Oracle Linux 6533 Published by

Oracle issued a new wave of updates for Oracle Linux 7, 8, 9, and 10, delivering critical security patches and bug fixes across a broad range of system components. Significant advisories include important security fixes for the Unbreakable Enterprise kernel, freerdp, java-17-openjdk, and python3.9, alongside moderate updates for python-idna, grafana, and libpng. The release also addresses stability issues through bug fix updates for makedumpfile, crash, kexec-tools, systemd, and perl-DBI across the supported operating system versions.

ELSA-2026-54486 Important: Oracle Linux 10 freerdp security update
ELSA-2026-54481 Moderate: Oracle Linux 10 python-idna security update
ELSA-2026-54178 Moderate: Oracle Linux 10 grafana security, bug fix, and enhancement update
ELSA-2026-36541 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-500170 Oracle Linux 10 makedumpfile bug fix update
ELBA-2026-500168 Oracle Linux 10 crash bug fix update
ELSA-2026-54268 Important: Oracle Linux 9 python3.9 security update
ELSA-2026-42887 Important: Oracle Linux 9 java-17-openjdk security update
ELBA-2026-500163 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500169 Oracle Linux 9 kexec-tools bug fix update
ELBA-2026-500167 Oracle Linux 9 crash bug fix update
ELBA-2026-500163 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500164 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELSA-2026-54290 Moderate: Oracle Linux 8 python-idna security update
ELSA-2026-54243 Important: Oracle Linux 8 grafana security update
ELSA-2026-53848 Important: Oracle Linux 8 isns-utils security update
ELSA-2026-52772 Important: Oracle Linux 8 perl-DBI:1.641 security update
ELSA-2026-52765 Moderate: Oracle Linux 8 kernel security update
ELBA-2026-500164 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500148 Oracle Linux 8 systemd bug fix update
ELBA-2026-500164 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
ELSA-2026-51183 Important: Oracle Linux 7 glib2 security update
ELSA-2026-51063 Important: Oracle Linux 7 libXfont2 security update
ELSA-2026-50808 Moderate: Oracle Linux 7 libpng security update
ELSA-2026-49603 Important: Oracle Linux 7 gstreamer1-plugins-good security update




ELSA-2026-54486 Important: Oracle Linux 10 freerdp security update


Oracle Linux Security Advisory ELSA-2026-54486

http://linux.oracle.com/errata/ELSA-2026-54486.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
freerdp-3.10.3-12.el10_2.8.x86_64.rpm
freerdp-devel-3.10.3-12.el10_2.8.x86_64.rpm
freerdp-libs-3.10.3-12.el10_2.8.x86_64.rpm
freerdp-server-3.10.3-12.el10_2.8.x86_64.rpm
libwinpr-3.10.3-12.el10_2.8.x86_64.rpm
libwinpr-devel-3.10.3-12.el10_2.8.x86_64.rpm

aarch64:
freerdp-3.10.3-12.el10_2.8.aarch64.rpm
freerdp-devel-3.10.3-12.el10_2.8.aarch64.rpm
freerdp-libs-3.10.3-12.el10_2.8.aarch64.rpm
freerdp-server-3.10.3-12.el10_2.8.aarch64.rpm
libwinpr-3.10.3-12.el10_2.8.aarch64.rpm
libwinpr-devel-3.10.3-12.el10_2.8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/freerdp-3.10.3-12.el10_2.8.src.rpm

Related CVEs:

CVE-2026-64620
CVE-2026-64621
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

Description of changes:

[2:3.10.3-12.8]
- Backport several CVE fixes (CVE-2026-64620, CVE-2026-64621, CVE-2026-64624,
CVE-2026-67289, CVE-2026-67299, CVE-2026-68580)
Resolves: RHEL-212621, RHEL-212978, RHEL-213168, RHEL-222783, RHEL-222983,
Resolves: RHEL-223604



ELSA-2026-54481 Moderate: Oracle Linux 10 python-idna security update


Oracle Linux Security Advisory ELSA-2026-54481

http://linux.oracle.com/errata/ELSA-2026-54481.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-idna-3.7-6.el10_2.noarch.rpm

aarch64:
python3-idna-3.7-6.el10_2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/python-idna-3.7-6.el10_2.src.rpm

Related CVEs:

CVE-2026-45409

Description of changes:

[3.7-6]
- Fix CVE-2026-45409: quadratic time complexity in IDNA validation

[3.7-5]
- rpminspect: Disable the unicode inspection



ELSA-2026-54178 Moderate: Oracle Linux 10 grafana security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54178

http://linux.oracle.com/errata/ELSA-2026-54178.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
grafana-10.2.6-28.el10_2.4.x86_64.rpm
grafana-selinux-10.2.6-28.el10_2.4.x86_64.rpm

aarch64:
grafana-10.2.6-28.el10_2.4.aarch64.rpm
grafana-selinux-10.2.6-28.el10_2.4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/grafana-10.2.6-28.el10_2.4.src.rpm

Related CVEs:

CVE-2026-8609
CVE-2026-33376
CVE-2026-33377
CVE-2026-33382

Description of changes:

[10.2.6-28.4]
- Resolves RHEL-211020: CVE-2026-33377

[10.2.6-28.3]
- Resolves RHEL-211376: CVE-2026-8609

[10.2.6-28.2]
- Resolves RHEL-210981: CVE-2026-33376

[10.2.6-28.1]
- Resolves RHEL-211389: CVE-2026-33382

[10.2.6-28]
- Resolves RHEL-188282: Remove Lua ExclusiveArch macro for Konflux build



ELSA-2026-36541 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-36541

http://linux.oracle.com/errata/ELSA-2026-36541.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.34.1.el10_2.x86_64.rpm
libperf-6.12.0-211.34.1.el10_2.x86_64.rpm
perf-6.12.0-211.34.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.34.1.el10_2.x86_64.rpm
rtla-6.12.0-211.34.1.el10_2.x86_64.rpm
rv-6.12.0-211.34.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.aarch64.rpm
libperf-6.12.0-211.34.1.el10_2.aarch64.rpm
perf-6.12.0-211.34.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.34.1.el10_2.aarch64.rpm
rtla-6.12.0-211.34.1.el10_2.aarch64.rpm
rv-6.12.0-211.34.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.34.1.el10_2.src.rpm

Related CVEs:

CVE-2026-43074
CVE-2026-43276
CVE-2026-43341
CVE-2026-46155
CVE-2026-46242
CVE-2026-46259

Description of changes:

[6.12.0-211.34.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 ioerr_work is cancelled in nvme_fc_delete_ctrl()" (Jaskaran Singh)
- tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke)
- MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong)
- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586}
- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598}
- fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li)
- rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu)
- rxrpc: Fix call removal to use RCU safe deletion (David Howells)
- rxrpc: Fix key quota calculation for multitoken keys (David Howells)
- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664}
- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075}
- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076}
- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak)
- Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower" (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak)
- powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini)
- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal)
- PCI/ACPI: Restrict program_hpx_type2() to AER bits (Håkon Bugge)
- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444}
- gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710}
- gfs2: Improve gfs2_consist_inode() usage (Andrew Price)
- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442}
- Revert "net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()" (Sasha Levin)
- Revert "net: ethernet: xscale: Check for PTP support properly" (Sasha Levin)
- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)
- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)
- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)
- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)
- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578}
- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580}
- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581}
- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583}
- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)
- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)
- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588}
- checkpatch: add support for Assisted-by tag (Sasha Levin)
- rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou)
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399}
- smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara)
- fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski)
- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590}
- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596}
- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597}
- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)
- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602}
- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)
- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)
- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brát)
- usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607}
- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman)
- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman)
- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617}
- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619}
- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman)
- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623}
- HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624}
- HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625}
- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626}
- i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman)
- can: raw: fix ro->uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532}
- nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian)
- ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako)
- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki)
- MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki)
- MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki)
- mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler)
- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407}
- i3c: fix uninitialized variable use in i2c setup (Jamie Iles)
- perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079}
- gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda)
- l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080}
- af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673}
- netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685}
- netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681}
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085}
- xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089}
- xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093}
- e1000: check return value of e1000_read_eeprom (Agalakov Daniil)
- tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou)
- nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou)
- ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099}
- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet)
- net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074}
- epoll: use refcount to reduce ep_mutex contention (Paolo Abeni)
- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maíra Canal)
- drm/vc4: Fix a memory leak in hang state error path (Maíra Canal) [Orabug: 39331212] {CVE-2026-43104}
- drm/vc4: Fix memory leak of BO array in hang state (Maíra Canal) [Orabug: 39331216] {CVE-2026-43105}
- PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li)
- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak)
- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai)
- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta)
- wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110}
- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband)
- HID: roccat: fix use-after-free in roccat_report_event (Benoît Sevens) [Orabug: 39331244] {CVE-2026-43111}
- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska)
- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko)
- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover)
- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby)
- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto)
- wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114}
- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (César Montoya)
- btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117}
- can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li)
- ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann)
- LTS version: v5.15.208 (Samasth Norway Ananda)
- LTS version: v5.15.207 (Samasth Norway Ananda)
- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174}
- x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov)
- LTS version: v5.15.206 (Samasth Norway Ananda)
- LTS version: v5.15.205 (Samasth Norway Ananda)
- LTS version: v5.15.204 (Samasth Norway Ananda)
- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787}
- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}

[5.15.0-323.203.2]
- net/mlx5: Add vhca_id_type support to IPsec alias creation (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5: Add vhca_id_type bit to alias context (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman) [Orabug: 38290328]
- net/mlx5e: Fix race condition during IPSec ESN update (Jianbo Liu) [Orabug: 38290328,39167462] {CVE-2026-23440}
- net/mlx5e: Prevent concurrent access to IPSec ASO context (Jianbo Liu) [Orabug: 38290328,39167465] {CVE-2026-23441}
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567286,39668793] {CVE-2026-46331}
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39673870,39753976] {CVE-2026-63807}
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673870,39686460] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39460221,39673870] {CVE-2026-46113}
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Derive shadow MMU page role from parent (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673870]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673870]
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39425999,39751167] {CVE-2026-43499,CVE-2026-53163}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425999,39706512] {CVE-2026-43499}
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659419]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619388,39639981,39648952] {CVE-2026-52943}
- fs/binfmt_elf: validate reserved VA ELF notes (Jianfeng Wang) [Orabug: 39681043]
- mm: preserve page-table boundaries for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- mm: enforce max_map_count for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- fs/kernfs: raise sb->maxbytes to MAX_LFS_FILESIZE (Jane Chu) [Orabug: 39209740]
- uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Dave Kleikamp) [Orabug: 39661609]
- uek-rpm: cnic: Trim the SNIC config for a faster boot (Dave Kleikamp) [Orabug: 39661609]
- net/rds: expand kref coverage to rds_notifier->n_conn (Sharath Srinivasan) [Orabug: 38945572]
- net/rds: fix crash by expanding kref coverage to rds_incoming.i_conn (Sharath Srinivasan) [Orabug: 38945572]
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 39480769]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452260] {CVE-2026-46043}

[5.15.0-323.203.1]
- net/rds: Wait for rdma_cm_event background work to finish (Gerd Rausch) [Orabug: 38112000]
- locking/mutex: Make contention tracepoints more consistent wrt adaptive spinning (Peter Zijlstra) [Orabug: 39598217]
- locking: Apply contention tracepoints in the slow path (Namhyung Kim) [Orabug: 39598217]
- locking: Add lock contention tracepoints (Namhyung Kim) [Orabug: 39598217]
- net/mlx5: Fix EQ IRQ affinity notifier debug messages (Praveen Kumar Kannoju) [Orabug: 39594875]
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39460234] {CVE-2026-46116}
- Revert "rds: ib: Add cm_id generation scheme in order to detect new ones" (Sharath Srinivasan) [Orabug: 39226005]

[5.15.0-322.203.3]
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548689,39674327] {CVE-2025-10263,CVE-2026-53354}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548689] {CVE-2025-10263}
- ARM: uek: Disable CONFIG_NVIDIA_CARMEL_CNP_ERRATUM (Boris Ostrovsky) [Orabug: 39548689] {CVE-2025-10263}
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548689] {CVE-2025-10263}
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548689] {CVE-2025-10263}
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548689] {CVE-2025-10263}
- net/rds: Make "rds_send_xmit" fairer (Gerd Rausch) [Orabug: 39532945]
- net/rds: Schedule rds_send_worker if there's more work to do (Gerd Rausch) [Orabug: 39532945]
- Revert "rds: Change return code from rds_send_xmit() when lock is taken" (Gerd Rausch) [Orabug: 39532945]
- Revert "Reapply "rds: ib: Make sure receives are posted before connection is up"" (Gerd Rausch) [Orabug: 39532945]
- Revert "rds: ib: Make sure a QP in INIT state is transitioned to ERR" (Gerd Rausch) [Orabug: 39532945]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526881] {CVE-2022-50073}
- mmc: dwcmshc_bf3_hw_reset: Log eMMC reset calls (Satyansh Shukla) [Orabug: 39333650]
- arm64: dts: pensando: drop elba penfw firmware node (Tom Saeger) [Orabug: 39522954]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262374,39543197] {CVE-2026-31657}
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39179363]

