From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
patches@lists.linux.dev, linux-kernel@vger.kernel.org,
torvalds@linux-foundation.org, akpm@linux-foundation.org,
linux@roeck-us.net, shuah@kernel.org, patches@kernelci.org,
lkft-triage@lists.linaro.org, pavel@nabladev.com,
jonathanh@nvidia.com, f.fainelli@gmail.com,
sudipm.mukherjee@gmail.com, rwarsow@gmx.de, conor@kernel.org,
hargar@microsoft.com, broonie@kernel.org, achill@achill.org,
sr@sladewatkins.com
Subject: [PATCH 6.18 00/94] 6.18.47-rc1 review
Date: Tue, 25 Aug 2026 15:24:56 +0200 [thread overview]
Message-ID: <20260825132541.887883084@linuxfoundation.org> (raw)
This is the start of the stable review cycle for the 6.18.47 release.
There are 94 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Thu, 27 Aug 2026 13:25:02 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.47-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 6.18.47-rc1
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Bluetooth: hci_aml: validate firmware segment lengths
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: ISO: zero the sockaddr before returning it in getname
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_sync: Fix accept list UAF during suspend
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Bluetooth: hci_event: validate LE Set CIG Parameters response
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_event: fix LE list UAF on reset
Linus Torvalds <torvalds@linux-foundation.org>
drm/xe: Don't hand out the flat CCS storage as usable VRAM
Michael Bommarito <michael.bommarito@gmail.com>
HID: hyperv: validate initial device info bounds
Ibrahim Hashimov <security@auditcode.ai>
HID: uclogic: fix use-after-free of inrange_timer on remove
Haoxiang Li <haoxiang_li2024@163.com>
HID: sensor: custom: Fix use-after-free in enable_sensor
Jann Horn <jannh@google.com>
HID: core: fix number/pointer type confusion on long items
Jiangshan Yi <yijiangshan@kylinos.cn>
HID: nintendo: stop device IO before hid_hw_stop on probe failure
Jiangshan Yi <yijiangshan@kylinos.cn>
HID: nintendo: register input device after capabilities are set
Ibrahim Hashimov <security@auditcode.ai>
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
Peter Zijlstra <peterz@infradead.org>
futex: Fix might_sleep() warning in futex_pivot_pending()
Hyunwoo Kim <imv4bel@gmail.com>
futex: Fix race on the initial mm->futex.phash.ref allocation
Thomas Gleixner <tglx@kernel.org>
futex/pi: Plug private futex exec() race
Thomas Gleixner <tglx@kernel.org>
futex: Sanitize and document task_struct::futex::state transitions
Kyle Zeng <kylebot@openai.com>
futex/pi: Reject cross-mm private futex owners
Donglin Lyu <DongLin_Lyu@outlook.com>
Input: atkbd - skip deactivate for HONOR ZQC-P
Cryolitia PukNgae <cryolitia.pukngae@linux.dev>
Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
Xiang Mei (Microsoft) <xmei5@asu.edu>
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Anand Khoje <anand.a.khoje@oracle.com>
net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Baul Lee <baul.lee@xbow.com>
HID: pidff: fix OOB write when hid->inputs is empty
Baul Lee <baul.lee@xbow.com>
HID: core: fix OOB read of field->usage in hid_set_field()
Lee Jones <lee@kernel.org>
HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
Jose Villaseñor Montfort <pepemontfort@gmail.com>
HID: magicmouse: do not keep a stale msc->input if no input is claimed
Christopher Kodama <ckhordiasma@gmail.com>
HID: magicmouse: re-enable multitouch after reset-resume
Andrei Fed <andfed.net@gmail.com>
HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
Dawid Wróbel <me@dawidwrobel.com>
ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
Bryam Vargas <hexlabsecurity@proton.me>
selinux: require a class's permission values to cover its permission count
Christian Göttsche <cgzones@googlemail.com>
selinux: more strict policy parsing
Christian Göttsche <cgzones@googlemail.com>
selinux: use u16 for security classes
Shardul Bankar <shardul.b@mpiricsoftware.com>
mptcp: pm: fix memory leak from alloc-during-teardown race
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: uniform announced addresses helpers
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: rename add_entry structure to add_addr
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: use for_each_subflow helper
Yifei Gao <gyf161023@gmail.com>
nvmet: pci-epf: put CQ ref on create_cq mapping failure
Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
Ibrahim Hashimov <security@auditcode.ai>
nvmet-tcp: bound SGL data length before allocating command buffers
Jiang HongHui <jiang_hh2019@163.com>
nvmet-fc: fix invalid free in LS IOD error path
Bryam Vargas <hexlabsecurity@proton.me>
nvmet-auth: zero the AUTH_RECEIVE response buffer
Griffin Kroah-Hartman <griffin@kroah.com>
dmaengine: fsl-edma: Add error handling for devm_kasprintf
Griffin Kroah-Hartman <griffin@kroah.com>
mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
Luxiao Xu <rakukuip@gmail.com>
ipv6: fix use-after-free in ip6_finish_output2()
Yong Wang <edragain@163.com>
ipv4: reject undersized MTUs in ip_do_fragment()
Maarten Lankhorst <dev@lankhorst.se>
drm/xe: Fix DPT allocation paths.
