Oracle Linux 6534 Published by

Oracle released a batch of security and maintenance patches for Linux versions 7 through 10. The update set addresses vulnerabilities and resolves issues across widely used software including .NET 8.0, .NET 9.0, OpenJDK 17, FreeRDP, nghttp2, BIND, and the Unbreakable Enterprise Kernel. Most advisories carry an Important severity rating, with several moderate patches issued for gnome-remote-desktop and nghttp2.

ELSA-2026-54574 Important: Oracle Linux 9 .NET 8.0 security, bug fix, and enhancement update
ELSA-2026-54512 Moderate: Oracle Linux 10 gnome-remote-desktop security update
ELSA-2026-42887 Important: Oracle Linux 8 java-17-openjdk security update
ELSA-2026-54485 Important: Oracle Linux 8 freerdp security update
ELSA-2026-54650 Moderate: Oracle Linux 10 nghttp2 security update
ELSA-2026-54590 Important: Oracle Linux 10 .NET 9.0 security, bug fix, and enhancement update
ELSA-2026-54541 Important: Oracle Linux 10 .NET 8.0 security, bug fix, and enhancement update
ELBA-2026-500173 Oracle Linux 10 image-builder bug fix update
ELBA-2026-500163 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELSA-2026-54662 Moderate: Oracle Linux 9 nghttp2 security update
ELSA-2026-54510 Important: Oracle Linux 9 bind security update
ELSA-2026-54487 Important: Oracle Linux 9 freerdp security update
ELSA-2026-54509 Important: Oracle Linux 8 bind9.16 security update
ELSA-2026-36083 Important: Oracle Linux 7 xorg-x11-server security update




ELSA-2026-54574 Important: Oracle Linux 9 .NET 8.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54574

http://linux.oracle.com/errata/ELSA-2026-54574.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el9_8.x86_64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el9_8.x86_64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el9_8.x86_64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el9_8.x86_64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el9_8.x86_64.rpm

aarch64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el9_8.aarch64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el9_8.aarch64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el9_8.aarch64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el9_8.aarch64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/dotnet8.0-8.0.130-1.0.1.el9_8.src.rpm

Related CVEs:

CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

Description of changes:

[8.0.130-1.0.1]
- Add support for Oracle Linux

[8.0.130-1]
- Update to .NET SDK 8.0.130 and Runtime 8.0.30
- Resolves: RHEL-235471



ELSA-2026-54512 Moderate: Oracle Linux 10 gnome-remote-desktop security update


Oracle Linux Security Advisory ELSA-2026-54512

http://linux.oracle.com/errata/ELSA-2026-54512.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
gnome-remote-desktop-49.3-4.el10_2.x86_64.rpm

aarch64:
gnome-remote-desktop-49.3-4.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/gnome-remote-desktop-49.3-4.el10_2.src.rpm

Related CVEs:

CVE-2026-18358

Description of changes:

[49.3-4]
- Backport connection throttling



ELSA-2026-42887 Important: Oracle Linux 8 java-17-openjdk security update


Oracle Linux Security Advisory ELSA-2026-42887

http://linux.oracle.com/errata/ELSA-2026-42887.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
java-17-openjdk-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-demo-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-demo-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-demo-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-devel-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-devel-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-devel-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-headless-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-headless-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-headless-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-javadoc-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-javadoc-zip-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-jmods-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-jmods-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-jmods-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-src-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-src-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-src-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-static-libs-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-static-libs-fastdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm
java-17-openjdk-static-libs-slowdebug-17.0.20.0.8-1.1.0.1.el8.x86_64.rpm

aarch64:
java-17-openjdk-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-demo-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-demo-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-demo-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-devel-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-devel-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-devel-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-headless-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-headless-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-headless-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-javadoc-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-javadoc-zip-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-jmods-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-jmods-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-jmods-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-src-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-src-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-src-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-static-libs-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-static-libs-fastdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm
java-17-openjdk-static-libs-slowdebug-17.0.20.0.8-1.1.0.1.el8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/java-17-openjdk-17.0.20.0.8-1.1.0.1.el8.src.rpm

Related CVEs:

CVE-2026-41254
CVE-2026-46917
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-47059
CVE-2026-47063
CVE-2026-60147

Description of changes:

[1:17.0.20.0.8-1.1.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]

[1:17.0.20.0.8-1.1]
- Sync java-17-openjdk-portable.specfile from openjdk-portable-rhel-8
- Add .0 to prelease

[1:17.0.20.0.8-1.1]
- Sync NEWS from private-gnu_andrew-rhel-8.5-vanilla

[1:17.0.20.0.8-1.1]
- Set tzdata requires and build requires to 2026b
- Set fipsver to 821eb26f706
- Delete comments about patch macro syntax
- Set bundled freetype version to 2.14.3
- Set bundled giflib version to 6.1.3
- Set bundled harfbuzz version to 14.2.0
- Set bundled lcms2 version to 2.19.1
- Set bundled libpng version to 1.6.58

[1:17.0.20.0.8-1.1]
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field (OPENJDK-4876)

[1:17.0.20.0.8-1]
- Update to jdk-17.0.20+8 (GA)
- Add to .gitignore openjdk-17.0.20+8.tar.xz
- Set updatever to 20
- Set buildver to 8
- Update sources to openjdk-17.0.20+8.tar.xz
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: RHEL-188876



ELSA-2026-54485 Important: Oracle Linux 8 freerdp security update


Oracle Linux Security Advisory ELSA-2026-54485

http://linux.oracle.com/errata/ELSA-2026-54485.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
freerdp-2.11.7-11.el8_10.x86_64.rpm
freerdp-devel-2.11.7-11.el8_10.i686.rpm
freerdp-devel-2.11.7-11.el8_10.x86_64.rpm
freerdp-libs-2.11.7-11.el8_10.i686.rpm
freerdp-libs-2.11.7-11.el8_10.x86_64.rpm
libwinpr-2.11.7-11.el8_10.i686.rpm
libwinpr-2.11.7-11.el8_10.x86_64.rpm
libwinpr-devel-2.11.7-11.el8_10.i686.rpm
libwinpr-devel-2.11.7-11.el8_10.x86_64.rpm

aarch64:
freerdp-2.11.7-11.el8_10.aarch64.rpm
freerdp-devel-2.11.7-11.el8_10.aarch64.rpm
freerdp-libs-2.11.7-11.el8_10.aarch64.rpm
libwinpr-2.11.7-11.el8_10.aarch64.rpm
libwinpr-devel-2.11.7-11.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/freerdp-2.11.7-11.el8_10.src.rpm

Related CVEs:

CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

Description of changes:

[2:2.11.7-11]
- Backport several CVE fixes (CVE-2026-64624, CVE-2026-67289, CVE-2026-67299,
CVE-2026-68580)
Resolves: RHEL-213173, RHEL-222796, RHEL-222972, RHEL-223606



ELSA-2026-54650 Moderate: Oracle Linux 10 nghttp2 security update


Oracle Linux Security Advisory ELSA-2026-54650

http://linux.oracle.com/errata/ELSA-2026-54650.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libnghttp2-1.68.0-3.el10_2.2.x86_64.rpm
libnghttp2-devel-1.68.0-3.el10_2.2.x86_64.rpm
nghttp2-1.68.0-3.el10_2.2.x86_64.rpm

aarch64:
libnghttp2-1.68.0-3.el10_2.2.aarch64.rpm
libnghttp2-devel-1.68.0-3.el10_2.2.aarch64.rpm
nghttp2-1.68.0-3.el10_2.2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nghttp2-1.68.0-3.el10_2.2.src.rpm

Related CVEs:

CVE-2026-58055

Description of changes:

[1.68.0-3.2]
- fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)



ELSA-2026-54590 Important: Oracle Linux 10 .NET 9.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54590

http://linux.oracle.com/errata/ELSA-2026-54590.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
aspnetcore-runtime-dbg-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
aspnetcore-targeting-pack-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-apphost-pack-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-hostfxr-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-runtime-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-runtime-dbg-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-9.0-9.0.120-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-9.0-source-built-artifacts-9.0.120-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-aot-9.0-9.0.120-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-dbg-9.0-9.0.120-1.0.1.el10_2.x86_64.rpm
dotnet-targeting-pack-9.0-9.0.19-1.0.1.el10_2.x86_64.rpm
dotnet-templates-9.0-9.0.120-1.0.1.el10_2.x86_64.rpm
netstandard-targeting-pack-2.1-9.0.120-1.0.1.el10_2.x86_64.rpm

aarch64:
aspnetcore-runtime-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
aspnetcore-runtime-dbg-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
aspnetcore-targeting-pack-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-apphost-pack-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-hostfxr-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-runtime-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-runtime-dbg-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-9.0-9.0.120-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-9.0-source-built-artifacts-9.0.120-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-aot-9.0-9.0.120-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-dbg-9.0-9.0.120-1.0.1.el10_2.aarch64.rpm
dotnet-targeting-pack-9.0-9.0.19-1.0.1.el10_2.aarch64.rpm
dotnet-templates-9.0-9.0.120-1.0.1.el10_2.aarch64.rpm
netstandard-targeting-pack-2.1-9.0.120-1.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/dotnet9.0-9.0.120-1.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

Description of changes:

[9.0.120-1.0.1]
- Add support for Oracle Linux

[9.0.120-1]
- Update to .NET SDK 9.0.120 and Runtime 9.0.19
- Resolves: RHEL-235477