[5.15.0-322.203.2]
- LTS version: v5.15.203 (Vijayendra Suman)
- io_uring/poll: correctly handle io_poll_add() return value on update (Jens Axboe)
- ksmbd: Fix dangling pointer in krb_authenticate (Sean Heelan)
- ksmbd: Fix refcount leak when invalid session is found on session lookup (Namjae Jeon)
- Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ (Luiz Augusto von Dentz) [Orabug: 39131105] {CVE-2026-23395}
- i2c: cp2615: fix serial string NULL-deref at probe (Johan Hovold)
- i2c: cp2615: replace deprecated strncpy with strscpy (Justin Stitt)
- ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() (Namjae Jeon)
- ksmbd: fix potencial OOB in get_file_all_info() for compound requests (Namjae Jeon)
- tracing: Fix potential deadlock in cpu hotplug with osnoise (Luo Haiyang) [Orabug: 39250863] {CVE-2026-31480}
- x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling() (Nikunj A Dadhania)
- mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (Tu Jinjiang) [Orabug: 39250813] {CVE-2026-31466}
- scsi: target: tcm_loop: Drain commands in target_reset handler (Josef Bacik) [Orabug: 39300990] {CVE-2026-43054}
- net: macb: Move devm_{free,request}_irq() out of spin lock area (Kevin Hao)
- dmaengine: sh: rz-dmac: Protect the driver specific lists (Claudiu Beznea)
- dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock (Claudiu Beznea)
- xfs: save ailp before dropping the AIL lock in push callbacks (Yuto Ohnuki) [Orabug: 39250775] {CVE-2026-31454}
- ext4: fix use-after-free in update_super_work when racing with umount (Jiayuan Chen) [Orabug: 39250727] {CVE-2026-31446}
- ext4: fix the might_sleep() warnings in kvfree() (Zqiang)
- ext4: publish jinode after initialization (Li Chen) [Orabug: 39250749] {CVE-2026-31450}
- usb: gadget: uvc: fix NULL pointer dereference during unbind race (Jimmy Hu)
- usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop (Kuen-Han Tsai) [Orabug: 39300667] {CVE-2026-31728}
- usb: gadget: f_hid: move list and spinlock inits from bind to alloc (Michael Zimmermann) [Orabug: 39300642] {CVE-2026-31721}
- net: rfkill: prevent unlimited numbers of rfkill events from being created (Greg Kroah-Hartman) [Orabug: 39262425] {CVE-2026-31670}
- seg6: separate dst_cache for input and output paths in seg6 lwtunnel (Andrea Mayer) [Orabug: 39262417] {CVE-2026-31668}
- Revert "mptcp: add needs_id for netlink appending addr" (Matthieu Baerts)
- xen/privcmd: unregister xenstore notifier on module exit (Guohan Zhao)
- netlink: add nla be16/32 types to minlen array (Florian Westphal) [Orabug: 39654776] {CVE-2024-26849}
- rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING) (David Howells)
- rxrpc: fix reference count leak in rxrpc_server_keyring() (Luxiao Xu)
- net: stmmac: fix integer underflow in chain mode (Tyllis Xu) [Orabug: 39262353] {CVE-2026-31649}
- net: qualcomm: qca_uart: report the consumed byte on RX skb allocation failure (Pengpeng Hou)
- mmc: vub300: fix NULL-deref on disconnect (Johan Hovold) [Orabug: 39262359] {CVE-2026-31651}
- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (Sebastian Brzezinka) [Orabug: 39262371] {CVE-2026-31656}
- net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (David Carlier) [Orabug: 39262378] {CVE-2026-31658}
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (M A Ramdhan) [Orabug: 39257891,39543209] {CVE-2026-31533}
- batman-adv: reject oversized global TT response buffers (Ruide Cao) [Orabug: 39262382] {CVE-2026-31659}
- nfc: pn533: allocate rx skb before consuming bytes (Pengpeng Hou)
- arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges (Shawn Guo)
- arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity (Shawn Guo)
- wifi: brcmsmac: Fix dma_free_coherent() size (Thomas Fourier) [Orabug: 39262390] {CVE-2026-31661}
- tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (Oleh Konko) [Orabug: 39262394] {CVE-2026-31662}
- netfilter: nft_ct: fix use-after-free in timeout object destroy (Tuan Do) [Orabug: 39262407] {CVE-2026-31665}
- apparmor: fix race between freeing data and fs accessing it (John Johansen)
- apparmor: fix race on rawdata dereference (John Johansen)
- apparmor: fix differential encoding verification (John Johansen)
- apparmor: fix unprivileged local user can do privileged policy management (John Johansen)
- apparmor: Fix double free of ns_name in aa_replace_profiles() (John Johansen)
- apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (Massimiliano Pellizzer)
- apparmor: fix side-effect bug in match_char() macro usage (Massimiliano Pellizzer)
- apparmor: fix: limit the number of levels of policy namespaces (John Johansen)
- apparmor: replace recursive profile removal with iterative approach (Massimiliano Pellizzer)
- apparmor: fix memory leak in verify_header (Massimiliano Pellizzer)
- apparmor: validate DFA start states are in bounds in unpack_pdb (Massimiliano Pellizzer)
- iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer (Nuno Sa)
- gpiolib: cdev: fix uninitialised kfifo (Kent Gibson) [Orabug: 36683267] {CVE-2024-36898}
- media: uvcvideo: Use heuristic to find stream entity (Ricardo Ribalda)
- media: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID (Thadeu Lima de Souza Cascardo) [Orabug: 38560508] {CVE-2025-40016}
- Input: uinput - take event lock when submitting FF request "event" (Dmitry Torokhov)
- Input: uinput - fix circular locking dependency with ff-core (Mikhail Gavrilov) [Orabug: 39262413] {CVE-2026-31667}
- mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen) [Orabug: 39262422] {CVE-2026-31669}
- xfrm_user: fix info leak in build_report() (Greg Kroah-Hartman) [Orabug: 39262429] {CVE-2026-31671}
- wifi: rt2x00usb: fix devres lifetime (Johan Hovold) [Orabug: 39262433] {CVE-2026-31672}
- lib/crypto: chacha: Zeroize permuted_state before it leaves scope (Eric Biggers) [Orabug: 39343667] {CVE-2026-43336}
- wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free (Alexander Popov)
- io_uring/tctx: work around xa_store() allocation error issue (Jens Axboe)
- usb: gadget: f_uac1_legacy: validate control request size (Taegu Ha)
- usb: gadget: f_rndis: Protect RNDIS options with mutex (Kuen-Han Tsai)
- usb: gadget: f_subset: Fix unbalanced refcnt in geth_free (Kuen-Han Tsai) [Orabug: 39343693] {CVE-2026-43343}
- staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser (Navaneeth K) [Orabug: 38773561] {CVE-2025-68256}
- smb: client: Fix refcount leak for cifs_sb_tlink (Shuhao Fu)
- net: mctp: Don't access ifa_index when missing (Matt Johnston)
- fbcon: Set fb_display[i]->mode to NULL when the mode is released (Quanmin Yan) [Orabug: 38737307] {CVE-2025-40323}
- can: gs_usb: gs_usb_receive_bulk_callback(): fix error message (Marc Kleine-Budde) [Orabug: 39654809] {CVE-2026-23155}
- can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error (Marc Kleine-Budde) [Orabug: 39654800] {CVE-2026-23082}
- can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak (Marc Kleine-Budde) [Orabug: 38914786] {CVE-2026-23031}
- usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer (Sebastian Urban)
- USB: dummy-hcd: Fix interrupt synchronization error (Alan Stern)
- USB: dummy-hcd: Fix locking/synchronization error (Alan Stern)
- thunderbolt: Fix property read in nhi_wake_supported() (Konrad Dybcio)
- net: ftgmac100: fix ring allocation unwind on open failure (Yufan Chen)
- vxlan: validate ND option lengths in vxlan_na_create (Ao Zhou) [Orabug: 39300690] {CVE-2026-31738}
- netfilter: ipset: drop logically empty buckets in mtype_del (Yifan Wu) [Orabug: 39205985] {CVE-2026-31418}
- comedi: me4000: Fix potential overrun of firmware buffer (Ian Abbott)
- comedi: me_daq: Fix potential overrun of firmware buffer (Ian Abbott)
- comedi: ni_atmio16d: Fix invalid clean-up after failed attach (Ian Abbott)
- comedi: Reinit dev->spinlock between attachments to low-level drivers (Ian Abbott)
- comedi: dt2815: add hardware detection to prevent crash (Deepanshu Kartikey)
- cdc-acm: new quirk for EPSON HMD (Oliver Neukum)
- bridge: br_nd_send: validate ND option lengths (Ao Zhou) [Orabug: 39300724] {CVE-2026-31752}
- phy: renesas: rcar-gen3-usb2: Assert PLL reset on PHY power off (Claudiu Beznea)
- phy: renesas: rcar-gen3-usb2: Lock around hardware registers and driver data (Claudiu Beznea)
- phy: renesas: rcar-gen3-usb2: Move IRQ request in probe (Claudiu Beznea)
- phy: renesas: rcar-gen3-usb2: Fix role detection on unbind/bind (Claudiu Beznea)
- usb: cdns3: gadget: fix state inconsistency on gadget init failure (Yongchao Wu)
- usb: cdns3: gadget: fix NULL pointer dereference in ep_queue (Yongchao Wu)
- usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() (Juneho Choi) [Orabug: 39300737] {CVE-2026-31756}
- usb: ehci-brcm: fix sleep during atomic (Justin Chen)
- usb: usbtmc: Flush anchored URBs in usbtmc_release (Heitor Alves de Siqueira) [Orabug: 39300742] {CVE-2026-31758}
- usb: ulpi: fix double free in ulpi_register_interface() error path (Guangshuo Li) [Orabug: 39300746] {CVE-2026-31759}
- usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive (Miao Li)
- iio: gyro: mpu3050: Fix out-of-sequence free_irq() (Ethan Tidmore)
- iio: gyro: mpu3050: Move iio_device_register() to correct location (Ethan Tidmore) [Orabug: 39300751] {CVE-2026-31761}
- iio: gyro: mpu3050: Fix irq resource leak (Ethan Tidmore) [Orabug: 39300756] {CVE-2026-31762}
- iio: gyro: mpu3050: Fix incorrect free_irq() variable (Ethan Tidmore) [Orabug: 39300761] {CVE-2026-31763}
- iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only (Francesco Lavra)
- iio: light: vcnl4035: fix scan buffer on big-endian (David Lechner)
- iio: dac: ad5770r: fix error return in ad5770r_read_raw() (Antoniu Miclaus)
- Input: xpad - add support for Razer Wolverine V3 Pro (Zoltan Illes)
- Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table (Christoffer Sandberg)
- Input: synaptics-rmi4 - fix a locking bug in an error path (Bart Van Assche)
- USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam (Jp Hein)
- USB: serial: option: add support for Rolling Wireless RW135R-GL (Wanquan Zhong)
- USB: serial: io_edgeport: add support for Blackbox IC135A (Frej Drejhammar)
- drm/ast: dp501: Fix initialization of SCU2C (Thomas Zimmermann)
- hwmon: (occ) Fix division by zero in occ_show_power_1() (Sanman Pradhan)
- MIPS: Fix the GCC version check for __multi3' workaround (Maciej W. Rozycki)
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (Oleh Konko) [Orabug: 39343662] {CVE-2026-43334}
- Bluetooth: SMP: derive legacy responder STK authentication from MITM state (Oleh Konko) [Orabug: 39300793] {CVE-2026-31773}
- ALSA: ctxfi: Fix missing SPDIFI1 index handling (Takashi Iwai) [Orabug: 39300800] {CVE-2026-31776}
- ALSA: caiaq: fix stack out-of-bounds read in init_card (Berk Cem Goksel) [Orabug: 39300808] {CVE-2026-31778}
- USB: serial: option: add MeiG Smart SRM825WN (Ernestas Kulik)
- wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation (Yasuaki Torimaru)
- drm/ioc32: stop speculation on the drm_compat_ioctl path (Greg Kroah-Hartman) [Orabug: 39300820] {CVE-2026-31781}
- riscv: kgdb: fix several debug register assignment bugs (Paul Walmsley)
- hwmon: (occ) Fix missing newline in occ_show_extended() (Sanman Pradhan)
- hwmon: (tps53679) Fix device ID comparison and printing in tps53676_identify() (Sanman Pradhan)
- hwmon: (pxe1610) Check return value of page-select write in probe (Sanman Pradhan)
- bpf: reject direct access to nullable PTR_TO_BUF pointers (Qi Tang) [Orabug: 39343659] {CVE-2026-43333}
- ipv6: avoid overflows in ip6_datagram_send_ctl() (Eric Dumazet) [Orabug: 39205971] {CVE-2026-31415}
- net/sched: cls_flow: fix NULL pointer dereference on shared blocks (Xiang Mei) [Orabug: 39206003] {CVE-2026-31422}
- net/sched: cls_fw: fix NULL pointer dereference on shared blocks (Xiang Mei) [Orabug: 39205999] {CVE-2026-31421}
- net/x25: Fix overflow when accumulating packets (Martin Schiller)
- net/x25: Fix potential double free of skb (Martin Schiller)
- net/mlx5: Avoid "No data available" when FW version queries fail (Saeed Mahameed)
- net: macb: properly unregister fixed rate clocks (Fedor Pchelkin) [Orabug: 39300849] {CVE-2026-43014}
- net: macb: fix clk handling on PCI glue driver removal (Fedor Pchelkin) [Orabug: 39300853] {CVE-2026-43015}
- Bluetooth: MGMT: validate LTK enc_size on load (Keenan Dong) [Orabug: 39300866] {CVE-2026-43020}
- netfilter: nf_tables: reject immediate NF_QUEUE verdict (Pablo Neira Ayuso) [Orabug: 39300881] {CVE-2026-43024}
- netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (Pablo Neira Ayuso) [Orabug: 39206017] {CVE-2026-31424}
- netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (Qi Tang) [Orabug: 39300889] {CVE-2026-43026}
- netfilter: nf_conntrack_helper: pass helper to expect cleanup (Qi Tang) [Orabug: 39300893] {CVE-2026-43027}
- netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr (Florian Westphal)
- netfilter: x_tables: ensure names are nul-terminated (Florian Westphal) [Orabug: 39300897] {CVE-2026-43028}
- netfilter: nfnetlink_log: account for netlink header size (Florian Westphal) [Orabug: 39205976] {CVE-2026-31416}
- netfilter: flowtable: strictly check for maximum number of actions (Pablo Neira Ayuso) [Orabug: 39343649] {CVE-2026-43329}
- net: ipv6: flowlabel: defer exclusive option free until RCU teardown (Zhengchuan Liang) [Orabug: 39263384] {CVE-2026-31680}
- bpf: Fix regsafe() for pointers to packet (Alexei Starovoitov) [Orabug: 39300903] {CVE-2026-43030}
- net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec (Suraj Gupta)
- NFC: pn533: bound the UART receive buffer (Pengpeng Hou)
- net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (Yochai Eisenrich) [Orabug: 39300917] {CVE-2026-43035}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Paolo Abeni) [Orabug: 39343677] {CVE-2026-43339}
- net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (Xiang Mei) [Orabug: 39206011] {CVE-2026-31423}
- bridge: br_nd_send: linearize skb before parsing ND options (Ao Zhou) [Orabug: 39263393] {CVE-2026-31682}
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300925] {CVE-2026-43037}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300929] {CVE-2026-43038}
- tg3: Fix race for querying speed/duplex (Thomas Bogendoerfer)
- net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (Yochai Eisenrich) [Orabug: 39300934] {CVE-2026-43040}
- net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak (Jiayuan Chen) [Orabug: 39300938] {CVE-2026-43041}
- crypto: af-alg - fix NULL pointer dereference in scatterwalk (Norbert Szetei) [Orabug: 39300946] {CVE-2026-43043}
- dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix common property warning (Frank Li)
- btrfs: reject root items with drop_progress and zero drop_level (Zhengyuan Huang) [Orabug: 39300958] {CVE-2026-43046}
- HID: multitouch: Check to ensure report responses match the request (Lee Jones) [Orabug: 39300962] {CVE-2026-43047}
- objtool: Fix Clang jump table detection (Josh Poimboeuf)
- btrfs: don't take device_list_mutex when querying zone info (Johannes Thumshirn)
- atm: lec: fix use-after-free in sock_def_readable() (Deepanshu Kartikey) [Orabug: 39300974] {CVE-2026-43050}
- HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (Benoît Sevens) [Orabug: 39300978] {CVE-2026-43051}
- futex: Clear stale exiting pointer in futex_lock_pi() retry path (Davidlohr Bueso) [Orabug: 39262274] {CVE-2026-31555}
- dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA (Tomi Valkeinen)
- dmaengine: xilinx_dma: Program interrupt delay timeout (Radhey Shyam Pandey)
- dmaengine: idxd: Fix freeing the allocated ida too late (Vinicius Costa Gomes)
- btrfs: fix lost error when running device stats on multiple devices fs (Filipe Manana)
- btrfs: fix super block offset in error message in btrfs_validate_super() (Mark Harmstone)
- dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction (Marek Vasut)
- dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA (Marek Vasut)
- dmaengine: xilinx: xilinx_dma: Fix dma_device directions (Marek Vasut)
- phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types() (Felix Gu)
- ext4: always drain queued discard work in ext4_mb_release() (Theodore Ts'O) [Orabug: 39323071] {CVE-2026-43065}
- ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (Baokun Li) [Orabug: 39323078] {CVE-2026-43066}
- ext4: reject mount if bigalloc with s_first_data_block != 0 (Helen Koike) [Orabug: 39250730] {CVE-2026-31447}
- ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (Ye Bin) [Orabug: 39323091] {CVE-2026-43068}
- ext4: make recently_deleted() properly work with lazy itable initialization (Jan Kara)
- ext4: convert inline data to extents when truncate exceeds inline size (Deepanshu Kartikey) [Orabug: 39250762] {CVE-2026-31452}
- xfs: stop reclaim before pushing AIL during unmount (Yuto Ohnuki) [Orabug: 39250778] {CVE-2026-31455}
- jbd2: gracefully abort on checkpointing state corruptions (Milos Nikic)
- scsi: ses: Handle positive SCSI error from ses_recv_diag() (Greg Kroah-Hartman)
- scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (Tyllis Xu)
- alarmtimer: Fix argument order in alarm_timer_forward() (Zhan Xusheng)
- erofs: add GFP_NOIO in the bio completion if needed (Jiucheng Xu)
- virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (Xietangxin) [Orabug: 39250825] {CVE-2026-31469}
- media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (Yuchan Nam) [Orabug: 39250837] {CVE-2026-31473}
- cpufreq: conservative: Reset requested_freq on limits change (Viresh Kumar)
- can: gw: fix OOB heap access in cgw_csum_crc8_rel() (Ali Norouzi) [Orabug: 39262307] {CVE-2026-31570}
- s390/barrier: Make array_index_mask_nospec() __always_inline (Vasily Gorbik)
- s390/syscalls: Add spectre boundary for syscall dispatch table (Greg Kroah-Hartman)
- spi: spi-fsl-lpspi: fix teardown order issue (UAF) (Marc Kleine-Budde)
- ASoC: adau1372: Fix clock leak on PLL lock failure (Jihed Chaibi)
- ASoC: adau1372: Fix unchecked clk_prepare_enable() return value (Jihed Chaibi)
- sysctl: fix uninitialized variable in proc_do_large_bitmap (Marc Buerg)
- hwmon: (adm1177) fix sysfs ABI violation and current unit conversion (Sanman Pradhan)
- ACPI: EC: Fix ECDT probe ordering issues (Hans de Goede)
- ACPI: EC: Fix EC address space handler unregistration (Hans de Goede)
- ACPICA: Allow address_space_handler Install and _REG execution as 2 separate steps (Hans de Goede)
- ACPICA: include/acpi/acpixf.h: Fix indentation (Hans de Goede)
- ASoC: Intel: catpt: Fix the device initialization (Cezary Rojewski)
- drm/i915/gmbus: fix spurious timeout on 512-byte burst reads (Samasth Norway Ananda)
- x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size (Mike Rapoport)
- scsi: scsi_transport_sas: Fix the maximum channel scanning issue (Yihang Li)
- RDMA/irdma: Return EINVAL for invalid arp index error (Tatyana Nikolova)
- RDMA/irdma: Fix deadlock during netdev reset with active connections (Anil Samal) [Orabug: 39262297] {CVE-2026-31565}
- RDMA/irdma: Remove reset check from irdma_modify_qp_to_err() (Tatyana Nikolova)
- RDMA/irdma: Clean up unnecessary dereference of event->cm_node (Ivan Barrera)
- RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce() (Tatyana Nikolova)
- RDMA/irdma: Update ibqp state to error if QP is already in error state (Tatyana Nikolova)
- RDMA/rw: Fall back to direct SGE on MR pool exhaustion (Chuck Lever)
- regmap: Synchronize cache for the page selector (Andy Shevchenko)
- net: macb: use the current queue number for stats (Paolo Valerio) [Orabug: 39250906] {CVE-2026-31494}
- netfilter: ctnetlink: use netlink policy range checks (David Carlier) [Orabug: 39250912] {CVE-2026-31495}
- netlink: allow be16 and be32 types in all uint policy checks (Florian Westphal)
- netlink: introduce bigendian integer types (Florian Westphal)
- netfilter: nft_payload: reject out-of-range attributes via policy (Florian Westphal)
- netlink: introduce NLA_POLICY_MAX_BE (Florian Westphal)
- netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (Weiming Shi) [Orabug: 39206030] {CVE-2026-31427}
- netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (Ao Zhou) [Orabug: 39263360] {CVE-2026-31674}
- netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (Weiming Shi) [Orabug: 39206034] {CVE-2026-31428}
- Bluetooth: btusb: clamp SCO altsetting table indices (Pengpeng Hou) [Orabug: 39250922] {CVE-2026-31497}
- Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (Hyunwoo Kim) [Orabug: 39250926] {CVE-2026-31498}
- dma-mapping: add missing inline for dma_free_attrs (Miguel Ojeda)
- net: enetc: fix the output issue of 'ethtool --show-ring' (Wei Fang)
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250952,39543208] {CVE-2026-31504}
- platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen (Alok Tiwari)
- rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size (Sabrina Dubroca)
- net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (Qi Tang)
- openvswitch: validate MPLS set/set_masked payload length (Ao Zhou) [Orabug: 39263381] {CVE-2026-31679}
- nfc: nci: fix circular locking dependency in nci_close_device (Jakub Kicinski)
- ionic: fix persistent MAC address override on PF (Mohammad Heib)
- pinctrl: mediatek: common: Fix probe failure for devices without EINT (Luca Leonardo Scorcia)
- Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb (Helen Koike) [Orabug: 39250973] {CVE-2026-31510}
- Bluetooth: hci_ll: Fix firmware leak on error path (Anas Iqbal) [Orabug: 39323114] {CVE-2026-43069}
- Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (Hyunwoo Kim) [Orabug: 39171454] {CVE-2026-31408}
- Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (Hyunwoo Kim) [Orabug: 39250982] {CVE-2026-31512}
- can: statistics: add missing atomic access in hot path (Oliver Hartkopp)
- af_key: validate families in pfkey_send_migrate() (Eric Dumazet) [Orabug: 39250997] {CVE-2026-31515}
- esp: fix skb leak with espintcp and async crypto (Sabrina Dubroca) [Orabug: 39251009] {CVE-2026-31518}
- xfrm: Fix the usage of skb->sk (Steffen Klassert)
- xfrm: call xdo_dev_state_delete during state update (Sabrina Dubroca)
- ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390 (Uzair Mughal)
- dma-buf: Include ioctl.h in UAPI header (Isaac J. Manjarres)
- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits() (Mark Brown)
- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg() (Mark Brown)
- module: Fix kernel panic when a symbol st_shndx is out of bounds (Ihor Solodrai) [Orabug: 39251026] {CVE-2026-31521}
- HID: mcp2221: cancel last I2C command on read error (Romain Sioen)
- net: usb: r8152: add TRENDnet TUC-ET2G (Valentin Spreckels)
- HID: magicmouse: avoid memory leak in magicmouse_report_fixup() (Günther Noack) [Orabug: 39251033] {CVE-2026-31522}
- HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2 (Julius Lehmann)
- nvme-pci: ensure we're polling a polled queue (Keith Busch) [Orabug: 39251039] {CVE-2026-31523}
- platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10 (Hans de Goede)
- platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1 (Leif Skunberg)
- nvme-pci: cap queue creation to used queues (Keith Busch)
- platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list (Peter Metz)
- HID: asus: avoid memory leak in asus_report_fixup() (Günther Noack) [Orabug: 39251045] {CVE-2026-31524}
- bpf: Release module BTF IDR before module unload (Kumar Kartikeya Dwivedi)
- sh: platform_early: remove pdev->driver_override check (Danilo Krummrich)
- xen/privcmd: add boot control for restricted usage in domU (Juergen Gross)