Linmao Li <lilinmao@kylinos.cn>
nfc: nci: free destination parameters when closing a connection
Samuel Page <sam@bynar.io>
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
Samuel Page <sam@bynar.io>
nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
Bryam Vargas <hexlabsecurity@proton.me>
nfc: nci: add data_len bound checks to activation parameter extractors
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: st21nfca: validate ATR_REQ length against the received frame
Xu Rao <raoxu@uniontech.com>
nfc: pn533: purge fragmented skbs during cleanup
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: llcp: reject PDUs shorter than the LLCP header
Muhammad Bilal <meatuni001@gmail.com>
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: llcp: bound the connect_sn TLV walk to the skb
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: microread: validate target discovery payload lengths
Bryam Vargas <hexlabsecurity@proton.me>
nfc: fdp: bound the device-reported read length and fix an skb leak
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: digital: clamp SENSF_RES length to the destination buffer
Pavitra Jha <jhapavitra98@gmail.com>
libceph: fix OOB read in decode_watchers() via missing bounds check
Hongling Zeng <zenghongling@kylinos.cn>
xfs: validate attr entry pointer before field access
Jiazi Liu <jiazi.liu1984@gmail.com>
ext4: fix incorrect function call when initializing s_resgid
Eric Biggers <ebiggers@kernel.org>
ext4: don't enable DAX on new encrypted files
Guanghui Yang <3497809730@qq.com>
ext4: propagate errors from fast commit range replay
Jia Zhu <zhujia.zj@bytedance.com>
ext4: avoid tail write_begin walk for uptodate folios
Guanghui Yang <3497809730@qq.com>
ext4: clear error before retrying inode xattr space fallback
Ryusuke Konishi <konishi.ryusuke@gmail.com>
nilfs2: reject invalid block index in GC ioctl
Matthias Goergens <matthias.goergens@gmail.com>
ext4: stop retrying saturated xattr cache entries
Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
kcov: fix data corruption and race conditions on PREEMPT_RT
Rik van Riel <riel@surriel.com>
null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
Ian Bridges <icb@fastmail.org>
ocfs2: fix missing metadata reservation for large xattrs
Jens Axboe <axboe@kernel.dk>
io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
Ali Ahmet Memis <ali@iusegentoo.com>
io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
Vishnu Razdan <vrazdan@openai.com>
io_uring/io-wq: fix worker accounting when canceling creation callbacks
Woraphat Khiaodaeng <worapat.kd2@gmail.com>
io_uring/cmd: fix iovec leak when the async cmd is not recycled
Takashi Iwai <tiwai@suse.de>
ALSA: dummy: Check card index validity at probe
Jens Axboe <axboe@kernel.dk>
io_uring/futex: don't mark futex wake requests as inflight
Guixin Liu <kanie@linux.alibaba.com>
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
Griffin Kroah-Hartman <griffin@kroah.com>
rndis_host: add overflow check in rndis_rx_fixup()
Geoffrey D. Bennett <g@b4.vu>
ALSA: scarlett2: Use a private URB for the notification endpoint
Geoffrey D. Bennett <g@b4.vu>
ALSA: FCP: Use a private URB for the notification endpoint
Peiyang He <peiyang_he@smail.nju.edu.cn>
iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
Shameer Kolothum <skolothumtho@nvidia.com>
iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
Steffen Persvold <spersvold@gmail.com>
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
Darrick J. Wong <djwong@kernel.org>
xfs: don't livelock in scrub on a circular unlinked list
Darrick J. Wong <djwong@kernel.org>
xfs: hoist per-bucket unlinked list check to helper
Darrick J. Wong <djwong@kernel.org>
xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
Christoph Hellwig <hch@lst.de>
xfs: add a xchk_ip_set_corrupt helper
Luca Fresi <luca.fresi@bithiatec.com>
serial: sc16is7xx: enable THRI before filling TX FIFO
Hugo Villeneuve <hvilleneuve@dimonoff.com>
serial: sc16is7xx: use guards for simple mutex locks
Hugo Villeneuve <hvilleneuve@dimonoff.com>
serial: sc16is7xx: rename EFR mutex with generic name
-------------
Diffstat:
Makefile | 4 +-
drivers/block/null_blk/zoned.c | 10 +-
drivers/bluetooth/hci_aml.c | 18 +-
drivers/dma/fsl-edma-main.c | 2 +
drivers/gpu/drm/xe/display/xe_fb_pin.c | 32 +--
drivers/gpu/drm/xe/xe_vram.c | 23 ++-
drivers/hid/hid-core.c | 11 +-
drivers/hid/hid-hyperv.c | 27 ++-
drivers/hid/hid-input.c | 3 +
drivers/hid/hid-magicmouse.c | 64 +++++-
drivers/hid/hid-nintendo.c | 22 +-
drivers/hid/hid-sensor-custom.c | 21 +-
drivers/hid/hid-uclogic-core.c | 12 +-
drivers/hid/usbhid/hid-pidff.c | 13 +-
drivers/input/keyboard/atkbd.c | 23 ++-
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 2 +
