All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core][wrynose 00/38] Patch review
@ 2026-09-09  7:28 Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
                   ` (37 more replies)
  0 siblings, 38 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:28 UTC (permalink / raw)
  To: openembedded-core

Please review this set of changes for wrynose and have comments back by
end of day Friday, September 11.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4697

The following changes since commit 31def396136be047e10c507a50264aad52ba6b0f:

  scripts/install-buildtools: Update to 6.0.3 (2026-09-04 16:21:55 +0200)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/wrynose-nut
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-nut

for you to fetch changes up to 4ce10a99a44924dd629fbd79268207b145ccfc62:

  gawk: skip randtest in ptest suite (2026-09-09 00:58:52 +0200)

----------------------------------------------------------------

Adarsh Jagadish Kamini (1):
  gnutls: fix CVE-2026-33845

Ankur Tyagi (1):
  wpa-supplicant: patch CVE-2026-58374

Bruce Ashfield (4):
  linux-yocto/6.18: update to v6.18.41
  linux-yocto/6.18: update to v6.18.43
  linux-yocto/6.18: update to v6.18.44
  linux-yocto/6.18: update to v6.18.48

Daniel Turull (1):
  libarchive: mark CVE-2026-14164 as fixed-version

Darsh Kelaiya (1):
  python3-lxml: fix CVE-2026-41066

Ghanshyam Banait (1):
  wget: fix CVE-2026-16599

Harish Sadineni (1):
  glibc: fix CVE-2026-19542

Hetvi Thakar (7):
  python3-pip: Fix CVE-2026-13346
  u-boot-tools: Ignore CVE-2026-29007
  u-boot-tools: Ignore CVE-2026-29008
  u-boot-tools: Ignore CVE-2026-29009
  u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix
  wget: Fix CVE-2026-58470
  python3-pip: Fix CVE-2026-8643

Hiago De Franco (1):
  improve_kernel_cve_report: fix backported-patch check

Himani Ramesh Barde (1):
  gawk: skip randtest in ptest suite

Himanshu Jadon (1):
  grub: disable grub-protect for native builds

Hitendra Prajapati (6):
  vim: Fix for CVE-2026-73072
  vim: Fix for CVE-2026-73073
  vim: Fix for CVE-2026-73074
  vim: Fix for CVE-2026-73076
  vim: Fix for CVE-2026-73077
  vim: Fix for CVE-2026-73078

Jaipaul Cheernam (1):
  p11-kit: upgrade 0.26.4 -> 0.26.5

Peter Marko (4):
  openssl: upgrade 3.5.7 -> 3.5.8
  apr-util: upgrade 1.6.3 -> 1.6.5
  curl: patch CVE-2026-11352
  curl: patch CVE-2026-11586

Peter Tatrai (2):
  testimage: handle bootlog variants on failed qemu tests
  time64: enable 64-bit time/file-offset flags for 32-bit nativesdk

Pratik Farkase (1):
  procps: ptest: skip flaky pgrep full process name match test

Vijay Anusuri (4):
  libxfont: Fix CVE-2026-56001
  libxfont: Fix CVE-2026-56002
  libxfont: Fix CVE-2026-56003
  perl: Fix CVE-2026-57433

 meta/classes-recipe/testimage.bbclass         |  27 +-
 meta/conf/distro/include/time64.inc           |  10 +
 meta/recipes-bsp/grub/grub2.inc               |   2 +
 ...-2026-33243.patch => CVE-2026-46728.patch} |  11 +-
 .../u-boot/u-boot-tools_2026.01.bb            |   8 +
 meta/recipes-bsp/u-boot/u-boot_2026.01.bb     |   4 +-
 .../{openssl_3.5.7.bb => openssl_3.5.8.bb}    |   2 +-
 .../wpa-supplicant/CVE-2026-58374-1.patch     |  52 +++
 .../wpa-supplicant/CVE-2026-58374-2.patch     |  47 +++
 .../wpa-supplicant/CVE-2026-58374-3.patch     |  55 +++
 .../wpa-supplicant/CVE-2026-58374-4.patch     |  46 +++
 .../wpa-supplicant/CVE-2026-58374-5.patch     |  47 +++
 .../wpa-supplicant/wpa-supplicant_2.11.bb     |   5 +
 .../glibc/glibc/0023-CVE-2026-19542.patch     |  98 +++++
 meta/recipes-core/glibc/glibc_2.43.bb         |   1 +
 .../perl/files/CVE-2026-57433.patch           |  32 ++
 meta/recipes-devtools/perl/perl_5.42.0.bb     |   1 +
 .../python/python3-lxml/CVE-2026-41066.patch  | 349 ++++++++++++++++++
 .../python/python3-lxml_6.0.2.bb              |   4 +-
 .../python/python3-pip/CVE-2026-13346.patch   | 206 +++++++++++
 .../CVE-2026-8643-regression_p1.patch         |  35 ++
 .../CVE-2026-8643-regression_p2.patch         |  69 ++++
 .../python/python3-pip/CVE-2026-8643.patch    |  80 ++++
 .../python/python3-pip_26.0.1.bb              |   7 +-
 meta/recipes-extended/gawk/gawk_5.4.0.bb      |   5 +-
 .../libarchive/libarchive_3.8.7.bb            |   4 +
 ...p-pgrep-full-process-name-match-test.patch |  39 ++
 meta/recipes-extended/procps/procps_4.0.6.bb  |   1 +
 .../wget/wget/CVE-2026-16599.patch            |  68 ++++
 .../wget/wget/CVE-2026-58470-regression.patch |  48 +++
 .../wget/wget/CVE-2026-58470.patch            |  79 ++++
 meta/recipes-extended/wget/wget_1.25.0.bb     |   3 +
 .../xorg-lib/libxfont/CVE-2026-56001.patch    |  87 +++++
 .../xorg-lib/libxfont/CVE-2026-56002.patch    | 150 ++++++++
 .../xorg-lib/libxfont/CVE-2026-56003.patch    | 114 ++++++
 .../xorg-lib/libxfont_1.5.4.bb                |   5 +
 .../linux/linux-yocto-rt_6.18.bb              |   6 +-
 .../linux/linux-yocto-tiny_6.18.bb            |   6 +-
 meta/recipes-kernel/linux/linux-yocto_6.18.bb |  24 +-
 ...le-function-prototype-warning-with-c.patch | 130 -------
 ...ion-Check-if-transform-is-supported-.patch |  37 --
 .../apr/apr-util/configfix.patch              |   4 +-
 .../{apr-util_1.6.3.bb => apr-util_1.6.5.bb}  |   4 +-
 .../curl/curl/CVE-2026-11352.patch            |  48 +++
 .../curl/curl/CVE-2026-11586.patch            | 203 ++++++++++
 meta/recipes-support/curl/curl_8.19.0.bb      |   2 +
 .../gnutls/gnutls/CVE-2026-33845.patch        | 166 +++++++++
 meta/recipes-support/gnutls/gnutls_3.8.12.bb  |   1 +
 .../{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb}  |   2 +-
 .../vim/files/CVE-2026-73072.patch            |  64 ++++
 .../vim/files/CVE-2026-73073.patch            | 105 ++++++
 .../vim/files/CVE-2026-73074.patch            | 115 ++++++
 .../vim/files/CVE-2026-73076.patch            | 167 +++++++++
 .../vim/files/CVE-2026-73077.patch            | 105 ++++++
 .../vim/files/CVE-2026-73078.patch            |  94 +++++
 meta/recipes-support/vim/vim.inc              |   6 +
 scripts/contrib/improve_kernel_cve_report.py  |   4 +-
 57 files changed, 2889 insertions(+), 205 deletions(-)
 rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%)
 rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%)
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
 create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch
 create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
 create mode 100644 meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-16599.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
 delete mode 100644 meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
 delete mode 100644 meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
 rename meta/recipes-support/apr/{apr-util_1.6.3.bb => apr-util_1.6.5.bb} (93%)
 create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11352.patch
 create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11586.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
 rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (97%)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73076.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch



^ permalink raw reply	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
                   ` (36 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:

    2fe596715f840 Linux 6.18.41
    6a7ecc25abe6f posix-cpu-timers: Prevent UAF caused by non-leader exec() race
    9f7268928ac0c posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
    221fc2f4d0eda Linux 6.18.40
    478c4d24193fe RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
    b87cbd4d198ae RDMA/bnxt_re: Initialize dpi variable to zero
    81e6faa5b6405 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
    1badb6866482d perf callchain: Handle multiple address spaces
    275eb39930947 seqlock: fix scoped_seqlock_read kernel-doc
    453cb79a15641 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks
    2764d031efd6d PCI: Fix Resizable BAR restore order
    2fb74141ec54e PCI: Fix BAR resize rollback path overwriting ret
    7425e7d82cb93 perf symbol: Fix ENOENT case for filename__read_build_id
    a888f3d5970ff pinctrl: airoha: fix pinctrl function mismatch issue
    267fdd9b6530c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
    779480ea79551 iommufd: Move vevent memory allocation outside spinlock
    73b5d5cb1f5a1 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
    ea7a76d7d614b KVM: arm64: nv: Re-translate VNCR before injecting abort
    459adfc6cd35f KVM: arm64: Deduplicate ASID retrieval code
    9d360fb820a3b samples/damon/mtier: fail early if address range parameters are invalid
    ec976851ad934 mm/damon/core: trace esz at first setup
    3b91c35961fa5 mm/damon/core: always put unsuccessfully committed target pids
    ba37cd4d8a751 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
    19d9996435db8 KVM: arm64: Ensure level is always initialized when relaxing perms
    c3a3d39867190 btrfs: fix incorrect buffered IO fallback for append direct writes
    998ee7f01ecfa btrfs: fix false IO failure after falling back to buffered write
    a4497a122e27f crypto: qat - fix restarting state leak on allocation failure
    6c78081d047c5 btrfs: remove folio parameter from ordered io related functions
    1a648c50a5057 btrfs: replace for_each_set_bit() with for_each_set_bitmap()
    99d4ae3fbb5b1 btrfs: concentrate the error handling of submit_one_sector()
    382fd8004cc60 crypto: atmel-sha204a - fail on hwrng registration error in probe path
    952db4b985c79 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
    69faa3779250d usb: gadget: f_fs: initialize reset_work at allocation time
    8a2fdbf92cdc7 functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions
    5fb0b09180a0f functionfs: switch to simple_remove_by_name()
    4744f07f6bb7c functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}()
    901c036cf6254 functionfs: don't abuse ffs_data_closed() on fs shutdown
    c3e6860252102 new helper: simple_remove_by_name()
    509b51327320b usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
    b78826a657998 usb: atm: ueagle-atm: remove function entry/exit debug messages
    6e5ef54b884f4 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
    41a4e80d5af04 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
    e534790c4c272 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
    bce232923aa9e xfs: use bio_reuse in the zone GC code
    adadb181ad42a xfs: only log freed extents for the current RTG in zoned growfs
    47c0e07433021 xfs: add a xfs_groups_to_rfsbs helper
    57454944737f3 bpf: Allow LPM map access from sleepable BPF programs
    8fccaeeb9e9c5 bpf: Consistently use bpf_rcu_lock_held() everywhere
    0b92ad64d6e4b bpf: Keep dynamic inner array lookups nullable
    c447be8d88c30 bpf: Introduce struct bpf_map_desc in verifier
    dccb3c557879d bpf: Consistently use reg_state() for register access in the verifier
    60eed44674295 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
    607217f7ad419 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
    7676ea09beb5d hfs/hfsplus: prevent getting negative values of offset/length
    f9b4b03ccc9c6 proc: protect ptrace_may_access() with exec_update_lock (part 1)
    07bf18dc63f78 seqlock: Change do_task_stat() to use scoped_seqlock_read()
    c897fd63762e0 seqlock: Introduce scoped_seqlock_read()
    497c6bae51674 proc: protect ptrace_may_access() with exec_update_lock (FD links)
    903d78e5aca77 proc: rename proc_setattr to proc_nochmod_setattr
    b56400364aed5 ksmbd: validate NTLMv2 response before updating session key
    74c2f0ffb81c8 ksmbd: Use HMAC-MD5 library for NTLMv2
    51c5f7e84cfed ksmbd: Use HMAC-SHA256 library for message signing and key generation
    bd27d9504d200 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash
    427faaa52b0b3 ksmbd: track the connection owning a byte-range lock
    6a37bc484f12e ksmbd: centralize ksmbd_conn final release to plug transport leak
    c7c884a1305aa ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
    e205f3e7e8c31 ksmbd: use opener credentials for FSCTL mutations
    90a93fb3230c9 cifs: SMB1 split: Add some #includes
    ff943e1f3d31f cifs: SMB1 split: Rename cifstransport.c
    36da806f7fbae Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
    6d0eeebe22ba7 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
    ef382a6baf0a9 media: nxp: imx8-isi: Fix use-after-free on remove
    4278953ff0cd4 media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
    49cd5ac6de8de crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
    4b51ee8a40fe4 staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
    5d76bc296bb58 staging: rtl8723bs: fix spaces around binary operators
    48323ebaeeeed staging: rtl8723bs: core: move constants to right side in comparison
    73cc54326de45 PCI: Skip Resizable BAR restore on read error
    f33837a754473 PCI: Move Resizable BAR code to rebar.c
    2242c75b63286 PCI: Add kerneldoc for pci_resize_resource()
    4b5322f0002aa PCI: Fix restoring BARs on BAR resize rollback path