- xen/privcmd: restrict usage in unprivileged domU (Juergen Gross) [Orabug: 39142872] {CVE-2026-31788}
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal) [Orabug: 39130949] {CVE-2026-23351}
- netfilter: nf_tables: de-constify set commit ops function argument (Florian Westphal)
- tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure (Josh Law)
- lib/bootconfig: check xbc_init_node() return in override path (Josh Law)
- drm/i915/gt: Check set_default_submission() before deferencing (Rahul Bukte) [Orabug: 39262235] {CVE-2026-31540}
- ksmbd: fix use-after-free of share_conf in compound request (Hyunwoo Kim)
- mtd: rawnand: brcmnand: skip DMA during panic write (Kamal Dasu)
- mtd: rawnand: serialize lock/unlock against other NAND operations (Kamal Dasu) [Orabug: 39167446] {CVE-2026-23434}
- i2c: fsi: Fix a potential leak in fsi_i2c_probe() (Christophe Jaillet)
- hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit() (Sanman Pradhan)
- icmp: fix NULL pointer dereference in icmp_tag_validation() (Weiming Shi) [Orabug: 39136287] {CVE-2026-23398}
- net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths (Anas Iqbal)
- net: mvpp2: guard flow control update with global_tx_fc in buffer switching (Muhammad Hammad Ijaz) [Orabug: 39167455] {CVE-2026-23438}
- nfnetlink_osf: validate individual option lengths in fingerprints (Weiming Shi) [Orabug: 39136283] {CVE-2026-23397}
- net: bonding: fix NULL deref in bond_debug_rlb_hash_show (Xiang Mei) [Orabug: 39262250] {CVE-2026-31546}
- udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n (Xiang Mei) [Orabug: 39167458] {CVE-2026-23439}
- net: macb: fix uninitialized rx_fs_lock (Fedor Pchelkin)
- wifi: mac80211: fix NULL deref in mesh_matches_local() (Xiang Mei) [Orabug: 39136279] {CVE-2026-23396}
- igc: fix missing update of skb->tail in igc_xmit_frame() (Kohei Enju)
- net: usb: aqc111: Do not perform PM inside suspend callback (Nikola Z. Ivanov)
- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() (Jiayuan Chen)
- net/smc: Fix slab-out-of-bounds issue in fallback (Wen Gu)
- net/smc: Only save the original clcsock callback functions (Wen Gu)
- PM: runtime: Fix a race condition related to device removal (Bart Van Assche) [Orabug: 39167501] {CVE-2026-23452}
- sched: idle: Consolidate the handling of two special cases (Rafael J. Wysocki)
- net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (Dipayaan Roy) [Orabug: 39167506] {CVE-2026-23454}
- net: bcmgenet: increase WoL poll timeout (Justin Chen)
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (Jenny Guanni Qu) [Orabug: 39167510] {CVE-2026-23455}
- netfilter: xt_time: use unsigned int for monthday bit shift (Jenny Guanni Qu)
- netfilter: xt_CT: drop pending enqueued packets on template removal (Pablo Neira Ayuso) [Orabug: 39131089] {CVE-2026-23391}
- netfilter: nft_ct: drop pending enqueued packets on removal (Pablo Neira Ayuso) [Orabug: 39322993] {CVE-2026-43060}
- netfilter: nft_ct: add seqadj extension for natted connections (Andrii Melnychenko) [Orabug: 38773356] {CVE-2025-68206}
- netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (Jenny Guanni Qu) [Orabug: 39167514] {CVE-2026-23456}
- netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (Lukas Johannes Möller) [Orabug: 39167518] {CVE-2026-23457}
- netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (Hyunwoo Kim) [Orabug: 39167522] {CVE-2026-23458}
- netfilter: ctnetlink: remove refcounting in expectation dumpers (Florian Westphal) [Orabug: 38423446] {CVE-2025-39764}
- net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect (Jiayuan Chen)
- Bluetooth: qca: fix ROM version reading on WCN3998 chips (Dmitry Baryshkov)
- Bluetooth: HIDP: Fix possible UAF (Luiz Augusto von Dentz) [Orabug: 39167534] {CVE-2026-23462}
- Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (Christian Eggers)
- Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU (Christian Eggers)
- Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU (Christian Eggers)
- firmware: arm_scpi: Fix device_node reference leak in probe path (Felix Gu)
- of: Add cleanup.h based auto release via __free(device_node) markings (Jonathan Cameron)
- wifi: mac80211: Fix static_branch_dec() underflow for aql_disable. (Kuniyuki Iwashima) [Orabug: 39262267] {CVE-2026-31551}
- soc: fsl: qbman: fix race condition in qman_destroy_fq (Richard Genoud)
- btrfs: tree-checker: fix misleading root drop_level error message (Zhengyuan Huang)
- batman-adv: avoid OGM aggregation when skb tailroom is insufficient (Ao Zhou) [Orabug: 39263397] {CVE-2026-31683}
- pmdomain: bcm: bcm2835-power: Increase ASB control timeout (Maíra Canal) [Orabug: 39262263] {CVE-2026-31550}
- mptcp: pm: avoid sending RM_ADDR over same subflow (Matthieu Baerts)
- drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink (Natalie Vock)
- net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (Andrew Lunn) [Orabug: 39131009] {CVE-2026-23368}
- smb: client: Don't log plaintext credentials in cifs_set_cifscreds (Thorsten Blum)
- RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (Jason Gunthorpe) [Orabug: 39130902] {CVE-2026-23335}
- wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() (Daniil Dulov) [Orabug: 39130905] {CVE-2026-23336}
- wifi: cfg80211: move scan done work to wiphy work (Johannes Berg)
- wifi: libertas: fix use-after-free in lbs_free_adapter() (Daniel Hodges) [Orabug: 39130709] {CVE-2026-23281}
- ext4: always allocate blocks only from groups inode can use (Jan Kara)
- ksmbd: fix null pointer dereference error in generate_encryptionkey (Namjae Jeon)
- ext4: fix dirtyclusters double decrement on fs shutdown (Brian Foster) [Orabug: 39451836] {CVE-2026-45920}
- ext4: drop extent cache when splitting extent fails (Zhang Yi) [Orabug: 39451764] {CVE-2026-45899}
- ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (Zhang Yi) [Orabug: 39452051] {CVE-2026-45985}
- ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths (Fedor Pchelkin)
- drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free (Jeongjun Park)
- drm/exynos: vidi: fix to avoid directly dereferencing user pointer (Jeongjun Park)
- drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() (Jeongjun Park) [Orabug: 39451950] {CVE-2026-45956}
- net: Handle napi_schedule() calls from non-interrupt (Frederic Weisbecker)
- net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz (Huacai Chen)
- drm/radeon: apply state adjust rules to some additional HAINAN vairants (Alex Deucher)
- serial: uartlite: fix PM runtime usage count underflow on probe (Maciej Andrzejewski Iceye)
- serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART BUSY (Ilpo Järvinen)
- serial: 8250: Fix TX deadlock when using DMA (Raul E Rangel) [Orabug: 39323001] {CVE-2026-43061}
- serial: 8250_pci: add support for the AX99100 (Martin Roukala)
- iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry (Guanghui Feng)
- mtd: Avoid boot crash in RedBoot partition table parser (Finn Thain) [Orabug: 39167571] {CVE-2026-23474}
- mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init() (Chen Ni)
- mtd: rawnand: pl353: make sure optimal timings are applied (Olivier Sobrie)
- mmc: sdhci: fix timing selection for 1-bit bus width (Luke Wang)
- mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (Matthew Schwartz)
- Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (Lukas Johannes Möller) [Orabug: 39167591] {CVE-2026-31393}
- Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() (Lukas Johannes Möller) [Orabug: 39323033] {CVE-2026-43062}
- net: macb: fix use-after-free access to PTP clock (Fedor Pchelkin) [Orabug: 39167600] {CVE-2026-31396}
- NFC: nxp-nci: allow GPIOs to sleep (Ian Ray)
- nvdimm/bus: Fix potential use after free in asynchronous initialization (Ira Weiny) [Orabug: 39167606] {CVE-2026-31399}
- sunrpc: fix cache_request leak in cache_release (Jeff Layton) [Orabug: 39167610] {CVE-2026-31400}
- driver: iio: add missing checks on iio_info's callback access (Julien Stephan) [Orabug: 37073038] {CVE-2024-46715}
- io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (Jens Axboe) [Orabug: 38970182] {CVE-2026-23113}
- l2tp: do not use sock_hold() in pppol2tp_session_get_sock() (Eric Dumazet)
- bpf: Forget ranges when refining tnum after JSET (Paul Chaignon) [Orabug: 38423331] {CVE-2025-39748}
- i3c: mipi-i3c-hci: Add missing TID field to no-op command descriptor (Adrian Hunter)
- i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort (Adrian Hunter)
- i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors (Adrian Hunter)
- iio: imu: inv_icm42600: fix odr switch to the same value (Jean-Baptiste Maneyrol)
- iio: gyro: mpu3050-i2c: fix pm_runtime error handling (Antoniu Miclaus)
- iio: gyro: mpu3050-core: fix pm_runtime error handling (Antoniu Miclaus) [Orabug: 39343732] {CVE-2026-43357}
- iio: chemical: bme680: Fix measurement wait duration calculation (Chris Spencer)
- iio: potentiometer: mcp4131: fix double application of wiper shift (Lukas Schmid)
- iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() (Antoniu Miclaus)
- iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas() (Antoniu Miclaus)
- iio: dac: ds4424: reject -128 RAW value (Oleksij Rempel)
- btrfs: abort transaction on failure to update root in the received subvol ioctl (Filipe Manana)
- lib/bootconfig: check bounds before writing in __xbc_open_brace() (Josh Law)
- lib/bootconfig: fix snprintf truncation check in xbc_node_compose_key_after() (Josh Law)
- x86/apic: Disable x2apic on resume if the kernel expects so (Shashank Balaji) [Orabug: 39343756] {CVE-2026-43363}
- lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error (Josh Law)
- xfs: fix undersized l_iclog_roundoff values (Darrick J. Wong) [Orabug: 39343761] {CVE-2026-43365}
- tracing: Fix trace_buf_size= cmdline parameter with sizes >= 2G (Calvin Owens)
- drm/amdgpu: Fix use-after-free race in VM acquire (Alysa Liu) [Orabug: 39343770] {CVE-2026-43370}
- net: ethernet: arc: emac: quiesce interrupts before requesting IRQ (Fan Wu)
- net: ncsi: fix skb leak in error paths (Jian Zhang)
- parisc: Fix initial page table creation for boot (Helge Deller)
- hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read (Sanman Pradhan)
- nouveau/dpcd: return EBUSY for aux xfer if the device is asleep (Dave Airlie) [Orabug: 39343797] {CVE-2026-43381}
- parisc: Increase initial mapping to 64 MB with KALLSYMS (Helge Deller)
- batman-adv: Avoid double-rtnl_lock ELP metric worker (Sven Eckelmann) [Orabug: 39343802] {CVE-2026-43382}
- ice: fix retry for AQ command 0x06EE (Jakub Staniszewski)
- net: mana: Ring doorbell at 4 CQ wraparounds (Long Li)
- media: dvb-net: fix OOB access in ULE extension header tables (Ariel Silver) [Orabug: 39171442] {CVE-2026-31405}
- staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() (Greg Kroah-Hartman) [Orabug: 39343817] {CVE-2026-43387}
- staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (Luka Gejak) [Orabug: 39343813] {CVE-2026-43386}
- irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS supports (Marc Zyngier)
- device property: Allow secondary lookup in fwnode_get_next_child_node() (Andy Shevchenko)
- time/jiffies: Mark jiffies_64_to_clock_t() notrace (Steven Rostedt)
- time: add kernel-doc in time.c (Randy Dunlap)
- ceph: fix i_nlink underrun during async unlink (Max Kellermann) [Orabug: 39343884] {CVE-2026-43420}
- libceph: admit message frames only in CEPH_CON_S_OPEN state (Ilya Dryomov)
- libceph: Use u32 for non-negative values in ceph_monmap_decode() (Raphael Zimmer) [Orabug: 39343844] {CVE-2026-43405}
- libceph: prevent potential out-of-bounds reads in process_message_header() (Ilya Dryomov) [Orabug: 39343847] {CVE-2026-43406}
- libceph: reject preamble if control segment is empty (Ilya Dryomov)
- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39343850] {CVE-2026-43407}
- tipc: fix divide-by-zero in tipc_sk_filter_connect() (Mehul Rao) [Orabug: 39343861] {CVE-2026-43411}
- mmc: core: Avoid bitfield RMW for claim/retune flags (Penghe Geng) [Orabug: 39386859] {CVE-2026-43484}
- mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index() (Felix Gu)
- mm/tracing: rss_stat: ensure curr is false from kthread context (Kalesh Singh)
- usb: image: mdc800: kill download URB on timeout (Ziyi Guo) [Orabug: 39343897] {CVE-2026-43425}
- usb: mdc800: handle signal and read racing (Oliver Neukum)
- usb: renesas_usbhs: fix use-after-free in ISR during device removal (Fan Wu) [Orabug: 39343902] {CVE-2026-43426}
- usb: class: cdc-wdm: fix reordering issue in read code path (Oliver Neukum) [Orabug: 39343906] {CVE-2026-43427}
- USB: core: Limit the length of unkillable synchronous timeouts (Alan Stern) [Orabug: 39343911] {CVE-2026-43428}
- USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts (Alan Stern) [Orabug: 39343917] {CVE-2026-43429}
- USB: usbcore: Introduce usb_bulk_msg_killable() (Alan Stern)
- usb: cdc-acm: Restore CAP_BRK functionnality to CH343 (Marc Zyngier)
- usb: core: don't power off roothub PHYs if phy_set_mode() fails (Gabor Juhos)
- usb: misc: uss720: properly clean up reference in uss720_probe() (Greg Kroah-Hartman)
- usb: yurex: fix race in probe (Oliver Neukum) [Orabug: 39343921] {CVE-2026-43430}
- usb: xhci: Fix memory leak in xhci_disable_slot() (Zilin Guan) [Orabug: 39343930] {CVE-2026-43432}
- usb/core/quirks: Add Huawei ME906S-device to wakeup quirk (Christoffer Sandberg)
- net: usb: lan78xx: skip LTM configuration for LAN7850 (Oleksij Rempel)
- net: usb: lan78xx: fix silent drop of packets with checksum errors (Oleksij Rempel)
- cgroup: fix race between task migration and iteration (Qingye Zhao) [Orabug: 39343948] {CVE-2026-43439}
- octeontx2-af: devlink: fix NIX RAS reporter recovery condition (Alok Tiwari)
- ASoC: detect empty DMI strings (Casey Connolly)
- ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition (Chen Ni)
- ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address() (Ben Dooks)
- e1000/e1000e: Fix leak in DMA error cleanup (Matt Vollrath) [Orabug: 39343961] {CVE-2026-43445}
- i40e: fix src IP mask checks and memcpy argument names in cloud filter (Alok Tiwari)
- nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (Sungwoo Kim) [Orabug: 39343972] {CVE-2026-43449}
- regulator: pca9450: Correct interrupt type (Peng Fan)
- regulator: pca9450: Make IRQ optional (Frieder Schrempf)
- netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (Yuan Tan) [Orabug: 39110656] {CVE-2026-23274}
- netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (Hyunwoo Kim) [Orabug: 39343976] {CVE-2026-43450}
- netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (Hyunwoo Kim) [Orabug: 39343980] {CVE-2026-43451}
- netfilter: x_tables: guard option walkers against 1-byte tail reads (David Dull) [Orabug: 39343984] {CVE-2026-43452}
- netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() (Jenny Guanni Qu) [Orabug: 39343988] {CVE-2026-43453}
- can: hi311x: hi3110_open(): add check for hi3110_power_enable() return value (Wenyuan Li)
- serial: caif: hold tty->link reference in ldisc_open and ser_release (Shuangpeng Bai)
- ASoC: soc-core: flush delayed work before removing DAIs and widgets (Matteo Cotifava) [Orabug: 39344004] {CVE-2026-43459}
- ASoC: core: Do not call link_exit() on uninitialized rtd objects (Amadeusz Sławiński)
- ASoC: core: Exit all links before removing their components (Cezary Rojewski)
- ASoC: soc-core: accept zero format at snd_soc_runtime_set_dai_fmt() (Kuninori Morimoto)
- ASoC: soc-core: drop delayed_work_pending() check before flush (Matteo Cotifava)
- net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit (Weiming Shi) [Orabug: 39110666] {CVE-2026-23277}
- net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (Gal Pressman) [Orabug: 39344017] {CVE-2026-43466}
- bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states (Hangbin Liu)
- xprtrdma: Decrement re_receiving on the early exit paths (Eric Badger) [Orabug: 39344026] {CVE-2026-43469}
- powerpc: 83xx: km83xx: Fix keymile vendor prefix (Jonathan Neuschäfer)
- remoteproc: sysmon: Correct subsys_name_len type in QMI request (Bjorn Andersson)
- powerpc/uaccess: Fix inline assembly for clang build on PPC32 (Christophe Leroy)
- ALSA: usb-audio: Check max frame size for implicit feedback mode, too (Takashi Iwai)
- ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0 (Takashi Iwai)
- scsi: ses: Fix devices attaching to different hosts (Tomas Henzl)
- ACPI: OSI: Add DMI quirk for Acer Aspire One D255 (Sofia Schneider)
- unshare: fix unshare_fs() handling (Al Viro) [Orabug: 39344034] {CVE-2026-43472}
- scsi: mpi3mr: Add NULL checks when resetting request and reply queues (Ranjan Kumar) [Orabug: 39344038] {CVE-2026-43473}
- ACPI: PM: Save NVS memory on Lenovo G70-35 (Piotr Mazek)
- scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (Jan Kiszka) [Orabug: 39344043] {CVE-2026-43475}
- net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira) [Orabug: 39103230,39362005] {CVE-2026-23270}
- net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (Jiayuan Chen) [Orabug: 39130790] {CVE-2026-23300}
- net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (Fernando Fernandez Mancera) [Orabug: 39130767] {CVE-2026-23293}
- net: stmmac: Fix error handling in VLAN add and delete paths (Ovidiu Panait)
- nfc: rawsock: cancel tx_work before socket teardown (Jakub Kicinski)
- nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback (Jakub Kicinski)
- nfc: nci: free skb on nci_transceive early error paths (Jakub Kicinski)
- net: nfc: nci: Fix zero-length proprietary notifications (Ian Ray)
- net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (Koichiro Den) [Orabug: 39130923] {CVE-2026-23340}
- amd-xgbe: fix sleep while atomic on suspend/resume (Raju Rangoju)
- ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() (Jakub Kicinski) [Orabug: 39130807] {CVE-2026-23304}
- xen/acpi-processor: fix _CST detection using undersized evaluation buffer (David Thomson)
- indirect_call_wrapper: do not reevaluate function pointer (Eric Dumazet)
- wifi: wlcore: Fix a locking bug (Bart Van Assche) [Orabug: 39167425] {CVE-2026-23420}
- can: mcp251x: fix deadlock in error path of mcp251x_open (Alban Bedel) [Orabug: 39130971] {CVE-2026-23357}
- can: bcm: fix locking for bcm_op runtime updates (Oliver Hartkopp) [Orabug: 39131187] {CVE-2026-23362}
- atm: lec: fix null-ptr-deref in lec_arp_clear_vccs (Jiayuan Chen) [Orabug: 39130726] {CVE-2026-23286}
- dpaa2-switch: do not clear any interrupts automatically (Ioana Ciornei)
- net: dpaa2-switch: serialize changes to priv->mac with a mutex (Vladimir Oltean)
- net: dpaa2-switch replace direct MAC access with dpaa2_switch_port_has_mac() (Vladimir Oltean)
- net: dpaa2-switch: assign port_priv->mac after dpaa2_mac_connect() call (Vladimir Oltean)
- net: dpaa2: replace dpaa2_mac_is_type_fixed() with dpaa2_mac_is_type_phy() (Vladimir Oltean)
- net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling in ALE table (Chintan Vankar)
- platform/x86: thinkpad_acpi: Fix errors reading battery thresholds (Jonathan Teh)
- selftests: mptcp: more stable simult_flows tests (Paolo Abeni)
- drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() (Lars Ellenberg) [Orabug: 39130965] {CVE-2026-23356}
- Squashfs: check metadata block offset is within range (Phillip Lougher) [Orabug: 39131079] {CVE-2026-23388}
- net/sched: ets: fix divide by zero in the offload path (Davide Caratti) [Orabug: 39131049] {CVE-2026-23379}
- IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() (Jason Gunthorpe) [Orabug: 39130742] {CVE-2026-23289}
- wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (Vahagn Vardanian) [Orabug: 39130701] {CVE-2026-23279}
- wifi: radiotap: reject radiotap with unknown bits (Johannes Berg) [Orabug: 39131005] {CVE-2026-23367}
- ALSA: usb-audio: Use correct version for UAC3 header validation (Jun Seo) [Orabug: 39130855] {CVE-2026-23318}
- platform/x86: dell-wmi: Add audio/mic mute key codes (Kurt Borja)
- platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data (Thorsten Blum) [Orabug: 39131016] {CVE-2026-23370}
- x86/efi: defer freeing of boot services memory (Mike Rapoport) [Orabug: 39130953] {CVE-2026-23352}
- HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them (Greg Kroah-Hartman) [Orabug: 39131061] {CVE-2026-23382}
- can: usb: etas_es58x: correctly anchor the urb in the read bulk callback (Greg Kroah-Hartman)
- can: ucan: Fix infinite loop from zero-length messages (Greg Kroah-Hartman)
- can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message (Greg Kroah-Hartman) [Orabug: 39130816] {CVE-2026-23307}
- net: usb: pegasus: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130750] {CVE-2026-23290}
- net: usb: kalmia: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130997] {CVE-2026-23365}
- net: usb: kaweth: validate USB endpoints (Greg Kroah-Hartman) [Orabug: 39130832] {CVE-2026-23312}
- nfc: pn533: properly drop the usb interface reference on disconnect (Greg Kroah-Hartman)
- media: dvb-core: fix wrong reinitialization of ringbuffer on reopen (Jens Axboe) [Orabug: 39103138] {CVE-2026-23253}
- eventpoll: Fix integer overflow in ep_loop_check_proc() (Jann Horn)
- net: arcnet: com20020-pci: fix support for 2.5Mbit cards (Ethan Nelson-Moore)
- ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314 (Takashi Iwai)
- fbcon: check return value of con2fb_acquire_newinfo() (Andrey Vatoropin) [Orabug: 39331304] {CVE-2026-43123}
- fbcon: move more common code into fb_open() (Daniel Vetter)
- fbcon: Extract fbcon_open/release helpers (Daniel Vetter)
- fbcon: Use delayed work for cursor (Daniel Vetter)
- ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths (Namjae Jeon)
- ALSA: hda/conexant: Add quirk for HP ZBook Studio G4 (Takashi Iwai)
- usb: cdns3: fix role switching during resume (Thomas Richard)
- usb: cdns3: call cdns_power_is_lost() only once in cdns_resume() (Théo Lebrun)
- usb: cdns3: remove redundant if branch (Hongyu Xie)
- clk: tegra: tegra124-emc: fix device leak on set_rate() (Johan Hovold)
- mfd: omap-usb-host: Fix OF populate on driver rebind (Johan Hovold)
- mfd: omap-usb-host: Convert to platform remove callback returning void (Uwe Kleine-König)
- mfd: qcom-pm8xxx: Fix OF populate on driver rebind (Johan Hovold)
- mfd: qcom-pm8xxx: Convert to platform remove callback returning void (Uwe Kleine-König)
- mfd: qcom-pm8xxx: switch away from using chained IRQ handlers (Dmitry Baryshkov)
- drm/tegra: dsi: fix device leak on probe (Johan Hovold)
- ata: libata-scsi: refactor ata_scsi_translate() (Damien Le Moal)
- ata: libata: remove pointless VPRINTK() calls (Hannes Reinecke)
- ata: libata-scsi: drop DPRINTK calls for cdb translation (Hannes Reinecke)
- scsi: ata: Call scsi_done() directly (Bart Van Assche)
- ARM: omap2: Fix reference count leaks in omap_control_init() (Xu Wang)
- ARM: OMAP2+: add missing of_node_put before break and return (Qing Wang)
- memory: mtk-smi: fix device leak on larb probe (Johan Hovold)
- memory: mtk-smi: Convert to platform remove callback returning void (Uwe Kleine-König)
- bpf: Fix stack-out-of-bounds write in devmap (Kohei Enju) [Orabug: 39130978] {CVE-2026-23359}
- btrfs: fix incorrect key offset in error message in check_dev_extent_item() (Mark Harmstone)
- ALSA: usb-audio: Use inclusive terms (Takashi Iwai)
- ALSA: usb-audio: Cap the packet size pre-calculations (Takashi Iwai)
- scsi: ufs: core: Move link recovery for hibern8 exit failure to wl_resume (Peter Wang)
- scsi: ufs: core: Always initialize the UIC done completion (Bart Van Assche)
- scsi: lpfc: Properly set WC for DPP mapping (Mathias Krause)
- ARM: clean up the memset64() C wrapper (Thomas Weißschuh)