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h | 1 +
drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 15 +-
drivers/iommu/iommufd/ioas.c | 4 +
drivers/mailbox/mailbox-mchp-ipc-sbi.c | 2 +
drivers/net/ethernet/pensando/ionic/ionic_lif.c | 17 +-
drivers/net/ethernet/pensando/ionic/ionic_txrx.c | 7 +-
drivers/net/usb/rndis_host.c | 6 +-
drivers/nfc/fdp/i2c.c | 27 +++
drivers/nfc/microread/microread.c | 31 ++-
drivers/nfc/pn533/pn533.c | 1 +
drivers/nfc/st21nfca/dep.c | 3 +
drivers/nvme/target/admin-cmd.c | 2 +-
drivers/nvme/target/fabrics-cmd-auth.c | 2 +-
drivers/nvme/target/fc.c | 2 +-
drivers/nvme/target/pci-epf.c | 10 +-
drivers/nvme/target/tcp.c | 18 +-
drivers/pci/controller/pci-host-generic.c | 11 +-
drivers/pci/ecam.c | 13 ++
drivers/tty/serial/sc16is7xx.c | 40 ++--
fs/exec.c | 8 +-
fs/ext4/crypto.c | 40 ++--
fs/ext4/fast_commit.c | 16 +-
fs/ext4/ialloc.c | 4 +
fs/ext4/inode.c | 11 +-
fs/ext4/super.c | 2 +-
fs/ext4/xattr.c | 7 +-
fs/nilfs2/ioctl.c | 20 +-
fs/ocfs2/xattr.c | 18 +-
fs/xfs/libxfs/xfs_attr_leaf.c | 14 ++
fs/xfs/scrub/agheader.c | 94 ++++++---
fs/xfs/scrub/agheader_repair.c | 17 +-
fs/xfs/scrub/bmap.c | 8 +-
fs/xfs/scrub/common.c | 10 +-
fs/xfs/scrub/common.h | 2 +
fs/xfs/scrub/dir.c | 2 +-
fs/xfs/scrub/dirtree.c | 4 +-
fs/xfs/scrub/metapath.c | 6 +-
fs/xfs/scrub/nlinks.c | 12 +-
fs/xfs/scrub/parent.c | 6 +-
fs/xfs/scrub/rtbitmap.c | 12 +-
fs/xfs/scrub/rtsummary.c | 12 +-
include/linux/futex.h | 2 +
include/linux/pci-ecam.h | 3 +
include/linux/sched.h | 8 +
include/linux/wait.h | 1 +
include/linux/wait_bit.h | 1 +
io_uring/futex.c | 11 +
io_uring/futex.h | 1 +
io_uring/io-wq.c | 9 +-
io_uring/opdef.c | 2 +-
io_uring/rsrc.c | 2 +-
io_uring/uring_cmd.c | 8 +-
kernel/futex/core.c | 122 +++++++----
kernel/futex/futex.h | 9 +
kernel/futex/pi.c | 125 +++++++++---
kernel/kcov.c | 90 ++++----
kernel/sched/wait.c | 15 ++
kernel/sched/wait_bit.c | 14 +-
lib/Kconfig.debug | 5 +-
net/bluetooth/hci_event.c | 8 +-
net/bluetooth/hci_sync.c | 46 ++++-
net/bluetooth/iso.c | 32 ++-
net/bluetooth/mgmt.c | 8 +
net/bluetooth/rfcomm/core.c | 24 ++-
net/ceph/osd_client.c | 5 +-
net/ipv4/ip_output.c | 4 +
net/ipv6/ip6_output.c | 2 +
net/mptcp/options.c | 2 +-
net/mptcp/pm.c | 74 ++++---
net/mptcp/pm_kernel.c | 22 +-
net/mptcp/pm_userspace.c | 10 +-
net/mptcp/protocol.h | 25 +--
net/mptcp/subflow.c | 4 +-
net/nfc/digital_technology.c | 2 +
net/nfc/llcp_commands.c | 18 +-
net/nfc/llcp_core.c | 15 +-
net/nfc/nci/ntf.c | 36 +++-
net/nfc/nci/rsp.c | 1 +
net/xfrm/xfrm_state.c | 4 +-
security/selinux/include/security.h | 1 +
security/selinux/ss/avtab.c | 35 +++-
security/selinux/ss/avtab.h | 13 ++
security/selinux/ss/conditional.c | 18 +-
security/selinux/ss/constraint.h | 1 +
security/selinux/ss/policydb.c | 248 +++++++++++++++++++----
security/selinux/ss/policydb.h | 31 ++-
security/selinux/ss/services.c | 8 +-
sound/drivers/dummy.c | 6 +
sound/soc/codecs/lpass-tx-macro.c | 4 +-
sound/usb/fcp.c | 38 ++--
sound/usb/mixer.c | 6 +
sound/usb/mixer.h | 2 +
sound/usb/mixer_scarlett2.c | 98 +++++----
109 files changed, 1533 insertions(+), 570 deletions(-)
next reply other threads:[~2026-08-25 13:39 UTC|newest]
Thread overview: 104+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 13:24 Greg Kroah-Hartman [this message]
2026-08-25 13:24 ` [PATCH 6.18 01/94] serial: sc16is7xx: rename EFR mutex with generic name Greg Kroah-Hartman
2026-08-25 13:24 ` [PATCH 6.18 02/94] serial: sc16is7xx: use guards for simple mutex locks Greg Kroah-Hartman
2026-08-25 13:24 ` [PATCH 6.18 03/94] serial: sc16is7xx: enable THRI before filling TX FIFO Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 04/94] xfs: add a xchk_ip_set_corrupt helper Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 05/94] xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 06/94] xfs: hoist per-bucket unlinked list check to helper Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 07/94] xfs: dont livelock in scrub on a circular unlinked list Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 08/94] PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 09/94] Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 10/94] iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 11/94] iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 12/94] ALSA: FCP: Use a private URB for the notification endpoint Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 13/94] ALSA: scarlett2: " Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 14/94] rndis_host: add overflow check in rndis_rx_fixup() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 15/94] nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 16/94] io_uring/futex: dont mark futex wake