64] thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf - scsi: target: iscsi: Validate CHAP_R length before base64 decode - drm/hyperv: validate resolution_count and fix WIN8 fallback - drm/hyperv: validate VMBus packet size in receive callback - [amd64] drm/i915: Fix potential UAF in TTM object purge - drm/amd/pm/si: Disregard vblank time when no displays are connected - serial: altera_jtaguart: handle uart_add_one_port() failures - serial: qcom-geni: fix UART_RX_PAR_EN bit position - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ - serial: sh-sci: fix memory region release in error path - serial: zs: Fix swapped RI/DSR modem line transition counting - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger - drm/amdkfd: Check for pdd drm file first in CRIU restore path - serial: dz: Fix bootconsole message clobbering at chip reset - serial: dz: Fix bootconsole handover lockup - serial: dz: Convert to use a platform device - serial: zs: Fix bootconsole handover lockup - serial: zs: Switch to using channel reset - serial: zs: Convert to use a platform device - USB: serial: cypress_m8: fix memory corruption with small endpoint - USB: serial: digi_acceleport: fix memory corruption with small endpoints - xhci: tegra: Fix ghost USB device on dual-role port unplug - iommu: Skip PASID validation for devices without PASID capability - [amd64] x86/boot: Disable stack protector for early boot code - [amd64] x86/kexec: Disable KCOV instrumentation after load_segments() (CVE-2026-43331) - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer - serdev: Provide a bustype shutdown function - Bluetooth: hci_qca: Migrate to serdev specific shutdown function - Bluetooth: hci_qca: Convert timeout from jiffies to ms - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes - ALSA: scarlett2: Allow flash writes ending at segment boundary - mm/memory: fix spurious warning when unmapping device-private/exclusive pages - [amd64] platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery - net: hsr: defer node table free until after RCU readers - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient - ice: fix VF queue configuration with low MTU values - ring-buffer: Flush and stop persistent ring buffer on panic - mptcp: cleanup fallback dummy mapping generation - mptcp: reset rcv wnd on disconnect - [arm64] tlb: Flush walk cache when unsharing PMD tables - [arm64] octeontx2-pf: avoid double free of pool->stack on AQ init failure - mptcp: introduce the mptcp_init_skb helper - mptcp: handle first subflow closing consistently - mptcp: do not drop partial packets - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() - iio: chemical: scd30: Use guard(mutex) to allow early returns - iio: chemical: scd30: fix division by zero in write_raw - iio: dac: ad5686: fix ref bit initialization for single-channel parts - ALSA: firewire-motu: Protect register DSP event queue positions - [arm64] usb: dwc3: xilinx: fix error handling in zynqmp init error paths - usb: musb: omap2430: Fix use-after-free in omap2430_probe() - usb: typec: ucsi: Check if power role change actually happened before handling - [amd64] thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() - usb: typec: ucsi: Don't update power_supply on power role change if not connected - [amd64] x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' - [amd64] x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock - hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock - mm: perform all memfd seal checks in a single place - mm/memfd: fix spelling and grammatical issues - memfd: deny writeable mappings when implying SEAL_WRITE - usb: core: Fix SuperSpeed root hub wMaxPacketSize - ethtool: cmis_cdb: Fix incorrect read / write length extension - net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow - [arm64] KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.94 - bpf: Free reuseport cBPF prog after RCU grace period. (CVE-2026-52910) - USB: serial: mct_u232: fix memory corruption with small endpoint - [armhf] group is_permission_fault() with is_translation_fault() - [armhf] allow __do_kernel_fault() to report execution of memory faults - [armhf] fix hash_name() fault - [armhf] fix branch predictor hardening - net: phy: micrel: fix LAN8814 QSGMII soft reset - wifi: remove zero-length arrays - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl - ipv6: mcast: Fix use-after-free when processing MLD queries - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS - [arm64] tee: optee: prevent use-after-free when the client exits before the supplicant - [arm64]soc: qcom: ice: Return -ENODEV if the ICE platform device is not found - erofs: add sysfs node to drop internal caches - erofs: tidy up synchronous decompression - erofs: fix use-after-free on sbi->sync_decompress - ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id - ipvs: clear the svc scheduler ptr early on edit - netfilter: synproxy: add mutex to guard hook reference counting - netfilter: conntrack_irc: fix possible out-of-bounds read - netfilter: nft_ct: bail out on template ct in get eval - netfilter: bridge: make ebt_snat ARP rewrite writable - dm cache policy smq: check allocation under invalidate lock - net/sched: act_api: use RCU with deferred freeing for action lifecycle - 6lowpan: fix off-by-one in multicast context address compression - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() - devlink: Release nested relation on devlink free - [arm64] drm/imx: Fix three kernel-doc warnings in dcss-scaler.c - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap - pcnet32: stop holding device spin lock during napi_complete_done - net: Annotate sk->sk_write_space() for UDP SOCKMAP. - hsr: Remove WARN_ONCE() in hsr_addr_is_self(). - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr - net: lan743x: permit VLAN-tagged packets up to configured MTU - net: fec: fix pinctrl default state restore order on resume - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() - Bluetooth: MGMT: validate advertising TLV before type checks - Bluetooth: RFCOMM: validate skb length in MCC handlers - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling - Bluetooth: bnep: reject short frames before parsing - Bluetooth: fix memory leak in error path of hci_alloc_dev() - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync - Bluetooth: ISO: Fix not using bc_sid as advertisement SID - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls - Bluetooth: MGMT: Fix backward compatibility with userspace - [arm64] octeontx2-pf: Fix NDC sync operation errors - [arm64] octeontx2-af: Fix initialization of mcam's entry2target_pffunc field - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options - ptp: vclock: Switch from RCU to SRCU - net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown - net_sched: act_pedit: use RCU in tcf_pedit_dump() - net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) - [arm64] octeontx2-af: npc: Fix CPT channel mask in npc_install_flow - vxlan: vnifilter: send notification on VNI add - vxlan: vnifilter: fix spurious notification on VNI update - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr - sctp: purge outqueue on stale COOKIE-ECHO handling - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() - time: Fix off-by-one in settimeofday() usec validation - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams - ALSA: seq: dummy: fix UMP event stack overread - ima: kexec: skip IMA segment validation after kexec soft reboot - ima: kexec: move IMA log copy from kexec load to execute - spi: cadence-quadspi: fix unclocked access on unbind (CVE-2026-46203) - tools/rv: Fix cleanup after failed trace setup - tap: free page on error paths in tap_get_user_xdp() (CVE-2026-46320) - [arm64] tlb: Allow XZR argument to TLBI ops - [arm64] tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI - iomap: don't revert iov_iter on partially completed buffered writes - dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() - netlabel: validate unlabeled address and mask attribute lengths - gpio: mvebu: fix NULL pointer dereference in suspend/resume - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls - tcp: restrict SO_ATTACH_FILTER to priv users - net: add pskb_may_pull() to skb_gro_receive_list() - net/mlx4: avoid GCC 10 __bad_copy_from() false positive - net: ibm: emac: Fix use-after-free during device removal - netdev: fix double-free in netdev_nl_bind_rx_doit() - net: phy: clean the sfp upstream if phy probing fails - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure - net/mlx5: Use effective affinity mask for IRQ selection - ipv6: sit: reload inner IPv6 header after GSO offloads - net: openvswitch: fix possible kfree_skb of ERR_PTR - r8152: handle the return value of usb_reset_device() - gpio: zynq: fix runtime PM leak on remove - sctp: fix uninit-value in __sctp_rcv_asconf_lookup() - net: guard timestamp cmsgs to real error queue skbs - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() - rds: mark snapshot pages dirty in rds_info_getsockopt() - netfilter: revalidate bridge ports - netfilter: nf_conntrack: destroy stale expectfn expectations on unregister - netfilter: x_tables: avoid leaking percpu counter pointers - netfilter: nf_log: validate MAC header was set before dumping it - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag - [arm64,armhf] net: mvpp2: sync RX data at the hardware packet offset - [arm64,armhf] net: mvpp2: limit XDP frame size to the RX buffer - [arm64,armhf] net: mvpp2: Add metadata support for xdp mode - [arm64,armhf] net: mvpp2: refill RX buffers before XDP or skb use - [arm64,armhf] net: mvpp2: build skb from XDP-adjusted data on XDP_PASS - ipv6: Fix a potential NPD in cleanup_prefix_route() - netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) - writeback: Avoid contention on wb->list_lock when switching inodes - writeback: Fix use after free in inode_switch_wbs_work_fn() - xfrm: hold device only for the asynchronous decryption - xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663) - [amd64] KVM: VMX: Update SVI during runtime APICv activation - [arm64] clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked - clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs - [arm64] clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time - drm/virtio: Fix driver removal with disabled KMS - [arm64,armhf] drm/vc4: fix krealloc() memory leak - drm/xe: fix refcount leak in xe_range_fence_insert() - netfilter: nft_tunnel: fix use-after-free on object destroy - [arm64] tee: shm: fix shm leak in register_shm_helper() - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig - [arm64] soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() - [amd64] accel/ivpu: Add bounds checks for firmware log indices - [amd64] accel/ivpu: Add buffer overflow check in MS get_info_ioctl - [amd64] accel/ivpu: Fix signed integer truncation in IPC receive - tracing/probes: Point the error offset correctly for eprobe argument error - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying - [amd64] KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA - [amd64] drm/i915/gem: Fix phys BO pread/pwrite with offset - pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL - xfrm: espintcp: do not reuse an in-progress partial send - USB: serial: io_ti: fix heap overflow in get_manuf_info() - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() - USB: serial: option: add usb-id for Dell Wireless DW5826e-m - USB: serial: kl5kusb105: fix bulk-out buffer overflow - ALSA: timer: Forcibly close timer instances at closing - ALSA: timer: Fix UAF at snd_timer_user_params() - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() - mm/huge_memory: update file PMD counter before folio_put() - mm/damon/ops-common: call folio_test_lru() after folio_get() - RDMA/srp: bound SRP_RSP sense copy by the received length - zram: fix use-after-free in zram_bvec_write_partial() - udp: clear skb->dev before running a sockmap verdict - mptcp: fix retransmission loop when csum is enabled - mptcp: close TOCTOU race while computing rcv_wnd - mptcp: allow subflow rcv wnd to shrink - mptcp: sockopt: check timestamping ret value - mptcp: add-addr: always drop other suboptions - wifi: nl80211: reject oversized EMA RNR lists - vsock/vmci: fix sk_ack_backlog leak on failed handshake - timers/migration: Fix livelock in tmigr_handle_remote_up() - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write - bnxt_en: Fix NULL pointer dereference - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush - pidfd: refuse access to tasks that have started exiting harder - fs/qnx6: fix pointer arithmetic in directory iteration - fuse: reject fuse_notify() pagecache ops on directories - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter - i2c: tegra: Fix NOIRQ suspend/resume - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard - ipc/shm: serialize orphan cleanup with shm_nattch updates - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context - misc: fastrpc: fix use-after-free race in fastrpc_map_create - misc: fastrpc: fix DMA address corruption due to find_vma misuse - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback - net/mlx5: Reorder completion before putting command entry in cmd_work_handler - net: bonding: fix NULL pointer dereference in bond_do_ioctl() - net: mv643xx: fix OF node refcount - net: rds: clear i_sends on setup unwind - nvmem: core: fix use-after-free bugs in error paths - nvmem: layouts: onie-tlv: fix hang on unknown types - [arm64] octeontx2-af: fix memory leak in rvu_setup_hw_resources() - io_uring/kbuf: don't truncate end buffer for bundles - io_uring/wait: fix min_timeout behavior - mm/hugetlb: restore reservation on error in hugetlb folio copy paths - mmc: core: Fix host controller programming for fixed driver type - mmc: dw_mmc-rockchip: Add missing private data for very old controllers - mmc: litex_mmc: Set mandatory idle clocks before CMD0 - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC - mmc: sdhci: add signal voltage switch in sdhci_resume_host - pmdomain: imx: fix OF node refcount - rtase: Avoid sleeping in get_stats64() - rtase: Reset TX subqueue when clearing TX ring - sctp: diag: reject stale associations in dump_one path - sctp: stream: fully roll back denied add-stream state - [amd64] thunderbolt: Reject zero-length property entries in validator - [amd64] thunderbolt: Bound root directory content to block size - [amd64] thunderbolt: Clamp XDomain response data copy to allocation size - [amd64] thunderbolt: Validate XDomain request packet size before type cast - [amd64] thunderbolt: Limit XDomain response copy to actual frame size - [arm64] slimbus: qcom-ngd-ctrl: fix OF node refcount - [arm64] slimbus: qcom-ngd-ctrl: Fix up platform_driver registration - [arm64] slimbus: qcom-ngd-ctrl: Fix probe error path ordering - [arm64] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd - [arm64] slimbus: qcom-ngd-ctrl: Initialize controller resources in controller - [arm64] slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership - [arm64] slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD - [arm64] slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock - drm/amdkfd: fix NULL dereference in get_queue_ids() - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 - drm/xe: Clear pending_disable before signaling suspend fence - [arm64,armhf] drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups - drm/amdgpu: restart the CS if some parts of the VM are still invalidated - drm/amd/pm: fix smu13 power limit default/cap calculation - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range - drm/amd/display: Bound VBIOS record-chain walk loops - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs - drm/amd/display: Use krealloc_array() in dal_vector_reserve() - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling - driver core: reject devices with unregistered buses - mailbox: Fix NULL message support in mbox_send_message() - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf - sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() - netfilter: nft_fib: fix stale stack leak via the OIFNAME register - mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper - RDMA/umem: Move umem dmabuf revoke logic into helper function - RDMA/umem: Add helpers for umem dmabuf revoke lock - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible - RDMA/umem: fix kernel-doc warnings - RDMA: Move DMA block iterator logic into dedicated files - RDMA/umem: Fix truncation for block sizes >= 4G - mm/hugetlb: avoid false positive lockdep assertion - mptcp: fix missing wakeups in edge scenarios - ipmi:ssif: Remove unnecessary indention - ipmi:ssif: NULL thread on error - ipvs: skip ipv6 extension headers for csum checks (CVE-2026-45850) - vsock/virtio: fix potential unbounded skb queue - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc - block: fix handling of dead zone write plugs - [arm64] cputype: Add NVIDIA Olympus definitions - [arm64] cputype: Add C1-Ultra definitions - [arm64] cputype: Add C1-Premium definitions - [arm64] errata: Mitigate TLBI errata on various Arm CPUs - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU - net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() - tcp: use EXPORT_IPV6_MOD[_GPL]() - tcp: secure_seq: add back ports to TS offset (CVE-2026-23247) - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation - vsock/virtio: fix skb overhead overflow on 32-bit builds - netfilter: require Ethernet MAC header before using eth_hdr() . [ Salvatore Bonaccorso ] * [rt] Refresh "ARM: enable irq in translation/section permission fault" * ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909) linux (6.12.94-1~bpo12+1) bookworm-backports; urgency=medium . * Rebuild for bookworm-backports . linux (6.12.94-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.91 - io_uring/kbuf: use mem_is_zero() - blk-cgroup: wait for blkcg cleanup before initializing new disk - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START - fs/mbcache: cancel shrink work before destroying the cache - md/raid1: fix the comparing region of interval tree - drbd: Balance RCU calls in drbd_adm_dump_devices() - loop: fix partition scan race between udev and loop_reread_partitions() - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() - blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() - pstore/ram: fix resource leak when ioremap() fails - md: wake raid456 reshape waiters before suspend - btrfs: pass struct btrfs_inode to clone_copy_inline_extent() - btrfs: fix deadlock between reflink and transaction commit when using flushoncommit - [amd64] ACPI: x86: cmos_rtc: Clean up address space handler driver - [amd64] ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver - devres: fix missing node debug info in devm_krealloc() - thermal/drivers/spear: Fix error condition for reading st,thermal-flags - debugfs: check for NULL pointer in debugfs_create_str() - debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() - soundwire: debugfs: initialize firmware_file to empty string - PCI: use generic driver_override infrastructure - platform/wmi: use generic driver_override infrastructure - [s390x] cio: use generic driver_override infrastructure - bus: fsl-mc: use generic driver_override infrastructure - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter - hrtimers: Update the return type of enqueue_hrtimer() - hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() - hrtimer: Reduce trace noise in hrtimer_start() - locking: Fix rwlock support in - firmware: dmi: Correct an indexing error in dmi.h - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet - bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n - [s390x] bpf: Zero-extend bpf prog return values and kfunc arguments - params: Replace __modinit with __init_or_module - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() - wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control - wifi: mt76: mt7615: fix use_cts_prot support - wifi: mt76: mt7915: fix use_cts_prot support - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() - wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor - wifi: mt76: mt7921: Place upper limit on station AID - [arm64] cpufeature: Make PMUVer and PerfMon unsigned - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() - wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() - wifi: mt76: mt7921: fix 6GHz regulatory update on connection - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path - bpf: Fix variable length stack write over spilled pointers - bpf,arc_jit: Fix missing newline in pr_err messages - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() - r8152: fix incorrect register write to USB_UPHY_XTAL - [powerpc*] crash: fix backup region offset update to elfcorehdr - [powerpc*] crash: Update backup region offset in elfcorehdr on memory hotplug - macvlan: annotate data-races around port->bc_queue_len_used - bpf: fix end-of-list detection in cgroup_storage_get_next_key() - bpf: Fix stale offload->prog pointer after constant blinding - wifi: brcmfmac: Fix error pointer dereference - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() - wifi: ath10k: fix station lookup failure during disconnect - ACPI: AGDI: fix missing newline in error message - [arm64] kexec: Remove duplicate allocation for trans_pgd - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb - net: bcmgenet: add bcmgenet_has_* helpers - net: bcmgenet: move DESC_INDEX flow to ring 0 - net: bcmgenet: support reclaiming unsent Tx packets - net: bcmgenet: switch to use 64bit statistics - net: bcmgenet: fix racing timeout handler - eth: fbnic: Use wake instead of start - netfilter: xt_socket: enable defrag after all other checks - netfilter: nft_fwd_netdev: check ttl/hl before forwarding - bpf: fix mm lifecycle in open-coded task_vma iterator - bpf: switch task_vma iterator from mmap_lock to per-VMA locks - bpf: return VMA snapshot from task_vma iterator - bpf: Fix RCU stall in bpf_fd_array_map_clear() - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf - bpf: Relax scalar id equivalence for state pruning - bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars - net/sched: act_ct: Only release RCU read lock after ct_ft - net: airoha: Implement BQL support - net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() - bpf: Allow instructions with arena source and non-arena dest registers - net/rds: Optimize rds_ib_laddr_check - net/rds: Restrict use of RDS/IB to the initial network namespace - bpf: Fix OOB in pcpu_init_value - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls - net: ipa: Fix programming of QTIME_TIMESTAMP_CFG - net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ - dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 - net: phy: fix a return path in get_phy_c45_ids() - net/mlx5e: Fix features not applied during netdev registration - net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp - Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec - net: phy: qcom: at803x: Use the correct bit to disable extended next page - ipv4: udp: fix typos in comments - ipv6: udp: fix typos in comments - udp: Force compute_score to always inline - tcp: Don't set treq->req_usec_ts in cookie_tcp_reqsk_init(). - sctp: fix missing encap_port propagation for GSO fragments - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master - drm/komeda: fix integer overflow in AFBC framebuffer size check - ASoC: SOF: ipc3: Use standard dev_dbg API - ASoC: add symmetric_ prefix for dai->rate/channels/sample_bits - ASoC: soc-compress: use function to clear symmetric params - drm/sun4i: backend: fix error pointer dereference - ASoC: sti: Return errors from regmap_field_alloc() - ASoC: sti: use managed regmap_field allocations - dm cache: fix null-deref with concurrent writes in passthrough mode - dm cache: fix write path cache coherency in passthrough mode - dm cache: fix write hang in passthrough mode - dm cache policy smq: fix missing locks in invalidating cache blocks - dm cache: fix concurrent write failure in passthrough mode - dm cache: support shrinking the origin device - dm cache: fix dirty mapping checking in passthrough mode switching - platform/chrome: chromeos_tbmc: Drop wakeup source on remove - PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding - PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() - dm cache metadata: fix memory leak on metadata abort retry - dm log: fix out-of-bounds write due to region_count overflow - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check - spi: spi-nxp-fspi: enable runtime pm for fspi - spi: nxp-fspi: Use reinit_completion() for repeated operations - spi: fsl-qspi: Use reinit_completion() for repeated operations - media: i2c: og01a1b: Replace client->dev usage - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe - drm/v3d: Handle error from drm_sched_entity_init() - drm/sun4i: Fix resource leaks - drm/amdgpu: Add default case in DVI mode validation - dm init: ensure device probing has finished in dm-mod.waitfor= - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break - crypto: tegra - finalize crypto req on error - crypto: tegra - Transfer HASH init function to crypto engine - crypto: tegra - Reserve keyslots to allocate dynamically - crypto: tegra - Disable softirqs before finalizing request - crypto: atmel - Use unregister_{aeads,ahashes,skciphers} - crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs - padata: Remove cpu online check from cpu add and removal - padata: Put CPU offline callback in ONLINE section to allow failure - PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation - drm/amdgpu/gfx10: look at the right prop for gfx queue priority - drm/amdgpu/gfx11: look at the right prop for gfx queue priority - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo - drm/imagination: Switch reset_reason fields from enum to u32 - iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() - [arm64] drm/msm/dpu: fix mismatch between power and frequency - [arm64] drm/msm/dsi: add the missing parameter description - [arm64] drm/msm/dsi: fix bits_per_pclk - [arm64] drm/msm/dsi: fix hdisplay calculation for CMD mode panel - [arm64] drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first - drm/panel: simple: Correct G190EAN01 prepare timing - PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support - ALSA: core: Validate compress device numbers without dynamic minors - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels - drm/amd/pm/ci: Fill DW8 fields from SMC - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board - drm/amdgpu: add amdgpu_device reference in ip block - drm/amdgpu: update the handle ptr in dump_ip_state - drm/amdgpu: update the handle ptr in early_init - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled - hwmon: Switch back to struct platform_driver::remove() - hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') - [amd64] ASoC: SOF: Intel: hda: Place check before dereference - [arm64] drm/msm/a6xx: Fix HLSQ register dumping - [arm64] drm/msm/shrinker: Fix can_block() logic - [arm64] drm/msm/a6xx: Fix dumping A650+ debugbus blocks - [arm64] drm/msm/a6xx: Use barriers while updating HFI Q headers - pmdomain: ti: omap_prm: Fix a reference leak on device node - pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() - PM: domains: De-constify fields in struct dev_pm_domain_attach_data - ASoC: fsl_micfil: Add access property for "VAD Detected" - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() - ASoC: fsl_easrc: Change the type for iec958 channel status controls - [amd64] iommu/amd: Remove protection_domain.dev_cnt variable - [amd64] iommu/amd: xarray to track protection_domain->iommu list - [amd64] iommu/amd: Do not detach devices in domain free path - [amd64] iommu/amd: Reduce domain lock scope in attach device path - [amd64] iommu/amd: Rearrange attach device code - [amd64] iommu/amd: Convert dev_data lock from spinlock to mutex - [amd64] iommu/amd: Introduce helper function to update 256-bit DTE - [amd64] iommu/amd: Introduce helper function get_dte256() - [amd64] iommu/amd: Fix clone_alias() to use the original device's devid - [arm64] ASoC: qcom: qdsp6: topology: check widget type before accessing data - crypto: qat - introduce fuse array - crypto: qat - disable 4xxx AE cluster when lead engine is fused off - crypto: qat - disable 420xx AE cluster when lead engine is fused off - crypto: qat - fix type mismatch in RAS sysfs show functions - crypto: qat - use swab32 macro - ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] - PCI: Enable AtomicOps only if Root Port supports them - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found - Documentation: fix a hugetlbfs reservation statement - ALSA: scarlett2: Add missing sentinel initializer field - ASoC: SOF: compress: return the configured codec from get_params - PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports - PCI: tegra194: Fix polling delay for L2 state - PCI: tegra194: Increase LTSSM poll time on surprise link down - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down - PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() - PCI: tegra194: Don't force the device into the D0 state before L2 - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" - PCI: tegra194: Disable direct speed change for Endpoint mode - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode - PCI: tegra194: Allow system suspend when the Endpoint link is not up - PCI: tegra194: Free up Endpoint resources during remove() - PCI: tegra194: Use DWC IP core version - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well - PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback - ALSA: sc6000: Keep the programmed board state in card-private data - dm cache: fix missing return in invalidate_committed's error path - crypto: jitterentropy - replace long-held spinlock with mutex - ALSA: hda/realtek - fixed speaker no sound update - gfs2: Call unlock_new_inode before d_instantiate - net/socket.c: switch to CLASS(fd) - fdget(), trivial conversions - fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() - quota: Fix race of dquot_scan_active() with quota deactivation - gfs2: add some missing log locking - gfs2: prevent NULL pointer dereference during unmount - efi/capsule-loader: fix incorrect sizeof in phys array reallocation - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine - [arm64] dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon - memory: tegra124-emc: Fix dll_change check - memory: tegra30-emc: Fix dll_change check - [arm64] dts: imx8-apalis: Fix LEDs name collision - [arm64] dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config - [arm64] dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) - iommufd: vfio compatibility extension check for noiommu mode - [arm64] dts: mediatek: mt6795: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7981b: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7986a: Fix gpio-ranges pin count - [arm64] dts: qcom: msm8953-xiaomi-vince: correct wled ovp value - [arm64] dts: qcom: msm8953-xiaomi-daisy: fix backlight - [arm64] dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi - [arm64] dts: rockchip: Correct Fan Supply for Gameforce Ace - [arm64] dts: rockchip: Correct Joystick Axes on Gameforce Ace - [arm64] soc: qcom: ocmem: make the core clock optional - [arm64] soc: qcom: ocmem: register reasons for probe deferrals - [arm64] soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available - bus: rifsc: fix RIF configuration check for peripherals - [arm64] dts: qcom: sm8450: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix GIC_ITS range length - [arm64] dts: qcom: sm8650: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix xo clock supply of platform SD host controller - [arm64] dts: qcom: sm8650: Fix xo clock supply of SD host controller - [arm64] dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl - [arm64] dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot - [arm64] dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins - [arm64] dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins - [arm64] dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label - [arm64] dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing - [arm64] dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit - [arm64] dts: lx2160a: remove duplicate pinmux nodes - [arm64] dts: lx2160a: rename pinmux nodes for readability - [arm64] dts: lx2160a: add sda gpio references for i2c bus recovery - [arm64] dts: lx2160a: change zeros to hexadecimal in pinmux nodes - [arm64] dts: lx2160a: complete pinmux for rcwsr12 configuration word - [arm64] dts: imx8qm-mek: switch Type-C connector power-role to dual - [arm64] dts: imx8qxp-mek: switch Type-C connector power-role to dual - soc/tegra: cbb: Set ERD on resume for err interrupt - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure - ocfs2/dlm: validate qr_numregions in dlm_match_regions() - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison - soc: qcom: llcc: fix v1 SB syndrome register offset - [arm64] soc: qcom: aoss: compare against normalized cooling state - [arm64] dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP - [arm64] xor: fix conflicting attributes for xor_block_template - firmware: arm_ffa: Use the correct buffer size during RXTX_MAP - ocfs2: fix listxattr handling when the buffer is full - ocfs2: validate bg_bits during freefrag scan - ocfs2: validate group add input before caching - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() - soundwire: cadence: Clear message complete before signaling waiting thread - tracing: Rebuild full_name on each hist_field_name() call - hte: tegra194: remove Kconfig dependency on Tegra194 SoC - remoteproc: xlnx: Fix sram property parsing - ima: check return value of crypto_shash_final() in boot aggregate - HID: asus: make asus_resume adhere to linux kernel coding standards - HID: asus: do not abort probe when not necessary - mtd: physmap_of_gemini: Fix disabled pinctrl state check - ima_fs: don't bother with removal of files in directory we'll be removing - ima_fs: get rid of lookup-by-dentry stuff - ima_fs: Correctly create securityfs files for unsupported hash algos - dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations - mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook - mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook - mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions - cxl/pci: Check memdev driver binding status in cxl_reset_done() - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob - HID: usbhid: fix deadlock in hid_post_reset() - ext4: fix possible null-ptr-deref in mbt_kunit_exit() - [arm64] bpf, arm64: Fix off-by-one in check_imm signed range check - bpf, sockmap: Fix af_unix iter deadlock - bpf, sockmap: Fix af_unix null-ptr-deref in proto update - bpf, sockmap: Take state lock for af_unix iter - bpf: Fix precedence bug in convert_bpf_ld_abs alignment check - bpf: Fix NULL deref in map_kptr_match_type for scalar regs - bpf: allow UTF-8 literals in bpf_bprintf_prepare() - bpf: Validate node_id in arena_alloc_pages() - bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT - pinctrl: pinctrl-pic32: Fix resource leak - pinctrl: cy8c95x0: remove duplicate error message - pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() - pinctrl: cy8c95x0: Avoid returning positive values to user space - perf branch: Avoid incrementing NULL - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace - pinctrl: realtek: Fix function signature for config argument - pinctrl: abx500: Fix type of 'argument' variable - pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers - perf lock: Fix option value type in parse_max_stack - perf stat: Fix opt->value type for parse_cache_level - perf tools: Fix module symbol resolution for non-zero .text sh_addr - perf expr: Return -EINVAL for syntax error in expr__find_ids() - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure - ipmi: ssif_bmc: fix message desynchronization after truncated response - ipmi: ssif_bmc: change log level to dbg in irq callback - perf evsel: Add alternate_hw_config and use in evsel__match - perf tool_pmu: Factor tool events into their own PMU - perf python: Add parse_events function - perf cgroup: Update metric leader in evlist__expand_cgroup - perf maps: Fix copy_from that can break sorted by name order - perf util: Kill die() prototype, dead for a long time - reset: replace boolean parameters with flags parameter - reset: Add devres helpers to request pre-deasserted reset controls - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() - platform/surface: surfacepro3_button: Drop wakeup source on remove - leds: lgm-sso: Remove duplicate assignments for priv->mmap - tty: hvc_iucv: fix off-by-one in number of supported devices - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() - nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist() - [amd64] platform/x86: asus-wmi: adjust screenpad power/brightness handling - [amd64] platform/x86: asus-wmi: fix screenpad brightness range - tty: serial: ip22zilog: Fix section mispatch warning - fs/ntfs3: terminate the cached volume label after UTF-8 conversion - [amd64] platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() - [amd64] platform/x86: dell-wmi-sysman: bound enumeration string aggregation - RDMA/core: Prefer NLA_NUL_STRING - clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source - scsi: sg: Fix sysctl sg-big-buff register during sg_init() - scsi: sg: Resolve soft lockup issue when opening /dev/sgX - clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers - clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting - scsi: target: core: Fix integer overflow in UNMAP bounds check - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Use retention for USB power domains - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() - clk: imx8mq: Correct the CSI PHY sels - [amd64] x86/um/vdso: Drop VDSO64-y from Makefile - clk: qoriq: avoid format string warning - clk: xgene: Fix mapping leak in xgene_pllclk_init() - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets - clk: qcom: dispcc-sc7180: Add missing MDSS resets - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() - clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON - clk: visconti: pll: initialize clk_init_data to zero - f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() - [amd64] drm/i915: Relocate the SKL wm sanitation code - [amd64] drm/i915/wm: Verify the correct plane DDB entry - crypto: sa2ul - Fix AEAD fallback algorithm names - crypto: ccp - copy IV using skcipher ivsize - erofs: add encoded extent on-disk definition - erofs: do sanity check on m->type in z_erofs_load_compact_lcluster() - erofs: avoid infinite loops due to corrupted subpage compact indexes (CVE-2025-68251) - erofs: unify lcn as u64 for 32-bit platforms - [arm64] dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT - PCMCIA: Fix garbled log messages for KERN_CONT - [arm64] dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT - [arm64] dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names - net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir - macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF - net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys - nexthop: fix IPv6 route referencing IPv4 nexthop - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch - tcp: add data-race annotations around tp->data_segs_out and tp->total_retrans - tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE - tcp: annotate data-races around tp->bytes_sent - tcp: annotate data-races around tp->bytes_retrans - tcp: annotate data-races around tp->dsack_dups - tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) - tcp: annotate data-races around tp->plb_rehash - ice: update PCS latency settings for E825 10G/25Gb modes - ice: Remove jumbo_remove step from TX path - ice: fix double-free of tx_buf skb - ice: fix ICE_AQ_LINK_SPEED_M for 200G - i40e: don't advertise IFF_SUPP_NOFCS - e1000e: Unroll PTP in probe error handling - ipv6: fix possible UAF in icmpv6_rcv() - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks - pppoe: drop PFC frames - net/mlx5: Fix HCA caps leak on notifier init failure - openvswitch: cap upcall PID array size and pre-size vport replies - netfilter: nft_osf: restrict it to ipv4 - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO - netfilter: conntrack: remove sprintf usage - netfilter: xtables: restrict several matches to inet family - ipvs: fix MTU check for GSO packets in tunnel mode - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check - slip: reject VJ receive packets on instances with no rstate array - slip: bound decode() reads against the compressed packet length - [arm64] dts: meson-gxl-p230: fix ethernet PHY interrupt number - pwm: atmel-tcb: Cache clock rates and mark chip as atomic - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() - ksmbd: destroy async_ida in ksmbd_conn_free() - ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open - ksmbd: scope conn->binding slowpath to bound sessions only - net/rds: zero per-item info buffer before handing it to visitors - ice: fix timestamp interrupt configuration for E825C - ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() - net/sched: sch_pie: annotate data-races in pie_dump_stats() - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() - net/sched: sch_red: annotate data-races in red_dump_stats() - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() - net: dsa: realtek: rtl8365mb: fix mode mask calculation - net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() - virtio_net: Split struct virtio_net_rss_config - virtio_net: Fix endian with virtio_net_ctrl_rss - virtio_net: Use new RSS config structs - virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls - tipc: fix double-free in tipc_buf_append() - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() - fs/adfs: validate nzones in adfs_validate_bblk() - rtc: abx80x: Disable alarm feature if no interrupt attached - kbuild: builddeb - avoid recompiles for non-cross-compiles - fbdev: offb: fix PCI device reference leak on probe failure - mailbox: mtk-cmdq: Fix CURR and END addr for task insert case - mailbox: mailbox-test: free channels on probe error - cgroup/rdma: fix integer overflow in rdmacg_try_charge() - mailbox: add sanity check for channel array - mailbox: mailbox-test: don't free the reused channel - mailbox: mailbox-test: initialize struct earlier - mailbox: mailbox-test: make data_ready a per-instance variable - fsnotify: fix inode reference leak in fsnotify_recalc_mask() - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() - cgroup: Increment nr_dying_subsys_* from rmdir context - tracing: branch: Fix inverted check on stat tracer registration - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers - netfilter: arp_tables: fix IEEE1394 ARP payload parsing - nvme-pci: fix missed admin queue sq doorbell write - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG - drm/amdgpu: fix spelling typos - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) - netfilter: xt_policy: fix strict mode inbound policy matching - netfilter: nf_conntrack_sip: don't use simple_strtoul - [amd64] ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ - drm/sysfb: ofdrm: fix PCI device reference leaks - arm64/scs: Fix potential sign extension issue of advance_loc4 - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() - netdevsim: zero initialize struct iphdr in dummy sk_buff - net/sched: netem: fix probability gaps in 4-state loss model - net/sched: netem: fix queue limit check to include reordered packets - net/sched: netem: only reseed PRNG when seed is explicitly provided - net/sched: netem: validate slot configuration - net/sched: netem: fix slot delay calculation overflow - net/sched: netem: check for negative latency and jitter - net/sched: sch_choke: annotate data-races in choke_dump_stats() - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() - vrf: Fix a potential NPD when removing a port from a VRF - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit - NFC: trf7970a: Ignore antenna noise when checking for RF field - net/sched: taprio: fix NULL pointer dereference in class dump - neigh: let neigh_xmit take skb ownership - tcp: make probe0 timer handle expired user timeout - net, treewide: define and use MAC_ADDR_STR_LEN - netconsole: allow selection of egress interface via MAC address - netpoll: Extract carrier wait function - netpoll: extract IPv4 address retrieval into helper function - netpoll: fix IPv6 local-address corruption - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams - sched/fair: Clear rel_deadline when initializing forked entities - net: mctp i2c: check length before marking flow active - net: phy: dp83869: fix setting CLK_O_SEL field. - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring - ASoC: codecs: ab8500: Fix casting of private data - netfilter: skip recording stale or retransmitted INIT - sctp: discard stale INIT after handshake completion - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) - netconsole: propagate device name truncation in dev_name_store() - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 - ALSA: hda/conexant: Fix missing error check for jack detection - ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup - drm/amd/display: Allow DCE link encoder without AUX registers - drm/amd/display: Read EDID from VBIOS embedded panel info - drm/xe/debugfs: Correct printing of register whitelist ranges - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() - page_pool: Set `dma_sync` to false for devmem memory provider - net: page_pool: create hooks for custom memory providers - page_pool: fix memory-provider leak in page_pool_create_percpu() error path - iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING - iavf: stop removing VLAN filters from PF on interface down - iavf: wait for PF confirmation before removing VLAN filters - iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler - ice: fix NULL pointer dereference in ice_reset_all_vfs() - net: tls: fix strparser anchor skb leak on offload RX setup failure - sfc: fix error code in efx_devlink_info_running_versions() - net/sched: cls_flower: revert unintended changes - [arm64] Reserve an extra page for early kernel mapping - smb: client: correctly handle ErrorContextData as a flexible array - smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) - LoongArch: KVM: Compile switch.S directly into the kernel - ntfs: ->d_compare() must not block - PCI: Initialize temporary device in new_id_store() - net: bcmgenet: Initialize u64 stats seq counter - net: bcmgenet: fix leaking free_bds - [amd64] iommu/amd: Reorder attach device code - [amd64] iommu/amd: Put list_add/del(dev_data) back under the domain->lock - perf tool_pmu: Fix aggregation on duration_time - net/sched: sch_pie: annotate more data-races in pie_dump_stats() - netpoll: Extract IPv6 address retrieval function - netpoll: pass buffer size to egress_dev() to avoid MAC truncation - page_pool: fix incorrect mp_ops error handling - crypto: af_alg - Cap AEAD AD length to 0x80000000 - i40e: Cleanup PTP pins on probe failure - workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path - netfilter: nf_conntrack_sip: get helper before allocating expectation - audit: fix incorrect inheritable capability in CAPSET records - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" - netfilter: nft_ct: fix missing expect put in obj eval - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() - [s390x] KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic - [amd64] KVM: x86: Fix Xen hypercall tracepoint argument assignment - netfilter: nf_tables: unconditionally bump set->nelems before insertion (CVE-2026-23272) - ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands - smb/client: fix possible infinite loop and oob read in symlink_data() - [amd64] drm/i915/dp: Fix VSC dynamic range signaling for RGB formats - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans - ALSA: usb-audio: Bound MIDI endpoint descriptor scans - ceph: fix a buffer leak in __ceph_setxattr() - ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size - io-wq: check that the predecessor is hashed in io_wq_remove_pending() - [powerpc*] warp: Fix error handling in pika_dtm_thread - netfs: fix error handling in netfs_extract_user_iter() - irqchip/riscv-imsic: Clear interrupt move state during CPU offlining - libceph: Fix potential out-of-bounds access in osdmap_decode() - libceph: Fix potential null-ptr-deref in decode_choose_args() - libceph: Fix