-
Wed Oct 29 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-200.51.10.el10uek]
- uek-rpm: Fix packaging fips140.ko.debug files into kernel-uek (Harshit Mogalapalli) [Orabug: 38592440]
- crypto/jitterentropy: do not hand-define core kernel types (Nick Alcock) [Orabug: 38589527]
- net/mlx5: DR, use the right action structs for STEv3 (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: Restore missing trace event when enabling vport QoS (Carolina Jubran) [Orabug: 37984345]
- net/mlx5: Fix vport QoS cleanup on error (Carolina Jubran) [Orabug: 37984345]
- net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq (Stanislav Fomichev) [Orabug: 37984345]
- platform/mellanox: mlxreg-io: use sysfs_emit() instead of sprintf() (Ai Chao) [Orabug: 37984345]
- platform/mellanox: mlxreg-hotplug: use sysfs_emit() instead of sprintf() (Ai Chao) [Orabug: 37984345]
- mlxsw: Do not store Tx header length as driver parameter (Amit Cohen) [Orabug: 37984345]
- mlxsw: Move Tx header handling to PCI driver (Amit Cohen) [Orabug: 37984345]
- mlxsw: Define Tx header fields in txheader.h (Amit Cohen) [Orabug: 37984345]
- mlxsw: Initialize txhdr_info according to PTP operations (Amit Cohen) [Orabug: 37984345]
- mlxsw: Add mlxsw_txhdr_info structure (Amit Cohen) [Orabug: 37984345]
- net/mlx5: fix unintentional sign extension on shift of dest_attr->vport.vhca_id (Colin Ian King) [Orabug: 37984345]
- net/mlx5e: CT: Offload connections with hardware steering rules (Cosmin Ratiu) [Orabug: 37984345]
- net/mlx5e: CT: Make mlx5_ct_fs_smfs_ct_validate_flow_rule reusable (Cosmin Ratiu) [Orabug: 37984345]
- net/mlx5e: CT: Add initial support for Hardware Steering (Cosmin Ratiu) [Orabug: 37984345]
- net/mlx5: HWS, rework the check if matcher size can be increased (Yevgeny Kliteynik) [Orabug: 37984345]
- selftests/net/forwarding: teamd command not found (Alessandro Zanni) [Orabug: 37984345]
- net/mlx5: HWS, update flow - support through bigger action RTC (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, update flow - remove the use of dual RTCs (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: fs, add HWS to steering mode options (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS get capabilities (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, set create match definer to not supported by HWS (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add support for dest vport HWS action (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS fte API functions (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add dest table cache (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, manage flow counters HWS action sharing by refcount (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS modify header API function (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS packet reformat API function (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS actions pool (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS flow group API functions (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS flow table API functions (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: fs, add HWS root namespace functions (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: SHAMPO: Introduce new SHAMPO specific HCA caps (Saeed Mahameed) [Orabug: 37984345]
- net/mlx5: Add support for MRTCQ register (Jianbo Liu) [Orabug: 37984345]
- net/mlx5: Update mlx5_ifc to support FEC for 200G per lane link modes (Jianbo Liu) [Orabug: 37984345]
- netdevsim: add queue management API support (Jakub Kicinski) [Orabug: 37984345]
- netdevsim: add queue alloc/free helpers (Jakub Kicinski) [Orabug: 37984345]
- netdevsim: allocate rqs individually (Jakub Kicinski) [Orabug: 37984345]
- netdevsim: support NAPI config (Jakub Kicinski) [Orabug: 37984345]
- net/mlx5e: Update TX ESN context for IPSec hardware offload (Jianbo Liu) [Orabug: 37984345]
- xfrm: Support ESN context update to hardware for TX (Jianbo Liu) [Orabug: 37984345]
- net/mlx5: HWS, set timeout on polling for completion (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, support flow sampler destination (Vlad Dogaru) [Orabug: 37984345]
- net/mlx5: HWS, use the right size when writing arg data (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, handle returned error value in pool alloc (Vlad Dogaru) [Orabug: 37984345]
- net/mlx5: HWS, separate SQ that HWS uses from the usual traffic SQs (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, num_of_rules counter on matcher should be atomic (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, reduce memory consumption of a matcher struct (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, remove wrong deletion of the miss table list (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, add error message on failure to move rules (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, simplify allocations as we support only FDB (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, denote how refcounts are protected (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, remove implementation of unused FW commands (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, remove the use of duplicated structs (Yevgeny Kliteynik) [Orabug: 37984345]
- RDMA/mlx5: Fix link status down event for MPV (Patrisious Haddad) [Orabug: 37984345]
- RDMA/mlx5: Handle link status event only for LAG device (Yuyu Li) [Orabug: 37984345]
- RDMA/mlx4: Support report_port_event() ops (Yuyu Li) [Orabug: 37984345]
- RDMA/core: Support link status events dispatching (Yuyu Li) [Orabug: 37984345]
- RDMA/core: Add ib_query_netdev_port() to query netdev port by IB device. (Yuyu Li) [Orabug: 37984345]
- RDMA/core: Remove unused ibdev_printk (Dr. David Alan Gilbert) [Orabug: 37984345]
- net/mlx5: Remove PTM support log message (Carolina Jubran) [Orabug: 37984345]
- net/mlx5: DR, add support for ConnectX-8 steering (Itamar Gozlan) [Orabug: 37984345]
- net/mlx5: DR, expand SWS STE callbacks and consolidate common structs (Itamar Gozlan) [Orabug: 37984345]
- net/mlx5: HWS, do not initialize native API queues (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: HWS, no need to expose mlx5hws_send_queues_open/close (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: fs, retry insertion to hash table on EBUSY (Mark Bloch) [Orabug: 37984345]
- net/mlx5: fs, add mlx5_fs_pool API (Moshe Shemesh) [Orabug: 37984345]
- net/mlx5: LAG, Support LAG over Multi-Host NICs (Rongwei Liu) [Orabug: 37984345]
- net/mlx5: LAG, Refactor lag logic (Rongwei Liu) [Orabug: 37984345]
- char:ipmi: Fix a not-used variable on a non-ACPI system (Corey Minyard) [Orabug: 37984345]
- net/mlx5e: Report rx_discards_phy via rx_dropped (Yafang Shao) [Orabug: 37984345]
- mlxsw: Switch to napi_gro_receive() (Ido Schimmel) [Orabug: 37984345]
- net/mlx5: Add device cap abs_native_port_num (Rongwei Liu) [Orabug: 37984345]
- mlxsw: spectrum_flower: Do not allow mixing sample and mirror actions (Ido Schimmel) [Orabug: 37984345]
- RDMA/mlx4: Use DMA iterator to write MTT (Leon Romanovsky) [Orabug: 37984345]
- RDMA/mlx4: Use ib_umem_find_best_pgsz() to calculate MTT size (Leon Romanovsky) [Orabug: 37984345]
- net/mlx5: qos: Add ifc support for cross-esw scheduling (Cosmin Ratiu) [Orabug: 37984345]
- net/mlx5: Add support for new scheduling elements (Carolina Jubran) [Orabug: 37984345]
- net/mlx5: Add ConnectX-8 device to ifc (Yevgeny Kliteynik) [Orabug: 37984345]
- net/mlx5: ifc: Reorganize mlx5_ifc_flow_table_context_bits (Cosmin Ratiu) [Orabug: 37984345]
- RDMA/nldev: Add IB device and net device rename events (Chiara Meiohas) [Orabug: 37984345]
-
Mon Oct 27 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-200.51.9.el10uek]
- net/mlx5: Fix lockdep assertion on sync reset unload event (Moshe Shemesh) [Orabug: 37944844]
- net-shapers: implement cap validation in the core (Paolo Abeni) [Orabug: 37944844]
- net: shaper: implement introspection support (Paolo Abeni) [Orabug: 37944844]
- netlink: spec: add shaper introspection support (Paolo Abeni) [Orabug: 37944844]
- net-shapers: implement shaper cleanup on queue deletion (Paolo Abeni) [Orabug: 37944844]
- net-shapers: implement delete support for NODE scope shaper (Paolo Abeni) [Orabug: 37944844]
- net-shapers: implement NL group operation (Paolo Abeni) [Orabug: 37944844]
- net-shapers: implement NL set and delete operations (Paolo Abeni) [Orabug: 37944844]
- net-shapers: implement NL get operation (Paolo Abeni) [Orabug: 37944844]
- netlink: spec: add shaper YAML spec (Paolo Abeni) [Orabug: 37944844]
- genetlink: extend info user-storage to match NL cb ctx (Paolo Abeni) [Orabug: 37944844]
- EDAC/bluefield: Don't use bluefield_edac_readl() result on error (David Thompson) [Orabug: 37944844]
- xsk: Bring back busy polling support in XDP_COPY (Samiullah Khawaja) [Orabug: 37944844]
- net: page_pool: don't try to stash the napi id (Jakub Kicinski) [Orabug: 37944844]
- xsk: Bring back busy polling support (Stanislav Fomichev) [Orabug: 37944844]
- net: Make napi_hash_lock irq safe (Joe Damato) [Orabug: 37944844]
- virtchnl: fix m68k build. (Paolo Abeni) [Orabug: 37944844]
- net/mlx5: fs, Add support for RDMA RX steering over IB link layer (Patrisious Haddad) [Orabug: 37944844]
- RDMA/mlx5: Extend ODP statistics with operation count (Chiara Meiohas) [Orabug: 37944844]
- Fix a potential abuse of seq_printf() format string in drivers (David Wang) [Orabug: 37944844]
- i2c: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 37944844]
- net/mlx5e: SHAMPO, Rework header allocation loop (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5e: SHAMPO, Drop info array (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5e: SHAMPO, Change frag page setup order during allocation (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5e: SHAMPO, Fix page_index calculation inconsistency (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5e: SHAMPO, Simplify UMR allocation for headers (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5: Make vport QoS enablement more flexible for future extensions (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Integrate esw_qos_vport_enable logic into rate operations (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Generalize scheduling element operations (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Refactor scheduling element configuration bitmasks (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Generalize max_rate and min_rate setting for nodes (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Simplify QoS normalization by removing error handling (Carolina Jubran) [Orabug: 37944844]
- mlx5/core: deduplicate {mlx5_,}eq_update_ci() (Caleb Sander Mateos) [Orabug: 37944844]
- mlx5/core: relax memory barrier in eq_update_ci() (Caleb Sander Mateos) [Orabug: 37944844]
- netdevsim: add more hw_features (Sabrina Dubroca) [Orabug: 37944844]
- mlx5/core: Schedule EQ comp tasklet only if necessary (Caleb Sander Mateos) [Orabug: 37944844]
- mlx5_en: use read sequence for gettimex64 (Vadim Fedorenko) [Orabug: 37944844]
- RDMA/mlx5: Add implementation for ufile_hw_cleanup device operation (Patrisious Haddad) [Orabug: 37944844]
- RDMA/core: Move ib_uverbs_file struct to uverbs_types.h (Patrisious Haddad) [Orabug: 37944844]
- RDMA/core: Add device ufile cleanup operation (Patrisious Haddad) [Orabug: 37944844]
- RDMA/mlx5: Support querying per-plane IB PortCounters (Mark Zhang) [Orabug: 37944844]
- RDMA/mlx5: Support OOO RX WQE consumption (Edward Srouji) [Orabug: 37944844]
- net/mlx5: Introduce data placement ordering bits (Edward Srouji) [Orabug: 37944844]
- net/mlx5e: do not create xdp_redirect for non-uplink rep (William Tu) [Orabug: 37944844]
- net/mlx5e: move XDP_REDIRECT sq to dynamic allocation (William Tu) [Orabug: 37944844]
- net/mlx5: HWS, renamed the files in accordance with naming convention (Yevgeny Kliteynik) [Orabug: 37944844]
- net/mlx5: Rework esw qos domain init and cleanup (Cosmin Ratiu) [Orabug: 37944844]
- dim: pass dim_sample to net_dim() by reference (Caleb Sander Mateos) [Orabug: 37944844]
- dim: make dim_calc_stats() inputs const pointers (Caleb Sander Mateos) [Orabug: 37944844]
- net/mlx5: DPLL, Add clock quality level op implementation (Jiri Pirko) [Orabug: 37944844]
- dpll: add clock quality level attribute and op (Jiri Pirko) [Orabug: 37944844]
- mlx5: simplify EQ interrupt polling logic (Caleb Sander Mateos) [Orabug: 37944844]
- mlx5: fix typo in "mlx5_cqwq_get_cqe_enahnced_comp" (Caleb Sander Mateos) [Orabug: 37944844]
- net/mlx5e: Update features on ring size change (Dragos Tatulea) [Orabug: 37944844]
- net/mlx5e: Update features on MTU change (Dragos Tatulea) [Orabug: 37944844]
- netdevsim: macsec: pad u64 to correct length in logs (Ales Nezbeda) [Orabug: 37944844]
- EDAC/bluefield: Use Arm SMC for EMI access on BlueField-2 (David Thompson) [Orabug: 37944844]
- selftests: mlxsw: devlink_trap_police: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: qos_max_descriptors: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: qos_ets_strict: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: qos_mc_aware: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- selftests: ETS: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- selftests: RED: Use defer for test cleanup (Petr Machata) [Orabug: 37944844]
- net/mlx5: fs, rename modify header struct member action (Moshe Shemesh) [Orabug: 37944844]
- net/mlx5: fs, rename packet reformat struct member action (Moshe Shemesh) [Orabug: 37944844]
- net/mlx5: Only create VEPA flow table when in VEPA mode (Benjamin Poirier) [Orabug: 37944844]
- net/mlx5: Add sync reset drop mode support (Moshe Shemesh) [Orabug: 37944844]
- net/mlx5: Generalize QoS operations for nodes and vports (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Simplify QoS scheduling element configuration (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Remove vport QoS enabled flag (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Refactor vport QoS to use scheduling node structure (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Refactor vport scheduling element creation function (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Introduce node struct and rename group terminology to node (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Rename vport QoS group reference to parent (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Restrict domain list insertion to root TSAR ancestors (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Add parent group support in rate group structure (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Introduce node type to rate group structure (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Refactor QoS group scheduling element creation (Carolina Jubran) [Orabug: 37944844]
- platform/x86: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 37944844]
- mlx4: Add support for persistent NAPI config to RX CQs (Joe Damato) [Orabug: 37944844]
- mlx5: Add support for persistent NAPI config (Joe Damato) [Orabug: 37944844]
- net: napi: Add napi_config (Joe Damato) [Orabug: 37944844]
- net: napi: Make gro_flush_timeout per-NAPI (Joe Damato) [Orabug: 37944844]
- net: napi: Make napi_defer_hard_irqs per-NAPI (Joe Damato) [Orabug: 37944844]
- mmc: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 37944844]
- virtchnl: support queue rate limit and quanta size configuration (Wenjun Wu) [Orabug: 37944844]
- net/mlx5: Add support check for TSAR types in QoS scheduling (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: Unify QoS element type checks across NIC and E-Switch (Carolina Jubran) [Orabug: 37944844]
- net/mlx5: qos: Refactor locking to a qos domain mutex (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Store rate groups in a qos domain (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Rename rate group 'list' as 'parent_entry' (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Add an explicit 'dev' to vport trace calls (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Store the eswitch in a mlx5_esw_rate_group (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Drop 'esw' param from vport qos functions (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Always create group0 (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Maintain rate group vport members in a list (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Refactor and document bw_share calculation (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Consistently name vport vars as 'vport' (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Rename vport 'tsar' into 'sched_elem'. (Cosmin Ratiu) [Orabug: 37944844]
- net/mlx5: qos: Flesh out element_attributes in mlx5_ifc.h (Cosmin Ratiu) [Orabug: 37944844]
- selftests: mlxsw: sch_red_core: Lower TBF rate (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: sch_red_core: Send more packets for drop tests (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: sch_red_core: Sleep before querying queue depth (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: sch_red_core: Increase backlog size tolerance (Petr Machata) [Orabug: 37944844]
- selftests: mlxsw: sch_red_ets: Increase required backlog (Petr Machata) [Orabug: 37944844]
- ipv4: remove fib_info_lock (Eric Dumazet) [Orabug: 37944844]
- ipv4: use rcu in ip_fib_check_default() (Eric Dumazet) [Orabug: 37944844]
- ipv4: remove fib_devindex_hashfn() (Eric Dumazet) [Orabug: 37944844]
- net: ethernet: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 37944844]
- selftests: mlxsw: rtnetlink: Use devlink_reload() API (Amit Cohen) [Orabug: 37944844]
- ipv4: avoid quadratic behavior in FIB insertion of common address (Alexandre Ferrieux) [Orabug: 37944844]
- Revert "net/mlx5: Fix lockdep assertion on sync reset unload event" (Qing Huang) [Orabug: 37944844]
- uek-rpm: BF3: build BF3 smartnic kernel (Thomas Tai) [Orabug: 38551182]
- uek-rpm: BF3: add denylist.txt.S.emb3 and modules.yaml.S.emb3 (Thomas Tai) [Orabug: 38551182]
- uek-rpm: BF3: Add config file for BF3 smartnic (Thomas Tai) [Orabug: 38551182]
- uek: kabi: update kABI files for FIPS symbols (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek: update spec files to include FIPS symvers (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek-rpm: Enable CRYPTO_FIPS140_EXTMOD in the spec file (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert all DECLARE_CRYPTO_API[0-6] macros to DECLARE_CRYPTO_API (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek-rpm: set new FIPS module name (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips/fips140-glue.c: fips_name/fips_version lengths (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/testmgr.c: fix crash in __alg_test_hash (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek-rpm: build FIPS module in kernel-uek.spec (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek-rpm: enable ECDH and ECC configs (Saeed Mirzamohammadi) [Orabug: 38493695]