requests as inflight Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 17/94] ALSA: dummy: Check card index validity at probe Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 18/94] io_uring/cmd: fix iovec leak when the async cmd is not recycled Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 19/94] io_uring/io-wq: fix worker accounting when canceling creation callbacks Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 20/94] io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 21/94] io_uring/uring_cmd: dont skip completion for a synchronous multishot cmd Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 22/94] ocfs2: fix missing metadata reservation for large xattrs Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 23/94] null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 24/94] kcov: fix data corruption and race conditions on PREEMPT_RT Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 25/94] ext4: stop retrying saturated xattr cache entries Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 26/94] nilfs2: reject invalid block index in GC ioctl Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 27/94] ext4: clear error before retrying inode xattr space fallback Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 28/94] ext4: avoid tail write_begin walk for uptodate folios Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 29/94] ext4: propagate errors from fast commit range replay Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 30/94] ext4: dont enable DAX on new encrypted files Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 31/94] ext4: fix incorrect function call when initializing s_resgid Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 32/94] xfs: validate attr entry pointer before field access Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 33/94] libceph: fix OOB read in decode_watchers() via missing bounds check Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 34/94] nfc: digital: clamp SENSF_RES length to the destination buffer Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 35/94] nfc: fdp: bound the device-reported read length and fix an skb leak Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 36/94] nfc: microread: validate target discovery payload lengths Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 37/94] nfc: llcp: bound the connect_sn TLV walk to the skb Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 38/94] nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 39/94] nfc: llcp: reject PDUs shorter than the LLCP header Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 40/94] nfc: pn533: purge fragmented skbs during cleanup Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 41/94] nfc: st21nfca: validate ATR_REQ length against the received frame Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 42/94] nfc: nci: add data_len bound checks to activation parameter extractors Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 43/94] nfc: nci: fix out-of-bounds write in nci_target_auto_activated() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 44/94] nfc: nci: fix uninit-value in the RF discover/activated NTF handlers Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 45/94] nfc: nci: free destination parameters when closing a connection Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 46/94] drm/xe: Fix DPT allocation paths Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 47/94] ipv4: reject undersized MTUs in ip_do_fragment() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 48/94] ipv6: fix use-after-free in ip6_finish_output2() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 49/94] mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 50/94] dmaengine: fsl-edma: Add error handling for devm_kasprintf Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 51/94] nvmet-auth: zero the AUTH_RECEIVE response buffer Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 52/94] nvmet-fc: fix invalid free in LS IOD error path Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 53/94] nvmet-tcp: bound SGL data length before allocating command buffers Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 54/94] nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 55/94] nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 56/94] nvmet: pci-epf: put CQ ref on create_cq mapping failure Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 57/94] mptcp: pm: use for_each_subflow helper Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 58/94] mptcp: pm: rename add_entry structure to add_addr Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 59/94] mptcp: pm: uniform announced addresses