ELSA-2026-54541 Important: Oracle Linux 10 .NET 8.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54541

http://linux.oracle.com/errata/ELSA-2026-54541.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el10_2.x86_64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el10_2.x86_64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el10_2.x86_64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el10_2.x86_64.rpm

aarch64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el10_2.aarch64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el10_2.aarch64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el10_2.aarch64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/dotnet8.0-8.0.130-1.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

Description of changes:

[8.0.130-1.0.1]
- Add support for Oracle Linux

[8.0.130-1]
- Update to .NET SDK 8.0.130 and Runtime 8.0.30
- Resolves: RHEL-235472



ELBA-2026-500173 Oracle Linux 10 image-builder bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500173

http://linux.oracle.com/errata/ELBA-2026-500173.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
image-builder-72.0.0-1.0.1.el10.x86_64.rpm

aarch64:
image-builder-72.0.0-1.0.1.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/image-builder-72.0.0-1.0.1.el10.src.rpm

Description of changes:

[72.0.0-1.0.1]
- Adopt upstream image-builder 72.0.0 tarball and spec file [Orabug: 39666668]
- Adopt Oracle Linux Support merged upstream in PR 2404



ELBA-2026-500163 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500163

http://linux.oracle.com/errata/ELBA-2026-500163.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-core-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-debug-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-debug-core-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-debug-devel-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-debug-modules-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-devel-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-doc-5.15.0-323.211.3.3.el9uek.noarch.rpm
kernel-uek-modules-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-modules-extra-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-container-5.15.0-323.211.3.3.el9uek.x86_64.rpm
kernel-uek-container-debug-5.15.0-323.211.3.3.el9uek.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-5.15.0-323.211.3.3.el9uek.src.rpm

Description of changes:

[5.15.0-323.211.3.3]
- Revert "x86/alternatives: Add alt_instr.flags" (Harshit Mogalapalli) [Orabug: 39853924]

[5.15.0-323.211.3.2]
- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39848333]
- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39848194]
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39848194] {CVE-2026-64561}
- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39848194]
- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39848194]
- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39848194]
- KVM: x86/mmu: Document the "rules" for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39848194]
- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39848194]
- KVM: x86/mmu: Directly "destroy" PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39848194]
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov (AMD)) [Orabug: 39849605] {CVE-2026-68480}
- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39849605]
- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39849605]
- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39849605]
- x86/alternatives: Add alt_instr.flags (Borislav Petkov (AMD)) [Orabug: 39849605]
- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39849605]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39848314]

[5.15.0-323.211.3.1]
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39816016] {CVE-2026-64531}
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39816098] {CVE-2026-64600}