    c18646165f21f PCI: Free saved list without holding pci_bus_sem
    534f20cdddc31 PCI: Try BAR resize even when no window was released
    dbb1d8507dd92 PCI: Change pci_dev variable from 'bridge' to 'dev'
    0d1c263e6fd73 PCI/IOV: Adjust ->barsz[] when changing BAR size
    0dfad346c293e PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
    e53d54b92f0c2 PCI: imx6: Fix reference clock source selection for i.MX95
    1228926e1e4d6 binder: cache secctx size before release zeroes it
    79ac87bb1a4c8 binder: Use LIST_HEAD() to initialize on stack list head
    7ed120b1a007b vfio/mlx5: Fix racy bitfields and tighten struct layout
    f8272331da877 ALSA: hda/tas2781: Cancel async firmware request at unbind
    6438d0707087e firmware_loader: Add cancel helper for async requests
    1ed7ff33cfc8c ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
    ad5c5bdb0f580 ALSA: scarlett2: Allow selecting config_set by firmware version
    2745574697ee4 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
    7f680924c5c2b ACPI: NFIT: core: Fix possible deadlock and missing notifications
    cf5f93228e7ab ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
    d57d2aae87b23 ACPI: bus: Introduce devm_acpi_install_notify_handler()
    34f4d0e4e5065 ACPI: driver: Check ACPI_COMPANION() against NULL during probe
    3b2628f7682ae ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
    83f29da85dc9d crypto: xilinx-trng - Remove crypto_rng interface
    f84c0bae0e8dd mmc: sdhci-esdhc-imx: fix resume error handling
    174dc8103ab7b mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
    5b8f11cbe8ad5 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
    4f96903e2fd22 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
    aa276aa6cbfbc mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
    52990f6b57526 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
    eefcd3ca245c1 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
    c02237966c199 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
    8d94498cc4453 mmc: block: fix RPMB device unregister ordering
    cf7258f57d180 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
    4b5de4007e5bf mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
    de2bc884d8870 mtd: rawnand: fsl_ifc: return errors for failed page reads
    bf9848a22a8e5 mmc: vub300: defer reset until cmd_mutex is unlocked
    04ebd3766861f mtd: mchp23k256: use SPI match data for chip caps
    ac2d9f6b4f905 mtd: onenand: samsung: report DMA completion timeouts
    a59cfa165aee3 wifi: mwifiex: fix permanently busy scans after multiple roam iterations
    b8df3a993f690 wifi: mac80211: free ack status frame on TX header build failure
    90576bd6921a9 wifi: ieee80211: validate MLE common info length
    584657c5fc58d wifi: cfg80211: validate EHT MLE before MLD ID read
    3c1e92f75e11a powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
    82753ac86cb3d reset: sunxi: fix memory region leak on ioremap failure
    3fb7edd2018bb ipvs: reload ip header after head reallocation
    d4ec18f48ce78 ipvs: fix more places with wrong ipv6 transport offsets
    39151f0708c84 memstick: ms_block: reject a card that reports too many blocks
    a75d2b5249e38 macsec: fix promiscuity refcount leak in macsec_dev_open()
    fd701fc0d0652 llc: fix SAP refcount leak when creating incoming sockets
    6744ab60dfac5 Bluetooth: btrtl: validate firmware patch bounds
    dbd14f736be02 net: openvswitch: reject oversized nested action attrs
    6926d13865aaa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
    688bd4c6144d2 riscv: vdso: Do not use LTO for the vDSO
    55b26abb1fa1e wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
    bdc0b8bfdc142 wifi: mac80211: fix memory leak in ieee80211_register_hw()
    65446b85595a4 wifi: mwifiex: fix roaming to different channel in host_mlme mode
    816559409e340 wifi: rt2x00: avoid full teardown before work setup in probe
    262da8b6ea03d net/mlx5: free mlx5_st_idx_data on final dealloc
    9b8df4da2cf79 powerpc/pseries: fix memory leak on krealloc failure in papr_init
    afa0db5322c5f mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
    d94160a5d1ac3 selftests/landlock: Fix screwed up pointers in the scoped_signal_test
    ba481c0b53760 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
    4ff3960f35271 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
    9a0464fcfae4f pmdomain: imx: Fix i.MX8MP power notifier
    c844b7d9a9586 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
    8131a91fe2dea selftests/rseq: Fix a building error for riscv arch
    3dfec7490f3a2 s390/mm: Fix type mismatch in get_align_mask().
    c6b4d454865a8 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
    fad36954b2959 tracing/osnoise: Call synchronize_rcu() when unregistering
    eadd0c2c76aee riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
    38cc4867540ae drbd: reject data replies with an out-of-range payload size
    91ec52dd2a5d9 ata: libata-core: Allow capacity transition to zero for locked drives
    7a9a69641b68a ata: libata-core: Skip HPA resize for locked drives
    52007bfdce531 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
    1155a9d0a2e0d fs/resctrl: Free mon_data structures on rdt_get_tree() failure
    ccdf1770a4ba2 cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
    5f5783c7806fc arm64: smp: Fix hot-unplug tearing by forcing unregistration
    26b131b2d5b55 net: macb: drop in-flight Tx SKBs on close
    b2f426a9a2288 dibs: loopback: validate offset and size in move_data()
    2cf10d0425622 macsec: don't read an unset MAC header in macsec_encrypt()
    83fb4c2c5344f ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
    247d055504dcc ipvs: use parsed transport offset in SCTP state lookup
    61a7ff4a62003 llc: fix SAP refcount leak in llc_ui_autobind()
    685fb410d90e5 selftests: net: make busywait timeout clock portable
    5df30f05db965 octeontx2-pf: fix SQB pointer leak on init failure