helpers Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 60/94] mptcp: pm: fix memory leak from alloc-during-teardown race Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 61/94] selinux: use u16 for security classes Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 62/94] selinux: more strict policy parsing Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.18 63/94] selinux: require a classs permission values to cover its permission count Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 64/94] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 65/94] HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 66/94] HID: magicmouse: re-enable multitouch after reset-resume Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 67/94] HID: magicmouse: do not keep a stale msc->input if no input is claimed Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 68/94] HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 69/94] HID: core: fix OOB read of field->usage in hid_set_field() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 70/94] HID: pidff: fix OOB write when hid->inputs is empty Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 71/94] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 72/94] xfrm: fix sk_dst_cache double-free in xfrm_user_policy() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 73/94] Input: atkbd - skip deactivate for HONOR FMB-Ps internal keyboard Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 74/94] Input: atkbd - skip deactivate for HONOR ZQC-P Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 75/94] futex/pi: Reject cross-mm private futex owners Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 76/94] futex: Sanitize and document task_struct::futex::state transitions Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 77/94] futex/pi: Plug private futex exec() race Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 78/94] futex: Fix race on the initial mm->futex.phash.ref allocation Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 79/94] futex: Fix might_sleep() warning in futex_pivot_pending() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 80/94] HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 81/94] HID: nintendo: register input device after capabilities are set Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 82/94] HID: nintendo: stop device IO before hid_hw_stop on probe failure Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 83/94] HID: core: fix number/pointer type confusion on long items Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 84/94] HID: sensor: custom: Fix use-after-free in enable_sensor Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 85/94] HID: uclogic: fix use-after-free of inrange_timer on remove Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 86/94] HID: hyperv: validate initial device info bounds Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 87/94] drm/xe: Dont hand out the flat CCS storage as usable VRAM Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 88/94] Bluetooth: hci_event: fix LE list UAF on reset Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 89/94] Bluetooth: hci_event: validate LE Set CIG Parameters response Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 90/94] Bluetooth: hci_sync: Fix accept list UAF during suspend Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 91/94] Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 92/94] Bluetooth: ISO: zero the sockaddr before returning it in getname Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 93/94] Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.18 94/94] Bluetooth: hci_aml: validate firmware segment lengths Greg Kroah-Hartman
2026-08-25 19:33 ` [PATCH 6.18 00/94] 6.18.47-rc1 review Pavel Machek
2026-08-25 23:12 ` Florian Fainelli
2026-08-26 0:05 ` Shuah Khan
2026-08-26 6:09 ` Ron Economos
2026-08-26 6:28 ` Wentao Guan
2026-08-26 10:32 ` Brett A C Sheffield
2026-08-26 12:19 ` Miguel Ojeda
2026-08-26 14:14 ` Peter Schneider
2026-08-27 12:30 ` Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825132541.887883084@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=achill@achill.org \
--cc=akpm@linux-foundation.org \
--cc=broonie@kernel.org \
--cc=conor@kernel.org \
--cc=f.fainelli@gmail.com \
--cc=hargar@microsoft.com \
--cc=jonathanh@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@roeck-us.net \
--cc=lkft-triage@lists.linaro.org \
--cc=patches@kernelci.org \
--cc=patches@lists.linux.dev \
--cc=pavel@nabladev.com \
--cc=rwarsow@gmx.de \
--cc=shuah@kernel.org \
--cc=sr@sladewatkins.com \
--cc=stable@vger.kernel.org \
--cc=sudipm.mukherjee@gmail.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.