[5.15.0-323.211.3]
- LTS version: v5.15.211 (Vijayendra Suman)
- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844553] {CVE-2025-23131}
- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786549] {CVE-2026-64529}
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)
- Documentation: ioctl-number: Extend "Include File" column width (Bagas Sanjaya)
- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)
- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753883] {CVE-2026-53388}
- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri) [Orabug: 39637380] {CVE-2026-53157}
- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)
- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)
- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)
- misc: fastrpc: Add dma_mask to fastrpc_channel_ctx (Abel Vesa)
- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)
- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753890] {CVE-2026-53391}
- nfsd: check get_user() return when reading princhashlen (Dominik Woźniak)
- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753905] {CVE-2026-53397}
- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753909] {CVE-2026-53398}
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753928] {CVE-2026-53403}
- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753936] {CVE-2026-63794}
- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753942] {CVE-2026-63796}
- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)
- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753953] {CVE-2026-63800}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753957] {CVE-2026-63801}
- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753963] {CVE-2026-63803}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753979] {CVE-2026-63808}
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)
- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753982] {CVE-2026-63809}
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)
- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754021] {CVE-2026-63822}
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)
- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754024] {CVE-2026-63823}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754028] {CVE-2026-63824}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754053] {CVE-2026-63831}
- crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503789] {CVE-2025-39931}
- ext4: add bounds check for inline data length in ext4_read_inline_page (Yuto Ohnuki)
- ntfs3: reject direct userspace writes to reserved $LX* xattrs (Konstantin Komarov)
- ring-buffer: Remove ring_buffer_read_prepare_sync() (Bjoern Doebel)
- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)
- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)
- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)
- batman-adv: tt: track roam count per VID (Sven Eckelmann)
- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)
- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)
- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)
- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754066] {CVE-2026-63834}
- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754070] {CVE-2026-63835}
- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)
- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)
- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)
- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)
- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)
- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)
- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754076] {CVE-2026-63836}
- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)
- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)
- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)
- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)
- kselftest/arm64: signal: Skip SVE signal test if not enough VLs supported (Yijia Wang)
- Revert "ptp: add testptp mask test" (Petr Machata)
- Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753856] {CVE-2026-53381}
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753871] {CVE-2026-53385}
- regulator: core: fix locking in regulator_resolve_supply() error path (André Draszik) [Orabug: 39489558] {CVE-2026-46252}
- af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) [Orabug: 39619334] {CVE-2026-52928}
- xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman)
- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662073] {CVE-2026-53325}
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)
- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760892] {CVE-2026-64191}
- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg)
- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)
- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)
- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)
- drm/v3d: Skip CSD when it has zeroed workgroups (Maíra Canal)
- drm/v3d: Store the active job inside the queue's state (Maíra Canal)
- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589885] {CVE-2026-52909}
- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637312] {CVE-2026-53138}
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637410] {CVE-2026-53167}
- LTS version: v5.15.210 (Vijayendra Suman)
- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637279] {CVE-2026-53131}
- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)
- batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann)
- ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev)
- Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz)
- media: rc: igorplugusb: fix control request setup packet (Henri A) [Orabug: 39785220] {CVE-2026-64240}
- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) [Orabug: 39784982] {CVE-2026-64092}
- media: rc: ttusbir: fix inverted error logic (Oliver Neukum)
- apparmor: validate default DFA states are in bounds (Ben Hutchings)
- fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter (Ben Hutchings)
- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754146] {CVE-2026-63867}
- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon)
- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni)
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674327] {CVE-2026-53354}
- arm64: cputype: Add NVIDIA Olympus definitions (Shanker Donthineni)
- selinux: enable genfscon labeling for securityfs (Christian Göttsche)
- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt)
- ksmbd: Compare MACs in constant time (Eric Biggers)
- net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343685] {CVE-2026-43341}
- batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann)
- batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) [Orabug: 39460622] {CVE-2026-46208}
- blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (Tejun Heo)
- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451541] {CVE-2026-45850}
- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637477] {CVE-2026-53189}
- RDMA/umem: Fix truncation for block sizes >= 4G (Jason Gunthorpe)
- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)
- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)
- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637516] {CVE-2026-53199}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637292] {CVE-2026-53134}
- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)
- tty: serial: qcom-geni-serial: align #define values (Bartosz Golaszewski)
- tty: serial: qcom-geni-serial: remove unused symbols (Bartosz Golaszewski)
- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)
- serial: altera_jtaguart: Use platform_get_irq_optional() to get the interrupt (Lad Prabhakar)
- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786537] {CVE-2026-64524}
- drm/hyperv: Remove support for Hyper-V 2008 and 2008R2/Win7 (Michael Kelley)
- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)
- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754211] {CVE-2026-63891}
- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)
- usb: gadget: f_hid: tidy error handling in hidg_alloc (John Keeping)
- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)
- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786545] {CVE-2026-64528}
- tty: serial: samsung: use u32 for register interactions (Tudor Ambarus)
- serial: samsung_tty: Use port lock wrappers (Thomas Gleixner)
- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)
- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)
- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)
- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)
- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)
- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681273] {CVE-2026-53358}
- phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang)
- phy: tegra: xusb: Disable trk clk when not in use (Wayne Chang)
- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755010] {CVE-2026-63875}
- spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) [Orabug: 39754942] {CVE-2026-64170}
- spi: qup: switch to use modern name (Yang Yingliang)
- octeontx2-pf: avoid double free of pool->stack on AQ init failure (Dawei Feng)
- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly)
- mptcp: do not drop partial packets (Shardul Bankar)
- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)
- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)
- use less confusing names for iov_iter direction initializers (Al Viro)
- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) [Orabug: 39754825] {CVE-2026-64116}
- ipv6/addrconf: annotate data-races around devconf fields (II) (Eric Dumazet)
- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)
- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754840] {CVE-2026-64123}
- Bluetooth: serialize accept_q access (Jiexun Wang) [Orabug: 39619283] {CVE-2026-52918}
- Bluetooth: Init sk_peer_* on bt_sock_alloc (Luiz Augusto von Dentz)
- Bluetooth: Consolidate code around sk_alloc into a helper function (Luiz Augusto von Dentz)
- qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) [Orabug: 39754830] {CVE-2026-64118}
- Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) [Orabug: 39754849] {CVE-2026-64126}
- Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2 (Luiz Augusto von Dentz)
- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)
- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakuş) [Orabug: 39681270] {CVE-2026-53357}
- smb: client: require net admin for CIFS SWN netlink (Michael Bommarito)
- genetlink: Use internal flags for multicast groups (Ido Schimmel)
- spi: lantiq-ssc: fix controller deregistration (Johan Hovold)
- spi: st-ssc4: fix controller deregistration (Johan Hovold)
- f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu)
- f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang)
- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts)
- mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts) [Orabug: 39460320] {CVE-2026-46137}
- mptcp: pm: prio: skip closed subflows (Matthieu Baerts)
- smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva)
- btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) [Orabug: 39460410] {CVE-2026-46160}
- smb: client: validate dacloffset before building DACL pointers (Michael Bommarito)
- pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) [Orabug: 39524579] {CVE-2026-46292}
- tracing/probes: Limit size of event probe to 3K (Steven Rostedt)
- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) [Orabug: 39460405] {CVE-2026-46159}
- spi: topcliff-pch: fix controller deregistration (Johan Hovold)
- spi: topcliff-pch: Convert to platform remove callback returning void (Uwe Kleine-König)
- fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) [Orabug: 39460548] {CVE-2026-46191}
- mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon)
- spi: uniphier: fix controller deregistration (Johan Hovold)
- spi: tegra20-sflash: fix controller deregistration (Johan Hovold)
- spi: tegra114: fix controller deregistration (Johan Hovold)
- spi: sun6i: fix controller deregistration (Johan Hovold)
- spi: zynq-qspi: fix controller deregistration (Johan Hovold)
- spi: ti-qspi: fix controller deregistration (Johan Hovold)
- spi: spi-ti-qspi: Convert to platform remove callback returning void (Uwe Kleine-König)
- spi: sun4i: fix controller deregistration (Johan Hovold)
- spi: syncuacer: fix controller deregistration (Johan Hovold)
- xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) [Orabug: 39460554] {CVE-2026-46193}
- net: ipv6: stop checking crypto_ahash_alignmask (Eric Biggers)
- net: ipv4: stop checking crypto_ahash_alignmask (Eric Biggers)
- usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan)
- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) [Orabug: 39460504] {CVE-2026-46180}
- usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne)
- smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito)
- tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) [Orabug: 39460568] {CVE-2026-46196}
- crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum)
- printk: add print_hex_dump_devel() (Thorsten Blum)
- ALSA: aloop: Fix peer runtime UAF during format-change stop (Cássio Gabriel) [Orabug: 39452424] {CVE-2026-46090}
- ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452292] {CVE-2026-46052}
- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo)
- can: ucan: fix devres lifetime (Johan Hovold)
- can: ucan: fix typos in comments (Julia Lawall)
- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452305] {CVE-2026-46056}
- hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan)
- hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey)
- udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) [Orabug: 39452078] {CVE-2026-45991}
- mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S)
- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin)
- randomize_kstack: Maintain kstack_offset per task (Ryan Roberts)
- fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) [Orabug: 39452332] {CVE-2026-46065}
- net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452412] {CVE-2026-46086}
- net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452124] {CVE-2026-46003}
- net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming)
- net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452247] {CVE-2026-46038}
- net: qrtr: ns: Change servers radix tree to xarray (Vignesh Viswanathan)
- net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452208] {CVE-2026-46026}
- ALSA: core: Fix potential data race at fasync handling (Takashi Iwai)
- sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury)
- media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452433] {CVE-2026-46091}
- erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang)
- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum)
- media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum)
- ALSA: aoa: i2sbus: clear stale prepared state (Cássio Gabriel)
- ALSA: aoa: Use guard() for mutex locks (Takashi Iwai)
- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452344] {CVE-2026-46069}
- thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452187] {CVE-2026-46021}
- wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452438] {CVE-2026-46092}
- rtw88: 8821ce: Disable PCIe ASPM L1 for 8821CE using chip ID (Jimmy Hon)
- arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual)
- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) [Orabug: 39300581] {CVE-2026-31700}
- ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito)
- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito)
- smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito)
- smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang)
- smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito)
- f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() (Yongpeng Yang)
- f2fs: fix to do sanity check on dcc->discard_cmd_cnt conditionally (Chao Yu)
- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner)
- net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343806] {CVE-2026-43383}
- io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) [Orabug: 39619351] {CVE-2026-52933}
- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)
- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655978] {CVE-2026-52946}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674253] {CVE-2026-53329}
- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637296] {CVE-2026-53135}
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637301] {CVE-2026-53136}
- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland)
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (Bjorn Andersson)
- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637337] {CVE-2026-53146}
- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637346] {CVE-2026-53148}
- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637351] {CVE-2026-53149}
- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637356] {CVE-2026-53150}
- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619338] {CVE-2026-52929}
- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619278] {CVE-2026-52917}
- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)
- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)
- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)
- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)
- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674284] {CVE-2026-53337}
- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)
- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)
- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619342] {CVE-2026-52930}
- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)
- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)
- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)
- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodríguez)
- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)
- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637414] {CVE-2026-53168}
- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637428] {CVE-2026-53176}
- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637432] {CVE-2026-53177}
- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637447] {CVE-2026-53181}
- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)
- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)
- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)
- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)
- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637467] {CVE-2026-53186}
- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)
- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637489] {CVE-2026-53192}
- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637496] {CVE-2026-53194}
- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637502] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637506] {CVE-2026-53196}
- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)
- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674335] {CVE-2026-53356}
- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637545] {CVE-2026-53208}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637555] {CVE-2026-53212}
- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637561] {CVE-2026-53213}
- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)
- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637568] {CVE-2026-53215}
- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)
- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637571] {CVE-2026-53216}
- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637575] {CVE-2026-53217}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637578] {CVE-2026-53218}
- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619384] {CVE-2026-52942}
- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637582] {CVE-2026-53219}
- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637592] {CVE-2026-53221}
- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637599] {CVE-2026-53223}
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637609] {CVE-2026-53225}
- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637618] {CVE-2026-53227}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637622] {CVE-2026-53228}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621562] {CVE-2026-52947}
- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637662] {CVE-2026-53238}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637666] {CVE-2026-53239}
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland)
- KVM: arm64: Remove VPIPT I-cache handling (Marc Zyngier)
- nfsd: don't ignore the return code of svc_proc_register() (Jeff Layton) [Orabug: 37844165] {CVE-2025-22026}
- fs/ntfs3: Return error for inconsistent extended attributes (Edward Lo)
- ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250744] {CVE-2026-31449}
- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)
- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674319] {CVE-2026-53352}
- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619311] {CVE-2026-52924}
- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637680] {CVE-2026-53245}
- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754155] {CVE-2026-63870}
- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637694] {CVE-2026-53249}
- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39785002] {CVE-2026-53252}
- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637706] {CVE-2026-53253}
- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)
- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637711] {CVE-2026-53254}
- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637716] {CVE-2026-53255}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637720] {CVE-2026-53256}
- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson)
- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754149] {CVE-2026-63868}
- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)
- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)
- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637741] {CVE-2026-53263}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637748] {CVE-2026-53264}
- dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39784967] {CVE-2026-53265}
- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637753] {CVE-2026-53266}
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637763] {CVE-2026-53268}
- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637768] {CVE-2026-53269}
- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637772] {CVE-2026-53270}
- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)
- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637782] {CVE-2026-53273}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637790] {CVE-2026-53275}
- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621568] {CVE-2026-52948}
- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)
- compiler-clang.h: Add __diag infrastructure for clang (Nathan Chancellor)
- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754236] {CVE-2026-63898}
- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589889] {CVE-2026-52910}
- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michał Pecio)
- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)
- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)
- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754248] {CVE-2026-63901}
- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)
- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)
- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)
- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754408] {CVE-2026-63956}
- serial: zs: Switch to using channel reset (Maciej W. Rozycki)
- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)
- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)
- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)
- serial: sh-sci: fix memory region release in error path (Hongling Zeng)
- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786542] {CVE-2026-64527}
- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754216] {CVE-2026-63892}
- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754220] {CVE-2026-63893}
- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)
- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)
- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754232] {CVE-2026-63897}
- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754240] {CVE-2026-63899}
- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754244] {CVE-2026-63900}
- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754252] {CVE-2026-63902}
- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754256] {CVE-2026-63903}
- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong)
- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)
- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)
- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754260] {CVE-2026-63904}
- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito) [Orabug: 39754264] {CVE-2026-63905}
- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)
- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)
- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michał Pecio)
- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)
- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)
- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)
- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)
- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolás Bazaes)
- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754271] {CVE-2026-63908}
- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754278] {CVE-2026-63912}
- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)
- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754282] {CVE-2026-63913}
- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)
- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754286] {CVE-2026-63914}
- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)
- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)
- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754294] {CVE-2026-63916}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754298] {CVE-2026-63917}
- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754304] {CVE-2026-63919}
- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754307] {CVE-2026-63920}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754311] {CVE-2026-63921}
- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754315] {CVE-2026-63922}
- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754322] {CVE-2026-63924}
- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754326] {CVE-2026-63925}
- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754329] {CVE-2026-63926}
- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785158] {CVE-2026-64237}
- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754333] {CVE-2026-63927}
- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)
- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)
- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754337] {CVE-2026-63928}
- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)
- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)
- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)
- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)
- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)
- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)
- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)
- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)
- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)
- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)
- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)
- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754375] {CVE-2026-63942}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754387] {CVE-2026-63947}
- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754391] {CVE-2026-63948}
- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619307] {CVE-2026-52923}
- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)
- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)
- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)
- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754412] {CVE-2026-63957}
- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)
- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754428] {CVE-2026-63961}
- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)
- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)
- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)
- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher)
- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)
- phy: mscc: Use PHY_ID_MATCH_VENDOR to minimize PHY ID table (Harini Katakam)
- RDMA/rxe: Fix double free in rxe_srq_from_init (Jiasheng Jiang) [Orabug: 39451551] {CVE-2026-45852}
- Revert "RDMA/rxe: Fix double free in rxe_srq_from_init" (Ben Hutchings)
- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Högander)
- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)
- drm/i915/psr: Read Intel DPCD workaround register (Jouni Högander)
- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Högander)
- wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456849] {CVE-2025-39863}
- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754761] {CVE-2026-64095}
- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754744] {CVE-2026-64090}
- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754748] {CVE-2026-64091}
- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)
- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619357] {CVE-2026-52934}
- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754757] {CVE-2026-64094}
- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)
- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann)
- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754456] {CVE-2026-63971}
- gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (Marco Scardovi)
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754468] {CVE-2026-63975}
- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754471] {CVE-2026-63976}
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754489] {CVE-2026-63984}
- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754492] {CVE-2026-63985}
- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754502] {CVE-2026-63990}
- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)
- ASoC: codecs: simple-mux: Fix enum control bounds check (Cássio Gabriel)
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754510] {CVE-2026-63992}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754513] {CVE-2026-63993}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754516] {CVE-2026-63994}
- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cássio Gabriel)
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754536] {CVE-2026-64002}
- net/iucv: fix locking in .getsockopt (Breno Leitao)
- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)
- net: netlink: don't set nsid on local notifications (Ilya Maximets)
- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)
- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619329] {CVE-2026-52927}
- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754553] {CVE-2026-64007}
- nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee)
- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754558] {CVE-2026-64009}
- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)
- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)
- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)
- dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323060] {CVE-2026-43064}
- drm: Remove plane hsub/vsub alignment requirement for core helpers (Carlos Eduardo Gallo Filho)
- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754570] {CVE-2026-64012}
- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr)
- net/sched: cls_fw: fix NULL dereference of "old" filters before change() (Davide Caratti) [Orabug: 39622011] {CVE-2026-53080}
- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754575] {CVE-2026-64014}
- LTS version: v5.15.209 (Samasth Norway Ananda)
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) [Orabug: 39754586] {CVE-2026-64018}
- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski)
- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko)
- string: add mem_is_zero() helper to check if memory area is all zeros (Jani Nikula)
- net: ag71xx: check error for platform_get_irq (Rosen Penev)
- tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) [Orabug: 39784962] {CVE-2026-64028}
- bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) [Orabug: 39754613] {CVE-2026-64032}
- net: bridge: Flush multicast groups when snooping is disabled (Petr Machata)
- RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li)
- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)
- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) [Orabug: 39754619] {CVE-2026-64034}
- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle)
- net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw (Arınç Ünal)
- net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle)
- net: dsa: mt7530: sync driver-specific behavior of MT7531 variants (Daniel Golle)
- drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) [Orabug: 39754629] {CVE-2026-64039}
- net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) [Orabug: 39754638] {CVE-2026-64046}
- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) [Orabug: 39754642] {CVE-2026-64047}
- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) [Orabug: 39754904] {CVE-2026-64153}
- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao)
- HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn)
- wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) [Orabug: 39754909] {CVE-2026-64155}
- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore)
- net: ethernet: cortina: Carry over frag counter (Linus Walleij)
- net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann)
- net: ethernet: cortina: Make RX SKB per-port (Linus Walleij)
- irqchip/ath79-cpu: Remove unused function (Rosen Penev)
- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos)
- ice: fix locking in ice_dcb_rebuild() (Bart Van Assche)
- tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima)
- netfilter: x_tables: unregister the templates first (Florian Westphal)
- ARM: integrator: Fix early initialization (Guenter Roeck)
- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow)
- kunit: config: Enable KUNIT_DEBUGFS by default (David Gow)
- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla)
- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) [Orabug: 39754932] {CVE-2026-64166}
- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain)
- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain)
- batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) [Orabug: 39754734] {CVE-2026-64088}
- batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) [Orabug: 39754740] {CVE-2026-64089}
- batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) [Orabug: 39619346] {CVE-2026-52931}
- batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann) [Orabug: 39785109] {CVE-2026-64218}
- batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) [Orabug: 39619274] {CVE-2026-52916}
- batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) [Orabug: 39619287] {CVE-2026-52919}
- batman-adv: fix fragment reassembly length accounting (Ruide Cao) [Orabug: 39619266] {CVE-2026-52914}
- batman-adv: dat: handle forward allocation error (Sven Eckelmann)
- batman-adv: clear current gateway during teardown (Ruijie Li) [Orabug: 39619323] {CVE-2026-52926}
- batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) [Orabug: 39754765] {CVE-2026-64096}
- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) [Orabug: 39785113] {CVE-2026-64219}
- drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland)
- drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader)
- drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau)
- device property: set fwnode->secondary to NULL in fwnode_init() (Bartosz Golaszewski) [Orabug: 39785117] {CVE-2026-64220}
- RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito)
- spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold)
- spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold)
- scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) [Orabug: 39754786] {CVE-2026-64103}
- tracing: Do not call map->ops->elt_free() if elt_alloc() fails (Masami Hiramatsu) [Orabug: 39754948] {CVE-2026-64173}
- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) [Orabug: 39754952] {CVE-2026-64174}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) [Orabug: 39754812] {CVE-2026-64113}
- ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (Michael Bommarito) [Orabug: 39754817] {CVE-2026-64114}
- wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung)
- vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) [Orabug: 39754821] {CVE-2026-64115}
- ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt)
- netfilter: ipset: stop hash:* range iteration at end (Nan Li) [Orabug: 39619299] {CVE-2026-52921}
- netfilter: nf_queue: hold bridge skb->dev while queued (Haoze Xie) [Orabug: 39619255] {CVE-2026-52912}
- netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) [Orabug: 39619270] {CVE-2026-52915}
- net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) [Orabug: 39754845] {CVE-2026-64125}
- phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) [Orabug: 39754963] {CVE-2026-64177}
- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) [Orabug: 39523054] {CVE-2026-46275}
- Bluetooth: bnep: Fix UAF read of dev->name (Jann Horn) [Orabug: 39754967] {CVE-2026-64178}
- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal)
- ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) [Orabug: 39754862] {CVE-2026-64133}
- ALSA: ua101: Reject too-short USB descriptors (Cássio Gabriel)
- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain)
- sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) [Orabug: 39754983] {CVE-2026-64185}
- Revert "s390/cio: Fix device lifecycle handling in css_alloc_subchannel()" (Sasha Levin)
- KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (Sean Christopherson) [Orabug: 37901590] {CVE-2025-23141}
- wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300982] {CVE-2026-43052}
- net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (Vladimir Oltean)
- Revert "x86/vdso: Fix output operand size of RDPID" (Sasha Levin)
- s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou)
- io_uring: prevent opcode speculation (Pavel Begunkov) [Orabug: 37702113] {CVE-2025-21863}
- io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) [Orabug: 39523050] {CVE-2026-46274}
- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold)
- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek)
- drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka)
- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcalá)
- libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) [Orabug: 39621580] {CVE-2026-52954}
- libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) [Orabug: 39621584] {CVE-2026-52955}
- libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) [Orabug: 39621592] {CVE-2026-52957}
- libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) [Orabug: 39621596] {CVE-2026-52958}
- powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke)
- ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) [Orabug: 39621609] {CVE-2026-52962}
- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cássio Gabriel) [Orabug: 39621613] {CVE-2026-52963}
- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah)
- KVM: x86: Fix Xen hypercall tracepoint argument assignment (Maqiang)
- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) [Orabug: 39621628] {CVE-2026-52969}
- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia)
- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski)
- netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) [Orabug: 39621633] {CVE-2026-52970}
- audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia) [Orabug: 39653209] {CVE-2026-53287}
- i40e: Cleanup PTP pins on probe failure (Matt Vollrath)
- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) [Orabug: 39655982] {CVE-2026-52972}
- net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet)
- flow_dissector: Do not count vlan tags inside tunnel payload (Qingqing Yang)
- flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) [Orabug: 39524619] {CVE-2026-46306}
- btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) [Orabug: 39784984] {CVE-2026-64164}
- drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristóf)
- drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristóf)
- ALSA: hda/conexant: Fix missing error check for jack detection (Wangdicheng) [Orabug: 39653220] {CVE-2026-53291}
- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (Wangdicheng)
- ALSA: hda/conexant: fix some typos (Oldherl Oh)
- ALSA: hda/conexant: add a new hda codec SN6140 (Bo Liu)
- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet)
- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) [Orabug: 39451517] {CVE-2026-45846}
- ipv6: rename and move ip6_dst_lookup_tunnel() (Beniamino Galvani)
- ipv4: add new arguments to udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: remove "proto" argument from udp_tunnel_dst_lookup() (Beniamino Galvani)
- ipv4: rename and move ip_route_output_tunnel() (Beniamino Galvani)
- sctp: discard stale INIT after handshake completion (Xin Long)
- netfilter: skip recording stale or retransmitted INIT (Xin Long)
- ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt)
- net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher)
- NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts)
- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Dandan Zhang)
- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Jun Zhan) [Orabug: 39621670] {CVE-2026-52982}
- vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) [Orabug: 39619318] {CVE-2026-52925}
- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet)