potential out-of-bounds access in crush_decode() - libceph: handle rbtree insertion error in decode_choose_args() - [amd64] iommu/vt-d: Disable DMAR for Intel Q35 IGFX - [amd64] drm/i915: skip __i915_request_skip() for already signaled requests - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() - drm/xe/dma-buf: handle empty bo and UAF races - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup - drm/gma500/oaktrail_lvds: fix hang on init failure - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init - iommufd: Fix return value of iommufd_fault_fops_write() - eventfs: Use list_add_tail_rcu() for SRCU-protected children list - drm/v3d: Reject empty multisync extension to prevent infinite loop - btrfs: use inode already stored in local variable at btrfs_rmdir() - btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() - btrfs: fix missing last_unlink_trans update when removing a directory - smb: client: Use FullSessionKey for AES-256 encryption key derivation - btrfs: do not mark inode incompressible after inline attempt fails - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() - sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new - mptcp: pm: prio: skip closed subflows - mptcp: drop __mptcp_fastopen_gen_msk_ackseq() - mptcp: fix rx timestamp corruption on fastopen - f2fs: fix incorrect file address mapping when inline inode is unwritten - f2fs: fix false alarm of lockdep on cp_global_sem lock - spi: sifive: Simplify clock handling with devm_clk_get_enabled() - spi: sifive: fix controller deregistration - mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 - mptcp: pm: ADD_ADDR rtx: fix potential data-race - mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker - netfs: Fix potential uninitialised var in netfs_extract_user_iter() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.92 - mptcp: sync the msk->sndbuf at accept() time - mptcp: pm: ADD_ADDR rtx: allow ID 0 - mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (CVE-2026-46158) - mptcp: pm: ADD_ADDR rtx: free sk if last (CVE-2026-46170) - ksmbd: validate owner of durable handle on reconnect (CVE-2026-31717) - drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (CVE-2026-46216) - [s390x] debug: Reject zero-length input before trimming a newline - Revert "perf cgroup: Update metric leader in evlist__expand_cgroup" - Revert "perf tool_pmu: Fix aggregation on duration_time" - Revert "perf python: Add parse_events function" - Revert "perf tool_pmu: Factor tool events into their own PMU" - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420) - spi: spi-dw-dma: fix print error log when wait finish transaction (CVE-2026-31560) - Revert "x86/vdso: Fix output operand size of RDPID" - sched/deadline: Less agressive dl_server handling - sched/deadline: Fix dl_server_stopped() - sched/deadline: Fix dl_server getting stuck - sched/deadline: Fix dl_server behaviour - sched/deadline: Stop dl_server before CPU goes offline - ksmbd: close durable scavenger races against m_fp_list lookups - af_unix: Give up GC if MSG_PEEK intervened. (CVE-2026-23394) - drm/imagination: Synchronize interrupts before suspending the GPU (CVE-2026-23469) - ata: libata-scsi: improve readability of ata_scsi_qc_issue() - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS - perf parse-events: Expose/rename config_term_name - Revert "ice: fix double-free of tx_buf skb" - Revert "ice: Remove jumbo_remove step from TX path" - tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 - net/mlx5e: Trigger neighbor resolution for unresolved destinations - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init - [amd64] x86/fgraph: Fix return_to_handler regs.rsp value - [amd64] iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set - [riscv64] fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends on HAVE_DYNAMIC_FTRACE_WITH_ARGS - [riscv64] fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (CVE-2025-22069) - hwmon: (pmbus/core) Protect regulator operations with mutex - [arm64] Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL - sysfs: don't remove existing directory on update failure - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() - ksmbd: fix null pointer dereference in compare_guid_key() - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow - ksmbd: validate SID in parent security descriptor during ACL inheritance - smb: client: require net admin for CIFS SWN netlink - smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() - smb: client: use data_len for SMB2 READ encrypted folioq copy - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX - ALSA: ua101: Reject too-short USB descriptors - ALSA: pcm: Don't setup bogus iov_iter for silencing - ALSA: asihpi: Fix potential OOB array access at reading cache - efi: Allocate runtime workqueue before ACPI init - io_uring/waitid: clear waitid info before copying it to userspace - drivers/base/memory: fix memory block reference leak in poison accounting - ipv6: ioam: refresh hdr pointer before ioam6_event() - mm/memory_hotplug: fix memory block reference leak on remove - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START - Bluetooth: bnep: Fix UAF read of dev->name - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer - Bluetooth: MGMT: validate Add Extended Advertising Data length - Bluetooth: serialize accept_q access - phonet/pep: disable BH around forwarded sk_receive_skb() - net: bcmgenet: keep RBUF EEE/PM disabled - net: ifb: report ethtool stats over num_tx_queues - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() - netfilter: ip6t_hbh: reject oversized option lists - netfilter: nf_queue: hold bridge skb->dev while queued - netfilter: ipset: stop hash:* range iteration at end - netfilter: nft_inner: Fix IPv6 inner_thoff desync - sched_ext: Fix missing warning in scx_set_task_state() default case - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path - cgroup/cpuset: Reset DL migration state on can_attach() failure - fs/ntfs3: handle attr_set_size() errors when truncating files - l2tp: use list_del_rcu in l2tp_session_unhash - qed: fix double free in qed_cxt_tables_alloc() - ring-buffer: Fix reporting of missed events in iterator - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() - vsock/vmci: fix UAF when peer resets connection during handshake - vsock/virtio: reset connection on receiving queue overflow - wifi: ath11k: clear shared SRNG pointer state on restart - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 - ixgbevf: fix use-after-free in VEPA multicast source pruning - rbd: eliminate a race in lock_dwork draining on unmap - lsm: hold cred_guard_mutex for lsm_set_self_attr() - [arm64] octeontx2-af: CGX: add bounds check to cgx_speed_mbps index - ice: fix setting promisc mode while adding VID filter - ice: restore PTP Rx timestamp config after ethtool set-channels - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() - af_unix: Fix UAF read of tail->len in unix_stream_data_wait() - wifi: mac80211: consume only present negotiated TTLM maps - cifs: Fix busy dentry used after unmounting - tracing: Do not call map->ops->elt_free() if elt_alloc() fails - [arm64] probes: Handle probes on hinted conditional branch instructions - [arm64] KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits - [arm64] KVM: arm64: vgic: Free private_irqs when init fails after allocation - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe - spi: qup: fix error pointer deref after DMA setup failure - [arm64] phy: tegra: xusb: Fix per-pad high-speed termination calibration - scsi: isci: Fix use-after-free in device removal path - spi: ep93xx: fix error pointer deref after DMA setup failure - spi: sprd: fix error pointer deref after DMA setup failure - spi: ti-qspi: fix use-after-free after DMA setup failure - RDMA/siw: Reject MPA FPDU length underflow before signed receive math - device property: set fwnode->secondary to NULL in fwnode_init() - drm/virtio: use uninterruptible resv lock for plane updates - drm/amdgpu/vpe: Force collaborate sync after TRAP - drm/bridge: it66121: acquire reset GPIO in probe - drm/bridge: megachips: remove bridge when irq request fails - drm/amd/display: Fix integer overflow in bios_get_image() - drm/amd/display: Validate GPIO pin LUT table size before iterating - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async - batman-adv: mcast: fix use-after-free in orig_node RCU release - batman-adv: clear current gateway during teardown - batman-adv: dat: handle forward allocation error - batman-adv: fix fragment reassembly length accounting - batman-adv: fix tp_meter counter underflow during shutdown - batman-adv: frag: disallow unicast fragment in fragment - batman-adv: bla: fix report_work leak on backbone_gw purge - batman-adv: tp_meter: avoid use of uninit sender vars - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown - batman-adv: tp_meter: fix race condition in send error reporting - batman-adv: tt: fix negative last_changeset_len - batman-adv: tt: fix negative tt_buff_len - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock - hwmon: (pmbus/adm1266) reject implausible blackbox record_count - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors - [arm64] pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume - HID: uclogic: Fix regression of input name assignment - [riscv64] mm: Fixup no5lvl failure when vaddr is invalid - [arm64] pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 - ALSA: hda: cs35l56: Put ACPI device after setting companion - ALSA: hda: cs35l41: Put ACPI device on missing physical node - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() - netfilter: x_tables: unregister the templates first - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() - tcp: Fix imbalanced icsk_accept_queue count. - ice: fix setting RSS VSI hash for E830 - ice: fix locking in ice_dcb_rebuild() - net: lan966x: avoid unregistering netdev on register failure - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access - NFSD: Fix infinite loop in layout state revocation - irqchip/ath79-cpu: Remove unused function - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation - nsfs: fix wrong error code returned for pidns ioctls - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT - zonefs: handle integer overflow in zonefs_fname_to_fno - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). - [powerpc*] fix dead default for GUEST_STATE_BUFFER_TEST - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call - netfs: Fix overrun check in netfs_extract_user_iter() - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone - netfs: Defer the emission of trace_netfs_folio() - netfs: Fix streaming write being overwritten - netfs: Fix potential deadlock in write-through mode - netfs: Fix write streaming disablement if fd open O_RDWR - netfs: Fix early put of sink folio in netfs_read_gaps() - netfs: Fix partial invalidation of streaming-write folio - netfs: Fix a few minor bugs in netfs_page_mkwrite() - netfs: Remove unnecessary references to pages - netfs: Fix folio->private handling in netfs_perform_write() - net: ethernet: cortina: Make RX SKB per-port - net: ethernet: cortina: Drop half-assembled SKB - net: ethernet: cortina: Carry over frag counter - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference - wifi: ath11k: fix error path leaks in some WMI WOW calls - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() - wifi: ath10k: skip WMI and beacon transmission when device is wedged - blk-integrity: remove seed for user mapped buffers - block: don't overwrite bip_vcnt in bio_integrity_copy_user() - block: recompute nr_integrity_segments in blk_insert_cloned_request - HID: quirks: really enable the intended work around for appledisplay - block: modify bio_integrity_map_user to accept iov_iter as argument - block: drop direction param from bio_integrity_copy_user() - blk-integrity: use simpler alignment check - blk-integrity: enable p2p source and destination - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() - accel/qaic: Add overflow check to remap_pfn_range during mmap - net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics - [arm64] drm/msm/dsi: don't dump registers past the mapped region - [arm64] drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN - [powerpc*] time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring - net: tls: prevent chain-after-chain in plain text SG - net: phy: DP83TC811: add reading of abilities - [amd64] x86/xen: Fix xen_e820_swap_entry_with_ram() - tls: Preserve sk_err across recvmsg() when data has been copied - net/mlx5: Do not restore destination-less TC rules - scsi: sd: Fix return code handling in sd_spinup_disk() - ALSA: scarlett2: Add missing error check when initialise Autogain Status - io_uring/net: punt IORING_OP_BIND async if it needs file create - btrfs: fix squota accounting during enable generation - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() - [arm64] drm/msm/snapshot: fix dumping of the unaligned regions - drm/xe/gsc: Fix double-free of managed BO in error path - drm/xe/vf: Fix signature of print functions - drm/xe/pf: Fix CFI failure in debugfs access - wifi: ath11k: fix peer resolution on rx path when peer_id=0 - ice: ptp: serialize E825 PHY timer start with PTP lock - [amd64] drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP - [arm64] net: dsa: mt7530: fix FDB entries not aging out with short timeout - [arm64] net: dsa: mt7530: preserve VLAN tags on trapped link-local frames - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 - [amd64] platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: hp_accel: Check ACPI_COMPANION() against NULL - [amd64] platform/x86: intel-hid: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL - RDMA/rtrs: Fix use-after-free in path file creation cleanup - net: bridge: Flush multicast groups when snooping is disabled - bridge: mcast: Fix a possible use-after-free when removing a bridge port - pds_core: fix error handling in pdsc_devcmd_wait - pds_core: fix debugfs_lookup dentry leak and error handling - wifi: mac80211: fix MLE defragmentation - ALSA: seq: Serialize UMP output teardown with event_input - tracing: Avoid NULL return from hist_field_name() on truncation - Bluetooth: btmtk: fix urb->setup_packet leak in error paths - net: ag71xx: check error for platform_get_irq - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() - drm/xe/oa: Fix exec_queue leak on width check in stream open - [arm64] octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs - net: mana: validate rx_req_idx to prevent out-of-bounds array access - pds_core: ensure null-termination for firmware version strings - net: gro: don't merge zcopy skbs - landlock: Fix TCP handling of short AF_UNSPEC addresses - block: make bio_integrity_map_user() static inline - security/keys: fix missed RCU read section on lookup https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.93 - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size - [arm64] drm/v3d: Fix use-after-free of CPU job query arrays on error path - [arm64] drm/v3d: Release indirect CSD GEM reference on CPU job free - net/sched: cls_fw: fix NULL dereference of "old" filters before change() - net: mctp: ensure our nlmsg responses are initialised (CVE-2026-45930) - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit - net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked - bcache: fix uninitialized closure object - net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (CVE-2026-43219) - [arm64] Introduce esr_is_ubsan_brk() - [arm64] debug: clean up single_step_handler logic - [arm64] refactor aarch32_break_handler() - [arm64] debug: call software breakpoint handlers statically - [arm64] debug: call step handlers statically - [arm64] debug: remove break/step handler registration infrastructure - [arm64] entry: Add entry and exit functions for debug exceptions - [arm64] debug: split hardware breakpoint exception entry - [arm64] debug: refactor reinstall_suspended_bps() - [arm64] debug: split single stepping exception entry - [arm64] debug: split hardware watchpoint exception entry - [arm64] debug: split brk64 exception entry - [arm64] debug: split bkpt32 exception entry - [arm64] debug: remove debug exception registration infrastructure - [arm64] debug: always unmask interrupts in el0_softstp() - nfc: llcp: Fix use-after-free in llcp_sock_release() - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() - xfrm: Check for underflow in xfrm_state_mtu - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems - netfilter: synproxy: refresh tcphdr after skb_ensure_writable - netfilter: xt_cpu: prefer raw_smp_processor_id - netfilter: ebtables: fix OOB read in compat_mtw_from_user - tun: free page on short-frame rejection in tun_xdp_one() (CVE-2026-46321) - tun: free page on build_skb failure in tun_xdp_one() (CVE-2026-46322) - vsock: keep poll shutdown state consistent - net: netlink: fix sending unassigned nsid after assigned one - net: netlink: don't set nsid on local notifications - net/smc: Do not re-initialize smc hashtables - [s390x] net/iucv: fix locking in .getsockopt - scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues - ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() - ALSA: pcm: oss: Fix setup list UAF on proc write error - [amd64] ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors - net: hsr: fix potential OOB access in supervision frame handling - [amd64] accel/ivpu: prevent uninitialized data bug in debugfs - gpio: mxc: fix irq_high handling - net: Avoid checksumming unreadable skb tail on trim - ethtool: rss: fix hkey leak when indir_size is 0 - ethtool: module: avoid leaking a netdev ref on module flash errors - ethtool: module: check fw_flash_in_progress under rtnl_lock - ethtool: module: fix cleanup if socket used for flashing multiple devices - ethtool: cmis: require exact CDB reply length - ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl - net: ethtool: Add new parameters and a function to support EPL - net: ethtool: Add support for writing firmware blocks using EPL payload - ethtool: cmis: validate start_cmd_payload_size from module - ethtool: cmis: validate fw->size against start_cmd_payload_size - tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() - ASoC: codecs: simple-mux: Fix enum control bounds check - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() - bonding: refuse to enslave CAN devices - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES - ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error - ethtool: pse-pd: fix missing ethnl_ops_complete() - ethtool: strset: fix header attribute index in ethnl_req_get_phydev() - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback - ethtool: eeprom: add more safeties to EEPROM Netlink fallback - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() - net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" - net/sched: fix packet loop on netem when duplicate is on - net/sched: act_mirred: Move the recursion counter struct netdev_xmit - net/sched: act_mirred: add loop detection - net: Introduce skb tc depth field to track packet loops - net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop - net/sched: act_mirred: Fix return code in early mirred redirect error paths - net/handshake: Use spin_lock_bh for hn_lock - nvme-tcp: store negative errno in queue->tls_err - net/handshake: Pass negative errno through handshake_complete() - remove pointless includes of - net/handshake: Take a long-lived file reference at submit - net/handshake: Drain pending requests at net namespace exit - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close - [arm64,armhf] gpio: rockchip: convert bank->clk to devm_clk_get_enabled() - [amd64,arm64] net: mana: Add NULL guards in teardown path to prevent panic on attach failure - sctp: fix race between sctp_wait_for_connect and peeloff - ipv6: fix possible infinite loop in rt6_fill_node() - ipv6: fix possible infinite loop in fib6_select_path() - net: skbuff: fix pskb_carve leaking zcopy pages - perf: Fix dangling cgroup pointer in cpuctx - batman-adv: v: stop OGMv2 on disabled interface - batman-adv: tvlv: abort OGM send on tvlv append failure - batman-adv: tt: reject oversized local TVLV buffers - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface - batman-adv: tvlv: reject oversized TVLV packets - batman-adv: iv: recover OGM scheduling after forward packet error - batman-adv: tp_meter: avoid role confusion in tp_list - [s390x] cio: Restore GFP_DMA for CHSC allocation - batman-adv: tp_meter: directly shut down timer on cleanup - batman-adv: tt: fix TOCTOU race for reported vlans - batman-adv: tt: avoid empty VLAN responses - batman-adv: bla: avoid double decrement of bla.num_requests - mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303) - media: rc: fix race between unregister and urb/irq callbacks - media: rc: ttusbir: fix inverted error logic - inet: frags: add inet_frag_queue_flush() - inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) - HID: core: Add printk_ratelimited variants to hid_warn() etc - HID: pass the buffer size to hid_report_raw_event - HID: core: introduce hid_safe_input_report() - HID: core: Fix size_t specifier in hid_report_raw_event() - [amd64] drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register - [amd64] drm/i915/psr: Read Intel DPCD workaround register - drm/dp: Add eDP 1.5 bit definition - [amd64] drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used - [arm64] io: Rename ioremap_prot() to __ioremap_prot() - [arm64] io: Extract user memory type in ioremap_prot() (CVE-2026-23346) - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X - batman-adv: tt: prevent TVLV entry number overflow - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer - usb: typec: ucsi: ccg: reject firmware images without a ':' record header - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers - usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO - usb: typec: altmodes/displayport: validate count before reading Status Update VDO - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT - usb: typec: ucsi: validate connector number in ucsi_connector_change() - USB: serial: safe_serial: fix memory corruption with small endpoint - media: rc: igorplugusb: fix control request setup packet - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse - Bluetooth: btusb: Allow firmware re-download when version matches - hpfs: fix a crash if hpfs_map_dnode_bitmap fails - ipc: limit next_id allocation to the valid ID range - auxdisplay: line-display: fix OOB read on zero-length message_store() - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn - Bluetooth: HIDP: fix missing length checks in hidp_input_report() - Bluetooth: ISO: fix UAF in iso_recv_frame - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync - Input: xpad - fix out-of-bounds access for Share button - parport: Fix race between port and client registration (Closes: #1130365) - USB: cdc-acm: Fix bit overlap and move quirk definitions to header - [arm64] KVM: arm64: PMU: Preserve AArch32 counter low bits - [amd64] KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC - [amd64] KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use - [amd64] KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests - [amd64] KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 - [amd64] KVM: SEV: Compute the correct max length of the in-GHCB scratch area - [amd64] KVM: SEV: Check PSC request indices against the actual size of the buffer - [amd64] KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer - [amd64] KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux - iio: adc: npcm: fix unbalanced clk_disable_unprepare() - iio: dac: max5821: fix return value check in powerdown sync - iio: dac: ad5686: fix input raw value check - iio: dac: ad5686: acquire lock when doing powerdown control - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw - iio: gyro: itg3200: fix i2c read into the wrong stack location - iio: gyro: adis16260: fix division by zero in write_raw - iio: ssp_sensors: cancel delayed work_refresh on remove - iio: temperature: tsys01: fix broken PROM checksum validation - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL - iio: light: cm3323: fix reg_conf not being initialized correctly - iio: buffer: hw-consumer: fix use-after-free in error path - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() - USB: serial: omninet: fix memory corruption with small endpoint - usb: cdns3: gadget: fix request skipping after clearing halt - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles - usb: dwc2: Fix use after free in debug code - Input: elan_i2c - validate firmware size before use - wireguard: send: append trailer after expanding head - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data - macsec: fix replay protection at XPN lower-PN wrap - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() - [arm64] ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params - ipv6: exthdrs: refresh nh after handling HAO option - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). - ipv6: validate extension header length before copying to cmsg - xfrm: input: hold netns during deferred transport reinjection - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname - ip6: vti: Use ip6_tnl.net in vti6_changelink(). - net: skbuff: fix missing zerocopy reference in pskb_carve helpers - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() - nfc: hci: fix out-of-bounds read in HCP header parsing - xfrm: route MIGRATE notifications to caller's netns - xfrm: ah: use skb_to_full_sk in async output callbacks - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - [arm64] ASoC: qcom: q6asm-dai: close stream only when running - [arm64] ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks - xfrm: esp: restore combined single-frag length gate - Input: xpad - add "Nova 2 Lite" from GameSir - Input: xpad - add support for ASUS ROG RAIKIRI II - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 - [amd64] comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() - [amd64] comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() - counter: Fix refcount leak in counter_alloc() error path - tty: serial: pch_uart: add check for dma_alloc_coherent() - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers - usb: chipidea: core: convert ci_role_switch to local variable - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers - usb: storage: Add quirks for PNY Elite Portable SSD - usbip: vudc: Fix use after free bug in vudc_remove due to race condition - usb: usbtmc: check URB actual_length for interrupt-IN notifications - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize - usb: typec: tcpm: improve handling of DISCOVER_MODES failures - USB: serial: option: add MeiG SRM813Q - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL - USB: serial: belkin_sa: validate interrupt status length - USB: serial: cypress_m8: validate interrupt packet headers - USB: serial: keyspan: fix missing indat transfer sanity check - USB: serial: mxuport: fix memory corruption with small endpoint - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind - usb: gadget: net2280: Fix double free in probe error path - usb: gadget: f_hid: fix device reference leak in hidg_alloc() - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports - usb: gadget: f_fs: copy only received bytes on short ep0 read - usb: gadget: f_fs: serialize DMABUF cancel against request completion - [amd64] thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() - [amd64] thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf - scsi: target: iscsi: Validate CHAP_R length before base64 decode - drm/hyperv: validate resolution_count and fix WIN8 fallback - drm/hyperv: validate VMBus packet size in receive callback - [amd64] drm/i915: Fix potential UAF in TTM object purge - drm/amd/pm/si: Disregard vblank time when no displays are connected - serial: altera_jtaguart: handle uart_add_one_port() failures - serial: qcom-geni: fix UART_RX_PAR_EN bit position - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ - serial: sh-sci: fix memory region release in error path - serial: zs: Fix swapped RI/DSR modem line transition counting - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger - drm/amdkfd: Check for pdd drm file first in CRIU restore path - serial: dz: Fix bootconsole message clobbering at chip reset - serial: dz: Fix bootconsole handover lockup - serial: dz: Convert to use a platform device - serial: zs: Fix bootconsole handover lockup - serial: zs: Switch to using channel reset - serial: zs: Convert to use a platform device - USB: serial: cypress_m8: fix memory corruption with small endpoint - USB: serial: digi_acceleport: fix memory corruption with small endpoints - xhci: tegra: Fix ghost USB device on dual-role port unplug - iommu: Skip PASID validation for devices without PASID capability - [amd64] x86/boot: Disable stack protector for early boot code - [amd64] x86/kexec: Disable KCOV instrumentation after load_segments() (CVE-2026-43331) - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer - serdev: Provide a bustype shutdown function - Bluetooth: hci_qca: Migrate to serdev specific shutdown function - Bluetooth: hci_qca: Convert timeout from jiffies to ms - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes - ALSA: scarlett2: Allow flash writes ending at segment boundary - mm/memory: fix spurious warning when unmapping device-private/exclusive pages - [amd64] platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery - net: hsr: defer node table free until after RCU readers - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient - ice: fix VF queue configuration with low MTU values - ring-buffer: Flush and stop persistent ring buffer on panic - mptcp: cleanup fallback dummy mapping generation - mptcp: reset rcv wnd on disconnect - [arm64] tlb: Flush walk cache when unsharing PMD tables - [arm64] octeontx2-pf: avoid double free of pool->stack on AQ init failure - mptcp: introduce the mptcp_init_skb helper - mptcp: handle first subflow closing consistently - mptcp: do not drop partial packets - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() - iio: chemical: scd30: Use guard(mutex) to allow early returns - iio: chemical: scd30: fix division by zero in write_raw - iio: dac: ad5686: fix ref bit initialization for single-channel parts - ALSA: firewire-motu: Protect register DSP event queue positions - [arm64] usb: dwc3: xilinx: fix error handling in zynqmp init error paths - usb: musb: omap2430: Fix use-after-free in omap2430_probe() - usb: typec: ucsi: Check if power role change actually happened before handling - [amd64] thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() - usb: typec: ucsi: Don't update power_supply on power role change if not connected - [amd64] x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' - [amd64] x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock - hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock - mm: perform all memfd seal checks in a single place - mm/memfd: fix spelling and grammatical issues - memfd: deny writeable mappings when implying SEAL_WRITE - usb: core: Fix SuperSpeed root hub wMaxPacketSize - ethtool: cmis_cdb: Fix incorrect read / write length extension - net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow - [arm64] KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.94 - bpf: Free reuseport cBPF prog after RCU grace period. (CVE-2026-52910) - USB: serial: mct_u232: fix memory corruption with small endpoint - [armhf] group is_permission_fault() with is_translation_fault() - [armhf] allow __do_kernel_fault() to report execution of memory faults - [armhf] fix hash_name() fault - [armhf] fix branch predictor hardening - net: phy: micrel: fix LAN8814 QSGMII soft reset - wifi: remove zero-length arrays - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl - ipv6: mcast: Fix use-after-free when processing MLD queries - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS - [arm64] tee: optee: prevent use-after-free when the client exits before the supplicant - [arm64]soc: qcom: ice: Return -ENODEV if the ICE platform device is not found - erofs: add sysfs node to drop internal caches - erofs: tidy up synchronous decompression - erofs: fix use-after-free on sbi->sync_decompress - ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id - ipvs: clear the svc scheduler ptr early on edit - netfilter: synproxy: add mutex to guard hook reference counting - netfilter: conntrack_irc: fix possible out-of-bounds read - netfilter: nft_ct: bail out on template ct in get eval - netfilter: bridge: make ebt_snat ARP rewrite writable - dm cache policy smq: check allocation under invalidate lock - net/sched: act_api: use RCU with deferred freeing for action lifecycle - 6lowpan: fix off-by-one in multicast context address compression - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() - devlink: Release nested relation on devlink free - [arm64] drm/imx: Fix three kernel-doc warnings in dcss-scaler.c - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap - pcnet32: stop holding device spin lock during napi_complete_done - net: Annotate sk->sk_write_space() for UDP SOCKMAP. - hsr: Remove WARN_ONCE() in hsr_addr_is_self(). - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr - net: lan743x: permit VLAN-tagged packets up to configured MTU - net: fec: fix pinctrl default state restore order on resume - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() - Bluetooth: MGMT: validate advertising TLV before type checks - Bluetooth: RFCOMM: validate skb length in MCC handlers - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling - Bluetooth: bnep: reject short frames before parsing - Bluetooth: fix memory leak in error path of hci_alloc_dev() - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync - Bluetooth: ISO: Fix not using bc_sid as advertisement SID - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls - Bluetooth: MGMT: Fix backward compatibility with userspace - [arm64] octeontx2-pf: Fix NDC sync operation errors - [arm64] octeontx2-af: Fix initialization of mcam's entry2target_pffunc field - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options - ptp: vclock: Switch from RCU to SRCU - net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown - net_sched: act_pedit: use RCU in tcf_pedit_dump() - net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) - [arm64] octeontx2-af: npc: Fix CPT channel mask in npc_install_flow - vxlan: vnifilter: send notification on VNI add - vxlan: vnifilter: fix spurious notification on VNI update - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr - sctp: purge outqueue on stale COOKIE-ECHO handling - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() - time: Fix off-by-one in settimeofday() usec validation - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams - ALSA: seq: dummy: fix UMP event stack overread - ima: kexec: skip IMA segment validation after kexec soft reboot - ima: kexec: move IMA log copy from kexec load to execute - spi: cadence-quadspi: fix unclocked access on unbind (CVE-2026-46203) - tools/rv: Fix cleanup after failed trace setup - tap: free page on error paths in tap_get_user_xdp() (CVE-2026-46320) - [arm64] tlb: Allow XZR argument to TLBI ops - [arm64] tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI - iomap: don't revert iov_iter on partially completed buffered writes - dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() - netlabel: validate unlabeled address and mask attribute lengths - gpio: mvebu: fix NULL pointer dereference in suspend/resume - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls - tcp: restrict SO_ATTACH_FILTER to priv users - net: add pskb_may_pull() to skb_gro_receive_list() - net/mlx4: avoid GCC 10 __bad_copy_from() false positive - net: ibm: emac: Fix use-after-free during device removal - netdev: fix double-free in netdev_nl_bind_rx_doit() - net: phy: clean the sfp upstream if phy probing fails - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure - net/mlx5: Use effective affinity mask for IRQ selection - ipv6: sit: reload inner IPv6 header after GSO offloads - net: openvswitch: fix possible kfree_skb of ERR_PTR - r8152: handle the return value of usb_reset_device() - gpio: zynq: fix runtime PM leak on remove - sctp: fix uninit-value in __sctp_rcv_asconf_lookup() - net: guard timestamp cmsgs to real error queue skbs - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() - rds: mark snapshot pages dirty in rds_info_getsockopt() - netfilter: revalidate bridge ports - netfilter: nf_conntrack: destroy stale expectfn expectations on unregister - netfilter: x_tables: avoid leaking percpu counter pointers - netfilter: nf_log: validate MAC header was set before dumping it - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag - [arm64,armhf] net: mvpp2: sync RX data at the hardware packet offset - [arm64,armhf] net: mvpp2: limit XDP frame size to the RX buffer - [arm64,armhf] net: mvpp2: Add metadata support for xdp mode - [arm64,armhf] net: mvpp2: refill RX buffers before XDP or skb use - [arm64,armhf] net: mvpp2: build skb from XDP-adjusted data on XDP_PASS - ipv6: Fix a potential NPD in cleanup_prefix_route() - netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) - writeback: Avoid contention on wb->list_lock when switching inodes - writeback: Fix use after free in inode_switch_wbs_work_fn() - xfrm: hold device only for the asynchronous decryption - xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663) - [amd64] KVM: VMX: Update SVI during runtime APICv activation - [arm64] clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked - clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs - [arm64] clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time - drm/virtio: Fix driver removal with disabled KMS - [arm64,armhf] drm/vc4: fix krealloc() memory leak - drm/xe: fix refcount leak in xe_range_fence_insert() - netfilter: nft_tunnel: fix use-after-free on object destroy - [arm64] tee: shm: fix shm leak in register_shm_helper() - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig - [arm64] soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() - [amd64] accel/ivpu: Add bounds checks for firmware log indices - [amd64] accel/ivpu: Add buffer overflow check in MS get_info_ioctl - [amd64] accel/ivpu: Fix signed integer truncation in IPC receive - tracing/probes: Point the error offset correctly for eprobe argument error - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying - [amd64] KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA - [amd64] drm/i915/gem: Fix phys BO pread/pwrite with offset - pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL - xfrm: espintcp: do not reuse an in-progress partial send - USB: serial: io_ti: fix heap overflow in get_manuf_info() - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() - USB: serial: option: add usb-id for Dell Wireless DW5826e-m - USB: serial: kl5kusb105: fix bulk-out buffer overflow - ALSA: timer: Forcibly close timer instances at closing - ALSA: timer: Fix UAF at snd_timer_user_params() - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() - mm/huge_memory: update file PMD counter before folio_put() - mm/damon/ops-common: call folio_test_lru() after folio_get() - RDMA/srp: bound SRP_RSP sense copy by the received length - zram: fix use-after-free in zram_bvec_write_partial() - udp: clear skb->dev before running a sockmap verdict - mptcp: fix retransmission loop when csum is enabled - mptcp: close TOCTOU race while computing rcv_wnd - mptcp: allow subflow rcv wnd to shrink - mptcp: sockopt: check timestamping ret value - mptcp: add-addr: always drop other suboptions - wifi: nl80211: reject oversized EMA RNR lists - vsock/vmci: fix sk_ack_backlog leak on failed handshake - timers/migration: Fix livelock in tmigr_handle_remote_up() - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write - bnxt_en: Fix NULL pointer dereference - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush - pidfd: refuse access to tasks that have started exiting harder - fs/qnx6: fix pointer arithmetic in directory iteration - fuse: reject fuse_notify() pagecache ops on directories - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter - i2c: tegra: Fix NOIRQ suspend/resume - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard - ipc/shm: serialize orphan cleanup with shm_nattch updates - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context - misc: fastrpc: fix use-after-free race in fastrpc_map_create - misc: fastrpc: fix DMA address corruption due to find_vma misuse - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback - net/mlx5: Reorder completion before putting command entry in cmd_work_handler - net: bonding: fix NULL pointer dereference in bond_do_ioctl() - net: mv643xx: fix OF node refcount - net: rds: clear i_sends on setup unwind - nvmem: core: fix use-after-free bugs in error paths - nvmem: layouts: onie-tlv: fix hang on unknown types - [arm64] octeontx2-af: fix memory leak in rvu_setup_hw_resources() - io_uring/kbuf: don't truncate end buffer for bundles - io_uring/wait: fix min_timeout behavior - mm/hugetlb: restore reservation on error in hugetlb folio copy paths - mmc: core: Fix host controller programming for fixed driver type - mmc: dw_mmc-rockchip: Add missing private data for very old controllers - mmc: litex_mmc: Set mandatory idle clocks before CMD0 - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC - mmc: sdhci: add signal voltage switch in sdhci_resume_host - pmdomain: imx: fix OF node refcount - rtase: Avoid sleeping in get_stats64() - rtase: Reset TX subqueue when clearing TX ring - sctp: diag: reject stale associations in dump_one path - sctp: stream: fully roll back denied add-stream state - [amd64] thunderbolt: Reject zero-length property entries in validator - [amd64] thunderbolt: Bound root directory content to block size - [amd64] thunderbolt: Clamp XDomain response data copy to allocation size - [amd64] thunderbolt: Validate XDomain request packet size before type cast - [amd64] thunderbolt: Limit XDomain response copy to actual frame size - [arm64] slimbus: qcom-ngd-ctrl: fix OF node refcount - [arm64] slimbus: qcom-ngd-ctrl: Fix up platform_driver registration - [arm64] slimbus: qcom-ngd-ctrl: Fix probe error path ordering - [arm64] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd - [arm64] slimbus: qcom-ngd-ctrl: Initialize controller resources in controller - [arm64] slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership - [arm64] slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD - [arm64] slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock - drm/amdkfd: fix NULL dereference in get_queue_ids() - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 - drm/xe: Clear pending_disable before signaling suspend fence - [arm64,armhf] drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups - drm/amdgpu: restart the CS if some parts of the VM are still invalidated - drm/amd/pm: fix smu13 power limit default/cap calculation - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range - drm/amd/display: Bound VBIOS record-chain walk loops - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs - drm/amd/display: Use krealloc_array() in dal_vector_reserve() - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling - driver core: reject devices with unregistered buses - mailbox: Fix NULL message support in mbox_send_message() - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf - sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() - netfilter: nft_fib: fix stale stack leak via the OIFNAME register - mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper - RDMA/umem: Move umem dmabuf revoke logic into helper function - RDMA/umem: Add helpers for umem dmabuf revoke lock - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible - RDMA/umem: fix kernel-doc warnings - RDMA: Move DMA block iterator logic into dedicated files - RDMA/umem: Fix truncation for block sizes >= 4G - mm/hugetlb: avoid false positive lockdep assertion - mptcp: fix missing wakeups in edge scenarios - ipmi:ssif: Remove unnecessary indention - ipmi:ssif: NULL thread on error - ipvs: skip ipv6 extension headers for csum checks (CVE-2026-45850) - vsock/virtio: fix potential unbounded skb queue - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc - block: fix handling of dead zone write plugs - [arm64] cputype: Add NVIDIA Olympus definitions - [arm64] cputype: Add C1-Ultra definitions - [arm64] cputype: Add C1-Premium definitions - [arm64] errata: Mitigate TLBI errata on various Arm CPUs - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU - net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() - tcp: use EXPORT_IPV6_MOD[_GPL]() - tcp: secure_seq: add back ports to TS offset (CVE-2026-23247) - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation - vsock/virtio: fix skb overhead overflow on 32-bit builds - netfilter: require Ethernet MAC header before using eth_hdr() . [ Salvatore Bonaccorso ] * [rt] Refresh "ARM: enable irq in translation/section permission fault" * ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909) linux (6.12.90-2) trixie-security; urgency=high . * smb: client: reject userspace cifs.spnego descriptions * net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) linux (6.12.90-2~bpo12+1) bookworm-backports; urgency=high . * Rebuild for bookworm-backports . linux (6.12.90-2) trixie-security; urgency=high . * smb: client: reject userspace cifs.spnego descriptions * net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) linux (6.12.90-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.89 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.90 - HID: playstation: Clamp num_touch_reports - media: uvcvideo: Enable VB2_DMABUF for metadata stream - [arm64] dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd & gpio pinmux - [arm64] regulator: mt6357: fix OF node reference imbalance - [arm64,armhf] regulator: rk808: fix OF node reference imbalance - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap - [amd64] media: intel/ipu6: fix error pointer dereference - media: saa7164: add ioremap return checks and cleanups - spi: aspeed-smc: fix controller deregistration - [amd64] platform/x86: hp-wmi: Ignore backlight and FnLock events - vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy - [arm64] drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() - [amd64] drm/i915/psr: Init variable to avoid early exit from et alignment loop - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count. - drm/amdgpu: gate VM CPU HDP flush on reset lock - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x - drm/amdkfd: Add upper bound check for num_of_nodes - drm/amdgpu: Add bounds checking to ib_{get,set}_value - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB - drm/amdgpu/vce: Prevent partial address patches - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg - drm/amd/display: Change dither policy for 10 bpc output back to dithering - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() - drm/amdkfd: validate SVM ioctl nattr against buffer size - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() - drm/radeon: add missing revision check for CI - drm/amdgpu: zero-initialize GART table on allocation - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds - drm/amdkfd: Make all TLB-flushes heavy-weight - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission - drm/amdgpu/pm: add missing revision check for CI - drm/amdgpu/pm: align Hawaii mclk workaround with radeon - [arm64] dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL - batman-adv: fix integer overflow on buff_pos - batman-adv: reject new tp_meter sessions during teardown - batman-adv: stop caching unowned originator pointers in BAT IV - batman-adv: bla: prevent use-after-free when deleting claims - batman-adv: bla: only purge non-released claims - batman-adv: bla: put backbone reference on failed claim hash insert - usb: typec: tcpm: reset internal port states on soft reset AMS - usb: dwc3: Move GUID programming after PHY initialization - ALSA: hda: cs35l56: Propagate ASP TX source control errors - ALSA: misc: Use guard() for spin locks - ALSA: core: Serialize deferred fasync state checks - ALSA: seq: Notify client and port info changes - ALSA: seq: Fix UMP group 16 filtering - Bluetooth: hci_conn: fix potential UAF in create_big_sync - [arm64,armhf] spi: tegra20-sflash: fix controller deregistration - [arm64,armhf] spi: tegra114: fix controller deregistration - mm/hugetlb_cma: round up per_node before logging it - block: cleanup blkdev_report_zones() - block: reorganize struct blk_zone_wplug - block: fix zone write plug removal - tracefs: Fix default permissions not being applied on initial mount - fbcon: Avoid OOB font access if console rotation fails - mm/damon/core: disallow time-quota setting zero esz - mm/damon/core: implement damon_kdamond_pid() - mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values - mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values - bonding: fix use-after-free due to enslave fail after slave array update (CVE-2026-23171) - io_uring/kbuf: support min length left for incremental buffers - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() - btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() - btrfs: fix double free in create_space_info_sub_group() error path - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak - tracing/probes: Limit size of event probe to 3K - batman-adv: stop tp_meter sessions during mesh teardown - batman-adv: tp_meter: fix tp_num leak on kmalloc failure - vsock: fix buffer size clamping order - vsock/virtio: fix length and offset in tap skb for split packets - vsock/virtio: fix empty payload in tap skb for non-linear buffers - vsock/virtio: fix accept queue count leak on transport mismatch - drm/amdgpu/vcn3: Avoid overflow on msg bound check - drm/amdgpu/vcn4: Avoid overflow on msg bound check . [ Salvatore Bonaccorso ] * Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Closes: #1136790) * net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300) * net: skbuff: propagate shared-frag marker through frag-transfer helpers linux (6.12.90-1~bpo12+1) bookworm-backports; urgency=high . * Rebuild for bookworm-backports . linux (6.12.90-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.89 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.90 - HID: playstation: Clamp num_touch_reports - media: uvcvideo: Enable VB2_DMABUF for metadata stream - [arm64] dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd & gpio pinmux - [arm64] regulator: mt6357: fix OF node reference imbalance - [arm64,armhf] regulator: rk808: fix OF node reference imbalance - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap - [amd64] media: intel/ipu6: fix error pointer dereference - media: saa7164: add ioremap return checks and cleanups - spi: aspeed-smc: fix controller deregistration - [amd64] platform/x86: hp-wmi: Ignore backlight and FnLock events - vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy - [arm64] drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() - [amd64] drm/i915/psr: Init variable to avoid early exit from et alignment loop - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count. - drm/amdgpu: gate VM CPU HDP flush on reset lock - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x - drm/amdkfd: Add upper bound check for num_of_nodes - drm/amdgpu: Add bounds checking to ib_{get,set}_value - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB - drm/amdgpu/vce: Prevent partial address patches - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg - drm/amd/display: Change dither policy for 10 bpc output back to dithering - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() - drm/amdkfd: validate SVM ioctl nattr against buffer size - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() - drm/radeon: add missing revision check for CI - drm/amdgpu: zero-initialize GART table on allocation - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds - drm/amdkfd: Make all TLB-flushes heavy-weight - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission - drm/amdgpu/pm: add missing revision check for CI - drm/amdgpu/pm: align Hawaii mclk workaround with radeon - [arm64] dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL - batman-adv: fix integer overflow on buff_pos - batman-adv: reject new tp_meter sessions during teardown - batman-adv: stop caching unowned originator pointers in BAT IV - batman-adv: bla: prevent use-after-free when deleting claims - batman-adv: bla: only purge non-released claims - batman-adv: bla: put backbone reference on failed claim hash insert - usb: typec: tcpm: reset internal port states on soft reset AMS - usb: dwc3: Move GUID programming after PHY initialization - ALSA: hda: cs35l56: Propagate ASP TX source control errors - ALSA: misc: Use guard() for spin locks - ALSA: core: Serialize deferred fasync state checks - ALSA: seq: Notify client and port info changes - ALSA: seq: Fix UMP group 16 filtering - Bluetooth: hci_conn: fix potential UAF in create_big_sync - [arm64,armhf] spi: tegra20-sflash: fix controller deregistration - [arm64,armhf] spi: tegra114: fix controller deregistration - mm/hugetlb_cma: round up per_node before logging it - block: cleanup blkdev_report_zones() - block: reorganize struct blk_zone_wplug - block: fix zone write plug removal - tracefs: Fix default permissions not being applied on initial mount - fbcon: Avoid OOB font access if console rotation fails - mm/damon/core: disallow time-quota setting zero esz - mm/damon/core: implement damon_kdamond_pid() - mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values - mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values - bonding: fix use-after-free due to enslave fail after slave array update (CVE-2026-23171) - io_uring/kbuf: support min length left for incremental buffers - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() - btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() - btrfs: fix double free in create_space_info_sub_group() error path - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak - tracing/probes: Limit size of event probe to 3K - batman-adv: stop tp_meter sessions during mesh teardown - batman-adv: tp_meter: fix tp_num leak on kmalloc failure - vsock: fix buffer size clamping order - vsock/virtio: fix length and offset in tap skb for split packets - vsock/virtio: fix empty payload in tap skb for non-linear buffers - vsock/virtio: fix accept queue count leak on transport mismatch - drm/amdgpu/vcn3: Avoid overflow on msg bound check - drm/amdgpu/vcn4: Avoid overflow on msg bound check . [ Salvatore Bonaccorso ] * Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Closes: #1136790) * net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300) * net: skbuff: propagate shared-frag marker through frag-transfer helpers linux (6.12.88-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.87 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.88 - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() - ipmi: Add limits to event and receive message requests - ipmi: Check event message buffer response for bad data - ipmi:si: Return state to normal if message allocation fails - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free - ACPI: scan: Use acpi_dev_put() in object add error paths - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug - ACPI: video: force native backlight on HP OMEN 16 (8A44) - ASoC: SOF: Don't allow pointer operations on unconfigured streams - spi: rockchip: fix controller deregistration - ksmbd: rewrite stop_sessions() with restartable iteration - mm: convert mm_lock_seq to a proper seqcount - [amd64] x86: shadow stacks: proper error handling for mmap lock (CVE-2026-43109) - [amd64] x86/shstk: Prevent deadlock during shstk sigreturn - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected GFN - [amd64] iommu/amd: Use atomic64_inc_return() in iommu.c - [amd64] iommu/amd: serialize sequence allocation under concurrent TLB invalidations (CVE-2026-43220) (Closes: #1135313) - flow_dissector: do not dissect PPPoE PFC frames - net: txgbe: fix RTNL assertion warning when remove module - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) - [amd64] KVM: SVM: check validity of VMCB controls when returning from SMM - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (CVE-2026-31499) - exit: prevent preemption of oopsing TASK_DEAD task - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr - wifi: mt76: mt7925: fix incorrect length field in txpower command - wifi: mt76: mt7921: fix a potential clc buffer length underflow - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work - wifi: b43legacy: enforce bounds check on firmware key index in RX path - wifi: mac80211: drop stray 'static' from fast-RX rx_result - wifi: rsi: fix kthread lifetime race between self-exit and external-stop - wifi: mac80211: use safe list iteration in radar detect work - wifi: ath5k: do not access array OOB (Closes: #1119093) - wifi: mac80211: remove station if connection prep fails - wifi: b43: enforce bounds check on firmware key index in b43_rx() - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task - usb: usblp: fix heap leak in IEEE 1284 device ID via short response - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl - ALSA: usb-audio: midi2: Restart output URBs on resume - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() - ALSA: usb-audio: Fix UAC3 cluster descriptor size check - USB: omap_udc: DMA: Don't enable burst 4 mode - USB: serial: option: add Telit Cinterion LE910Cx compositions - usb: ulpi: fix memory leak on ulpi_register() error paths - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger - ALSA: firewire-tascam: Do not drop unread control events - xfrm: provide message size for XFRM_MSG_MAPPING - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() - xfrm: ah: account for ESN high bits in async callbacks - selinux: don't reserve xattr slot when we won't fill it - selinux: shrink critical section in sel_write_load() - selinux: prune /sys/fs/selinux/disable - Bluetooth: virtio_bt: clamp rx length before skb_put - Bluetooth: virtio_bt: validate rx pkt_type header length - Bluetooth: btmtk: validate WMT event SKB length before struct access - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() - [armhf] spi: sun4i: fix controller deregistration - [armhf] spi: ti-qspi: fix controller deregistration - spi: sun6i: fix controller deregistration - fanotify: fix false positive on permission events - [arm64] KVM: arm64: Fix kvm_vcpu_initialized() macro parameter - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo - sound: ua101: fix division by zero at probe - net: libwx: fix VF illegal register access - ip6_gre: Use cached t->net in ip6erspan_changelink(). - net/rds: handle zerocopy send cleanup before the message is queued - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler - hwmon: (ltc2992) Clamp threshold writes to hardware range - hwmon: (ltc2992) Fix u32 overflow in power read path - clk: rk808: fix OF node reference imbalance - hwmon: (corsair-psu) Close HID device on probe errors - af_unix: Reject SIOCATMARK on non-stream sockets - block: add pgmap check to biovec_phys_mergeable - cifs: abort open_cached_dir if we don't request leases - cifs: change_conf needs to be called for session setup - extcon: ptn5150: handle pending IRQ events during system resume - gpio: of: clear OF_POPULATED on hog nodes in remove path - hv_sock: fix ARM64 support - ibmveth: Disable GSO for packets with small MSS - ice: fix double free in ice_sf_eth_activate() error path - spi: microchip-core-qspi: fix controller deregistration - udf: reject descriptors with oversized CRC length - thermal: core: Free thermal zone ID later during removal - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp - spi: topcliff-pch: fix controller deregistration - spi: topcliff-pch: fix use-after-free on unbind - clk: imx: imx8-acm: fix flags for acm clocks - clk: microchip: mpfs-ccc: fix out of bounds access during output registration - cpuidle: powerpc: avoid double clear when breaking snooze - [amd64] ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table - [arm64] ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop - [arm64] ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens - [arm64] ASoC: qcom: q6apm: remove child devices when apm is removed - btrfs: fix double free in create_space_info() error path - dm-thin: fix metadata refcount underflow - dm: don't report warning when doing deferred remove - dm: fix a buffer overflow in ioctl processing - eventfs: Hold eventfs_mutex and SRCU when remount walks events - dm-verity-fec: correctly reject too-small FEC devices - dm-verity-fec: correctly reject too-small hash devices - isofs: validate Rock Ridge CE continuation extent against volume size - isofs: validate block number from NFS file handle in isofs_export_iget - [arm64] iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() - lib/scatterlist: fix length calculations in extract_kvec_to_sg - lib/scatterlist: fix temp buffer in extract_user_to_sg() - libceph: Fix slab-out-of-bounds access in auth message processing - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies - nvme-apple: drop invalid put of admin queue reference count - nvmet-tcp: fix race between ICReq handling and queue teardown - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free - openvswitch: vport: fix self-deadlock on release of tunnel ports - pmdomain: core: Fix detach procedure for virtual devices in genpd - [arm64] RDMA/hns: Fix unlocked call to hns_roce_qp_remove() - [s390x] debug: Reject zero-length input in debug_input_flush_fn() - smb/client: fix out-of-bounds read in smb2_compound_op() - smb/client: fix out-of-bounds read in symlink_data() - smb: client: use kzalloc to zero-initialize security descriptor buffer - smb: client: validate dacloffset before building DACL pointers - [amd64] KVM: x86: check for nEPT/nNPT in slow flush hypercalls - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock - PCI: Update saved_config_space upon resource assignment (Closes: #1131025) - PCI/AER: Clear only error bits in PCIe Device Status - PCI/AER: Stop ruling out unbound devices as error source - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage - power: supply: max17042: avoid overflow when determining health - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() - RDMA/mana: Validate rx_hash_key_len - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads - RDMA/rxe: Reject unknown opcodes before ICRC processing - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path - mptcp: fastclose msk when linger time is 0 - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure - mptcp: sockopt: set timestamp flags on subflow socket, not msk - mptcp: fix scheduling with atomic in timestamp sockopt - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() - f2fs: fix fiemap boundary handling when read extent cache is incomplete - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() - f2fs: fix node_cnt race between extent node destroy and writeback - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() - [arm64] KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value - [arm64] KVM: arm64: Fix initialisation order in __pkvm_init_finalise() - bpf: Fix use-after-free in arena_vm_close on fork - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info - fs: prepare for adding LSM blob to backing_file - dma-mapping: drop unneeded includes from dma-mapping.h - dma-mapping: add __dma_from_device_group_begin()/end() - hwmon: (powerz) Avoid cacheline sharing for DMA buffer - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs - udf: fix partition descriptor append bookkeeping - mtd: spinand: winbond: Declare the QE bit on W25NxxJW - hfsplus: fix uninit-value by validating catalog record size - hfsplus: fix held lock freed on hfsplus_fill_super() - erofs: move {in,out}pages into struct z_erofs_decompress_req - erofs: tidy up z_erofs_lz4_handle_overlap() - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() - gtp: disable BH before calling udp_tunnel_xmit_skb() - printk: add print_hex_dump_devel() - crypto: caam - guard HMAC key hex dumps in hash_digest_key - ALSA: aloop: Fix peer runtime UAF during format-change stop - net: stmmac: avoid shadowing global buf_sz - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() - net: stmmac: Prevent NULL deref when RX memory exhausted - wifi: mt76: mt7925: fix incorrect TLV length in CLC command - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() - [arm64] KVM: arm64: Wake-up from WFI when iqrchip is in userspace - [amd64] x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache - ksmbd: validate inherited ACE SID length . [ Salvatore Bonaccorso ] * ptrace: slightly saner 'get_dumpable()' logic linux (6.12.88-1~bpo12+1) bookworm-backports; urgency=high . * Rebuild for bookworm-backports . linux (6.12.88-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.87 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.88 - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() - ipmi: Add limits to event and receive message requests - ipmi: Check event message buffer response for bad data - ipmi:si: Return state to normal if message allocation fails - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free - ACPI: scan: Use acpi_dev_put() in object add error paths - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug - ACPI: video: force native backlight on HP OMEN 16 (8A44) - ASoC: SOF: Don't allow pointer operations on unconfigured streams - spi: rockchip: fix controller deregistration - ksmbd: rewrite stop_sessions() with restartable iteration - mm: convert mm_lock_seq to a proper seqcount - [amd64] x86: shadow stacks: proper error handling for mmap lock (CVE-2026-43109) - [amd64] x86/shstk: Prevent deadlock during shstk sigreturn - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected GFN - [amd64] iommu/amd: Use atomic64_inc_return() in iommu.c - [amd64] iommu/amd: serialize sequence allocation under concurrent TLB invalidations (CVE-2026-43220) (Closes: #1135313) - flow_dissector: do not dissect PPPoE PFC frames - net: txgbe: fix RTNL assertion warning when remove module - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) - [amd64] KVM: SVM: check validity of VMCB controls when returning from SMM - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (CVE-2026-31499) - exit: prevent preemption of oopsing TASK_DEAD task - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr - wifi: mt76: mt7925: fix incorrect length field in txpower command - wifi: mt76: mt7921: fix a potential clc buffer length underflow - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work - wifi: b43legacy: enforce bounds check on firmware key index in RX path - wifi: mac80211: drop stray 'static' from fast-RX rx_result - wifi: rsi: fix kthread lifetime race between self-exit and external-stop - wifi: mac80211: use safe list iteration in radar detect work - wifi: ath5k: do not access array OOB (Closes: #1119093) - wifi: mac80211: remove station if connection prep fails - wifi: b43: enforce bounds check on firmware key index in b43_rx() - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task - usb: usblp: fix heap leak in IEEE 1284 device ID via short response - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl - ALSA: usb-audio: midi2: Restart output URBs on resume - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() - ALSA: usb-audio: Fix UAC3 cluster descriptor size check - USB: omap_udc: DMA: Don't enable burst 4 mode - USB: serial: option: add Telit Cinterion LE910Cx compositions - usb: ulpi: fix memory leak on ulpi_register() error paths - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger - ALSA: firewire-tascam: Do not drop unread control events - xfrm: provide message size for XFRM_MSG_MAPPING - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() - xfrm: ah: account for ESN high bits in async callbacks - selinux: don't reserve xattr slot when we won't fill it - selinux: shrink critical section in sel_write_load() - selinux: prune /sys/fs/selinux/disable - Bluetooth: virtio_bt: clamp rx length before skb_put - Bluetooth: virtio_bt: validate rx pkt_type header length - Bluetooth: btmtk: validate WMT event SKB length before struct access - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() - [armhf] spi: sun4i: fix controller deregistration - [armhf] spi: ti-qspi: fix controller deregistration - spi: sun6i: fix controller deregistration - fanotify: fix false positive on permission events - [arm64] KVM: arm64: Fix kvm_vcpu_initialized() macro parameter - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo - sound: ua101: fix division by zero at probe - net: libwx: fix VF illegal register access - ip6_gre: Use cached t->net in ip6erspan_changelink(). - net/rds: handle zerocopy send cleanup before the message is queued - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler - hwmon: (ltc2992) Clamp threshold writes to hardware range - hwmon: (ltc2992) Fix u32 overflow in power read path - clk: rk808: fix OF node reference imbalance - hwmon: (corsair-psu) Close HID device on probe errors - af_unix: Reject SIOCATMARK on non-stream sockets - block: add pgmap check to biovec_phys_mergeable - cifs: abort open_cached_dir if we don't request leases - cifs: change_conf needs to be called for session setup - extcon: ptn5150: handle pending IRQ events during system resume - gpio: of: clear OF_POPULATED on hog nodes in remove path - hv_sock: fix ARM64 support - ibmveth: Disable GSO for packets with small MSS - ice: fix double free in ice_sf_eth_activate() error path - spi: microchip-core-qspi: fix controller deregistration - udf: reject descriptors with oversized CRC length - thermal: core: Free thermal zone ID later during removal - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp - spi: topcliff-pch: fix controller deregistration - spi: topcliff-pch: fix use-after-free on unbind - clk: imx: imx8-acm: fix flags for acm clocks - clk: microchip: mpfs-ccc: fix out of bounds access during output registration - cpuidle: powerpc: avoid double clear when breaking snooze - [amd64] ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table - [arm64] ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop - [arm64] ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens - [arm64] ASoC: qcom: q6apm: remove child devices when apm is removed - btrfs: fix double free in create_space_info() error path - dm-thin: fix metadata refcount underflow - dm: don't report warning when doing deferred remove - dm: fix a buffer overflow in ioctl processing - eventfs: Hold eventfs_mutex and SRCU when remount walks events - dm-verity-fec: correctly reject too-small FEC devices - dm-verity-fec: correctly reject too-small hash devices - isofs: validate Rock Ridge CE continuation extent against volume size - isofs: validate block number from NFS file handle in isofs_export_iget - [arm64] iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() - lib/scatterlist: fix length calculations in extract_kvec_to_sg - lib/scatterlist: fix temp buffer in extract_user_to_sg() - libceph: Fix slab-out-of-bounds access in auth message processing - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies - nvme-apple: drop invalid put of admin queue reference count - nvmet-tcp: fix race between ICReq handling and queue teardown - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free - openvswitch: vport: fix self-deadlock on release of tunnel ports - pmdomain: core: Fix detach procedure for virtual devices in genpd - [arm64] RDMA/hns: Fix unlocked call to hns_roce_qp_remove() - [s390x] debug: Reject zero-length input in debug_input_flush_fn() - smb/client: fix out-of-bounds read in smb2_compound_op() - smb/client: fix out-of-bounds read in symlink_data() - smb: client: use kzalloc to zero-initialize security descriptor buffer - smb: client: validate dacloffset before building DACL pointers - [amd64] KVM: x86: check for nEPT/nNPT in slow flush hypercalls - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock - PCI: Update saved_config_space upon resource assignment (Closes: #1131025) - PCI/AER: Clear only error bits in PCIe Device Status - PCI/AER: Stop ruling out unbound devices as error source - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage - power: supply: max17042: avoid overflow when determining health - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() - RDMA/mana: Validate rx_hash_key_len - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads - RDMA/rxe: Reject unknown opcodes before ICRC processing - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path - mptcp: fastclose msk when linger time is 0 - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure - mptcp: sockopt: set timestamp flags on subflow socket, not msk - mptcp: fix scheduling with atomic in timestamp sockopt - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() - f2fs: fix fiemap boundary handling when read extent cache is incomplete - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() - f2fs: fix node_cnt race between extent node destroy and writeback - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() - [arm64] KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value - [arm64] KVM: arm64: Fix initialisation order in __pkvm_init_finalise() - bpf: Fix use-after-free in arena_vm_close on fork - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info - fs: prepare for adding LSM blob to backing_file - dma-mapping: drop unneeded includes from dma-mapping.h - dma-mapping: add __dma_from_device_group_begin()/end() - hwmon: (powerz) Avoid cacheline sharing for DMA buffer - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs - udf: fix partition descriptor append bookkeeping - mtd: spinand: winbond: Declare the QE bit on W25NxxJW - hfsplus: fix uninit-value by validating catalog record size - hfsplus: fix held lock freed on hfsplus_fill_super() - erofs: move {in,out}pages into struct z_erofs_decompress_req - erofs: tidy up z_erofs_lz4_handle_overlap() - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() - gtp: disable BH before calling udp_tunnel_xmit_skb() - printk: add print_hex_dump_devel() - crypto: caam - guard HMAC key hex dumps in hash_digest_key - ALSA: aloop: Fix peer runtime UAF during format-change stop - net: stmmac: avoid shadowing global buf_sz - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() - net: stmmac: Prevent NULL deref when RX memory exhausted - wifi: mt76: mt7925: fix incorrect TLV length in CLC command - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() - [arm64] KVM: arm64: Wake-up from WFI when iqrchip is in userspace - [amd64] x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache - ksmbd: validate inherited ACE SID length . [ Salvatore Bonaccorso ] * ptrace: slightly saner 'get_dumpable()' logic linux-signed-amd64 (6.12.94+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.94-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.91 - io_uring/kbuf: use mem_is_zero() - blk-cgroup: wait for blkcg cleanup before initializing new disk - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START - fs/mbcache: cancel shrink work before destroying the cache - md/raid1: fix the comparing region of interval tree - drbd: Balance RCU calls in drbd_adm_dump_devices() - loop: fix partition scan race between udev and loop_reread_partitions() - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() - blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() - pstore/ram: fix resource leak when ioremap() fails - md: wake raid456 reshape waiters before suspend - btrfs: pass struct btrfs_inode to clone_copy_inline_extent() - btrfs: fix deadlock between reflink and transaction commit when using flushoncommit - [amd64] ACPI: x86: cmos_rtc: Clean up address space handler driver - [amd64] ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver - devres: fix missing node debug info in devm_krealloc() - thermal/drivers/spear: Fix error condition for reading st,thermal-flags - debugfs: check for NULL pointer in debugfs_create_str() - debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() - soundwire: debugfs: initialize firmware_file to empty string - PCI: use generic driver_override infrastructure - platform/wmi: use generic driver_override infrastructure - [s390x] cio: use generic driver_override infrastructure - bus: fsl-mc: use generic driver_override infrastructure - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter - hrtimers: Update the return type of enqueue_hrtimer() - hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() - hrtimer: Reduce trace noise in hrtimer_start() - locking: Fix rwlock support in - firmware: dmi: Correct an indexing error in dmi.h - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet - bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n - [s390x] bpf: Zero-extend bpf prog return values and kfunc arguments - params: Replace __modinit with __init_or_module - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() - wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control - wifi: mt76: mt7615: fix use_cts_prot support - wifi: mt76: mt7915: fix use_cts_prot support - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() - wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor - wifi: mt76: mt7921: Place upper limit on station AID - [arm64] cpufeature: Make PMUVer and PerfMon unsigned - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() - wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() - wifi: mt76: mt7921: fix 6GHz regulatory update on connection - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path - bpf: Fix variable length stack write over spilled pointers - bpf,arc_jit: Fix missing newline in pr_err messages - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() - r8152: fix incorrect register write to USB_UPHY_XTAL - [powerpc*] crash: fix backup region offset update to elfcorehdr - [powerpc*] crash: Update backup region offset in elfcorehdr on memory hotplug - macvlan: annotate data-races around port->bc_queue_len_used - bpf: fix end-of-list detection in cgroup_storage_get_next_key() - bpf: Fix stale offload->prog pointer after constant blinding - wifi: brcmfmac: Fix error pointer dereference - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() - wifi: ath10k: fix station lookup failure during disconnect - ACPI: AGDI: fix missing newline in error message - [arm64] kexec: Remove duplicate allocation for trans_pgd - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb - net: bcmgenet: add bcmgenet_has_* helpers - net: bcmgenet: move DESC_INDEX flow to ring 0 - net: bcmgenet: support reclaiming unsent Tx packets - net: bcmgenet: switch to use 64bit statistics - net: bcmgenet: fix racing timeout handler - eth: fbnic: Use wake instead of start - netfilter: xt_socket: enable defrag after all other checks - netfilter: nft_fwd_netdev: check ttl/hl before forwarding - bpf: fix mm lifecycle in open-coded task_vma iterator - bpf: switch task_vma iterator from mmap_lock to per-VMA locks - bpf: return VMA snapshot from task_vma iterator - bpf: Fix RCU stall in bpf_fd_array_map_clear() - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf - bpf: Relax scalar id equivalence for state pruning - bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars - net/sched: act_ct: Only release RCU read lock after ct_ft - net: airoha: Implement BQL support - net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() - bpf: Allow instructions with arena source and non-arena dest registers - net/rds: Optimize rds_ib_laddr_check - net/rds: Restrict use of RDS/IB to the initial network namespace - bpf: Fix OOB in pcpu_init_value - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls - net: ipa: Fix programming of QTIME_TIMESTAMP_CFG - net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ - dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 - net: phy: fix a return path in get_phy_c45_ids() - net/mlx5e: Fix features not applied during netdev registration - net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp - Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec - net: phy: qcom: at803x: Use the correct bit to disable extended next page - ipv4: udp: fix typos in comments - ipv6: udp: fix typos in comments - udp: Force compute_score to always inline - tcp: Don't set treq->req_usec_ts in cookie_tcp_reqsk_init(). - sctp: fix missing encap_port propagation for GSO fragments - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master - drm/komeda: fix integer overflow in AFBC framebuffer size check - ASoC: SOF: ipc3: Use standard dev_dbg API - ASoC: add symmetric_ prefix for dai->rate/channels/sample_bits - ASoC: soc-compress: use function to clear symmetric params - drm/sun4i: backend: fix error pointer dereference - ASoC: sti: Return errors from regmap_field_alloc() - ASoC: sti: use managed regmap_field allocations - dm cache: fix null-deref with concurrent writes in passthrough mode - dm cache: fix write path cache coherency in passthrough mode - dm cache: fix write hang in passthrough mode - dm cache policy smq: fix missing locks in invalidating cache blocks - dm cache: fix concurrent write failure in passthrough mode - dm cache: support shrinking the origin device - dm cache: fix dirty mapping checking in passthrough mode switching - platform/chrome: chromeos_tbmc: Drop wakeup source on remove - PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding - PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() - dm cache metadata: fix memory leak on metadata abort retry - dm log: fix out-of-bounds write due to region_count overflow - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check - spi: spi-nxp-fspi: enable runtime pm for fspi - spi: nxp-fspi: Use reinit_completion() for repeated operations - spi: fsl-qspi: Use reinit_completion() for repeated operations - media: i2c: og01a1b: Replace client->dev usage - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe - drm/v3d: Handle error from drm_sched_entity_init() - drm/sun4i: Fix resource leaks - drm/amdgpu: Add default case in DVI mode validation - dm init: ensure device probing has finished in dm-mod.waitfor= - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break - crypto: tegra - finalize crypto req on error - crypto: tegra - Transfer HASH init function to crypto engine - crypto: tegra - Reserve keyslots to allocate dynamically - crypto: tegra - Disable softirqs before finalizing request - crypto: atmel - Use unregister_{aeads,ahashes,skciphers} - crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs - padata: Remove cpu online check from cpu add and removal - padata: Put CPU offline callback in ONLINE section to allow failure - PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation - drm/amdgpu/gfx10: look at the right prop for gfx queue priority - drm/amdgpu/gfx11: look at the right prop for gfx queue priority - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo - drm/imagination: Switch reset_reason fields from enum to u32 - iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() - [arm64] drm/msm/dpu: fix mismatch between power and frequency - [arm64] drm/msm/dsi: add the missing parameter description - [arm64] drm/msm/dsi: fix bits_per_pclk - [arm64] drm/msm/dsi: fix hdisplay calculation for CMD mode panel - [arm64] drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first - drm/panel: simple: Correct G190EAN01 prepare timing - PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support - ALSA: core: Validate compress device numbers without dynamic minors - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels - drm/amd/pm/ci: Fill DW8 fields from SMC - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board - drm/amdgpu: add amdgpu_device reference in ip block - drm/amdgpu: update the handle ptr in dump_ip_state - drm/amdgpu: update the handle ptr in early_init - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled - hwmon: Switch back to struct platform_driver::remove() - hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') - [amd64] ASoC: SOF: Intel: hda: Place check before dereference - [arm64] drm/msm/a6xx: Fix HLSQ register dumping - [arm64] drm/msm/shrinker: Fix can_block() logic - [arm64] drm/msm/a6xx: Fix dumping A650+ debugbus blocks - [arm64] drm/msm/a6xx: Use barriers while updating HFI Q headers - pmdomain: ti: omap_prm: Fix a reference leak on device node - pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() - PM: domains: De-constify fields in struct dev_pm_domain_attach_data - ASoC: fsl_micfil: Add access property for "VAD Detected" - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() - ASoC: fsl_easrc: Change the type for iec958 channel status controls - [amd64] iommu/amd: Remove protection_domain.dev_cnt variable - [amd64] iommu/amd: xarray to track protection_domain->iommu list - [amd64] iommu/amd: Do not detach devices in domain free path - [amd64] iommu/amd: Reduce domain lock scope in attach device path - [amd64] iommu/amd: Rearrange attach device code - [amd64] iommu/amd: Convert dev_data lock from spinlock to mutex - [amd64] iommu/amd: Introduce helper function to update 256-bit DTE - [amd64] iommu/amd: Introduce helper function get_dte256() - [amd64] iommu/amd: Fix clone_alias() to use the original device's devid - [arm64] ASoC: qcom: qdsp6: topology: check widget type before accessing data - crypto: qat - introduce fuse array - crypto: qat - disable 4xxx AE cluster when lead engine is fused off - crypto: qat - disable 420xx AE cluster when lead engine is fused off - crypto: qat - fix type mismatch in RAS sysfs show functions - crypto: qat - use swab32 macro - ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] - PCI: Enable AtomicOps only if Root Port supports them - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found - Documentation: fix a hugetlbfs reservation statement - ALSA: scarlett2: Add missing sentinel initializer field - ASoC: SOF: compress: return the configured codec from get_params - PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports - PCI: tegra194: Fix polling delay for L2 state - PCI: tegra194: Increase LTSSM poll time on surprise link down - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down - PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() - PCI: tegra194: Don't force the device into the D0 state before L2 - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" - PCI: tegra194: Disable direct speed change for Endpoint mode - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode - PCI: tegra194: Allow system suspend when the Endpoint link is not up - PCI: tegra194: Free up Endpoint resources during remove() - PCI: tegra194: Use DWC IP core version - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well - PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback - ALSA: sc6000: Keep the programmed board state in card-private data - dm cache: fix missing return in invalidate_committed's error path - crypto: jitterentropy - replace long-held spinlock with mutex - ALSA: hda/realtek - fixed speaker no sound update - gfs2: Call unlock_new_inode before d_instantiate - net/socket.c: switch to CLASS(fd) - fdget(), trivial conversions - fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() - quota: Fix race of dquot_scan_active() with quota deactivation - gfs2: add some missing log locking - gfs2: prevent NULL pointer dereference during unmount - efi/capsule-loader: fix incorrect sizeof in phys array reallocation - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine - [arm64] dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon - memory: tegra124-emc: Fix dll_change check - memory: tegra30-emc: Fix dll_change check - [arm64] dts: imx8-apalis: Fix LEDs name collision - [arm64] dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config - [arm64] dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) - iommufd: vfio compatibility extension check for noiommu mode - [arm64] dts: mediatek: mt6795: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7981b: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7986a: Fix gpio-ranges pin count - [arm64] dts: qcom: msm8953-xiaomi-vince: correct wled ovp value - [arm64] dts: qcom: msm8953-xiaomi-daisy: fix backlight - [arm64] dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi - [arm64] dts: rockchip: Correct Fan Supply for Gameforce Ace - [arm64] dts: rockchip: Correct Joystick Axes on Gameforce Ace - [arm64] soc: qcom: ocmem: make the core clock optional - [arm64] soc: qcom: ocmem: register reasons for probe deferrals - [arm64] soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available - bus: rifsc: fix RIF configuration check for peripherals - [arm64] dts: qcom: sm8450: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix GIC_ITS range length - [arm64] dts: qcom: sm8650: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix xo clock supply of platform SD host controller - [arm64] dts: qcom: sm8650: Fix xo clock supply of SD host controller - [arm64] dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl - [arm64] dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot - [arm64] dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins - [arm64] dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins - [arm64] dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label - [arm64] dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing - [arm64] dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit - [arm64] dts: lx2160a: remove duplicate pinmux nodes - [arm64] dts: lx2160a: rename pinmux nodes for readability - [arm64] dts: lx2160a: add sda gpio references for i2c bus recovery - [arm64] dts: lx2160a: change zeros to hexadecimal in pinmux nodes - [arm64] dts: lx2160a: complete pinmux for rcwsr12 configuration word - [arm64] dts: imx8qm-mek: switch Type-C connector power-role to dual - [arm64] dts: imx8qxp-mek: switch Type-C connector power-role to dual - soc/tegra: cbb: Set ERD on resume for err interrupt - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure - ocfs2/dlm: validate qr_numregions in dlm_match_regions() - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison - soc: qcom: llcc: fix v1 SB syndrome register offset - [arm64] soc: qcom: aoss: compare against normalized cooling state - [arm64] dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP - [arm64] xor: fix conflicting attributes for xor_block_template - firmware: arm_ffa: Use the correct buffer size during RXTX_MAP - ocfs2: fix listxattr handling when the buffer is full - ocfs2: validate bg_bits during freefrag scan - ocfs2: validate group add input before caching - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() - soundwire: cadence: Clear message complete before signaling waiting thread - tracing: Rebuild full_name on each hist_field_name() call - hte: tegra194: remove Kconfig dependency on Tegra194 SoC - remoteproc: xlnx: Fix sram property parsing - ima: check return value of crypto_shash_final() in boot aggregate - HID: asus: make asus_resume adhere to linux kernel coding standards - HID: asus: do not abort probe when not necessary - mtd: physmap_of_gemini: Fix disabled pinctrl state check - ima_fs: don't bother with removal of files in directory we'll be removing - ima_fs: get rid of lookup-by-dentry stuff - ima_fs: Correctly create securityfs files for unsupported hash algos - dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations - mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook - mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook - mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions - cxl/pci: Check memdev driver binding status in cxl_reset_done() - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob - HID: usbhid: fix deadlock in hid_post_reset() - ext4: fix possible null-ptr-deref in mbt_kunit_exit() - [arm64] bpf, arm64: Fix off-by-one in check_imm signed range check - bpf, sockmap: Fix af_unix iter deadlock - bpf, sockmap: Fix af_unix null-ptr-deref in proto update - bpf, sockmap: Take state lock for af_unix iter - bpf: Fix precedence bug in convert_bpf_ld_abs alignment check - bpf: Fix NULL deref in map_kptr_match_type for scalar regs - bpf: allow UTF-8 literals in bpf_bprintf_prepare() - bpf: Validate node_id in arena_alloc_pages() - bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT - pinctrl: pinctrl-pic32: Fix resource leak - pinctrl: cy8c95x0: remove duplicate error message - pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() - pinctrl: cy8c95x0: Avoid returning positive values to user space - perf branch: Avoid incrementing NULL - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace - pinctrl: realtek: Fix function signature for config argument - pinctrl: abx500: Fix type of 'argument' variable - pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers - perf lock: Fix option value type in parse_max_stack - perf stat: Fix opt->value type for parse_cache_level - perf tools: Fix module symbol resolution for non-zero .text sh_addr - perf expr: Return -EINVAL for syntax error in expr__find_ids() - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure - ipmi: ssif_bmc: fix message desynchronization after truncated response - ipmi: ssif_bmc: change log level to dbg in irq callback - perf evsel: Add alternate_hw_config and use in evsel__match - perf tool_pmu: Factor tool events into their own PMU - perf python: Add parse_events function - perf cgroup: Update metric leader in evlist__expand_cgroup - perf maps: Fix copy_from that can break sorted by name order - perf util: Kill die() prototype, dead for a long time - reset: replace boolean parameters with flags parameter - reset: Add devres helpers to request pre-deasserted reset controls - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() - platform/surface: surfacepro3_button: Drop wakeup source on remove - leds: lgm-sso: Remove duplicate assignments for priv->mmap - tty: hvc_iucv: fix off-by-one in number of supported devices - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() - nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist() - [amd64] platform/x86: asus-wmi: adjust screenpad power/brightness handling - [amd64] platform/x86: asus-wmi: fix screenpad brightness range - tty: serial: ip22zilog: Fix section mispatch warning - fs/ntfs3: terminate the cached volume label after UTF-8 conversion - [amd64] platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() - [amd64] platform/x86: dell-wmi-sysman: bound enumeration string aggregation - RDMA/core: Prefer NLA_NUL_STRING - clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source - scsi: sg: Fix sysctl sg-big-buff register during sg_init() - scsi: sg: Resolve soft lockup issue when opening /dev/sgX - clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers - clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting - scsi: target: core: Fix integer overflow in UNMAP bounds check - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Use retention for USB power domains - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() - clk: imx8mq: Correct the CSI PHY sels - [amd64] x86/um/vdso: Drop VDSO64-y from Makefile - clk: qoriq: avoid format string warning - clk: xgene: Fix mapping leak in xgene_pllclk_init() - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets - clk: qcom: dispcc-sc7180: Add missing MDSS resets - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() - clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON - clk: visconti: pll: initialize clk_init_data to zero - f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() - [amd64] drm/i915: Relocate the SKL wm sanitation code - [amd64] drm/i915/wm: Verify the correct plane DDB entry - crypto: sa2ul - Fix AEAD fallback algorithm names - crypto: ccp - copy IV using skcipher ivsize - erofs: add encoded extent on-disk definition - erofs: do sanity check on m->type in z_erofs_load_compact_lcluster() - erofs: avoid infinite loops due to corrupted subpage compact indexes (CVE-2025-68251) - erofs: unify lcn as u64 for 32-bit platforms - [arm64] dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT - PCMCIA: Fix garbled log messages for KERN_CONT - [arm64] dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT - [arm64] dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names - net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir - macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF - net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys - nexthop: fix IPv6 route referencing IPv4 nexthop - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch - tcp: add data-race annotations around tp->data_segs_out and tp->total_retrans - tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE - tcp: annotate data-races around tp->bytes_sent - tcp: annotate data-races around tp->bytes_retrans - tcp: annotate data-races around tp->dsack_dups - tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) - tcp: annotate data-races around tp->plb_rehash - ice: update PCS latency settings for E825 10G/25Gb modes - ice: Remove jumbo_remove step from TX path - ice: fix double-free of tx_buf skb - ice: fix