- uek-rpm: make cryptd built-in to the kernel (Saeed Mirzamohammadi) [Orabug: 38493695]
- scripts/extract-fips: add script to extract FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add zstd to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add lzo-rle to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add lzo to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add lz4hc to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add lz4 to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add crct10dif-ce to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add crct10dif-generic to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add crc32c-generic to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add crc32-generic to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add xxhash64-generic to FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/testmgr: mark xxhash64 as non-cryptographic (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: scripts and glue for FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/fips140: add FIPS 140 module loader (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add ecdh to fips module to fix the TPM issue (Saeed Mirzamohammadi) [Orabug: 38493695]
- arch/arm64/crypto: fix module_cpu_feature_match (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/x86: CRYPTO_MODULE_DEVICE_TABLE (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: change module_init/exit to crypto_module_init/exit (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add lib crypto algos to fips module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add crypto/crypto_null.c to module (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: add sig.c to fips module (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert geniv to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert skcipher to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert rng to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert lskcipher to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert kpp to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert cipher to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert akcipher to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert aead to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- fips: adjust two arm64 symbols (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert asymmetric_keys to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/sha256_generic: embed lib/crypto/sha256.c (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/sha1_generic: embed lib/crypto/sha1.c (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert rsa/rsa_helper to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert ecc to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert aes_generic to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert dh/dh_helper to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert sha256_generic/sha512_generic to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert sha3_generic to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert sha1_generic to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert testmgr to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert hash/shash/ahash to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert cryptd to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert algapi.c to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: convert api.c to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/aes_generic: embed lib/crypto/aes.c (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: only apply crypto API fixups for load_module_mem() (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: avoid modifying struct module (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: add a mechanism for pluggable crypto APIs (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: Kconfig - add CRYPTO_FIPS140_EXTMOD (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: keep initial module reference with MODULE_INIT_MEM (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: fix init_module02 and finit_module02 (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: add MODULE_INIT_MEM flag (Saeed Mirzamohammadi) [Orabug: 38493695]
- module: add load_module_mem() helper (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: make sure crypto_alg_tested() finds the correct algorithm (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: testmgr: check that we got the expected alg (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: alg - add CRYPTO_ALG_FIPS_PROVIDED flag (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: pass struct crypto_alg directly to alg_test() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/testmgr: add helper to alg_test() (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/algapi.c: disable crypto_check_module_sig() for FIPS module (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/algapi: don't init algapi in fips mode (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/testmgr: mark non-crypto algorithms (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/testmgr: make fips_allowed a bit set (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/crypto_user: don't overwrite net->crypto_nlsk on error (Saeed Mirzamohammadi) [Orabug: 38493695]
- certs/system_keyring: export restrict_link_by_builtin_*trusted (Saeed Mirzamohammadi) [Orabug: 38493695]
- lib/crypto/mpi/mpi-bit.c: export mpi_set_bit (Saeed Mirzamohammadi) [Orabug: 38493695]
- arch/x86/boot/string.h: override memmove()/strlen() (Saeed Mirzamohammadi) [Orabug: 38493695]
- libcrc32c: panic on failure (Saeed Mirzamohammadi) [Orabug: 38493695]
- testmgr: standardize alg/driver output in logs (Saeed Mirzamohammadi) [Orabug: 38493695]
- KEYS: trusted: eat -ENOENT from the crypto API (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: hide crypto_default_rng (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto: api - Disallow identical template names (Saeed Mirzamohammadi) [Orabug: 38493695]
- crypto/jitterentropy.c: use kernel's ARRAY_SIZE (Saeed Mirzamohammadi) [Orabug: 38493695]
- params: use arch_initcall (Saeed Mirzamohammadi) [Orabug: 38493695]
- Revert "Revert "crypto: shash - avoid comparing pointers to exported functions under CFI"" (Saeed Mirzamohammadi) [Orabug: 38493695]
- Revert "extract-vmlinux: Check for uncompressed image as fallback" (Saeed Mirzamohammadi) [Orabug: 38493695]
-
Wed Oct 22 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-200.51.8.el10uek]
- cifs: Do not query WSL EAs for native SMB symlink (Pali Rohár) [Orabug: 37978666]
- Fix SMB311 posix special file creation to servers which do not advertise reparse support (Steve French) [Orabug: 37978666]
- smb: client: fix native SMB symlink traversal (Paulo Alcantara) [Orabug: 37978666]
- smb: client: fix regression with native SMB symlinks (Paulo Alcantara) [Orabug: 37978666]
- cifs: Fix support for WSL-style symlinks (Pali Rohár) [Orabug: 37978666]
- cifs: Check if server supports reparse points before using them (Pali Rohár) [Orabug: 37978666]
- cifs: Fix parsing native symlinks directory/file type (Pali Rohár) [Orabug: 37978666]
- cifs: Add support for creating WSL-style symlinks (Pali Rohár) [Orabug: 37978666]
- cifs: Add support for creating NFS-style symlinks (Pali Rohár) [Orabug: 37978666]
- cifs: Add support for creating native Windows sockets (Pali Rohár) [Orabug: 37978666]
- cifs: Add mount option -o reparse=none (Pali Rohár) [Orabug: 37978666]
- cifs: Add mount option -o symlink= for choosing symlink create type (Pali Rohár) [Orabug: 37978666]
- cifs: Fix creating and resolving absolute NT-style symlinks (Pali Rohár) [Orabug: 37978666]
- cifs: Simplify reparse point check in cifs_query_path_info() function (Pali Rohár) [Orabug: 37978666]
- cifs: Rename struct reparse_posix_data to reparse_nfs_data_buffer and move to common/smb2pdu.h (Pali Rohár) [Orabug: 37978666]
- cifs: Remove struct reparse_posix_data from struct cifs_open_info_data (Pali Rohár) [Orabug: 37978666]
- cifs: Remove unicode parameter from parse_reparse_point() function (Pali Rohár) [Orabug: 37978666]
- cifs: Change translation of STATUS_NOT_A_REPARSE_POINT to -ENODATA (Pali Rohár) [Orabug: 37978666]
- cifs: Remove duplicate struct reparse_symlink_data and SYMLINK_FLAG_RELATIVE (Pali Rohár) [Orabug: 37978666]
- smb3: add missing tracepoint for querying wsl EAs (Steve French) [Orabug: 37978666]
- smb3: fix compiler warning in reparse code (Steve French) [Orabug: 37978666]
- cifs: Add support for parsing WSL-style symlinks (Pali Rohár) [Orabug: 37978666]
- cifs: Validate content of native symlink (Pali Rohár) [Orabug: 37978666]
-
Tue Oct 21 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-200.51.7.el10uek]
- uek-rpm: Enable CONFIG_INTEL_TDX_HOST (Liam Merwick) [Orabug: 38359602]
- KVM: TDX: Fix uninitialized error code for __tdx_bringup() (Tony Lindgren) [Orabug: 38359602]
- KVM: TDX: Reject fully in-kernel irqchip if EOIs are protected, i.e. for TDX VMs (Sagi Shahar) [Orabug: 38359602]
- x86/kvm: Force legacy PCI hole to UC when overriding MTRRs for TDX/SNP (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Do not retry locally when the retry is caused by invalid memslot (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Select TDX's KVM_GENERIC_xxx dependencies iff CONFIG_KVM_INTEL_TDX=y (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Remove redundant __GFP_ZERO (Qianfeng Rong) [Orabug: 38359602]
- KVM: TDX: Move TDX hardware setup from main.c to tdx.c (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Use kvm_arch_vcpu.host_debugctl to restore the host's DEBUGCTL (Sean Christopherson) [Orabug: 38359602]
- x86/virt/tdx: Use precalculated TDVPR page physical address (Kai Huang) [Orabug: 38359602]
- KVM/TDX: Explicitly do WBINVD when no more TDX SEAMCALLs (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Update the kexec section in the TDX documentation (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Remove the !KEXEC_CORE dependency (Kai Huang) [Orabug: 38359602]
- x86/kexec: Disable kexec/kdump on platforms with TDX partial write erratum (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Mark memory cache state incoherent when making SEAMCALL (Kai Huang) [Orabug: 38359602]
- x86/sme: Use percpu boolean to control WBINVD during kexec (Kai Huang) [Orabug: 38359602]
- x86/kexec: Consolidate relocate_kernel() function parameters (Kai Huang) [Orabug: 38359602]
- x86/tdx: Skip clearing reclaimed pages unless X86_BUG_TDX_PW_MCE is present (Adrian Hunter) [Orabug: 38359602]
- x86/tdx: Tidy reset_pamt functions (Adrian Hunter) [Orabug: 38359602]
- x86/tdx: Eliminate duplicate code in tdx_clear_page() (Adrian Hunter) [Orabug: 38359602]
- x86/sev: Disable ftrace branch profiling in SEV startup code (Ard Biesheuvel) [Orabug: 38359602]
- x86/kexec: Use typedef for relocate_kernel_fn function prototype (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Cope with relocate_kernel() not being at the start of the page (David Woodhouse) [Orabug: 38359602]
- kexec_core: Add and update comments regarding the KEXEC_JUMP flow (Rafael J. Wysocki) [Orabug: 38359602]
- x86/kexec: Mark machine_kexec() with __nocfi (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Fix location of relocate_kernel with -ffunction-sections (Nathan Chancellor) [Orabug: 38359602]
- x86/kexec: Fix stack and handling of re-entry point for ::preserve_context (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Use correct swap page in swap_pages function (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Ensure preserve_context flag is set on return to kernel (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Disable global pages before writing to control page (David Woodhouse) [Orabug: 38359602]
- x86/sev: Don't hang but terminate on failure to remap SVSM CA (Ard Biesheuvel) [Orabug: 38359602]
- x86/sev: Avoid WARN()s and panic()s in early boot code (Ard Biesheuvel) [Orabug: 38359602]
- x86/sev: Disable UBSAN on SEV code that may execute very early (Ard Biesheuvel) [Orabug: 38359602]
- x86/boot/64: Fix spurious undefined reference when CONFIG_X86_5LEVEL=n, on GCC-12 (Ard Biesheuvel) [Orabug: 38359602]
- x86/kexec: Mark relocate_kernel page as ROX instead of RWX (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Clean up register usage in relocate_kernel() (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Eliminate writes through kernel mapping of relocate_kernel page (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Drop page_list argument from relocate_kernel() (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Add data section to relocate_kernel (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Move relocate_kernel to kernel .data section (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Invoke copy of relocate_kernel() instead of the original (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Copy control page into place in machine_kexec_prepare() (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Only swap pages for ::preserve_context mode (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Use named labels in swap_pages in relocate_kernel_64.S (David Woodhouse) [Orabug: 38359602]
- x86/kexec: Clean up and document register use in relocate_kernel_64.S (David Woodhouse) [Orabug: 38359602]
- KVM: TDX: Report supported optional TDVMCALLs in TDX capabilities (Paolo Bonzini) [Orabug: 38359602]
- KVM: TDX: Exit to userspace for SetupEventNotifyInterrupt (Paolo Bonzini) [Orabug: 38359602]
- KVM: TDX: Exit to userspace for GetTdVmCallInfo (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Handle TDG.VP.VMCALL<GetQuote> (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Add new TDVMCALL status code for unsupported subfuncs (Binbin Wu) [Orabug: 38359602]
- KVM: x86/mmu: Reject direct bits in gpa passed to KVM_PRE_FAULT_MEMORY (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86/mmu: Embed direct bits into gpa for KVM_PRE_FAULT_MEMORY (Paolo Bonzini) [Orabug: 38359602]
- KVM: VMX: use __always_inline for is_td_vcpu and is_td (Edward Adam Davis) [Orabug: 38359602]
- x86/tdx: mark tdh_vp_enter() as __flatten (Paolo Bonzini) [Orabug: 38359602]
- KVM: VMX: Clean up and macrofy x86_ops (Vishal Verma) [Orabug: 38359602]
- KVM: VMX: Define a VMX glue macro for kvm_complete_insn_gp() (Vishal Verma) [Orabug: 38359602]
- KVM: VMX: Move vt_apicv_pre_state_restore() to posted_intr.c and tweak name (Vishal Verma) [Orabug: 38359602]
- KVM: x86: Revert kvm_x86_ops.mem_enc_ioctl() back to an OPTIONAL hook (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Do not use kvm_rip_read() unconditionally for KVM_PROFILING (Adrian Hunter) [Orabug: 38359602]
- KVM: x86: Do not use kvm_rip_read() unconditionally in KVM tracepoints (Adrian Hunter) [Orabug: 38359602]
- x86/tdx: Emit warning if IRQs are enabled during HLT #VE handling (Vishal Annapurve) [Orabug: 38359602]
- x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT (Kirill A. Shutemov) [Orabug: 38359602]
- Documentation/virt/kvm: Document on Trust Domain Extensions (TDX) (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Make TDX VM type supported (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: KVM: TDX: Always honor guest PAT on TDX enabled guests (Yan Zhao) [Orabug: 38359602]
- KVM: x86: remove shadow_memtype_mask (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86: Introduce Intel specific quirk KVM_X86_QUIRK_IGNORE_GUEST_PAT (Yan Zhao) [Orabug: 38359602]
- KVM: x86: Quirk initialization of feature MSRs to KVM's max configuration (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Co-locate initialization of feature MSRs in kvm_arch_vcpu_create() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Introduce supported_quirks to block disabling quirks (Yan Zhao) [Orabug: 38359602]
- KVM: x86: Allow vendor code to disable quirks (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86: do not allow re-enabling quirks (Paolo Bonzini) [Orabug: 38359602]
- KVM: TDX: Enable guest access to MTRR MSRs (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Add a method to ignore hypercall patching (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Ignore setting up mce (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add methods to ignore accesses to TSC (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add methods to ignore VMX preemption timer (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add method to ignore guest instruction emulation (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add methods to ignore accesses to CPU state (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Bypass register cache when querying CPL from kvm_sched_out() (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Handle TDG.VP.VMCALL<GetTdVmCallInfo> hypercall (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Enable guest access to LMCE related MSRs (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle TDX PV rdmsr/wrmsr hypercall (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Implement callbacks for MSR operations (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Move KVM_MAX_MCE_BANKS to header file (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle TDX PV HLT hypercall (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle TDX PV CPUID hypercall (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Kick off vCPUs when SEAMCALL is busy during TD page removal (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Retry locally in TDX EPT violation handler on RET_PF_RETRY (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Detect unexpected SEPT violations due to pending SPTEs (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Handle EPT violation/misconfig exit (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle EXIT_REASON_OTHER_SMI (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle EXCEPTION_NMI and EXTERNAL_INTERRUPT (Isaku Yamahata) [Orabug: 38359602]
- KVM: VMX: Add a helper for NMI handling (Sean Christopherson) [Orabug: 38359602]
- KVM: VMX: Move emulation_required to struct vcpu_vt (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Add methods to ignore virtual apic related operation (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Force APICv active for TDX guest (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Enforce KVM_IRQCHIP_SPLIT for TDX guests (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Always block INIT/SIPI (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle SMI request as !CONFIG_KVM_SMM (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Implement methods to inject NMI (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Wait lapic expire when timer IRQ was injected (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Assume timer IRQ was injected if APIC state is protected (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Implement non-NMI interrupt injection (Isaku Yamahata) [Orabug: 38359602]