- net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet)
- net: sched: choke: remove unused variables in struct choke_sched_data (Zhengchao Shao)
- net/sched: netem: validate slot configuration (Stephen Hemminger)
- net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) [Orabug: 39621677] {CVE-2026-52984}
- net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger)
- net: sched: sch_netem: Refactor code in 4-state loss generator (Harshit Mogalapalli)
- netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) [Orabug: 39621681] {CVE-2026-52985}
- cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer)
- scsi: sr: Add memory allocation failure handling for get_capabilities() (Enze Li)
- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [Orabug: 39621685] {CVE-2026-52986}
- netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) [Orabug: 39619293] {CVE-2026-52920}
- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristóf)
- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristóf)
- drm/amdgpu: fix spelling typos (Alexandre Demers)
- netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) [Orabug: 39451507] {CVE-2026-45844}
- tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao)
- btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone)
- mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang)
- mailbox: mailbox-test: initialize struct earlier (Wolfram Sang)
- mailbox: mailbox-test: don't free the reused channel (Wolfram Sang)
- mailbox: add sanity check for channel array (Wolfram Sang) [Orabug: 39653234] {CVE-2026-53295}
- cgroup/rdma: fix integer overflow in rdmacg_try_charge() (Tao Cui)
- mailbox: mailbox-test: free channels on probe error (Wolfram Sang)
- fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi)
- rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin)
- fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju)
- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju)
- tipc: fix double-free in tipc_buf_append() (Lee Jones) [Orabug: 39621708] {CVE-2026-52993}
- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev)
- net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet)
- net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet)
- net: sched: gred/red: remove unused variables in struct red_stats (Zhengchao Shao)
- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet)
- net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet)
- net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet)
- ksmbd: scope conn->binding slowpath to bound sessions only (Hyunwoo Kim)
- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (Daemyung Kang)
- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Yan Jun)
- slip: bound decode() reads against the compressed packet length (Weiming Shi) [Orabug: 39451500] {CVE-2026-45843}
- slip: reject VJ receive packets on instances with no rstate array (Weiming Shi) [Orabug: 39451493] {CVE-2026-45842}
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) [Orabug: 39621724] {CVE-2026-52998}
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) [Orabug: 39621730] {CVE-2026-52999}
- ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang)
- netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) [Orabug: 39621740] {CVE-2026-53001}
- netfilter: conntrack: remove sprintf usage (Florian Westphal) [Orabug: 39621746] {CVE-2026-53002}
- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) [Orabug: 39451485] {CVE-2026-45841}
- netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso)
- openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) [Orabug: 39451479] {CVE-2026-45840}
- pppoe: drop PFC frames (Qingfang Deng) [Orabug: 39621751] {CVE-2026-53003}
- flow_dissector: Add number of vlan tags dissector (Boris Sukholitko)
- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) [Orabug: 39621757] {CVE-2026-53004}
- ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) [Orabug: 39621765] {CVE-2026-53006}
- e1000e: Unroll PTP in probe error handling (Matt Vollrath)
- i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju)
- tcp: annotate data-races around (tp->write_seq - tp->snd_nxt) (Eric Dumazet)
- net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) [Orabug: 39621780] {CVE-2026-53011}
- net/sched: taprio: rename close_time to end_time (Vladimir Oltean)
- net/sched: taprio: refactor one skb dequeue from TXQ to separate function (Vladimir Oltean)
- net/sched: taprio: continue with other TXQs if one dequeue() failed (Vladimir Oltean)
- net/sched: taprio: replace safety precautions with comments (Vladimir Oltean)
- net/sched: taprio: stop going through private ops for dequeue and peek (Vladimir Oltean)
- nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) [Orabug: 39621784] {CVE-2026-53012}
- net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu)
- PCMCIA: Fix garbled log messages for KERN_CONT (René Rebe)
- crypto: ccp - copy IV using skcipher ivsize (Paul Moses) [Orabug: 39621796] {CVE-2026-53016}
- crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham)
- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven)
- clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio)
- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio)
- clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven)
- clk: qoriq: avoid format string warning (Arnd Bergmann)
- clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak)
- clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu)
- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu)
- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett)
- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett)
- clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett)
- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett)
- scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) [Orabug: 39621811] {CVE-2026-53021}
- scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yangerkun) [Orabug: 39653261] {CVE-2026-53304}
- RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) [Orabug: 39754131] {CVE-2026-63860}
- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) [Orabug: 39621815] {CVE-2026-53022}
- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin)
- fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou)
- nfs/blocklayout: Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko)
- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal)
- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki)
- tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap)
- tty: hvc: remove HVC_IUCV_MAGIC (Ahelenia Ziemiańska)
- leds: lgm-sso: Remove duplicate assignments for priv->mmap (Chen Ni)
- platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki)
- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni)
- dev_printk: add new dev_err_probe() helpers (Nuno Sa)
- driver core: Move dev_err_probe() to where it belogs (Andy Shevchenko)
- driver core: device.h: remove extern from function prototypes (Greg Kroah-Hartman)
- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai)
- perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo)
- perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan)
- pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin)
- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach)
- perf branch: Avoid incrementing NULL (Ian Rogers)
- pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore)
- HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) [Orabug: 39621857] {CVE-2026-53037}
- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud)
- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav)
- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav)
- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang)
- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen)
- mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni)
- HID: asus: do not abort probe when not necessary (Denis Benato)
- HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato)
- ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges)
- tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou)
- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li)
- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli)
- ocfs2: validate group add input before caching (Zhengyuan Huang) [Orabug: 39621864] {CVE-2026-53039}
- ocfs2: validate bg_bits during freefrag scan (Zhengyuan Huang) [Orabug: 39621868] {CVE-2026-53040}
- ocfs2: fix listxattr handling when the buffer is full (Zhengyuan Huang) [Orabug: 39621872] {CVE-2026-53041}
- soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari)
- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) [Orabug: 39653274] {CVE-2026-53309}
- ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo) [Orabug: 39621878] {CVE-2026-53043}
- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki)
- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberger)
- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov)
- soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov)
- soc: qcom: ocmem: use scoped device node handling to simplify error paths (Krzysztof Kozlowski)
- memory: tegra30-emc: Fix dll_change check (Mikko Perttunen)
- memory: tegra124-emc: Fix dll_change check (Mikko Perttunen)
- ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafał Miłecki)
- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith)
- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) [Orabug: 39621893] {CVE-2026-53047}
- gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) [Orabug: 39621897] {CVE-2026-53048}
- gfs2: add some missing log locking (Andreas Gruenbacher) [Orabug: 39621900] {CVE-2026-53049}
- quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) [Orabug: 39621904] {CVE-2026-53050}
- ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marlière)
- ktest: Honor empty per-test option overrides (Ricardo B. Marlière)
- ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marlière)
- ALSA: sc6000: Keep the programmed board state in card-private data (Cássio Gabriel)
- ALSA: sc6000: Use standard print API (Takashi Iwai)
- PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar)
- PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-select" (Vidya Sagar)
- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy)
- PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar)
- PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value (Frank Li)
- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long)
- Documentation: fix a hugetlbfs reservation statement (Jane Chu)
- PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer)
- ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang)
- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang)
- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang)
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang)
- pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe() (Felix Gu)
- pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu)
- drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen)
- drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark)
- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Huanglei)
- ALSA: hda/realtek: Whitespace fix (Luke D. Jones)
- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristóf)
- drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristóf)
- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristóf)
- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristóf)
- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristóf)
- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristóf)
- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristóf)
- ALSA: core: Validate compress device numbers without dynamic minors (Cássio Gabriel)
- drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel)
- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich)
- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao)
- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko)
- dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet)
- drm/sun4i: Fix resource leaks (Ethan Tidmore)
- spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu)
- dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) [Orabug: 39621924] {CVE-2026-53059}
- dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) [Orabug: 39621929] {CVE-2026-53060}
- dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) [Orabug: 39621933] {CVE-2026-53061}
- dm cache: support shrinking the origin device (Ming-Hung Tsai)
- dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai)
- dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) [Orabug: 39621937] {CVE-2026-53062}
- dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai)
- dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) [Orabug: 39621946] {CVE-2026-53064}
- ASoC: sti: use managed regmap_field allocations (Sander Vanheule)
- ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule)
- drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov)
- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) [Orabug: 39621966] {CVE-2026-53069}
- sctp: fix missing encap_port propagation for GSO fragments (Xin Long)
- net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier)
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) [Orabug: 39621973] {CVE-2026-53071}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) [Orabug: 39621976] {CVE-2026-53072}
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) [Orabug: 39621980] {CVE-2026-53073}
- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz)
- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) [Orabug: 39621984] {CVE-2026-53074}
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) [Orabug: 39621987] {CVE-2026-53075}
- net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) [Orabug: 39531630] {CVE-2026-46319}
- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen)
- 6pack: propagage new tty types (Jiri Slaby)
- netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal)
- netfilter: xt_socket: enable defrag after all other checks (Florian Westphal)
- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) [Orabug: 39622043] {CVE-2026-53088}
- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi)
- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) [Orabug: 39754142] {CVE-2026-63865}
- bpf-lsm: Make bpf_lsm_userns_create() sleepable (Frederick Lawler)
- wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) [Orabug: 39622061] {CVE-2026-53093}
- bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) [Orabug: 39451462] {CVE-2026-45838}
- macvlan: annotate data-races around port->bc_queue_len_used (Eric Dumazet)
- powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain)
- r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu)
- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) [Orabug: 39622069] {CVE-2026-53096}
- bpf, devmap: Remove unnecessary if check in for loop (Thorsten Blum)
- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu)
- params: Replace __modinit with __init_or_module (Petr Pavlu)
- kernel: globalize lookup_or_create_module_kobject() (Shyam Saini)
- kernel: param: rename locate_module_kobject (Shyam Saini)
- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen)
- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen)
- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) [Orabug: 39622109] {CVE-2026-53112}
- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan)
- firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello)
(Bart Van Assche)
- irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney)
- debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han)
- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon)
- devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich)
- pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt)
- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey)
- drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) [Orabug: 39622158] {CVE-2026-53128}
- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (Hyungjung Joo)
- bcache: fix uninitialized closure object (Mingzhe Zou)
- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng)
- vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) [Orabug: 39460646] {CVE-2026-46214}
- vsock: fix buffer size clamping order (Norbert Szetei) [Orabug: 39460717] {CVE-2026-46234}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) [Orabug: 39445785] {CVE-2026-45836}
- batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) [Orabug: 39460707] {CVE-2026-46231}
- batman-adv: bla: only purge non-released claims (Sven Eckelmann) [Orabug: 39460713] {CVE-2026-46233}
- batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) [Orabug: 39460640] {CVE-2026-46212}
- batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) [Orabug: 39460733] {CVE-2026-46238}
- batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) [Orabug: 39460614] {CVE-2026-46206}
- batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) [Orabug: 39460580] {CVE-2026-46198}
- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) [Orabug: 39460689] {CVE-2026-46227}
- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher)
- drm/amdgpu/pm: add missing revision check for CI (Alex Deucher)
- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) [Orabug: 39460668] {CVE-2026-46220}
- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore)
- drm/radeon: add missing revision check for CI (Alex Deucher)
- drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) [Orabug: 39460573] {CVE-2026-46197}
- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) [Orabug: 39460627] {CVE-2026-46209}
- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) [Orabug: 39460702] {CVE-2026-46230}
- spi: mpc52xx: fix use-after-free on unbind (Johan Hovold)
- spi: orion: fix clock imbalance on registration failure (Johan Hovold)
- spi: imx: fix runtime pm leak on probe deferral (Johan Hovold)
- spi: mtk-nor: fix controller deregistration (Johan Hovold)
- media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu)
- media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov)
- regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold)
- regulator: act8945a: fix OF node reference imbalance (Johan Hovold)
- media: rc: streamzap: Error handling in probe (Oliver Neukum)
- media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum)
- regulator: max77650: fix OF node reference imbalance (Johan Hovold)
- staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus)
- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich)
- media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda)
- platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal)
- mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) [Orabug: 39460450] {CVE-2026-46168}
- mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan)
- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar)
- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar)
- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) [Orabug: 39460540] {CVE-2026-46189}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) [Orabug: 39460303] {CVE-2026-46133}
- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) [Orabug: 39460277] {CVE-2026-46127}
- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) [Orabug: 39460496] {CVE-2026-46178}
- power: supply: max17042: avoid overflow when determining health (André Draszik)
- PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner)
- PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue)
- s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik)
- RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe)
- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) [Orabug: 39524613] {CVE-2026-46304}
- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) [Orabug: 39460415] {CVE-2026-46161}
- libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) [Orabug: 39460244] {CVE-2026-46119}
- isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) [Orabug: 39460265] {CVE-2026-46124}
- isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) [Orabug: 39524609] {CVE-2026-46303}
- dm-verity-fec: correctly reject too-small hash devices (Eric Biggers)
- dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers)
- dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) [Orabug: 39524585] {CVE-2026-46294}
- dm: don't report warning when doing deferred remove (Mikulas Patocka)
- dm-thin: fix metadata refcount underflow (Mikulas Patocka) [Orabug: 39460195] {CVE-2026-46107}
- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cássio Gabriel)
- ASoC: fsl_easrc: fix comment typo (Joseph Salisbury)
- cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde)
- spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold)
- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum)
- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum)
- udf: reject descriptors with oversized CRC length (Michael Bommarito) [Orabug: 39753576] {CVE-2026-53369}
- ibmveth: Disable GSO for packets with small MSS (Mingming Cao)
- hv_sock: fix ARM64 support (Hamza Mahfooz)
- extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang)
- hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak)
- hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan)
- hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan)
- parisc: Fix IRQ leak in LASI driver (Hongling Zeng)
- ip6_gre: Use cached t->net in ip6erspan_changelink(). (Maoyi Xie) [Orabug: 39460248] {CVE-2026-46120}
- sound: ua101: fix division by zero at probe (Seungju Cheon) [Orabug: 39460519] {CVE-2026-46184}
- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Aizen) [Orabug: 39460297] {CVE-2026-46132}
- fanotify: fix false positive on permission events (Miklos Szeredi) [Orabug: 39460374] {CVE-2026-46150}
- spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold)
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) [Orabug: 39445772] {CVE-2026-45834}
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39445781] {CVE-2026-45835}
- Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito)
- Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito)
- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) [Orabug: 39460469] {CVE-2026-46172}
- xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li)
- ALSA: firewire-tascam: Do not drop unread control events (Cássio Gabriel)
- usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) [Orabug: 39654820] {CVE-2026-46109}
- USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda)
- USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen)
- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cássio Gabriel)
- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai) [Orabug: 39460352] {CVE-2026-46146}
- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) [Orabug: 39460438] {CVE-2026-46167}
- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) [Orabug: 39460379] {CVE-2026-46151}
- wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) [Orabug: 39460257] {CVE-2026-46122}
- wifi: ath5k: do not access array OOB (Jiri Slaby) [Orabug: 39524622] {CVE-2026-46307}
- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) [Orabug: 39460532] {CVE-2026-46187}
- wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) [Orabug: 39460424] {CVE-2026-46163}
- ipmi:ssif: NULL thread on error (Corey Minyard)
- ipmi:ssif: Remove unnecessary indention (Corey Minyard)
- ipmi:ssif: Clean up kthread on errors (Corey Minyard) [Orabug: 39452264] {CVE-2026-46044}
- ipmi:ssif: Fix a shutdown race (Corey Minyard)
- net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) [Orabug: 39425987] {CVE-2026-43496}
- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c (Dipendra Khadka)
- um: virt-pci: Fix build failure (Florian Fainelli)
- spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250891] {CVE-2026-31489}
- ksmbd: do not expire session on binding failure (Hyunwoo Kim)
- spi: rockchip: fix controller deregistration (Johan Hovold)
- ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra)
- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan)
- ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li)
- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta)
- ipmi:si: Return state to normal if message allocation fails (Corey Minyard) [Orabug: 39460202] {CVE-2026-46108}
- ipmi: Check event message buffer response for bad data (Corey Minyard) [Orabug: 39460284] {CVE-2026-46128}
- ipmi: Add limits to event and receive message requests (Corey Minyard) [Orabug: 39460490] {CVE-2026-46177}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [Orabug: 39460368] {CVE-2026-46149}
- netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452465] {CVE-2026-46101}
- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452458] {CVE-2026-46099}
- ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39784983] {CVE-2026-46048}
- drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) [Orabug: 39524543] {CVE-2026-46276}
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426004] {CVE-2026-43501}
- ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai)
- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai)
- driver core: Add kernel-doc for DEV_FLAG_COUNT enum value (Douglas Anderson)
- crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452232] {CVE-2026-46033}
- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer)
- ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner)
- ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner)
- ktest: Fix the month in the name of the failure directory (Steven Rostedt)
- IB/core: Fix zero dmac race in neighbor resolution (Chen Zhao)
- dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452197] {CVE-2026-46023}
- crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum)
- crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li)
- crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier)
- crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum)
- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum)
- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers)
- taskstats: set version in TGID exit notifications (Yiyang Chen)
- tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452160] {CVE-2026-46015}
- inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452251] {CVE-2026-46040}
- md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452350] {CVE-2026-46070}
- md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452288] {CVE-2026-46051}
- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452270] {CVE-2026-46046}
- mtd: docg3: fix use-after-free in docg3_release() (James Kim)
- mtd: docg3: Convert to platform remove callback returning void (Uwe Kleine-König)
- io_uring/poll: fix backport of io_poll_add() changes (Jens Axboe)
- io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored (Jens Axboe)
- KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed)
- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed)
- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed)
- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed)
- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson)
- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452395] {CVE-2026-46082}
- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452062] {CVE-2026-45987}
- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed)
- userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov)
- rtc: ntxec: fix OF node reference imbalance (Johan Hovold)
- tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong)
- mmc: block: use single block write in retry (Bin Liu)
- power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski)
- tpm: avoid -Wunused-but-set-variable (Arnd Bergmann)
- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452202] {CVE-2026-46024}
- ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452244] {CVE-2026-46037}
- drm/arcpgu: fix device node leak (Luca Ceresoli)
- net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li)
- iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos)
- ALSA: 6fire: Fix input volume change detection (Cássio Gabriel)
- ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452127] {CVE-2026-46004}
- ALSA: caiaq: Fix control_put() result and cache rollback (Cássio Gabriel)
- selftests/mqueue: Fix incorrectly named file (Simon Liebold)
- parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller)
- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett)
- md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452285] {CVE-2026-46050}
- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cássio Gabriel)
- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452281] {CVE-2026-46049}
- ALSA: aoa: i2sbus: fix OF node lifetime handling (Cássio Gabriel)
- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452120] {CVE-2026-46002}
- net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452275] {CVE-2026-46047}
- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni)
- lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law)
- Revert "ALSA: usb: Increase volume range that triggers a warning" (Rongrong)
- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den)
- net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452469] {CVE-2026-46102}
- net: caif: clear client service pointer on teardown (Zhengchuan Liang)
- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452417] {CVE-2026-46088}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410864] {CVE-2026-43493}
- um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito)
- driver core: Don't let a device probe until it's ready (Douglas Anderson)
- padata: Remove comment for reorder_work (Herbert Xu)
- padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335056] {CVE-2025-38584}
- ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452389] {CVE-2026-46080}
- device property: Make modifications of fwnode "flags" thread safe (Douglas Anderson)
- scsi: ufs: core: Fix use-after free in init error and remove paths (André Draszik)
- firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann)
- ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu)
- ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu)
- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu)
- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452134] {CVE-2026-46006}
- ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai)
- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michał Pecio)
- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cássio Gabriel)
- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cássio Gabriel)
- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cássio Gabriel) [Orabug: 39452171] {CVE-2026-46018}
- ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park)
- tty: n_gsm: fix flow control handling in tx path (Daniel Starke)
- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento)
- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300568] {CVE-2026-31697}
- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300572] {CVE-2026-31698}
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300576] {CVE-2026-31699}
- ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300587] {CVE-2026-31701}
- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae)
- fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong)
- fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300557] {CVE-2026-31694}
- fs/ntfs3: validate rec->used in journal-replay file record check (Greg Kroah-Hartman)
- iommu: fix a reference count leak in iommu_sva_bind_device() (Vasant Karasulli)
- rxrpc: Fix anonymous key handling (David Howells)
- rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39342679,39368252]
- ksmbd: unset conn->binding on failed binding request (Namjae Jeon)
- scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor)
- Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave" (Guocai He)
- drivers: base: Free devm resources when unregistering a device (David Gow)
- cpufreq: Avoid a bad reference count on CPU node (Miquel Sabaté Solà) [Orabug: 37206351] {CVE-2024-50012}
- net: clear the dst when changing skb protocol (Jakub Kicinski) [Orabug: 38158471] {CVE-2025-38192}
- fbdev: efifb: Register sysfs groups through driver core (Thomas Weißschuh) [Orabug: 37205941] {CVE-2024-49925}
- md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Yu Kuai) [Orabug: 37649831] {CVE-2025-21712}
- cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343645] {CVE-2026-43328}
- cpufreq: governor: Free dbs_data directly when gov->init() fails (Liao Chang)
- rxrpc: Fix recvmsg() unconditional requeue (David Howells)
- fs/ntfs3: Add more attributes checks in mi_enum_attr() (Konstantin Komarov) {CVE-2023-45896}
- btrfs: lock the inode in shared mode before starting fiemap (Filipe Manana)
- f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode (Chao Yu)
- can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (Marc Kleine-Budde) [Orabug: 38773752] {CVE-2025-68307}
- Bluetooth: af_bluetooth: Fix deadlock (Luiz Augusto von Dentz) [Orabug: 36544919] {CVE-2024-26886}
- iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol)
- pstore: inode: Only d_invalidate() is needed (Kees Cook) [Orabug: 36598300] {CVE-2024-27389}
- f2fs: fix to wait on block writeback for post_read case (Chao Yu)
- net: stmmac: fix TSO DMA API usage causing oops (Russell King) [Orabug: 37434619] {CVE-2024-56719}
- drm/amdgpu: unmap and remove csa_va properly (Lang Yu)
- binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773485] {CVE-2025-68239}
- gfs2: No more self recovery (Andreas Gruenbacher) [Orabug: 38351909] {CVE-2025-38659}
- bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO (Kumar Kartikeya Dwivedi)
- dlm: fix possible lkb_resource null dereference (Alexander Aring) [Orabug: 37472202] {CVE-2024-47809}
- Bluetooth: hci_core: Fix use-after-free in vhci_flush() (Kuniyuki Iwashima) [Orabug: 38175068] {CVE-2025-38250}
- mailbox: Prevent out-of-bounds access in of_mbox_index_xlate() (Joonwon Kang)
- btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970329] {CVE-2026-23157}
- btrfs: send: check for inline extents in range_is_hole_in_parent() (Qu Wenruo) [Orabug: 38970284] {CVE-2026-23141}
- x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov)
- spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli)
- fs: dlm: fix use after free in midcomms commit (Alexander Aring)
- dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu)
- net/sched: cls_u32: use skb_header_pointer_careful() (Eric Dumazet) [Orabug: 38970488] {CVE-2026-23204}
- net: add skb_header_pointer_careful() helper (Eric Dumazet)
- dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887637] {CVE-2025-71161}
- blk-mq: use quiesced elevator switch when reinitializing queues (Keith Busch)
- wifi: iwlwifi: read txq->read_ptr under lock (Johannes Berg) [Orabug: 36683388] {CVE-2024-36922}
- f2fs: fix null-ptr-deref in f2fs_submit_page_bio() (Ye Bin)
- s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens)
- ALSA: control: Avoid WARN() for symlink errors (Takashi Iwai) [Orabug: 37434224] {CVE-2024-56657}
- nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() (Jaskaran Singh) [Orabug: 38730673] {CVE-2025-40261}
- Revert "nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()" (Jaskaran Singh)
- tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke)
- MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong)
- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586}
- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598}
- fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li)
- rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu)
- rxrpc: Fix call removal to use RCU safe deletion (David Howells)
- rxrpc: Fix key quota calculation for multitoken keys (David Howells)
- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664}
- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075}
- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076}
- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak)
- Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower" (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak)
- arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak)
- powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini)
- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal)
- PCI/ACPI: Restrict program_hpx_type2() to AER bits (Håkon Bugge)
- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444}
- gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710}
- gfs2: Improve gfs2_consist_inode() usage (Andrew Price)
- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442}
- Revert "net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()" (Sasha Levin)
- Revert "net: ethernet: xscale: Check for PTP support properly" (Sasha Levin)
- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)
- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)
- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)
- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)
- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578}
- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580}
- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581}
- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583}
- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)
- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)
- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588}
- checkpatch: add support for Assisted-by tag (Sasha Levin)
- rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou)
- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399}
- smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara)
- fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski)
- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590}
- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596}
- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597}
- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)
- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602}
- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)
- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)
- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brát)
- usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607}
- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman)
- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman)
- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617}
- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)
- ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619}
- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman)
- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623}
- HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624}
- HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625}
- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626}
- i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman)
- can: raw: fix ro->uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532}
- nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian)
- ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako)
- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki)
- MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki)
- MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki)
- mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler)
- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407}
- i3c: fix uninitialized variable use in i2c setup (Jamie Iles)
- perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079}
- gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda)
- l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080}
- af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673}
- netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685}
- netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681}
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085}
- xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089}
- xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093}
- e1000: check return value of e1000_read_eeprom (Agalakov Daniil)
- tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou)
- nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou)
- ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099}
- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet)
- net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074}
- epoll: use refcount to reduce ep_mutex contention (Paolo Abeni)
- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maíra Canal)
- drm/vc4: Fix a memory leak in hang state error path (Maíra Canal) [Orabug: 39331212] {CVE-2026-43104}
- drm/vc4: Fix memory leak of BO array in hang state (Maíra Canal) [Orabug: 39331216] {CVE-2026-43105}
- PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li)
- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak)
- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai)
- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta)
- wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110}
- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband)
- HID: roccat: fix use-after-free in roccat_report_event (Benoît Sevens) [Orabug: 39331244] {CVE-2026-43111}
- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska)
- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko)
- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover)
- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby)
- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto)
- wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114}
- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (César Montoya)
- btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117}
- can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li)
- ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann)
- LTS version: v5.15.208 (Samasth Norway Ananda)
- LTS version: v5.15.207 (Samasth Norway Ananda)
- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174}
- x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov)
- LTS version: v5.15.206 (Samasth Norway Ananda)
- LTS version: v5.15.205 (Samasth Norway Ananda)
- LTS version: v5.15.204 (Samasth Norway Ananda)
- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787}
- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}