ICE_AQ_LINK_SPEED_M for 200G - i40e: don't advertise IFF_SUPP_NOFCS - e1000e: Unroll PTP in probe error handling - ipv6: fix possible UAF in icmpv6_rcv() - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks - pppoe: drop PFC frames - net/mlx5: Fix HCA caps leak on notifier init failure - openvswitch: cap upcall PID array size and pre-size vport replies - netfilter: nft_osf: restrict it to ipv4 - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO - netfilter: conntrack: remove sprintf usage - netfilter: xtables: restrict several matches to inet family - ipvs: fix MTU check for GSO packets in tunnel mode - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check - slip: reject VJ receive packets on instances with no rstate array - slip: bound decode() reads against the compressed packet length - [arm64] dts: meson-gxl-p230: fix ethernet PHY interrupt number - pwm: atmel-tcb: Cache clock rates and mark chip as atomic - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() - ksmbd: destroy async_ida in ksmbd_conn_free() - ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open - ksmbd: scope conn->binding slowpath to bound sessions only - net/rds: zero per-item info buffer before handing it to visitors - ice: fix timestamp interrupt configuration for E825C - ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() - net/sched: sch_pie: annotate data-races in pie_dump_stats() - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() - net/sched: sch_red: annotate data-races in red_dump_stats() - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() - net: dsa: realtek: rtl8365mb: fix mode mask calculation - net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() - virtio_net: Split struct virtio_net_rss_config - virtio_net: Fix endian with virtio_net_ctrl_rss - virtio_net: Use new RSS config structs - virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls - tipc: fix double-free in tipc_buf_append() - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() - fs/adfs: validate nzones in adfs_validate_bblk() - rtc: abx80x: Disable alarm feature if no interrupt attached - kbuild: builddeb - avoid recompiles for non-cross-compiles - fbdev: offb: fix PCI device reference leak on probe failure - mailbox: mtk-cmdq: Fix CURR and END addr for task insert case - mailbox: mailbox-test: free channels on probe error - cgroup/rdma: fix integer overflow in rdmacg_try_charge() - mailbox: add sanity check for channel array - mailbox: mailbox-test: don't free the reused channel - mailbox: mailbox-test: initialize struct earlier - mailbox: mailbox-test: make data_ready a per-instance variable - fsnotify: fix inode reference leak in fsnotify_recalc_mask() - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() - cgroup: Increment nr_dying_subsys_* from rmdir context - tracing: branch: Fix inverted check on stat tracer registration - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers - netfilter: arp_tables: fix IEEE1394 ARP payload parsing - nvme-pci: fix missed admin queue sq doorbell write - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG - drm/amdgpu: fix spelling typos - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) - netfilter: xt_policy: fix strict mode inbound policy matching - netfilter: nf_conntrack_sip: don't use simple_strtoul - [amd64] ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ - drm/sysfb: ofdrm: fix PCI device reference leaks - arm64/scs: Fix potential sign extension issue of advance_loc4 - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() - netdevsim: zero initialize struct iphdr in dummy sk_buff - net/sched: netem: fix probability gaps in 4-state loss model - net/sched: netem: fix queue limit check to include reordered packets - net/sched: netem: only reseed PRNG when seed is explicitly provided - net/sched: netem: validate slot configuration - net/sched: netem: fix slot delay calculation overflow - net/sched: netem: check for negative latency and jitter - net/sched: sch_choke: annotate data-races in choke_dump_stats() - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() - vrf: Fix a potential NPD when removing a port from a VRF - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit - NFC: trf7970a: Ignore antenna noise when checking for RF field - net/sched: taprio: fix NULL pointer dereference in class dump - neigh: let neigh_xmit take skb ownership - tcp: make probe0 timer handle expired user timeout - net, treewide: define and use MAC_ADDR_STR_LEN - netconsole: allow selection of egress interface via MAC address - netpoll: Extract carrier wait function - netpoll: extract IPv4 address retrieval into helper function - netpoll: fix IPv6 local-address corruption - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams - sched/fair: Clear rel_deadline when initializing forked entities - net: mctp i2c: check length before marking flow active - net: phy: dp83869: fix setting CLK_O_SEL field. - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring - ASoC: codecs: ab8500: Fix casting of private data - netfilter: skip recording stale or retransmitted INIT - sctp: discard stale INIT after handshake completion - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) - netconsole: propagate device name truncation in dev_name_store() - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 - ALSA: hda/conexant: Fix missing error check for jack detection - ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup - drm/amd/display: Allow DCE link encoder without AUX registers - drm/amd/display: Read EDID from VBIOS embedded panel info - drm/xe/debugfs: Correct printing of register whitelist ranges - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() - page_pool: Set `dma_sync` to false for devmem memory provider - net: page_pool: create hooks for custom memory providers - page_pool: fix memory-provider leak in page_pool_create_percpu() error path - iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING - iavf: stop removing VLAN filters from PF on interface down - iavf: wait for PF confirmation before removing VLAN filters - iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler - ice: fix NULL pointer dereference in ice_reset_all_vfs() - net: tls: fix strparser anchor skb leak on offload RX setup failure - sfc: fix error code in efx_devlink_info_running_versions() - net/sched: cls_flower: revert unintended changes - [arm64] Reserve an extra page for early kernel mapping - smb: client: correctly handle ErrorContextData as a flexible array - smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) - LoongArch: KVM: Compile switch.S directly into the kernel - ntfs: ->d_compare() must not block - PCI: Initialize temporary device in new_id_store() - net: bcmgenet: Initialize u64 stats seq counter - net: bcmgenet: fix leaking free_bds - [amd64] iommu/amd: Reorder attach device code - [amd64] iommu/amd: Put list_add/del(dev_data) back under the domain->lock - perf tool_pmu: Fix aggregation on duration_time - net/sched: sch_pie: annotate more data-races in pie_dump_stats() - netpoll: Extract IPv6 address retrieval function - netpoll: pass buffer size to egress_dev() to avoid MAC truncation - page_pool: fix incorrect mp_ops error handling - crypto: af_alg - Cap AEAD AD length to 0x80000000 - i40e: Cleanup PTP pins on probe failure - workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path - netfilter: nf_conntrack_sip: get helper before allocating expectation - audit: fix incorrect inheritable capability in CAPSET records - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" - netfilter: nft_ct: fix missing expect put in obj eval - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() - [s390x] KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic - [amd64] KVM: x86: Fix Xen hypercall tracepoint argument assignment - netfilter: nf_tables: unconditionally bump set->nelems before insertion (CVE-2026-23272) - ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands - smb/client: fix possible infinite loop and oob read in symlink_data() - [amd64] drm/i915/dp: Fix VSC dynamic range signaling for RGB formats - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans - ALSA: usb-audio: Bound MIDI endpoint descriptor scans - ceph: fix a buffer leak in __ceph_setxattr() - ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size - io-wq: check that the predecessor is hashed in io_wq_remove_pending() - [powerpc*] warp: Fix error handling in pika_dtm_thread - netfs: fix error handling in netfs_extract_user_iter() - irqchip/riscv-imsic: Clear interrupt move state during CPU offlining - libceph: Fix potential out-of-bounds access in osdmap_decode() - libceph: Fix potential null-ptr-deref in decode_choose_args() - libceph: Fix potential out-of-bounds access in crush_decode() - libceph: handle rbtree insertion error in decode_choose_args() - [amd64] iommu/vt-d: Disable DMAR for Intel Q35 IGFX - [amd64] drm/i915: skip __i915_request_skip() for already signaled requests - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() - drm/xe/dma-buf: handle empty bo and UAF races - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup - drm/gma500/oaktrail_lvds: fix hang on init failure - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init - iommufd: Fix return value of iommufd_fault_fops_write() - eventfs: Use list_add_tail_rcu() for SRCU-protected children list - drm/v3d: Reject empty multisync extension to prevent infinite loop - btrfs: use inode already stored in local variable at btrfs_rmdir() - btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() - btrfs: fix missing last_unlink_trans update when removing a directory - smb: client: Use FullSessionKey for AES-256 encryption key derivation - btrfs: do not mark inode incompressible after inline attempt fails - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() - sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new - mptcp: pm: prio: skip closed subflows - mptcp: drop __mptcp_fastopen_gen_msk_ackseq() - mptcp: fix rx timestamp corruption on fastopen - f2fs: fix incorrect file address mapping when inline inode is unwritten - f2fs: fix false alarm of lockdep on cp_global_sem lock - spi: sifive: Simplify clock handling with devm_clk_get_enabled() - spi: sifive: fix controller deregistration - mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 - mptcp: pm: ADD_ADDR rtx: fix potential data-race - mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker - netfs: Fix potential uninitialised var in netfs_extract_user_iter() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.92 - mptcp: sync the msk->sndbuf at accept() time - mptcp: pm: ADD_ADDR rtx: allow ID 0 - mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (CVE-2026-46158) - mptcp: pm: ADD_ADDR rtx: free sk if last (CVE-2026-46170) - ksmbd: validate owner of durable handle on reconnect (CVE-2026-31717) - drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (CVE-2026-46216) - [s390x] debug: Reject zero-length input before trimming a newline - Revert "perf cgroup: Update metric leader in evlist__expand_cgroup" - Revert "perf tool_pmu: Fix aggregation on duration_time" - Revert "perf python: Add parse_events function" - Revert "perf tool_pmu: Factor tool events into their own PMU" - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420) - spi: spi-dw-dma: fix print error log when wait finish transaction (CVE-2026-31560) - Revert "x86/vdso: Fix output operand size of RDPID" - sched/deadline: Less agressive dl_server handling - sched/deadline: Fix dl_server_stopped() - sched/deadline: Fix dl_server getting stuck - sched/deadline: Fix dl_server behaviour - sched/deadline: Stop dl_server before CPU goes offline - ksmbd: close durable scavenger races against m_fp_list lookups - af_unix: Give up GC if MSG_PEEK intervened. (CVE-2026-23394) - drm/imagination: Synchronize interrupts before suspending the GPU (CVE-2026-23469) - ata: libata-scsi: improve readability of ata_scsi_qc_issue() - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS - perf parse-events: Expose/rename config_term_name - Revert "ice: fix double-free of tx_buf skb" - Revert "ice: Remove jumbo_remove step from TX path" - tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 - net/mlx5e: Trigger neighbor resolution for unresolved destinations - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init - [amd64] x86/fgraph: Fix return_to_handler regs.rsp value - [amd64] iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set - [riscv64] fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends on HAVE_DYNAMIC_FTRACE_WITH_ARGS - [riscv64] fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (CVE-2025-22069) - hwmon: (pmbus/core) Protect regulator operations with mutex - [arm64] Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL - sysfs: don't remove existing directory on update failure - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() - ksmbd: fix null pointer dereference in compare_guid_key() - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow - ksmbd: validate SID in parent security descriptor during ACL inheritance - smb: client: require net admin for CIFS SWN netlink - smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() - smb: client: use data_len for SMB2 READ encrypted folioq copy - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX - ALSA: ua101: Reject too-short USB descriptors - ALSA: pcm: Don't setup bogus iov_iter for silencing - ALSA: asihpi: Fix potential OOB array access at reading cache - efi: Allocate runtime workqueue before ACPI init - io_uring/waitid: clear waitid info before copying it to userspace - drivers/base/memory: fix memory block reference leak in poison accounting - ipv6: ioam: refresh hdr pointer before ioam6_event() - mm/memory_hotplug: fix memory block reference leak on remove - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START - Bluetooth: bnep: Fix UAF read of dev->name - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer - Bluetooth: MGMT: validate Add Extended Advertising Data length - Bluetooth: serialize accept_q access - phonet/pep: disable BH around forwarded sk_receive_skb() - net: bcmgenet: keep RBUF EEE/PM disabled - net: ifb: report ethtool stats over num_tx_queues - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() - netfilter: ip6t_hbh: reject oversized option lists - netfilter: nf_queue: hold bridge skb->dev while queued - netfilter: ipset: stop hash:* range iteration at end - netfilter: nft_inner: Fix IPv6 inner_thoff desync - sched_ext: Fix missing warning in scx_set_task_state() default case - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path - cgroup/cpuset: Reset DL migration state on can_attach() failure - fs/ntfs3: handle attr_set_size() errors when truncating files - l2tp: use list_del_rcu in l2tp_session_unhash - qed: fix double free in qed_cxt_tables_alloc() - ring-buffer: Fix reporting of missed events in iterator - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() - vsock/vmci: fix UAF when peer resets connection during handshake - vsock/virtio: reset connection on receiving queue overflow - wifi: ath11k: clear shared SRNG pointer state on restart - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 - ixgbevf: fix use-after-free in VEPA multicast source pruning - rbd: eliminate a race in lock_dwork draining on unmap - lsm: hold cred_guard_mutex for lsm_set_self_attr() - [arm64] octeontx2-af: CGX: add bounds check to cgx_speed_mbps index - ice: fix setting promisc mode while adding VID filter - ice: restore PTP Rx timestamp config after ethtool set-channels - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() - af_unix: Fix UAF read of tail->len in unix_stream_data_wait() - wifi: mac80211: consume only present negotiated TTLM maps - cifs: Fix busy dentry used after unmounting - tracing: Do not call map->ops->elt_free() if elt_alloc() fails - [arm64] probes: Handle probes on hinted conditional branch instructions - [arm64] KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits - [arm64] KVM: arm64: vgic: Free private_irqs when init fails after allocation - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe - spi: qup: fix error pointer deref after DMA setup failure - [arm64] phy: tegra: xusb: Fix per-pad high-speed termination calibration - scsi: isci: Fix use-after-free in device removal path - spi: ep93xx: fix error pointer deref after DMA setup failure - spi: sprd: fix error pointer deref after DMA setup failure - spi: ti-qspi: fix use-after-free after DMA setup failure - RDMA/siw: Reject MPA FPDU length underflow before signed receive math - device property: set fwnode->secondary to NULL in fwnode_init() - drm/virtio: use uninterruptible resv lock for plane updates - drm/amdgpu/vpe: Force collaborate sync after TRAP - drm/bridge: it66121: acquire reset GPIO in probe - drm/bridge: megachips: remove bridge when irq request fails - drm/amd/display: Fix integer overflow in bios_get_image() - drm/amd/display: Validate GPIO pin LUT table size before iterating - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async - batman-adv: mcast: fix use-after-free in orig_node RCU release - batman-adv: clear current gateway during teardown - batman-adv: dat: handle forward allocation error - batman-adv: fix fragment reassembly length accounting - batman-adv: fix tp_meter counter underflow during shutdown - batman-adv: frag: disallow unicast fragment in fragment - batman-adv: bla: fix report_work leak on backbone_gw purge - batman-adv: tp_meter: avoid use of uninit sender vars - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown - batman-adv: tp_meter: fix race condition in send error reporting - batman-adv: tt: fix negative last_changeset_len - batman-adv: tt: fix negative tt_buff_len - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock - hwmon: (pmbus/adm1266) reject implausible blackbox record_count - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors - [arm64] pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume - HID: uclogic: Fix regression of input name assignment - [riscv64] mm: Fixup no5lvl failure when vaddr is invalid - [arm64] pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 - ALSA: hda: cs35l56: Put ACPI device after setting companion - ALSA: hda: cs35l41: Put ACPI device on missing physical node - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() - netfilter: x_tables: unregister the templates first - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() - tcp: Fix imbalanced icsk_accept_queue count. - ice: fix setting RSS VSI hash for E830 - ice: fix locking in ice_dcb_rebuild() - net: lan966x: avoid unregistering netdev on register failure - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access - NFSD: Fix infinite loop in layout state revocation - irqchip/ath79-cpu: Remove unused function - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation - nsfs: fix wrong error code returned for pidns ioctls - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT - zonefs: handle integer overflow in zonefs_fname_to_fno - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). - [powerpc*] fix dead default for GUEST_STATE_BUFFER_TEST - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call - netfs: Fix overrun check in netfs_extract_user_iter() - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone - netfs: Defer the emission of trace_netfs_folio() - netfs: Fix streaming write being overwritten - netfs: Fix potential deadlock in write-through mode - netfs: Fix write streaming disablement if fd open O_RDWR - netfs: Fix early put of sink folio in netfs_read_gaps() - netfs: Fix partial invalidation of streaming-write folio - netfs: Fix a few minor bugs in netfs_page_mkwrite() - netfs: Remove unnecessary references to pages - netfs: Fix folio->private handling in netfs_perform_write() - net: ethernet: cortina: Make RX SKB per-port - net: ethernet: cortina: Drop half-assembled SKB - net: ethernet: cortina: Carry over frag counter - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference - wifi: ath11k: fix error path leaks in some WMI WOW calls - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() - wifi: ath10k: skip WMI and beacon transmission when device is wedged - blk-integrity: remove seed for user mapped buffers - block: don't overwrite bip_vcnt in bio_integrity_copy_user() - block: recompute nr_integrity_segments in blk_insert_cloned_request - HID: quirks: really enable the intended work around for appledisplay - block: modify bio_integrity_map_user to accept iov_iter as argument - block: drop direction param from bio_integrity_copy_user() - blk-integrity: use simpler alignment check - blk-integrity: enable p2p source and destination - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() - accel/qaic: Add overflow check to remap_pfn_range during mmap - net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics - [arm64] drm/msm/dsi: don't dump registers past the mapped region - [arm64] drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN - [powerpc*] time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring - net: tls: prevent chain-after-chain in plain text SG - net: phy: DP83TC811: add reading of abilities - [amd64] x86/xen: Fix xen_e820_swap_entry_with_ram() - tls: Preserve sk_err across recvmsg() when data has been copied - net/mlx5: Do not restore destination-less TC rules - scsi: sd: Fix return code handling in sd_spinup_disk() - ALSA: scarlett2: Add missing error check when initialise Autogain Status - io_uring/net: punt IORING_OP_BIND async if it needs file create - btrfs: fix squota accounting during enable generation - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() - [arm64] drm/msm/snapshot: fix dumping of the unaligned regions - drm/xe/gsc: Fix double-free of managed BO in error path - drm/xe/vf: Fix signature of print functions - drm/xe/pf: Fix CFI failure in debugfs access - wifi: ath11k: fix peer resolution on rx path when peer_id=0 - ice: ptp: serialize E825 PHY timer start with PTP lock - [amd64] drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP - [arm64] net: dsa: mt7530: fix FDB entries not aging out with short timeout - [arm64] net: dsa: mt7530: preserve VLAN tags on trapped link-local frames - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 - [amd64] platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: hp_accel: Check ACPI_COMPANION() against NULL - [amd64] platform/x86: intel-hid: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL - RDMA/rtrs: Fix use-after-free in path file creation cleanup - net: bridge: Flush multicast groups when snooping is disabled - bridge: mcast: Fix a possible use-after-free when removing a bridge port - pds_core: fix error handling in pdsc_devcmd_wait - pds_core: fix debugfs_lookup dentry leak and error handling - wifi: mac80211: fix MLE defragmentation - ALSA: seq: Serialize UMP output teardown with event_input - tracing: Avoid NULL return from hist_field_name() on truncation - Bluetooth: btmtk: fix urb->setup_packet leak in error paths - net: ag71xx: check error for platform_get_irq - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() - drm/xe/oa: Fix exec_queue leak on width check in stream open - [arm64] octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs - net: mana: validate rx_req_idx to prevent out-of-bounds array access - pds_core: ensure null-termination for firmware version strings - net: gro: don't merge zcopy skbs - landlock: Fix TCP handling of short AF_UNSPEC addresses - block: make bio_integrity_map_user() static inline - security/keys: fix missed RCU read section on lookup https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.93 - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size - [arm64] drm/v3d: Fix use-after-free of CPU job query arrays on error path - [arm64] drm/v3d: Release indirect CSD GEM reference on CPU job free - net/sched: cls_fw: fix NULL dereference of "old" filters before change() - net: mctp: ensure our nlmsg responses are initialised (CVE-2026-45930) - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit - net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked - bcache: fix uninitialized closure object - net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (CVE-2026-43219) - [arm64] Introduce esr_is_ubsan_brk() - [arm64] debug: clean up single_step_handler logic - [arm64] refactor aarch32_break_handler() - [arm64] debug: call software breakpoint handlers statically - [arm64] debug: call step handlers statically - [arm64] debug: remove break/step handler registration infrastructure - [arm64] entry: Add entry and exit functions for debug exceptions - [arm64] debug: split hardware breakpoint exception entry - [arm64] debug: refactor reinstall_suspended_bps() - [arm64] debug: split single stepping exception entry - [arm64] debug: split hardware watchpoint exception entry - [arm64] debug: split brk64 exception entry - [arm64] debug: split bkpt32 exception entry - [arm64] debug: remove debug exception registration infrastructure - [arm64] debug: always unmask interrupts in el0_softstp() - nfc: llcp: Fix use-after-free in llcp_sock_release() - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() - xfrm: Check for underflow in xfrm_state_mtu - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems - netfilter: synproxy: refresh tcphdr after skb_ensure_writable - netfilter: xt_cpu: prefer raw_smp_processor_id - netfilter: ebtables: fix OOB read in compat_mtw_from_user - tun: free page on short-frame rejection in tun_xdp_one() (CVE-2026-46321) - tun: free page on build_skb failure in tun_xdp_one() (CVE-2026-46322) - vsock: keep poll shutdown state consistent - net: netlink: fix sending unassigned nsid after assigned one - net: netlink: don't set nsid on local notifications - net/smc: Do not re-initialize smc hashtables - [s390x] net/iucv: fix locking in .getsockopt - scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues - ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() - ALSA: pcm: oss: Fix setup list UAF on proc write error - [amd64] ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors - net: hsr: fix potential OOB access in supervision frame handling - [amd64] accel/ivpu: prevent uninitialized data bug in debugfs - gpio: mxc: fix irq_high handling - net: Avoid checksumming unreadable skb tail on trim - ethtool: rss: fix hkey leak when indir_size is 0 - ethtool: module: avoid leaking a netdev ref on module flash errors - ethtool: module: check fw_flash_in_progress under rtnl_lock - ethtool: module: fix cleanup if socket used for flashing multiple devices - ethtool: cmis: require exact CDB reply length - ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl - net: ethtool: Add new parameters and a function to support EPL - net: ethtool: Add support for writing firmware blocks using EPL payload - ethtool: cmis: validate start_cmd_payload_size from module - ethtool: cmis: validate fw->size against start_cmd_payload_size - tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() - ASoC: codecs: simple-mux: Fix enum control bounds check - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() - bonding: refuse to enslave CAN devices - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES - ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error - ethtool: pse-pd: fix missing ethnl_ops_complete() - ethtool: strset: fix header attribute index in ethnl_req_get_phydev() - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback - ethtool: eeprom: add more safeties to EEPROM Netlink fallback - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() - net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" - net/sched: fix packet loop on netem when duplicate is on - net/sched: act_mirred: Move the recursion counter struct netdev_xmit - net/sched: act_mirred: add loop detection - net: Introduce skb tc depth field to track packet loops - net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop - net/sched: act_mirred: Fix return code in early mirred redirect error paths - net/handshake: Use spin_lock_bh for hn_lock - nvme-tcp: store negative errno in queue->tls_err - net/handshake: Pass negative errno through handshake_complete() - remove pointless includes of - net/handshake: Take a long-lived file reference at submit - net/handshake: Drain pending requests at net namespace exit - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close - [arm64,armhf] gpio: rockchip: convert bank->clk to devm_clk_get_enabled() - [amd64,arm64] net: mana: Add NULL guards in teardown path to prevent panic on attach failure - sctp: fix race between sctp_wait_for_connect and peeloff - ipv6: fix possible infinite loop in rt6_fill_node() - ipv6: fix possible infinite loop in fib6_select_path() - net: skbuff: fix pskb_carve leaking zcopy pages - perf: Fix dangling cgroup pointer in cpuctx - batman-adv: v: stop OGMv2 on disabled interface - batman-adv: tvlv: abort OGM send on tvlv append failure - batman-adv: tt: reject oversized local TVLV buffers - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface - batman-adv: tvlv: reject oversized TVLV packets - batman-adv: iv: recover OGM scheduling after forward packet error - batman-adv: tp_meter: avoid role confusion in tp_list - [s390x] cio: Restore GFP_DMA for CHSC allocation - batman-adv: tp_meter: directly shut down timer on cleanup - batman-adv: tt: fix TOCTOU race for reported vlans - batman-adv: tt: avoid empty VLAN responses - batman-adv: bla: avoid double decrement of bla.num_requests - mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303) - media: rc: fix race between unregister and urb/irq callbacks - media: rc: ttusbir: fix inverted error logic - inet: frags: add inet_frag_queue_flush() - inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) - HID: core: Add printk_ratelimited variants to hid_warn() etc - HID: pass the buffer size to hid_report_raw_event - HID: core: introduce hid_safe_input_report() - HID: core: Fix size_t specifier in hid_report_raw_event() - [amd64] drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register - [amd64] drm/i915/psr: Read Intel DPCD workaround register - drm/dp: Add eDP 1.5 bit definition - [amd64] drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used - [arm64] io: Rename ioremap_prot() to __ioremap_prot() - [arm64] io: Extract user memory type in ioremap_prot() (CVE-2026-23346) - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X - batman-adv: tt: prevent TVLV entry number overflow - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer - usb: typec: ucsi: ccg: reject firmware images without a ':' record header - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers - usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO - usb: typec: altmodes/displayport: validate count before reading Status Update VDO - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT - usb: typec: ucsi: validate connector number in ucsi_connector_change() - USB: serial: safe_serial: fix memory corruption with small endpoint - media: rc: igorplugusb: fix control request setup packet - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse - Bluetooth: btusb: Allow firmware re-download when version matches - hpfs: fix a crash if hpfs_map_dnode_bitmap fails - ipc: limit next_id allocation to the valid ID range - auxdisplay: line-display: fix OOB read on zero-length message_store() - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn - Bluetooth: HIDP: fix missing length checks in hidp_input_report() - Bluetooth: ISO: fix UAF in iso_recv_frame - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync - Input: xpad - fix out-of-bounds access for Share button - parport: Fix race between port and client registration (Closes: #1130365) - USB: cdc-acm: Fix bit overlap and move quirk definitions to header - [arm64] KVM: arm64: PMU: Preserve AArch32 counter low bits - [amd64] KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC - [amd64] KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use - [amd64] KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests - [amd64] KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 - [amd64] KVM: SEV: Compute the correct max length of the in-GHCB scratch area - [amd64] KVM: SEV: Check PSC request indices against the actual size of the buffer - [amd64] KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer - [amd64] KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux - iio: adc: npcm: fix unbalanced clk_disable_unprepare() - iio: dac: max5821: fix return value check in powerdown sync - iio: dac: ad5686: fix input raw value check - iio: dac: ad5686: acquire lock when doing powerdown control - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw - iio: gyro: itg3200: fix i2c read into the wrong stack location - iio: gyro: adis16260: fix division by zero in write_raw - iio: ssp_sensors: cancel delayed work_refresh on remove - iio: temperature: tsys01: fix broken PROM checksum validation - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL - iio: light: cm3323: fix reg_conf not being initialized correctly - iio: buffer: hw-consumer: fix use-after-free in error path - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() - USB: serial: omninet: fix memory corruption with small endpoint - usb: cdns3: gadget: fix request skipping after clearing halt - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles - usb: dwc2: Fix use after free in debug code - Input: elan_i2c - validate firmware size before use - wireguard: send: append trailer after expanding head - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data - macsec: fix replay protection at XPN lower-PN wrap - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() - [arm64] ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params - ipv6: exthdrs: refresh nh after handling HAO option - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). - ipv6: validate extension header length before copying to cmsg - xfrm: input: hold netns during deferred transport reinjection - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname - ip6: vti: Use ip6_tnl.net in vti6_changelink(). - net: skbuff: fix missing zerocopy reference in pskb_carve helpers - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() - nfc: hci: fix out-of-bounds read in HCP header parsing - xfrm: route MIGRATE notifications to caller's netns - xfrm: ah: use skb_to_full_sk in async output callbacks - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - [arm64] ASoC: qcom: q6asm-dai: close stream only when running - [arm64] ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks - xfrm: esp: restore combined single-frag length gate - Input: xpad - add "Nova 2 Lite" from GameSir - Input: xpad - add support for ASUS ROG RAIKIRI II - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 - [amd64] comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() - [amd64] comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() - counter: Fix refcount leak in counter_alloc() error path - tty: serial: pch_uart: add check for dma_alloc_coherent() - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers - usb: chipidea: core: convert ci_role_switch to local variable - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers - usb: storage: Add quirks for PNY Elite Portable SSD - usbip: vudc: Fix use after free bug in vudc_remove due to race condition - usb: usbtmc: check URB actual_length for interrupt-IN notifications - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize - usb: typec: tcpm: improve handling of DISCOVER_MODES failures - USB: serial: option: add MeiG SRM813Q - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL - USB: serial: belkin_sa: validate interrupt status length - USB: serial: cypress_m8: validate interrupt packet headers - USB: serial: keyspan: fix missing indat transfer sanity check - USB: serial: mxuport: fix memory corruption with small endpoint - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind - usb: gadget: net2280: Fix double free in probe error path - usb: gadget: f_hid: fix device reference leak in hidg_alloc() - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports - usb: gadget: f_fs: copy only received bytes on short ep0 read - usb: gadget: f_fs: serialize DMABUF cancel against request completion - [amd64] thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() - [amd64] thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf - scsi: target: iscsi: Validate CHAP_R length before base64 decode - drm/hyperv: validate resolution_count and fix WIN8 fallback - drm/hyperv: validate VMBus packet size in receive callback - [amd64] drm/i915: Fix potential UAF in TTM object purge - drm/amd/pm/si: Disregard vblank time when no displays are connected - serial: altera_jtaguart: handle uart_add_one_port() failures - serial: qcom-geni: fix UART_RX_PAR_EN bit position - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ - serial: sh-sci: fix memory region release in error path - serial: zs: Fix swapped RI/DSR modem line transition counting - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger - drm/amdkfd: Check for pdd drm file first in CRIU restore path - serial: dz: Fix bootconsole message clobbering at chip reset - serial: dz: Fix bootconsole handover lockup - serial: dz: Convert to use a platform device - serial: zs: Fix bootconsole handover lockup - serial: zs: Switch to using channel reset - serial: zs: Convert to use a platform device - USB: serial: cypress_m8: fix memory corruption with small endpoint - USB: serial: digi_acceleport: fix memory corruption with small endpoints - xhci: tegra: Fix ghost USB device on dual-role port unplug - iommu: Skip PASID validation for devices without PASID capability - [amd64] x86/boot: Disable stack protector for early boot code - [amd64] x86/kexec: Disable KCOV instrumentation after load_segments() (CVE-2026-43331) - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer - serdev: Provide a bustype shutdown function - Bluetooth: hci_qca: Migrate to serdev specific shutdown function - Bluetooth: hci_qca: Convert timeout from jiffies to ms - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes - ALSA: scarlett2: Allow flash writes ending at segment boundary - mm/memory: fix spurious warning when unmapping device-private/exclusive pages - [amd64] platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery - net: hsr: defer node table free until after RCU readers - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient - ice: fix VF queue configuration with low MTU values - ring-buffer: Flush and stop persistent ring buffer on panic - mptcp: cleanup fallback dummy mapping generation - mptcp: reset rcv wnd on disconnect - [arm64] tlb: Flush walk cache when unsharing PMD tables - [arm64] octeontx2-pf: avoid double free of pool->stack on AQ init failure - mptcp: introduce the mptcp_init_skb helper - mptcp: handle first subflow closing consistently - mptcp: do not drop partial packets - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() - iio: chemical: scd30: Use guard(mutex) to allow early returns - iio: chemical: scd30: fix division by zero in write_raw - iio: dac: ad5686: fix ref bit initialization for single-channel parts - ALSA: firewire-motu: Protect register DSP event queue positions - [arm64] usb: dwc3: xilinx: fix error handling in zynqmp init error paths - usb: musb: omap2430: Fix use-after-free in omap2430_probe() - usb: typec: ucsi: Check if power role change actually happened before handling - [amd64] thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() - usb: typec: ucsi: Don't update power_supply on power role change if not connected - [amd64] x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' - [amd64] x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock - hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock - mm: perform all memfd seal checks in a single place - mm/memfd: fix spelling and grammatical issues - memfd: deny writeable mappings when implying SEAL_WRITE - usb: core: Fix SuperSpeed root hub wMaxPacketSize - ethtool: cmis_cdb: Fix incorrect read / write length extension - net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow - [arm64] KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.94 - bpf: Free reuseport cBPF prog after RCU grace period. (CVE-2026-52910) - USB: serial: mct_u232: fix memory corruption with small endpoint - [armhf] group is_permission_fault() with is_translation_fault() - [armhf] allow __do_kernel_fault() to report execution of memory faults - [armhf] fix hash_name() fault - [armhf] fix branch predictor hardening - net: phy: micrel: fix LAN8814 QSGMII soft reset - wifi: remove zero-length arrays - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl - ipv6: mcast: Fix use-after-free when processing MLD queries - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS - [arm64] tee: optee: prevent use-after-free when the client exits before the supplicant - [arm64]soc: qcom: ice: Return -ENODEV if the ICE platform device is not found - erofs: add sysfs node to drop internal caches - erofs: tidy up synchronous decompression - erofs: fix use-after-free on sbi->sync_decompress - ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id - ipvs: clear the svc scheduler ptr early on edit - netfilter: synproxy: add mutex to guard hook reference counting - netfilter: conntrack_irc: fix possible out-of-bounds read - netfilter: nft_ct: bail out on template ct in get eval - netfilter: bridge: make ebt_snat ARP rewrite writable - dm cache policy smq: check allocation under invalidate lock - net/sched: act_api: use RCU with deferred freeing for action lifecycle - 6lowpan: fix off-by-one in multicast context address compression - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() - devlink: Release nested relation on devlink free - [arm64] drm/imx: Fix three kernel-doc warnings in dcss-scaler.c - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap - pcnet32: stop holding device spin lock during napi_complete_done - net: Annotate sk->sk_write_space() for UDP SOCKMAP. - hsr: Remove WARN_ONCE() in hsr_addr_is_self(). - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr - net: lan743x: permit VLAN-tagged packets up to configured MTU - net: fec: fix pinctrl default state restore order on resume - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() - Bluetooth: MGMT: validate advertising TLV before type checks - Bluetooth: RFCOMM: validate skb length in MCC handlers - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling - Bluetooth: bnep: reject short frames before parsing - Bluetooth: fix memory leak in error path of hci_alloc_dev() - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync - Bluetooth: ISO: Fix not using bc_sid as advertisement SID - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls - Bluetooth: MGMT: Fix backward compatibility with userspace - [arm64] octeontx2-pf: Fix NDC sync operation errors - [arm64] octeontx2-af: Fix initialization of mcam's entry2target_pffunc field - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options - ptp: vclock: Switch from RCU to SRCU - net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown - net_sched: act_pedit: use RCU in tcf_pedit_dump() - net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) - [arm64] octeontx2-af: npc: Fix CPT channel mask in npc_install_flow - vxlan: vnifilter: send notification on VNI add - vxlan: vnifilter: fix spurious notification on VNI update - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr - sctp: purge outqueue on stale COOKIE-ECHO handling - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() - time: Fix off-by-one in settimeofday() usec validation - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams - ALSA: seq: dummy: fix UMP event stack overread - ima: kexec: skip IMA segment validation after kexec soft reboot - ima: kexec: move IMA log copy from kexec load to execute - spi: cadence-quadspi: fix unclocked access on unbind (CVE-2026-46203) - tools/rv: Fix cleanup after failed trace setup - tap: free page on error paths in tap_get_user_xdp() (CVE-2026-46320) - [arm64] tlb: Allow XZR argument to TLBI ops - [arm64] tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI - iomap: don't revert iov_iter on partially completed buffered writes - dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() - netlabel: validate unlabeled address and mask attribute lengths - gpio: mvebu: fix NULL pointer dereference in suspend/resume - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls - tcp: restrict SO_ATTACH_FILTER to priv users - net: add pskb_may_pull() to skb_gro_receive_list() - net/mlx4: avoid GCC 10 __bad_copy_from() false positive - net: ibm: emac: Fix use-after-free during device removal - netdev: fix double-free in netdev_nl_bind_rx_doit() - net: phy: clean the sfp upstream if phy probing fails - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure - net/mlx5: Use effective affinity mask for IRQ selection - ipv6: sit: reload inner IPv6 header after GSO offloads - net: openvswitch: fix possible kfree_skb of ERR_PTR - r8152: handle the return value of usb_reset_device() - gpio: zynq: fix runtime PM leak on remove - sctp: fix uninit-value in __sctp_rcv_asconf_lookup() - net: guard timestamp cmsgs to real error queue skbs - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() - rds: mark snapshot pages dirty in rds_info_getsockopt() - netfilter: revalidate bridge ports - netfilter: nf_conntrack: destroy stale expectfn expectations on unregister - netfilter: x_tables: avoid leaking percpu counter pointers - netfilter: nf_log: validate MAC header was set before dumping it - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag - [arm64,armhf] net: mvpp2: sync RX data at the hardware packet offset - [arm64,armhf] net: mvpp2: limit XDP frame size to the RX buffer - [arm64,armhf] net: mvpp2: Add metadata support for xdp mode - [arm64,armhf] net: mvpp2: refill RX buffers before XDP or skb use - [arm64,armhf] net: mvpp2: build skb from XDP-adjusted data on XDP_PASS - ipv6: Fix a potential NPD in cleanup_prefix_route() - netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) - writeback: Avoid contention on wb->list_lock when switching inodes - writeback: Fix use after free in inode_switch_wbs_work_fn() - xfrm: hold device only for the asynchronous decryption - xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663) - [amd64] KVM: VMX: Update SVI during runtime APICv activation - [arm64] clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked - clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs - [arm64] clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time - drm/virtio: Fix driver removal with disabled KMS - [arm64,armhf] drm/vc4: fix krealloc() memory leak - drm/xe: fix refcount leak in xe_range_fence_insert() - netfilter: nft_tunnel: fix use-after-free on object destroy - [arm64] tee: shm: fix shm leak in register_shm_helper() - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig - [arm64] soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() - [amd64] accel/ivpu: Add bounds checks for firmware log indices - [amd64] accel/ivpu: Add buffer overflow check in MS get_info_ioctl - [amd64] accel/ivpu: Fix signed integer truncation in IPC receive - tracing/probes: Point the error offset correctly for eprobe argument error - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying - [amd64] KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA - [amd64] drm/i915/gem: Fix phys BO pread/pwrite with offset - pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL - xfrm: espintcp: do not reuse an in-progress partial send - USB: serial: io_ti: fix heap overflow in get_manuf_info() - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() - USB: serial: option: add usb-id for Dell Wireless DW5826e-m - USB: serial: kl5kusb105: fix bulk-out buffer overflow - ALSA: timer: Forcibly close timer instances at closing - ALSA: timer: Fix UAF at snd_timer_user_params() - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() - mm/huge_memory: update file PMD counter before folio_put() - mm/damon/ops-common: call folio_test_lru() after folio_get() - RDMA/srp: bound SRP_RSP sense copy by the received length - zram: fix use-after-free in zram_bvec_write_partial() - udp: clear skb->dev before running a sockmap verdict - mptcp: fix retransmission loop when csum is enabled - mptcp: close TOCTOU race while computing rcv_wnd - mptcp: allow subflow rcv wnd to shrink - mptcp: sockopt: check timestamping ret value - mptcp: add-addr: always drop other suboptions - wifi: nl80211: reject oversized EMA RNR lists - vsock/vmci: fix sk_ack_backlog leak on failed handshake - timers/migration: Fix livelock in tmigr_handle_remote_up() - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write - bnxt_en: Fix