    77caf2d6eba7c mac802154: remove interfaces with RCU list deletion
    f0745496f7c17 s390/monwriter: Reject buffer reuse with different data length
    a5a367756926d irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
    018d7ad26cb8b mm/compaction: handle free_pages_prepare() properly in compaction_free()
    2faf0198168d2 riscv: probes: save original sp in rethook trampoline
    d8d4fa0c4f818 hwmon: (asus_atk0110) Check package count before accessing element
    07f5eb6d268a3 net: wwan: iosm: bound device offsets in the MUX downlink decoder
    1286a41563337 ata: pata_pxa: Fix DMA channel leak on probe error
    1dce4f4bb3c1c net/mlx5: HWS, fix matcher leak on resize target setup failure
    82fc886e244c7 orangefs: keep the readdir entry size 64-bit in fill_from_part()
    2c76c01a505c1 tracing/probes: Fix double addition of offset for @+FOFFSET
    b4427ee3667c5 hwmon: (max1619) add missing 'select REGMAP' to Kconfig
    6c52226072a3c fhandle: reject detached mounts in capable_wrt_mount()
    e2b7ee61989f2 net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    5889064919a1e net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
    99a6f37b113c4 net: lan743x: Initialize eth_syslock spinlock before use
    ac58088d70b8a fsl/fman: Free init resources on KeyGen failure in fman_init()
    f0aad157576da hwmon: (occ) unregister sysfs devices outside occ lock
    715cce38424fb net: liquidio: fix BAR resource leak on PF number failure
    664480021f6a4 hwmon: (w83793) remove vrm sysfs file on probe failure
    c6c990f7208c9 hwmon: (w83627hf) remove VID sysfs files on error and remove
    8dc6c7e8c9678 rtc: mpfs: fix counter upload completion condition
    6e21d1253ef13 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
    6c98ccdb9a096 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
    f5c5065963024 ipmi: fix refcount leak in i_ipmi_request()
    a66d45e0ce6d7 espintcp: use sk_msg_free_partial to fix partial send
    ddbb6e3dc9bb4 ipmi: Fix user refcount underflow in event delivery
    a65f49b6f7ece LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
    20ac8131f8c90 LoongArch: Fix nr passing in set_direct_map_valid_noflush()
    612cda6630f2e pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
    4b73889941b95 selftests/bpf: Add simple strscpy() implementation
    da7f17c2d5bb4 KVM: TDX: Account all non-transient page allocations for per-TD structures
    d0cc2c74060be drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
    6cec36c795c03 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
    55da782eb4545 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
    35267819b2507 gve: fix header buffer corruption with header-split and HW-GRO
    2059c28bd725b ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
    cb5cca1d2a908 ieee802154: ca8210: fix cas_ctl leak on spi_async failure
    314f21c9dd0dc ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
    1905ebabe638c ieee802154: admin-gate legacy LLSEC dump operations
    19c148cb82d11 octeontx2-af: Free BPID bitmap on setup failure
    234cd54fc500f net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
    03d8843b143eb net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
    68cadc3698c7d net: ipip: require CAP_NET_ADMIN in the device netns for changelink
    9571af2eec802 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
    0b2f9c908f930 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
    6596baf804110 net: ena: clean up XDP TX queues when regular TX setup fails
    ab625256882e0 selftests: net: fix file owner for broadcast_ether_dst test
    b3d8354078461 net/sched: act_ct: preserve tc_skb_cb across defragmentation
    3f85fcd520aa7 net: ixp4xx_hss: fix duplicate HDLC netdev allocation
    e89b8829693e6 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
    121c5f31c3fb7 net: ethernet: ti: icssg: guard PA stat lookups
    3118e97dae533 net: sit: require CAP_NET_ADMIN in the device netns for changelink
    5d7bd8790309b gpios: palmas: add .get_direction() op
    d3b9026ef78da gpio: mt7621: avoid corruption of shared interrupt trigger state
    4e16bc75c7502 gpio-f7188x: Add support for NCT6126D version B
    b6e040b5143cc gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
    ac761e66708d5 gpio: tegra: do not call pinctrl for GPIO direction
    0630f2c3c16c0 gpio: mt7621: more robust management of IRQ domain teardown
    6cb15b81ff545 cpu: hotplug: Bound hotplug states sysfs output
    f77117530fc3f cpu: hotplug: Preserve per instance callback errors
    afd147e59b32a selftests/ftrace: Drop invalid top-level local in test_ownership
    ea6a188ee805e posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
    633cadbc0b832 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
    fcff712d0e3d1 wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
    b33ac2d39953e tracing/user_events: Fix use-after-free in user_event_mm_dup()
    ed3cc4218070d net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
    0e8115a7ed9a9 Input: ims-pcu - fix type confusion in CDC union descriptor parsing
    f516cba88bf95 Input: ims-pcu - fix race condition in reset_device sysfs callback
    383934c249a98 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
    9c964fc9507ae Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
    99c428d7ef644 Input: ims-pcu - fix firmware leak in async update
    05ac85da12198 Input: ims-pcu - fix DMA mapping violation in line setup
    f28c5cabb2df0 Input: ims-pcu - add response length checks
    c8d3d83f2eaaf Input: ims-pcu - validate control endpoint type
    6329d1af316a4 Input: ims-pcu - release data interface on disconnect
    87e2f89dea078 Input: ims-pcu - only expose sysfs attributes on control interface
    6aacc18004b1a Input: ims-pcu - fix use-after-free and double-free in disconnect
    df87532e92122 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