[5.15.0-323.203.2]
- net/mlx5: Add vhca_id_type support to IPsec alias creation (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5: Add vhca_id_type bit to alias context (Patrisious Haddad) [Orabug: 38732933]
- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman) [Orabug: 38290328]
- net/mlx5e: Fix race condition during IPSec ESN update (Jianbo Liu) [Orabug: 38290328,39167462] {CVE-2026-23440}
- net/mlx5e: Prevent concurrent access to IPSec ASO context (Jianbo Liu) [Orabug: 38290328,39167465] {CVE-2026-23441}
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567286,39668793] {CVE-2026-46331}
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567286] {CVE-2026-46331}
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39673870,39753976] {CVE-2026-63807}
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673870,39686460] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39460221,39673870] {CVE-2026-46113}
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Derive shadow MMU page role from parent (Paolo Bonzini) [Orabug: 39673870]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673870]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673870]
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39425999,39751167] {CVE-2026-43499,CVE-2026-53163}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425999,39706512] {CVE-2026-43499}
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659419]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619388,39639981,39648952] {CVE-2026-52943}
- fs/binfmt_elf: validate reserved VA ELF notes (Jianfeng Wang) [Orabug: 39681043]
- mm: preserve page-table boundaries for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- mm: enforce max_map_count for reserved VA mappings (Jianfeng Wang) [Orabug: 39681043]
- fs/kernfs: raise sb->maxbytes to MAX_LFS_FILESIZE (Jane Chu) [Orabug: 39209740]
- uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Dave Kleikamp) [Orabug: 39661609]
- uek-rpm: cnic: Trim the SNIC config for a faster boot (Dave Kleikamp) [Orabug: 39661609]
- net/rds: expand kref coverage to rds_notifier->n_conn (Sharath Srinivasan) [Orabug: 38945572]
- net/rds: fix crash by expanding kref coverage to rds_incoming.i_conn (Sharath Srinivasan) [Orabug: 38945572]
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 39480769]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452260] {CVE-2026-46043}