NULL pointer dereference - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush - pidfd: refuse access to tasks that have started exiting harder - fs/qnx6: fix pointer arithmetic in directory iteration - fuse: reject fuse_notify() pagecache ops on directories - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter - i2c: tegra: Fix NOIRQ suspend/resume - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard - ipc/shm: serialize orphan cleanup with shm_nattch updates - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context - misc: fastrpc: fix use-after-free race in fastrpc_map_create - misc: fastrpc: fix DMA address corruption due to find_vma misuse - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback - net/mlx5: Reorder completion before putting command entry in cmd_work_handler - net: bonding: fix NULL pointer dereference in bond_do_ioctl() - net: mv643xx: fix OF node refcount - net: rds: clear i_sends on setup unwind - nvmem: core: fix use-after-free bugs in error paths - nvmem: layouts: onie-tlv: fix hang on unknown types - [arm64] octeontx2-af: fix memory leak in rvu_setup_hw_resources() - io_uring/kbuf: don't truncate end buffer for bundles - io_uring/wait: fix min_timeout behavior - mm/hugetlb: restore reservation on error in hugetlb folio copy paths - mmc: core: Fix host controller programming for fixed driver type - mmc: dw_mmc-rockchip: Add missing private data for very old controllers - mmc: litex_mmc: Set mandatory idle clocks before CMD0 - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC - mmc: sdhci: add signal voltage switch in sdhci_resume_host - pmdomain: imx: fix OF node refcount - rtase: Avoid sleeping in get_stats64() - rtase: Reset TX subqueue when clearing TX ring - sctp: diag: reject stale associations in dump_one path - sctp: stream: fully roll back denied add-stream state - [amd64] thunderbolt: Reject zero-length property entries in validator - [amd64] thunderbolt: Bound root directory content to block size - [amd64] thunderbolt: Clamp XDomain response data copy to allocation size - [amd64] thunderbolt: Validate XDomain request packet size before type cast - [amd64] thunderbolt: Limit XDomain response copy to actual frame size - [arm64] slimbus: qcom-ngd-ctrl: fix OF node refcount - [arm64] slimbus: qcom-ngd-ctrl: Fix up platform_driver registration - [arm64] slimbus: qcom-ngd-ctrl: Fix probe error path ordering - [arm64] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd - [arm64] slimbus: qcom-ngd-ctrl: Initialize controller resources in controller - [arm64] slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership - [arm64] slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD - [arm64] slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock - drm/amdkfd: fix NULL dereference in get_queue_ids() - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 - drm/xe: Clear pending_disable before signaling suspend fence - [arm64,armhf] drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups - drm/amdgpu: restart the CS if some parts of the VM are still invalidated - drm/amd/pm: fix smu13 power limit default/cap calculation - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range - drm/amd/display: Bound VBIOS record-chain walk loops - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs - drm/amd/display: Use krealloc_array() in dal_vector_reserve() - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling - driver core: reject devices with unregistered buses - mailbox: Fix NULL message support in mbox_send_message() - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf - sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() - netfilter: nft_fib: fix stale stack leak via the OIFNAME register - mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper - RDMA/umem: Move umem dmabuf revoke logic into helper function - RDMA/umem: Add helpers for umem dmabuf revoke lock - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible - RDMA/umem: fix kernel-doc warnings - RDMA: Move DMA block iterator logic into dedicated files - RDMA/umem: Fix truncation for block sizes >= 4G - mm/hugetlb: avoid false positive lockdep assertion - mptcp: fix missing wakeups in edge scenarios - ipmi:ssif: Remove unnecessary indention - ipmi:ssif: NULL thread on error - ipvs: skip ipv6 extension headers for csum checks (CVE-2026-45850) - vsock/virtio: fix potential unbounded skb queue - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc - block: fix handling of dead zone write plugs - [arm64] cputype: Add NVIDIA Olympus definitions - [arm64] cputype: Add C1-Ultra definitions - [arm64] cputype: Add C1-Premium definitions - [arm64] errata: Mitigate TLBI errata on various Arm CPUs - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU - net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() - tcp: use EXPORT_IPV6_MOD[_GPL]() - tcp: secure_seq: add back ports to TS offset (CVE-2026-23247) - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation - vsock/virtio: fix skb overhead overflow on 32-bit builds - netfilter: require Ethernet MAC header before using eth_hdr() . [ Salvatore Bonaccorso ] * [rt] Refresh "ARM: enable irq in translation/section permission fault" * ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909) linux-signed-amd64 (6.12.94+1~bpo12+1) bookworm-backports; urgency=medium . * Sign kernel from linux 6.12.94-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-amd64 (6.12.90+2) trixie-security; urgency=high . * Sign kernel from linux 6.12.90-2 . * smb: client: reject userspace cifs.spnego descriptions * net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) linux-signed-amd64 (6.12.90+2~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.90-2~bpo12+1 . * Rebuild for bookworm-backports linux-signed-amd64 (6.12.90+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.90-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.89 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.90 - HID: playstation: Clamp num_touch_reports - media: uvcvideo: Enable VB2_DMABUF for metadata stream - [arm64] dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd & gpio pinmux - [arm64] regulator: mt6357: fix OF node reference imbalance - [arm64,armhf] regulator: rk808: fix OF node reference imbalance - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap - [amd64] media: intel/ipu6: fix error pointer dereference - media: saa7164: add ioremap return checks and cleanups - spi: aspeed-smc: fix controller deregistration - [amd64] platform/x86: hp-wmi: Ignore backlight and FnLock events - vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy - [arm64] drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() - [amd64] drm/i915/psr: Init variable to avoid early exit from et alignment loop - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count. - drm/amdgpu: gate VM CPU HDP flush on reset lock - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x - drm/amdkfd: Add upper bound check for num_of_nodes - drm/amdgpu: Add bounds checking to ib_{get,set}_value - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB - drm/amdgpu/vce: Prevent partial address patches - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg - drm/amd/display: Change dither policy for 10 bpc output back to dithering - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() - drm/amdkfd: validate SVM ioctl nattr against buffer size - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() - drm/radeon: add missing revision check for CI - drm/amdgpu: zero-initialize GART table on allocation - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds - drm/amdkfd: Make all TLB-flushes heavy-weight - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission - drm/amdgpu/pm: add missing revision check for CI - drm/amdgpu/pm: align Hawaii mclk workaround with radeon - [arm64] dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL - batman-adv: fix integer overflow on buff_pos - batman-adv: reject new tp_meter sessions during teardown - batman-adv: stop caching unowned originator pointers in BAT IV - batman-adv: bla: prevent use-after-free when deleting claims - batman-adv: bla: only purge non-released claims - batman-adv: bla: put backbone reference on failed claim hash insert - usb: typec: tcpm: reset internal port states on soft reset AMS - usb: dwc3: Move GUID programming after PHY initialization - ALSA: hda: cs35l56: Propagate ASP TX source control errors - ALSA: misc: Use guard() for spin locks - ALSA: core: Serialize deferred fasync state checks - ALSA: seq: Notify client and port info changes - ALSA: seq: Fix UMP group 16 filtering - Bluetooth: hci_conn: fix potential UAF in create_big_sync - [arm64,armhf] spi: tegra20-sflash: fix controller deregistration - [arm64,armhf] spi: tegra114: fix controller deregistration - mm/hugetlb_cma: round up per_node before logging it - block: cleanup blkdev_report_zones() - block: reorganize struct blk_zone_wplug - block: fix zone write plug removal - tracefs: Fix default permissions not being applied on initial mount - fbcon: Avoid OOB font access if console rotation fails - mm/damon/core: disallow time-quota setting zero esz - mm/damon/core: implement damon_kdamond_pid() - mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values - mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values - bonding: fix use-after-free due to enslave fail after slave array update (CVE-2026-23171) - io_uring/kbuf: support min length left for incremental buffers - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() - btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() - btrfs: fix double free in create_space_info_sub_group() error path - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak - tracing/probes: Limit size of event probe to 3K - batman-adv: stop tp_meter sessions during mesh teardown - batman-adv: tp_meter: fix tp_num leak on kmalloc failure - vsock: fix buffer size clamping order - vsock/virtio: fix length and offset in tap skb for split packets - vsock/virtio: fix empty payload in tap skb for non-linear buffers - vsock/virtio: fix accept queue count leak on transport mismatch - drm/amdgpu/vcn3: Avoid overflow on msg bound check - drm/amdgpu/vcn4: Avoid overflow on msg bound check . [ Salvatore Bonaccorso ] * Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Closes: #1136790) * net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300) * net: skbuff: propagate shared-frag marker through frag-transfer helpers linux-signed-amd64 (6.12.90+1~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.90-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-amd64 (6.12.88+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.88-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.87 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.88 - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() - ipmi: Add limits to event and receive message requests - ipmi: Check event message buffer response for bad data - ipmi:si: Return state to normal if message allocation fails - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free - ACPI: scan: Use acpi_dev_put() in object add error paths - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug - ACPI: video: force native backlight on HP OMEN 16 (8A44) - ASoC: SOF: Don't allow pointer operations on unconfigured streams - spi: rockchip: fix controller deregistration - ksmbd: rewrite stop_sessions() with restartable iteration - mm: convert mm_lock_seq to a proper seqcount - [amd64] x86: shadow stacks: proper error handling for mmap lock (CVE-2026-43109) - [amd64] x86/shstk: Prevent deadlock during shstk sigreturn - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected GFN - [amd64] iommu/amd: Use atomic64_inc_return() in iommu.c - [amd64] iommu/amd: serialize sequence allocation under concurrent TLB invalidations (CVE-2026-43220) (Closes: #1135313) - flow_dissector: do not dissect PPPoE PFC frames - net: txgbe: fix RTNL assertion warning when remove module - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) - [amd64] KVM: SVM: check validity of VMCB controls when returning from SMM - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (CVE-2026-31499) - exit: prevent preemption of oopsing TASK_DEAD task - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr - wifi: mt76: mt7925: fix incorrect length field in txpower command - wifi: mt76: mt7921: fix a potential clc buffer length underflow - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work - wifi: b43legacy: enforce bounds check on firmware key index in RX path - wifi: mac80211: drop stray 'static' from fast-RX rx_result - wifi: rsi: fix kthread lifetime race between self-exit and external-stop - wifi: mac80211: use safe list iteration in radar detect work - wifi: ath5k: do not access array OOB (Closes: #1119093) - wifi: mac80211: remove station if connection prep fails - wifi: b43: enforce bounds check on firmware key index in b43_rx() - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task - usb: usblp: fix heap leak in IEEE 1284 device ID via short response - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl - ALSA: usb-audio: midi2: Restart output URBs on resume - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() - ALSA: usb-audio: Fix UAC3 cluster descriptor size check - USB: omap_udc: DMA: Don't enable burst 4 mode - USB: serial: option: add Telit Cinterion LE910Cx compositions - usb: ulpi: fix memory leak on ulpi_register() error paths - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger - ALSA: firewire-tascam: Do not drop unread control events - xfrm: provide message size for XFRM_MSG_MAPPING - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() - xfrm: ah: account for ESN high bits in async callbacks - selinux: don't reserve xattr slot when we won't fill it - selinux: shrink critical section in sel_write_load() - selinux: prune /sys/fs/selinux/disable - Bluetooth: virtio_bt: clamp rx length before skb_put - Bluetooth: virtio_bt: validate rx pkt_type header length - Bluetooth: btmtk: validate WMT event SKB length before struct access - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() - [armhf] spi: sun4i: fix controller deregistration - [armhf] spi: ti-qspi: fix controller deregistration - spi: sun6i: fix controller deregistration - fanotify: fix false positive on permission events - [arm64] KVM: arm64: Fix kvm_vcpu_initialized() macro parameter - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo - sound: ua101: fix division by zero at probe - net: libwx: fix VF illegal register access - ip6_gre: Use cached t->net in ip6erspan_changelink(). - net/rds: handle zerocopy send cleanup before the message is queued - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler - hwmon: (ltc2992) Clamp threshold writes to hardware range - hwmon: (ltc2992) Fix u32 overflow in power read path - clk: rk808: fix OF node reference imbalance - hwmon: (corsair-psu) Close HID device on probe errors - af_unix: Reject SIOCATMARK on non-stream sockets - block: add pgmap check to biovec_phys_mergeable - cifs: abort open_cached_dir if we don't request leases - cifs: change_conf needs to be called for session setup - extcon: ptn5150: handle pending IRQ events during system resume - gpio: of: clear OF_POPULATED on hog nodes in remove path - hv_sock: fix ARM64 support - ibmveth: Disable GSO for packets with small MSS - ice: fix double free in ice_sf_eth_activate() error path - spi: microchip-core-qspi: fix controller deregistration - udf: reject descriptors with oversized CRC length - thermal: core: Free thermal zone ID later during removal - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp - spi: topcliff-pch: fix controller deregistration - spi: topcliff-pch: fix use-after-free on unbind - clk: imx: imx8-acm: fix flags for acm clocks - clk: microchip: mpfs-ccc: fix out of bounds access during output registration - cpuidle: powerpc: avoid double clear when breaking snooze - [amd64] ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table - [arm64] ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop - [arm64] ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens - [arm64] ASoC: qcom: q6apm: remove child devices when apm is removed - btrfs: fix double free in create_space_info() error path - dm-thin: fix metadata refcount underflow - dm: don't report warning when doing deferred remove - dm: fix a buffer overflow in ioctl processing - eventfs: Hold eventfs_mutex and SRCU when remount walks events - dm-verity-fec: correctly reject too-small FEC devices - dm-verity-fec: correctly reject too-small hash devices - isofs: validate Rock Ridge CE continuation extent against volume size - isofs: validate block number from NFS file handle in isofs_export_iget - [arm64] iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() - lib/scatterlist: fix length calculations in extract_kvec_to_sg - lib/scatterlist: fix temp buffer in extract_user_to_sg() - libceph: Fix slab-out-of-bounds access in auth message processing - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies - nvme-apple: drop invalid put of admin queue reference count - nvmet-tcp: fix race between ICReq handling and queue teardown - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free - openvswitch: vport: fix self-deadlock on release of tunnel ports - pmdomain: core: Fix detach procedure for virtual devices in genpd - [arm64] RDMA/hns: Fix unlocked call to hns_roce_qp_remove() - [s390x] debug: Reject zero-length input in debug_input_flush_fn() - smb/client: fix out-of-bounds read in smb2_compound_op() - smb/client: fix out-of-bounds read in symlink_data() - smb: client: use kzalloc to zero-initialize security descriptor buffer - smb: client: validate dacloffset before building DACL pointers - [amd64] KVM: x86: check for nEPT/nNPT in slow flush hypercalls - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock - PCI: Update saved_config_space upon resource assignment (Closes: #1131025) - PCI/AER: Clear only error bits in PCIe Device Status - PCI/AER: Stop ruling out unbound devices as error source - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage - power: supply: max17042: avoid overflow when determining health - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() - RDMA/mana: Validate rx_hash_key_len - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads - RDMA/rxe: Reject unknown opcodes before ICRC processing - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path - mptcp: fastclose msk when linger time is 0 - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure - mptcp: sockopt: set timestamp flags on subflow socket, not msk - mptcp: fix scheduling with atomic in timestamp sockopt - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() - f2fs: fix fiemap boundary handling when read extent cache is incomplete - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() - f2fs: fix node_cnt race between extent node destroy and writeback - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() - [arm64] KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value - [arm64] KVM: arm64: Fix initialisation order in __pkvm_init_finalise() - bpf: Fix use-after-free in arena_vm_close on fork - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info - fs: prepare for adding LSM blob to backing_file - dma-mapping: drop unneeded includes from dma-mapping.h - dma-mapping: add __dma_from_device_group_begin()/end() - hwmon: (powerz) Avoid cacheline sharing for DMA buffer - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs - udf: fix partition descriptor append bookkeeping - mtd: spinand: winbond: Declare the QE bit on W25NxxJW - hfsplus: fix uninit-value by validating catalog record size - hfsplus: fix held lock freed on hfsplus_fill_super() - erofs: move {in,out}pages into struct z_erofs_decompress_req - erofs: tidy up z_erofs_lz4_handle_overlap() - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() - gtp: disable BH before calling udp_tunnel_xmit_skb() - printk: add print_hex_dump_devel() - crypto: caam - guard HMAC key hex dumps in hash_digest_key - ALSA: aloop: Fix peer runtime UAF during format-change stop - net: stmmac: avoid shadowing global buf_sz - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() - net: stmmac: Prevent NULL deref when RX memory exhausted - wifi: mt76: mt7925: fix incorrect TLV length in CLC command - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() - [arm64] KVM: arm64: Wake-up from WFI when iqrchip is in userspace - [amd64] x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache - ksmbd: validate inherited ACE SID length . [ Salvatore Bonaccorso ] * ptrace: slightly saner 'get_dumpable()' logic linux-signed-amd64 (6.12.88+1~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.88-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-arm64 (6.12.94+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.94-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.91 - io_uring/kbuf: use mem_is_zero() - blk-cgroup: wait for blkcg cleanup before initializing new disk - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START - fs/mbcache: cancel shrink work before destroying the cache - md/raid1: fix the comparing region of interval tree - drbd: Balance RCU calls in drbd_adm_dump_devices() - loop: fix partition scan race between udev and loop_reread_partitions() - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() - blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() - pstore/ram: fix resource leak when ioremap() fails - md: wake raid456 reshape waiters before suspend - btrfs: pass struct btrfs_inode to clone_copy_inline_extent() - btrfs: fix deadlock between reflink and transaction commit when using flushoncommit - [amd64] ACPI: x86: cmos_rtc: Clean up address space handler driver - [amd64] ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver - devres: fix missing node debug info in devm_krealloc() - thermal/drivers/spear: Fix error condition for reading st,thermal-flags - debugfs: check for NULL pointer in debugfs_create_str() - debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() - soundwire: debugfs: initialize firmware_file to empty string - PCI: use generic driver_override infrastructure - platform/wmi: use generic driver_override infrastructure - [s390x] cio: use generic driver_override infrastructure - bus: fsl-mc: use generic driver_override infrastructure - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter - hrtimers: Update the return type of enqueue_hrtimer() - hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() - hrtimer: Reduce trace noise in hrtimer_start() - locking: Fix rwlock support in - firmware: dmi: Correct an indexing error in dmi.h - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet - bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n - [s390x] bpf: Zero-extend bpf prog return values and kfunc arguments - params: Replace __modinit with __init_or_module - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() - wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control - wifi: mt76: mt7615: fix use_cts_prot support - wifi: mt76: mt7915: fix use_cts_prot support - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() - wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor - wifi: mt76: mt7921: Place upper limit on station AID - [arm64] cpufeature: Make PMUVer and PerfMon unsigned - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() - wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() - wifi: mt76: mt7921: fix 6GHz regulatory update on connection - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path - bpf: Fix variable length stack write over spilled pointers - bpf,arc_jit: Fix missing newline in pr_err messages - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() - r8152: fix incorrect register write to USB_UPHY_XTAL - [powerpc*] crash: fix backup region offset update to elfcorehdr - [powerpc*] crash: Update backup region offset in elfcorehdr on memory hotplug - macvlan: annotate data-races around port->bc_queue_len_used - bpf: fix end-of-list detection in cgroup_storage_get_next_key() - bpf: Fix stale offload->prog pointer after constant blinding - wifi: brcmfmac: Fix error pointer dereference - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() - wifi: ath10k: fix station lookup failure during disconnect - ACPI: AGDI: fix missing newline in error message - [arm64] kexec: Remove duplicate allocation for trans_pgd - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb - net: bcmgenet: add bcmgenet_has_* helpers - net: bcmgenet: move DESC_INDEX flow to ring 0 - net: bcmgenet: support reclaiming unsent Tx packets - net: bcmgenet: switch to use 64bit statistics - net: bcmgenet: fix racing timeout handler - eth: fbnic: Use wake instead of start - netfilter: xt_socket: enable defrag after all other checks - netfilter: nft_fwd_netdev: check ttl/hl before forwarding - bpf: fix mm lifecycle in open-coded task_vma iterator - bpf: switch task_vma iterator from mmap_lock to per-VMA locks - bpf: return VMA snapshot from task_vma iterator - bpf: Fix RCU stall in bpf_fd_array_map_clear() - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf - bpf: Relax scalar id equivalence for state pruning - bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars - net/sched: act_ct: Only release RCU read lock after ct_ft - net: airoha: Implement BQL support - net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() - bpf: Allow instructions with arena source and non-arena dest registers - net/rds: Optimize rds_ib_laddr_check - net/rds: Restrict use of RDS/IB to the initial network namespace - bpf: Fix OOB in pcpu_init_value - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls - net: ipa: Fix programming of QTIME_TIMESTAMP_CFG - net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ - dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 - net: phy: fix a return path in get_phy_c45_ids() - net/mlx5e: Fix features not applied during netdev registration - net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp - Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec - net: phy: qcom: at803x: Use the correct bit to disable extended next page - ipv4: udp: fix typos in comments - ipv6: udp: fix typos in comments - udp: Force compute_score to always inline - tcp: Don't set treq->req_usec_ts in cookie_tcp_reqsk_init(). - sctp: fix missing encap_port propagation for GSO fragments - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master - drm/komeda: fix integer overflow in AFBC framebuffer size check - ASoC: SOF: ipc3: Use standard dev_dbg API - ASoC: add symmetric_ prefix for dai->rate/channels/sample_bits - ASoC: soc-compress: use function to clear symmetric params - drm/sun4i: backend: fix error pointer dereference - ASoC: sti: Return errors from regmap_field_alloc() - ASoC: sti: use managed regmap_field allocations - dm cache: fix null-deref with concurrent writes in passthrough mode - dm cache: fix write path cache coherency in passthrough mode - dm cache: fix write hang in passthrough mode - dm cache policy smq: fix missing locks in invalidating cache blocks - dm cache: fix concurrent write failure in passthrough mode - dm cache: support shrinking the origin device - dm cache: fix dirty mapping checking in passthrough mode switching - platform/chrome: chromeos_tbmc: Drop wakeup source on remove - PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding - PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() - dm cache metadata: fix memory leak on metadata abort retry - dm log: fix out-of-bounds write due to region_count overflow - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check - spi: spi-nxp-fspi: enable runtime pm for fspi - spi: nxp-fspi: Use reinit_completion() for repeated operations - spi: fsl-qspi: Use reinit_completion() for repeated operations - media: i2c: og01a1b: Replace client->dev usage - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe - drm/v3d: Handle error from drm_sched_entity_init() - drm/sun4i: Fix resource leaks - drm/amdgpu: Add default case in DVI mode validation - dm init: ensure device probing has finished in dm-mod.waitfor= - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break - crypto: tegra - finalize crypto req on error - crypto: tegra - Transfer HASH init function to crypto engine - crypto: tegra - Reserve keyslots to allocate dynamically - crypto: tegra - Disable softirqs before finalizing request - crypto: atmel - Use unregister_{aeads,ahashes,skciphers} - crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs - padata: Remove cpu online check from cpu add and removal - padata: Put CPU offline callback in ONLINE section to allow failure - PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation - drm/amdgpu/gfx10: look at the right prop for gfx queue priority - drm/amdgpu/gfx11: look at the right prop for gfx queue priority - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo - drm/imagination: Switch reset_reason fields from enum to u32 - iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() - [arm64] drm/msm/dpu: fix mismatch between power and frequency - [arm64] drm/msm/dsi: add the missing parameter description - [arm64] drm/msm/dsi: fix bits_per_pclk - [arm64] drm/msm/dsi: fix hdisplay calculation for CMD mode panel - [arm64] drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first - drm/panel: simple: Correct G190EAN01 prepare timing - PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support - ALSA: core: Validate compress device numbers without dynamic minors - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels - drm/amd/pm/ci: Fill DW8 fields from SMC - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board - drm/amdgpu: add amdgpu_device reference in ip block - drm/amdgpu: update the handle ptr in dump_ip_state - drm/amdgpu: update the handle ptr in early_init - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled - hwmon: Switch back to struct platform_driver::remove() - hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') - [amd64] ASoC: SOF: Intel: hda: Place check before dereference - [arm64] drm/msm/a6xx: Fix HLSQ register dumping - [arm64] drm/msm/shrinker: Fix can_block() logic - [arm64] drm/msm/a6xx: Fix dumping A650+ debugbus blocks - [arm64] drm/msm/a6xx: Use barriers while updating HFI Q headers - pmdomain: ti: omap_prm: Fix a reference leak on device node - pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() - PM: domains: De-constify fields in struct dev_pm_domain_attach_data - ASoC: fsl_micfil: Add access property for "VAD Detected" - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() - ASoC: fsl_easrc: Change the type for iec958 channel status controls - [amd64] iommu/amd: Remove protection_domain.dev_cnt variable - [amd64] iommu/amd: xarray to track protection_domain->iommu list - [amd64] iommu/amd: Do not detach devices in domain free path - [amd64] iommu/amd: Reduce domain lock scope in attach device path - [amd64] iommu/amd: Rearrange attach device code - [amd64] iommu/amd: Convert dev_data lock from spinlock to mutex - [amd64] iommu/amd: Introduce helper function to update 256-bit DTE - [amd64] iommu/amd: Introduce helper function get_dte256() - [amd64] iommu/amd: Fix clone_alias() to use the original device's devid - [arm64] ASoC: qcom: qdsp6: topology: check widget type before accessing data - crypto: qat - introduce fuse array - crypto: qat - disable 4xxx AE cluster when lead engine is fused off - crypto: qat - disable 420xx AE cluster when lead engine is fused off - crypto: qat - fix type mismatch in RAS sysfs show functions - crypto: qat - use swab32 macro - ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] - PCI: Enable AtomicOps only if Root Port supports them - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found - Documentation: fix a hugetlbfs reservation statement - ALSA: scarlett2: Add missing sentinel initializer field - ASoC: SOF: compress: return the configured codec from get_params - PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports - PCI: tegra194: Fix polling delay for L2 state - PCI: tegra194: Increase LTSSM poll time on surprise link down - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down - PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() - PCI: tegra194: Don't force the device into the D0 state before L2 - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" - PCI: tegra194: Disable direct speed change for Endpoint mode - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode - PCI: tegra194: Allow system suspend when the Endpoint link is not up - PCI: tegra194: Free up Endpoint resources during remove() - PCI: tegra194: Use DWC IP core version - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well - PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback - ALSA: sc6000: Keep the programmed board state in card-private data - dm cache: fix missing return in invalidate_committed's error path - crypto: jitterentropy - replace long-held spinlock with mutex - ALSA: hda/realtek - fixed speaker no sound update - gfs2: Call unlock_new_inode before d_instantiate - net/socket.c: switch to CLASS(fd) - fdget(), trivial conversions - fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() - quota: Fix race of dquot_scan_active() with quota deactivation - gfs2: add some missing log locking - gfs2: prevent NULL pointer dereference during unmount - efi/capsule-loader: fix incorrect sizeof in phys array reallocation - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine - [arm64] dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon - memory: tegra124-emc: Fix dll_change check - memory: tegra30-emc: Fix dll_change check - [arm64] dts: imx8-apalis: Fix LEDs name collision - [arm64] dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config - [arm64] dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) - iommufd: vfio compatibility extension check for noiommu mode - [arm64] dts: mediatek: mt6795: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7981b: Fix gpio-ranges pin count - [arm64] dts: mediatek: mt7986a: Fix gpio-ranges pin count - [arm64] dts: qcom: msm8953-xiaomi-vince: correct wled ovp value - [arm64] dts: qcom: msm8953-xiaomi-daisy: fix backlight - [arm64] dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi - [arm64] dts: rockchip: Correct Fan Supply for Gameforce Ace - [arm64] dts: rockchip: Correct Joystick Axes on Gameforce Ace - [arm64] soc: qcom: ocmem: make the core clock optional - [arm64] soc: qcom: ocmem: register reasons for probe deferrals - [arm64] soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available - bus: rifsc: fix RIF configuration check for peripherals - [arm64] dts: qcom: sm8450: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix GIC_ITS range length - [arm64] dts: qcom: sm8650: Fix GIC_ITS range length - [arm64] dts: qcom: sm8550: Fix xo clock supply of platform SD host controller - [arm64] dts: qcom: sm8650: Fix xo clock supply of SD host controller - [arm64] dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes - [arm64] dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl - [arm64] dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot - [arm64] dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins - [arm64] dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins - [arm64] dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label - [arm64] dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing - [arm64] dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit - [arm64] dts: lx2160a: remove duplicate pinmux nodes - [arm64] dts: lx2160a: rename pinmux nodes for readability - [arm64] dts: lx2160a: add sda gpio references for i2c bus recovery - [arm64] dts: lx2160a: change zeros to hexadecimal in pinmux nodes - [arm64] dts: lx2160a: complete pinmux for rcwsr12 configuration word - [arm64] dts: imx8qm-mek: switch Type-C connector power-role to dual - [arm64] dts: imx8qxp-mek: switch Type-C connector power-role to dual - soc/tegra: cbb: Set ERD on resume for err interrupt - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure - ocfs2/dlm: validate qr_numregions in dlm_match_regions() - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison - soc: qcom: llcc: fix v1 SB syndrome register offset - [arm64] soc: qcom: aoss: compare against normalized cooling state - [arm64] dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP - [arm64] xor: fix conflicting attributes for xor_block_template - firmware: arm_ffa: Use the correct buffer size during RXTX_MAP - ocfs2: fix listxattr handling when the buffer is full - ocfs2: validate bg_bits during freefrag scan - ocfs2: validate group add input before caching - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() - soundwire: cadence: Clear message complete before signaling waiting thread - tracing: Rebuild full_name on each hist_field_name() call - hte: tegra194: remove Kconfig dependency on Tegra194 SoC - remoteproc: xlnx: Fix sram property parsing - ima: check return value of crypto_shash_final() in boot aggregate - HID: asus: make asus_resume adhere to linux kernel coding standards - HID: asus: do not abort probe when not necessary - mtd: physmap_of_gemini: Fix disabled pinctrl state check - ima_fs: don't bother with removal of files in directory we'll be removing - ima_fs: get rid of lookup-by-dentry stuff - ima_fs: Correctly create securityfs files for unsupported hash algos - dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations - mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook - mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook - mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions - cxl/pci: Check memdev driver binding status in cxl_reset_done() - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob - HID: usbhid: fix deadlock in hid_post_reset() - ext4: fix possible null-ptr-deref in mbt_kunit_exit() - [arm64] bpf, arm64: Fix off-by-one in check_imm signed range check - bpf, sockmap: Fix af_unix iter deadlock - bpf, sockmap: Fix af_unix null-ptr-deref in proto update - bpf, sockmap: Take state lock for af_unix iter - bpf: Fix precedence bug in convert_bpf_ld_abs alignment check - bpf: Fix NULL deref in map_kptr_match_type for scalar regs - bpf: allow UTF-8 literals in bpf_bprintf_prepare() - bpf: Validate node_id in arena_alloc_pages() - bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT - pinctrl: pinctrl-pic32: Fix resource leak - pinctrl: cy8c95x0: remove duplicate error message - pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() - pinctrl: cy8c95x0: Avoid returning positive values to user space - perf branch: Avoid incrementing NULL - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace - pinctrl: realtek: Fix function signature for config argument - pinctrl: abx500: Fix type of 'argument' variable - pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers - perf lock: Fix option value type in parse_max_stack - perf stat: Fix opt->value type for parse_cache_level - perf tools: Fix module symbol resolution for non-zero .text sh_addr - perf expr: Return -EINVAL for syntax error in expr__find_ids() - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure - ipmi: ssif_bmc: fix message desynchronization after truncated response - ipmi: ssif_bmc: change log level to dbg in irq callback - perf evsel: Add alternate_hw_config and use in evsel__match - perf tool_pmu: Factor tool events into their own PMU - perf python: Add parse_events function - perf cgroup: Update metric leader in evlist__expand_cgroup - perf maps: Fix copy_from that can break sorted by name order - perf util: Kill die() prototype, dead for a long time - reset: replace boolean parameters with flags parameter - reset: Add devres helpers to request pre-deasserted reset controls - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() - platform/surface: surfacepro3_button: Drop wakeup source on remove - leds: lgm-sso: Remove duplicate assignments for priv->mmap - tty: hvc_iucv: fix off-by-one in number of supported devices - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() - nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist() - [amd64] platform/x86: asus-wmi: adjust screenpad power/brightness handling - [amd64] platform/x86: asus-wmi: fix screenpad brightness range - tty: serial: ip22zilog: Fix section mispatch warning - fs/ntfs3: terminate the cached volume label after UTF-8 conversion - [amd64] platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() - [amd64] platform/x86: dell-wmi-sysman: bound enumeration string aggregation - RDMA/core: Prefer NLA_NUL_STRING - clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source - scsi: sg: Fix sysctl sg-big-buff register during sg_init() - scsi: sg: Resolve soft lockup issue when opening /dev/sgX - clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers - clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting - scsi: target: core: Fix integer overflow in UNMAP bounds check - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Add missing GDSCs - clk: qcom: gcc-sc8180x: Use retention for USB power domains - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() - clk: imx8mq: Correct the CSI PHY sels - [amd64] x86/um/vdso: Drop VDSO64-y from Makefile - clk: qoriq: avoid format string warning - clk: xgene: Fix mapping leak in xgene_pllclk_init() - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets - clk: qcom: dispcc-sc7180: Add missing MDSS resets - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() - clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON - clk: visconti: pll: initialize clk_init_data to zero - f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() - [amd64] drm/i915: Relocate the SKL wm sanitation code - [amd64] drm/i915/wm: Verify the correct plane DDB entry - crypto: sa2ul - Fix AEAD fallback algorithm names - crypto: ccp - copy IV using skcipher ivsize - erofs: add encoded extent on-disk definition - erofs: do sanity check on m->type in z_erofs_load_compact_lcluster() - erofs: avoid infinite loops due to corrupted subpage compact indexes (CVE-2025-68251) - erofs: unify lcn as u64 for 32-bit platforms - [arm64] dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT - PCMCIA: Fix garbled log messages for KERN_CONT - [arm64] dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT - [arm64] dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT - [arm64] dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names - net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir - macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF - net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys - nexthop: fix IPv6 route referencing IPv4 nexthop - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch - tcp: add data-race annotations around tp->data_segs_out and tp->total_retrans - tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE - tcp: annotate data-races around tp->bytes_sent - tcp: annotate data-races around tp->bytes_retrans - tcp: annotate data-races around tp->dsack_dups - tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) - tcp: annotate data-races around tp->plb_rehash - ice: update PCS latency settings for E825 10G/25Gb modes - ice: Remove jumbo_remove step from TX path - ice: fix double-free of tx_buf skb - ice: fix ICE_AQ_LINK_SPEED_M for 200G - i40e: don't advertise IFF_SUPP_NOFCS - e1000e: Unroll PTP in probe error handling - ipv6: fix possible UAF in icmpv6_rcv() - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks - pppoe: drop PFC frames - net/mlx5: Fix HCA caps leak on notifier init failure - openvswitch: cap upcall PID array size and pre-size vport replies - netfilter: nft_osf: restrict it to ipv4 - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO - netfilter: conntrack: remove sprintf usage - netfilter: xtables: restrict several matches to inet family - ipvs: fix MTU check for GSO packets in tunnel mode - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check - slip: reject VJ receive packets on instances with no rstate array - slip: bound decode() reads against the compressed packet length - [arm64] dts: meson-gxl-p230: fix ethernet PHY interrupt number - pwm: atmel-tcb: Cache clock rates and mark chip as atomic - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() - ksmbd: destroy async_ida in ksmbd_conn_free() - ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open - ksmbd: scope conn->binding slowpath to bound sessions only - net/rds: zero per-item info buffer before handing it to visitors - ice: fix timestamp interrupt configuration for E825C - ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() - net/sched: sch_pie: annotate data-races in pie_dump_stats() - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() - net/sched: sch_red: annotate data-races in red_dump_stats() - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() - net: dsa: realtek: rtl8365mb: fix mode mask calculation - net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() - virtio_net: Split struct virtio_net_rss_config - virtio_net: Fix endian with virtio_net_ctrl_rss - virtio_net: Use new RSS config structs - virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls - tipc: fix double-free in tipc_buf_append() - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() - fs/adfs: validate nzones in adfs_validate_bblk() - rtc: abx80x: Disable alarm feature if no interrupt attached - kbuild: builddeb - avoid recompiles for non-cross-compiles - fbdev: offb: fix PCI device reference leak on probe failure - mailbox: mtk-cmdq: Fix CURR and END addr for task insert case - mailbox: mailbox-test: free channels on probe error - cgroup/rdma: fix integer overflow in rdmacg_try_charge() - mailbox: add sanity check for channel array - mailbox: mailbox-test: don't free the reused channel - mailbox: mailbox-test: initialize struct earlier - mailbox: mailbox-test: make data_ready a per-instance variable - fsnotify: fix inode reference leak in fsnotify_recalc_mask() - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() - cgroup: Increment nr_dying_subsys_* from rmdir context - tracing: branch: Fix inverted check on stat tracer registration - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers - netfilter: arp_tables: fix IEEE1394 ARP payload parsing - nvme-pci: fix missed admin queue sq doorbell write - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG - drm/amdgpu: fix spelling typos - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) - netfilter: xt_policy: fix strict mode inbound policy matching - netfilter: nf_conntrack_sip: don't use simple_strtoul - [amd64] ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ - drm/sysfb: ofdrm: fix PCI device reference leaks - arm64/scs: Fix potential sign extension issue of advance_loc4 - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() - netdevsim: zero initialize struct iphdr in dummy sk_buff - net/sched: netem: fix probability gaps in 4-state loss model - net/sched: netem: fix queue limit check to include reordered packets - net/sched: netem: only reseed PRNG when seed is explicitly provided - net/sched: netem: validate slot configuration - net/sched: netem: fix slot delay calculation overflow - net/sched: netem: check for negative latency and jitter - net/sched: sch_choke: annotate data-races in choke_dump_stats() - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() - vrf: Fix a potential NPD when removing a port from a VRF - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit - NFC: trf7970a: Ignore antenna noise when checking for RF field - net/sched: taprio: fix NULL pointer dereference in class dump - neigh: let neigh_xmit take skb ownership - tcp: make probe0 timer handle expired user timeout - net, treewide: define and use MAC_ADDR_STR_LEN - netconsole: allow selection of egress interface via MAC address - netpoll: Extract carrier wait function - netpoll: extract IPv4 address retrieval into helper function - netpoll: fix IPv6 local-address corruption - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams - sched/fair: Clear rel_deadline when initializing forked entities - net: mctp i2c: check length before marking flow active - net: phy: dp83869: fix setting CLK_O_SEL field. - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring - ASoC: codecs: ab8500: Fix casting of private data - netfilter: skip recording stale or retransmitted INIT - sctp: discard stale INIT after handshake completion - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) - netconsole: propagate device name truncation in dev_name_store() - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 - ALSA: hda/conexant: Fix missing error check for jack detection - ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup - drm/amd/display: Allow DCE link encoder without AUX