    9b871369cbb45 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
    cb7bdae7fba40 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
    004ccd2d3b4ac scsi: target: Bound PR-OUT TransportID parsing to the received buffer
    f1516c56ac540 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
    255fb7b0cdc94 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
    d0a8a6660d58e scsi: sg: Report request-table problems when any status is set
    ed08497977820 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
    d495b403d5b35 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
    257321a1c036d accel/ivpu: Reject firmware log with size smaller than header
    4e370b5289624 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
    7aa8f3dba5342 dma-fence: Make dma_fence_dedup_array() robust against 0-count input
    089e05b644d5a dm-verity: make error counter atomic
    c8d743bb0e98a dm-verity: increase sprintf buffer size
    f15eaa3801f2f dm-verity: fix a possible NULL pointer dereference
    2a0858cba1dab dm-verity: avoid double increment of &use_bh_wq_enabled
    5dfd804263527 dm-integrity: don't increment hash_offset twice
    aa5113e7155f4 dm-integrity: fix a bug if the bio is out of limits
    0c4e9bb1d4101 dm-integrity: fix leaking uninitialized kernel memory
    92e3c93d60be1 dm_early_create: fix freeing used table on dm_resume failure
    ee458c3c18343 dm-stats: fix merge accounting
    461d36b5ddafc dm-stats: fix dm_jiffies_to_msec64
    1247615aadb74 dm-pcache: reject option groups without values
    e0b0163a65758 dm-log: fix a bitset_size overflow on 32bit machines
    d61c12573ed97 dm-ioctl: fix a possible overflow in list_version_get_info
    021dab70eb37d dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
    1fcb5e29dd7a5 dm era: fix out-of-bounds memory access for non-zero start sector
    7f76245960a33 dm thin metadata: fix metadata snapshot consistency on commit failure
    ac2136dc4441d dm thin metadata: fix superblock refcount leak on snapshot shadow failure
    8a3c44a003176 net: sparx5: unregister blocking notifier on init failure
    ffd17a393921a block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
    2977b5fe401c1 block: fix race in blk_time_get_ns() returning 0
    af382ffca93e5 block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
    0b6252afcd196 bpf: Add missing access_ok call to copy_user_syms
    c4f626ddf2350 bpf,fork: wipe ->bpf_storage before bailouts that access it
    0993dc5fc619c bpf: Reset register bounds before narrowing retval range in check_mem_access()
    b06a4a397ac82 can: bcm: add missing rcu list annotations and operations
    35f0ac19efb1a can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
    cd830e0bc25ee can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
    37beb16e08cae can: isotp: serialize TX state transitions under so->rx_lock
    7bef39ba76eb7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
    b88a511308779 can: isotp: use unconditional synchronize_rcu() in isotp_release()
    765ba1c91823a can: esd_usb: kill anchored URBs before freeing netdevs
    5e4c8e08ce957 netdev-genl: report NAPI thread PID in the caller's pid namespace
    26355295ce21c nvmet: fix refcount leak in nvmet_sq_create()
    2944113ad5fbc nvmet-rdma: handle inline data with a nonzero offset
    2eaa3ad450141 nvmet-auth: reject short AUTH_RECEIVE buffers
    59cef6abc924a nvme-apple: Prevent shared tags across queues on Apple A11
    0ffc032294a29 NFS: Charge unstable writes by request size, not folio size
    ebe0a55d954fa sctp: validate STALE_COOKIE cause length before reading staleness
    d44b828eb551b spi: uniphier: Fix completion initialization order before devm_request_irq()
    9b092f9e6b34d time: Fix off-by-one in compat settimeofday() usec validation
    ada4b9a5087ea tpm: Make the TPM character devices non-seekable
    95bdf3950d668 tpm: fix event_size output in tpm1_binary_bios_measurements_show
    8ca2a19a987a7 xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
    e0f688ccb20f1 xfrm: use compat translator only for u64 alignment mismatch
    5b0c4c916f202 xfrm: nat_keepalive: avoid double free on send error
    16d3ccdabb8de xen/gntdev: fix error handling in ioctl
    e497fef9ad7e9 ufs: core: tracing: Do not dereference pointers in TP_printk()
    0ced34b4bbc04 tcp: Decrement tcp_md5_needed static branch
    33a1bee413628 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
    bccae122dab8f ice: fix ice_init_link() error return preventing probe
    8bd84316bbaf3 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
    e6a395a71f465 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
    2f3f471a448a5 i2c: mediatek: fix WRRD for SoCs without auto_restart option
    5d3240f42a667 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
    6d2c973926d06 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
    500716a007b2e hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
    1dcd7565e5909 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
    3cd6f93f3d593 ksmbd: fix integer overflow in set_file_allocation_info()
    6cc1518357369 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
    fe623f9515bb0 pkey: Move keytype check from pkey api to handler
    eafc5aca71564 platform/x86/amd/pmc: Don't log during intermediate wakeups
    e628d9169f9e1 platform/x86/amd/pmc: Add delay_suspend module parameter
    27d16a19ae74f platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
    d8bc45c4c1a45 platform/x86/amd/pmc: Check for intermediate wakeup in function
    cea03d67db3a8 platform/x86: ISST: Restore SST-PP control to all domains
    1e41ca4a7fba2 platform/x86: dell-laptop: fix missing cleanups in init error path
    ddbc4a8a4fe29 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
    7926c1e4be863 dmaengine: tegra: Fix burst size calculation
    933654508b2bc sunrpc: fix uninitialized xprt_create_args structure
    934d1cd40e289 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