[5.15.0-322.202.1]
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446044,39754206] {CVE-2026-63890}
- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (Michael Bommarito) [Orabug: 39446044,39754203] {CVE-2026-63889}
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446044,39754199] {CVE-2026-63888}
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446044,39754193] {CVE-2026-63887}
- ima: process_measurement() needlessly takes inode_lock() on MAY_READ (Frederick Lawler) [Orabug: 39390378]
- net: sched: act_api: implement generic walker and search for tc action (Zhengchao Shao) [Orabug: 39342047]
- btrfs: reserve extra space for the free space tree (Josef Bacik) [Orabug: 39281379]
- btrfs: include the free space tree in the global rsv minimum calculation (Josef Bacik) [Orabug: 39281379]

[5.15.0-321.202.5]
- Revert "ip6_tunnel: Fix usage of skb_vlan_inet_prepare()" (Harshit Mogalapalli) [Orabug: 39476647]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463672,39476933] {CVE-2026-46243}



ELBA-2026-500169 Oracle Linux 9 kexec-tools bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500169

http://linux.oracle.com/errata/ELBA-2026-500169.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kexec-tools-2.0.31-1.0.4.el9.x86_64.rpm

aarch64:
kexec-tools-2.0.31-1.0.4.el9.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kexec-tools-2.0.31-1.0.4.el9.src.rpm

Description of changes:

[2.0.31-1.0.4]
- Fix wrong exclusion of compound tail pages on Linux 7.1 [Orabug: 39765177]



ELBA-2026-500167 Oracle Linux 9 crash bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500167

http://linux.oracle.com/errata/ELBA-2026-500167.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
crash-9.0.2-1.0.2.el9.x86_64.rpm
crash-devel-9.0.2-1.0.2.el9.i686.rpm
crash-devel-9.0.2-1.0.2.el9.x86_64.rpm

aarch64:
crash-9.0.2-1.0.2.el9.aarch64.rpm
crash-devel-9.0.2-1.0.2.el9.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/crash-9.0.2-1.0.2.el9.src.rpm

Description of changes:

[9.0.2-1.0.2]
- Add Linux 7.1 compatibility for date reporting, module symbols, and x86_64 ORC backtraces [Orabug: 39765177]



ELBA-2026-500163 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500163

http://linux.oracle.com/errata/ELBA-2026-500163.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-core-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-debug-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-debug-core-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-debug-devel-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-debug-modules-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-debug-modules-extra-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-devel-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-doc-5.15.0-323.211.3.3.el8uek.noarch.rpm
kernel-uek-modules-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-modules-extra-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-container-5.15.0-323.211.3.3.el8uek.x86_64.rpm
kernel-uek-container-debug-5.15.0-323.211.3.3.el8uek.x86_64.rpm

aarch64:
bpftool-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-core-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-debug-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-debug-core-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-debug-devel-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-debug-modules-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-debug-modules-extra-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-devel-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-doc-5.15.0-323.211.3.3.el8uek.noarch.rpm
kernel-uek-modules-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-modules-extra-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-container-5.15.0-323.211.3.3.el8uek.aarch64.rpm
kernel-uek-container-debug-5.15.0-323.211.3.3.el8uek.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.15.0-323.211.3.3.el8uek.src.rpm

Description of changes:

[5.15.0-323.211.3.3]
- Revert "x86/alternatives: Add alt_instr.flags" (Harshit Mogalapalli) [Orabug: 39853924]

[5.15.0-323.211.3.2]
- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39848333]
- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39848194]
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39848194] {CVE-2026-64561}
- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39848194]
- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39848194]
- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39848194]
- KVM: x86/mmu: Document the "rules" for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39848194]
- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39848194]
- KVM: x86/mmu: Directly "destroy" PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39848194]
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov (AMD)) [Orabug: 39849605] {CVE-2026-68480}
- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39849605]
- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39849605]
- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39849605]
- x86/alternatives: Add alt_instr.flags (Borislav Petkov (AMD)) [Orabug: 39849605]
- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39849605]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39848314]

[5.15.0-323.211.3.1]
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39816016] {CVE-2026-64531}
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39816098] {CVE-2026-64600}