registers - drm/amd/display: Read EDID from VBIOS embedded panel info - drm/xe/debugfs: Correct printing of register whitelist ranges - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() - page_pool: Set `dma_sync` to false for devmem memory provider - net: page_pool: create hooks for custom memory providers - page_pool: fix memory-provider leak in page_pool_create_percpu() error path - iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING - iavf: stop removing VLAN filters from PF on interface down - iavf: wait for PF confirmation before removing VLAN filters - iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler - ice: fix NULL pointer dereference in ice_reset_all_vfs() - net: tls: fix strparser anchor skb leak on offload RX setup failure - sfc: fix error code in efx_devlink_info_running_versions() - net/sched: cls_flower: revert unintended changes - [arm64] Reserve an extra page for early kernel mapping - smb: client: correctly handle ErrorContextData as a flexible array - smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) - LoongArch: KVM: Compile switch.S directly into the kernel - ntfs: ->d_compare() must not block - PCI: Initialize temporary device in new_id_store() - net: bcmgenet: Initialize u64 stats seq counter - net: bcmgenet: fix leaking free_bds - [amd64] iommu/amd: Reorder attach device code - [amd64] iommu/amd: Put list_add/del(dev_data) back under the domain->lock - perf tool_pmu: Fix aggregation on duration_time - net/sched: sch_pie: annotate more data-races in pie_dump_stats() - netpoll: Extract IPv6 address retrieval function - netpoll: pass buffer size to egress_dev() to avoid MAC truncation - page_pool: fix incorrect mp_ops error handling - crypto: af_alg - Cap AEAD AD length to 0x80000000 - i40e: Cleanup PTP pins on probe failure - workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path - netfilter: nf_conntrack_sip: get helper before allocating expectation - audit: fix incorrect inheritable capability in CAPSET records - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" - netfilter: nft_ct: fix missing expect put in obj eval - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() - [s390x] KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic - [amd64] KVM: x86: Fix Xen hypercall tracepoint argument assignment - netfilter: nf_tables: unconditionally bump set->nelems before insertion (CVE-2026-23272) - ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands - smb/client: fix possible infinite loop and oob read in symlink_data() - [amd64] drm/i915/dp: Fix VSC dynamic range signaling for RGB formats - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans - ALSA: usb-audio: Bound MIDI endpoint descriptor scans - ceph: fix a buffer leak in __ceph_setxattr() - ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size - io-wq: check that the predecessor is hashed in io_wq_remove_pending() - [powerpc*] warp: Fix error handling in pika_dtm_thread - netfs: fix error handling in netfs_extract_user_iter() - irqchip/riscv-imsic: Clear interrupt move state during CPU offlining - libceph: Fix potential out-of-bounds access in osdmap_decode() - libceph: Fix potential null-ptr-deref in decode_choose_args() - libceph: Fix potential out-of-bounds access in crush_decode() - libceph: handle rbtree insertion error in decode_choose_args() - [amd64] iommu/vt-d: Disable DMAR for Intel Q35 IGFX - [amd64] drm/i915: skip __i915_request_skip() for already signaled requests - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() - drm/xe/dma-buf: handle empty bo and UAF races - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup - drm/gma500/oaktrail_lvds: fix hang on init failure - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init - iommufd: Fix return value of iommufd_fault_fops_write() - eventfs: Use list_add_tail_rcu() for SRCU-protected children list - drm/v3d: Reject empty multisync extension to prevent infinite loop - btrfs: use inode already stored in local variable at btrfs_rmdir() - btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() - btrfs: fix missing last_unlink_trans update when removing a directory - smb: client: Use FullSessionKey for AES-256 encryption key derivation - btrfs: do not mark inode incompressible after inline attempt fails - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() - sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new - mptcp: pm: prio: skip closed subflows - mptcp: drop __mptcp_fastopen_gen_msk_ackseq() - mptcp: fix rx timestamp corruption on fastopen - f2fs: fix incorrect file address mapping when inline inode is unwritten - f2fs: fix false alarm of lockdep on cp_global_sem lock - spi: sifive: Simplify clock handling with devm_clk_get_enabled() - spi: sifive: fix controller deregistration - mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 - mptcp: pm: ADD_ADDR rtx: fix potential data-race - mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker - netfs: Fix potential uninitialised var in netfs_extract_user_iter() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.92 - mptcp: sync the msk->sndbuf at accept() time - mptcp: pm: ADD_ADDR rtx: allow ID 0 - mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (CVE-2026-46158) - mptcp: pm: ADD_ADDR rtx: free sk if last (CVE-2026-46170) - ksmbd: validate owner of durable handle on reconnect (CVE-2026-31717) - drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (CVE-2026-46216) - [s390x] debug: Reject zero-length input before trimming a newline - Revert "perf cgroup: Update metric leader in evlist__expand_cgroup" - Revert "perf tool_pmu: Fix aggregation on duration_time" - Revert "perf python: Add parse_events function" - Revert "perf tool_pmu: Factor tool events into their own PMU" - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420) - spi: spi-dw-dma: fix print error log when wait finish transaction (CVE-2026-31560) - Revert "x86/vdso: Fix output operand size of RDPID" - sched/deadline: Less agressive dl_server handling - sched/deadline: Fix dl_server_stopped() - sched/deadline: Fix dl_server getting stuck - sched/deadline: Fix dl_server behaviour - sched/deadline: Stop dl_server before CPU goes offline - ksmbd: close durable scavenger races against m_fp_list lookups - af_unix: Give up GC if MSG_PEEK intervened. (CVE-2026-23394) - drm/imagination: Synchronize interrupts before suspending the GPU (CVE-2026-23469) - ata: libata-scsi: improve readability of ata_scsi_qc_issue() - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS - perf parse-events: Expose/rename config_term_name - Revert "ice: fix double-free of tx_buf skb" - Revert "ice: Remove jumbo_remove step from TX path" - tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 - net/mlx5e: Trigger neighbor resolution for unresolved destinations - net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init - [amd64] x86/fgraph: Fix return_to_handler regs.rsp value - [amd64] iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set - [riscv64] fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends on HAVE_DYNAMIC_FTRACE_WITH_ARGS - [riscv64] fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (CVE-2025-22069) - hwmon: (pmbus/core) Protect regulator operations with mutex - [arm64] Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL - sysfs: don't remove existing directory on update failure - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() - ksmbd: fix null pointer dereference in compare_guid_key() - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow - ksmbd: validate SID in parent security descriptor during ACL inheritance - smb: client: require net admin for CIFS SWN netlink - smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() - smb: client: use data_len for SMB2 READ encrypted folioq copy - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX - ALSA: ua101: Reject too-short USB descriptors - ALSA: pcm: Don't setup bogus iov_iter for silencing - ALSA: asihpi: Fix potential OOB array access at reading cache - efi: Allocate runtime workqueue before ACPI init - io_uring/waitid: clear waitid info before copying it to userspace - drivers/base/memory: fix memory block reference leak in poison accounting - ipv6: ioam: refresh hdr pointer before ioam6_event() - mm/memory_hotplug: fix memory block reference leak on remove - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START - Bluetooth: bnep: Fix UAF read of dev->name - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer - Bluetooth: MGMT: validate Add Extended Advertising Data length - Bluetooth: serialize accept_q access - phonet/pep: disable BH around forwarded sk_receive_skb() - net: bcmgenet: keep RBUF EEE/PM disabled - net: ifb: report ethtool stats over num_tx_queues - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() - netfilter: ip6t_hbh: reject oversized option lists - netfilter: nf_queue: hold bridge skb->dev while queued - netfilter: ipset: stop hash:* range iteration at end - netfilter: nft_inner: Fix IPv6 inner_thoff desync - sched_ext: Fix missing warning in scx_set_task_state() default case - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path - cgroup/cpuset: Reset DL migration state on can_attach() failure - fs/ntfs3: handle attr_set_size() errors when truncating files - l2tp: use list_del_rcu in l2tp_session_unhash - qed: fix double free in qed_cxt_tables_alloc() - ring-buffer: Fix reporting of missed events in iterator - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() - vsock/vmci: fix UAF when peer resets connection during handshake - vsock/virtio: reset connection on receiving queue overflow - wifi: ath11k: clear shared SRNG pointer state on restart - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 - ixgbevf: fix use-after-free in VEPA multicast source pruning - rbd: eliminate a race in lock_dwork draining on unmap - lsm: hold cred_guard_mutex for lsm_set_self_attr() - [arm64] octeontx2-af: CGX: add bounds check to cgx_speed_mbps index - ice: fix setting promisc mode while adding VID filter - ice: restore PTP Rx timestamp config after ethtool set-channels - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() - af_unix: Fix UAF read of tail->len in unix_stream_data_wait() - wifi: mac80211: consume only present negotiated TTLM maps - cifs: Fix busy dentry used after unmounting - tracing: Do not call map->ops->elt_free() if elt_alloc() fails - [arm64] probes: Handle probes on hinted conditional branch instructions - [arm64] KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits - [arm64] KVM: arm64: vgic: Free private_irqs when init fails after allocation - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe - spi: qup: fix error pointer deref after DMA setup failure - [arm64] phy: tegra: xusb: Fix per-pad high-speed termination calibration - scsi: isci: Fix use-after-free in device removal path - spi: ep93xx: fix error pointer deref after DMA setup failure - spi: sprd: fix error pointer deref after DMA setup failure - spi: ti-qspi: fix use-after-free after DMA setup failure - RDMA/siw: Reject MPA FPDU length underflow before signed receive math - device property: set fwnode->secondary to NULL in fwnode_init() - drm/virtio: use uninterruptible resv lock for plane updates - drm/amdgpu/vpe: Force collaborate sync after TRAP - drm/bridge: it66121: acquire reset GPIO in probe - drm/bridge: megachips: remove bridge when irq request fails - drm/amd/display: Fix integer overflow in bios_get_image() - drm/amd/display: Validate GPIO pin LUT table size before iterating - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async - batman-adv: mcast: fix use-after-free in orig_node RCU release - batman-adv: clear current gateway during teardown - batman-adv: dat: handle forward allocation error - batman-adv: fix fragment reassembly length accounting - batman-adv: fix tp_meter counter underflow during shutdown - batman-adv: frag: disallow unicast fragment in fragment - batman-adv: bla: fix report_work leak on backbone_gw purge - batman-adv: tp_meter: avoid use of uninit sender vars - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown - batman-adv: tp_meter: fix race condition in send error reporting - batman-adv: tt: fix negative last_changeset_len - batman-adv: tt: fix negative tt_buff_len - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock - hwmon: (pmbus/adm1266) reject implausible blackbox record_count - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors - [arm64] pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume - HID: uclogic: Fix regression of input name assignment - [riscv64] mm: Fixup no5lvl failure when vaddr is invalid - [arm64] pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 - ALSA: hda: cs35l56: Put ACPI device after setting companion - ALSA: hda: cs35l41: Put ACPI device on missing physical node - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() - netfilter: x_tables: unregister the templates first - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() - tcp: Fix imbalanced icsk_accept_queue count. - ice: fix setting RSS VSI hash for E830 - ice: fix locking in ice_dcb_rebuild() - net: lan966x: avoid unregistering netdev on register failure - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access - NFSD: Fix infinite loop in layout state revocation - irqchip/ath79-cpu: Remove unused function - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation - nsfs: fix wrong error code returned for pidns ioctls - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT - zonefs: handle integer overflow in zonefs_fname_to_fno - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). - [powerpc*] fix dead default for GUEST_STATE_BUFFER_TEST - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call - netfs: Fix overrun check in netfs_extract_user_iter() - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone - netfs: Defer the emission of trace_netfs_folio() - netfs: Fix streaming write being overwritten - netfs: Fix potential deadlock in write-through mode - netfs: Fix write streaming disablement if fd open O_RDWR - netfs: Fix early put of sink folio in netfs_read_gaps() - netfs: Fix partial invalidation of streaming-write folio - netfs: Fix a few minor bugs in netfs_page_mkwrite() - netfs: Remove unnecessary references to pages - netfs: Fix folio->private handling in netfs_perform_write() - net: ethernet: cortina: Make RX SKB per-port - net: ethernet: cortina: Drop half-assembled SKB - net: ethernet: cortina: Carry over frag counter - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference - wifi: ath11k: fix error path leaks in some WMI WOW calls - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() - wifi: ath10k: skip WMI and beacon transmission when device is wedged - blk-integrity: remove seed for user mapped buffers - block: don't overwrite bip_vcnt in bio_integrity_copy_user() - block: recompute nr_integrity_segments in blk_insert_cloned_request - HID: quirks: really enable the intended work around for appledisplay - block: modify bio_integrity_map_user to accept iov_iter as argument - block: drop direction param from bio_integrity_copy_user() - blk-integrity: use simpler alignment check - blk-integrity: enable p2p source and destination - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() - accel/qaic: Add overflow check to remap_pfn_range during mmap - net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics - [arm64] drm/msm/dsi: don't dump registers past the mapped region - [arm64] drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN - [powerpc*] time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring - net: tls: prevent chain-after-chain in plain text SG - net: phy: DP83TC811: add reading of abilities - [amd64] x86/xen: Fix xen_e820_swap_entry_with_ram() - tls: Preserve sk_err across recvmsg() when data has been copied - net/mlx5: Do not restore destination-less TC rules - scsi: sd: Fix return code handling in sd_spinup_disk() - ALSA: scarlett2: Add missing error check when initialise Autogain Status - io_uring/net: punt IORING_OP_BIND async if it needs file create - btrfs: fix squota accounting during enable generation - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() - [arm64] drm/msm/snapshot: fix dumping of the unaligned regions - drm/xe/gsc: Fix double-free of managed BO in error path - drm/xe/vf: Fix signature of print functions - drm/xe/pf: Fix CFI failure in debugfs access - wifi: ath11k: fix peer resolution on rx path when peer_id=0 - ice: ptp: serialize E825 PHY timer start with PTP lock - [amd64] drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP - [arm64] net: dsa: mt7530: fix FDB entries not aging out with short timeout - [arm64] net: dsa: mt7530: preserve VLAN tags on trapped link-local frames - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 - [amd64] platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: hp_accel: Check ACPI_COMPANION() against NULL - [amd64] platform/x86: intel-hid: Check ACPI_HANDLE() against NULL - [amd64] platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL - RDMA/rtrs: Fix use-after-free in path file creation cleanup - net: bridge: Flush multicast groups when snooping is disabled - bridge: mcast: Fix a possible use-after-free when removing a bridge port - pds_core: fix error handling in pdsc_devcmd_wait - pds_core: fix debugfs_lookup dentry leak and error handling - wifi: mac80211: fix MLE defragmentation - ALSA: seq: Serialize UMP output teardown with event_input - tracing: Avoid NULL return from hist_field_name() on truncation - Bluetooth: btmtk: fix urb->setup_packet leak in error paths - net: ag71xx: check error for platform_get_irq - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() - drm/xe/oa: Fix exec_queue leak on width check in stream open - [arm64] octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs - net: mana: validate rx_req_idx to prevent out-of-bounds array access - pds_core: ensure null-termination for firmware version strings - net: gro: don't merge zcopy skbs - landlock: Fix TCP handling of short AF_UNSPEC addresses - block: make bio_integrity_map_user() static inline - security/keys: fix missed RCU read section on lookup https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.93 - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size - [arm64] drm/v3d: Fix use-after-free of CPU job query arrays on error path - [arm64] drm/v3d: Release indirect CSD GEM reference on CPU job free - net/sched: cls_fw: fix NULL dereference of "old" filters before change() - net: mctp: ensure our nlmsg responses are initialised (CVE-2026-45930) - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit - net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked - bcache: fix uninitialized closure object - net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (CVE-2026-43219) - [arm64] Introduce esr_is_ubsan_brk() - [arm64] debug: clean up single_step_handler logic - [arm64] refactor aarch32_break_handler() - [arm64] debug: call software breakpoint handlers statically - [arm64] debug: call step handlers statically - [arm64] debug: remove break/step handler registration infrastructure - [arm64] entry: Add entry and exit functions for debug exceptions - [arm64] debug: split hardware breakpoint exception entry - [arm64] debug: refactor reinstall_suspended_bps() - [arm64] debug: split single stepping exception entry - [arm64] debug: split hardware watchpoint exception entry - [arm64] debug: split brk64 exception entry - [arm64] debug: split bkpt32 exception entry - [arm64] debug: remove debug exception registration infrastructure - [arm64] debug: always unmask interrupts in el0_softstp() - nfc: llcp: Fix use-after-free in llcp_sock_release() - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() - xfrm: Check for underflow in xfrm_state_mtu - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems - netfilter: synproxy: refresh tcphdr after skb_ensure_writable - netfilter: xt_cpu: prefer raw_smp_processor_id - netfilter: ebtables: fix OOB read in compat_mtw_from_user - tun: free page on short-frame rejection in tun_xdp_one() (CVE-2026-46321) - tun: free page on build_skb failure in tun_xdp_one() (CVE-2026-46322) - vsock: keep poll shutdown state consistent - net: netlink: fix sending unassigned nsid after assigned one - net: netlink: don't set nsid on local notifications - net/smc: Do not re-initialize smc hashtables - [s390x] net/iucv: fix locking in .getsockopt - scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues - ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() - ALSA: pcm: oss: Fix setup list UAF on proc write error - [amd64] ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors - net: hsr: fix potential OOB access in supervision frame handling - [amd64] accel/ivpu: prevent uninitialized data bug in debugfs - gpio: mxc: fix irq_high handling - net: Avoid checksumming unreadable skb tail on trim - ethtool: rss: fix hkey leak when indir_size is 0 - ethtool: module: avoid leaking a netdev ref on module flash errors - ethtool: module: check fw_flash_in_progress under rtnl_lock - ethtool: module: fix cleanup if socket used for flashing multiple devices - ethtool: cmis: require exact CDB reply length - ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl - net: ethtool: Add new parameters and a function to support EPL - net: ethtool: Add support for writing firmware blocks using EPL payload - ethtool: cmis: validate start_cmd_payload_size from module - ethtool: cmis: validate fw->size against start_cmd_payload_size - tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() - ASoC: codecs: simple-mux: Fix enum control bounds check - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() - bonding: refuse to enslave CAN devices - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES - ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error - ethtool: pse-pd: fix missing ethnl_ops_complete() - ethtool: strset: fix header attribute index in ethnl_req_get_phydev() - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback - ethtool: eeprom: add more safeties to EEPROM Netlink fallback - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() - net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" - net/sched: fix packet loop on netem when duplicate is on - net/sched: act_mirred: Move the recursion counter struct netdev_xmit - net/sched: act_mirred: add loop detection - net: Introduce skb tc depth field to track packet loops - net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop - net/sched: act_mirred: Fix return code in early mirred redirect error paths - net/handshake: Use spin_lock_bh for hn_lock - nvme-tcp: store negative errno in queue->tls_err - net/handshake: Pass negative errno through handshake_complete() - remove pointless includes of - net/handshake: Take a long-lived file reference at submit - net/handshake: Drain pending requests at net namespace exit - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close - [arm64,armhf] gpio: rockchip: convert bank->clk to devm_clk_get_enabled() - [amd64,arm64] net: mana: Add NULL guards in teardown path to prevent panic on attach failure - sctp: fix race between sctp_wait_for_connect and peeloff - ipv6: fix possible infinite loop in rt6_fill_node() - ipv6: fix possible infinite loop in fib6_select_path() - net: skbuff: fix pskb_carve leaking zcopy pages - perf: Fix dangling cgroup pointer in cpuctx - batman-adv: v: stop OGMv2 on disabled interface - batman-adv: tvlv: abort OGM send on tvlv append failure - batman-adv: tt: reject oversized local TVLV buffers - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface - batman-adv: tvlv: reject oversized TVLV packets - batman-adv: iv: recover OGM scheduling after forward packet error - batman-adv: tp_meter: avoid role confusion in tp_list - [s390x] cio: Restore GFP_DMA for CHSC allocation - batman-adv: tp_meter: directly shut down timer on cleanup - batman-adv: tt: fix TOCTOU race for reported vlans - batman-adv: tt: avoid empty VLAN responses - batman-adv: bla: avoid double decrement of bla.num_requests - mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303) - media: rc: fix race between unregister and urb/irq callbacks - media: rc: ttusbir: fix inverted error logic - inet: frags: add inet_frag_queue_flush() - inet: frags: flush pending skbs in fqdir_pre_exit() (CVE-2025-68768) - HID: core: Add printk_ratelimited variants to hid_warn() etc - HID: pass the buffer size to hid_report_raw_event - HID: core: introduce hid_safe_input_report() - HID: core: Fix size_t specifier in hid_report_raw_event() - [amd64] drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register - [amd64] drm/i915/psr: Read Intel DPCD workaround register - drm/dp: Add eDP 1.5 bit definition - [amd64] drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used - [arm64] io: Rename ioremap_prot() to __ioremap_prot() - [arm64] io: Extract user memory type in ioremap_prot() (CVE-2026-23346) - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X - batman-adv: tt: prevent TVLV entry number overflow - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer - usb: typec: ucsi: ccg: reject firmware images without a ':' record header - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers - usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO - usb: typec: altmodes/displayport: validate count before reading Status Update VDO - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT - usb: typec: ucsi: validate connector number in ucsi_connector_change() - USB: serial: safe_serial: fix memory corruption with small endpoint - media: rc: igorplugusb: fix control request setup packet - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse - Bluetooth: btusb: Allow firmware re-download when version matches - hpfs: fix a crash if hpfs_map_dnode_bitmap fails - ipc: limit next_id allocation to the valid ID range - auxdisplay: line-display: fix OOB read on zero-length message_store() - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn - Bluetooth: HIDP: fix missing length checks in hidp_input_report() - Bluetooth: ISO: fix UAF in iso_recv_frame - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync - Input: xpad - fix out-of-bounds access for Share button - parport: Fix race between port and client registration (Closes: #1130365) - USB: cdc-acm: Fix bit overlap and move quirk definitions to header - [arm64] KVM: arm64: PMU: Preserve AArch32 counter low bits - [amd64] KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC - [amd64] KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use - [amd64] KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests - [amd64] KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 - [amd64] KVM: SEV: Compute the correct max length of the in-GHCB scratch area - [amd64] KVM: SEV: Check PSC request indices against the actual size of the buffer - [amd64] KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer - [amd64] KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux - iio: adc: npcm: fix unbalanced clk_disable_unprepare() - iio: dac: max5821: fix return value check in powerdown sync - iio: dac: ad5686: fix input raw value check - iio: dac: ad5686: acquire lock when doing powerdown control - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw - iio: gyro: itg3200: fix i2c read into the wrong stack location - iio: gyro: adis16260: fix division by zero in write_raw - iio: ssp_sensors: cancel delayed work_refresh on remove - iio: temperature: tsys01: fix broken PROM checksum validation - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL - iio: light: cm3323: fix reg_conf not being initialized correctly - iio: buffer: hw-consumer: fix use-after-free in error path - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() - USB: serial: omninet: fix memory corruption with small endpoint - usb: cdns3: gadget: fix request skipping after clearing halt - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles - usb: dwc2: Fix use after free in debug code - Input: elan_i2c - validate firmware size before use - wireguard: send: append trailer after expanding head - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data - macsec: fix replay protection at XPN lower-PN wrap - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() - [arm64] ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params - ipv6: exthdrs: refresh nh after handling HAO option - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). - ipv6: validate extension header length before copying to cmsg - xfrm: input: hold netns during deferred transport reinjection - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname - ip6: vti: Use ip6_tnl.net in vti6_changelink(). - net: skbuff: fix missing zerocopy reference in pskb_carve helpers - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() - nfc: hci: fix out-of-bounds read in HCP header parsing - xfrm: route MIGRATE notifications to caller's netns - xfrm: ah: use skb_to_full_sk in async output callbacks - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - [arm64] ASoC: qcom: q6asm-dai: close stream only when running - [arm64] ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks - xfrm: esp: restore combined single-frag length gate - Input: xpad - add "Nova 2 Lite" from GameSir - Input: xpad - add support for ASUS ROG RAIKIRI II - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 - [amd64] comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() - [amd64] comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() - counter: Fix refcount leak in counter_alloc() error path - tty: serial: pch_uart: add check for dma_alloc_coherent() - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers - usb: chipidea: core: convert ci_role_switch to local variable - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers - usb: storage: Add quirks for PNY Elite Portable SSD - usbip: vudc: Fix use after free bug in vudc_remove due to race condition - usb: usbtmc: check URB actual_length for interrupt-IN notifications - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize - usb: typec: tcpm: improve handling of DISCOVER_MODES failures - USB: serial: option: add MeiG SRM813Q - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL - USB: serial: belkin_sa: validate interrupt status length - USB: serial: cypress_m8: validate interrupt packet headers - USB: serial: keyspan: fix missing indat transfer sanity check - USB: serial: mxuport: fix memory corruption with small endpoint - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind - usb: gadget: net2280: Fix double free in probe error path - usb: gadget: f_hid: fix device reference leak in hidg_alloc() - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports - usb: gadget: f_fs: copy only received bytes on short ep0 read - usb: gadget: f_fs: serialize DMABUF cancel against request completion - [amd64] thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() - [amd64] thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf - scsi: target: iscsi: Validate CHAP_R length before base64 decode - drm/hyperv: validate resolution_count and fix WIN8 fallback - drm/hyperv: validate VMBus packet size in receive callback - [amd64] drm/i915: Fix potential UAF in TTM object purge - drm/amd/pm/si: Disregard vblank time when no displays are connected - serial: altera_jtaguart: handle uart_add_one_port() failures - serial: qcom-geni: fix UART_RX_PAR_EN bit position - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ - serial: sh-sci: fix memory region release in error path - serial: zs: Fix swapped RI/DSR modem line transition counting - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger - drm/amdkfd: Check for pdd drm file first in CRIU restore path - serial: dz: Fix bootconsole message clobbering at chip reset - serial: dz: Fix bootconsole handover lockup - serial: dz: Convert to use a platform device - serial: zs: Fix bootconsole handover lockup - serial: zs: Switch to using channel reset - serial: zs: Convert to use a platform device - USB: serial: cypress_m8: fix memory corruption with small endpoint - USB: serial: digi_acceleport: fix memory corruption with small endpoints - xhci: tegra: Fix ghost USB device on dual-role port unplug - iommu: Skip PASID validation for devices without PASID capability - [amd64] x86/boot: Disable stack protector for early boot code - [amd64] x86/kexec: Disable KCOV instrumentation after load_segments() (CVE-2026-43331) - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer - serdev: Provide a bustype shutdown function - Bluetooth: hci_qca: Migrate to serdev specific shutdown function - Bluetooth: hci_qca: Convert timeout from jiffies to ms - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes - ALSA: scarlett2: Allow flash writes ending at segment boundary - mm/memory: fix spurious warning when unmapping device-private/exclusive pages - [amd64] platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery - net: hsr: defer node table free until after RCU readers - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient - ice: fix VF queue configuration with low MTU values - ring-buffer: Flush and stop persistent ring buffer on panic - mptcp: cleanup fallback dummy mapping generation - mptcp: reset rcv wnd on disconnect - [arm64] tlb: Flush walk cache when unsharing PMD tables - [arm64] octeontx2-pf: avoid double free of pool->stack on AQ init failure - mptcp: introduce the mptcp_init_skb helper - mptcp: handle first subflow closing consistently - mptcp: do not drop partial packets - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() - iio: chemical: scd30: Use guard(mutex) to allow early returns - iio: chemical: scd30: fix division by zero in write_raw - iio: dac: ad5686: fix ref bit initialization for single-channel parts - ALSA: firewire-motu: Protect register DSP event queue positions - [arm64] usb: dwc3: xilinx: fix error handling in zynqmp init error paths - usb: musb: omap2430: Fix use-after-free in omap2430_probe() - usb: typec: ucsi: Check if power role change actually happened before handling - [amd64] thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() - usb: typec: ucsi: Don't update power_supply on power role change if not connected - [amd64] x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' - [amd64] x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock - hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock - mm: perform all memfd seal checks in a single place - mm/memfd: fix spelling and grammatical issues - memfd: deny writeable mappings when implying SEAL_WRITE - usb: core: Fix SuperSpeed root hub wMaxPacketSize - ethtool: cmis_cdb: Fix incorrect read / write length extension - net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow - [arm64] KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.94 - bpf: Free reuseport cBPF prog after RCU grace period. (CVE-2026-52910) - USB: serial: mct_u232: fix memory corruption with small endpoint - [armhf] group is_permission_fault() with is_translation_fault() - [armhf] allow __do_kernel_fault() to report execution of memory faults - [armhf] fix hash_name() fault - [armhf] fix branch predictor hardening - net: phy: micrel: fix LAN8814 QSGMII soft reset - wifi: remove zero-length arrays - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl - ipv6: mcast: Fix use-after-free when processing MLD queries - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS - [arm64] tee: optee: prevent use-after-free when the client exits before the supplicant - [arm64]soc: qcom: ice: Return -ENODEV if the ICE platform device is not found - erofs: add sysfs node to drop internal caches - erofs: tidy up synchronous decompression - erofs: fix use-after-free on sbi->sync_decompress - ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id - ipvs: clear the svc scheduler ptr early on edit - netfilter: synproxy: add mutex to guard hook reference counting - netfilter: conntrack_irc: fix possible out-of-bounds read - netfilter: nft_ct: bail out on template ct in get eval - netfilter: bridge: make ebt_snat ARP rewrite writable - dm cache policy smq: check allocation under invalidate lock - net/sched: act_api: use RCU with deferred freeing for action lifecycle - 6lowpan: fix off-by-one in multicast context address compression - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() - devlink: Release nested relation on devlink free - [arm64] drm/imx: Fix three kernel-doc warnings in dcss-scaler.c - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap - pcnet32: stop holding device spin lock during napi_complete_done - net: Annotate sk->sk_write_space() for UDP SOCKMAP. - hsr: Remove WARN_ONCE() in hsr_addr_is_self(). - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr - net: lan743x: permit VLAN-tagged packets up to configured MTU - net: fec: fix pinctrl default state restore order on resume - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() - Bluetooth: MGMT: validate advertising TLV before type checks - Bluetooth: RFCOMM: validate skb length in MCC handlers - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling - Bluetooth: bnep: reject short frames before parsing - Bluetooth: fix memory leak in error path of hci_alloc_dev() - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync - Bluetooth: ISO: Fix not using bc_sid as advertisement SID - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls - Bluetooth: MGMT: Fix backward compatibility with userspace - [arm64] octeontx2-pf: Fix NDC sync operation errors - [arm64] octeontx2-af: Fix initialization of mcam's entry2target_pffunc field - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options - ptp: vclock: Switch from RCU to SRCU - net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown - net_sched: act_pedit: use RCU in tcf_pedit_dump() - net/sched: fix pedit partial COW leading to page cache corruption (CVE-2026-46331) - [arm64] octeontx2-af: npc: Fix CPT channel mask in npc_install_flow - vxlan: vnifilter: send notification on VNI add - vxlan: vnifilter: fix spurious notification on VNI update - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr - sctp: purge outqueue on stale COOKIE-ECHO handling - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() - time: Fix off-by-one in settimeofday() usec validation - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams - ALSA: seq: dummy: fix UMP event stack overread - ima: kexec: skip IMA segment validation after kexec soft reboot - ima: kexec: move IMA log copy from kexec load to execute - spi: cadence-quadspi: fix unclocked access on unbind (CVE-2026-46203) - tools/rv: Fix cleanup after failed trace setup - tap: free page on error paths in tap_get_user_xdp() (CVE-2026-46320) - [arm64] tlb: Allow XZR argument to TLBI ops - [arm64] tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI - iomap: don't revert iov_iter on partially completed buffered writes - dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() - netlabel: validate unlabeled address and mask attribute lengths - gpio: mvebu: fix NULL pointer dereference in suspend/resume - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls - tcp: restrict SO_ATTACH_FILTER to priv users - net: add pskb_may_pull() to skb_gro_receive_list() - net/mlx4: avoid GCC 10 __bad_copy_from() false positive - net: ibm: emac: Fix use-after-free during device removal - netdev: fix double-free in netdev_nl_bind_rx_doit() - net: phy: clean the sfp upstream if phy probing fails - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure - net/mlx5: Use effective affinity mask for IRQ selection - ipv6: sit: reload inner IPv6 header after GSO offloads - net: openvswitch: fix possible kfree_skb of ERR_PTR - r8152: handle the return value of usb_reset_device() - gpio: zynq: fix runtime PM leak on remove - sctp: fix uninit-value in __sctp_rcv_asconf_lookup() - net: guard timestamp cmsgs to real error queue skbs - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() - rds: mark snapshot pages dirty in rds_info_getsockopt() - netfilter: revalidate bridge ports - netfilter: nf_conntrack: destroy stale expectfn expectations on unregister - netfilter: x_tables: avoid leaking percpu counter pointers - netfilter: nf_log: validate MAC header was set before dumping it - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag - [arm64,armhf] net: mvpp2: sync RX data at the hardware packet offset - [arm64,armhf] net: mvpp2: limit XDP frame size to the RX buffer - [arm64,armhf] net: mvpp2: Add metadata support for xdp mode - [arm64,armhf] net: mvpp2: refill RX buffers before XDP or skb use - [arm64,armhf] net: mvpp2: build skb from XDP-adjusted data on XDP_PASS - ipv6: Fix a potential NPD in cleanup_prefix_route() - netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) - writeback: Avoid contention on wb->list_lock when switching inodes - writeback: Fix use after free in inode_switch_wbs_work_fn() - xfrm: hold device only for the asynchronous decryption - xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663) - [amd64] KVM: VMX: Update SVI during runtime APICv activation - [arm64] clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked - clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs - [arm64] clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time - drm/virtio: Fix driver removal with disabled KMS - [arm64,armhf] drm/vc4: fix krealloc() memory leak - drm/xe: fix refcount leak in xe_range_fence_insert() - netfilter: nft_tunnel: fix use-after-free on object destroy - [arm64] tee: shm: fix shm leak in register_shm_helper() - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig - [arm64] soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() - [amd64] accel/ivpu: Add bounds checks for firmware log indices - [amd64] accel/ivpu: Add buffer overflow check in MS get_info_ioctl - [amd64] accel/ivpu: Fix signed integer truncation in IPC receive - tracing/probes: Point the error offset correctly for eprobe argument error - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying - [amd64] KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA - [amd64] drm/i915/gem: Fix phys BO pread/pwrite with offset - pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL - xfrm: espintcp: do not reuse an in-progress partial send - USB: serial: io_ti: fix heap overflow in get_manuf_info() - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() - USB: serial: option: add usb-id for Dell Wireless DW5826e-m - USB: serial: kl5kusb105: fix bulk-out buffer overflow - ALSA: timer: Forcibly close timer instances at closing - ALSA: timer: Fix UAF at snd_timer_user_params() - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() - mm/huge_memory: update file PMD counter before folio_put() - mm/damon/ops-common: call folio_test_lru() after folio_get() - RDMA/srp: bound SRP_RSP sense copy by the received length - zram: fix use-after-free in zram_bvec_write_partial() - udp: clear skb->dev before running a sockmap verdict - mptcp: fix retransmission loop when csum is enabled - mptcp: close TOCTOU race while computing rcv_wnd - mptcp: allow subflow rcv wnd to shrink - mptcp: sockopt: check timestamping ret value - mptcp: add-addr: always drop other suboptions - wifi: nl80211: reject oversized EMA RNR lists - vsock/vmci: fix sk_ack_backlog leak on failed handshake - timers/migration: Fix livelock in tmigr_handle_remote_up() - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write - bnxt_en: Fix NULL pointer dereference - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush - pidfd: refuse access to tasks that have started exiting harder - fs/qnx6: fix pointer arithmetic in directory iteration - fuse: reject fuse_notify() pagecache ops on directories - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter - i2c: tegra: Fix NOIRQ suspend/resume - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard - ipc/shm: serialize orphan cleanup with shm_nattch updates - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context - misc: fastrpc: fix use-after-free race in fastrpc_map_create - misc: fastrpc: fix DMA address corruption due to find_vma misuse - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback - net/mlx5: Reorder completion before putting command entry in cmd_work_handler - net: bonding: fix NULL pointer dereference in bond_do_ioctl() - net: mv643xx: fix OF node refcount - net: rds: clear i_sends on setup unwind - nvmem: core: fix use-after-free bugs in error paths - nvmem: layouts: onie-tlv: fix hang on unknown types - [arm64] octeontx2-af: fix memory leak in rvu_setup_hw_resources() - io_uring/kbuf: don't truncate end buffer for bundles - io_uring/wait: fix min_timeout behavior - mm/hugetlb: restore reservation on error in hugetlb folio copy paths - mmc: core: Fix host controller programming for fixed driver type - mmc: dw_mmc-rockchip: Add missing private data for very old controllers - mmc: litex_mmc: Set mandatory idle clocks before CMD0 - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC - mmc: sdhci: add signal voltage switch in sdhci_resume_host - pmdomain: imx: fix OF node refcount - rtase: Avoid sleeping in get_stats64() - rtase: Reset TX subqueue when clearing TX ring - sctp: diag: reject stale associations in dump_one path - sctp: stream: fully roll back denied add-stream state - [amd64] thunderbolt: Reject zero-length property entries in validator - [amd64] thunderbolt: Bound root directory content to block size - [amd64] thunderbolt: Clamp XDomain response data copy to allocation size - [amd64] thunderbolt: Validate XDomain request packet size before type cast - [amd64] thunderbolt: Limit XDomain response copy to actual frame size - [arm64] slimbus: qcom-ngd-ctrl: fix OF node refcount - [arm64] slimbus: qcom-ngd-ctrl: Fix up platform_driver registration - [arm64] slimbus: qcom-ngd-ctrl: Fix probe error path ordering - [arm64] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd - [arm64] slimbus: qcom-ngd-ctrl: Initialize controller resources in controller - [arm64] slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership - [arm64] slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD - [arm64] slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock - drm/amdkfd: fix NULL dereference in get_queue_ids() - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 - drm/xe: Clear pending_disable before signaling suspend fence - [arm64,armhf] drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups - drm/amdgpu: restart the CS if some parts of the VM are still invalidated - drm/amd/pm: fix smu13 power limit default/cap calculation - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range - drm/amd/display: Bound VBIOS record-chain walk loops - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs - drm/amd/display: Use krealloc_array() in dal_vector_reserve() - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling - driver core: reject devices with unregistered buses - mailbox: Fix NULL message support in mbox_send_message() - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf - sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() - netfilter: nft_fib: fix stale stack leak via the OIFNAME register - mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper - RDMA/umem: Move umem dmabuf revoke logic into helper function - RDMA/umem: Add helpers for umem dmabuf revoke lock - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible - RDMA/umem: fix kernel-doc warnings - RDMA: Move DMA block iterator logic into dedicated files - RDMA/umem: Fix truncation for block sizes >= 4G - mm/hugetlb: avoid false positive lockdep assertion - mptcp: fix missing wakeups in edge scenarios - ipmi:ssif: Remove unnecessary indention - ipmi:ssif: NULL thread on error - ipvs: skip ipv6 extension headers for csum checks (CVE-2026-45850) - vsock/virtio: fix potential unbounded skb queue - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc - block: fix handling of dead zone write plugs - [arm64] cputype: Add NVIDIA Olympus definitions - [arm64] cputype: Add C1-Ultra definitions - [arm64] cputype: Add C1-Premium definitions - [arm64] errata: Mitigate TLBI errata on various Arm CPUs - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU - net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() - tcp: use EXPORT_IPV6_MOD[_GPL]() - tcp: secure_seq: add back ports to TS offset (CVE-2026-23247) - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation - vsock/virtio: fix skb overhead overflow on 32-bit builds - netfilter: require Ethernet MAC header before using eth_hdr() . [ Salvatore Bonaccorso ] * [rt] Refresh "ARM: enable irq in translation/section permission fault" * ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909) linux-signed-arm64 (6.12.94+1~bpo12+1) bookworm-backports; urgency=medium . * Sign kernel from linux 6.12.94-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-arm64 (6.12.90+2) trixie-security; urgency=high . * Sign kernel from linux 6.12.90-2 . * smb: client: reject userspace cifs.spnego descriptions * net/rds: reset op_nents when zerocopy page pin fails (CVE-2026-43494) linux-signed-arm64 (6.12.90+2~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.90-2~bpo12+1 . * Rebuild for bookworm-backports linux-signed-arm64 (6.12.90+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.90-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.89 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.90 - HID: playstation: Clamp num_touch_reports - media: uvcvideo: Enable VB2_DMABUF for metadata stream - [arm64] dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd & gpio pinmux - [arm64] regulator: mt6357: fix OF node reference imbalance - [arm64,armhf] regulator: rk808: fix OF node reference imbalance - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap - [amd64] media: intel/ipu6: fix error pointer dereference - media: saa7164: add ioremap return checks and cleanups - spi: aspeed-smc: fix controller deregistration - [amd64] platform/x86: hp-wmi: Ignore backlight and FnLock events - vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy - [arm64] drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() - [amd64] drm/i915/psr: Init variable to avoid early exit from et alignment loop - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count. - drm/amdgpu: gate VM CPU HDP flush on reset lock - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x - drm/amdkfd: Add upper bound check for num_of_nodes - drm/amdgpu: Add bounds checking to ib_{get,set}_value - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB - drm/amdgpu/vce: Prevent partial address patches - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg - drm/amd/display: Change dither policy for 10 bpc output back to dithering - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() - drm/amdkfd: validate SVM ioctl nattr against buffer size - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() - drm/radeon: add missing revision check for CI - drm/amdgpu: zero-initialize GART table on allocation - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds - drm/amdkfd: Make all TLB-flushes heavy-weight - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission - drm/amdgpu/pm: add missing revision check for CI - drm/amdgpu/pm: align Hawaii mclk workaround with radeon - [arm64] dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL - batman-adv: fix integer overflow on buff_pos - batman-adv: reject new tp_meter sessions during teardown - batman-adv: stop caching unowned originator pointers in BAT IV - batman-adv: bla: prevent use-after-free when deleting claims - batman-adv: bla: only purge non-released claims - batman-adv: bla: put backbone reference on failed claim hash insert - usb: typec: tcpm: reset internal port states on soft reset AMS - usb: dwc3: Move GUID programming after PHY initialization - ALSA: hda: cs35l56: Propagate ASP TX source control errors - ALSA: misc: Use guard() for spin locks - ALSA: core: Serialize deferred fasync state checks - ALSA: seq: Notify client and port info changes - ALSA: seq: Fix UMP group 16 filtering - Bluetooth: hci_conn: fix potential UAF in create_big_sync - [arm64,armhf] spi: tegra20-sflash: fix controller deregistration - [arm64,armhf] spi: tegra114: fix controller deregistration - mm/hugetlb_cma: round up per_node before logging it - block: cleanup blkdev_report_zones() - block: reorganize struct blk_zone_wplug - block: fix zone write plug removal - tracefs: Fix default permissions not being applied on initial mount - fbcon: Avoid OOB font access if console rotation fails - mm/damon/core: disallow time-quota setting zero esz - mm/damon/core: implement damon_kdamond_pid() - mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values - mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values - bonding: fix use-after-free due to enslave fail after slave array update (CVE-2026-23171) - io_uring/kbuf: support min length left for incremental buffers - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() - btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() - btrfs: fix double free in create_space_info_sub_group() error path - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak - tracing/probes: Limit size of event probe to 3K - batman-adv: stop tp_meter sessions during mesh teardown - batman-adv: tp_meter: fix tp_num leak on kmalloc failure - vsock: fix buffer size clamping order - vsock/virtio: fix length and offset in tap skb for split packets - vsock/virtio: fix empty payload in tap skb for non-linear buffers - vsock/virtio: fix accept queue count leak on transport mismatch - drm/amdgpu/vcn3: Avoid overflow on msg bound check - drm/amdgpu/vcn4: Avoid overflow on msg bound check . [ Salvatore Bonaccorso ] * Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Closes: #1136790) * net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300) * net: skbuff: propagate shared-frag marker through frag-transfer helpers linux-signed-arm64 (6.12.90+1~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.90-1~bpo12+1 . * Rebuild for bookworm-backports linux-signed-arm64 (6.12.88+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.88-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.87 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.88 - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() - ipmi: Add limits to event and receive message requests - ipmi: Check event message buffer response for bad data - ipmi:si: Return state to normal if message allocation fails - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free - ACPI: scan: Use acpi_dev_put() in object add error paths - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug - ACPI: video: force native backlight on HP OMEN 16 (8A44) - ASoC: SOF: Don't allow pointer operations on unconfigured streams - spi: rockchip: fix controller deregistration - ksmbd: rewrite stop_sessions() with restartable iteration - mm: convert mm_lock_seq to a proper seqcount - [amd64] x86: shadow stacks: proper error handling for mmap lock (CVE-2026-43109) - [amd64] x86/shstk: Prevent deadlock during shstk sigreturn - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected GFN - [amd64] iommu/amd: Use atomic64_inc_return() in iommu.c - [amd64] iommu/amd: serialize sequence allocation under concurrent TLB invalidations (CVE-2026-43220) (Closes: #1135313) - flow_dissector: do not dissect PPPoE PFC frames - net: txgbe: fix RTNL assertion warning when remove module - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) - [amd64] KVM: SVM: check validity of VMCB controls when returning from SMM - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (CVE-2026-31499) - exit: prevent preemption of oopsing TASK_DEAD task - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr - wifi: mt76: mt7925: fix incorrect length field in txpower command - wifi: mt76: mt7921: fix a potential clc buffer length underflow - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work - wifi: b43legacy: enforce bounds check on firmware key index in RX path - wifi: mac80211: drop stray 'static' from fast-RX rx_result - wifi: rsi: fix kthread lifetime race between self-exit and external-stop - wifi: mac80211: use safe list iteration in radar detect work - wifi: ath5k: do not access array OOB (Closes: #1119093) - wifi: mac80211: remove station if connection prep fails - wifi: b43: enforce bounds check on firmware key index in b43_rx() - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task - usb: usblp: fix heap leak in IEEE 1284 device ID via short response - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl - ALSA: usb-audio: midi2: Restart output URBs on resume - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() - ALSA: usb-audio: Fix UAC3 cluster descriptor size check - USB: omap_udc: DMA: Don't enable burst 4 mode - USB: serial: option: add Telit Cinterion LE910Cx compositions - usb: ulpi: fix memory leak on ulpi_register() error paths - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger - ALSA: firewire-tascam: Do not drop unread control events - xfrm: provide message size for XFRM_MSG_MAPPING - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() - xfrm: ah: account for ESN high bits in async callbacks - selinux: don't reserve xattr slot when we won't fill it - selinux: shrink critical section in sel_write_load() - selinux: prune /sys/fs/selinux/disable - Bluetooth: virtio_bt: clamp rx length before skb_put - Bluetooth: virtio_bt: validate rx pkt_type header length - Bluetooth: btmtk: validate WMT event SKB length before struct access - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() - [armhf] spi: sun4i: fix controller deregistration - [armhf] spi: ti-qspi: fix controller deregistration - spi: sun6i: fix controller deregistration - fanotify: fix false positive on permission events - [arm64] KVM: arm64: Fix kvm_vcpu_initialized() macro parameter - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo - sound: ua101: fix division by zero at probe - net: libwx: fix VF illegal register access - ip6_gre: Use cached t->net in ip6erspan_changelink(). - net/rds: handle zerocopy send cleanup before the message is queued - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler - hwmon: (ltc2992) Clamp threshold writes to hardware range - hwmon: (ltc2992) Fix u32 overflow in power read path - clk: rk808: fix OF node reference imbalance - hwmon: (corsair-psu) Close HID device on probe errors - af_unix: Reject SIOCATMARK on non-stream sockets - block: add pgmap check to biovec_phys_mergeable - cifs: abort open_cached_dir if we don't request leases - cifs: change_conf needs to be called for session setup - extcon: ptn5150: handle pending IRQ events during system resume - gpio: of: clear OF_POPULATED on hog nodes in remove path - hv_sock: fix ARM64 support - ibmveth: Disable GSO for packets with small MSS - ice: fix double free in ice_sf_eth_activate() error path - spi: microchip-core-qspi: fix controller deregistration - udf: reject descriptors with oversized CRC length - thermal: core: Free thermal zone ID later during removal - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp - spi: topcliff-pch: fix controller deregistration - spi: topcliff-pch: fix use-after-free on unbind - clk: imx: imx8-acm: fix flags for acm clocks - clk: microchip: mpfs-ccc: fix out of bounds access during output registration - cpuidle: powerpc: avoid double clear when breaking snooze - [amd64] ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table - [arm64] ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop - [arm64] ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens - [arm64] ASoC: qcom: q6apm: remove child devices when apm is removed - btrfs: fix double free in create_space_info() error path - dm-thin: fix metadata refcount underflow - dm: don't report warning when doing deferred remove - dm: fix a buffer overflow in ioctl processing - eventfs: Hold eventfs_mutex and SRCU when remount walks events - dm-verity-fec: correctly reject too-small FEC devices - dm-verity-fec: correctly reject too-small hash devices - isofs: validate Rock Ridge CE continuation extent against volume size - isofs: validate block number from NFS file handle in isofs_export_iget - [arm64] iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() - lib/scatterlist: fix length calculations in extract_kvec_to_sg - lib/scatterlist: fix temp buffer in extract_user_to_sg() - libceph: Fix slab-out-of-bounds access in auth message processing - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies - nvme-apple: drop invalid put of admin queue reference count - nvmet-tcp: fix race between ICReq handling and queue teardown - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free - openvswitch: vport: fix self-deadlock on release of tunnel ports - pmdomain: core: Fix detach procedure for virtual devices in genpd - [arm64] RDMA/hns: Fix unlocked call to hns_roce_qp_remove() - [s390x] debug: Reject zero-length input in debug_input_flush_fn() - smb/client: fix out-of-bounds read in smb2_compound_op() - smb/client: fix out-of-bounds read in symlink_data() - smb: client: use kzalloc to zero-initialize security descriptor buffer - smb: client: validate dacloffset before building DACL pointers - [amd64] KVM: x86: check for nEPT/nNPT in slow flush hypercalls - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock - PCI: Update saved_config_space upon resource assignment (Closes: #1131025) - PCI/AER: Clear only error bits in PCIe Device Status - PCI/AER: Stop ruling out unbound devices as error source - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage - power: supply: max17042: avoid overflow when determining health - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() - RDMA/mana: Validate rx_hash_key_len - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads - RDMA/rxe: Reject unknown opcodes before ICRC processing - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path - mptcp: fastclose msk when linger time is 0 - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure - mptcp: sockopt: set timestamp flags on subflow socket, not msk - mptcp: fix scheduling with atomic in timestamp sockopt - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() - f2fs: fix fiemap boundary handling when read extent cache is incomplete - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() - f2fs: fix node_cnt race between extent node destroy and writeback - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() - [arm64] KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value - [arm64] KVM: arm64: Fix initialisation order in __pkvm_init_finalise() - bpf: Fix use-after-free in arena_vm_close on fork - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info - fs: prepare for adding LSM blob to backing_file - dma-mapping: drop unneeded includes from dma-mapping.h - dma-mapping: add __dma_from_device_group_begin()/end() - hwmon: (powerz) Avoid cacheline sharing for DMA buffer - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs - udf: fix partition descriptor append bookkeeping - mtd: spinand: winbond: Declare the QE bit on W25NxxJW - hfsplus: fix uninit-value by validating catalog record size - hfsplus: fix held lock freed on hfsplus_fill_super() - erofs: move {in,out}pages into struct z_erofs_decompress_req - erofs: tidy up z_erofs_lz4_handle_overlap() - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() - gtp: disable BH before calling udp_tunnel_xmit_skb() - printk: add print_hex_dump_devel() - crypto: caam - guard HMAC key hex dumps in hash_digest_key - ALSA: aloop: Fix peer runtime UAF during format-change stop - net: stmmac: avoid shadowing global buf_sz - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() - net: stmmac: Prevent NULL deref when RX memory exhausted - wifi: mt76: mt7925: fix incorrect TLV length in CLC command - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() - [arm64] KVM: arm64: Wake-up from WFI when iqrchip is in userspace - [amd64] x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache - ksmbd: validate inherited ACE SID length . [ Salvatore Bonaccorso ] * ptrace: slightly saner 'get_dumpable()' logic linux-signed-arm64 (6.12.88+1~bpo12+1) bookworm-backports; urgency=high . * Sign kernel from linux 6.12.88-1~bpo12+1 . * Rebuild for bookworm-backports linuxcnc (1:2.9.4-2+deb13u1) trixie; urgency=medium . * Team upload. . * Added 0010-sanitize-hal-paths.patch to sanitize name for module in rtapi_app (Closes: #1140943). * Added d/gbp.conf to enforce the use of pristine-tar and using correct git branch for stable updates. lxd (5.0.2+git20231211.1364ae4-9+deb13u7) trixie-security; urgency=high . * Cherry-pick fixes for the following security issues: - CVE-2026-9639 / GHSA-j93m-3j9p-m5m8 - CVE-2026-9640 / GHSA-ppq7-4492-5552 - CVE-2026-48749 / GHSA-vghh-5rfx-xhq8 - CVE-2026-48750 / GHSA-9j25-mm2h-2f76 - CVE-2026-48751 / GHSA-47w9-6r3f-938g - CVE-2026-48752 / GHSA-jpf8-86f3-wp38 - CVE-2026-48755 / GHSA-fmc8-p6q7-75cc - CVE-2026-48769 / GHSA-pjff-c2wc-f6jm - CVE-2026-55621 / GHSA-7mr3-28h5-m5vx - CVE-2026-55622 / GHSA-qx75-2p3r-pwm5 lxml-html-clean (0.4.4-1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. - CVE-2026-28348: CSS @import Filter Bypass via Unicode Escapes - CVE-2026-28350: tag injection through default Cleaner configuration . lxml-html-clean (0.4.4-1) unstable; urgency=medium . * New upstream version. * Bump standards version. lxml-html-clean (0.4.3-1) unstable; urgency=medium . * New upstream version. Closes: #1114193. * Bump standards version. mediawiki (1:1.43.9+dfsg-1~deb13u1) trixie-security; urgency=medium . * New upstream version 1.43.9, fixing CVE-2026-58024, CVE-2026-58025, CVE-2026-58026, CVE-2026-58027, CVE-2026-58028, CVE-2026-58029, CVE-2026-58030, CVE-2026-58032, CVE-2026-58033, CVE-2026-58037. This version is not affected by CVE-2026-58036. * Drop patches merged upstream. mediawiki (1:1.43.8+dfsg-2) unstable; urgency=medium . * Cherry-pick upstream patch fixing CVE-2026-34095 mitigation * Refresh patches mediawiki (1:1.43.8+dfsg-1) unstable; urgency=medium . * New upstream version 1.43.8, fixing CVE-2026-5266, CVE-2026-34086, CVE-2026-34087, CVE-2026-34088, CVE-2026-34091, CVE-2026-34092, CVE-2026-34093, CVE-2026-34094, CVE-2026-34095. This version is not affected by CVE-2026-34089, CVE-2026-34090. mesa (25.0.7-2+deb13u1) trixie; urgency=high . * Non-maintainer upload by the LTS Team. * Backport patch for CVE-2026-40393: - backport support function STACK_ARRAY, cherry-pick file from upstream. - backport commits fixing the issue miniupnpd (2.3.9-2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-5720: integer underflow in SOAPAction header parsing (Closes: #1134334) mistral (20.0.0-2+deb13u1) trixie-security; urgency=medium . * CVE-2026-41283: Mistral policy enforcement bypass allows unauthorized public resource creation and arbitrary code execution. Applied upstream patches: - Restrict publicize policies to admin only - Remove unnecessary expect_errors=True from policy tests - Add code_sources publicize policy and enforcement - Restrict code_sources and dynamic_actions policies to - Add dynamic_actions publicize policy and enforcement - Add workbooks publicize policy and enforcement - Add cron_triggers publicize policy and enforcement - Add environments publicize policy and enforcement (Closes: #1138843) * OSSN-0098: Mistral workflow execution context exposes Keystone auth token. Applied upstream patch: "Strip sensitive info from workflow execution context" (Closes: #1138849). modsecurity (3.0.14-1+deb13u1) trixie; urgency=medium . [ Ervin Hegedus ] * Add fixes for CVE-2026-30923 and CVE-2026-42268 mutt (2.2.13-1+deb13u1) trixie; urgency=medium . * CVE-2026-43859 CVE-2026-43860 CVE-2026-43861 CVE-2026-43862 CVE-2026-43863 CVE-2026-43864 (Closes: #1135699) mxml (3.3.1-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-5037: Out-of-bounds read in index_sort() (Closes: #1132328) mxml (3.3.1-1+deb13u1~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Rebuild for bookworm. . mxml (3.3.1-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-5037: Out-of-bounds read in index_sort() (Closes: #1132328) nagios4 (4.4.6-4.1+deb13u1) trixie-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. nbconvert (7.16.6-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-39377: Arbitrary File Write via Path Traversal in Cell Attachment Filenames (Closes: #1134889) * CVE-2026-39378: Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding (Closes: #1134890) netatalk (4.2.3~ds-1+deb13u2) trixie-security; urgency=high . [ Daniel Markstedt ] * add patch that fixes: CVE-2026-44047 CVE-2026-44048 CVE-2026-44049 CVE-2026-44050 CVE-2026-44051 CVE-2026-44052 CVE-2026-44054 CVE-2026-44055 CVE-2026-44057 CVE-2026-44060 CVE-2026-44062 CVE-2026-44064 CVE-2026-44066 CVE-2026-44068 CVE-2026-44076 CVE-2026-45354 CVE-2026-45355 CVE-2026-45356 CVE-2026-45698 CVE-2026-45699 neutron (2:26.0.3-0+deb13u2) trixie-security; urgency=medium . * New upstream point release. * Removed patches applied upstream: - Add_state_reporting_back_to_metadata_agents.patch - Fix_LoopingCallBase_argument_issue.patch * Add start-time=%t in neutron-api-uwsgi.ini. * Add haproxy as runtime depends of neutron-ovn-agent. Thanks to Sakirnth Nagarasa for the report (Closes: #1135272). * CVE-2026-50266 / OSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks. Added upstream patch: Fix port RBAC policies to require network ownership (Closes: #1138844). neutron (2:26.0.0-9+deb13u1) trixie; urgency=medium . * OSSA-2026-016: Neutron tagging policy bypass allows project readers to mutate tags. Added upstream patch: "Fix plural policy names in tagging controller and floatingip policy" (Closes: #1138172). nghttp2 (1.64.0-1.1+deb13u1) trixie-security; urgency=medium . * Non-maintainer upload by the Security Team. * CVE-2026-27135 (Closes: #1131369) Fix missing iframe->state validations to avoid assertion failure. * Add test for CVE-2026-27135 (cherry-picked from upstream c619c7b) nginx (1.26.3-3+deb13u7) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055) (Closes: #1140359) * Charset: fixed another rare buffer overread in recode_from_utf8() (CVE-2026-48142) (Closes: #1140361) nginx (1.26.3-3+deb13u6) trixie-security; urgency=medium . * Apply both patches to fix CVE-2026-42946. In the previous version, only one part of the patch was applied, so the fix was incomplete. This really fixes CVE-2026-42946, thanks to charles@debian.org for pointing it out. * d/p/CVE-2026-42946.patch rename to d/p/CVE-2026-42946.2.patch * d/p/CVE-2026-42946.1.patch add * backport fix for buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256) from upstream 1.30.2 nginx. * d/p/CVE-2026-9256.patch add * backport max_headers directive from upstream nginx. It limits the number of request headers accepted from clients. Fixes remote denial-of-service exploit. And move max_headers from core module to the ngx_http_header_count_module to avoid potential ABI breakage and keep all the 3rd party modules compatible with the new version of nginx without recompilation. A big thanks to Miao Wang for preparing the modification. Fixes TEMP-1138794-BADE22. * d/p/FIX-HTTP2bomb.patch add nginx (1.26.3-3+deb13u5) trixie-security; urgency=medium . * backport changes from upstream nginx, HTTP/3 address spoofing (CVE-2026-40460), buffer overflow in the ngx_http_rewrite_module (CVE-2026-42945), buffer overread in the ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), resolver use-after-free in OCSP (CVE-2026-40701), buffer overread in the ngx_http_charset_module (CVE-2026-42934) * d/p/CVE-2026-40460.patch add * d/p/CVE-2026-42945.patch add * d/p/CVE-2026-42946.patch add * d/p/CVE-2026-40701.patch add * d/p/CVE-2026-42934.patch add node-shell-quote (1.7.4+~1.7.1-1+deb13u1) trixie-security; urgency=medium . * Team upload * Validate object-token shapes (Closes: #1137372, CVE-2026-9277) node-shell-quote (1.7.4+~1.7.1-1+deb12u1) bookworm-security; urgency=medium . * Team upload * Validate object-token shapes (Closes: #1137372, CVE-2026-9277) nss (2:3.110-1+deb13u3) trixie; urgency=medium . * Non-maintainer upload. * improve handling of escape sequences in pk11uri_ParseAttributes (CVE-2026-12318) nss (2:3.110-1+deb13u2) trixie-security; urgency=medium . * CVE-2026-6766 * CVE-2026-6767 * CVE-2026-6772 ojalgo (55.0.0+ds-1+deb13u1) trixie; urgency=medium . * Team upload. * Use a simplified salsa-ci.yml for trixie. * Backport upstream and Debian fixes from 56.2.1-3. Closes: #1140433. okular (4:25.04.2-1+deb13u1) trixie-security; urgency=medium . * Multiple security issues in parsing Fax files opencc (1.1.9+ds1-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-15536: Out-of-bounds read (Closes: #1126286) openjpeg2 (2.5.3-2.1~deb13u2) trixie-security; urgency=medium . * CVE-2026-6192 (Closes: #1133832) openslide (3.4.1+dfsg-7+deb13u1) trixie; urgency=medium . * CVE-2026-48977.patch: new: fix CVE-2026-48977. The change lacks attempt to apply the test case, because the binary representation of a newly introduced test file is not possible in the patch. (Closes: #1140003) openssl (3.5.6-1~deb13u2) trixie-security; urgency=medium . * CVE-2026-7383 ("Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion") * CVE-2026-9076 ("Out-of-Bounds Read in CMS Password-Based Decryption") * CVE-2026-34180 ("Heap Buffer Over-read in ASN.1 Content Parsing") * CVE-2026-34181 ("PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys") * CVE-2026-34182 ("CMS AuthEnvelopedData Processing May Accept Forged Messages") * CVE-2026-34183 ("Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler") * CVE-2026-42764 ("NULL pointer dereference in QUIC server initial packet handling") * CVE-2026-42766 ("Possible NULL Dereference in Password-Based CMS Decryption") * CVE-2026-42767 ("NULL Pointer Dereference in CRMF EncryptedValue Decryption") * CVE-2026-42768 ("Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()") * CVE-2026-42769 ("Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate") * CVE-2026-42770 ("FFC-DH Peer Validation Uses Attacker-Supplied q") * CVE-2026-45445 ("AES-OCB IV Ignored on EVP_Cipher() Path") * CVE-2026-45446 ("Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes") * CVE-2026-45447 ("Heap Use-After-Free in OpenSSL PKCS7_verify()") openvpn (2.6.14-1+deb13u3) trixie-security; urgency=high . * Cherry-pick upstream security patches from the 2.6.21 release - CVE-2026-12996: Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed sequence of control channel + authentication packets - CVE-2026-13117: Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable sequence of dynamic tls-crypt control-channel packets - CVE-2026-13122: Fix server crash on reception of suitably malformed auth-token, if --auth-gen-token external-auth is active - CVE-2026-12932: Fix memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes - CVE-2026-11771: Fix possible 1-byte buffer overrun on NTLMv2 proxy responses. - CVE-2026-13698: Fix another memory leak on reception of suitable tls-crypt-v2 packets that could lead to an out of memory situation and server crash openvpn (2.6.14-1+deb13u2) trixie-security; urgency=medium . * Cherry-pick upstream security patches - CVE-2026-40215: fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances - CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key pdns (4.9.16-0+deb13u1) trixie-security; urgency=medium . * New upstream version 4.9.16, fixing security issue CVE-2026-42005. pdns (4.9.15-0+deb13u1) trixie-security; urgency=medium . * New upstream version 4.9.15, fixing security issues CVE-2026-42000, CVE-2026-42001, CVE-2026-42002, CVE-2026-42396. pdns-recursor (5.2.11-0+deb13u1) trixie-security; urgency=medium . * New upstream version 5.2.11, fixing security issues CVE-2026-33612, CVE-2026-40012, CVE-2026-42005, CVE-2026-42390, CVE-2026-42390, CVE-2026-42388, CVE-2026-42387, CVE-2026-52690. php-guzzlehttp-psr7 (2.7.1-1+deb13u1) trixie; urgency=medium . * Backport fixes from upstream - Encode plus sign in withQueryValue() and withQueryValues() (#636) - Harden ServerRequest globals handling (#660) - Normalize global header values (#718) - Reject control characters in URI hosts (#715) [CVE-2026-49214] - Reject malformed Host authorities (#717) [CVE-2026-48998] (Closes: #1138265) * Track debian/trixie branch php-league-csv (9.23.0+dfsg-1+deb13u1) trixie; urgency=medium . * Add upstream patch to fix failing test with PHP 8.4.14+ (Closes: #1137038) php-twig (3.27.0-0+deb13u1) trixie-security; urgency=medium . [ Fabien Potencier ] * Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing [CVE-2026-24425] * Fix sandbox `__toString` bypasses [CVE-2026-47732] * Pre-escape HTML input on the `spaceless` filter [CVE-2026-46628] * Document template_from_string caveats when used in a sandboxed env [CVE-2026-46634] * Document that the sandbox doesn't protect against resource exhaustion [CVE-2026-46627] * Fix sandbox bypass in deprecated internal wrappers [CVE-2026-48805] * Fix sandbox bypass in the "column" filter under SourcePolicyInterface [CVE-2026-48808] * Fix sandbox __toString bypass via Traversable in join/replace filters * Fix sandbox `__toString` bypass via the `in` and `not in` operators [CVE-2026-48807] * Fix sandbox __toString policy bypass via dynamic mapping keys [CVE-2026-48806] * Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders [CVE-2026-46636] * Update CHANGELOG * Prepare the 3.27.0 release . [ Alexandre Daubois ] * Fix sandbox bypass in object destructuring assignment [CVE-2026-46639] * Fix unbounded memoisation of `IntlDateFormatter` / `NumberFormatter` [CVE-2026-46629] * Fix sandbox bypass: PHP code injection via {% use %} template name [CVE-2026-46633] * Fix sandbox bypass in the `{% sandbox %}` tag when including a preloaded template [CVE-2026-46638] * Fix sandbox bypass: PHP code injection via _self / import macro reference [CVE-2026-46640] * Fix sandbox bypass in the "column" filter [CVE-2026-46635] . [ Nicolas Grekas ] * Fix XSS by adjusting `is_safe` annotation on HTML-emitting filters [CVE-2026-46637] * Pre-escape HTML input on `inline_css` and `inky_to_html` filters * [Profiler] Escape template and profile names in HtmlDumper [CVE-2026-47730] . [ David Prévot ] * Track debian/trixie branch * Refresh patches * Make phpab tolerant * Update build for related path php-twig (3.26.0-1) unstable; urgency=medium . [ Fabien Potencier ] * Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing [CVE-2026-24425] * Fix sandbox `__toString` bypasses [CVE-2026-47732] * Pre-escape HTML input on the `spaceless` filter [CVE-2026-46628] * Document template_from_string caveats when used in a sandboxed env [CVE-2026-46634] * Document that the sandbox doesn't protect against resource exhaustion [CVE-2026-46627] * Update CHANGELOG * Prepare the 3.26.0 release . [ Alexandre Daubois ] * Fix sandbox bypass in object destructuring assignment [CVE-2026-46639] * Fix unbounded memoisation of `IntlDateFormatter` / `NumberFormatter` [CVE-2026-46629] * Fix sandbox bypass: PHP code injection via {% use %} template name [CVE-2026-46633] * Fix sandbox bypass in the `{% sandbox %}` tag when including a preloaded template [CVE-2026-46638] * Fix sandbox bypass: PHP code injection via _self / import macro reference [CVE-2026-46640] * Fix sandbox bypass in the "column" filter [CVE-2026-46635] . [ Nicolas Grekas ] * Fix XSS by adjusting `is_safe` annotation on HTML-emitting filters [CVE-2026-46637] * Pre-escape HTML input on `inline_css` and `inky_to_html` filters * [Profiler] Escape template and profile names in HtmlDumper [CVE-2026-47730] . [ David Prévot ] * Use full version with RequiresPhp * Update standards version to 4.7.4 php-twig (3.26.0-0+deb13u1) trixie-security; urgency=medium . [ Fabien Potencier ] * Fix sandbox bypass: propagate sandbox state to checkArrow for source-policy sandboxing [CVE-2026-24425] * Fix sandbox `__toString` bypasses [CVE-2026-47732] * Pre-escape HTML input on the `spaceless` filter [CVE-2026-46628] * Document template_from_string caveats when used in a sandboxed env [CVE-2026-46634] * Document that the sandbox doesn't protect against resource exhaustion [CVE-2026-46627] * Update CHANGELOG * Prepare the 3.26.0 release . [ Alexandre Daubois ] * Fix sandbox bypass in object destructuring assignment [CVE-2026-46639] * Fix unbounded memoisation of `IntlDateFormatter` / `NumberFormatter` [CVE-2026-46629] * Fix sandbox bypass: PHP code injection via {% use %} template name [CVE-2026-46633] * Fix sandbox bypass in the `{% sandbox %}` tag when including a preloaded template [CVE-2026-46638] * Fix sandbox bypass: PHP code injection via _self / import macro reference [CVE-2026-46640] * Fix sandbox bypass in the "column" filter [CVE-2026-46635] . [ Nicolas Grekas ] * Fix XSS by adjusting `is_safe` annotation on HTML-emitting filters [CVE-2026-46637] * Pre-escape HTML input on `inline_css` and `inky_to_html` filters * [Profiler] Escape template and profile names in HtmlDumper [CVE-2026-47730] . [ David Prévot ] * Track debian/trixie branch * Refresh patches * Make phpab tolerant * Update build for related path php-twig (3.24.0-1) unstable; urgency=medium . [ Fabien Potencier ] * Add support for renaming variables in object destructuring * Deprecate passing a non-AbstractExpression node to Parser::setParent() * Deprecate passing non AbstractExpression nodes to MatchesBinary * Add getOperatorTokens() to ExpressionParserInterface to separate operator token registration from parser identity * Prepare the 3.24.0 release . [ HypeMC ] * Support short-circuiting in null-safe operator chains . [ Matthias Pigulla ] * Add `html_attr_relaxed` escaping strategy * Add an `html_attr` function to make outputting HTML attributes easier . [ David Prévot ] * Refresh patches * Reorder Files paragraphs in debian/copyright by directory depth * Upgrade upstream signing key to new packet format php-twig (3.23.0-2) unstable; urgency=medium . * Compatibility with recent PHPUnit (13) php-twig (3.23.0-1) unstable; urgency=medium . [ Fabien Potencier ] * Fix spread operator behavior * Add === and !== operators * Add the = assignment operator * Add support for object and mapping destructuring * Update CHANGELOG . [ Ondřej Machulda ] * Fix opcache preload warning for unlinked anonymous class . [ Felds Liscia ] * Add null-safe operator . [ David Prévot ] * Convert d/watch to version 5 * Update build for related path * Update Standards-Version to 4.7.3 php-twig (3.22.2-2) unstable; urgency=medium . * Source-only upload php-twig (3.22.2-1) unstable; urgency=medium . [ Fabien Potencier ] * Update CHANGELOG * Prepare the 3.22.2 release . [ Younes ENNAJI ] * [Core] Fix cycle() with non-countable ArrayAccess+Traversable objects . [ Tac Tacelosky ] * use getShareDir as an indicator of Symfony version . [ Andreas ] * Avoid ord deprecation in PHP 8.5 . [ David Prévot ] * Revert "Require recent php-symfony-intl for changed tests" php-twig (3.22.1-3) unstable; urgency=medium . * [Intl] Update data to ICU 78.1 * Require recent php-symfony-intl for changed tests php-twig (3.22.1-2) unstable; urgency=medium . * Source-only upload php-twig (3.22.1-1) unstable; urgency=medium . [ Fabien Potencier ] * Prepare the 3.22.1 release . [ Javier Eguiluz ] * Allow Symfony 8 packages in Twig extra packages . [ Andreas Erhard ] * Add caution note for random function usage php-twig (3.22.0-2) unstable; urgency=medium . * Source-only upload for testing migration php-twig (3.22.0-1) unstable; urgency=medium . [ Fabien Potencier ] * Fix compatibility layer * Update CHANGELOG . [ Simon André ] * Compile 'index' with repr (not string) in EmbedNode . [ Doeke Norg ] * Update configuration keys + allow extra keys for extensions . [ Vincent Langlet ] * Support two words test guard . [ Nicolas Grekas ] * Fix compatibility with Symfony 8 * Fix accessing arrays with stringable objects as key . [ Christophe Coevoet ] * Avoid errors when failing to guess the template info for an error . [ David Prévot ] * Make phpab tolerant * debian/control: Document nocheck flags php-twig (3.21.1-3) unstable; urgency=medium . * Source-only upload for testing migration php-twig (3.21.1-2) unstable; urgency=medium . * Upload to unstable now that trixie has been released * PHPunit 12 compatibility: additional fixes * Remove Rules-Requires-Root * Fix intl test php-twig (3.21.1-1) experimental; urgency=medium . * Upload to experimental during the freeze . [ Fabien Potencier ] * Introduce operator classes to describe operators provided by extensions instead of arrays * Fix testing and expression when it evaluates to an instance of Markup * Prepare the 3.21.1 release . [ Jérôme Tamarelle ] * Create attributes `AsTwigFilter`, `AsTwigFunction` and `AsTwigTest` to ease extension development . [ David Prévot ] * Update Standards-Version to 4.7.2 php8.4 (8.4.23-1~deb13u1) trixie-security; urgency=high . * New upstream version 8.4.23 + [CVE-2026-14355]: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. php8.4 (8.4.22-1) unstable; urgency=medium . * Update the php-fpm-reopenlogs script to not depend on PID file * New upstream version 8.4.22 php8.4 (8.4.21-1) unstable; urgency=medium . * New upstream version 8.4.21 (Closes: #1136054) php8.4 (8.4.21-1~deb13u1) trixie-security; urgency=high . * New upstream version 8.4.21 + [CVE-2026-7263]: Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS() + [CVE-2026-29078, CVE-2026-29079]: Upgrade to lexbor v2.7.0 + [CVE-2026-6735]: XSS within status endpoint + [CVE-2026-7259]: Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() + [CVE-2026-6104]: Out-of-bounds access in mbfl_name2encoding_ex() + [CVE-2025-14179]: SQL injection via NUL bytes in quoted strings + [CVE-2026-6722]: Stale SOAP_GLOBAL(ref_map) pointer with Apache Map + [CVE-2026-7261]: Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION + [CVE-2026-7262]: Broken Apache map value NULL check + [CVE-2026-7568]: Signed integer overflow of char array offset + [CVE-2026-7258]: Consistently pass unsigned char to ctype.h functions php8.4 (8.4.20-1) unstable; urgency=medium . * New upstream version 8.4.20 php8.4 (8.4.16-1) unstable; urgency=medium . * Add preliminary LiteSpeed SAPI support * New upstream version 8.4.16 + [CVE-2025-14180]: Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null deref). + [CVE-2025-14178]: Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in array_merge()). + [CVE-2025-14177]: Fixed GHSA-3237-qqm7-mfv7 (Information Leak of Memory in getimagesize). pillow (11.1.0-5+deb13u4) trixie; urgency=medium . * Followup fix for CVE-2026-42310 (Closes: #1141330) pillow (11.1.0-5+deb13u3) trixie-security; urgency=medium . * CVE-2026-42308 * CVE-2026-42310 * CVE-2026-42311 poco (1.13.0-6+deb13u1) trixie; urgency=medium . * QA upload. * CVE-2025-6375: Segmentation fault in MultipartStreamBuf (Closes: #1108157) poetry (2.1.2+dfsg-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-34591: Wheel Path Traversal Leading to Arbitrary File Write (Closes: #1132609) poppler (25.03.0-5+deb13u4) trixie; urgency=medium . * Team upload * Fix creation of ill-formed PDF document signatures (Poppler issue #1596) - fixes "Invalid signature time when signing a PDF" (Closes: #1127146) Signatures made with previous versions of Poppler may not be recognized by other applications as valid. poppler (25.03.0-5+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * SplashOutputDev: Fix integer overflow in tilingPatternFill (CVE-2026-10118) (Closes: #1138708) * Make sure regex doesn't stack overflow by limiting it (CVE-2025-43718) (Closes: #1117046) * Check for duplicate entries (CVE-2025-52885) (Closes: #1117853) postfix (3.10.11-0+deb13u1) trixie; urgency=medium . * New upstream version 3.10.11, fixing 5 low-impact issues: - Bugfix: null pointer read and heap data overread in the Postfix SMTP client's smtp_dns_reply_filter - Robustness: the Postfix SMTP server will no longer receive (and discard) an unlimited amount of text while receiving a long SMTP command line - Robustness: do not receive (and discard) unlimited amounts of data with BDAT commands - Bugfix: panic (assertion failure and voluntary crash) while parsing a TLSA reply with length 3 - Bugfix: the SMTP client did not xtext_quote a '+' character in a DSN ORCPT parameter value. A strict receiver implementation could reject or discard the parameter value (this has never been reported to happen) postfix (3.10.10-0+deb13u1) trixie; urgency=medium . [ Michael Tokarev ] * keep postfix running during upgrades (Closes: #1120869) * linux7.patch: support building of the source on 7.x kernels . * new upstream stable/bugfix release 3.10.10: - Bitrot: builds with musl libc broke, because they were using an obsolete NO_SNPRINTF code path. - Two fixes for a signed integer overshift condition (a left shift into the sign bit). This "works" on contemporary CPUs, but may break in the future. - Fix an 'uninitialized value' error in the 'collate.pl' script. . * new upstream stable/bugfix release 3.10.9: - Bugfix: The RFC 2047 encoder for the sender "full name" could loop when a very long full_name_encoding_charset value was configured in main.cf. - Bugfix buffer over-read when Postfix an enhanced status code is not followed by other text. For example, "5.7.2" without text after the three-number code. This CANNOT be triggered with an SMTP or LMTP server response; is confirmed with an access(5) table and likely with a policy server response; can possibly be triggered with pipe-to-command output, header_checks(5), body_checks(5), an error(8) transport in transport_maps, or a milter response; and is confirmed with a DNSBL server TXT response while Postfix is configured with "$rbl_code $rbl_text" in rbl_reply_maps or default_rbl_reply. This could result in process termination. (Closes: #1135718, CVE-2026-43964) - Code cleanup: log a fatal error instead of dereferencing a null pointer after a first/next cursor initialization failure. - Portability: support for recent FreeBSD, NetBSD, and OpenBSD versions. - Bugfix: When truncating a database file, the cdb: database client looked at the file size from before requesting an exclusive lock on a database file, instead of the file size after the exclusive lock was granted. - Bugfix: file descriptor leak after fork() failure. - Mistakes in debug logging. - Unchecked null pointer results after an out-of-memory condition in a library dependency. Found by Claude Opus 4.6. The fix is to return an error status or to log a fatal error. - Missing or incomplete guards for ssize_t or int overflow. These limits are unlikely to be exceeded because the size of in-memory objects is limited by design (the number of in-memory objects is also limited). . * new upstream stable/bugfix release 3.10.8: - Improved Milter error handling for messages that arrive over a long-lived SMTP connection. - Fix "posttls-finger -v -v -v" panic and recursive panic. . * new upstream stable/bugfix release 3.10.7: - build fix for modern compilers and standard bool types (already included in debian) . * new upstream stable/bugfix release 3.10.6: - Bugfix: warning messages that smtp_tls_wrappermode requires "smtp_tls_security_level = encrypt". Root cause: support for "TLS-Required: no" broke client-side TLS wrappermode support, by downgrading a connection to TLS security level 'may'. The fix changes the downgrade level for wrappermode connections to 'encrypt'. Rationale: by design, TLS can be optional only for connections that use STARTTLS. The downgrade to unauthenticated 'encrypt' allows a sender to avoid an email delivery problem. - New logging: the Postfix SMTP client will log a warning when an MX hostname does not match STS policy MX patterns, with "smtp_tls_enforce_sts_mx_patterns = yes" in Postfix, and with TLSRPT support enabled in a TLS policy plugin. It will log a successful match only when verbose logging is enabled. - Bugfix: SMTP client null pointer crash when an STS policy plugin sends no policy_string or no mx_pattern attributes. This can happen only during tests with a fake STS plugin. - Bugfix: segfault when a duplicate parameter name is given to "postconf -X" or "postconf -#'. - Documentation: removed incorrect text from the parameter description for smtp_cname_overrides_servername . [ Aaron Thompson ] * debian-postfix-chroot-cmd.patch: Fix non-ASCII whitespace typo * configure-instance.in: fix typo * d/README.Debian: minor copyediting * Fix some cosmetic typos postfix (3.10.8-1) unstable; urgency=medium . * New upstream version 3.10.8 * Revert "rules: specify -std=gnu17 for CC (#1097639)" (similar solution is adopted upstream) postfix (3.10.6-4) unstable; urgency=medium . * disable chrooting by default finally, after 25 years of everyone suffering. Only limited support for chroot mode will be provided for backwards compatibility. With this in mind, let's close all chroot-related bugs. Closes: #151692, #1084167, #606007, #631665, #714770, #406348, Closes: #1026394, #257096, #278530, #776685, #893516, #935825, Closes: #678808, #896879, #412413, #802043 * yes there's no 3.10.6-3 changelog entry - which was chroot disabling without closing the bugs. postfix (3.10.6-3) unstable; urgency=medium . * disable chrooting by default finally, after 25 years of everyone suffering postfix (3.10.6-1) unstable; urgency=medium . * new upstream stable release: . - Bugfix (defect introduced: Postfix 3.10, date: 20250117). Symptom: warning messages that smtp_tls_wrappermode requires "smtp_tls_security_level = encrypt". Root cause: support for "TLS-Required: no" broke client-side TLS wrappermode support, by downgrading a connection to TLS security level 'may'. The fix changes the downgrade level for wrappermode connections to 'encrypt'. Rationale: by design, TLS can be optional only for connections that use STARTTLS. The downgrade to unauthenticated 'encrypt' allows a sender to avoid an email delivery problem. Problem reported by Joshua Tyler Cochran. . - New logging: the Postfix SMTP client will log a warning when an MX hostname does not match STS policy MX patterns, with "smtp_tls_enforce_sts_mx_patterns = yes" in Postfix, and with TLSRPT support enabled in a TLS policy plugin. It will log a successful match only when verbose logging is enabled. . - Bugfix (defect introduced: Postfix 3.10, date: 20240902): SMTP client null pointer crash when an STS policy plugin sends no policy_string or no mx_pattern attributes. This can happen only during tests with a fake STS plugin. . - Bugfix (defect introduced: Postfix 2.9, date: 20120307): segfault when a duplicate parameter name is given to "postconf -X" or "postconf -#'. . - Documentation: removed incorrect text from the parameter description for smtp_cname_overrides_servername. File: proto/postconf.proto. postfix (3.10.5-3) unstable; urgency=medium . [ Aaron Thompson ] * debian-postfix-chroot-cmd.patch: Fix non-ASCII whitespace typo * configure-instance.in: fix typo * d/README.Debian: minor copyediting * Fix some cosmetic typos . [ Michael Tokarev ] * changelog: fix the Closes: #1120869 line in the previous upload . postfix (3.10.5-2) unstable; urgency=medium . * keep postfix running during upgrades (Closes: #1120869) . Instead of stopping postfix instances before upgrade and starting them after, keep them running during whole upgrade, and restart in one go when finished. . Sometimes during upgrade, old running instance might try to run a new binary which is somehow incompatible with the old instance. Or a new binary try to load old dictionary module and fails. In the worst case, it will cause throttle for this service, but it will be over on restart after upgrade. . But keeping postfix running will make 2 things happen: . 1. In many situations, email will continue working during upgrades; 2. Secondary instances will be restarted automatically too . * d/rules: stop stopping/restarting postfix-resolvconf, since it is pointless postfix (3.10.5-2) unstable; urgency=medium . * keep postfix running during upgrades (#1120869) . Instead of stopping postfix instances before upgrade and starting them after, keep them running during whole upgrade, and restart in one go when finished. . Sometimes during upgrade, old running instance might try to run a new binary which is somehow incompatible with the old instance. Or a new binary try to load old dictionary module and fails. In the worst case, it will cause throttle for this service, but it will be over on restart after upgrade. . But keeping postfix running will make 2 things happen: . 