    ba33b4f9d3423 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
    781f28bd982cf tpm: restore timeout for key creation commands
    36ca587f55a2c irqchip/crossbar: Use correct index in crossbar_domain_free()
    0d078152fcab7 taskstats: retain dead thread stats in TGID queries
    9ac007affa77c mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
    3fac46068fe4c openrisc: Fix jump_label smp syncing
    ff7bcc9d71bf4 mtd: rawnand: Pause continuous reads at block boundaries
    0fd20c1905abc mtd: spi-nor: spansion: use die erase for multi-die devices only
    c0806df5cf806 mtd: spi-nor: swp: Improve locking user experience
    433e5e70cdc1e s390/pkey: Check length in pkey_pckmo handler implementation
    693bf91d4db13 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
    c9ef79e34bc1e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
    e5824d5b841d9 net: thunderbolt: Fix frags[] overflow by bounding frame_count
    fc74244e0cc25 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
    3ebe0ee6527e8 bus: mhi: host: pci_generic: Fix the physical function check
    012683accbb7d fpga: dfl: add bounds check in dfh_get_param_size()
    2174c68f623b7 ocfs2: reject non-inline dinodes with i_size and zero i_clusters
    5e512d370a01b ocfs2: reject dinodes whose i_rdev disagrees with the file type
    4db3b6a2a8ecf ocfs2: reject dinodes with non-canonical i_mode type
    499714de42ab4 ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
    671889c553ea5 ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
    bd73971fad89d ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
    d5d5a21fb33cd ocfs2: avoid moving extents to occupied clusters
    4bbfcf9c7e46c mtd: rawnand: fix condition in 'nand_select_target()'
    a8874c34c4a97 net/9p: fix infinite loop in p9_client_rpc on fatal signal
    ace3a0c839f3b mtd: rawnand: pl353: fix probe resource allocation
    b6337e3687d3d ocfs2: use kzalloc for quota recovery bitmap allocation
    bf53557a96d4c openrisc: Add full instruction cache invalidate functions
    8d263bae573dc scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
    83405848e4030 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
    a7bbf83dfebdc power: supply: bq257xx: Fix VSYSMIN clamping logic
    8d610017c992d 9p: skip nlink update in cacheless mode to fix WARN_ON
    d8dcbbfa0d695 mtd: slram: remove failed entries from the device list
    4e4beef747c68 kcov: use WRITE_ONCE() for selftest mode stores
    da5234df09416 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
    749e2051da3b0 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
    07ed8b1785480 fs/proc: fix KPF_KSM reported for all anonymous pages
    b6a6fb6803d52 proc: only bump parent nlink when registering directories
    4d67bdef35c32 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
    43b987ed35be9 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
    40a04601a3f66 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
    f18c561eb9c51 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
    f322955d9a1c3 riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
    1caee6e084a96 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
    bd2e9be9ebb64 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
    193e6471e985c power: supply: charger-manager: fix refcount leak in is_full_charged()
    1f18aac263722 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
    ff05a98150ebb ntfs3: fix out-of-bounds read in decompress_lznt
    f3624cc069195 ntfs3: validate split-point offset in indx_insert_into_buffer
    aaa1f956c0fc4 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
    0fad25687d4d3 ntfs3: cap RESTART_TABLE free-chain walker at rt->used
    be306b8d9143a fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
    908c9243ba309 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
    7adb38279812c fs/ntfs3: validate lcns_follow in log_replay conversion
    50b5e83384e7f fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
    d240cd98f5f7b fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
    09fddd52c1b0c fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
    ccd6b70798737 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
    640627f07c79b mm/damon/core: make charge_addr_from aware of end-address exclusivity
    722e6c54bde63 mm/memory_hotplug: fix incorrect altmap passing in error path
    1697d253f51cf mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
    9227b387eee50 power: supply: max17042: fix OF node reference imbalance
    a3d81de441233 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
    a39d281f207b9 mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
    d3fd2d358df0c MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
    11a3bc25f2c30 MIPS: ip22-gio: fix device reference leak in probe
    2c551f14f55e4 MIPS: ip22-gio: fix kfree() of static object
    620a37ea7d626 MIPS: ip22-gio: fix gio device memory leak
    51aad3d89a2dd remoteproc: qcom: Fix leak when custom dump_segments addition fails
    69e18135e2a00 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
    46d59ff421824 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
    1161c4b5bd004 lockd: Plug nlm_file leak when nlm_do_fopen() fails
    66014ab165cb0 sunrpc: harden rq_procinfo lifecycle to prevent double-free
    65b23bec1fca6 sunrpc: wait for in-flight TLS handshake callback when cancel loses race
    3f9ee75a97a76 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
    30d490bb2c4cd nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
    f4ca396bdd60b nvdimm/btt: Free arenas on btt_init() error paths
    78955fdce8ff6 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
    7199c78c3a3e3 Bluetooth: SCO: hold sk properly in sco_conn_ready
    77eb0cf57009e Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
    96dd35f1942cd HID: playstation: validate num_touch_reports in DualShock 4 reports