[5.15.0-323.211.3]
- LTS version: v5.15.211 (Vijayendra Suman)
- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844553] {CVE-2025-23131}
- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786549] {CVE-2026-64529}
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)
- Documentation: ioctl-number: Extend "Include File" column width (Bagas Sanjaya)
- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)
- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753883] {CVE-2026-53388}
- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri) [Orabug: 39637380] {CVE-2026-53157}
- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)
- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)
- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)
- misc: fastrpc: Add dma_mask to fastrpc_channel_ctx (Abel Vesa)
- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)
- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753890] {CVE-2026-53391}
- nfsd: check get_user() return when reading princhashlen (Dominik Woźniak)
- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753905] {CVE-2026-53397}
- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753909] {CVE-2026-53398}
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753928] {CVE-2026-53403}
- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753936] {CVE-2026-63794}
- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753942] {CVE-2026-63796}
- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)
- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753953] {CVE-2026-63800}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753957] {CVE-2026-63801}
- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753963] {CVE-2026-63803}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753979] {CVE-2026-63808}
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)
- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753982] {CVE-2026-63809}
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)
- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754021] {CVE-2026-63822}
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)
- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754024] {CVE-2026-63823}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754028] {CVE-2026-63824}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754053] {CVE-2026-63831}
- crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503789] {CVE-2025-39931}
- ext4: add bounds check for inline data length in ext4_read_inline_page (Yuto Ohnuki)
- ntfs3: reject direct userspace writes to reserved $LX* xattrs (Konstantin Komarov)
- ring-buffer: Remove ring_buffer_read_prepare_sync() (Bjoern Doebel)
- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)
- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)
- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)
- batman-adv: tt: track roam count per VID (Sven Eckelmann)
- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)
- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)
- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)
- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754066] {CVE-2026-63834}
- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754070] {CVE-2026-63835}
- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)
- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)
- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)
- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)
- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)
- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)
- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754076] {CVE-2026-63836}
- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)
- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)
- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)
- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)
- kselftest/arm64: signal: Skip SVE signal test if not enough VLs supported (Yijia Wang)
- Revert "ptp: add testptp mask test" (Petr Machata)
- Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753856] {CVE-2026-53381}
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753871] {CVE-2026-53385}
- regulator: core: fix locking in regulator_resolve_supply() error path (André Draszik) [Orabug: 39489558] {CVE-2026-46252}
- af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) [Orabug: 39619334] {CVE-2026-52928}
- xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman)
- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662073] {CVE-2026-53325}
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)
- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760892] {CVE-2026-64191}
- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg)
- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)
- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)
- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)
- drm/v3d: Skip CSD when it has zeroed workgroups (Maíra Canal)
- drm/v3d: Store the active job inside the queue's state (Maíra Canal)
- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589885] {CVE-2026-52909}
- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637312] {CVE-2026-53138}
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637410] {CVE-2026-53167}
- LTS version: v5.15.210 (Vijayendra Suman)
- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637279] {CVE-2026-53131}
- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)
- batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann)
- ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev)
- Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz)
- media: rc: igorplugusb: fix control request setup packet (Henri A) [Orabug: 39785220] {CVE-2026-64240}
- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) [Orabug: 39784982] {CVE-2026-64092}
- media: rc: ttusbir: fix inverted error logic (Oliver Neukum)
- apparmor: validate default DFA states are in bounds (Ben Hutchings)
- fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter (Ben Hutchings)
- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754146] {CVE-2026-63867}
- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon)
- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni)
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674327] {CVE-2026-53354}
- arm64: cputype: Add NVIDIA Olympus definitions (Shanker Donthineni)
- selinux: enable genfscon labeling for securityfs (Christian Göttsche)
- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt)
- ksmbd: Compare MACs in constant time (Eric Biggers)
- net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343685] {CVE-2026-43341}
- batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann)
- batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) [Orabug: 39460622] {CVE-2026-46208}
- blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (Tejun Heo)
- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451541] {CVE-2026-45850}
- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637477] {CVE-2026-53189}
- RDMA/umem: Fix truncation for block sizes >= 4G (Jason Gunthorpe)
- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)
- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)
- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637516] {CVE-2026-53199}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637292] {CVE-2026-53134}
- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)
- tty: serial: qcom-geni-serial: align #define values (Bartosz Golaszewski)
- tty: serial: qcom-geni-serial: remove unused symbols (Bartosz Golaszewski)
- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)
- serial: altera_jtaguart: Use platform_get_irq_optional() to get the interrupt (Lad Prabhakar)
- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786537] {CVE-2026-64524}
- drm/hyperv: Remove support for Hyper-V 2008 and 2008R2/Win7 (Michael Kelley)
- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)
- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754211] {CVE-2026-63891}
- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)
- usb: gadget: f_hid: tidy error handling in hidg_alloc (John Keeping)
- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)
- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786545] {CVE-2026-64528}
- tty: serial: samsung: use u32 for register interactions (Tudor Ambarus)
- serial: samsung_tty: Use port lock wrappers (Thomas Gleixner)
- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)
- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)
- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)
- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)
- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)
- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681273] {CVE-2026-53358}
- phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang)
- phy: tegra: xusb: Disable trk clk when not in use (Wayne Chang)
- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755010] {CVE-2026-63875}
- spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) [Orabug: 39754942] {CVE-2026-64170}
- spi: qup: switch to use modern name (Yang Yingliang)
- octeontx2-pf: avoid double free of pool->stack on AQ init failure (Dawei Feng)
- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly)
- mptcp: do not drop partial packets (Shardul Bankar)
- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)
- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)
- use less confusing names for iov_iter direction initializers (Al Viro)
- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) [Orabug: 39754825] {CVE-2026-64116}
- ipv6/addrconf: annotate data-races around devconf fields (II) (Eric Dumazet)
- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)
- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754840] {CVE-2026-64123}
- Bluetooth: serialize accept_q access (Jiexun Wang) [Orabug: 39619283] {CVE-2026-52918}
- Bluetooth: Init sk_peer_* on bt_sock_alloc (Luiz Augusto von Dentz)
- Bluetooth: Consolidate code around sk_alloc into a helper function (Luiz Augusto von Dentz)
- qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) [Orabug: 39754830] {CVE-2026-64118}
- Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) [Orabug: 39754849] {CVE-2026-64126}
- Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2 (Luiz Augusto von Dentz)
- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)
- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakuş) [Orabug: 39681270] {CVE-2026-53357}
- smb: client: require net admin for CIFS SWN netlink (Michael Bommarito)
- genetlink: Use internal flags for multicast groups (Ido Schimmel)
- spi: lantiq-ssc: fix controller deregistration (Johan Hovold)
- spi: st-ssc4: fix controller deregistration (Johan Hovold)
- f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu)
- f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang)
- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts)
- mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts) [Orabug: 39460320] {CVE-2026-46137}
- mptcp: pm: prio: skip closed subflows (Matthieu Baerts)
- smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva)
- btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) [Orabug: 39460410] {CVE-2026-46160}
- smb: client: validate dacloffset before building DACL pointers (Michael Bommarito)
- pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) [Orabug: 39524579] {CVE-2026-46292}
- tracing/probes: Limit size of event probe to 3K (Steven Rostedt)
- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) [Orabug: 39460405] {CVE-2026-46159}
- spi: topcliff-pch: fix controller deregistration (Johan Hovold)
- spi: topcliff-pch: Convert to platform remove callback returning void (Uwe Kleine-König)
- fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) [Orabug: 39460548] {CVE-2026-46191}
- mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon)
- spi: uniphier: fix controller deregistration (Johan Hovold)
- spi: tegra20-sflash: fix controller deregistration (Johan Hovold)
- spi: tegra114: fix controller deregistration (Johan Hovold)
- spi: sun6i: fix controller deregistration (Johan Hovold)
- spi: zynq-qspi: fix controller deregistration (Johan Hovold)
- spi: ti-qspi: fix controller deregistration (Johan Hovold)
- spi: spi-ti-qspi: Convert to platform remove callback returning void (Uwe Kleine-König)
- spi: sun4i: fix controller deregistration (Johan Hovold)
- spi: syncuacer: fix controller deregistration (Johan Hovold)
- xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) [Orabug: 39460554] {CVE-2026-46193}
- net: ipv6: stop checking crypto_ahash_alignmask (Eric Biggers)
- net: ipv4: stop checking crypto_ahash_alignmask (Eric Biggers)
- usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan)
- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) [Orabug: 39460504] {CVE-2026-46180}
- usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne)
- smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito)
- tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) [Orabug: 39460568] {CVE-2026-46196}
- crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum)
- printk: add print_hex_dump_devel() (Thorsten Blum)
- ALSA: aloop: Fix peer runtime UAF during format-change stop (Cássio Gabriel) [Orabug: 39452424] {CVE-2026-46090}
- ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452292] {CVE-2026-46052}
- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo)
- can: ucan: fix devres lifetime (Johan Hovold)
- can: ucan: fix typos in comments (Julia Lawall)
- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452305] {CVE-2026-46056}
- hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan)
- hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey)
- udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) [Orabug: 39452078] {CVE-2026-45991}
- mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S)
- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin)
- randomize_kstack: Maintain kstack_offset per task (Ryan Roberts)
- fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) [Orabug: 39452332] {CVE-2026-46065}
- net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452412] {CVE-2026-46086}
- net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452124] {CVE-2026-46003}
- net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming)
- net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452247] {CVE-2026-46038}
- net: qrtr: ns: Change servers radix tree to xarray (Vignesh Viswanathan)
- net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452208] {CVE-2026-46026}
- ALSA: core: Fix potential data race at fasync handling (Takashi Iwai)
- sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury)
- media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452433] {CVE-2026-46091}
- erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang)
- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum)
- media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum)
- ALSA: aoa: i2sbus: clear stale prepared state (Cássio Gabriel)
- ALSA: aoa: Use guard() for mutex locks (Takashi Iwai)
- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452344] {CVE-2026-46069}
- thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452187] {CVE-2026-46021}
- wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452438] {CVE-2026-46092}
- rtw88: 8821ce: Disable PCIe ASPM L1 for 8821CE using chip ID (Jimmy Hon)
- arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual)
- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) [Orabug: 39300581] {CVE-2026-31700}
- ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito)
- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito)
- smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito)
- smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang)
- smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito)
- f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() (Yongpeng Yang)
- f2fs: fix to do sanity check on dcc->discard_cmd_cnt conditionally (Chao Yu)
- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner)
- net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343806] {CVE-2026-43383}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) [Orabug: 39619351] {CVE-2026-52933}
- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)
- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655978] {CVE-2026-52946}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674253] {CVE-2026-53329}
- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637296] {CVE-2026-53135}
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637301] {CVE-2026-53136}
- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland)
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (Bjorn Andersson)
- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637337] {CVE-2026-53146}
- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637346] {CVE-2026-53148}
- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637351] {CVE-2026-53149}
- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637356] {CVE-2026-53150}
- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619338] {CVE-2026-52929}
- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619278] {CVE-2026-52917}
- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)
- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)
- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)
- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)
- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674284] {CVE-2026-53337}
- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)
- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)
- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619342] {CVE-2026-52930}
- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)
- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)
- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)
- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodríguez)
- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)
- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637414] {CVE-2026-53168}
- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637428] {CVE-2026-53176}
- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637432] {CVE-2026-53177}
- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637447] {CVE-2026-53181}
- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)
- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)
- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)
- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)
- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637467] {CVE-2026-53186}
- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)
- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637489] {CVE-2026-53192}
- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637496] {CVE-2026-53194}
- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637502] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637506] {CVE-2026-53196}
- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)
- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674335] {CVE-2026-53356}
- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637545] {CVE-2026-53208}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637555] {CVE-2026-53212}
- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637561] {CVE-2026-53213}
- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)
- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637568] {CVE-2026-53215}
- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)
- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637571] {CVE-2026-53216}
- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637575] {CVE-2026-53217}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637578] {CVE-2026-53218}
- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619384] {CVE-2026-52942}
- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637582] {CVE-2026-53219}
- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637592] {CVE-2026-53221}
- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637599] {CVE-2026-53223}
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637609] {CVE-2026-53225}
- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637618] {CVE-2026-53227}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637622] {CVE-2026-53228}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621562] {CVE-2026-52947}
- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637662] {CVE-2026-53238}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637666] {CVE-2026-53239}
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland)
- KVM: arm64: Remove VPIPT I-cache handling (Marc Zyngier)
- nfsd: don't ignore the return code of svc_proc_register() (Jeff Layton) [Orabug: 37844165] {CVE-2025-22026}
- fs/ntfs3: Return error for inconsistent extended attributes (Edward Lo)
- ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250744] {CVE-2026-31449}
- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)
- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674319] {CVE-2026-53352}
- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619311] {CVE-2026-52924}
- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637680] {CVE-2026-53245}
- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754155] {CVE-2026-63870}
- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637694] {CVE-2026-53249}
- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39785002] {CVE-2026-53252}
- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637706] {CVE-2026-53253}
- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)
- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637711] {CVE-2026-53254}
- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637716] {CVE-2026-53255}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637720] {CVE-2026-53256}
- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson)
- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754149] {CVE-2026-63868}
- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)
- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)
- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637741] {CVE-2026-53263}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637748] {CVE-2026-53264}
- dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39784967] {CVE-2026-53265}
- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637753] {CVE-2026-53266}
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637763] {CVE-2026-53268}
- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637768] {CVE-2026-53269}
- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637772] {CVE-2026-53270}
- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)
- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637782] {CVE-2026-53273}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637790] {CVE-2026-53275}
- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621568] {CVE-2026-52948}
- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)
- compiler-clang.h: Add __diag infrastructure for clang (Nathan Chancellor)
- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754236] {CVE-2026-63898}
- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589889] {CVE-2026-52910}
- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michał Pecio)
- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)
- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)
- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754248] {CVE-2026-63901}
- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)
- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)
- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)
- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754408] {CVE-2026-63956}
- serial: zs: Switch to using channel reset (Maciej W. Rozycki)
- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)
- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)
- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)
- serial: sh-sci: fix memory region release in error path (Hongling Zeng)
- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786542] {CVE-2026-64527}
- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754216] {CVE-2026-63892}
- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754220] {CVE-2026-63893}
- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)
- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)
- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754232] {CVE-2026-63897}
- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754240] {CVE-2026-63899}
- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754244] {CVE-2026-63900}
- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754252] {CVE-2026-63902}
- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754256] {CVE-2026-63903}
- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong)
- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)
- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)
- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754260] {CVE-2026-63904}
- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito) [Orabug: 39754264] {CVE-2026-63905}
- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)
- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)
- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michał Pecio)
- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)
- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)
- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)
- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)
- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolás Bazaes)
- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754271] {CVE-2026-63908}
- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754278] {CVE-2026-63912}
- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)
- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754282] {CVE-2026-63913}
- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)
- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754286] {CVE-2026-63914}
- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)
- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)
- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754294] {CVE-2026-63916}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754298] {CVE-2026-63917}
- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754304] {CVE-2026-63919}
- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754307] {CVE-2026-63920}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754311] {CVE-2026-63921}
- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754315] {CVE-2026-63922}
- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754322] {CVE-2026-63924}
- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754326] {CVE-2026-63925}
- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754329] {CVE-2026-63926}
- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785158] {CVE-2026-64237}
- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754333] {CVE-2026-63927}
- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)
- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)
- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754337] {CVE-2026-63928}
- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)
- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)
- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)
- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)
- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)
- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)
- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)
- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)
- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)
- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)
- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)
- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754375] {CVE-2026-63942}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754387] {CVE-2026-63947}
- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754391] {CVE-2026-63948}
- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619307] {CVE-2026-52923}
- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)
- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)
- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)
- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754412] {CVE-2026-63957}
- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)
- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754428] {CVE-2026-63961}
- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)
- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)
- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)
- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher)
- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)
- phy: mscc: Use PHY_ID_MATCH_VENDOR to minimize PHY ID table (Harini Katakam)
- RDMA/rxe: Fix double free in rxe_srq_from_init (Jiasheng Jiang) [Orabug: 39451551] {CVE-2026-45852}
- Revert "RDMA/rxe: Fix double free in rxe_srq_from_init" (Ben Hutchings)
- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Högander)
- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)
- drm/i915/psr: Read Intel DPCD workaround register (Jouni Högander)
- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Högander)
- wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456849] {CVE-2025-39863}
- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754761] {CVE-2026-64095}
- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754744] {CVE-2026-64090}
- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754748] {CVE-2026-64091}
- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)
- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619357] {CVE-2026-52934}
- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754757] {CVE-2026-64094}
- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)
- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann)
- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754456] {CVE-2026-63971}
- gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (Marco Scardovi)
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754468] {CVE-2026-63975}
- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754471] {CVE-2026-63976}
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754489] {CVE-2026-63984}
- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754492] {CVE-2026-63985}
- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754502] {CVE-2026-63990}
- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)
- ASoC: codecs: simple-mux: Fix enum control bounds check (Cássio Gabriel)
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754510] {CVE-2026-63992}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754513] {CVE-2026-63993}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754516] {CVE-2026-63994}
- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cássio Gabriel)
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754536] {CVE-2026-64002}
- net/iucv: fix locking in .getsockopt (Breno Leitao)
- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)
- net: netlink: don't set nsid on local notifications (Ilya Maximets)
- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)
- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619329] {CVE-2026-52927}
- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754553] {CVE-2026-64007}
- nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee)
- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754558] {CVE-2026-64009}
- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)
- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)
- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)
- dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323060] {CVE-2026-43064}
- drm: Remove plane hsub/vsub alignment requirement for core helpers (Carlos Eduardo Gallo Filho)
- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754570] {CVE-2026-64012}
- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr)
- net/sched: cls_fw: fix NULL dereference of "old" filters before change() (Davide Caratti) [Orabug: 39622011] {CVE-2026-53080}
- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754575] {CVE-2026-64014}
- LTS version: v5.15.209 (Samasth Norway Ananda)
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) [Orabug: 39754586] {CVE-2026-64018}
- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski)
- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko)
- string: add mem_is_zero() helper to check if memory area is all zeros (Jani Nikula)
- net: ag71xx: check error for platform_get_irq (Rosen Penev)
- tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) [Orabug: 39784962] {CVE-2026-64028}
- bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) [Orabug: 39754613] {CVE-2026-64032}
- net: bridge: Flush multicast groups when snooping is disabled (Petr Machata)
- RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li)
- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)
- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) [Orabug: 39754619] {CVE-2026-64034}
- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle)
- net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw (Arınç Ünal)
- net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle)
- net: dsa: mt7530: sync driver-specific behavior of MT7531 variants (Daniel Golle)
- drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) [Orabug: 39754629] {CVE-2026-64039}
- net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) [Orabug: 39754638] {CVE-2026-64046}
- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) [Orabug: 39754642] {CVE-2026-64047}
- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) [Orabug: 39754904] {CVE-2026-64153}
- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao)
- HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn)
- wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) [Orabug: 39754909] {CVE-2026-64155}
- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore)
- net: ethernet: cortina: Carry over frag counter (Linus Walleij)
- net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann)
- net: ethernet: cortina: Make RX SKB per-port (Linus Walleij)
- irqchip/ath79-cpu: Remove unused function (Rosen Penev)
- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos)
- ice: fix locking in ice_dcb_rebuild() (Bart Van Assche)
- tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima)
- netfilter: x_tables: unregister the templates first (Florian Westphal)
- ARM: integrator: Fix early initialization (Guenter Roeck)
- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow)
- kunit: config: Enable KUNIT_DEBUGFS by default (David Gow)
- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla)
- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) [Orabug: 39754932] {CVE-2026-64166}
- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain)
- batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) [Orabug: 39754734] {CVE-2026-64088}
- batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) [Orabug: 39754740] {CVE-2026-64089}
- batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) [Orabug: 39619346] {CVE-2026-52931}
- batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann) [Orabug: 39785109] {CVE-2026-64218}
- batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) [Orabug: 39619274] {CVE-2026-52916}
- batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) [Orabug: 39619287] {CVE-2026-52919}
- batman-adv: fix fragment reassembly length accounting (Ruide Cao) [Orabug: 39619266] {CVE-2026-52914}
- batman-adv: dat: handle forward allocation error (Sven Eckelmann)
- batman-adv: clear current gateway during teardown (Ruijie Li) [Orabug: 39619323] {CVE-2026-52926}
- batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) [Orabug: 39754765] {CVE-2026-64096}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) [Orabug: 39785113] {CVE-2026-64219}
- drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland)
- drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader)
- drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau)
- device property: set fwnode->secondary to NULL in fwnode_init() (Bartosz Golaszewski) [Orabug: 39785117] {CVE-2026-64220}
- RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito)
- spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold)
- spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold)
- scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) [Orabug: 39754786] {CVE-2026-64103}
- tracing: Do not call map->ops->elt_free() if elt_alloc() fails (Masami Hiramatsu) [Orabug: 39754948] {CVE-2026-64173}
- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) [Orabug: 39754952] {CVE-2026-64174}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) [Orabug: 39754812] {CVE-2026-64113}
- ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (Michael Bommarito) [Orabug: 39754817] {CVE-2026-64114}
- wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung)
- vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) [Orabug: 39754821] {CVE-2026-64115}
- ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt)
- netfilter: ipset: stop hash:* range iteration at end (Nan Li) [Orabug: 39619299] {CVE-2026-52921}
- netfilter: nf_queue: hold bridge skb->dev while queued (Haoze Xie) [Orabug: 39619255] {CVE-2026-52912}
- netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) [Orabug: 39619270] {CVE-2026-52915}
- net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) [Orabug: 39754845] {CVE-2026-64125}
- phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) [Orabug: 39754963] {CVE-2026-64177}
- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) [Orabug: 39523054] {CVE-2026-46275}
- Bluetooth: bnep: Fix UAF read of dev->name (Jann Horn) [Orabug: 39754967] {CVE-2026-64178}
- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal)
- ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) [Orabug: 39754862] {CVE-2026-64133}
- ALSA: ua101: Reject too-short USB descriptors (Cássio Gabriel)
- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain)
- sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) [Orabug: 39754983] {CVE-2026-64185}
- Revert "s390/cio: Fix device lifecycle handling in css_alloc_subchannel()" (Sasha Levin)
- KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (Sean Christopherson) [Orabug: 37901590] {CVE-2025-23141}
- wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300982] {CVE-2026-43052}
- net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (Vladimir Oltean)
- Revert "x86/vdso: Fix output operand size of RDPID" (Sasha Levin)
- s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou)
- io_uring: prevent opcode speculation (Pavel Begunkov) [Orabug: 37702113] {CVE-2025-21863}
- io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) [Orabug: 39523050] {CVE-2026-46274}
- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold)
- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek)
- drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka)
- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcalá)
- libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) [Orabug: 39621580] {CVE-2026-52954}
- libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) [Orabug: 39621584] {CVE-2026-52955}
- libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) [Orabug: 39621592] {CVE-2026-52957}
- libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) [Orabug: 39621596] {CVE-2026-52958}
- powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke)
- ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) [Orabug: 39621609] {CVE-2026-52962}
- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cássio Gabriel) [Orabug: 39621613] {CVE-2026-52963}
- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah)
- KVM: x86: Fix Xen hypercall tracepoint argument assignment (Maqiang)
- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) [Orabug: 39621628] {CVE-2026-52969}
- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia)
- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski)
- netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) [Orabug: 39621633] {CVE-2026-52970}
- audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia) [Orabug: 39653209] {CVE-2026-53287}
- i40e: Cleanup PTP pins on probe failure (Matt Vollrath)
- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) [Orabug: 39655982] {CVE-2026-52972}
- net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet)
- flow_dissector: Do not count vlan tags inside tunnel payload (Qingqing Yang)
- flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) [Orabug: 39524619] {CVE-2026-46306}
- btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) [Orabug: 39784984] {CVE-2026-64164}
- drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristóf)
- drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristóf)
- ALSA: hda/conexant: Fix missing error check for jack detection (Wangdicheng) [Orabug: 39653220] {CVE-2026-53291}
- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (Wangdicheng)
- ALSA: hda/conexant: fix some typos (Oldherl Oh)
- ALSA: hda/conexant: add a new hda codec SN6140 (Bo Liu)
- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet)
- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) [Orabug: 39451517] {CVE-2026-45846}
- ipv6: rename and move ip6_dst_lookup_tunnel() (Beniamino Galvani)
- ipv4: add new arguments to udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: remove "proto" argument from udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: rename and move ip_route_output_tunnel() (Beniamino Galvani)
- sctp: discard stale INIT after handshake completion (Xin Long)
- netfilter: skip recording stale or retransmitted INIT (Xin Long)
- ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt)
- net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher)
- NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts)
- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Dandan Zhang)
- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Jun Zhan) [Orabug: 39621670] {CVE-2026-52982}
- vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) [Orabug: 39619318] {CVE-2026-52925}
- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet)
- net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet)
- net: sched: choke: remove unused variables in struct choke_sched_data (Zhengchao Shao)
- net/sched: netem: validate slot configuration (Stephen Hemminger)
- net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) [Orabug: 39621677] {CVE-2026-52984}
- net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger)
- net: sched: sch_netem: Refactor code in 4-state loss generator (Harshit Mogalapalli)
- netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) [Orabug: 39621681] {CVE-2026-52985}
- cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer)
- scsi: sr: Add memory allocation failure handling for get_capabilities() (Enze Li)
- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [Orabug: 39621685] {CVE-2026-52986}
- netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) [Orabug: 39619293] {CVE-2026-52920}
- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristóf)
- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristóf)
- drm/amdgpu: fix spelling typos (Alexandre Demers)
- netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) [Orabug: 39451507] {CVE-2026-45844}
- tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao)
- btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone)
- mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang)
- mailbox: mailbox-test: initialize struct earlier (Wolfram Sang)
- mailbox: mailbox-test: don't free the reused channel (Wolfram Sang)
- mailbox: add sanity check for channel array (Wolfram Sang) [Orabug: 39653234] {CVE-2026-53295}
- cgroup/rdma: fix integer overflow in rdmacg_try_charge() (Tao Cui)
- mailbox: mailbox-test: free channels on probe error (Wolfram Sang)
- fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi)
- rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin)
- fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju)
- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju)
- tipc: fix double-free in tipc_buf_append() (Lee Jones) [Orabug: 39621708] {CVE-2026-52993}
- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev)
- net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet)
- net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet)
- net: sched: gred/red: remove unused variables in struct red_stats (Zhengchao Shao)
- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet)
- net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet)
- net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet)
- ksmbd: scope conn->binding slowpath to bound sessions only (Hyunwoo Kim)
- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (Daemyung Kang)
- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Yan Jun)
- slip: bound decode() reads against the compressed packet length (Weiming Shi) [Orabug: 39451500] {CVE-2026-45843}
- slip: reject VJ receive packets on instances with no rstate array (Weiming Shi) [Orabug: 39451493] {CVE-2026-45842}
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) [Orabug: 39621724] {CVE-2026-52998}
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) [Orabug: 39621730] {CVE-2026-52999}
- ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang)
- netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) [Orabug: 39621740] {CVE-2026-53001}
- netfilter: conntrack: remove sprintf usage (Florian Westphal) [Orabug: 39621746] {CVE-2026-53002}
- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) [Orabug: 39451485] {CVE-2026-45841}
- netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso)
- openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) [Orabug: 39451479] {CVE-2026-45840}
- pppoe: drop PFC frames (Qingfang Deng) [Orabug: 39621751] {CVE-2026-53003}
- flow_dissector: Add number of vlan tags dissector (Boris Sukholitko)
- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) [Orabug: 39621757] {CVE-2026-53004}
- ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) [Orabug: 39621765] {CVE-2026-53006}
- e1000e: Unroll PTP in probe error handling (Matt Vollrath)
- i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju)
- tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) (Eric Dumazet)
- net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) [Orabug: 39621780] {CVE-2026-53011}
- net/sched: taprio: rename close_time to end_time (Vladimir Oltean)
- net/sched: taprio: refactor one skb dequeue from TXQ to separate function (Vladimir Oltean)
- net/sched: taprio: continue with other TXQs if one dequeue() failed (Vladimir Oltean)
- net/sched: taprio: replace safety precautions with comments (Vladimir Oltean)
- net/sched: taprio: stop going through private ops for dequeue and peek (Vladimir Oltean)
- nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) [Orabug: 39621784] {CVE-2026-53012}
- net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu)
- PCMCIA: Fix garbled log messages for KERN_CONT (René Rebe)
- crypto: ccp - copy IV using skcipher ivsize (Paul Moses) [Orabug: 39621796] {CVE-2026-53016}
- crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham)
- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven)
- clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio)
- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio)
- clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven)
- clk: qoriq: avoid format string warning (Arnd Bergmann)
- clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak)
- clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu)
- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu)
- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett)
- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett)
- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett)
- scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) [Orabug: 39621811] {CVE-2026-53021}
- scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yangerkun) [Orabug: 39653261] {CVE-2026-53304}
- RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) [Orabug: 39754131] {CVE-2026-63860}
- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) [Orabug: 39621815] {CVE-2026-53022}
- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin)
- fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou)
- nfs/blocklayout: Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko)
- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal)
- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki)
- tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap)
- tty: hvc: remove HVC_IUCV_MAGIC (Ahelenia Ziemiańska)
- leds: lgm-sso: Remove duplicate assignments for priv->mmap (Chen Ni)
- platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki)
- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni)
- dev_printk: add new dev_err_probe() helpers (Nuno Sa)
- driver core: Move dev_err_probe() to where it belogs (Andy Shevchenko)
- driver core: device.h: remove extern from function prototypes (Greg Kroah-Hartman)
- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai)
- perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo)
- perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan)
- pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin)
- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach)
- perf branch: Avoid incrementing NULL (Ian Rogers)
- pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore)
- HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) [Orabug: 39621857] {CVE-2026-53037}
- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud)
- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav)
- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav)
- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang)
- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen)
- mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni)
- HID: asus: do not abort probe when not necessary (Denis Benato)
- HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato)
- ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges)
- tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou)
- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li)
- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli)
- ocfs2: validate group add input before caching (Zhengyuan Huang) [Orabug: 39621864] {CVE-2026-53039}
- ocfs2: validate bg_bits during freefrag scan (Zhengyuan Huang) [Orabug: 39621868] {CVE-2026-53040}
- ocfs2: fix listxattr handling when the buffer is full (Zhengyuan Huang) [Orabug: 39621872] {CVE-2026-53041}
- soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari)
- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) [Orabug: 39653274] {CVE-2026-53309}
- ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo) [Orabug: 39621878] {CVE-2026-53043}
- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki)
- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberger)
- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov)
- soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov)
- soc: qcom: ocmem: use scoped device node handling to simplify error paths (Krzysztof Kozlowski)
- memory: tegra30-emc: Fix dll_change check (Mikko Perttunen)
- memory: tegra124-emc: Fix dll_change check (Mikko Perttunen)
- ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafał Miłecki)
- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith)
- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) [Orabug: 39621893] {CVE-2026-53047}
- gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) [Orabug: 39621897] {CVE-2026-53048}
- gfs2: add some missing log locking (Andreas Gruenbacher) [Orabug: 39621900] {CVE-2026-53049}
- quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) [Orabug: 39621904] {CVE-2026-53050}
- ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marlière)
- ktest: Honor empty per-test option overrides (Ricardo B. Marlière)
- ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marlière)
- ALSA: sc6000: Keep the programmed board state in card-private data (Cássio Gabriel)
- ALSA: sc6000: Use standard print API (Takashi Iwai)
- PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar)
- PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" (Vidya Sagar)
- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar)
- PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value (Frank Li)
- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long)
- Documentation: fix a hugetlbfs reservation statement (Jane Chu)
- PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer)
- ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang)
- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang)
- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang)
- pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() (Felix Gu)
- pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu)
- drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen)
- drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark)
- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Huanglei)
- ALSA: hda/realtek: Whitespace fix (Luke D. Jones)
- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristóf)
- drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristóf)
- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristóf)
- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristóf)
- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristóf)
- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristóf)
- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristóf)
- ALSA: core: Validate compress device numbers without dynamic minors (Cássio Gabriel)
- drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel)
- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich)
- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao)
- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko)
- dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet)
- drm/sun4i: Fix resource leaks (Ethan Tidmore)
- spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu)
- dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) [Orabug: 39621924] {CVE-2026-53059}
- dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) [Orabug: 39621929] {CVE-2026-53060}
- dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) [Orabug: 39621933] {CVE-2026-53061}
- dm cache: support shrinking the origin device (Ming-Hung Tsai)
- dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai)
- dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) [Orabug: 39621937] {CVE-2026-53062}
- dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai)
- dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) [Orabug: 39621946] {CVE-2026-53064}
- ASoC: sti: use managed regmap_field allocations (Sander Vanheule)
- ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule)
- drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov)
- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) [Orabug: 39621966] {CVE-2026-53069}
- sctp: fix missing encap_port propagation for GSO fragments (Xin Long)
- net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier)
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) [Orabug: 39621973] {CVE-2026-53071}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) [Orabug: 39621976] {CVE-2026-53072}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) [Orabug: 39621980] {CVE-2026-53073}
- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz)
- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) [Orabug: 39621984] {CVE-2026-53074}
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) [Orabug: 39621987] {CVE-2026-53075}
- net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) [Orabug: 39531630] {CVE-2026-46319}
- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen)
- 6pack: propagage new tty types (Jiri Slaby)
- netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal)
- netfilter: xt_socket: enable defrag after all other checks (Florian Westphal)
- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) [Orabug: 39622043] {CVE-2026-53088}
- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi)
- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) [Orabug: 39754142] {CVE-2026-63865}
- bpf-lsm: Make bpf_lsm_userns_create() sleepable (Frederick Lawler)
- wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) [Orabug: 39622061] {CVE-2026-53093}
- bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) [Orabug: 39451462] {CVE-2026-45838}
- macvlan: annotate data-races around port->bc_queue_len_used (Eric Dumazet)
- powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain)
- r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu)
- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) [Orabug: 39622069] {CVE-2026-53096}
- bpf, devmap: Remove unnecessary if check in for loop (Thorsten Blum)
- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu)
- params: Replace __modinit with __init_or_module (Petr Pavlu)
- kernel: globalize lookup_or_create_module_kobject() (Shyam Saini)
- kernel: param: rename locate_module_kobject (Shyam Saini)
- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen)
- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen)
- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) [Orabug: 39622109] {CVE-2026-53112}
- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan)
- firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello)
(Bart Van Assche)
- irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney)
- debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han)
- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon)
- devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich)
- pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt)
- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey)
- drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) [Orabug: 39622158] {CVE-2026-53128}
- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (Hyungjung Joo)
- bcache: fix uninitialized closure object (Mingzhe Zou)
- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng)
- vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) [Orabug: 39460646] {CVE-2026-46214}
- vsock: fix buffer size clamping order (Norbert Szetei) [Orabug: 39460717] {CVE-2026-46234}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) [Orabug: 39445785] {CVE-2026-45836}
- batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) [Orabug: 39460707] {CVE-2026-46231}
- batman-adv: bla: only purge non-released claims (Sven Eckelmann) [Orabug: 39460713] {CVE-2026-46233}
- batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) [Orabug: 39460640] {CVE-2026-46212}
- batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) [Orabug: 39460733] {CVE-2026-46238}
- batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) [Orabug: 39460614] {CVE-2026-46206}
- batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) [Orabug: 39460580] {CVE-2026-46198}
- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) [Orabug: 39460689] {CVE-2026-46227}
- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher)
- drm/amdgpu/pm: add missing revision check for CI (Alex Deucher)
- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) [Orabug: 39460668] {CVE-2026-46220}
- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore)
- drm/radeon: add missing revision check for CI (Alex Deucher)
- drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) [Orabug: 39460573] {CVE-2026-46197}
- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) [Orabug: 39460627] {CVE-2026-46209}
- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) [Orabug: 39460702] {CVE-2026-46230}
- spi: mpc52xx: fix use-after-free on unbind (Johan Hovold)
- spi: orion: fix clock imbalance on registration failure (Johan Hovold)
- spi: imx: fix runtime pm leak on probe deferral (Johan Hovold)
- spi: mtk-nor: fix controller deregistration (Johan Hovold)
- media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu)
- media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov)
- regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold)
- regulator: act8945a: fix OF node reference imbalance (Johan Hovold)
- media: rc: streamzap: Error handling in probe (Oliver Neukum)
- media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum)
- regulator: max77650: fix OF node reference imbalance (Johan Hovold)
- staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus)
- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich)
- media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda)
- platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal)
- mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) [Orabug: 39460450] {CVE-2026-46168}
- mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan)
- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar)
- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar)
- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) [Orabug: 39460540] {CVE-2026-46189}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) [Orabug: 39460303] {CVE-2026-46133}
- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) [Orabug: 39460277] {CVE-2026-46127}
- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) [Orabug: 39460496] {CVE-2026-46178}
- power: supply: max17042: avoid overflow when determining health (André Draszik)
- PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner)
- PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue)
- s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik)
- RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe)
- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) [Orabug: 39524613] {CVE-2026-46304}
- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) [Orabug: 39460415] {CVE-2026-46161}
- libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) [Orabug: 39460244] {CVE-2026-46119}
- isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) [Orabug: 39460265] {CVE-2026-46124}
- isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) [Orabug: 39524609] {CVE-2026-46303}
- dm-verity-fec: correctly reject too-small hash devices (Eric Biggers)
- dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers)
- dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) [Orabug: 39524585] {CVE-2026-46294}
- dm: don't report warning when doing deferred remove (Mikulas Patocka)
- dm-thin: fix metadata refcount underflow (Mikulas Patocka) [Orabug: 39460195] {CVE-2026-46107}
- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cássio Gabriel)
- ASoC: fsl_easrc: fix comment typo (Joseph Salisbury)
- cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde)
- spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold)
- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum)
- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum)
- udf: reject descriptors with oversized CRC length (Michael Bommarito) [Orabug: 39753576] {CVE-2026-53369}
- ibmveth: Disable GSO for packets with small MSS (Mingming Cao)
- hv_sock: fix ARM64 support (Hamza Mahfooz)
- extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang)
- hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak)
- hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan)
- hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan)
- parisc: Fix IRQ leak in LASI driver (Hongling Zeng)
- ip6_gre: Use cached t->net in ip6erspan_changelink(). (Maoyi Xie) [Orabug: 39460248] {CVE-2026-46120}
- sound: ua101: fix division by zero at probe (Seungju Cheon) [Orabug: 39460519] {CVE-2026-46184}
- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Aizen) [Orabug: 39460297] {CVE-2026-46132}
- fanotify: fix false positive on permission events (Miklos Szeredi) [Orabug: 39460374] {CVE-2026-46150}
- spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold)
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) [Orabug: 39445772] {CVE-2026-45834}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39445781] {CVE-2026-45835}
- Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito)
- Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito)
- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) [Orabug: 39460469] {CVE-2026-46172}
- xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li)
- ALSA: firewire-tascam: Do not drop unread control events (Cássio Gabriel)
- usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) [Orabug: 39654820] {CVE-2026-46109}
- USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda)
- USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen)
- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cássio Gabriel)
- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai) [Orabug: 39460352] {CVE-2026-46146}
- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) [Orabug: 39460438] {CVE-2026-46167}
- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) [Orabug: 39460379] {CVE-2026-46151}
- wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) [Orabug: 39460257] {CVE-2026-46122}
- wifi: ath5k: do not access array OOB (Jiri Slaby) [Orabug: 39524622] {CVE-2026-46307}
- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) [Orabug: 39460532] {CVE-2026-46187}
- wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) [Orabug: 39460424] {CVE-2026-46163}
- ipmi:ssif: NULL thread on error (Corey Minyard)
- ipmi:ssif: Remove unnecessary indention (Corey Minyard)
- ipmi:ssif: Clean up kthread on errors (Corey Minyard) [Orabug: 39452264] {CVE-2026-46044}
- ipmi:ssif: Fix a shutdown race (Corey Minyard)
- net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) [Orabug: 39425987] {CVE-2026-43496}
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c (Dipendra Khadka)
- um: virt-pci: Fix build failure (Florian Fainelli)
- spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250891] {CVE-2026-31489}
- ksmbd: do not expire session on binding failure (Hyunwoo Kim)
- spi: rockchip: fix controller deregistration (Johan Hovold)
- ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra)
- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan)
- ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li)
- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta)
- ipmi:si: Return state to normal if message allocation fails (Corey Minyard) [Orabug: 39460202] {CVE-2026-46108}
- ipmi: Check event message buffer response for bad data (Corey Minyard) [Orabug: 39460284] {CVE-2026-46128}
- ipmi: Add limits to event and receive message requests (Corey Minyard) [Orabug: 39460490] {CVE-2026-46177}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [Orabug: 39460368] {CVE-2026-46149}
- netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452465] {CVE-2026-46101}
- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452458] {CVE-2026-46099}
- ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39784983] {CVE-2026-46048}
- drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) [Orabug: 39524543] {CVE-2026-46276}
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426004] {CVE-2026-43501}
- ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai)
- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai)
- driver core: Add kernel-doc for DEV_FLAG_COUNT enum value (Douglas Anderson)
- crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452232] {CVE-2026-46033}
- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer)
- ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner)
- ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner)
- ktest: Fix the month in the name of the failure directory (Steven Rostedt)
- IB/core: Fix zero dmac race in neighbor resolution (Chen Zhao)
- dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452197] {CVE-2026-46023}
- crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum)
- crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li)
- crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier)
- crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum)
- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum)
- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers)
- taskstats: set version in TGID exit notifications (Yiyang Chen)
- tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452160] {CVE-2026-46015}
- inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452251] {CVE-2026-46040}
- md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452350] {CVE-2026-46070}
- md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452288] {CVE-2026-46051}
- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452270] {CVE-2026-46046}
- mtd: docg3: fix use-after-free in docg3_release() (James Kim)
- mtd: docg3: Convert to platform remove callback returning void (Uwe Kleine-König)
- io_uring/poll: fix backport of io_poll_add() changes (Jens Axboe)
- io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored (Jens Axboe)
- KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed)
- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed)
- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed)
- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed)
- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson)
- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452395] {CVE-2026-46082}
- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452062] {CVE-2026-45987}
- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed)
- userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov)
- rtc: ntxec: fix OF node reference imbalance (Johan Hovold)
- tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong)
- mmc: block: use single block write in retry (Bin Liu)
- power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski)
- tpm: avoid -Wunused-but-set-variable (Arnd Bergmann)
- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452202] {CVE-2026-46024}
- ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452244] {CVE-2026-46037}
- drm/arcpgu: fix device node leak (Luca Ceresoli)
- net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li)
- iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos)
- ALSA: 6fire: Fix input volume change detection (Cássio Gabriel)
- ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452127] {CVE-2026-46004}
- ALSA: caiaq: Fix control_put() result and cache rollback (Cássio Gabriel)
- selftests/mqueue: Fix incorrectly named file (Simon Liebold)
- parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller)
- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett)
- md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452285] {CVE-2026-46050}
- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cássio Gabriel)
- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452281] {CVE-2026-46049}
- ALSA: aoa: i2sbus: fix OF node lifetime handling (Cássio Gabriel)
- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452120] {CVE-2026-46002}
- net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452275] {CVE-2026-46047}
- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni)
- lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law)
- Revert "ALSA: usb: Increase volume range that triggers a warning" (Rongrong)
- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den)
- net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452469] {CVE-2026-46102}
- net: caif: clear client service pointer on teardown (Zhengchuan Liang)
- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452417] {CVE-2026-46088}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410864] {CVE-2026-43493}
- um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito)
- driver core: Don't let a device probe until it's ready (Douglas Anderson)
- padata: Remove comment for reorder_work (Herbert Xu)
- padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335056] {CVE-2025-38584}
- ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452389] {CVE-2026-46080}
- device property: Make modifications of fwnode "flags" thread safe (Douglas Anderson)
- scsi: ufs: core: Fix use-after free in init error and remove paths (André Draszik)
- firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann)
- ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu)
- ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu)
- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu)
- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452134] {CVE-2026-46006}
- ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai)
- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michał Pecio)
- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cássio Gabriel)
- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cássio Gabriel)
- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cássio Gabriel) [Orabug: 39452171] {CVE-2026-46018}
- ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park)
- tty: n_gsm: fix flow control handling in tx path (Daniel Starke)
- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento)
- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300568] {CVE-2026-31697}
- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300572] {CVE-2026-31698}
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300576] {CVE-2026-31699}
- ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300587] {CVE-2026-31701}
- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae)
- fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong)
- fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300557] {CVE-2026-31694}
- fs/ntfs3: validate rec->used in journal-replay file record check (Greg Kroah-Hartman)
- iommu: fix a reference count leak in iommu_sva_bind_device() (Vasant Karasulli)
- rxrpc: Fix anonymous key handling (David Howells)
- rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39342679,39368252]
- ksmbd: unset conn->binding on failed binding request (Namjae Jeon)
- scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor)
- Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave" (Guocai He)
- drivers: base: Free devm resources when unregistering a device (David Gow)
- cpufreq: Avoid a bad reference count on CPU node (Miquel Sabaté Solà) [Orabug: 37206351] {CVE-2024-50012}
- net: clear the dst when changing skb protocol (Jakub Kicinski) [Orabug: 38158471] {CVE-2025-38192}
- fbdev: efifb: Register sysfs groups through driver core (Thomas Weißschuh) [Orabug: 37205941] {CVE-2024-49925}
- md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Yu Kuai) [Orabug: 37649831] {CVE-2025-21712}
- cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343645] {CVE-2026-43328}
- cpufreq: governor: Free dbs_data directly when gov->init() fails (Liao Chang)
- rxrpc: Fix recvmsg() unconditional requeue (David Howells)
- fs/ntfs3: Add more attributes checks in mi_enum_attr() (Konstantin Komarov) {CVE-2023-45896}
- btrfs: lock the inode in shared mode before starting fiemap (Filipe Manana)
- f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode (Chao Yu)
- can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (Marc Kleine-Budde) [Orabug: 38773752] {CVE-2025-68307}
- Bluetooth: af_bluetooth: Fix deadlock (Luiz Augusto von Dentz) [Orabug: 36544919] {CVE-2024-26886}
- iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol)
- pstore: inode: Only d_invalidate() is needed (Kees Cook) [Orabug: 36598300] {CVE-2024-27389}
- f2fs: fix to wait on block writeback for post_read case (Chao Yu)
- net: stmmac: fix TSO DMA API usage causing oops (Russell King) [Orabug: 37434619] {CVE-2024-56719}
- drm/amdgpu: unmap and remove csa_va properly (Lang Yu)
- binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773485] {CVE-2025-68239}
- gfs2: No more self recovery (Andreas Gruenbacher) [Orabug: 38351909] {CVE-2025-38659}
- bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO (Kumar Kartikeya Dwivedi)
- dlm: fix possible lkb_resource null dereference (Alexander Aring) [Orabug: 37472202] {CVE-2024-47809}
- Bluetooth: hci_core: Fix use-after-free in vhci_flush() (Kuniyuki Iwashima) [Orabug: 38175068] {CVE-2025-38250}
- mailbox: Prevent out-of-bounds access in of_mbox_index_xlate() (Joonwon Kang)
- btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970329] {CVE-2026-23157}
- btrfs: send: check for inline extents in range_is_hole_in_parent() (Qu Wenruo) [Orabug: 38970284] {CVE-2026-23141}
- x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov)
- spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli)
- fs: dlm: fix use after free in midcomms commit (Alexander Aring)
- dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu)
- net/sched: cls_u32: use skb_header_pointer_careful() (Eric Dumazet) [Orabug: 38970488] {CVE-2026-23204}
- net: add skb_header_pointer_careful() helper (Eric Dumazet)
- dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887637] {CVE-2025-71161}
- blk-mq: use quiesced elevator switch when reinitializing queues (Keith Busch)
- wifi: iwlwifi: read txq->read_ptr under lock (Johannes Berg) [Orabug: 36683388] {CVE-2024-36922}
- f2fs: fix null-ptr-deref in f2fs_submit_page_bio() (Ye Bin)
- s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens)
- ALSA: control: Avoid WARN() for symlink errors (Takashi Iwai) [Orabug: 37434224] {CVE-2024-56657}
- nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() (Jaskaran Singh) [Orabug: 38730673] {CVE-2025-40261}
- Revert "nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()" (Jaskaran Singh)
- tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke)
- MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong)
- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586}
- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598}
- fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li)
- rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu)
- rxrpc: Fix call removal to use RCU safe deletion (David Howells)
- rxrpc: Fix key quota calculation for multitoken keys (David Howells)
- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664}
- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075}
- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076}
- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak)
- Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower" (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak)
- powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini)
- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal)
- PCI/ACPI: Restrict program_hpx_type2() to AER bits (Håkon Bugge)
- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444}
- gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710}
- gfs2: Improve gfs2_consist_inode() usage (Andrew Price)
- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442}
- Revert "net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()" (Sasha Levin)
- Revert "net: ethernet: xscale: Check for PTP support properly" (Sasha Levin)
- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)
- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)
- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)
- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)
- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578}
- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580}
- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581}
- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583}
- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)
- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)
- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588}
- checkpatch: add support for Assisted-by tag (Sasha Levin)
- rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou)
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399}
- smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara)
- fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski)
- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590}
- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596}
- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597}
- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)
- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602}
- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)
- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)
- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brát)
- usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607}
- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman)
- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman)
- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617}
- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619}
- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman)
- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623}
- HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624}
- HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625}
- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626}
- i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman)
- can: raw: fix ro->uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532}
- nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian)
- ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako)
- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki)
- MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki)
- MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki)
- mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler)
- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407}
- i3c: fix uninitialized variable use in i2c setup (Jamie Iles)
- perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079}
- gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda)
- l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080}
- af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673}
- netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685}
- netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681}
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085}
- xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089}
- xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093}
- e1000: check return value of e1000_read_eeprom (Agalakov Daniil)
- tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou)
- nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou)
- ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099}
- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet)
- net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074}
- epoll: use refcount to reduce ep_mutex contention (Paolo Abeni)
- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maíra Canal)
- drm/vc4: Fix a memory leak in hang state error path (Maíra Canal) [Orabug: 39331212] {CVE-2026-43104}
- drm/vc4: Fix memory leak of BO array in hang state (Maíra Canal) [Orabug: 39331216] {CVE-2026-43105}
- PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li)
- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak)
- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai)
- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta)
- wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110}
- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband)
- HID: roccat: fix use-after-free in roccat_report_event (Benoît Sevens) [Orabug: 39331244] {CVE-2026-43111}
- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska)
- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko)
- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover)
- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby)
- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto)
- wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114}
- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (César Montoya)
- btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117}
- can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li)
- ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann)
- LTS version: v5.15.208 (Samasth Norway Ananda)
- LTS version: v5.15.207 (Samasth Norway Ananda)
- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174}
- x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov)
- LTS version: v5.15.206 (Samasth Norway Ananda)
- LTS version: v5.15.205 (Samasth Norway Ananda)
- LTS version: v5.15.204 (Samasth Norway Ananda)
- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787}
- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}