- KVM: VMX: Move posted interrupt delivery code to common header (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Disable PI wakeup for IPIv (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add support for find pending IRQ in a protected local APIC (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Handle TDX PV MMIO hypercall (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Handle TDX PV port I/O hypercall (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle TDG.VP.VMCALL<ReportFatalError> (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Handle TDG.VP.VMCALL<MapGPA> (Binbin Wu) [Orabug: 38359602]
- KVM: TDX: Handle KVM hypercall with TDG.VP.VMCALL (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add a place holder for handler of TDX hypercalls (TDG.VP.VMCALL) (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add a place holder to handle TDX VM exit (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Move pv_unhalted check out of kvm_vcpu_has_events() (Binbin Wu) [Orabug: 38359602]
- KVM: x86: Have ____kvm_emulate_hypercall() read the GPRs (Binbin Wu) [Orabug: 38359602]
- KVM: x86: Add a switch_db_regs flag to handle TDX's auto-switched behavior (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Save and restore IA32_DEBUGCTL (Adrian Hunter) [Orabug: 38359602]
- KVM: TDX: Disable support for TSX and WAITPKG (Adrian Hunter) [Orabug: 38359602]
- KVM: TDX: restore user ret MSRs (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Allow to update cached values in kvm_user_return_msrs w/o wrmsr (Chao Gao) [Orabug: 38359602]
- KVM: TDX: restore host xsave state when exit from the guest TD (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: vcpu_run: save/restore host state(host kernel gs) (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Implement TDX vcpu enter/exit path (Isaku Yamahata) [Orabug: 38359602]
- KVM: VMX: Move common fields of struct vcpu_{vmx,tdx} to a struct (Binbin Wu) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrapper to enter/exit TDX guest (Kai Huang) [Orabug: 38359602]
- KVM: TDX: Handle SEPT zap error due to page add error in premap (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Skip updating CPU dirty logging request for TDs (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86: Make cpu_dirty_log_size a per-VM value (Yan Zhao) [Orabug: 38359602]
- KVM: VMX: read the PML log in the same order as it was written (Maxim Levitsky) [Orabug: 38359602]
- KVM: VMX: refactor PML terminology (Maxim Levitsky) [Orabug: 38359602]
- KVM: x86: Remove hwapic_irr_update() from kvm_x86_ops (Chao Gao) [Orabug: 38359602]
- KVM: x86/mmu: Add parameter "kvm" to kvm_mmu_page_ad_need_write_protect() (Yan Zhao) [Orabug: 38359602]
- KVM: Add parameter "kvm" to kvm_cpu_dirty_log_size() and its callers (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Handle vCPU dissociation (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Finalize VM initialization (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add an ioctl to create initial guest memory (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Export kvm_tdp_map_page() (Rick Edgecombe) [Orabug: 38359602]
- KVM: x86/mmu: Bail out kvm_tdp_map_page() when VM dead (Yan Zhao) [Orabug: 38359602]
- KVM: TDX: Implement hook to get max mapping level of private pages (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Implement hooks to propagate changes of TDP MMU mirror page table (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Handle TLB tracking for TDX (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Set per-VM shadow_mmio_value to 0 (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Add setter for shadow_mmio_value (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Require TDP MMU, mmio caching and EPT A/D bits for TDX (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Set gfn_direct_bits to shared bit (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add load_mmu_pgd method for TDX (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Add accessors VMX VMCS helpers (Isaku Yamahata) [Orabug: 38359602]
- KVM: VMX: Teach EPT violation helper about private mem (Rick Edgecombe) [Orabug: 38359602]
- KVM: VMX: Split out guts of EPT violation to common/exposed function (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Do not enable page track for TD guest (Yan Zhao) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Add a helper function to walk down the TDP MMU (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Implement memslot deletion for TDX (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TD measurement of initial contents (Isaku Yamahata) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers to remove a TD private page (Isaku Yamahata) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers to manage TDX TLB tracking (Isaku Yamahata) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers to add TD private pages (Isaku Yamahata) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrapper tdh_mem_sept_add() to add SEPT pages (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Register TDX host key IDs to cgroup misc controller (Zhiming Hu) [Orabug: 38359602]
- KVM: x86/mmu: Taking guest pa into consideration when calculate tdp level (Xiaoyao Li) [Orabug: 38359602]
- KVM: x86: Introduce KVM_TDX_GET_CPUID (Xiaoyao Li) [Orabug: 38359602]
- KVM: TDX: Do TDX specific vcpu initialization (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Short-circuit all of kvm_apic_set_base() if MSR value is unchanged (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Unpack msr_data structure prior to calling kvm_apic_set_base() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Make kvm_recalculate_apic_map() local to lapic.c (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Rename APIC base setters to better capture their relationship (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Move kvm_set_apic_base() implementation to lapic.c (from x86.c) (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Drop superfluous kvm_lapic_set_base() call when setting APIC state (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Short-circuit all kvm_lapic_set_base() if MSR value isn't changing (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: create/free TDX vcpu structure (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Don't offline the last cpu of one package when there's TDX guest (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Make pmu_intel.c ignore guest TD case (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: add ioctl to initialize VM with TDX specific parameters (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: expose cpuid_entry2_find for TDX (Paolo Bonzini) [Orabug: 38359602]
- KVM: TDX: Support per-VM KVM_CAP_MAX_VCPUS extension check (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: create/destroy VM structure (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Get system-wide info about TDX module on initialization (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add place holder for TDX VM specific mem_enc_op ioctl (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add helper functions to print TDX SEAMCALL error (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add TDX "architectural" error codes (Sean Christopherson) [Orabug: 38359602]
- KVM: TDX: Define TDX architectural definitions (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Add placeholders for TDX VM/vCPU structures (Isaku Yamahata) [Orabug: 38359602]
- KVM: TDX: Get TDX global information (Kai Huang) [Orabug: 38359602]
- KVM: VMX: Initialize TDX during KVM module load (Kai Huang) [Orabug: 38359602]
- KVM: VMX: Refactor VMX module init/exit functions (Kai Huang) [Orabug: 38359602]
- KVM: Export hardware virtualization enabling/disabling functions (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Add tdx_guest_keyid_alloc/free() to alloc and free TDX guest KeyID (Isaku Yamahata) [Orabug: 38359602]
- x86/virt/tdx: Read essential global metadata for KVM (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: allocate tdx_sys_info in static memory (Paolo Bonzini) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX flush operations (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX VM/vCPU field access (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX page cache management (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX vCPU creation (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX TD creation (Rick Edgecombe) [Orabug: 38359602]
- x86/virt/tdx: Add SEAMCALL wrappers for TDX KeyID management (Rick Edgecombe) [Orabug: 38359602]
- asm-generic: add an optional pfn_valid check to page_to_phys (Christoph Hellwig) [Orabug: 38359602]
- asm-generic: provide generic page_to_phys and phys_to_page implementations (Christoph Hellwig) [Orabug: 38359602]
- KVM: x86: Add infrastructure for secure TSC (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Push down setting vcpu.arch.user_set_tsc (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: move vm_destroy callback at end of kvm_arch_destroy_vm (Paolo Bonzini) [Orabug: 38359602]
- x86/tdx: Mark message.bytes as nonstring (Kees Cook) [Orabug: 38359602]
- KVM: x86/mmu: Return RET_PF* instead of 1 in kvm_mmu_page_fault() (Yan Zhao) [Orabug: 38359602]
- KVM: x86/mmu: Prevent aliased memslot GFNs (Rick Edgecombe) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Don't zap valid mirror roots in kvm_tdp_mmu_zap_all() (Rick Edgecombe) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Take root types for kvm_tdp_mmu_invalidate_all_roots() (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Propagate tearing down mirror page tables (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Propagate building mirror page tables (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Propagate attr_filter to MMU notifier callbacks (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Support mirror root for TDP MMU (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Take root in tdp_mmu_for_each_pte() (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Introduce KVM MMU root types to specify page table type (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Extract root invalid check from tdx_mmu_next_root() (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Support GFN direct bits (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/tdp_mmu: Take struct kvm in iter loops (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Make kvm_tdp_mmu_alloc_root() return void (Rick Edgecombe) [Orabug: 38359602]
- KVM: x86/mmu: Add an is_mirror member for union kvm_mmu_page_role (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86/mmu: Add an external pointer to struct kvm_mmu_page (Isaku Yamahata) [Orabug: 38359602]
- KVM: x86: Add a VM type define for TDX (Rick Edgecombe) [Orabug: 38359602]
- KVM: x86/mmu: Zap invalid roots with mmu_lock holding for write at uninit (Rick Edgecombe) [Orabug: 38359602]
- KVM: guest_memfd: Remove RCU-protected attribute from slot->gmem.file (Yan Zhao) [Orabug: 38359602]
- KVM: x86: Refactor __kvm_emulate_hypercall() into a macro (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86: Always complete hypercall via function callback (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Bump hypercall stat prior to fully completing hypercall (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Move "emulate hypercall" function declarations to x86.h (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Add a helper to check for user interception of KVM hypercalls (Binbin Wu) [Orabug: 38359602]
- KVM: x86: clear vcpu->run->hypercall.ret before exiting for KVM_EXIT_HYPERCALL (Paolo Bonzini) [Orabug: 38359602]
- KVM: x86: Add interrupt injection information to the kvm_entry tracepoint (Maxim Levitsky) [Orabug: 38359602]
- KVM: x86: Use only local variables (no bitmask) to init kvm_cpu_caps (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Explicitly track feature flags that are enabled at runtime (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Explicitly track feature flags that require vendor enabling (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Rename "SF" macro to "SCATTERED_F" (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Pull CPUID capabilities from boot_cpu_data only as needed (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Add a macro for features that are synthesized into boot_cpu_data (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Drop superfluous host XSAVE check when adjusting guest XSAVES caps (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Replace (almost) all guest CPUID feature queries with cpu_caps (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Reject userspace attempts to access ARCH_CAPABILITIES w/o support (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Reject userspace attempts to access PERF_CAPABILITIES w/o PDCM (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Shuffle code to prepare for dropping guest_cpuid_has() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Update guest cpu_caps at runtime for dynamic CPUID-based features (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Update OS{XSAVE,PKE} bits in guest CPUID irrespective of host support (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Drop unnecessary check that cpuid_entry2_find() returns right leaf (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Avoid double CPUID lookup when updating MWAIT at runtime (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Initialize guest cpu_caps based on KVM support (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Treat MONTIOR/MWAIT as a "partially emulated" feature (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Extract code for generating per-entry emulated CPUID information (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Initialize guest cpu_caps based on guest CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Replace guts of "governed" features with comprehensive cpu_caps (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Rename "governed features" helpers to use "guest_cpu_cap" (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Advertise HYPERVISOR in KVM_GET_SUPPORTED_CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Advertise TSC_DEADLINE_TIMER in KVM_GET_SUPPORTED_CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Remove all direct usage of cpuid_entry2_find() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Move kvm_find_cpuid_entry{,_index}() up near cpuid_entry2_find() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Always operate on kvm_vcpu data in cpuid_entry2_find() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Remove unnecessary caching of KVM's PV CPUID base (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Clear PV_UNHALT for !HLT-exiting only when userspace sets CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Swap incoming guest CPUID into vCPU before massaging in KVM_SET_CPUID2 (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Add a macro to init CPUID features that KVM emulates in software (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: AMD's IBPB is not equivalent to Intel's IBPB (Jim Mattson) [Orabug: 38359602]
- KVM: x86: Add a macro to init CPUID features that ignore host kernel support (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Harden CPU capabilities processing against out-of-scope features (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: #undef SPEC_CTRL_SSBD in cpuid.c to avoid macro collisions (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Handle kernel- and KVM-defined CPUID words in a single helper (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Add a macro to precisely handle aliased 0x1.EDX CPUID features (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Add a macro to init CPUID features that are 64-bit only (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Rename kvm_cpu_cap_mask() to kvm_cpu_cap_init() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Unpack F() CPUID feature flag macros to one flag per line of code (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Account for max supported CPUID leaf when getting raw host CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Do reverse CPUID sanity checks in __feature_leaf() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Don't update PV features caches when enabling enforcement capability (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Zero out PV features cache when the CPUID leaf is not present (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Account for KVM-reserved CR4 bits when passing through CR4 on VMX (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Explicitly do runtime CPUID updates "after" initial setup (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Do all post-set CPUID processing during vCPU creation (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Limit use of F() and SF() to kvm_cpu_cap_{mask,init_kvm_defined}() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Use feature_bit() to clear CONSTANT_TSC when emulating CPUID (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: expose MSR_PLATFORM_INFO as a feature MSR (Paolo Bonzini) [Orabug: 38359602]
- x86: KVM: Advertise CPUIDs for new instructions in Clearwater Forest (Tao Su) [Orabug: 38359602]
- x86/virt/tdx: Require the module to assert it has the NO_RBP_MOD mitigation (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Switch to use auto-generated global metadata reading code (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Use dedicated struct members for PAMT entry sizes (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Use auto-generated code to read global metadata (Paolo Bonzini) [Orabug: 38359602]
- x86/virt/tdx: Start to track all global metadata in one structure (Kai Huang) [Orabug: 38359602]
- x86/virt/tdx: Rename 'struct tdx_tdmr_sysinfo' to reflect the spec better (Kai Huang) [Orabug: 38359602]
- x86/tdx: Dump attributes and TD_CTLS on boot (Kirill A. Shutemov) [Orabug: 38359602]
- x86/tdx: Disable unnecessary virtualization exceptions (Kirill A. Shutemov) [Orabug: 38359602]
- x86/tdx: Enable CPU topology enumeration (Kirill A. Shutemov) [Orabug: 38359602]
- KVM: x86/mmu: Drop per-VM zapped_obsolete_pages list (Vipin Sharma) [Orabug: 38359602]
- KVM: x86/mmu: Remove KVM's MMU shrinker (Vipin Sharma) [Orabug: 38359602]
- KVM: x86/mmu: WARN if huge page recovery triggered during dirty logging (David Matlack) [Orabug: 38359602]
- KVM: x86/mmu: Rename make_huge_page_split_spte() to make_small_spte() (David Matlack) [Orabug: 38359602]