    88ba845468508 mfd: tps6586x: Fix OF node refcount
    d8e2f3e1bc207 cifs: invalidate cfid on unlink/rename/rmdir
    3256c05d5a9db batman-adv: tt: prevent TVLV OOB check overflow
    d2b657c9653fc batman-adv: mcast: avoid OOB read of num_dests header
    a90f4fff90253 batman-adv: frag: fix primary_if leak on failed linearization
    c945f6007e785 batman-adv: clean untagged VLAN on netdev registration failure
    8f54162e07d3e batman-adv: frag: free unfragmentable packet
    2c989ab8e2054 batman-adv: fix VLAN priority offset
    6a65ac8a81e90 batman-adv: tt: avoid request storms during pending request
    ee878decf9e57 batman-adv: dat: fix tie-break for candidate selection
    9e16b6751a820 batman-adv: ensure minimal ethernet header on TX
    8f76277d02176 batman-adv: dat: ensure accessible eth_hdr proto field
    e5e18886aadd3 batman-adv: bla: reacquire gw address after skb realloc
    3b4c70c40f2e1 batman-adv: dat: acquire ARP hw source only after skb realloc
    b8afcf799b2cc batman-adv: access unicast_ttvn skb->data only after skb realloc
    85a71a81854e0 batman-adv: retrieve ethhdr after potential skb realloc on RX
    e6b43acd34b21 batman-adv: gw: acquire ethernet header only after skb realloc
    fa1ebae4206e6 s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
    8514585aa9553 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
    221ee479a49fb cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
    5ab0eba9c8819 perf/x86/amd/lbr: Fix kernel address leakage
    046f6244da9b6 perf/x86/amd/brs: Fix kernel address leakage
    394e2bdf7594e x86/boot: Reject too long acpi_rsdp= values
    f7c67c97b37c1 x86/boot: Validate console=uart8250 baud rate to fix early boot hang
    1a1d6e3ef6cf5 x86/video: Only fall back to vga_default_device() without screen info
    19ffeb30fdfce tools/power/x86/intel-speed-select: Harden daemon pidfile open
    16a42c88c4667 mfd: sm501: Fix reference leak on failed device registration
    6dd51d84a9502 leds: uleds: Fix potential buffer overread
    3a134c3fb5f0d selinux: fix incorrect execmem checks on overlayfs
    d61a80b17254b selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
    fc633a598206d selinux: check connect-related permissions on TCP Fast Open
    e9cdf741ffcb4 soc: fsl: qe: panic on ioremap() failure in qe_reset()
    c6854d9f4e1bd soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
    c4d6442ac3ed0 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
    1c4f67c89fd27 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    679ced28a9dc2 netfilter: xt_nat: reject unsupported target families
    b2dbbedfa935c netfilter: ecache: fix inverted time_after() check
    3cd9a5792cbea netfilter: nf_conncount: fix zone comparison in tuple dedup
    a58230f3a7c4f netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
    2bcf2c5052fb5 netfilter: nf_nat_sip: reload possible stale data pointer
    02b6b0e892aea netfilter: nft_set_pipapo: don't leak bad clone into future transaction
    0ca505346c5e2 netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
    07f9ddbf5e799 netfilter: xt_cluster: reject template conntracks in hash match
    a1b672a3b5372 netfilter: nfnl_cthelper: apply per-class values when updating policies
    aff589556ed77 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
    ca028334343a1 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
    e42d8322b67f2 ASoC: mediatek: mt8183: Release reserved memory on cleanup
    4b068759d3087 ASoC: mediatek: mt8183: Check runtime resume during probe
    51c367230e30e ASoC: mediatek: mt8192: Release reserved memory on cleanup
    e0f276f1918a2 ASoC: mediatek: mt8192: Check runtime resume during probe
    d3abaedf6a584 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
    121577383b5cf ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
    4ebe2c3a7db63 fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
    009a8514745b1 fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
    58bc18e03481b fbdev: vesafb: fix memory leak in vesafb_probe()
    d81860691e4cf fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
    e1ca9b8559e0f fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
    12fe6a56506ed fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
    ad54698255a4b fbdev: s3fb: fix potential memory leak in s3_pci_probe()
    146b708bc75f1 fbdev: i740fb: fix potential memory leak in i740fb_probe()
    c2c795a320e7e fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
    febb5b4f67ace fbdev: efifb: fix memory leak in efifb_probe()
    9423e1f105270 fbdev: sm712: Fix operator precedence in big_swap macro
    d684ce2db92b1 fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
    e8c9aae8c9508 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
    6854cf33dddb2 fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
    d5436e18e4fc2 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
    4ead4def04659 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
    5c50db5bcbb90 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
    884b44256041e KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
    09f35145f3a4a KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
    5000bcae71c86 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
    7099e7148f81c KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
    7996013b85687 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
    d1379888cc423 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
    97542f15dc4cf KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
    ba06690b28be9 KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
    df72596278b0e KVM: s390: pci: Fix handling of AIF enable without AISB
    d19dca8194ebe KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
    79fdd2aa774e4 KVM: arm64: vgic: Check the interrupt is still ours before migrating it
    5fb75c5272950 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