[5.15.0-323.203.2]
- net/mlx5: Add vhca_id_type support to IPsec alias creation (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5: Add vhca_id_type bit to alias context (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman) [Orabug: 38290328]
- net/mlx5e: Fix race condition during IPSec ESN update (Jianbo Liu) [Orabug: 38290328,39167462] {CVE-2026-23440}
- net/mlx5e: Prevent concurrent access to IPSec ASO context (Jianbo Liu) [Orabug: 38290328,39167465] {CVE-2026-23441}
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567286,39668793] {CVE-2026-46331}
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39673870,39753976] {CVE-2026-63807}
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673870,39686460] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39460221,39673870] {CVE-2026-46113}
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Derive shadow MMU page role from parent (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673870]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673870]
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39425999,39751167] {CVE-2026-43499,CVE-2026-53163}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425999,39706512] {CVE-2026-43499}
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659419]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619388,39639981,39648952] {CVE-2026-52943}
- fs/binfmt_elf: validate reserved VA ELF notes (Jianfeng Wang) [Orabug: 39681043]
- mm: preserve page-table boundaries for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- mm: enforce max_map_count for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- fs/kernfs: raise sb->maxbytes to MAX_LFS_FILESIZE (Jane Chu) [Orabug: 39209740]
- uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Dave Kleikamp) [Orabug: 39661609]
- uek-rpm: cnic: Trim the SNIC config for a faster boot (Dave Kleikamp) [Orabug: 39661609]
- net/rds: expand kref coverage to rds_notifier->n_conn (Sharath Srinivasan) [Orabug: 38945572]
- net/rds: fix crash by expanding kref coverage to rds_incoming.i_conn (Sharath Srinivasan) [Orabug: 38945572]
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 39480769]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452260] {CVE-2026-46043}