1. In many situations, email will continue working during upgrades; 2. Secondary instances will be restarted automatically too . * d/rules: stop stopping/restarting postfix-resolvconf, since it is pointless postfix (3.10.5-1) unstable; urgency=medium . * new upstream stable release. From the Release Notes: . * Workaround for an interface mis-match between the Postfix SMTP client and MTA-STS policy plugins. . * The existing behavior is to connect to any MX host listed in DNS, and to match the server certificate against any STS policy MX host pattern. . * The corrected behavior is to connect to an MX host only if its name matches any STS policy MX host pattern, and to match the server certificate against the MX hostname. . The corrected behavior must be enabled in two places: in Postfix with a new parameter "smtp_tls_enforce_sts_mx_patterns" (default: "yes") and in an MTA-STS plugin by enabling TLSRPT support, so that the plugin forwards STS policy attributes to Postfix. This works even if Postfix TLSRPT support is disabled at build time or at runtime. . * TLSRPT Workaround: when a TLSRPT policy-type value is "no-policy-found", pretend that the TLSRPT policy domain value is equal to the recipient domain. This ignores that different policy types (TLSA, STS) use different policy domains. But this is what Microsoft does, and therefore, what other tools expect. . * Bugfix (defect introduced: Postfix 3.0): the Postfix SMTP client's connection reuse logic did not distinguish between sessions that require SMTPUTF8 support, and sessions that do not. The solution is 1) to store sessions with different SMTPUTF8 requirements under distinct connection cache storage keys, and 2) to not cache a connection when SMTPUTF8 is required but the server does not support that feature. . * Bugfix (defect introduced: Postfix 3.0, date 20140731): the smtpd 'disconnect' command statistics did not count commands with "bad syntax" and "bad UTF-8 syntax" errors. . * Bugfix: the August 2025 patch broke DBM library support which is still needed on Solaris; and the same change could result in warnings with "database X is older than source file Y". . * Postfix 3.11 forward compatibility: to avoid ugly warnings when Postfix 3.11 is rolled back to an older version, allow a preliminary 'size' record in maildrop queue files created with Postfix 3.11 or later. . * Bugfix (defect introduced: Postfix 3.8, date 20220128): non-reproducible build, because the 'postconf -e' output order for new main.cf entries was no longer deterministic. Problem reported by Oleksandr Natalenko, diagnosis by Eray Aslan. . * To make builds predictable, add missing meta_directory and shlib_directory settings to the stock main.cf file. Problem diagnosed by Eray Aslan. . * Bugfix (defect introduced: Postfix 3.9, date 20230517): posttls-finger(1) logged an incorrectly-formatted port number. Viktor Dukhovni. postgresql-17 (17.10-0+deb13u1) trixie-security; urgency=medium . * New upstream version 17.10. . + Prevent unbounded recursion while processing startup packets (Michael Paquier) . A malicious client could crash the connected backend by alternating rejected SSL and GSS encryption requests indefinitely. . The PostgreSQL Project thanks Calif.io (in collaboration with Claude and Anthropic Research) for reporting this problem. (CVE-2026-6479) . + Fix assorted integer overflows in memory-allocation calculations (Tom Lane, Nathan Bossart, Heikki Linnakangas) . Various places were incautious about the possibility of integer overflow in calculations of how much memory to allocate. Overflow would lead to allocating a too-small buffer which the caller would then write past the end of. This would at least trigger server crashes, and probably could be exploited for arbitrary code execution. In many but by no means all cases, the hazard exists only in 32-bit builds. . The PostgreSQL Project thanks Xint Code, Bruce Dang, Sven Klemm, and Pavel Kohout for reporting these problems. (CVE-2026-6473) . + Properly quote subscription names in pg_createsubscriber (Nathan Bossart) . The given subscription name was inserted into SQL commands without quoting, so that SQL injection could be achieved in the (perhaps unlikely) case that the subscription name comes from an untrusted source. . The PostgreSQL Project thanks Yu Kunpeng for reporting this problem. (CVE-2026-6476) . + Properly quote object names in logical replication origin checks (Pavel Kohout) . ALTER SUBSCRIPTION ... REFRESH PUBLICATION interpolated schema and relation names into SQL commands without quoting them, allowing execution of arbitrary SQL on the publisher. . The PostgreSQL Project thanks Pavel Kohout for reporting this problem. (CVE-2026-6638) . + Reject over-length options in ts_headline() (Michael Paquier) . The StartSel, StopSel and FragmentDelimiter strings must not exceed 32Kb in length, but this was not checked for. An over-length value would typically crash the server. . The PostgreSQL Project thanks Xint Code for reporting this problem. (CVE-2026-6473) . + Guard against malicious time zone names in timeofday() and pg_strftime() (Tom Lane) . A crafted time zone setting could pass % sequences to snprintf(), potentially causing crashes or disclosure of server memory. Another path to similar results was to overflow the limited-size output buffer used by pg_strftime(). . The PostgreSQL Project thanks Xint Code for reporting this problem. (CVE-2026-6474) . + When creating a multirange type, ensure the user has CREATE privilege on the schema specified for the multirange type (Jelte Fennema-Nio) . The multirange type can be put into a different schema than its parent range type, but we neglected to apply the required privilege check when doing so. . The PostgreSQL Project thanks Jelte Fennema-Nio for reporting this problem. (CVE-2026-6472) . + Use timing-safe string comparisons in authentication code (Michael Paquier) . Use timingsafe_bcmp() instead of memcpy() or strcmp() when checking passwords, hashes, etc. It is not known whether the data dependency of those functions is usefully exploitable in any of these places, but in the interests of safety, replace them. . The PostgreSQL Project thanks Joe Conway for reporting this problem. (CVE-2026-6478) . + Mark PQfn() as unsafe, and avoid using it within libpq (Nathan Bossart) . For a non-integral result type, PQfn() is not passed the size of the output buffer, so it cannot check that the data returned by the server will fit. A malicious server could therefore overwrite client memory. This is unfixable without an API change, so mark the function as deprecated. Internally to libpq, use a variant version that can apply the missing check. . The PostgreSQL Project thanks Yu Kunpeng and Martin Heistermann for reporting this problem. (CVE-2026-6477) . + Prevent path traversal in pg_basebackup and pg_rewind (Michael Paquier) . These applications failed to validate output file paths read from their input, so that a malicious source could overwrite any file writable by these applications. Constrain where data can be written by rejecting paths that are absolute or contain parent-directory references. . The PostgreSQL Project thanks XlabAI Team of Tencent Xuanwu Lab and Valery Gubanov for reporting this problem. (CVE-2026-6475) . + Guard against field overflow within contrib/intarray's query_int type and contrib/ltree's ltxtquery type (Tom Lane) . Parsing of these query structures did not check for overflow of 16-bit fields, so that construction of an invalid query tree was possible. This can crash the server when executing the query. . The PostgreSQL Project thanks Xint Code for reporting this problem. (CVE-2026-6473) . + Guard against overly long values of contrib/ltree's lquery type (Michael Paquier) . Values with more than 64K items caused internal overflows, potentially resulting in stack smashes or wrong answers. . The PostgreSQL Project thanks Vergissmeinnicht, A1ex, and Jihe Wang for reporting this problem. (CVE-2026-6473) . + Prevent SQL injection and buffer overruns in contrib/spi (Nathan Bossart) . check_foreign_key() was insufficiently careful about quoting key values, and also used fixed-length buffers for constructing queries. While this module is only meant as example code, it still shouldn't contain such dangerous errors. . The PostgreSQL Project thanks Nikolay Samokhvalov for reporting this problem. (CVE-2026-6637) protobuf (3.21.12-11+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Fix CVE-2026-0994: JSON recursion depth bypass (closes: #1126302). * Fix CVE-2026-6409: PHP Denial of Service (closes: #1134895). . [ Hlib Korzhynskyy ] * Complete fix of CVE-2024-7254 (closes: #1082381): - add recursion checks and recursion limit, - add tests. . [ Laszlo Boszormenyi (GCS) ] * Fix CVE-2025-4565: data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit (closes: #1108057). psd-tools (1.10.7+dfsg.1-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-27809: Compression module vulnerabilities (Closes: #1129098) pupnp (1:1.14.20-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-41682: SSRF port confusion pymdown-extensions (10.13-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-68142: ReDOS in Figure Capture extension (Closes: #1123672) pyopenssl (25.0.0-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-27448: Unhandled exceptions in set_tlsext_servername_callback callbacks did not cancel connections * CVE-2026-27459: Buffer overflow in DTLS cookie callback pytest-httpbin (2.1.0-1+deb13u1) trixie; urgency=medium . * Team upload. * Disable flaky test. Closes: #1137653. python-daphne (4.1.2-2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-44545: DoS via unbounded WebSocket message sizes * CVE-2026-44546: Header injection on WebSocket upgrade path * (Closes: #1138864) python-django (3:4.2.28-0+deb13u2) stable-proposed-updates; urgency=medium . * The fix for CVE-2025-6069 in the python3.13 source package (released as part of a suite of updates in 3.13.5-2+deb13u2) modified Python's html.parser.HTMLParser class in such a way that changed the behaviour of Django's strip_tags() method. As a result of this change, we update the testsuite here for the newly expected results in order to prevent a build failure. (Closes: #1137039) python-dynaconf (3.1.7-2+deb13u1) trixie; urgency=medium . * CVE-2026-33154 (Closes: #1131476) python-grpc-tools (1.14.1-8+deb13u1) trixie; urgency=medium . * Team upload. . [ Theodore Tucker ] * d/patches: Fix shadowed variable in grpc_tools/command.py (Closes: #1132763) python-handy-archives (0.2.0-5+deb13u1) trixie; urgency=medium . * Fix Zip64 end of central directory locator. (Closes: #1137041) python-idna (3.10-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-45409: DoS from specially crafted inputs (Closes: #1139164) python-iniparse (0.5.1-1+deb13u1) trixie; urgency=medium . * Team upload. * Fix race condition in test_multiprocessing. Closes: #1137634. python-jwcrypto (1.5.6-1.1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . python-jwcrypto (1.5.6-1.1) unstable; urgency=medium . * Non-maintainer upload. * CVE-2026-39373: JWT bomb Attack in deserialize (Closes: #1133006) python-markdown (3.7-2+deb13u1) trixie; urgency=medium . * Adapt to changes in html.parser module in the new Python, backported to Trixie as part of CVE fixes (closes: #1137043). python-marshmallow (3.26.2-0+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * New upstream release. - CVE-2025-68480: DoS with Schema.load(many) (Closes: #1123888) python-marshmallow (3.26.1-0.4) unstable; urgency=medium . * Non-maintainer upload. * Disable useless Salsa CI tests * Drop "Rules-Requires-Root: no": it is the default now * Bump Standards-Version to 4.7.3, drop Priority: tag * Drop unused python3-tz build-dep * Rewrite d/watch in v5 format python-marshmallow (3.26.1-0.3) unstable; urgency=medium . * Non-maintainer upload. * Handle new error message in newer Python (closes: #1123267). python-memray (1.17.0+dfsg-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-32722: XSS in generated HTML reports via unescaped command-line metadata (Closes: #1131372) python-oslo.messaging (16.1.0-3+deb13u1) trixie-security; urgency=medium . * Add fix-not-using-non-durable.patch. * CVE-2026-44393 / OSSN-0096: oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake. Added upstream patch: Fix RabbitMQ TLS hostname verification (Closes: #1138848). python-urllib3 (2.3.0-3+deb13u2) trixie-security; urgency=medium . * CVE-2026-44431 (Closes: #1136653) python-virtualenv (20.31.2+ds-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-22702: Time-of-Check-Time-of-Use Vulnerabilities in Directory Creation (Closes: #1125191) python-webob (1:1.8.10-0+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * New upstream release. - CVE-2026-44889: Location header normalization during redirect leads to open redirect python-webob (1:1.8.9-2) unstable; urgency=medium . * Team upload. * Add debian/salsa-ci.yml * Mark build-deps as !nocheck or !nodoc * Remove redundant Priority: optional from source stanza. * Update lintian override info format . [ Shanavas M ] * Fix test failure (Closes: #1123459) * Bumped standards version to 4.7.4 python-xmltodict (0.13.0-1.1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . python-xmltodict (0.13.0-1.1) unstable; urgency=medium . * Non-maintainer upload. * CVE-2025-9375: XML Injection (Closes: #1113825) python-xmltodict (0.13.0-1.1~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Rebuild for bookworm. . python-xmltodict (0.13.0-1.1) unstable; urgency=medium . * Non-maintainer upload. * CVE-2025-9375: XML Injection (Closes: #1113825) python3.13 (3.13.5-2+deb13u3) trixie; urgency=medium . [ Stefano Rivera ] * Patches: - Fix a crash in SNI callback when the SSL object is gone. - Fix reference leaks in ssl.SSLContext objects. (Closes: #1138157) - Avoid garbage collecting objects too early when sharing __dict__ (Closes: #1108039) - Update the patch for CVE-2026-6019 to use decodeURIComponent. . [ Moritz Mühlenhoff ] * CVE-2026-1502 * CVE-2026-3276 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-9669 qemu (1:10.0.11+ds-0+deb13u1) trixie; urgency=medium . * new upstream stable/bugfix release: - Update version for 10.0.11 release - linux-user: Fix AT_PHDR when program headers are relocated into their own segment - hw/pci: Replace assert with bounds check and return - ppc/pnv_phb3: Error out on invalid config access - linux-user/xtensa: fix unlock of uninitialized frame pointer on sigreturn - linux-user/xtensa: save/restore FP registers across signal delivery - target/xtensa: add cpu_set_fcr/fsr helpers to sync fp_status - ui/sdl2: Set GL ES profile before creating initial GL context - hw/9pfs: reject . and .. in Twstat rename - hw/9pfs: fix abort due to illegal name with Twstat rename - gdbstub: Update x86 control register bits - target/i386: apply mod to immediate count of an RCL/RCR operation - hw/uefi: fix parse_hexstr (Closes: CVE-2026-48915) - target/riscv: mask vxrm csrw write to the low 2 bits - disas/riscv.c: fix inst_length() - target/riscv/cpu_helper.c: add PMA access fault - target/riscv/cpu_helper.c: fault with reserved PTE.PBMT val - target/riscv/insn_trans/trans_rvzicbo.c.inc: save opcode before helpers - disas/riscv.c: add 'cbo' insns to disassembler - target/riscv/csr.c: fix mstatus.UXL reserved value - target/riscv/csr.c: do not allow mstatus MPV/GVA writes - target/riscv/cpu_helper.c: allow LOAD_ADDR_MIS promotion to AMO fault - virtio: Allow to fill a whole virtqueue in order - libvduse: fix buffer overflow in vduse_queue_read_indirect_desc() (Closes: CVE-2026-6425) - libvhost-user: fix buffer overflow in virtqueue_read_indirect_desc() (Closes: CVE-2026-6425) - tests/qtest: Add amd-iommu command buffer head wrap test - amd_iommu: Update command buffer head ptr in MMIO region after wraparound - amd_iommu: restrict command buffer head/tail ranges to ring size - linux-user: add preadv2/preadv2 - system/rtc: Fix a possible year-2038 integer overflow problem - linux-user/strace: add fsmount series of syscalls - linux-user: implement fsmount(2) series of syscalls - fpu: Handle all rounding modes in partsN_uncanon_normal - hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet - qed: Don't try to flush during incoming migration - qcow2: Fix data loss on zero write with detect-zeroes=unmap - iotests/046: Test that discard/write_zeroes wait for dependencies - qcow2: Fix corruption on discard during write with COW - qemu-io: Add 'aio_discard' command - virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (Closes: #1139923, CVE-2026-48914) - block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment - s390x/pci: Fix interrupt forwarding disable for interpreted devices - target/s390x: Make container ids in SysIB_15x 1-based - tests/unit: add test-envlist covering setenv/unsetenv name matching - util/envlist: fix prefix-match in envlist_unsetenv() name lookup - 9pfs: fix missing rename lock in v9fs_co_readdir_many (Closes: CVE-2026-48004) - tests/9pfs: add deep absolute path test - tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset - hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors - hw/9pfs: add error handling to v9fs_fix_path() - hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type - hw/9pfs: add NULL check in v9fs_path_is_ancestor() - hw/9pfs: move G_GNUC_PRINTF to header - linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn - linux-user/sh4: restore FP rounding mode on sigreturn - linux-user/sh4: preserve T/M/Q bits across signal delivery - linux-user/mips: save/restore FCSR across signal delivery - linux-user/ppc: restore fp_status from FPSCR on sigreturn - hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() - hw/net/rocker_of_dpa: Check group ID pointers are not NULL - target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault - target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 - target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs - target/arm: SVE2 FMAXP, FMINP must honour AH=1 - block/linux-aio: bound ioq_submit() recursion depth - mc146818rtc: Fix get_guest_rtc_ns() overflow bug - apic: fix delivery bitmask with modified xAPIC ids - lsi53c895a: clear tag byte when processing messages - lsi53c895a: fix use-after-free of cancelled request - ui: fix validation of VNC extended clipboard data length (Closes: CVE-2026-8343) - ui/vnc: fix OOB read updating VNC update frequency stats (Closes: CVE-2026-48003) - ui/vnc: fix OOB write in lossy rect worker code (Closes: CVE-2026-48002) - ui/vnc: fix OOB write in VNC stats array (Closes: CVE-2026-48002) - ui/vnc: fix OOB read access in VNC SASL mechname array - target/riscv: clear mseccfg on reset for all dependent extensions - target/riscv: Update the local interrupt mask - target/riscv: Add mseccfg to VMStateDescription - target/riscv: Save stimer and vstimer in CPU vmstate - target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation - target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL - hw/char: sifive_uart: Implement txctrl.txen and rxctrl.rxen - hw/char: sifive_uart: Avoid infinite delay of async xmit function - target/riscv: Allow mseccfg access based on ext_zicfilp - hw/riscv/riscv-iommu: Fix Svnapot 64KB pages - target/riscv: Update MISA.X for non-standard extensions - target/riscv: Update MISA.C for Zc* extensions qemu (1:10.0.10+ds-0+deb13u1) trixie; urgency=medium . * 10.0.10 upstream stable/bugfix release: - Update version for 10.0.10 release - block/graph-lock: fix missed wakeup in bdrv_graph_co_rdunlock() - block: Add more defaults to DEFAULT_BLOCK_CONF - block: Create DEFAULT_BLOCK_CONF macro - ide-test: Test reset during TRIM - ide-test: Factor out wait_dma_completion() - ide: Clean up ide_trim_co_entry() to be idiomatic coroutine code - ide: Minimal fix for deadlock between TRIM and drain - block: Add flags parameter to blk_*_pdiscard() - block: Add blk_co_start/end_request() and BDRV_REQ_NO_QUEUE - blkdebug: Add 'delay-ns' option - linux-user/sh4: Fix setup_sigtramp to match Linux kernel trampoline pattern - linux-user/sh4: Fix target_ucontext tuc_link field type - linux-user: Fix AT_EXECFN in AUXV for symlinked programs - hw/nvme: fix admin cq msix setup - tests/functional/qemu_test/asset.py: Don't use setxattr when it doesn't exist - meson.build: Add -fzero-init-padding-bits=all - hw/i2c/microbit_i2c: Don't index off end of twi_read_sequence[] - aspeed/hace: Prevent total_req_len overflow - aspeed/hace: Fix out-of-bounds read in has_padding() - hw/display/cirrus_vga: Fix packed-24 color-expansion transparent copies - hw/display/cirrus_vga: Fix packed-24 color-expansion transparent pattern fills - hw/ufs: Keep MCQ SQs alive while requests are outstanding - hw/ufs: Reject zero-depth MCQ queues - hw/ufs: Guard MCQ CQ accesses against missing queues - hw/ufs: Validate MCQ SQ references before use - hw/uefi: check auth.hdr_length minimum size (Closes: CVE-2026-8341) - hw/uefi: avoid possibly unaligned variable_auth_2 struct field access (Closes: CVE-2026-41440) - hw/uefi: verify data size before accessing it in wrap_pkcs7 (Closes: CVE-2026-41439) - hw/uefi: add name_size check to uefi_vars_mm_lock_variable() (Closes: CVE-2026-41438) - hw/uefi: fix ucs2 string helper functions (Closes: CVE-2026-41437) - hw/uefi: verify pio_xfer_offset before calculating buffer checksum (Closes: CVE-2026-41436) - hw/uefi: fix buffer overruns (Closes: CVE-2026-41435) - hw/misc/bcm2835_rng: Specify valid memory access sizes - target/arm: Report IL=0 for Thumb 16-bit BKPT insn - target/microblaze: Fix endianness used to disassemble - hw/intc/arm_gicv3: Fix NS write to ICC_AP1Rn_EL1 when prebits < 7 - hw/net/allwinner-sun8i-emac: Flush queued packets when rx is enabled - hw/ppc/e500: fix bus-frequency property hardcoded to zero in CPU FDT node - hw/ppc/e500: Move clock and TB frequency to machine class - tests/rcutorture: Fix build error - hw/intc/xics: Add a check for an invalid server id - linux-user: Translate errno in IP_RECVERR and IPV6_RECVERR - linux-user: Allow getsockopt() with NULL optval address - linux-user: Flush errors by using exit() instead of _exit() in error path - linux-user: Add missing CDROM ioctls - target/riscv: Use ELEN for Fractional LMUL check - target/riscv: Don't OR mip.SEIP when mvien is one - target/riscv: Generate access fault if sc comparison fails - riscv_htif: reject invalid signature ranges (end <= begin) - hw/intc: fix heap OOB in ACLINT MTIMER multi-socket - target/riscv: fix stale ptshift and base on page walk restart - hw/riscv/virt-acpi-build.c: Use kvm timer frequency when kvm enabled - linux-user: Flush errors by using exit() instead of _exit() in error path - linux-user: Use abi_int for imr_ifindex in ip_mreqn struct - linux-user: Fix CLONE_PARENT_SETTID when using fork-like clone - linux-user: Add getsockopt() for SO_RCVTIMEO_NEW and SO_SNDTIMEO_NEW - linux-user: Add setsockopt() for SO_RCVTIMEO_NEW and SO_SNDTIMEO_NEW - linux-user: Define SO_TIMESTAMP*_NEW and SO_RCVTIMEIO_NEW - linux-user/mips: sync k0 TLS for EF_MIPS_MACH_OCTEON userlands - linux-user/strace: Use pointer type for read and write values - linux-user/arm/nwfpe: Use thread-local storage for qemufpa - linux-user/arm/nwfpe: Replace user_registers with current_cpu - linux-user: Don't define target_stat64 struct for loongarch64 - linux-user: fix off-by-one in host_to_target_for_each_rtattr() - linux-user/ppc: Fix ppc64 rt_sigframe stack offset - hw/sh4/sh7750: Remove forgotten abort() in the MM_ITLB_DATA handler - hw/misc: Fix the valid access size to the avr-power device - migration: vmstate_save_state_v: fix double error_setg - hw/display: don't accidentally autofree existing virgl resources (Closes: CVE-2026-6502) - meson: add missing semicolon in pthread_condattr_setclock test - target/i386/tcg: fix decoding of MOVBE and CRC32 in 16-bit mode - target/i386: fix missing PF_INSTR in SIGSEGV context - target/i386: fix strList leak in x86_cpu_get_unavailable_features - target/arm/tcg/translate.c: remove MO_TE usage - ui/console-vc: fix off-by-one in CSI J 2 (clear entire screen) - ui/spice-app: detect runtime directory creation failures - serial COM: windows serial COM PollingFunc don't sleep - util/cutils: Fix heap corruption under Windows - virtio-blk: fix zone report buffer out-of-memory (Closes: CVE-2026-5761) - qemu-keymap: fix altgr modifier lookup for newer xkeyboard-config - hw/uefi: fix heap overflow (Closes: CVE-2026-5744) - virtio-scsi: pass the same cdb_size to virtio_scsi_pop_req and virtio_scsi_handle_cmd_req_prepare (Closes: CVE-2026-5763) - util/readline: Fix out-of-bounds access in readline_insert_char() - target/arm: fix fault_s1ns for stage 2 faults - target/arm: do_ats_write(): avoid assertion when ptw failed - bsd-user, linux-user: signal: recursive signal delivery fix - linux-user: Make openat2() use -L for absolute paths - linux-user: update select timeout writeback - linux-user: fix name_to_handle_at when AT_HANDLE_MNT_ID_UNIQUE flag is set - util: fix missing aio_wait sym in qemu guest agent only build - monitor: Fix deadlock in monitor_cleanup - scsi: Don't consider LOGICAL UNIT NOT SUPPORTED guest recoverable - ide: Fix potential assertion failure on VM stop for PIO read error - ui/vnc-jobs: fix VncRectEntry leak on job cleanup - hw/net/rocker: Avoid double-free of l2_flood.group_ids - lsi53c895a: keep SCSIRequest alive during DMA - lsi53c895a: keep lsi_request alive as long as the SCSIRequest - lsi53c895a: keep lsi_request and SCSIRequest in local variables - lsi53c895a: do not do anything else if a reset is requested by writing ISTAT0 - lsi53c895a: keep a reference to the device while SCRIPTS execute (Closes: #1085299, CVE-2024-6519) - scripts/qemu-guest-agent/fsfreeze-hook: Fix syslog-fallback logic - scripts/qemu-guest-agent/fsfreeze-hook: Avoid use of PIPESTATUS - scripts/qemu-guest-agent/fsfreeze-hook: Avoid bash-isms - hw/nvme: fix heap-buffer-overflow in nvme_abort - hw/nvme: re-enable wzds bit in namespace dlfeat - tcg: Pass host-endian values to plugin_gen_mem_callbacks_* - hw/audio/sb16: validate VMState fields in post_load - block/curl: free s->password in cleanup paths - linux-aio: Resubmit tails of short reads/writes - linux-aio: Put all parameters into qemu_laiocb - hw/dma/pl080: Fix transfer logic in PL080 - linux-user/i386/signal.c: Correct definition of target_fpstate_32 - hw/ssi/aspeed_smc: Convert mem ops to read/write_with_attrs for error handling - hw/net/ftgmac100: Improve DMA error handling - hw/usb/hcd-ohci: check for MPS=0 to avoid infinite loop (Closes: CVE-2026-3890) - rust: suggest passing --locked to "cargo install" - target/riscv: rvv: Fix page probe issues in vext_ldff - target/riscv: rvv: Fix missing flags merge in probe_pages for cross-page accesses - Expand the probe_pages helper function to handle probe flags - block: Drop detach_subchain for bdrv_replace_node - virtio-gpu: fix overflow check when allocating 2d image (Closes: CVE-2026-3886) - io: Fix TLS bye task leak - ppc/pnv: generate dtb after machine initialization is complete - ppc/pnv: fix dumpdtb option - block/mirror: fix assertion failure upon duplicate complete for job using 'replaces' - throttle-group: Fix race condition in throttle_group_restart_queue() - target/i386: fix NULL pointer dereference in legacy-cache=off handling - hw/dma/pl080: Ignore bottom 2 bits of LLI register - hw/dma/pl080: Update interrupts after pl080_run() - hw/dma/pl080: Handle bogus swidth and dwidth in transfers - linux-user: fix mremap with old_size=0 for shared mappings - linux-user: Fix zero_bss for RX PT_LOAD segments - hw/net/rtl8319: Work around GCC sanitizer / -Wstringop-overflow bug . * 10.0.9 stable/bugfix release: - Update version for 10.0.9 release - hyperv/syndbg: check length returned by cpu_physical_memory_map() (Closes: CVE-2026-3842) - fuse: Copy write buffer content before polling - target/loongarch: Avoid recursive PNX exception on CSR_BADI fetch - target/loongarch: Preserve PTE permission bits in LDPTE - hw/net/npcm_gmac: Catch accesses off the end of the register array - linux-user: fix TIOCGSID ioctl - tests/tcg/multiarch/test-mmap: Check mmaps beyond reserved_va - bsd-user: Deal with mmap where start > reserved_va - linux-user: Deal with mmap where start > reserved_va - hw/net/xilinx_ethlite: Check for oversized TX packets - virtio-gpu: Ensure BHs are invoked only from main-loop thread - block/nfs: Do not enter coroutine from CB - block: Never drop BLOCK_IO_ERROR with action=stop for rate limiting - block/throttle-groups: fix deadlock with iolimits and muliple iothreads - mirror: Fix missed dirty bitmap writes during startup (Closes: #1129349) - block/curl: fix concurrent completion handling - block/vmdk: fix OOB read in vmdk_read_extent() (Closes: #1128478, CVE-2026-2243) - hw/net/smc91c111: Don't allow negative-length packets - io: fix cleanup for websock I/O source data on cancellation - io: fix cleanup for TLS I/O source data on cancellation - io: separate freeing of tasks from marking them as complete - target/i386/hvf/x86_mmu: Fix compiler warning - hw/i386/vmmouse: Fix hypercall clobbers - tests/docker: upgrade most non-lcitool debian tests to debian 13 - hw/9pfs: fix missing EOPNOTSUPP on Twstat and Trenameat for fs synth driver - hw/9pfs: fix data race in v9fs_mark_fids_unreclaim() - target/arm: set the correct TI bits for WFIT traps - hw/ssi/xilinx_spips: Reset TX FIFO in reset - hw/misc/virt_ctrl: Fix incorrect trace event in read operation - virtio-snd: tighten read amount in in_cb (Closes: #1129604, CVE-2026-3195) - virtio-snd: fix max_size bounds check in input cb (Closes: #1129604, CVE-2026-3195) - virtio-snd: handle 5.14.6.2 for PCM_INFO properly (Closes: #1129605, CVE-2026-3196) - virtio-snd: remove TODO comments - virtio-gpu-virgl: Add virtio-gpu-virgl-hostmem-region type (was in virtio-gpu-virgl-Add-virtio-gpu-virgl-hostmem-region.patch) - target/arm: Fix feature check in DO_SVE2_RRX, DO_SVE2_RRX_TB - target/arm: Account for SME in aarch64_sve_narrow_vq() assertion - target/arm: Introduce ARMCPU.sme_max_vq - hw/i2c/aspeed_i2c: Fix out-of-bounds read in I2C MMIO handlers - docs/about/emulation: Add documentation for hotblocks plugin arguments - contrib/plugins/hotblocks: Print uint64_t with PRIu64 rather than PRId64 - contrib/plugins/hotblocks: Fix off by one error in iteration of sorted blocks - contrib/plugins/hotblocks: Correctly free sorted counts list - contrib/plugins: Fix type conflict of GLib function pointers - python: drop uses of pkg_resources - plugins: fix cross-build using LLVM for Windows targets - s390x/pci: Fix endianness for zPCI BAR values qtmir (0.8.0~git20250407.ea2f477-1+deb13u1) trixie; urgency=medium . * debian/patches: + Add 0009_src-modules-Add-header-for-getpid.patch. Add include for getpid() function. + Add 0002_src-modules-Re-introduce-lost-workaround-for-font-re.patch. Regression fix, fix arbitrary font rendering glitches. (LP:#1583088). + Add 0011_src-platforms-Wrap-window-activity-change-in-a-try-c.patch. Selecting the active window can lead to a range exception, so avoid a crash by wrapping this in a try-catch. + Add 0012_src-modules-Partial-revert-of-e73ef71622ad3202b77bf6.patch. Drop overzealous code when removing a window. + Trivial rebase of 2003_disable-benchmarks.patch. + Add 0022_modules-MirSurface-try-to-let-Mir-forceClose-dead-su.patch. Attempt at forceClosing dead surfaces. + Add 0031a_src-platforms-Select-GLRenderingProvider-based-on-su.patch and 0031b_src-platforms-fix-anonymous-call-for-C-20.patch. Support Lomiri on Asahi Linux. + Add 0033_src-platforms-Do-not-composite-again-on-running-comp.patch. Don't crash when GRID_UNIT_PX is set to other values than 8. Fix scaling support in Lomiri. + Add 0034_src-platforms-Remove-guard-producing-dead-code-use-c.patch. src/platforms: Remove guard producing dead code; use caching instead. + Add 0035_src-platforms-Export-Xwayland-DISPLAY-to-systemd-and.patch. src/platforms: Export Xwayland DISPLAY to systemd and DBus. + Add 1001_do-not-focus-windows-on-touchdown-events.patch. wrappedwindowmanagementpolicy: do not focus windows on touch down events. Otherwise Mir will incorrectly focus the last opened window in Lomiri spread. rauc (1.13-3+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2026-34155: Improper Signing of Plain Bundles Exceeding 2 GiB redis (5:8.0.2-3+deb13u2) trixie-security; urgency=high . * CVE-2025-67733: RESP protocol injection via Lua error_reply. A user could manipulate data read by a connection by injecting CR/LF sequences into a Redis error reply. * CVE-2026-21863: Remote DoS with malformed Cluster bus message. A peer could send a crafted PING/PONG/MEET packet whose gossip count or ping-extension header exceeds the received packet length, causing out-of-bounds reads and a server crash. request-tracker5 (5.0.7+dfsg-4+deb13u3) trixie-security; urgency=high . * Include missing default configuration items for security vulnerability fixes included in 5.0.7+dfsg-3. Namely: RestrictLinkDomains and Cipher in %SMIME. * Apply upstream patch which fixes several security vulnerabilities: - [CVE-2026-6841] Reflected cross-site scripting via the search "Page" URL parameter. - [CVE-2026-41073] Spreadsheet (CSV/formula) injection via ticket values that are exported to a spreadsheet from search results. User-controlled data is not sanitized before being written to the output file, which can cause spreadsheet applications such as Microsoft Excel to interpret crafted values as formulas or macros when the file is opened. - [CVE-2026-41075] SQL injection via the entry_aggregator parameter in JSON search. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. - [CVE-2026-41076] LDAP authentication bypass when RT is configured to authenticate users against an LDAP or Active Directory server. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. - [CVE-2026-44229] Cross-site scripting via uploaded content that is served inline rather than as an attachment. - [CVE-2026-44230] Reflected cross-site scripting on search-results chart pages. - [CVE-2026-44231] Privilege escalation and information disclosure via the REST 2.0 user collection endpoint. A Privileged RT user can obtain authentication credentials belonging to other users, including administrators, and use those credentials to read data via RT's RSS and iCal feed endpoints. The same request that exposes the credentials also rotates them, which invalidates previously-distributed feed URLs across the instance. resource-agents (1:4.16.0-3+deb13u2) trixie; urgency=medium . * debian/patches: fix bash syntax error (Closes: #1133386) rhino (1.7.15.1-0.1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . rhino (1.7.15.1-0.1) unstable; urgency=medium . * Non-maintainer upload. * New upstream release. - CVE-2025-66453: High CPU usage and potential DoS when passing specific numbers to toFixed() (Closes: #1121953) rlottie (0.1+dfsg-4.2+deb13u2) trixie; urgency=medium . * Fix off-by-one error in Fortify-FreeType-raster.patch. * Add Fixed-vpath-potential-issue.patch to fix CVE-2026-47319. (Closes: #1138919) * Add Limit-recursion-in-LOTLayerItem.patch to fix CVE-2026-47320. (Closes: #1138920) * New Fixed-signed-shift-issue.patch probably fixes CVE-2026-10305. (Closes: #1139179) * New Fix-heap-buffer-overflow-from-short-truncation.patch. roundcube (1.6.16+dfsg-0+deb13u1) trixie-security; urgency=high . * New upstream security and bugfix release (closes: #1137507). + Fix CVE-2026-48842: pre-auth SQL injection in `virtuser_query plugin` via `preg_replace()` backslash escape bypass. + Fix CVE-2026-48843: SSRF bypass via specific local address URLs. Add support non quad-dotted IPs and non-decimal fields to d/p/Avoid-dependency-on-new-package-mlocati-ip-lib.patch in order to match the new upstream behavior. + Fix CVE-2026-48844: Code injection vulnerability via code evaluation support in LDAP autovalues option. Code evaluation support has now been removed. + Fix CVE-2026-48845: Local/private URL fetch bypass when remote resources were not allowed. + Fix CVE-2026-48846: Bypass of remote image blocking via CSS `var()`. + Fix CVE-2026-48847: Pre-auth arbitrary file delete via redis/memcache session poisoning bypass. + Fix CVE-2026-48848: CSS injection bypass in HTML sanitizer via SVG . + Fix CVE-2026-48849: Stored XSS/HTML/CSS injection in subject field of the draft restore dialog. + Fix PHP8 warnings. + Fix potential too long value in IMAP ID command. * Refresh d/patches. roundcube (1.6.15+dfsg-1) unstable; urgency=high . * New upstream security and bugfix release (closes: #1132268). + Fix SVG animate FUNCIRI attribute bypass (remote image loading via fill/filter/stroke). + Fix regression where mail search would fail on non-ascii search criteria. + Fix regression where some data url images could get ignored/lost. * Refresh d/patches and remove those applied upstream. * d/control: Add Build-Depends: node-source-map. * Improve custom patch to avoid dependency on mlocati/ip-lib: + Trim leading zeros from the decimal representation of IPv4 octets to match GuzzleHTTP's mangling of invalid IP addresses. + Treat IPv4-mapped and IPv4-compatible addresses as belonging to the local range when the v4 address is also local. rsync (3.4.1+ds1-5+deb13u4) trixie; urgency=medium . * Non-maintainer upload. * Import upstream patch to reject overlong HTTP proxy response lines, avoiding a one byte out of bounds stack write when using RSYNC_PROXY. (CVE-2026-45232). rsync (3.4.1+ds1-5+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Address several vulnerabilities - CVE-2026-29518: Symlink-race TOCTOU in daemon (use chroot = no) - CVE-2026-43617: Authorization bypass via hostname resolution (daemon chroot mode) - CVE-2026-43618: Integer overflow in compressed-token decoder (info disclosure) - CVE-2026-43619: Symlink-race conditions in path-based syscalls - CVE-2026-43620: Out-of-bounds array read in receiver recv_files() * d/t/upstream-tests: Build t_chmod_secure and t_secure_relpath rtl-433 (25.02-1+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2025-34450: Buffer overflow in parse_rfraw() (Closes: #1126178) ruby-css-parser (1.19.0-1+deb13u1) trixie; urgency=medium . * Team upload. * Import upstream patch to stop disabling HTTPS certificate verification when loading remote CSS. (CVE-2026-44312) rust-time (0.3.37-1+deb13u1) trixie; urgency=medium . * Backport upstream fix for CVE-2026-25727 (Closes: #1128404) samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium . * switch to actual upstream release for the May-2026 security fixes: . * This is a security release in order to address the following defects: . CVE-2026-1933: Missing access checks on reparse point operations On a share marked "read only = yes" and on file handles opened R/O users can set or delete the reparse point xattrs on files that the user has write-access in the file system for. https://www.samba.org/samba/security/CVE-2026-1933.html . CVE-2026-2340: WORM vfs module does not block overwrites The WORM (Write-Once, Read Many) vfs module is supposed to lock write access to shared files, so they cannot be altered after initial writes. It was allowing files to be overwritten by renaming a newly created file over a protected file. https://www.samba.org/samba/security/CVE-2026-2340.html . CVE-2026-3012: auto-enrolment GPO installing CA certificate over http without verification To bootstrap a certificate chain a domain member must fetch a certificate without TLS. It was trusting HTTP for this when a more secure encrypted LDAP channel was also available. https://www.samba.org/samba/security/CVE-2026-3012.html . CVE-2026-3238: Denial of service against AD DC WINS server The WINS server component of the Active Directory Domain controller code in Samba is vulnerable to a NULL pointer dereference and crash caused by an unauthenticated UDP packet. https://www.samba.org/samba/security/CVE-2026-3238.html . CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server Samba file servers and classic (non-AD) domain controllers with samba-dcerpcd started as a system service and with a "check password script" that has the %u substitution character are vulnerable to a remote code execution. https://www.samba.org/samba/security/CVE-2026-4408.html . CVE-2026-4480: Unauthenticated Remote Code Execution in Samba printing subsystem Samba print servers with a "print command" that has the %J substitution character are vulnerable to a Remote Code Execution. https://www.samba.org/samba/security/CVE-2026-4480.html samba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium . * https://bugzilla.samba.org/show_bug.cgi?id=16018 May-2026 samba security update fixing the following issues: CVE-2026-1933: Missing access check on reparse point operations https://bugzilla.samba.org/show_bug.cgi?id=15992 CVE-2026-2340: vfs_worm does not block directory modification https://bugzilla.samba.org/show_bug.cgi?id=15997 CVE-2026-3012: group policy certificate enrollment uses http:// without validation https://bugzilla.samba.org/show_bug.cgi?id=16003 CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server https://bugzilla.samba.org/show_bug.cgi?id=16012 CVE-2026-4480: Unauthenticated Remote Code Execution using print command https://bugzilla.samba.org/show_bug.cgi?id=16033 CVE-2026-4408: Remote Code Execution in SAMR when check password script contains %u substitution placeholder https://bugzilla.samba.org/show_bug.cgi?id=16034 shim (16.1-2~deb13u1) trixie; urgency=medium . * Backport new shim release to trixie + Needed so we have a new shim signed with both Microsoft UEFI Root CAs * Disable NX for the trixie build + We don't have a complete NX boot chain here. * Also switch to using the default version of gcc in trixie shim (16.1-2~deb12u1) bookworm; urgency=medium . [ Steve McIntyre ] * Backport new shim release to bookworm + Needed so we have a new shim signed with both Microsoft UEFI Root CAs * Disable NX for the bookworm build + We don't have a complete NX boot chain here. * Also switch to using the default version of gcc in bookworm shim (16.1-1) unstable; urgency=medium . * New upstream release: 16.1 * Switch to gcc-14 * Drop old patches, no longer needed + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Add new patch from upstream: + 0001-Fix-build-with-binutils-2.46.patch. Closes: #1125741 * Add lintian overrides: + Ignore included binaries for unit tests * Bump SBAT revocation level to 2024040900 aka "shim,4\ngrub,4\ngrub.peimage,2\n" * Enable NX for the sid/forky build + We should have a complete NX boot chain now... shim-helpers-amd64-signed (1+16.1+2~deb13u1) trixie; urgency=medium . * Update to shim 16.1-2~deb13u1 shim-helpers-amd64-signed (1+16.1+2~deb12u1) bookworm; urgency=medium . * Update to shim 16.1-2~deb12u1 shim-helpers-amd64-signed (1+16.1+1) unstable; urgency=medium . * Update to shim 16.1-1 shim-helpers-arm64-signed (1+16.1+2~deb13u1) trixie; urgency=medium . * Update to shim 16.1-2~deb13u1 shim-helpers-arm64-signed (1+16.1+2~deb12u1) bookworm; urgency=medium . * Update to shim 16.1-2~deb12u1 shim-helpers-arm64-signed (1+16.1+1) unstable; urgency=medium . * Update to shim 16.1-1 shim-signed (1.51~1+deb13u1) trixie; urgency=medium . * Signed versions of the 16.1-2~deb13u1 shim build for trixie * Update build-dep to use 16.1-2~deb13u1 shim-signed (1.51~1+deb12u1) bookworm; urgency=medium . * Signed versions of the 16.1-2~deb12u1 shim build for bookworm * Update build-dep to use 16.1-2~deb12u1 shim-signed (1.50) unstable; urgency=medium . * Fix up stupid omission in the previous package upload - the changes in 1.49 did not take into account the "SecureBoot enabled" case when adding a default error trap. Closes: #1137098, #1137101. shim-signed (1.49) unstable; urgency=medium . * Make mokutil parsing more robust. Closes: #1137063 + Cope with "Platform is in Setup Mode" message + If we get any other unexpected output, print what we got for debugging. shim-signed (1.48) unstable; urgency=medium . * Add support for verifying and then combining signatures from multiple signed shims. + Existing sbverify versions in Debian are buggy when verifying. + Switch to using a python script verify_combine_sigs to fill in the gaps. * In preinst, try to verify that the signed shim we're trying to install will actually boot on this system - let's not break systems on upgrade. * We now include a dual-signed shim including the 2023 CA. Closes: #1112197 * The shim included is now NX-capable. Closes: #1064102 skanpage (25.04.2-1+deb13u1) trixie; urgency=medium . * CVE-2025-55174 (Closes: #1121443) smartdns (46.1+dfsg-1.1~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie. . smartdns (46.1+dfsg-1.1) unstable; urgency=medium . * Non-maintainer upload. * CVE-2026-1425: Stack buffer overflow in DNS SVCB/HTTPS record parsing (Closes: #1126538) sogo (5.12.1-3+deb13u2) trixie-security; urgency=medium . * Non-maintainer upload. . [ Peter Wienemann ] * Add patch to fix CVE-2026-46445 and CVE-2026-46446: - CVE-2026-46445: SQL injection vulnerability when at least one user source is a PostgreSQL database - CVE-2026-46446: SQL injection vulnerability when at least one user source is an SQL database (MariaDB or PostgreSQL) and passwords are stored in plain text * Add patch to fix CVE-2025-71276: (Closes: #1131605) XSS with events, tasks and contacts categories * Add patch to fix CVE-2026-3054: (Closes: #1130878) XSS via manipulation of the argument hint * Add patch to fix CVE-2026-33550: (Closes: #1131606) TOTP vulnerabilities: - If a user disables/enables it, it is not renewed. - Length is too short (12 rather than recommended 20). * Add patch to fix CVE-2026-8496: A maliciously crafted ICS calendar invitation file allows arbitrary JavaScript execution within the authenticated SOGo webmail session. * Add patch to fix a regression introduced by fix for CVE-2026-8496 * Add patch to fix CVE-2026-8851: SQL injection vulnerability in the access control list management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. * Add patch to fix folder path in fix for CVE-2026-8851 * Add patch to fix openid validation: Verify that the returned email domain is authorized and that the user exists in the local source. * Add two patches to fix XSS in message subject rendering * Add three patches to fix message rendering . [ Jordi Mallach ] * Add upstream patch to fix impersonation issues when importing events. spip (4.4.15+dfsg-0+deb13u1) trixie-security; urgency=medium . [ David Prévot ] * Document CVE in previouss changelog entry . [ Matthieu Marcillaud ] * build: Ajout du polyfill PHP 8.5 * build: update dependencies * build: Version 4.4.15 + Fix remote code execution vulnerability in the private space [CVE-2026-8429] + Fix remote code execution vulnerability in the public space that is limited to certain nginx configurations [CVE-2026-8430] spip (4.4.14+dfsg-1) unstable; urgency=medium . [ David Prévot ] * Document CVE in previouss changelog entry * Update mutualisation to 2.0.1 * Update standards version to 4.7.4, no changes needed. . [ Matthieu Marcillaud ] * build: Ajout du polyfill PHP 8.5 * build: update dependencies * build: Version 4.4.14 spip (4.4.13+dfsg-1) unstable; urgency=medium . [ Matthieu Marcillaud ] * build: Version 4.4.13 squid (6.13-2+deb13u2) trixie-security; urgency=medium . * CVE-2026-33515 * CVE-2026-33526 * CVE-2026-47729 * CVE-2026-50012 squirrel3 (3.1-8.2+deb13u1) trixie; urgency=medium . * Non-maintainer upload. * CVE-2021-41556: Sandbox Escape (Closes: #1016212) sshfs-fuse (3.7.3-1.2~deb13u1) trixie; urgency=medium . * Non-maintainer upload. * Rebuild for trixie . sshfs-fuse (3.7.3-1.2) unstable; urgency=high . * Non-maintainer upload. * add contain_symlinks option to prevent symlink escape attacks (CVE-2026-47187) (Closes: #1138293) * reject hostname option injection via bracketed mount source (CVE-2026-48711) (Closes: #1138293) sshfs-fuse (3.7.3-1.2~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Rebuild for bookworm . sshfs-fuse (3.7.3-1.2) unstable; urgency=high . * Non-maintainer upload. * add contain_symlinks option to prevent symlink escape attacks (CVE-2026-47187) (Closes: #1138293) * reject hostname option injection via bracketed mount source (CVE-2026-48711) (Closes: #1138293) starlette (0.46.1-3+deb13u2) trixie-security; urgency=medium . * CVE-2026-48710 (Closes: #1137375) starman (0.4018-0+deb13u1) trixie; urgency=medium . [ gregor herrmann ] * Import upstream version 0.4018. - Fix HTTP request smuggling: Transfer-Encoding now takes precedence over Content-Length per RFC 7230 §3.3.3 (CVE-2026-40560) Closes: #1135229 strongswan (6.0.1-6+deb13u6) trixie-security; urgency=medium . * d/patches: add fix for double-free when cloning empty IDs (CVE-2026-47895) swift (2.35.1-0+deb13u2) trixie-security; urgency=medium . * CVE-2026-49017: Swift proxy-server denial of service via truncated s3api chunked upload. Applied upstream patch: "s3api: Error on truncated aws-chunked input" (Closes: #1138170). symfony (6.4.41+dfsg-0+deb13u1) trixie-security; urgency=medium . [ Fabien Potencier ] * Update VERSION for 6.4.41 . [ Nicolas Grekas ] * [HtmlSanitizer] Reject BiDi override characters and percent-encode spaces in URLs [CVE-2026-45064] * [MonologBridge] Bind server:log to localhost by default [CVE-2026-45077] * [Yaml] Bound recursion depth in the parser [CVE-2026-45133] * [TwigBridge] Fix XSS issue in CodeExtension::fileExcerpt() [CVE-2026-45072] * [Cache] Validate the prefix given to AbstractAdapter::clear() [CVE-2026-45073] * [Yaml] Bound collection-alias resolution in the parser [CVE-2026-45304] * [Yaml] Harden the Parser::cleanup() regexes against catastrophic backtracking [CVE-2026-45305] * [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING'] [CVE-2026-46626] * [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient [CVE-2026-48736] * [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS [CVE-2026-48736] * [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs [CVE-2026-48760] * [HtmlSanitizer] Sanitize URL attributes on , ,