- KVM: x86/mmu: Recover TDP MMU huge page mappings in-place instead of zapping (David Matlack) [Orabug: 38359602]
- KVM: x86/mmu: Refactor TDP MMU iter need resched check (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Demote the WARN on yielded in xxx_cond_resched() to KVM_MMU_WARN_ON (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Check yielded_gfn for forward progress iff resched is needed (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Batch TLB flushes when zapping collapsible TDP MMU SPTEs (David Matlack) [Orabug: 38359602]
- KVM: x86/mmu: Drop @max_level from kvm_mmu_max_mapping_level() (David Matlack) [Orabug: 38359602]
- KVM: x86: Don't emit TLB flushes when aging SPTEs for mmu_notifiers (Sean Christopherson) [Orabug: 38359602]
- KVM: Allow arch code to elide TLB flushes when aging a young page (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Set Dirty bit for new SPTEs, even if _hardware_ A/D bits are disabled (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Dedup logic for detecting TLB flushes on leaf SPTE changes (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Stop processing TDP MMU roots for test_age if young SPTE found (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Process only valid TDP MMU roots when aging a gfn range (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Use Accessed bit even when _hardware_ A/D bits are disabled (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Set shadow_dirty_mask for EPT even if A/D bits disabled (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Set shadow_accessed_mask for EPT even if A/D bits disabled (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Add a dedicated flag to track if A/D bits are globally enabled (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: WARN and flush if resolving a TDP MMU fault clears MMU-writable (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Fold mmu_spte_update_no_track() into mmu_spte_update() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Drop ignored return value from kvm_tdp_mmu_clear_dirty_slot() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Don't flush TLBs when clearing Dirty bit in shadow MMU (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Don't force flush if SPTE update clears Accessed bit (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Fold all of make_spte()'s writable handling into one if-else (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Always set SPTE's dirty bit if it's created as writable (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Flush remote TLBs iff MMU-writable flag is cleared from RO SPTE (Sean Christopherson) [Orabug: 38359602]
- KVM: Don't grab reference on VM_MIXEDMAP pfns that have a "struct page" (Sean Christopherson) [Orabug: 38359602]
- KVM: Drop APIs that manipulate "struct page" via pfns (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Don't mark "struct page" accessed when zapping SPTEs (Sean Christopherson) [Orabug: 38359602]
- KVM: Make kvm_follow_pfn.refcounted_page a required field (Sean Christopherson) [Orabug: 38359602]
- KVM: Drop gfn_to_pfn() APIs now that all users are gone (Sean Christopherson) [Orabug: 38359602]
- KVM: Add support for read-only usage of gfn_to_page() (Sean Christopherson) [Orabug: 38359602]
- KVM: Convert gfn_to_page() to use kvm_follow_pfn() (Sean Christopherson) [Orabug: 38359602]
- KVM: arm64: Don't mark "struct page" accessed when making SPTE young (Sean Christopherson) [Orabug: 38359602]
- KVM: arm64: Use __gfn_to_page() when copying MTE tags to/from userspace (Sean Christopherson) [Orabug: 38359602]
- KVM: arm64: Use __kvm_faultin_pfn() to handle memory aborts (Sean Christopherson) [Orabug: 38359602]
- KVM: arm64: Mark "struct page" pfns accessed/dirty before dropping mmu_lock (Sean Christopherson) [Orabug: 38359602]
- KVM: VMX: Use __kvm_faultin_page() to get APIC access page/pfn (Sean Christopherson) [Orabug: 38359602]
- KVM: VMX: Hold mmu_lock until page is released when updating APIC access page (Sean Christopherson) [Orabug: 38359602]
- KVM: Move x86's API to release a faultin page to common KVM (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Don't mark unused faultin pages as accessed (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Put refcounted pages instead of blindly releasing pfns (Sean Christopherson) [Orabug: 38359602]
- KVM: guest_memfd: Provide "struct page" as output from kvm_gmem_get_pfn() (Sean Christopherson) [Orabug: 38359602]
- KVM: guest_memfd: Pass index, not gfn, to __kvm_gmem_get_pfn() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Convert page fault paths to kvm_faultin_pfn() (Sean Christopherson) [Orabug: 38359602]
- KVM: Add kvm_faultin_pfn() to specifically service guest page faults (Sean Christopherson) [Orabug: 38359602]
- KVM: Move declarations of memslot accessors up in kvm_host.h (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Mark pages/folios dirty at the origin of make_spte() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Add helper to "finish" handling a guest page fault (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Add common helper to handle prefetching SPTEs (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Put direct prefetched pages via kvm_release_page_clean() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Add "mmu" prefix fault-in helpers to free up generic names (Sean Christopherson) [Orabug: 38359602]
- KVM: x86: Don't fault-in APIC access page during initial allocation (Sean Christopherson) [Orabug: 38359602]
- KVM: Disallow direct access (w/o mmu_notifier) to unpinned pfn by default (Sean Christopherson) [Orabug: 38359602]
- KVM: Get writable mapping for __kvm_vcpu_map() only when necessary (Sean Christopherson) [Orabug: 38359602]
- KVM: Pass in write/dirty to kvm_vcpu_map(), not kvm_vcpu_unmap() (Sean Christopherson) [Orabug: 38359602]
- KVM: nVMX: Mark vmcs12's APIC access page dirty when unmapping (Sean Christopherson) [Orabug: 38359602]
- KVM: Pin (as in FOLL_PIN) pages during kvm_vcpu_map() (Sean Christopherson) [Orabug: 38359602]
- KVM: Migrate kvm_vcpu_map() to kvm_follow_pfn() (David Stevens) [Orabug: 38359602]
- KVM: pfncache: Precisely track refcounted pages (Sean Christopherson) [Orabug: 38359602]
- KVM: Move kvm_{set,release}_page_{clean,dirty}() helpers up in kvm_main.c (Sean Christopherson) [Orabug: 38359602]
- KVM: Provide refcounted page as output field in struct kvm_follow_pfn (Sean Christopherson) [Orabug: 38359602]
- KVM: Use plain "struct page" pointer instead of single-entry array (Sean Christopherson) [Orabug: 38359602]
- KVM: nVMX: Add helper to put (unmap) vmcs12 pages (Sean Christopherson) [Orabug: 38359602]
- KVM: nVMX: Drop pointless msr_bitmap_map field from struct nested_vmx (Sean Christopherson) [Orabug: 38359602]
- KVM: nVMX: Rely on kvm_vcpu_unmap() to track validity of eVMCS mapping (Sean Christopherson) [Orabug: 38359602]
- KVM: Use NULL for struct page pointer to indicate mremapped memory (Sean Christopherson) [Orabug: 38359602]
- KVM: Explicitly initialize all fields at the start of kvm_vcpu_map() (Sean Christopherson) [Orabug: 38359602]
- KVM: Remove pointless sanity check on @map param to kvm_vcpu_(un)map() (Sean Christopherson) [Orabug: 38359602]
- KVM: Introduce kvm_follow_pfn() to eventually replace "gfn_to_pfn" APIs (David Stevens) [Orabug: 38359602]
- KVM: Drop unused "hva" pointer from __gfn_to_pfn_memslot() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Drop kvm_page_fault.hva, i.e. don't track intermediate hva (Sean Christopherson) [Orabug: 38359602]
- KVM: Replace "async" pointer in gfn=>pfn with "no_wait" and error code (David Stevens) [Orabug: 38359602]
- KVM: Drop extra GUP (via check_user_page_hwpoison()) to detect poisoned page (Sean Christopherson) [Orabug: 38359602]
- KVM: Return ERR_SIGPENDING from hva_to_pfn() if GUP returns -EGAIN (Sean Christopherson) [Orabug: 38359602]
- KVM: Annotate that all paths in hva_to_pfn() might sleep (Sean Christopherson) [Orabug: 38359602]
- KVM: Drop @atomic param from gfn=>pfn and hva=>pfn APIs (Sean Christopherson) [Orabug: 38359602]
- KVM: Rename gfn_to_page_many_atomic() to kvm_prefetch_pages() (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Use gfn_to_page_many_atomic() when prefetching indirect PTEs (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Mark page/folio accessed only when zapping leaf SPTEs (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Mark folio dirty when creating SPTE, not when zapping/modifying (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Mark new SPTE as Accessed when synchronizing existing SPTE (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Invert @can_unsync and renamed to @synchronizing (Sean Christopherson) [Orabug: 38359602]
- KVM: x86/mmu: Don't overwrite shadow-present MMU SPTEs when prefaulting (Sean Christopherson) [Orabug: 38359602]
- KVM: Add kvm_release_page_unused() API to put pages that KVM never consumes (Sean Christopherson) [Orabug: 38359602]
- KVM: Allow calling kvm_release_page_{clean,dirty}() on a NULL page pointer (Sean Christopherson) [Orabug: 38359602]
- KVM: Drop KVM_ERR_PTR_BAD_PAGE and instead return NULL to indicate an error (Sean Christopherson) [Orabug: 38359602]
- NFSD: release read access of nfs4_file when a write delegation is returned (Dai Ngo) [Orabug: 38512200]
- NFSD: Offer write delegation for OPEN with OPEN4_SHARE_ACCESS_WRITE (Dai Ngo) [Orabug: 38512200]
- nfsd: implement OPEN_ARGS_SHARE_ACCESS_WANT_OPEN_XOR_DELEGATION (Jeff Layton) [Orabug: 38512200]
- nfsd: handle delegated timestamps in SETATTR (Jeff Layton) [Orabug: 38512200]
- nfsd: add support for delegated timestamps (Jeff Layton) [Orabug: 38512200]
- nfsd: rework NFS4_SHARE_WANT_* flag handling (Jeff Layton) [Orabug: 38512200]
- nfsd: add support for FATTR4_OPEN_ARGUMENTS (Jeff Layton) [Orabug: 38512200]
- nfsd: prepare delegation code for handing out *_ATTRS_DELEG delegations (Jeff Layton) [Orabug: 38512200]
- nfsd: rename NFS4_SHARE_WANT_* constants to OPEN4_SHARE_ACCESS_WANT_* (Jeff Layton) [Orabug: 38512200]
- nfsd: switch to autogenerated definitions for open_delegation_type4 (Jeff Layton) [Orabug: 38512200]
- nfs_common: make include/linux/nfs4.h include generated nfs4_1.h (Jeff Layton) [Orabug: 38512200]
- nfsd: fix handling of delegated change attr in CB_GETATTR (Jeff Layton) [Orabug: 38512200]
- nfsd: have nfsd4_deleg_getattr_conflict pass back write deleg pointer (Jeff Layton) [Orabug: 38512200]
- nfsd: drop the nfsd4_fattr_args "size" field (Jeff Layton) [Orabug: 38512200]
- nfsd: drop the ncf_cb_bmap field (Jeff Layton) [Orabug: 38512200]
- tls: skip setting sk_write_space on rekey (Sabrina Dubroca) [Orabug: 38295472]
- selftests: tls: add rekey tests (Sabrina Dubroca) [Orabug: 38295472]
- selftests: tls: add key_generation argument to tls_crypto_info_init (Sabrina Dubroca) [Orabug: 38295472]
- selftests: tls: add a selftest for wrapping rec_seq (Sabrina Dubroca) [Orabug: 38295472]
- docs: tls: document TLS1.3 key updates (Sabrina Dubroca) [Orabug: 38295472]
- tls: add counters for rekey (Sabrina Dubroca) [Orabug: 38295472]
- tls: implement rekey for TLS1.3 (Sabrina Dubroca) [Orabug: 38295472]
- tls: block decryption when a rekey is pending (Sabrina Dubroca) [Orabug: 38295472]
- uek-rpm: Enable few more options in UEK8U2 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Run savedefconfig for UEK8U2 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Set KFENCE_SAMPLE_INTERVAL to 100 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Enable MODULE_UNLOAD_TAINT_TRACKING in UEK8U2 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Enable DAMON_RECLAIM in UEK8U2 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Enable BLK_CGROUP_IOLATENCY in UEK8U2 (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Enable multiple compression techniques with ZRAM (Harshit Mogalapalli) [Orabug: 38488528]
- uek-rpm: Enable SQUASHFS_COMPILE_DECOMP_MULTI_PERCPU in UEK8 (Harshit Mogalapalli) [Orabug: 38488528]
- tools/selftests: add guard region test for /proc/$pid/pagemap (Lorenzo Stoakes) [Orabug: 38456071]
- fs/proc/task_mmu: add guard region bit to pagemap (Lorenzo Stoakes) [Orabug: 38456071]
- tools/testing/selftests: fix guard region test tmpfs assumption (Lorenzo Stoakes) [Orabug: 38456071]
- tools/selftests: add file/shmem-backed mapping guard region tests (Lorenzo Stoakes) [Orabug: 38456071]
- tools/selftests: expand all guard region tests to file-backed (Lorenzo Stoakes) [Orabug: 38456071]
- selftests/mm: rename guard-pages to guard-regions (Lorenzo Stoakes) [Orabug: 38456071]
- mm: allow guard regions in file-backed and read-only mappings (Lorenzo Stoakes) [Orabug: 38456071]
- selftests/mm: add fork CoW guard page test (Lorenzo Stoakes) [Orabug: 38456071]
- selftests/mm: add self tests for guard page feature (Lorenzo Stoakes) [Orabug: 38456071]
- tools: testing: update tools UAPI header for mman-common.h (Lorenzo Stoakes) [Orabug: 38456071]
- mm: madvise: implement lightweight guard page mechanism (Lorenzo Stoakes) [Orabug: 38456071]
- mm: add PTE_MARKER_GUARD PTE marker (Lorenzo Stoakes) [Orabug: 38456071]
- mm: pagewalk: add the ability to install PTEs (Lorenzo Stoakes) [Orabug: 38456071]
- uek-rpm: T93: build OcteonTX2 SPI controller (Dave Kleikamp) [Orabug: 38474944]
- drivers: spi: octeontx2: Fix compile errors and warnings (Dave Kleikamp) [Orabug: 38474944]
- drivers: spi: octeontx2: Fix typo in return code (Suneel Garapati) [Orabug: 38474944]
- drivers: spi: octeontx2: ACPI support for SPI driver (Piyush Malgujar) [Orabug: 38474944]
- drivers: spi: octeontx2: Resolve issues detected in static code analysis (Piyush Malgujar) [Orabug: 38474944]
- drivers: spi: octeontx2: Add fix for hw issue (Piyush Malgujar) [Orabug: 38474944]
- drivers: spi: octeontx2: use read after write for MPI_CFG (Piyush Malgujar) [Orabug: 38474944]
- drivers: spi: octeontx2: set tritx in config register (Piyush Malgujar) [Orabug: 38474944]
- drivers: spi: octeontx2: Support for octeontx2 spi controller (Piyush Malgujar) [Orabug: 38474944]
- uek-rpm: Build T93 smartnic kernel (Dave Kleikamp) [Orabug: 38474944]
- uek-rpm: T93: add modules.yaml.S.emb and denylist.txt.S.emb (Dave Kleikamp) [Orabug: 38474944]
- uek-rpm: Add config file for T93 smartnic (Dave Kleikamp) [Orabug: 38474944]
- iommu/arm-smmu-v3: Force 32 byte command queue memory reads (srokade) [Orabug: 38474944]
- uek-rpm: build embedded4 kernel (Joe Dobosenski) [Orabug: 38097144]
- uek-rpm: add UEK8 kconfig for embedded4 platform (Joe Dobosenski) [Orabug: 38097144]
- irqchip/pensando: Fix partial of_iomap() leak on error (#505) (Brad Larson) [Orabug: 38097144]
- mmc: core: Use HPI to interrupt lengthy cache flush (#495) (Brad Larson) [Orabug: 38097144]
- i2c: designware: Support stuck SDA line recovery (Brad Larson) [Orabug: 38097144]
- perf/arm-cmn: Enable AMD Pensando Salina SoC CMN PMU driver (Brad Larson) [Orabug: 38097144]
- arm64: Enable platform SError handler (Brad Larson) [Orabug: 38097144]
- spi: dw-mmio: Add AMD Pensando Salina SoC support (Brad Larson) [Orabug: 38097144]
- rtc: elbacpld: Support RTC in AMD Pensando system controller (Brad Larson) [Orabug: 38097144]
- mfd: Add AMD Pensando system controller (Brad Larson) [Orabug: 38097144]
- EDAC/elba: Add AMD Pensando Elba/Giglio SoC EDAC driver (Brad Larson) [Orabug: 38097144]
- mtd: spi-nor: winbond: Add support for W25Q02NW (Brad Larson) [Orabug: 38097144]
- irqchip/pensando: Add AMD Pensando IRQ driver (Brad Larson) [Orabug: 38097144]
- arm64: Add AMD Pensando UIO support (Brad Larson) [Orabug: 38097144]
- arm64: defconfig: Add AMD Pensando defconfig (Brad Larson) [Orabug: 38097144]
- soc/pensando: Add AMD Pensando SoC drivers (Brad Larson) [Orabug: 38097144]
- arm64: dts: Add AMD Pensando SoC support (Brad Larson) [Orabug: 38097144]
- i2c: rd1173: Add Lattice SPI to I2C bus driver (Brad Larson) [Orabug: 38097144]
- hwmon: (pmbus/tps53679) Add support for tps53659 (Brad Larson) [Orabug: 38097144]
- hwmon: (pmbus/ltc2978) Add support for ltc3888 (Brad Larson) [Orabug: 38097144]
- mmc: sdhci-cadence: Support ADMA with bounce buffers (Brad Larson) [Orabug: 38097144]
-
Tue Oct 21 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-106.51.1.el10uek]
- KVM: x86: Advertise SRSO_USER_KERNEL_NO to userspace (Harshit Mogalapalli) [Orabug: 38478491]
- KVM: SVM: Set/clear SRSO's BP_SPEC_REDUCE on 0 <=> 1 VM count transitions (Harshit Mogalapalli) [Orabug: 38478491]
- x86/bugs: KVM: Add support for SRSO_MSR_FIX (Harshit Mogalapalli) [Orabug: 38478491]
- x86/bugs: Add SRSO_USER_KERNEL_NO support (Harshit Mogalapalli) [Orabug: 38478491]
- x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit (Harshit Mogalapalli) [Orabug: 38478491]
- Revert "x86/bugs: Adjust SRSO mitigation to new features" (Harshit Mogalapalli) [Orabug: 38478491]
- uek-rpm: add "bpf" to CONFIG_LSM as overheads are reduced (Alan Maguire) [Orabug: 38519747]
- uek-rpm: Enable CONFIG_COMPAT_32BIT_TIME for x86 container kernel (Boris Ostrovsky) [Orabug: 38540664]
-
Tue Oct 14 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-105.51.5.el10uek]
- RDMA/mlx5: Fix vport loopback forcing for MPV device (Patrisious Haddad) [Orabug: 38226124]
- arm64: Utilize for_each_cpu_wrap for reference lookup (Beata Michalska) [Orabug: 38454705]
- arm64: Update AMU-based freq scale factor on entering idle (Beata Michalska) [Orabug: 38454705]
- arm64: Provide an AMU-based version of arch_freq_get_on_cpu (Beata Michalska) [Orabug: 38454705]
- cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry (Beata Michalska) [Orabug: 38454705]
- cpufreq: Allow arch_freq_get_on_cpu to return an error (Beata Michalska) [Orabug: 38454705]
- arch_topology: init capacity_freq_ref to 0 (Ionela Voinescu) [Orabug: 38454705]
- ACPI/HMAT: Move HMAT messages to pr_debug() (Dan Williams) [Orabug: 38454705]
- perf: arm_cspmu: nvidia: monitor all ports by default (Besar Wicaksono) [Orabug: 38454705]
- perf: arm_cspmu: nvidia: enable NVLINK-C2C port filtering (Besar Wicaksono) [Orabug: 38454705]
- perf: arm_cspmu: nvidia: fix sysfs path in the kernel doc (Besar Wicaksono) [Orabug: 38454705]
- perf: arm_cspmu: nvidia: remove unsupported SCF events (Besar Wicaksono) [Orabug: 38454705]
- cppc_cpufreq: Remove HiSilicon CPPC workaround (Jie Zhan) [Orabug: 38454705]
- Revert "sched/fair: Bump sd->max_newidle_lb_cost when newidle balance fails" (Joseph Salisbury) [Orabug: 38498945]
- uek-rpm/config-aarch64: Enable configs for Grace platform support (Vijay Kumar) [Orabug: 38526374]
- LTS version: v6.12.51 (Jack Vogel)
- ASoC: qcom: audioreach: fix potential null pointer dereference (Srinivas Kandagatla)
- wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() (Matvey Kovalev)
- mm: swap: check for stable address space before operating on the VMA (Charan Teja Kalla)