[5.15.0-323.203.1]
- net/rds: Wait for rdma_cm_event background work to finish (Gerd Rausch) [Orabug: 38112000]
- locking/mutex: Make contention tracepoints more consistent wrt adaptive spinning (Peter Zijlstra) [Orabug: 39598217]
- locking: Apply contention tracepoints in the slow path (Namhyung Kim) [Orabug: 39598217]
- locking: Add lock contention tracepoints (Namhyung Kim) [Orabug: 39598217]
- net/mlx5: Fix EQ IRQ affinity notifier debug messages (Praveen Kumar Kannoju) [Orabug: 39594875]
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39460234] {CVE-2026-46116}
- Revert "rds: ib: Add cm_id generation scheme in order to detect new ones" (Sharath Srinivasan) [Orabug: 39226005]



ELBA-2026-500164 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500164

http://linux.oracle.com/errata/ELBA-2026-500164.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-container-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-container-debug-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-debug-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-debug-devel-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-devel-5.4.17-2136.358.2.1.el8uek.x86_64.rpm
kernel-uek-doc-5.4.17-2136.358.2.1.el8uek.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.4.17-2136.358.2.1.el8uek.src.rpm

Description of changes:

[5.4.17-2136.358.2.1]
- Partial revert of "x86/alternatives: Optimize optimize_nops()" (Harshit Mogalapalli) [Orabug: 39855738]
- Revert "x86/alternatives: Add alt_instr.flags" (Harshit Mogalapalli) [Orabug: 39855738]



ELSA-2026-54290 Moderate: Oracle Linux 8 python-idna security update


Oracle Linux Security Advisory ELSA-2026-54290

http://linux.oracle.com/errata/ELSA-2026-54290.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-idna-2.5-8.el8_10.noarch.rpm

aarch64:
python3-idna-2.5-8.el8_10.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/python-idna-2.5-8.el8_10.src.rpm

Related CVEs:

CVE-2026-45409

Description of changes:

[2.5-8]
- Security fix for CVE-2026-45409
Resolves: RHEL-215650



ELSA-2026-54243 Important: Oracle Linux 8 grafana security update


Oracle Linux Security Advisory ELSA-2026-54243

http://linux.oracle.com/errata/ELSA-2026-54243.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
grafana-9.2.10-32.0.1.el8_10.1.x86_64.rpm
grafana-selinux-9.2.10-32.0.1.el8_10.1.x86_64.rpm

aarch64:
grafana-9.2.10-32.0.1.el8_10.1.aarch64.rpm
grafana-selinux-9.2.10-32.0.1.el8_10.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/grafana-9.2.10-32.0.1.el8_10.1.src.rpm

Related CVEs:

CVE-2026-33377
CVE-2026-42127

Description of changes:

[9.2.10-32.0.1.el8_10.1]
- Fixes CVE-2024-1442 Add email verification when updating user email [Orabug: 38550520]

[9.2.10-32.1]
- Resolves RHEL-219393: CVE-2026-42127
- Resolves RHEL-211017: CVE-2026-33377



ELSA-2026-53848 Important: Oracle Linux 8 isns-utils security update


Oracle Linux Security Advisory ELSA-2026-53848

http://linux.oracle.com/errata/ELSA-2026-53848.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
isns-utils-0.99-1.el8_10.1.x86_64.rpm
isns-utils-devel-0.99-1.el8_10.1.i686.rpm
isns-utils-devel-0.99-1.el8_10.1.x86_64.rpm
isns-utils-libs-0.99-1.el8_10.1.i686.rpm
isns-utils-libs-0.99-1.el8_10.1.x86_64.rpm

aarch64:
isns-utils-0.99-1.el8_10.1.aarch64.rpm
isns-utils-devel-0.99-1.el8_10.1.aarch64.rpm
isns-utils-libs-0.99-1.el8_10.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/isns-utils-0.99-1.el8_10.1.src.rpm

Related CVEs:

CVE-2026-55995

Description of changes:

[0.99-1.1]
- Fix double-free vulnerabilities in attrs.c error paths (CVE-2026-55995)



ELSA-2026-52772 Important: Oracle Linux 8 perl-DBI:1.641 security update


Oracle Linux Security Advisory ELSA-2026-52772

http://linux.oracle.com/errata/ELSA-2026-52772.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
perl-DBI-1.641-8.module+el8.10.0+90986+45c0847f.x86_64.rpm
perl-DBI-1.641-8.module+el8.10.0+90987+dfc813d3.x86_64.rpm

aarch64:
perl-DBI-1.641-8.module+el8.10.0+90986+45c0847f.aarch64.rpm
perl-DBI-1.641-8.module+el8.10.0+90987+dfc813d3.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/perl-DBI-1.641-8.module+el8.10.0+90986+45c0847f.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/perl-DBI-1.641-8.module+el8.10.0+90987+dfc813d3.src.rpm

Related CVEs:

CVE-2026-14380
CVE-2026-14739

Description of changes:

perl-DBI
[1.641-8]
- Fix unsafe string eval in DBI::Profile (CVE-2026-14380)
Resolves: RHEL-211151

[1.641-7]
- Fix patch.

[1.641-6]
- Fix heap overflow when preparsing SQL statements with excessive placeholders (CVE-2026-14739)
Resolves: RHEL-193298

[1.641-5]
- Fix stack overflow and buffer overflow in DBI.xs (CVE-2026-9698)
Resolves: RHEL-184974

[1.641-4]
- BR: perl(blib), perl(FileHandle) for tests

[1.641-3]
- Rebuild with enable hardening (bug #1636329)

[1.641-2]
- Rebuilding for multicontext errata test purposes (rhbz#1666480)

[1.641-1]
- 1.641 bump

[1.640-3]
- Add build-require gcc

[1.640-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

perl-DBI
[1.641-8]
- Fix unsafe string eval in DBI::Profile (CVE-2026-14380)
Resolves: RHEL-211151

[1.641-7]
- Fix patch.

[1.641-6]
- Fix heap overflow when preparsing SQL statements with excessive placeholders (CVE-2026-14739)
Resolves: RHEL-193298

[1.641-5]
- Fix stack overflow and buffer overflow in DBI.xs (CVE-2026-9698)
Resolves: RHEL-184974

[1.641-4]
- BR: perl(blib), perl(FileHandle) for tests

[1.641-3]
- Rebuild with enable hardening (bug #1636329)

[1.641-2]
- Rebuilding for multicontext errata test purposes (rhbz#1666480)

[1.641-1]
- 1.641 bump

[1.640-3]
- Add build-require gcc

[1.640-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild



ELSA-2026-52765 Moderate: Oracle Linux 8 kernel security update


Oracle Linux Security Advisory ELSA-2026-52765

http://linux.oracle.com/errata/ELSA-2026-52765.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.154.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.154.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.154.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.154.1.el8_10.x86_64.rpm
perf-4.18.0-553.154.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.154.1.el8_10.x86_64.rpm

aarch64:
bpftool-4.18.0-553.154.1.el8_10.aarch64.rpm
kernel-cross-headers-4.18.0-553.154.1.el8_10.aarch64.rpm
kernel-headers-4.18.0-553.154.1.el8_10.aarch64.rpm
kernel-tools-4.18.0-553.154.1.el8_10.aarch64.rpm
kernel-tools-libs-4.18.0-553.154.1.el8_10.aarch64.rpm
kernel-tools-libs-devel-4.18.0-553.154.1.el8_10.aarch64.rpm
perf-4.18.0-553.154.1.el8_10.aarch64.rpm
python3-perf-4.18.0-553.154.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.154.1.el8_10.src.rpm

Related CVEs:

CVE-2026-64496

Description of changes:

[4.18.0-553.153.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39832997]

[5.4.17-2136.358.2]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776792] {CVE-2026-64600}
- net: Work around Marvell NIC TX stalls (Venkat Venkatsubra) [Orabug: 39765820]

[5.4.17-2136.358.1]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673871]
- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673871]
- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673871]
- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673871]
- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673871]
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659401]
- net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567287]
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567287] {CVE-2026-46331}
- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39567287]
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39567287]
- net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39567287]
- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39567287]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (hkbinbin) [Orabug: 39452261] {CVE-2026-46043}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39426001]
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39426001] {CVE-2026-43499}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]

[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}

[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}

[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]

[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}

[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]

[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}



ELBA-2026-500148 Oracle Linux 8 systemd bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500148

http://linux.oracle.com/errata/ELBA-2026-500148.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
systemd-239-82.0.13.el8_10.17.i686.rpm
systemd-239-82.0.13.el8_10.17.x86_64.rpm
systemd-container-239-82.0.13.el8_10.17.i686.rpm
systemd-container-239-82.0.13.el8_10.17.x86_64.rpm
systemd-devel-239-82.0.13.el8_10.17.i686.rpm
systemd-devel-239-82.0.13.el8_10.17.x86_64.rpm
systemd-journal-remote-239-82.0.13.el8_10.17.x86_64.rpm
systemd-libs-239-82.0.13.el8_10.17.i686.rpm
systemd-libs-239-82.0.13.el8_10.17.x86_64.rpm
systemd-pam-239-82.0.13.el8_10.17.x86_64.rpm
systemd-tests-239-82.0.13.el8_10.17.x86_64.rpm
systemd-udev-239-82.0.13.el8_10.17.x86_64.rpm

aarch64:
systemd-239-82.0.13.el8_10.17.aarch64.rpm
systemd-container-239-82.0.13.el8_10.17.aarch64.rpm
systemd-devel-239-82.0.13.el8_10.17.aarch64.rpm
systemd-journal-remote-239-82.0.13.el8_10.17.aarch64.rpm
systemd-libs-239-82.0.13.el8_10.17.aarch64.rpm
systemd-pam-239-82.0.13.el8_10.17.aarch64.rpm
systemd-tests-239-82.0.13.el8_10.17.aarch64.rpm
systemd-udev-239-82.0.13.el8_10.17.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/systemd-239-82.0.13.el8_10.17.src.rpm

Description of changes:

[239-82.0.13.el8_10.17]
- coredump: fix %d backport [Orabug: 38584054]



ELBA-2026-500164 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500164

http://linux.oracle.com/errata/ELBA-2026-500164.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-container-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-container-debug-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-debug-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-debug-devel-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-devel-5.4.17-2136.358.2.1.el7uek.x86_64.rpm
kernel-uek-doc-5.4.17-2136.358.2.1.el7uek.noarch.rpm
kernel-uek-tools-5.4.17-2136.358.2.1.el7uek.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-5.4.17-2136.358.2.1.el7uek.src.rpm

Description of changes:

[5.4.17-2136.358.2.1]
- Partial revert of "x86/alternatives: Optimize optimize_nops()" (Harshit Mogalapalli) [Orabug: 39855738]
- Revert "x86/alternatives: Add alt_instr.flags" (Harshit Mogalapalli) [Orabug: 39855738]

[5.4.17-2136.358.2.0.1]
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov (AMD)) [Orabug: 39832992] {CVE-2026-68480}
- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39832992]
- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39832992]
- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39832992]
- x86/alternatives: Add alt_instr.flags (Borislav Petkov (AMD)) [Orabug: 39832992]
- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39832992]
- x86/alternative: Optimize single-byte NOPs at an arbitrary position (Borislav Petkov) [Orabug: 39832992]
- x86/alternative: Align insn bytes vertically (Borislav Petkov) [Orabug: 39832992]
(H. Peter Anvin (Intel)) [Orabug: 39832992]
- x86/alternatives: Optimize optimize_nops() (Peter Zijlstra) [Orabug: 39832992]
- x86: Add insn_decode_kernel() (Peter Zijlstra) [Orabug: 39832992]
- x86/insn: Add an insn_decode() API (Borislav Petkov) [Orabug: 39832992]
- x86/alternative: Use ALTERNATIVE_TERNARY() in _static_cpu_has() (Juergen Gross) [Orabug: 39832992]
- x86/alternative: Support ALTERNATIVE_TERNARY (Juergen Gross) [Orabug: 39832992]
- x86/alternative: Merge include files (Juergen Gross) [Orabug: 39832992]
- x86/alternative: Drop unused feature parameter from ALTINSTR_REPLACEMENT() (Juergen Gross) [Orabug: 39832992]
- x86/insn: Support big endian cross-compiles (Martin Schwidefsky) [Orabug: 39832992]
- x86/tools: Use tools headers for instruction decoder selftests (Vasily Gorbik) [Orabug: 39832992]
- tools headers: Get tools's linux/compiler.h closer to the kernel's (Arnaldo Carvalho de Melo) [Orabug: 39832992]
- perf build: Allow nested externs to enable BUILD_BUG() usage (Vasily Gorbik) [Orabug: 39832992]
- objtool: Allow nested externs to enable BUILD_BUG() (Vasily Gorbik) [Orabug: 39832992]
- objtool: Make relocation in alternative handling arch dependent (Julien Thierry) [Orabug: 39832992]
- x86/alternatives: Add pr_fmt() to debug macros (Borislav Petkov) [Orabug: 39832992]
- tools headers: Adopt verbatim copy of compiletime_assert() from kernel sources (Arnaldo Carvalho de Melo) [Orabug: 39832992]
- x86/alternatives: Teach text_poke_bp() to emulate instructions (Peter Zijlstra) [Orabug: 39832992]
- tools headers: Synchronize linux/bits.h with the kernel sources (Arnaldo Carvalho de Melo) [Orabug: 39832992]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39832997]

[5.4.17-2136.358.2]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776792] {CVE-2026-64600}
- net: Work around Marvell NIC TX stalls (Venkat Venkatsubra) [Orabug: 39765820]

[5.4.17-2136.358.1]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673871]
- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673871]
- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673871]
- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673871]
- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673871]
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659401]
- net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567287]
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567287] {CVE-2026-46331}
- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39567287]
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39567287]
- net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39567287]
- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39567287]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (hkbinbin) [Orabug: 39452261] {CVE-2026-46043}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39426001]
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39426001] {CVE-2026-43499}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]

[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}

[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}

[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]

[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}

[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]

[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}



ELSA-2026-51183 Important: Oracle Linux 7 glib2 security update


Oracle Linux Security Advisory ELSA-2026-51183

http://linux.oracle.com/errata/ELSA-2026-51183.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
glib2-2.56.1-9.0.7.el7_9.i686.rpm
glib2-2.56.1-9.0.7.el7_9.x86_64.rpm
glib2-devel-2.56.1-9.0.7.el7_9.i686.rpm
glib2-devel-2.56.1-9.0.7.el7_9.x86_64.rpm
glib2-doc-2.56.1-9.0.7.el7_9.noarch.rpm
glib2-fam-2.56.1-9.0.7.el7_9.x86_64.rpm
glib2-static-2.56.1-9.0.7.el7_9.i686.rpm
glib2-static-2.56.1-9.0.7.el7_9.x86_64.rpm
glib2-tests-2.56.1-9.0.7.el7_9.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/glib2-2.56.1-9.0.7.el7_9.src.rpm

Related CVEs:

CVE-2026-58016

Description of changes:

[2.56.1-9.0.7]
- Fixes CVE-2026-58016 [Orabug: 39844471]

[2.56.1-9.0.5]
- Fixes CVE-2025-14078 gvariant parser buffer underflow [Orabug: 39418716]

[2.56.1-9.0.3]
- Fixes CVE-2025-13601 g_escape_uri_string() overflow [Orabug: 38909821]

[2.56.1-9.0.1]
- Fix overflow of GDBusConnection serial [Orabug: 38666376]



ELSA-2026-51063 Important: Oracle Linux 7 libXfont2 security update


Oracle Linux Security Advisory ELSA-2026-51063

http://linux.oracle.com/errata/ELSA-2026-51063.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
libXfont2-2.0.3-1.0.1.el7.i686.rpm
libXfont2-2.0.3-1.0.1.el7.x86_64.rpm
libXfont2-devel-2.0.3-1.0.1.el7.i686.rpm
libXfont2-devel-2.0.3-1.0.1.el7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libXfont2-2.0.3-1.0.1.el7.src.rpm

Related CVEs:

CVE-2026-56001
CVE-2026-56002
CVE-2026-56003

Description of changes:

[2.0.3-1.0.1]
- Fix CVE-2026-56001, CVE-2026-56002, and CVE-2026-56003 [Orabug: 39843361]



ELSA-2026-50808 Moderate: Oracle Linux 7 libpng security update


Oracle Linux Security Advisory ELSA-2026-50808

http://linux.oracle.com/errata/ELSA-2026-50808.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpng-1.5.13-8.0.5.el7.i686.rpm
libpng-1.5.13-8.0.5.el7.x86_64.rpm
libpng-devel-1.5.13-8.0.5.el7.i686.rpm
libpng-devel-1.5.13-8.0.5.el7.x86_64.rpm
libpng-static-1.5.13-8.0.5.el7.i686.rpm
libpng-static-1.5.13-8.0.5.el7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libpng-1.5.13-8.0.5.el7.src.rpm

Related CVEs:

CVE-2026-33416

Description of changes:

[2:1.5.13-8.0.5]
- Fix CVE-2026-33416 [Orabug: 39836909]

[2:1.5.13-8.0.3]
- Fix CVE-2026-25646 [Orabug: 39093556]

[2:1.5.13-8.0.1]
- Fix CVE-2025-64720 [Orabug: 38824465]



ELSA-2026-49603 Important: Oracle Linux 7 gstreamer1-plugins-good security update


Oracle Linux Security Advisory ELSA-2026-49603

http://linux.oracle.com/errata/ELSA-2026-49603.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
gstreamer1-plugins-good-1.10.4-2.0.5.el7_9.i686.rpm
gstreamer1-plugins-good-1.10.4-2.0.5.el7_9.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/gstreamer1-plugins-good-1.10.4-2.0.5.el7_9.src.rpm

Related CVEs:

CVE-2026-53705

Description of changes:

[1.10.4-2.0.5]
- Fix CVE-2026-53705 [Orabug: 39822536]

[1.10.4-2.0.3]
- Security update for CVE-2026-3083 CVE-2026-3085 [Orabug: 39199326]

[1.10.4-2.0.1]
- Fixes CVE-2024-47537, CVE-2024-47540, CVE-2024-47613 and
- CVE-2024-47607 [Orabug: 37407070]