[5.15.0-323.203.1]
- net/rds: Wait for rdma_cm_event background work to finish (Gerd Rausch) [Orabug: 38112000]
- locking/mutex: Make contention tracepoints more consistent wrt adaptive spinning (Peter Zijlstra) [Orabug: 39598217]
- locking: Apply contention tracepoints in the slow path (Namhyung Kim) [Orabug: 39598217]
- locking: Add lock contention tracepoints (Namhyung Kim) [Orabug: 39598217]
- net/mlx5: Fix EQ IRQ affinity notifier debug messages (Praveen Kumar Kannoju) [Orabug: 39594875]
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39460234] {CVE-2026-46116}
- Revert "rds: ib: Add cm_id generation scheme in order to detect new ones" (Sharath Srinivasan) [Orabug: 39226005]



ELSA-2026-54662 Moderate: Oracle Linux 9 nghttp2 security update


Oracle Linux Security Advisory ELSA-2026-54662

http://linux.oracle.com/errata/ELSA-2026-54662.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
libnghttp2-1.43.0-6.el9_8.2.i686.rpm
libnghttp2-1.43.0-6.el9_8.2.x86_64.rpm
libnghttp2-devel-1.43.0-6.el9_8.2.i686.rpm
libnghttp2-devel-1.43.0-6.el9_8.2.x86_64.rpm
nghttp2-1.43.0-6.el9_8.2.x86_64.rpm

aarch64:
libnghttp2-1.43.0-6.el9_8.2.aarch64.rpm
libnghttp2-devel-1.43.0-6.el9_8.2.aarch64.rpm
nghttp2-1.43.0-6.el9_8.2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/nghttp2-1.43.0-6.el9_8.2.src.rpm

Related CVEs:

CVE-2026-58055

Description of changes:

[1.43.0-6.2]
- fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)



ELSA-2026-54510 Important: Oracle Linux 9 bind security update


Oracle Linux Security Advisory ELSA-2026-54510

http://linux.oracle.com/errata/ELSA-2026-54510.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind-9.16.23-40.0.1.el9_8.8.x86_64.rpm
bind-chroot-9.16.23-40.0.1.el9_8.8.x86_64.rpm
bind-devel-9.16.23-40.0.1.el9_8.8.i686.rpm
bind-devel-9.16.23-40.0.1.el9_8.8.x86_64.rpm
bind-dnssec-doc-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-dnssec-utils-9.16.23-40.0.1.el9_8.8.x86_64.rpm
bind-doc-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-libs-9.16.23-40.0.1.el9_8.8.i686.rpm
bind-libs-9.16.23-40.0.1.el9_8.8.x86_64.rpm
bind-license-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-utils-9.16.23-40.0.1.el9_8.8.x86_64.rpm
python3-bind-9.16.23-40.0.1.el9_8.8.noarch.rpm

aarch64:
bind-9.16.23-40.0.1.el9_8.8.aarch64.rpm
bind-chroot-9.16.23-40.0.1.el9_8.8.aarch64.rpm
bind-devel-9.16.23-40.0.1.el9_8.8.aarch64.rpm
bind-dnssec-doc-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-dnssec-utils-9.16.23-40.0.1.el9_8.8.aarch64.rpm
bind-doc-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-libs-9.16.23-40.0.1.el9_8.8.aarch64.rpm
bind-license-9.16.23-40.0.1.el9_8.8.noarch.rpm
bind-utils-9.16.23-40.0.1.el9_8.8.aarch64.rpm
python3-bind-9.16.23-40.0.1.el9_8.8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/bind-9.16.23-40.0.1.el9_8.8.src.rpm

Related CVEs:

CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

Description of changes:

[9.16.23-40.0.1.el9_8.8]
- Fix warning when changing device file permissions [Orabug: 36518580]

[32:9.16.23-40.8]
- Fix NSEC3 signer validation (CVE-2026-10723)

[32:9.16.23-40.7]
- Fix CVE-2026-13321: reject out-of-zone NSEC next owner names

[32:9.16.23-40.6]
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)

[32:9.16.23-40.5]
- Fix dns_rdataset_addnoqname() accepting unsigned NSEC/NSEC3
(CVE-2026-13204)

[32:9.16.23-40.4]
- Fix dnssec-signzone and RRSIG wildcard validation (CVE-2026-11721)

[32:9.16.23-40.3]
- Prevent cache memory exhaustion under sustained attack
(CVE-2026-11622, RHEL-213397)

[32:9.16.23-40.2]
- Fix GSS-API resource leak (CVE-2026-3039)
- Invalid handling of CLASS != IN (CVE-2026-5946)

[32:9.16.23-40.1]
- Prevent Denial of Service via maliciously crafted DNSSEC-validated zone
(CVE-2026-1519)



ELSA-2026-54487 Important: Oracle Linux 9 freerdp security update


Oracle Linux Security Advisory ELSA-2026-54487

http://linux.oracle.com/errata/ELSA-2026-54487.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
freerdp-2.11.7-7.el9_8.5.x86_64.rpm
freerdp-devel-2.11.7-7.el9_8.5.i686.rpm
freerdp-devel-2.11.7-7.el9_8.5.x86_64.rpm
freerdp-libs-2.11.7-7.el9_8.5.i686.rpm
freerdp-libs-2.11.7-7.el9_8.5.x86_64.rpm
libwinpr-2.11.7-7.el9_8.5.i686.rpm
libwinpr-2.11.7-7.el9_8.5.x86_64.rpm
libwinpr-devel-2.11.7-7.el9_8.5.i686.rpm
libwinpr-devel-2.11.7-7.el9_8.5.x86_64.rpm

aarch64:
freerdp-2.11.7-7.el9_8.5.aarch64.rpm
freerdp-devel-2.11.7-7.el9_8.5.aarch64.rpm
freerdp-libs-2.11.7-7.el9_8.5.aarch64.rpm
libwinpr-2.11.7-7.el9_8.5.aarch64.rpm
libwinpr-devel-2.11.7-7.el9_8.5.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/freerdp-2.11.7-7.el9_8.5.src.rpm

Related CVEs:

CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

Description of changes:

[2:2.11.7-7.5]
- Backport several CVE fixes (CVE-2026-64624, CVE-2026-67289, CVE-2026-67299,
CVE-2026-68580)
Resolves: RHEL-213169, RHEL-222785, RHEL-222966, RHEL-223605



ELSA-2026-54509 Important: Oracle Linux 8 bind9.16 security update


Oracle Linux Security Advisory ELSA-2026-54509

http://linux.oracle.com/errata/ELSA-2026-54509.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind9.16-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-chroot-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.i686.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.i686.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm

aarch64:
bind9.16-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-chroot-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-utils-9.16.23-0.22.el8_10.12.aarch64.rpm
python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/bind9.16-9.16.23-0.22.el8_10.12.src.rpm

Related CVEs:

CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

Description of changes:

[32:9.16.23-0.22.12]
- Fix NSEC3 signer validation (CVE-2026-10723)
- Resolves: RHEL-213499

[32:9.16.23-0.22.11]
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)
- Resolves: RHEL-213313

[32:9.16.23-0.22.10]
- Fix CVE-2026-11622: reference-counted DNS cache slab headers
- Resolves: RHEL-213396

[32:9.16.23-0.22.9]
- Fix CVE-2026-11721: RRSIG labels validation and out-of-zone signing
- Add new unit test
- Resolves: RHEL-213406

[32:9.16.23-0.22.8]
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)
- Add upstream rpz system test
- Resolves: RHEL-213478

[32:9.16.23-0.22.7]
- Fix CVE-2026-13204: ensure NSEC/NSEC3 has matching RRSIG
- Resolves: RHEL-213478



ELSA-2026-36083 Important: Oracle Linux 7 xorg-x11-server security update


Oracle Linux Security Advisory ELSA-2026-36083

http://linux.oracle.com/errata/ELSA-2026-36083.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
xorg-x11-server-Xdmx-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-Xephyr-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-Xnest-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-Xorg-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-Xvfb-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-Xwayland-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-common-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-devel-1.20.4-29.0.9.el7_9.i686.rpm
xorg-x11-server-devel-1.20.4-29.0.9.el7_9.x86_64.rpm
xorg-x11-server-source-1.20.4-29.0.9.el7_9.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/xorg-x11-server-1.20.4-29.0.9.el7_9.src.rpm

Related CVEs:

CVE-2026-50256
CVE-2026-50257
CVE-2026-50258
CVE-2026-50259
CVE-2026-50260
CVE-2026-50261
CVE-2026-50262
CVE-2026-50263
CVE-2026-50264

Description of changes:

[1.20.4-29.0.9]
- Security update for CVE-2026-50256 CVE-2026-50257 CVE-2026-50258
CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262
CVE-2026-50263 CVE-2026-50264 [Orabug: 39695293]

* Tue Jun 09 2026 Ronan Pigott 1.20.4-29.0.7
- Security update for CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 CVE-2026-34002 CVE-2026-34003 [Orabug: 39440282]

[1.20.4-29.0.5]
- Security update for CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 [Orabug: 38691191]

[1.20.4-29.0.3]
- Fix CVE-2025-49175, CVE-2025-49176, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 [Orabug: 38157695]

[1.20.4-29.0.1]
- Fixed CVE-2025-26594 CVE-2025-26595 CVE-2025-26596
- CVE-2025-26597 CVE-2025-26598 CVE-2025-26599 CVE-2025-26600
- CVE-2025-26601 [Orabug: 37712847]