- media: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID (Thadeu Lima de Souza Cascardo)
- media: rc: fix races with imon_disconnect() (Larshin Sergey)
- media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou)
- media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou)
- scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran)
- gcc-plugins: Remove TODO_verify_il for GCC >= 16 (Kees Cook)
- crypto: sha256 - fix crash at kexec (Breno Leitao)
- LTS version v6.12.50 (Jack Vogel)
- drm/i915/backlight: Return immediately when scale() finds invalid parameters (Guenter Roeck)
- Revert "usb: xhci: remove option to change a default ring's TRB cycle bit" (Niklas Neronin)
- iommufd: Fix race during abort for file descriptors (Jason Gunthorpe)
- fbcon: Fix OOB access in font allocation (Thomas Zimmermann)
- fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda)
- mm/hugetlb: fix folio is still mapped when deleted (Jinjiang Tu)
- kmsan: fix out-of-bounds access to shadow memory (Eric Biggers)
- gpiolib: Extend software-node support to support secondary software-nodes (Hans de Goede)
- fs/proc/task_mmu: check p->vec_buf for NULL (Jakub Acs)
- afs: Fix potential null pointer dereference in afs_put_server (Zhen Ni)
- drm/ast: Use msleep instead of mdelay for edid read (Nirmoy Das)
- arm64: dts: marvell: cn9132-clearfog: fix multi-lane pci x2 and x4 ports (Josua Mayer)
- arm64: dts: marvell: cn9132-clearfog: disable eMMC high-speed modes (Josua Mayer)
- ARM: dts: socfpga: sodia: Fix mdio bus probe and PHY address (Nobuhiro Iwamatsu)
- tracing: dynevent: Add a missing lockdown check on dynevent (Masami Hiramatsu (Google))
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (Eric Biggers)
- i40e: improve VF MAC filters accounting (Lukasz Czapnik)
- i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik)
- i40e: add max boundary check for VF filters (Lukasz Czapnik)
- i40e: fix validation of VF state in get resources (Lukasz Czapnik)
- i40e: fix input validation logic for action_meta (Lukasz Czapnik)
- i40e: fix idx validation in config queues msg (Lukasz Czapnik)
- i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik)
- i40e: add validation for ring_len param (Lukasz Czapnik)
- HID: asus: add support for missing PX series fn keys (Amit Chaudhari)
- smb: client: fix wrong index reference in smb2_compound_op() (Sang-Heon Jeon)
- platform/x86: lg-laptop: Fix WMAB call in fan_mode_store() (Daniel Lee)
- drm/panthor: Defer scheduler entitiy destruction to queue release (Adrián Larumbe)
- futex: Prevent use-after-free during requeue-PI (Sebastian Andrzej Siewior)
- drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita)
- mm: folio_may_be_lru_cached() unless folio_test_large() (Hugh Dickins)
- mm: revert "mm/gup: clear the LRU flag of a page before adding to LRU batch" (Hugh Dickins)
- mm/gup: local lru_add_drain() to avoid lru_add_drain_all() (Hugh Dickins)
- octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() (Dan Carpenter)
- net: dsa: lantiq_gswip: suppress -EINVAL errors for bridge FDB entries added to the CPU port (Vladimir Oltean)
- net: dsa: lantiq_gswip: move gswip_add_single_port_br() call to port_setup() (Vladimir Oltean)
- selftests: fib_nexthops: Fix creation of non-FDB nexthops (Ido Schimmel)
- nexthop: Forbid FDB status change while nexthop is in a group (Ido Schimmel)
- net: allow alloc_skb_with_frags() to use MAX_SKB_FRAGS (Jason Baron)
- bnxt_en: correct offset handling for IPv6 destination address (Alok Tiwari)
- vhost: Take a reference on the task in struct vhost_task. (Sebastian Andrzej Siewior)
- Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (Luiz Augusto von Dentz)
- Bluetooth: hci_sync: Fix hci_resume_advertising_sync (Luiz Augusto von Dentz)
- ethernet: rvu-af: Remove slash from the driver name (Petr Malat)
- net/smc: fix warning in smc_rx_splice() when calling get_page() (Sidraya Jayagond)
- net: tun: Update napi->skb after XDP process (Wang Liang)
- can: peak_usb: fix shift-out-of-bounds issue (Stéphane Grosjean)
- can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (Sabrina Dubroca)
- bpf: Reject bpf_timer for PREEMPT_RT (Leon Hwang)
- can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven)
- wifi: virt_wifi: Fix page fault on connect (James Guan)
- btrfs: don't allow adding block device of less than 1 MB (Mark Harmstone)
- bpf: Check the helper function is valid in get_helper_proto (Jiri Olsa)
- smb: server: use disable_work_sync in transport_rdma.c (Stefan Metzmacher)
- smb: server: don't use delayed_work for post_recv_credits_work (Stefan Metzmacher)
- cpufreq: Initialize cpufreq-based invariance before subsys (Christian Loehle)
- ARM: dts: kirkwood: Fix sound DAI cells for OpenRD clients (Jihed Chaibi)
- arm64: dts: imx8mp: Correct thermal sensor index (Peng Fan)
- firmware: imx: Add stub functions for SCMI MISC API (Peng Fan)
- HID: amd_sfh: Add sync across amd sfh work functions (Basavaraj Natikar)
- IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov)
- net: sfp: add quirk for FLYPRO copper SFP+ module (Aleksander Jan Bajkowski)
- ALSA: usb-audio: Add mute TLV for playback volumes on more devices (qaqland)
- ALSA: usb-audio: move mixer_quirks' min_mute into common quirk (Cryolitia PukNgae)
- ALSA: usb-audio: Add DSD support for Comtrue USB Audio device (noble.yang)
- i2c: designware: Add quirk for Intel Xe (Heikki Krogerus)
- mmc: sdhci-cadence: add Mobileye eyeQ support (Benoît Monin)
- net: sfp: add quirk for Potron SFP+ XGSPON ONU Stick (Chris Morgan)
- net: fec: rename struct fec_devinfo fec_imx6x_info -> fec_imx6sx_info (Marc Kleine-Budde)
- usb: core: Add 0x prefix to quirks debug output (Jiayi Li)
- ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai)
- ALSA: hda/realtek: Add support for ASUS NUC using CS35L41 HDA (Stefan Binding)
- ALSA: usb-audio: Convert comma to semicolon (Chen Ni)
- ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea)
- ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Drop unnecessary parentheses in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Fix code alignment in mixer_quirks (Cristian Ciocaltea)
- firewire: core: fix overlooked update of subsystem ABI version (Takashi Sakamoto)
- scsi: ufs: mcq: Fix memory allocation checks for SQE and CQE (Alok Tiwari)
-
Tue Oct 07 2025 Jack Vogel <jack.vogel@oracle.com> [6.12.0-105.49.4.el10uek]
- fs/dax: don't disassociate zero page entries (Alistair Popple) [Orabug: 36859857]
- device/dax: properly refcount device dax pages when mapping (Alistair Popple) [Orabug: 36859857]
- fs/dax: properly refcount fs dax pages (Alistair Popple) [Orabug: 36859857]
- fs/dax: Fix "don't skip locked entries when scanning entries" (Alistair Popple) [Orabug: 36859857]
- mm: decline to manipulate the refcount on a slab page (Matthew Wilcox (Oracle)) [Orabug: 36859857]
- dcssblk: mark DAX broken, remove FS_DAX_LIMITED support (Dan Williams) [Orabug: 36859857]
- mm/gup: don't allow FOLL_LONGTERM pinning of FS DAX pages (Alistair Popple) [Orabug: 36859857]
- mm/huge_memory: add vmf_insert_folio_pmd() (Alistair Popple) [Orabug: 36859857]
- mm/huge_memory: add vmf_insert_folio_pud() (Alistair Popple) [Orabug: 36859857]
- mm/rmap: add support for PUD sized mappings to rmap (Alistair Popple) [Orabug: 36859857]
- mm/memory: add vmf_insert_page_mkwrite() (Alistair Popple) [Orabug: 36859857]
- mm/memory: enhance insert_page_into_pte_locked() to create writable mappings (Alistair Popple) [Orabug: 36859857]
- mm: allow compound zone device pages (Alistair Popple) [Orabug: 36859857]
- mm/mm_init: move p2pdma page refcount initialisation to p2pdma (Alistair Popple) [Orabug: 36859857]
- mm/gup: remove redundant check for PCI P2PDMA page (Alistair Popple) [Orabug: 36859857]
- fs/dax: remove PAGE_MAPPING_DAX_SHARED mapping flag (Alistair Popple) [Orabug: 36859857]
- dax: use folios more widely within DAX (Matthew Wilcox (Oracle)) [Orabug: 36859857]
- dax: remove access to page->index (Matthew Wilcox (Oracle)) [Orabug: 36859857]
- fs/dax: ensure all pages are idle prior to filesystem unmount (Alistair Popple) [Orabug: 36859857]
- fs/dax: always remove DAX page-cache entries when breaking layouts (Alistair Popple) [Orabug: 36859857]
- mm: optimize invalidation of shadow entries (Shakeel Butt) [Orabug: 36859857]
- mm: optimize truncation of shadow entries (Shakeel Butt) [Orabug: 36859857]
- fs/dax: create a common implementation to break DAX layouts (Alistair Popple) [Orabug: 36859857]
- fs/dax: refactor wait for dax idle page (Alistair Popple) [Orabug: 36859857]
- fs/dax: don't skip locked entries when scanning entries (Alistair Popple) [Orabug: 36859857]
- fs/dax: return unmapped busy pages from dax_layout_busy_page_range() (Alistair Popple) [Orabug: 36859857]
- uek: kabi: Update check-kabi to support namespace checks (Saeed Mirzamohammadi) [Orabug: 38459242]
-
Wed Oct 01 2025 Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com> [6.12.0-105.49.3.el10uek]
- uek-rpm: Disable module xe build on 64k (Sherry Yang) [Orabug: 38490598]
-
Tue Sep 30 2025 Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com> [6.12.0-105.49.2.el10uek]
- io_uring: Hide kabi magic from user space (Sherry Yang) [Orabug: 38463157]
- LTS version: v6.12.49 (Harshit Mogalapalli)
- minmax.h: remove some #defines that are only expanded once (David Laight)
- minmax.h: simplify the variants of clamp() (David Laight)
- minmax.h: move all the clamp() definitions after the min/max() ones (David Laight)
- minmax.h: use BUILD_BUG_ON_MSG() for the lo < hi test in clamp() (David Laight)
- minmax.h: reduce the #define expansion of min(), max() and clamp() (David Laight)
- minmax.h: update some comments (David Laight)
- minmax.h: add whitespace around operators and after commas (David Laight)
- rtc: pcf2127: fix SPI command byte for PCF2131 backport (Bruno Thomsen)
- xhci: dbc: Fix full DbC transfer ring after several reconnects (Mathias Nyman)
- xhci: dbc: decouple endpoint allocation from initialization (Mathias Nyman)
- usb: xhci: remove option to change a default ring's TRB cycle bit (Niklas Neronin)
- usb: xhci: introduce macro for ring segment list iteration (Niklas Neronin)
- mptcp: pm: nl: announce deny-join-id0 flag (Matthieu Baerts)
- mm/gup: check ref_count instead of lru before migration (Hugh Dickins)
- mm: add folio_expected_ref_count() for reference count calculation (Shivank Garg)
- vmxnet3: unregister xdp rxq info in the reset path (Sankararaman Jayaraman) [Orabug: 37844478] {CVE-2025-22106}
- platform/x86: asus-wmi: Re-add extra keys to ignore_key_wlan quirk (Antheas Kapenekakis)
- platform/x86: asus-wmi: Fix ROG button mapping, tablet mode on ASUS ROG Z13 (Antheas Kapenekakis)
- io_uring: fix incorrect io_kiocb reference in io_link_skb (Yang Xiuwei)
- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher) [Orabug: 38503782] {CVE-2025-39929}
- crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503788] {CVE-2025-39931}
- smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work) (Stefan Metzmacher) [Orabug: 38503796] {CVE-2025-39932}
- smb: client: fix filename matching of deferred files (Paulo Alcantara)
- drm/xe: Fix a NULL vs IS_ERR() in xe_vm_add_compute_exec_queue() (Dan Carpenter)
- drm: bridge: cdns-mhdp8546: Fix missing mutex unlock on error path (Qi Xi)
- drm: bridge: anx7625: Fix NULL pointer dereference with early IRQ (Loic Poulain)
- drm/xe/tile: Release kobject for the failure path (Shuicheng Lin)
- ASoC: Intel: catpt: Expose correct bit depth to userspace (Amadeusz Sławiński)
- ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King)
- ASoC: wm8974: Correct PLL rate rounding (Charles Keepax)
- ASoC: wm8940: Correct typo in control name (Charles Keepax)
- ASoC: wm8940: Correct PLL rate rounding (Charles Keepax)
- io_uring/kbuf: drop WARN_ON_ONCE() from incremental length check (Jens Axboe)
- io_uring/msg_ring: kill alloc_cache for io_kiocb allocations (Jens Axboe)
- io_uring: include dying ring in task_work "should cancel" state (Jens Axboe)
- io_uring: backport io_should_terminate_tw() (Jens Axboe)
- io_uring/cmd: let cmds to know about dying task (Pavel Begunkov)
- ALSA: hda/realtek: Fix mute led for HP Laptop 15-dw4xx (Praful Adiga)
- selftests: mptcp: avoid spurious errors on TCP disconnect (Matthieu Baerts)
- selftests: mptcp: connect: catch IO errors on listen side (Matthieu Baerts)
- mptcp: propagate shutdown to subflows when possible (Matthieu Baerts)
- net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede)
- drm/amd/display: Allow RX6xxx & RX7700 to invoke amdgpu_irq_get/put (Ivan Lipski)
- mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier)
- ASoC: qcom: q6apm-lpass-dais: Fix missing set_fmt DAI op for I2S (Mohammad Rafi Shaik)
- ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if source graph failed (Krzysztof Kozlowski)
- ASoC: qcom: audioreach: Fix lpaif_type configuration for the I2S interface (Mohammad Rafi Shaik)
- btrfs: tree-checker: fix the incorrect inode ref size check (Qu Wenruo)
- iommu/amd/pgtbl: Fix possible race while increase page table level (Vasant Hegde)
- iommu/vt-d: Fix __domain_mapping()'s usage of switch_to_super_page() (Eugene Koira)
- LoongArch: Check the return value when creating kobj (Tao Cui)
- LoongArch: Align ACPI structures if ARCH_STRICT_ALIGN enabled (Huacai Chen)
- LoongArch: vDSO: Check kcalloc() result in init_vdso() (Guangshuo Li)
- LoongArch: Fix unreliable stack for live patching (Tiezhu Yang)
- objtool/LoongArch: Mark special atomic instruction as INSN_BUG type (Tiezhu Yang)
- objtool/LoongArch: Mark types based on break immediate code (Tiezhu Yang)
- LoongArch: Update help info of ARCH_STRICT_ALIGN (Tiezhu Yang)
- mm: revert "mm: vmscan.c: fix OOM on swap stress test" (Hugh Dickins)
- gup: optimize longterm pin_user_pages() for large folio (Li Zhe)
- dm-stripe: fix a possible integer overflow (Mikulas Patocka) [Orabug: 38503824] {CVE-2025-39940}
- dm-raid: don't set io_min and io_opt for raid1 (Mikulas Patocka)
- power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller)
- power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller)
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (Herbert Xu)
- nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor)
- ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size (Stefan Metzmacher)
- ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer (Namjae Jeon)
- perf/x86/intel: Fix crash in icl_update_topdown_event() (Kan Liang) [Orabug: 38180828] {CVE-2025-38322}
- octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() (Duoming Zhou)
- cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503847] {CVE-2025-39945}
- net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih)
- Revert "net/mlx5e: Update and set Xon/Xoff upon port speed set" (Tariq Toukan)
- tls: make sure to abort the stream if headers are bogus (Jakub Kicinski) [Orabug: 38503856] {CVE-2025-39946}
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima)
- octeon_ep: fix VF MAC address lifecycle handling (Sathesh Edara)
- bonding: don't set oif to bond dev when getting NS target destination (Hangbin Liu)
- net/mlx5e: Harden uplink netdev access against device unbind (Jianbo Liu) [Orabug: 38503862] {CVE-2025-39947}
- igc: don't fail igc_probe() on LED setup error (Kohei Enju)
- i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski)
- ice: fix Rx page leak on multi-buffer frames (Jacob Keller) [Orabug: 38503866] {CVE-2025-39948}
- ice: store max_frame and rx_buf_len only in ice_rx_ring (Jacob Keller)
- net: natsemi: fix `rx_dropped` double accounting on `netif_rx()` failure (Moon Yeounsu)
- selftests: mptcp: sockopt: fix error messages (Geliang Tang)
- mptcp: tfo: record 'deny join id0' info (Matthieu Baerts)
- selftests: mptcp: userspace pm: validate deny-join-id0 flag (Matthieu Baerts)
- mptcp: set remote_deny_join_id0 on SYN recv (Matthieu Baerts)
- bonding: set random address only when slaves already exist (Hangbin Liu)
- qed: Don't collect too many protection override GRC elements (Jamie Bainbridge) [Orabug: 38503868] {CVE-2025-39949}
- net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR (Anderson Nascimento)
- dpaa2-switch: fix buffer pool seeding for control traffic (Ioana Ciornei)
- um: Fix FD copy size in os_rcv_fd_msg() (Tiwei Bie)
- um: virtio_uml: Fix use-after-free after put_device in probe (Miaoqian Lin)
- btrfs: fix invalid extref key setup when replaying dentry (Filipe Manana)
- cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503889] {CVE-2025-39953}
- pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven)
- wifi: mac80211: fix incorrect type for ret (Liao Yuanhong)
- wifi: mac80211: increase scan_ies_len for S1G (Lachlan Hodges)
- ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto)
- nvme: fix PI insert on write (Christoph Hellwig)
- wifi: wilc1000: avoid buffer overflow in WID string configuration (Ajay Singh)
- LTS version: v6.12.48 (Harshit Mogalapalli)
- x86: disable image size check for test builds (Guenter Roeck)
- netfilter: nft_set_pipapo: fix null deref for empty set (Florian Westphal) [Orabug: 38492667] {CVE-2025-39867}
- drm/amdgpu: fix a memory leak in fence cleanup when unloading (Alex Deucher)
- drm/i915/power: fix size for for_each_set_bit() in abox iteration (Jani Nikula)
- net: mdiobus: release reset_gpio in mdiobus_unregister_device() (Csaba Buday)
- x86/cpu/topology: Always try cpu_parse_topology_ext() on AMD/Hygon (K Prateek Nayak)
- phy: ti-pipe3: fix device leak at unbind (Johan Hovold)
- phy: ti: omap-usb2: fix device leak at unbind (Johan Hovold)
- phy: tegra: xusb: fix device and OF node leak at probe (Johan Hovold)
- dmaengine: dw: dmamux: Fix device reference leak in rzn1_dmamux_route_allocate (Miaoqian Lin)
- dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494820] {CVE-2025-39923}
- usb: gadget: midi2: Fix MIDI2 IN EP max packet size (Takashi Iwai)
- usb: gadget: midi2: Fix missing UMP group attributes initialization (Takashi Iwai)
- usb: typec: tcpm: properly deliver cable vdms to altmode drivers (Rd Babiera)
- USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern)
- xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman)
- RISC-V: Remove unnecessary include from compat.h (Palmer Dabbelt)
- regulator: sy7636a: fix lifecycle of power good gpio (Andreas Kemnade)
- dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell)
- dmaengine: idxd: Fix double free in idxd_setup_wqs() (Dan Carpenter) [Orabug: 38461885] {CVE-2025-39870}
- dmaengine: idxd: Fix refcount underflow on module unload (Yi Sun)
- dmaengine: idxd: Remove improper idxd_free (Yi Sun) [Orabug: 38461887] {CVE-2025-39871}
- phy: qualcomm: phy-qcom-eusb2-repeater: fix override properties (Pengyu Luo)
- hsr: use hsr_for_each_port_rtnl in hsr_port_get_hsr (Hangbin Liu)
- hsr: use rtnl lock when iterating over ports (Hangbin Liu)
- net: hsr: Add VLAN CTAG filter support (Murali Karicheri)
- netfilter: nf_tables: restart set lookup on base_seq change (Florian Westphal)
- netfilter: nf_tables: make nft_set_do_lookup available unconditionally (Florian Westphal)
- netfilter: nf_tables: place base_seq in struct net (Florian Westphal)
- netfilter: nf_tables: Reintroduce shortened deletion notifications (Phil Sutter)
- netfilter: nft_set_rbtree: continue traversal if element is inactive (Florian Westphal)
- netfilter: nft_set_pipapo: don't check genbit from packetpath lookups (Florian Westphal)
- netfilter: nft_set_pipapo: don't return bogus extension pointer (Florian Westphal)
- netfilter: nft_set_pipapo: merge pipapo_get/lookup (Florian Westphal)
- netfilter: nft_set: remove one argument from lookup and update functions (Florian Westphal)
- netfilter: nft_set_pipapo: remove unused arguments (Florian Westphal)
- can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB (Anssi Hannula)
- can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa)
- can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa)
- drm/amd/display: use udelay rather than fsleep (Alex Deucher)
- i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494785] {CVE-2025-39911}
- igb: fix link test skipping when interface is admin down (Kohei Enju)
- docs: networking: can: change bcm_msg_head frames member to support flexible array (Alex Tran)
- tunnels: reset the GSO metadata before reusing the skb (Antoine Tenart)
- net: bridge: Bounce invalid boolopts (Petr Machata)
- genetlink: fix genl_bind() invoking bind() after -EPERM (Alok Tiwari) [Orabug: 38494831] {CVE-2025-39926}
- net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren)
- drm/panthor: validate group queue count (Chia-I Wu)
- Disable SLUB_TINY for build testing (Linus Torvalds)
- USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)
- USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda)
- dt-bindings: serial: brcm,bcm7271-uart: Constrain clocks (Krzysztof Kozlowski)
- serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve)
- tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt)
- Revert "net: usb: asix: ax88772: drop phylink use in PM to avoid MDIO runtime PM wakeups" (Paolo Abeni)
- Input: i8042 - add TUXEDO InfinityBook Pro Gen10 AMD to i8042 quirk table (Christoffer Sandberg)
- Input: iqs7222 - avoid enabling unused interrupts (Jeff Labundy)
- hrtimers: Unconditionally update target CPU base after offline timer migration (Xiongfeng Wang)
- btrfs: fix corruption reading compressed range when block size is smaller than page size (Qu Wenruo)
- btrfs: use readahead_expand() on compressed extents (Boris Burkov)
- mtd: spinand: winbond: Fix oob_layout for W25N01JW (Santhosh Kumar K)
- mm/hugetlb: add missing hugetlb_lock in __unmap_hugepage_range() (Jeongjun Park)
- mm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters() (Quanmin Yan)
- mm/damon/sysfs: fix use-after-free in state_show() (Stanislav Fort) [Orabug: 38461827] {CVE-2025-39877}
- ceph: fix race condition where r_parent becomes stale before sending message (Alex Markuze)
- ceph: fix race condition validating r_parent before applying state (Alex Markuze) [Orabug: 38494833] {CVE-2025-39927}
- libceph: fix invalid accesses to ceph_connection_v1_info (Ilya Dryomov) [Orabug: 38461835] {CVE-2025-39880}
- kernfs: Fix UAF in polling when open file is released (Chen Ridong) [Orabug: 38461841] {CVE-2025-39881}
- netlink: specs: mptcp: fix if-idx attribute type (Matthieu Baerts)
- netlink: specs: mptcp: replace underscores with dashes in names (Jakub Kicinski)
- netlink: specs: mptcp: clearly mention attributes (Matthieu Baerts)
- netlink: specs: mptcp: add missing 'server-side' attr (Matthieu Baerts)
- drm/amdgpu/vcn4: Fix IB parsing with multiple engine info packages (David Rosca)
- drm/amdgpu/vcn: Allow limiting ctx to instance 0 for AV1 at any time (David Rosca)
- drm/xe: Attempt to bring bos back to VRAM after eviction (Thomas Hellström)
- drm/mediatek: fix potential OF node use-after-free (Johan Hovold)
- mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters() (Quanmin Yan)
- mm/damon/core: set quota->charged_from to jiffies at first charge window (Sang-Heon Jeon)
- mm/memory-failure: fix redundant updates for already poisoned pages (Kyle Meyer)
- mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461846] {CVE-2025-39883}
- mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang)
- fuse: prevent overflow in copy_file_range return value (Miklos Szeredi)
- fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi)
- fuse: do not allow mapping a non-regular backing file (Amir Goldstein)
- mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello)
- mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello)
- mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin)
- net: usb: asix: ax88772: drop phylink use in PM to avoid MDIO runtime PM wakeups (Oleksij Rempel)
- i2c: i801: Hide Intel Birch Stream SoC TCO WDT (Chiasheng Lee)
- btrfs: fix subvolume deletion lockup caused by inodes xarray race (Omar Sandoval) [Orabug: 38461854] {CVE-2025-39884}
- btrfs: fix squota compressed stats leak (Boris Burkov)
- ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461857] {CVE-2025-39885}
- mptcp: sockopt: make sync_socket_options propagate SOCK_KEEPOPEN (Krister Johansen)
- compiler-clang.h: define __SANITIZE_*__ macros only when undefined (Nathan Chancellor)
- EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki)
- proc: fix type confusion in pde_set_flags() (Zijie Wang)
- tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. (Kuniyuki Iwashima) [Orabug: 38494795] {CVE-2025-39913}
- bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() (Peilin Ye) [Orabug: 38461865] {CVE-2025-39886}
- bpf: Allow fall back to interpreter for programs with stack size <= 512 (Kafai Wan)
- bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt (Daniel Borkmann) [Orabug: 38494805] {CVE-2025-39917}
- s390/cpum_cf: Deny all sampling events by counter PMU (Thomas Richter)
- s390/pai: Deny all events not handled by this PMU (Thomas Richter)
- tracing: Silence warning when chunk allocation fails in trace_pid_write (Pu Lehui) [Orabug: 38494800] {CVE-2025-39914}
- NFSv4/flexfiles: Fix layout merge mirror check. (Jonathan Curley)
- NFS: nfs_invalidate_folio() must observe the offset and size arguments (Trond Myklebust)
- NFSv4.2: Serialise O_DIRECT i/o and copy range (Trond Myklebust)
- NFSv4.2: Serialise O_DIRECT i/o and clone range (Trond Myklebust)
- NFSv4.2: Serialise O_DIRECT i/o and fallocate() (Trond Myklebust)
- NFS: Serialise O_DIRECT i/o and truncate() (Trond Myklebust)
- fs/nfs/io: make nfs_start_io_*() killable (Max Kellermann)
- ftrace/samples: Fix function size computation (Vladimir Riabchun)
- nfs/localio: restore creds before releasing pageio data (Scott Mayhew)
- nfs/localio: add direct IO enablement with sync and async IO support (Mike Snitzer)
- nfs/localio: remove extra indirect nfs_to call to check {read,write}_iter (Mike Snitzer)
- tracing: Fix tracing_marker may trigger page fault during preempt_disable (Luo Gengkun)
- NFSv4: Clear the NFS_CAP_XATTR flag if not supported by the server (Trond Myklebust)
- NFSv4: Clear NFS_CAP_OPEN_XOR and NFS_CAP_DELEGTIME if not supported (Trond Myklebust)
- NFSv4: Clear the NFS_CAP_FS_LOCATIONS flag if it is not set (Trond Myklebust)
- trace/fgraph: Fix error handling (Guenter Roeck)
- NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust)
- SUNRPC: call xs_sock_process_cmsg for all cmsg (Justin Worrell)
- flexfiles/pNFS: fix NULL checks on result of ff_layout_choose_ds_for_read (Tigran Mkrtchyan)
- drm/amdgpu: Add back JPEG to video caps for carrizo and newer (David Rosca)
- ALSA: hda/realtek: Fix built-in mic assignment on ASUS VivoBook X515UA (Takashi Iwai)
- Revert "drm/amd/display: Optimize cursor position updates" (Aurabindo Pillai)
- drm/amd/display: Fix error pointers in amdgpu_dm_crtc_mem_type_changed (Srinivasan Shanmugam)
- drm/i915/pmu: Fix zero delta busyness issue (Umesh Nerlige Ramappa)
- ext4: introduce linear search for dentries (Theodore Ts'O)
- Revert "udmabuf: fix vmap_udmabuf error page set" (Huan Yang)
- nvme-pci: skip nvme_write_sq_db on empty rqlist (Maurizio Lombardi)
- dma-debug: fix physical address calculation for struct dma_debug_entry (Fedor Pchelkin)
- dma-mapping: fix swapped dir/flags arguments to trace_dma_alloc_sgt_err (Sean Anderson)
- mm: introduce and use {pgd,p4d}_populate_kernel() (Harry Yoo)
- net/mlx5: HWS, change error flow on matcher disconnect (Yevgeny Kliteynik)
- kunit: kasan_test: disable fortify string checker on kasan_strings() test (Levi Yun)
- dma-debug: don't enforce dma mapping check on noncoherent allocations (Baochen Qiang)
- dma-mapping: trace more error paths (Sean Anderson)
- dma-mapping: use trace_dma_alloc for dma_alloc* instead of using trace_dma_map (Sean Anderson)
- dma-mapping: trace dma_alloc/free direction (Sean Anderson)
- dma-debug: store a phys_addr_t in struct dma_debug_entry (Christoph Hellwig)
- fhandle: use more consistent rules for decoding file handle from userns (Amir Goldstein)
- LTS version: v6.12.47 (Harshit Mogalapalli)
- LTS version: v6.12.46 (Harshit Mogalapalli)
- dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen)
- md/raid1: fix data lost for writemostly rdev (Yu Kuai)
- riscv, bpf: use lw when reading int cpu in bpf_get_smp_processor_id (Radim Krčmář)
- riscv, bpf: use lw when reading int cpu in BPF_MOV64_PERCPU_REG (Radim Krčmář)
- riscv: use lw when reading int cpu in asm_per_cpu (Radim Krčmář)
- riscv: use lw when reading int cpu in new_vmalloc_check (Radim Krčmář)
- riscv: Only allow LTO with CMODEL_MEDANY (Nathan Chancellor)
- ACPI: RISC-V: Fix FFH_CPPC_CSR error handling (Anup Patel)
- md: prevent incorrect update of resync/recovery offset (Li Nan)
- tools: gpio: remove the include directory on make clean (Zhang Jiao)
- drm/amd/amdgpu: Fix missing error return on kzalloc failure (Colin Ian King)
- perf bpf-utils: Harden get_bpf_prog_info_linear (Ian Rogers)
- perf bpf-utils: Constify bpil_array_desc (Ian Rogers)
- perf bpf-event: Fix use-after-free in synthesis (Ian Rogers)
- drm/bridge: ti-sn65dsi86: fix REFCLK setting (Michael Walle)
- spi: spi-fsl-lpspi: Clear status register after disabling the module (Larisa Grigore)
- spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore)
- spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore)
- spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore)
- scsi: sr: Reinstate rotational media flag (Ming Lei)
- block: add a queue_limits_commit_update_frozen helper (Christoph Hellwig)
- hwmon: mlxreg-fan: Prevent fans from getting stuck at 0 RPM (Vadim Pasternak)
- platform/x86/intel: power-domains: Use topology_logical_package_id() for package ID (David Arcari)
- platform/x86: asus-wmi: Remove extra keys from ignore_key_wlan quirk (Antheas Kapenekakis)
- pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang)
- pcmcia: omap: Add missing check for platform_get_resource (Chen Ni)
- Revert "drm/amdgpu: Avoid extra evict-restore process." (Alex Deucher)
- ALSA: hda/realtek: Fix headset mic for TongFang X6[AF]R5xxY (Aaron Erhardt)
- ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai)
- rust: support Rust >= 1.91.0 target spec (Miguel Ojeda)
- dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen)
- thermal/drivers/mediatek/lvts: Disable low offset IRQ for minimum threshold (Nícolas F R A Prado)
- mm: fix accounting of memmap pages (Sumanth Korikkar)
- kunit: kasan_test: disable fortify string checker on kasan_strings() test (Levi Yun)
- nouveau: fix disabling the nonstall irq due to storm code (Dave Airlie)
- mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494758] {CVE-2025-39902}
- mm, slab: cleanup slab_bug() parameters (Vlastimil Babka)
- mm: slub: call WARN() when detecting a slab corruption (Hyesoo Yu)
- mm: slub: Print the broken data before restoring them (Hyesoo Yu)
- md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb (Su Yue) [Orabug: 37844677] {CVE-2025-22124}
- net: fix NULL pointer dereference in l3mdev_l3_rcv (Wang Liang) [Orabug: 37844462] {CVE-2025-22103}
- wifi: ath11k: update channel list in worker when wait flag is set (Wen Gong)
- wifi: ath11k: update channel list in reg notifier instead reg worker (Wen Gong) [Orabug: 37844571] {CVE-2025-23133}
- ext4: avoid journaling sb update on error if journal is destroying (Ojaswin Mujoo) [Orabug: 37844503] {CVE-2025-22113}
- ext4: define ext4_journal_destroy wrapper (Ojaswin Mujoo)
- md/raid1,raid10: strip REQ_NOWAIT from member bios (Zheng Qixing)
- md/raid1,raid10: don't handle IO error for REQ_RAHEAD and REQ_NOWAIT (Yu Kuai)
- md/raid1,raid10: don't ignore IO flags (Yu Kuai)
- net: dsa: b53: do not enable EEE on bcm63xx (Jonas Gorski) [Orabug: 38180448] {CVE-2025-38272}
- net: dsa: b53/bcm_sf2: implement .support_eee() method (Russell King)
- net: dsa: provide implementation of .support_eee() (Russell King)
- net: dsa: add hook to determine whether EEE is supported (Russell King)
- fs/fhandle.c: fix a race in call of has_locked_children() (Al Viro) [Orabug: 38180547] {CVE-2025-38306}
- microchip: lan865x: Fix LAN8651 autoloading (Stefan Wahren)
- microchip: lan865x: Fix module autoloading (Stefan Wahren)
- net: pcs: rzn1-miic: Correct MODCTRL register offset (Lad Prabhakar)
- e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits) [Orabug: 38494738] {CVE-2025-39898}
- cifs: prevent NULL pointer dereference in UTF16 conversion (Makar Semyonov) [Orabug: 38456730] {CVE-2025-39838}
- batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort)
- scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456752] {CVE-2025-39841}
- platform/x86/amd/pmc: Add TUXEDO IB Pro Gen10 AMD to spurious 8042 quirks list (Christoffer Sandberg)
- drm/amd/display: Clear the CUR_ENABLE register on DCN314 w/out DPP PG (Ivan Lipski)
- drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher)
- net: ethernet: oa_tc6: Handle failure of spi_setup (Stefan Wahren)
- wifi: mt76: mt7925: fix the wrong bss cleanup for SAP (Ming Yen Hsieh)
- wifi: mt76: mt7996: Initialize hdr before passing to skb_put_data() (Nathan Chancellor)
- wifi: mt76: mt7925u: use connac3 tx aggr check in tx complete (Ming Yen Hsieh)
- wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494721] {CVE-2025-39891}
- soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson)
- of_numa: fix uninitialized memory nodes causing kernel panic (Yin Tirui) [Orabug: 38494765] {CVE-2025-39903}
- ocfs2: prevent release journal inode after journal shutdown (Edward Adam Davis) [Orabug: 38456756] {CVE-2025-39842}
- kasan: fix GCC mem-intrinsic prefix with sw tags (Ada Couprie Diaz)
- sched: Fix sched_numa_find_nth_cpu() if mask offline (Christian Loehle) [Orabug: 38494732] {CVE-2025-39895}
- mm: slub: avoid wake up kswapd in set_track_prepare (Yangshiguang) [Orabug: 38456759] {CVE-2025-39843}
- mm: fix possible deadlock in kmemleak (Gu Bowen)
- mm: move page table sync declarations to linux/pgtable.h (Harry Yoo) [Orabug: 38456762] {CVE-2025-39844}
- mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE (Sasha Levin) [Orabug: 38494745] {CVE-2025-39899}
- x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() (Harry Yoo) [Orabug: 38456765] {CVE-2025-39845}
- io_uring/msg_ring: ensure io_kiocb freeing is deferred for RCU (Jens Axboe) [Orabug: 38254135] {CVE-2025-38453}
- pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke)
- ACPI/IORT: Fix memory leak in iort_rmr_alloc_sids() (Miaoqian Lin)
- accel/ivpu: Prevent recovery work from being queued during device removal (Karol Wachowski)
- ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae)
- phy: mscc: Stop taking ts_lock for tx_queue and use its own lock (Horatiu Vultur)
- selftest: net: Fix weird setsockopt() in bind_bhash.c. (Kuniyuki Iwashima)
- ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456779] {CVE-2025-39847}
- net: xilinx: axienet: Add error handling for RX metadata pointer retrieval (Abin Joseph)
- net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang)
- ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet)
- mctp: return -ENOPROTOOPT for unknown getsockopt options (Alok Tiwari)
- net/smc: Remove validation of reserved bits in CLC Decline message (Mahanta Jambigi)
- ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter)
- net: thunder_bgx: decrement cleanup index before use (Rosen Penev)
- net: thunder_bgx: add a missing of_node_put (Rosen Penev)
- wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() (Dan Carpenter) [Orabug: 38456796] {CVE-2025-39849}
- wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter)
- wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter)
- vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects (Ido Schimmel) [Orabug: 38456798] {CVE-2025-39850}
- vxlan: Rename FDB Tx lookup function (Ido Schimmel)
- vxlan: Add RCU read-side critical sections in the Tx path (Ido Schimmel)
- vxlan: Avoid unnecessary updates to FDB 'used' time (Ido Schimmel)
- vxlan: Refresh FDB 'updated' time upon 'NTF_USE' (Ido Schimmel)
- net: vxlan: rename SKB_DROP_REASON_VXLAN_NO_REMOTE (Radu Rendec)
- net: vxlan: use kfree_skb_reason() in vxlan_mdb_xmit() (Menglong Dong)
- net: vxlan: use kfree_skb_reason() in vxlan_xmit() (Menglong Dong)
- net: vxlan: make vxlan_set_mac() return drop reasons (Menglong Dong)
- vxlan: Fix NPD when refreshing an FDB entry with a nexthop object (Ido Schimmel) [Orabug: 38456803] {CVE-2025-39851}
- net: vxlan: make vxlan_snoop() return drop reasons (Menglong Dong)
- net: vxlan: add skb drop reasons to vxlan_rcv() (Menglong Dong)
- net: tunnel: add pskb_inet_may_pull_reason() helper (Menglong Dong)
- net: skb: add pskb_network_may_pull_reason() helper (Menglong Dong)
- net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau)
- net/tcp: Fix socket memory leak in TCP-AO failure handling for IPv6 (Christoph Paasch) [Orabug: 38456808] {CVE-2025-39852}
- wifi: ath11k: fix group data packet drops during rekey (Rameshkumar Sundaram)
- ixgbe: fix incorrect map used in eee linkmode (Alok Tiwari) [Orabug: 38494817] {CVE-2025-39922}
- i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456812] {CVE-2025-39853}
- i40e: remove read access to debugfs files (Jacob Keller) [Orabug: 38494752] {CVE-2025-39901}
- idpf: set mac type when adding and removing MAC filters (Emil Tantilov)
- ice: fix NULL access of tx->in_use in ice_ll_ts_intr (Jacob Keller) [Orabug: 38456820] {CVE-2025-39854}
- net: mctp: mctp_fraq_queue should take ownership of passed skb (Jeremy Kerr)
- net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() (Liu Jian)
- macsec: read MACSEC_SA_ATTR_PN with nla_get_uint (Sabrina Dubroca)
- net: macb: Fix tx_ptr_lock locking (Sean Anderson)
- icmp: fix icmp_ndo_send address translation for reply direction (Fabian Bläse)
- bnxt_en: fix incorrect page count in RX aggr ring log (Alok Tiwari)
- selftests: drv-net: csum: fix interface name for remote host (Jakub Kicinski)
- mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin)
- xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari)
- net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y (Eric Dumazet) [Orabug: 38494749] {CVE-2025-39900}
- netfilter: nft_flowtable.sh: re-run with random mtu sizes (Florian Westphal)
- Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456832] {CVE-2025-39860}
- Bluetooth: vhci: Prevent use-after-free by removing debugfs files early (Ivan Pravdin) [Orabug: 38456841] {CVE-2025-39861}
- wifi: iwlwifi: uefi: check DSM item validity (Johannes Berg)
- netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter)
- netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (Wang Liang) [Orabug: 38494729] {CVE-2025-39894}
- wifi: mt76: fix linked list corruption (Felix Fietkau) [Orabug: 38494807] {CVE-2025-39918}
- wifi: mt76: free pending offchannel tx frames on wcid cleanup (Felix Fietkau)
- wifi: mt76: prevent non-offchannel mgmt tx during scan/roc (Felix Fietkau)
- wifi: mt76: mt7925: fix locking in mt7925_change_vif_links() (Harshit Mogalapalli)
- wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456848] {CVE-2025-39863}
- wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456857] {CVE-2025-39864}
- mmc: sdhci-of-arasan: Ensure CD logic stabilization before power-up (Sai Krishna Potthuri)
- mmc: sdhci-of-arasan: Support for emmc hardware reset (Paul Alvin)
- LoongArch: vDSO: Remove -nostdlib complier flag (Guan Wentao)
- LoongArch: vDSO: Remove --hash-style=sysv (Xi Ruoyao)
- net: usb: qmi_wwan: add Telit Cinterion FN990A w/audio composition (Fabio Porcedda)
- net: usb: qmi_wwan: fix Telit Cinterion FE990A name (Fabio Porcedda)
- net: usb: qmi_wwan: fix Telit Cinterion FN990A name (Fabio Porcedda)
- HID: core: Harden s32ton() against conversion to 0 bits (Alan Stern) [Orabug: 38334902] {CVE-2025-38556}
- HID: stop exporting hid_snto32() (Dmitry Torokhov)
- HID: simplify snto32() (Dmitry Torokhov)
- arm64: dts: imx8mp: Fix missing microSD slot vqmmc on Data Modul i.MX8M Plus eDM SBC (Marek Vasut)
- arm64: dts: imx8mp: Fix missing microSD slot vqmmc on DH electronics i.MX8M Plus DHCOM (Marek Vasut)
- arm64: dts: imx8mp-tqma8mpql: fix LDO5 power off (Markus Niebel)
- tee: optee: ffa: fix a typo of "optee_ffa_api_is_compatible" (Sungbae Yoo)
- arm64: dts: rockchip: Add vcc-supply to SPI flash on rk3399-pinebook-pro (Peter Robinson)
- tee: fix memory leak in tee_dyn_shm_alloc_helper (Pei Xiao)
- tee: fix NULL pointer dereference in tee_shm_put (Pei Xiao) [Orabug: 38456864] {CVE-2025-39865}
- fs: writeback: fix use-after-free in __mark_inode_dirty() (Jiufei Xue) [Orabug: 38456869] {CVE-2025-39866}
- btrfs: zoned: skip ZONE FINISH of conventional zones (Johannes Thumshirn)
- Bluetooth: hci_sync: Avoid adding default advertising on startup (Yang Li)
- cpupower: Fix a bug where the -t option of the set subcommand was not working. (Shinji Nomoto)
- drm/amd/display: Don't warn when missing DCE encoder caps (Timur Kristóf)
- cdc_ncm: Flag Intel OEM version of Fibocom L850-GL as WWAN (Lubomir Rintel)
- LoongArch: Save LBT before FPU in setup_sigcontext() (Huacai Chen)
- btrfs: avoid load/store tearing races when checking if an inode was logged (Filipe Manana)
- btrfs: fix race between setting last_dir_index_offset and inode logging (Filipe Manana)
- btrfs: fix race between logging inode and checking if it was logged before (Filipe Manana)
- bpf: Fix oob access in cgroup local storage (Daniel Borkmann) [Orabug: 38324116] {CVE-2025-38502}
- bpf: Move cgroup iterator helpers to bpf.h (Daniel Borkmann)
- bpf: Move bpf map owner out of common struct (Daniel Borkmann)
- bpf: Add cookie object to bpf maps (Daniel Borkmann)
- LTS version: v6.12.45 (Harshit Mogalapalli)
- thermal/drivers/mediatek/lvts_thermal: Add mt7988 lvts commands (Mason-Cw Chang)
- thermal/drivers/mediatek/lvts_thermal: Add lvts commands and their sizes to driver data (Mason-Cw Chang)
- thermal/drivers/mediatek/lvts_thermal: Change lvts commands array to static const (Mason-Cw Chang)
- Revert "drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS" (Imre Deak)
- PCI: dwc: Ensure that dw_pcie_wait_for_link() waits 100 ms after link up (Niklas Cassel)
- PCI: Rename PCIE_RESET_CONFIG_DEVICE_WAIT_MS to PCIE_RESET_CONFIG_WAIT_MS (Niklas Cassel)
- net: rose: fix a typo in rose_clear_routes() (Eric Dumazet)
- drm/amd/amdgpu: disable hwmon power1_cap* for gfx 11.0.3 on vf mode (Yang Wang)
- drm/mediatek: Fix device/node reference count leaks in mtk_drm_get_all_drm_priv (Ma Ke)
- drm/nouveau: fix error path in nvkm_gsp_fwsec_v2 (Timur Tabi)
- drm/nouveau/disp: Always accept linear modifier (James Jones)
- drm/xe/vm: Clear the scratch_pt pointer on error (Thomas Hellström)
- xfs: do not propagate ENODATA disk errors into xattr code (Eric Sandeen) [Orabug: 38440384] {CVE-2025-39835}
- smb3 client: fix return code mapping of remap_file_range (Steve French)
- net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)
- fs/smb: Fix inconsistent refcnt update (Shuhao Fu) [Orabug: 38440283] {CVE-2025-39819}
- dma/pool: Ensure DMA_DIRECT_REMAP allocations are decrypted (Shanker Donthineni)
- blk-zoned: Fix a lockdep complaint about recursive locking (Bart Van Assche)
- HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440226] {CVE-2025-39808}
- HID: wacom: Add a new Art Pen 2 (Ping Cheng)
- HID: logitech: Add ids for G PRO 2 LIGHTSPEED (Matt Coffin)
- HID: quirks: add support for Legion Go dual dinput modes (Antheas Kapenekakis)
- HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() (Qasim Ijaz) [Orabug: 38440221] {CVE-2025-39806}
- HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440308] {CVE-2025-39824}
- x86/cpu/topology: Use initial APIC ID from XTOPOLOGY leaf on AMD/HYGON (K Prateek Nayak)
- x86/microcode/AMD: Handle the case of no BIOS microcode (Borislav Petkov)
- RISC-V: KVM: fix stack overrun when loading vlenb (Radim Krčmář)
- net: macb: Disable clocks once (Neil Mandir)
- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440275] {CVE-2025-39817}
- fbnic: Move phylink resume out of service_task and into open/close (Alexander Duyck)
- l2tp: do not use sock_hold() in pppol2tp_session_get_sock() (Eric Dumazet)
- sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440248] {CVE-2025-39812}
- net: rose: include node references in rose_neigh refcount (Takamitsu Iwai)
- net: rose: convert 'use' field to refcount_t (Takamitsu Iwai)
- net: rose: split remove and free operations in rose_remove_neigh() (Takamitsu Iwai)
- net: hv_netvsc: fix loss of early receive events from host during channel open. (Dipayaan Roy)
- hv_netvsc: Link queues to NAPIs (Joe Damato)
- net: stmmac: Set CIC bit only for TX queues with COE (Rohan G Thomas)
- net: stmmac: xgmac: Correct supported speed modes (Rohan G Thomas)
- net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas)
- net/mlx5e: Set local Xoff after FW update (Alexei Lazar)
- net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar)
- net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar)
- net/mlx5: Nack sync reset when SFs are present (Moshe Shemesh)
- net/mlx5: Fix lockdep assertion on sync reset unload event (Moshe Shemesh) [Orabug: 38440365] {CVE-2025-39832}
- net/mlx5: Reload auxiliary drivers on fw_activate (Moshe Shemesh)
- bnxt_en: Fix stats context reservation logic (Michael Chan)
- bnxt_en: Adjust TX rings if reservation is less than requested (Michael Chan)
- bnxt_en: Fix memory corruption when FW resources change during ifdown (Sreekanth Reddy) [Orabug: 38440239] {CVE-2025-39810}
- phy: mscc: Fix when PTP clock is register and unregister (Horatiu Vultur)
- drm/xe: Don't trigger rebind on initial dma-buf validation (Matthew Brost)
- drm/xe/xe_sync: avoid race during ufence signaling (Kempczynski Zbigniew)
- efi: stmm: Fix incorrect buffer allocation method (Jan Kiszka)
- net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu)
- dt-bindings: display/msm: qcom,mdp5: drop lut clock (Dmitry Baryshkov)
- ice: fix incorrect counter for buffer allocation failures (Michal Kubiak)
- ice: use fixed adapter index for E825C embedded devices (Jacob Keller)
- ice: don't leave device non-functional if Tx scheduler config fails (Jacob Keller)
- drm/nouveau: remove unused memory target test (Timur Tabi)
- drm/nouveau: remove unused increment in gm200_flcn_pio_imem_wr (Timur Tabi)
- atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440344] {CVE-2025-39828}
- Bluetooth: hci_sync: fix set_local_name race condition (Pavel Shpakovskiy)
- Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz)
- Bluetooth: hci_event: Mark connection as closed during suspend disconnect (Ludovico de Nittis)
- Bluetooth: hci_event: Treat UNKNOWN_CONN_ID on disconnect as success (Ludovico de Nittis)
- net: macb: fix unregister_netdev call order in macb_remove() (Luoguangfei) [Orabug: 38440218] {CVE-2025-39805}
- HID: input: report battery status changes immediately (José Expósito)
- HID: input: rename hidinput_set_battery_charge_status() (José Expósito)
- powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan)
- drm/msm: update the high bitfield of certain DSI registers (Ayushi Makhija)
- drm/msm/kms: move snapshot init earlier in KMS init (Dmitry Baryshkov)
- of: reserved_mem: Restructure call site for dma_contiguous_early_fixup() (Oreoluwa Babatunde)
- drm/msm: Defer fd_install in SUBMIT ioctl (Rob Clark)
- vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov)
- ACPI: EC: Add device to acpi_ec_no_wakeup[] qurik list (Werner Sembach)
- erofs: fix atomic context detection when !CONFIG_DEBUG_LOCK_ALLOC (Junli Liu)
- ASoC: codecs: tx-macro: correct tx_macro_component_drv name (Alexey Klimov)
- smb: client: fix race with concurrent opens in rename(2) (Paulo Alcantara) [Orabug: 38440315] {CVE-2025-39825}
- smb: client: fix race with concurrent opens in unlink(2) (Paulo Alcantara)
- scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal)
- ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440257] {CVE-2025-39813}
- of: dynamic: Fix use after free in of_changeset_add_prop_helper() (Dan Carpenter)
- mips: lantiq: xway: sysctrl: rename the etop node (Aleksander Jan Bajkowski)
- mips: dts: lantiq: danube: add missing burst length property (Aleksander Jan Bajkowski)
- pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap)
- of: dynamic: Fix memleak when of_pci_add_properties() failed (Lizhi Hou)
- trace/fgraph: Fix the warning caused by missing unregister notifier (Ye Weihua) [Orabug: 38440352] {CVE-2025-39829}
- rtla: Check pkg-config install (Tao Chen)
- tools/latency-collector: Check pkg-config install (Tao Chen)
- LTS version: v6.12.44 (Harshit Mogalapalli)
- alloc_fdtable(): change calling conventions. (Al Viro)
- netfilter: nf_reject: don't leak dst refcount for loopback packets (Florian Westphal) [Orabug: 38401479] {CVE-2025-38732}
- s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter)
- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter)
- ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai)
- net/mlx5e: Preserve shared buffer capacity during headroom updates (Armen Ratner)
- net/mlx5e: Query FW for buffer ownership (Alexei Lazar)
- net/mlx5: Add IFC bits and enums for buf_ownership (Oren Sidi)
- net/mlx5: Relocate function declarations from port.h to mlx5_core.h (Shahar Shitrit)
- net/mlx5: Base ECVF devlink port attrs from 0 (Daniel Jurgens)
- Octeontx2-af: Skip overlap check for SPI field (Hariprasad Kelam)
- bonding: send LACPDUs periodically in passive mode after receiving partner's LACPDU (Hangbin Liu)
- bonding: update LACP activity flag after setting lacp_active (Hangbin Liu)
- ALSA: timer: fix ida_free call while not allocated (Dewei Meng) [Orabug: 38423453] {CVE-2025-39765}
- net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu)
- net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu) [Orabug: 38423455] {CVE-2025-39766}
- net: dsa: microchip: Fix KSZ9477 HSR port setup issue (Tristram Ha)
- ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing)
- s390/mm: Do not map lowcore with identity mapping (Heiko Carstens)
- LoongArch: Optimize module load time by optimizing PLT/GOT counting (Kanglong Wang)
- microchip: lan865x: fix missing Timer Increment config for Rev.B0/B1 (Parthiban Veerasooran)
- microchip: lan865x: fix missing netif_start_queue() call on device open (Parthiban Veerasooran)
- net/smc: fix UAF on smcsk after smc_listen_out() (D. Wythe)
- gve: prevent ethtool ops after shutdown (Jordan Rhee) [Orabug: 38401491] {CVE-2025-38735}
- phy: mscc: Fix timestamping for vsc8584 (Horatiu Vultur)
- cifs: Fix oops due to uninitialised variable (David Howells) [Orabug: 38401496] {CVE-2025-38737}
- net: ti: icssg-prueth: Fix HSR and switch offload Enablement during firwmare reload. (Md Danish Anwar)
- ppp: fix race conditions in ppp_fill_forward_path (Qingfang Deng) [Orabug: 38401498] {CVE-2025-39673}
- net: ethernet: mtk_ppe: add RCU lock around dev_fill_forward_path (Qingfang Deng)
- ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong)
- net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM (Jakub Ramaseuski) [Orabug: 38423463] {CVE-2025-39770}
- drm/amd/display: Don't print errors for nonexistent connectors (Timur Kristóf)
- drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() (Chenyuan Yang) [Orabug: 38401506] {CVE-2025-39675}
- drm/hisilicon/hibmc: fix the hibmc loaded failed bug (Baihan Li) [Orabug: 38423472] {CVE-2025-39772}
- drm/hisilicon/hibmc: fix the i2c device resource leak when vdac init failed (Baihan Li)
- drm/hisilicon/hibmc: refactored struct hibmc_drm_private (Baihan Li)
- rust: alloc: fix `rusttest` by providing `Cmalloc::aligned_layout` too (Miguel Ojeda)
- mlxsw: spectrum: Forward packets with an IPv4 link-local source IP (Ido Schimmel)
- iommu/amd: Avoid stack buffer overflow from kernel cmdline (Kees Cook) [Orabug: 38360924] {CVE-2025-38676}
- scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401511] {CVE-2025-39676}
- rtase: Fix Rx descriptor CRC error bit definition (Justin Lai)
- net: bridge: fix soft lockup in br_multicast_query_expired() (Wang Liang) [Orabug: 38423477] {CVE-2025-39773}
- net: xilinx: axienet: Fix RX skb ring management in DMAengine mode (Suraj Gupta)
- RDMA/hns: Fix dip entries leak on devices newer than hip09 (Junxian Huang)
- RDMA/bnxt_re: Fix to initialize the PBL array (Anantha Prabhu)
- RDMA/bnxt_re: Fix a possible memory leak in the driver (Kalesh Ap)
- RDMA/bnxt_re: Fix to remove workload check in SRQ limit path (Kashyap Desai)
- RDMA/bnxt_re: Fix to do SRQ armena by default (Kashyap Desai)
- RDMA/hns: Fix querying wrong SCC context for DIP algorithm (Wenglianfa)
- RDMA/erdma: Fix ignored return value of init_kernel_qp (Boshi Yu)
- rust: alloc: replace aligned_size() with Kmalloc::aligned_layout() (Danilo Krummrich)
- iosys-map: Fix undefined behavior in iosys_map_clear() (Gote, Nitin R)
- drm/tests: Fix drm_test_fb_xrgb8888_to_xrgb2101010() on big-endian (José Expósito)
- drm/tests: Do not use drm_fb_blit() in format-helper tests (Thomas Zimmermann)
- drm/format-helper: Add generic conversion to 32-bit formats (Thomas Zimmermann)
- drm/format-helper: Move helpers for pixel conversion to header file (Thomas Zimmermann)
- drm/format-helper: Add conversion from XRGB8888 to BGR888 (Kerem Karabay)
- drm/panic: Move drawing functions to drm_draw (Jocelyn Falempe)
- drm/tests: Fix endian warning (José Expósito)
- cgroup/cpuset: Fix a partition error with CPU hotplug (Waiman Long)
- cgroup/cpuset: Use static_branch_enable_cpuslocked() on cpusets_insane_config_key (Waiman Long)
- drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor(). (Fanhua Li) [Orabug: 38401536] {CVE-2025-39679}
- spi: spi-fsl-lpspi: Clamp too high speed_hz (Stefan Wahren)
- x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper (Tianxiang Peng) [Orabug: 38401540] {CVE-2025-39681}
- iio: imu: inv_icm42600: change invalid data error to -EBUSY (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: Convert to uXX and sXX integer types (Andy Shevchenko)
- iio: imu: inv_icm42600: use = { } instead of memset() (David Lechner)
- iio: imu: inv_icm42600: switch timestamp type from int64_t __aligned(8) to aligned_s64 (Jonathan Cameron)
- powerpc/boot: Fix build with gcc 15 (Michal Suchanek)
- ovl: use I_MUTEX_PARENT when locking parent in ovl_create_temp() (Neil Brown)
- drm/i915/icl+/tc: Cache the max lane count value (Imre Deak)
- compiler: remove __ADDRESSABLE_ASM{_STR,}() again (Jan Beulich)
- drm/i915/icl+/tc: Convert AUX powered WARN to a debug message (Imre Deak)
- tracing: Limit access to parser->buffer when trace_get_user failed (Pu Lehui) [Orabug: 38401545] {CVE-2025-39683}
- tracing: Remove unneeded goto out logic (Steven Rostedt)
- iio: temperature: maxim_thermocouple: use DMA-safe buffer for spi_read() (David Lechner)
- iio: light: as73211: Ensure buffer holes are zeroed (Jonathan Cameron)
- iio: light: Use aligned_s64 instead of open coding alignment. (Jonathan Cameron)
- usb: dwc3: pci: add support for the Intel Wildcat Lake (Krogerus Heikki)
- usb: dwc3: Remove WARN_ON for device endpoint command timeouts (Selvarasu Ganesan)
- usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai)
- usb: xhci: Fix slot_id resource race conflict (Weitao Wang)
- usb: typec: maxim_contaminant: re-enable cc toggle if cc is open and port is clean (Amit Sunil Dhamne)
- usb: typec: maxim_contaminant: disable low power mode when reading comparator values (Amit Sunil Dhamne)
- USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen)
- usb: storage: realtek_cr: Use correct byte order for bcs->Residue (Thorsten Blum)
- USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin)
- usb: renesas-xhci: Fix External ROM access timeouts (Marek Vasut)
- usb: core: hcd: fix accessing unmapped memory in SINGLE_STEP_SET_FEATURE test (Xu Yang)
- comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() (Ian Abbott)
- comedi: pcl726: Prevent invalid irq number (Edward Adam Davis)
- comedi: Make insn_rw_emulate_bits() do insn->n samples (Ian Abbott)
- usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li)
- cdx: Fix off-by-one error in cdx_rpmsg_probe() (Thorsten Blum)
- kcov, usb: Don't disable interrupts in kcov_remote_start_usb_softirq() (Sebastian Andrzej Siewior)
- most: core: Drop device reference after usage in get_channel() (Miaoqian Lin)
- iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner)
- iio: pressure: bmp280: Use IS_ERR() in bmp280_common_probe() (Salah Triki)
- ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401577] {CVE-2025-39689}
- fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun)
- mmc: sdhci_am654: Disable HS400 for AM62P SR1.0 and SR1.1 (Judith Mendez)
- drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak)
- cpuidle: governors: menu: Avoid selecting states with too much latency (Rafael J. Wysocki)
- cpuidle: menu: Remove iowait influence (Christian Loehle)
- use uniform permission checks for all mount propagation changes (Al Viro)
- fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401585] {CVE-2025-39691}
- smb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy() (Stefan Metzmacher)
- debugfs: fix mount options not being applied (Charalampos Mitrodimas)
- arm64: dts: ti: k3-am62*: Move eMMC pinmux to top level board file (Judith Mendez)
- arm64: dts: ti: k3-am6*: Remove disable-wp for eMMC (Judith Mendez)
- arm64: dts: ti: k3-am62*: Add non-removable flag for eMMC (Judith Mendez)
- arm64: dts: ti: k3-am6*: Add boot phase flag to support MMC boot (Judith Mendez)
- btrfs: subpage: keep TOWRITE tag until folio is cleaned (Naohiro Aota) [Orabug: 38423491] {CVE-2025-39779}
- ext4: preserve SB_I_VERSION on remount (Baokun Li)
- scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems (Ranjan Kumar)
- scsi: mpi3mr: Drop unnecessary volatile from __iomem pointers (Ranjan Kumar)
- iio: adc: ad7173: fix setting ODR in probe (David Lechner)
- PCI: rockchip: Set Target Link Speed to 5.0 GT/s before retraining (Geraldo Nascimento)
- PCI: rockchip: Use standard PCIe definitions (Geraldo Nascimento)
- PCI: imx6: Add IMX8MQ_EP third 64-bit BAR in epc_features (Richard Zhu)
- PCI: imx6: Add i.MX8Q PCIe Endpoint (EP) support (Frank Li)
- Mark xe driver as BROKEN if kernel page size is not 4kB (Simon Richter)
- mptcp: disable add_addr retransmission when timeout is 0 (Geliang Tang)
- mptcp: remove duplicate sk_reset_timer call (Geliang Tang)
- soc: qcom: mdt_loader: Fix error return values in mdt_header_valid() (Dan Carpenter)
- scsi: core: Fix command pass through retry regression (Mike Christie)
- drm/amd/display: Fill display clock and vblank time in dce110_fill_display_configs (Timur Kristóf)
- drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristóf)
- drm/amd/display: Fix DP audio DTO1 clock source on DCE 6. (Timur Kristóf)
- drm/amd/display: Fix Xorg desktop unresponsive on Replay panel (Tom Chung)
- drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristóf)
- drm/amd/display: Don't overclock DCE 6 by 15% (Timur Kristóf)
- drm/amd/display: Avoid a NULL pointer dereference (Mario Limonciello) [Orabug: 38401594] {CVE-2025-39693}
- drm/amdgpu/swm14: Update power limit logic (Alex Deucher)
- accel/habanalabs/gaudi2: Use kvfree() for memory allocated with kvcalloc() (Thorsten Blum)
- kvm: retry nx_huge_page_recovery_thread creation (Keith Busch)
- platform/x86/intel-uncore-freq: Check write blocked for ELC (Srinivas Pandruvada)
- s390/sclp: Fix SCCB present check (Peter Oberparleiter)
- RDMA/rxe: Flush delayed SKBs while releasing RXE resources (Zhu Yanjun) [Orabug: 38401605] {CVE-2025-39695}
- ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6 and EliteBook 830 G6 (Evgeniy Harchenko)
- mm/memory-failure: fix infinite UCE for VM_PFNMAP pfn (Tu Jinjiang)
- mm/debug_vm_pgtable: clear page table entries at destroy_args() (Herton Ronaldo Krzesinski)
- NFS: Fix a race when updating an existing write (Trond Myklebust) [Orabug: 38401608] {CVE-2025-39697}
- mmc: sdhci-pci-gli: GL9763e: Rename the gli_set_gl9763e() for consistency (Victor Shih)
- mmc: sdhci-pci-gli: GL9763e: Mask the replay timer timeout of AER (Victor Shih)
- memstick: Fix deadlock by moving removing flag earlier (Jiayi Li)
- mmc: sdhci-pci-gli: Add a new function to simplify the code (Victor Shih)
- iommu/arm-smmu-v3: Fix smmu_domain->nr_ats_masters decrement (Nicolin Chen)
- iov_iter: iterate_folioq: fix handling of offset >= folio size (Dominique Martinet)
- io_uring/futex: ensure io_futex_wait() cleans up properly on failure (Jens Axboe) [Orabug: 38401614] {CVE-2025-39698}
- sched_ext: initialize built-in idle state before ops.init() (Andrea Righi)
- ata: libata-scsi: Return aborted command when missing sense and result TF (Damien Le Moal)
- io_uring/net: commit partial buffers on retry (Jens Axboe) [Orabug: 38395103] {CVE-2025-38730}
- netfs: Fix unbuffered write error handling (David Howells) [Orabug: 38401724] {CVE-2025-39723}
- btrfs: send: make fs_path_len() inline and constify its argument (Filipe Manana)
- btrfs: send: use fallocate for hole punching with send stream v2 (Filipe Manana)
- btrfs: send: avoid path allocation for the current inode when issuing commands (Filipe Manana)
- btrfs: send: keep the current inode's path cached (Filipe Manana)
- btrfs: send: add and use helper to rename current inode when processing refs (Filipe Manana)
- btrfs: send: only use boolean variables at process_recorded_refs() (Filipe Manana)
- btrfs: send: factor out common logic when sending xattrs (Filipe Manana)
- xfs: fully decouple XFS_IBULK* flags from XFS_IWALK* flags (Christoph Hellwig)
- btrfs: zoned: requeue to unused block group list if zone finish failed (Naohiro Aota)
- btrfs: codify pattern for adding block_group to bg_list (Boris Burkov)
- btrfs: explicitly ref count block_group on new_bgs list (Boris Burkov)
- btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() (Filipe Manana) [Orabug: 38434999] {CVE-2025-39800}
- btrfs: always abort transaction on failure to add block group to free space tree (Filipe Manana)
- btrfs: move transaction aborts to the error site in add_block_group_free_space() (David Sterba)
- btrfs: qgroup: fix race between quota disable and quota rescan ioctl (Filipe Manana) [Orabug: 38423413] {CVE-2025-39759}
- btrfs: qgroup: drop unused parameter fs_info from __del_qgroup_rb() (David Sterba)
- usb: typec: fusb302: cache PD RX state (Sebastian Reichel)
- USB: typec: Use str_enable_disable-like helpers (Krzysztof Kozlowski)
- x86/sev: Ensure SVSM reserved fields in a page validation entry are initialized to zero (Tom Lendacky)
- mm/damon/ops-common: ignore migration request to invalid nodes (Seongjae Park) [Orabug: 38401618] {CVE-2025-39700}
- selftests: mptcp: pm: check flush doesn't reset limits (Matthieu Baerts)
- mptcp: pm: kernel: flush: do not reset ADD_ADDR limit (Matthieu Baerts)
- mptcp: drop skb if MPTCP skb extension allocation fails (Christoph Paasch)
- ACPI: pfr_update: Fix the driver update version check (Chen Yu)
- ipv6: sr: Fix MAC comparison to be constant-time (Eric Biggers)
- sched/ext: Fix invalid task state transitions on class switch (Andrea Righi) [Orabug: 38423494] {CVE-2025-39780}
- net, hsr: reject HSR frame if skb can't hold tag (Jakub Acs)
- LoongArch: KVM: Make function kvm_own_lbt() robust (Bibo Mao)
- drm/amd/display: Don't overwrite dce60_clk_mgr (Timur Kristóf)
- drm/amd/display: fix a Null pointer dereference vulnerability (Siyang Liu) [Orabug: 38401635] {CVE-2025-39705}
- drm/amd/display: Add primary plane to commits for correct VRR handling (Michel Dänzer)
- drm/amdkfd: Destroy KFD debugfs after destroy KFD wq (Amber Lin) [Orabug: 38401643] {CVE-2025-39706}
- drm/amdgpu: update mmhub 4.1.0 client id mappings (Alex Deucher)
- drm/amdgpu: update mmhub 3.0.1 client id mappings (Alex Deucher)
- drm/amdgpu: Update external revid for GC v9.5.0 (Lijo Lazar)
- drm/amdgpu: Initialize data to NULL in imu_v12_0_program_rlc_ram() (Nathan Chancellor)
- drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities (Peter Shkenev) [Orabug: 38401649] {CVE-2025-39707}
- drm/amdgpu: Avoid extra evict-restore process. (Gang Ba)
- drm/amd: Restore cached power limit during resume (Mario Limonciello)
- media: venus: venc: Clamp param smaller than 1fps and bigger than 240 (Ricardo Ribalda)
- media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda)
- media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz)
- media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz)
- media: venus: Fix MSM8998 frequency table (Konrad Dybcio)
- media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar)
- media: qcom: camss: cleanup media device allocated resource on error path (Vladimir Zapolskiy)
- media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls (Hans de Goede)
- media: mt9m114: Fix deadlock in get_frame_interval/set_frame_interval (Mathis Foerst)
- media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong)
- media: pisp_be: Fix pm_runtime underrun in probe (Jacopo Mondi)
- media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401675] {CVE-2025-39713}
- media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401682] {CVE-2025-39714}
- media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus)
- media: verisilicon: Fix AV1 decoder clock frequency (Nicolas Dufresne)
- media: vivid: fix wrong pixel_array control size (Hans Verkuil)
- media: ipu6: isys: Use correct pads for xlate_streams() (Sakari Ailus)
- media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li)
- media: hi556: correct the test pattern configuration (Bingbu Cao)
- media: gspca: Add bounds checking to firmware parser (Dan Carpenter)
- parisc: Update comments in make_insert_tlb (John David Anglin)
- parisc: Try to fixup kernel exception in bad_area_nosemaphore path of do_page_fault() (John David Anglin)
- parisc: Revise gateway LWS calls to probe user read access (John David Anglin)
- parisc: Revise __get_user() to probe user read access (John David Anglin)
- parisc: Rename pte_needs_flush() to pte_needs_cache_flush() in cache.c (John David Anglin)
- parisc: Makefile: explain that 64BIT requires both 32-bit and 64-bit compilers (Randy Dunlap)
- parisc: Drop WARN_ON_ONCE() from flush_cache_vmap (John David Anglin)
- parisc: Define and use set_pte_at() (John David Anglin)
- parisc: Check region is readable by user in raw_copy_from_user() (John David Anglin)
- soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter)
- kbuild: userprogs: use correct linker when mixing clang and GNU ld (Thomas Weißschuh)
- jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423507] {CVE-2025-39782}
- f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu)
- ASoC: SOF: amd: acp-loader: Use GFP_KERNEL for DMA allocations in resume context (Muhammad Usama Anjum)
- amdgpu/amdgpu_discovery: increase timeout limit for IFWI init (Xaver Hugl)
- phy: qcom: phy-qcom-m31: Update IPQ5332 M31 USB phy initialization sequence (Kathiravan Thirumoorthy)
- vhost/vsock: Avoid allocating arbitrarily-sized SKBs (Will Deacon)
- vsock/virtio: Validate length in packet header before skb_put() (Will Deacon) [Orabug: 38401705] {CVE-2025-39718}
- PCI: imx6: Delay link start until configfs 'start' written (Richard Zhu)
- PCI: imx6: Remove apps_reset toggling from imx_pcie_{assert/deassert}_core_reset (Richard Zhu)
- PCI: imx6: Add IMX8MM_EP and IMX8MP_EP fixed 256-byte BAR 4 in epc_features (Richard Zhu)
- PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal)
- PCI: endpoint: Fix configfs group list head handling (Damien Le Moal)
- PCI/portdrv: Use is_pciehp instead of is_hotplug_bridge (Lukas Wunner)
- readahead: fix return value of page_cache_next_miss() when no hole is found (Chi Zhiling)
- mtd: rawnand: renesas: Add missing check after DMA map (Thomas Fourier)
- mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier)
- mtd: spinand: propagate spinand_wait() errors from spinand_write_page() (Gabor Juhos)
- mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle)
- hwmon: (gsc-hwmon) fix fan pwm setpoint show functions (Tim Harvey)
- pwm: mediatek: Fix duty and period setting (Uwe Kleine-König)
- pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-König)
- pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea)
- wifi: ath11k: fix dest ring-buffer corruption when ring is full (Johan Hovold)
- wifi: ath11k: fix source ring-buffer corruption (Johan Hovold)
- wifi: ath11k: fix dest ring-buffer corruption (Johan Hovold)
- wifi: ath12k: fix dest ring-buffer corruption when ring is full (Johan Hovold)
- wifi: ath12k: fix source ring-buffer corruption (Johan Hovold)
- wifi: ath12k: fix dest ring-buffer corruption (Johan Hovold)
- wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor)
- iio: adc: ad_sigma_delta: change to buffer predisable (David Lechner)
- iio: imu: bno055: fix OOB access of hw_xlate array (David Lechner)
- zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski)
- soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423524]
- ata: libata-scsi: Fix CDL control (Igor Pylypiv)
- scsi: ufs: ufs-pci: Fix default runtime and system PM levels (Adrian Hunter)
- scsi: ufs: ufs-pci: Fix hibernate state transition for Intel MTL-like host controllers (Archana Patni)
- ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal)
- scsi: mpi3mr: Fix race between config read submit and interrupt completion (Ranjan Kumar)
- scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE (André Draszik)
- scsi: dt-bindings: mediatek,ufs: Add ufs-disable-mcq flag for UFS host (Macpaul Lin)
- dt-bindings: display: sprd,sharkl3-dsi-host: Fix missing clocks constraints (Krzysztof Kozlowski)
- dt-bindings: display: sprd,sharkl3-dpu: Fix missing clocks constraints (Krzysztof Kozlowski)
- apparmor: Fix 8-byte alignment for initial dfa blob streams (Helge Deller)
- arm64: dts: ti: k3-am62-verdin: Enable pull-ups on I2C buses (Emanuele Ghidoli)
- arm64: dts: ti: k3-am62a7-sk: fix pinmux for main_uart1 (Hong Guan)
- arm64: dts: exynos: gs101: ufs: add dma-coherent property (Peter Griffin)
- arm64: dts: ti: k3-pinctrl: Enable Schmitt Trigger by default (Alexander Sverdlin)
- arm64: dts: ti: k3-am62-main: Remove eMMC High Speed DDR support (Judith Mendez)
- btrfs: fix printing of mount info messages for NODATACOW/NODATASUM (Kyoji Ogasawara)
- btrfs: restore mount option info messages during mount (Kyoji Ogasawara)
- btrfs: fix incorrect log message for nobarrier mount option (Kyoji Ogasawara)
- btrfs: zoned: fix write time activation failure for metadata block group (Naohiro Aota)
- ext4: fix hole length calculation overflow in non-extent inodes (Zhang Yi)
- ext4: use kmalloc_array() for array space allocation (Liao Yuanhong)
- ext4: don't try to clear the orphan_present feature block device is r/o (Theodore Ts'O)
- ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo)
- ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo)
- ext4: check fast symlink for ea_inode correctly (Andreas Dilger)
- tracing: fprobe-event: Sanitize wildcard for fprobe event name (Masami Hiramatsu)
- ksmbd: fix refcount leak causing resource not released (Ziyan Xu)
- crypto: octeontx2 - Fix address alignment on CN10KB and CN10KA-B0 (Bharat Bhushan)
- crypto: octeontx2 - Fix address alignment on CN10K A0/A1 and OcteonTX2 (Bharat Bhushan)
- crypto: octeontx2 - Fix address alignment issue on ucode loading (Bharat Bhushan)
- crypto: qat - flush misc workqueue during device shutdown (Giovanni Cabiddu) [Orabug: 38401716] {CVE-2025-39721}
- crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP (John Ernberg)
- crypto: qat - lower priority for skcipher and aead algorithms (Giovanni Cabiddu)
- lib/crypto: mips/chacha: Fix clang build and remove unneeded byteswap (Eric Biggers)
- vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle)
- vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle)
- bus: mhi: host: Detect events pointing to unexpected TREs (Youssef Samir) [Orabug: 38423538] {CVE-2025-39790}
- bus: mhi: host: Fix endianness of BHI vector table (Alexander Wilhelm)
- usb: dwc3: imx8mp: fix device leak at unbind (Johan Hovold)
- usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold)
- usb: musb: omap2430: fix device leak at unbind (Johan Hovold)
- usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold)
- usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor)
- m68k: Fix lost column on framebuffer debug console (Finn Thain)
- dm: Check for forbidden splitting of zone write operations (Damien Le Moal)
- dm: dm-crypt: Do not partially accept write BIOs with zoned targets (Damien Le Moal) [Orabug: 38423543] {CVE-2025-39791}
- PM: runtime: Take active children into account in pm_runtime_get_if_in_use() (Rafael J. Wysocki)
- platform/chrome: cros_ec: Unregister notifier in cros_ec_unregister() (Tzung-Bi Shih)
- cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter)
- ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal)
- serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401726] {CVE-2025-39724}
-
Tue Sep 23 2025 Sherry Yang <sherry.yang@oracle.com> [6.12.0-105.43.1.el10uek]
- uek: kabi: update x86_64 kABI files for new symbols (Yifei Liu) [Orabug: 38019851]
- net/rds: Enforce sibling ToS lanes are not UP when auto reaping a conn (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: replace rds_conn_addr_list with reentrant code (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: Auto-reap dropped conn via sysctl net.rds.conn_reap_after_drop_secs (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: Enable tracing for rds_conn_reap() (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: Disallow user conn reap via sysctl net.rds.conn_user_reap_enable (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: Add sockopt member all_tos to reset/reap all conns for src-dst (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: Reap rds_rdma connections via sockopt RDS_CONN_REAP (Sharath Srinivasan) [Orabug: 38343379]
- net/rds: tracepoints for rds_conn_kref_get and put (Sharath Srinivasan) [Orabug: 38343388]
- net/rds: Add krefs to struct rds_connection (Sharath Srinivasan) [Orabug: 38343388]
- net/mlx5: HWS, fix bad parameter in CQ creation (Yevgeny Kliteynik) [Orabug: 38431789]
- net/mlx5e: Support RX xfrm state selector's UPSPEC for packet offload (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Add pass flow group for IPSec RX status table (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Add num_reserved_entries param for ipsec_ft_create() (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Skip IPSec RX policy check for crypto offload (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Move IPSec policy check after decryption (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Change the destination of IPSec RX SA miss rule (Jianbo Liu) [Orabug: 38431789]
- net/mlx5e: Add helper function to update IPSec default destination (Jianbo Liu) [Orabug: 38431789]
- net/mlx5: fs, add counter object to flow destination (Moshe Shemesh) [Orabug: 38431789]
- net/mlx5: DR, moved all the SWS code into a separate directory (Yevgeny Kliteynik) [Orabug: 38431789]
- net/mlx5: hw counters: Remove mlx5_fc_create_ex (Cosmin Ratiu) [Orabug: 38431789]
- net/mlx5: hw counters: Don't maintain a counter count (Cosmin Ratiu) [Orabug: 38431789]
- net/mlx5: hw counters: Drop unneeded cacheline alignment (Cosmin Ratiu) [Orabug: 38431789]
- net/mlx5: hw counters: Replace IDR+lists with xarray (Cosmin Ratiu) [Orabug: 38431789]
- net/mlx5: hw counters: Use kvmalloc for bulk query buffer (Cosmin Ratiu) [Orabug: 38431789]
- net/mlx5: hw counters: Make fc_stats & fc_pool private (Cosmin Ratiu) [Orabug: 38431789]
- uek: kabi: cleanup x86_64 kabi list for duplicate entries. (Yifei Liu) [Orabug: 38448304]
- KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero) [Orabug: 38459433]