    9f8eaef40e955 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
    33d79ad6ecedf LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
    f3efcef6648ba LoongArch: KVM: Fix FPU register width with user access API
    45f2e6505fcf6 LoongArch: KVM: Check the return values for put_user()
    efe27b19a15c3 LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
    199b570d7fca1 LoongArch: KVM: Validate irqchip index in irqfd routing
    1ee200a1764f8 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
    f550bf32b9a06 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
    7da4d1a6b7400 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
    804821b69b2d1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
    c632a27f35cff arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
    bd938c985ab34 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
    ead9f10428c73 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
    a98bda2305f3f ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
    4fd52ac541ce1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
    68f9773754f05 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
    e2e3fb995175c arm64: dts: qcom: sdm630: describe adsp_mem region properly
    508e55e81870d ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
    e8dc96a42571e arm64: dts: s32g3: Fix SWT8 watchdog address
    89edae4161412 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
    5526d1997aea6 net: ife: require ETH_HLEN to be pullable in ife_decode()
    908391d801b24 octeontx2-vf: clear stale mailbox IRQ state before request_irq()
    eebf439aa7a13 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
    e62adb157c2ea net: atm: reject out-of-range traffic classes in QoS validation
    22100a8f73d4a net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
    61a55fa24a5d7 tipc: restrict socket queue dumps in enqueue tracepoints
    d34deef34c99b ASoC: SOF: topology: validate vendor array size before parsing
    0c4fbdaca225b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
    711d912b18763 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
    fb4293173db2d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
    d8715b5a8fdb2 vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
    3a2b47d1b4b3d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
    2d8b3c3e12997 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
    b65e46eed9e52 idpf: add padding to PTP virtchnl structures
    1627e7d5c9b09 smb: client: fix overflow in passthrough ioctl bounds check
    327595e7c34e3 drm/xe: remove duplicate <kunit/test-bug.h> include
    3de77d2f34c2b octeontx2-af: fix VF bringup affecting PF promiscuous state
    ee3f7566bcf33 net/mlx5: Fix L3 tunnel entropy refcount leak
    1550b07bca2bb selftests/net: fix EVP_MD_CTX leak in tcp_mmap
    346e2d666a29a regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
    14e03ecd3b1b5 dm era: fix NULL pointer dereference in metadata_open()
    5b0427ba582d1 SUNRPC: pin upper rpc_clnt across the TLS connect_worker
    13965a7b190f3 SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
    b784cd1c24d89 cifs: validate DFS referral string offsets
    df0e3e70f6995 s390/zcrypt: Remove the empty file
    8f48cfe657409 ipvs: ensure inner headers in ICMP errors are in headroom
    7510451a58c27 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
    d73f4249776dd ipvs: use parsed transport offset in TCP state lookup
    d340e351a0a74 ipvs: pass parsed transport offset to state handlers
    238c612357b5a netfilter: nft_lookup: fix catchall element handling with inverted lookups
    f60ec3058a854 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
    27506827a01f6 ipv4: igmp: annotate data-races around timer-related fields
    d269eb67d2e58 ipv4: igmp: annotate data-races around im->users
    9ce741c22df4f ipv6: mcast: Fix potential UAF in MLD delayed work
    75e984fe0cb9e ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
    3bfcce441c552 gpio: mvebu: free generic chips on unbind
    7cc438c99bba3 perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
    9579d625171a1 octeontx2-pf: check DMAC extraction support before filtering
    7aa0e64fea778 net/sched: cake: reject overhead values that underflow length
    72119397cdff6 net: mdio: select REGMAP_MMIO instead of depending on it
    762116dfa7286 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
    267809e2c56fb accel/amdxdna: Fix potential amdxdna_umap lifetime race
    1cd434ac1c222 tracing: Make tracepoint_printk static as not exported
    5e15cf51982f8 gpio: dwapb: Defer clock gating until noirq
    6c736c5ccf4a3 gpio: dwapb: reduce allocation to single kzalloc
    d7b5497e0e45b gpio: dwapb: Use modern PM macros
    a3010b732d620 net: usb: lan78xx: disable VLAN filter in promiscuous mode
    e8a4c9fc437b1 net/tls: Consume empty data records in tls_sw_read_sock()
    b3eeb586f94c7 accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
    ec5e96aee75d2 ring-buffer: Fix event length with forced 8-byte alignment
    0c602cb8f148a Bluetooth: L2CAP: fix tx ident leak for commands without a response
    bfc9e7be289df Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
    b69b1ab121fe8 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
    da4d8eea0c5f3 Bluetooth: sco: Fix a race condition in sco_sock_timeout()
    dfc8373893b18 Bluetooth: MGMT: Fix adv monitor add failure cleanup
    23a83bac3356e Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
    026c236f0eefe amt: fix size calculation in amt_get_size()
    3bfb96d9bc6a7 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
    6f9b23eb92a89 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
    1b12612c367e4 net: qualcomm: rmnet: validate MAP frame length before ingress parsing
    b066420e57f34 qede: fix off-by-one in BD ring consumption on build_skb failure
    1e71a40d10154 net: microchip: vcap: fix races on the shared Super VCAP block
    5c7e3755abf66 net/mlx5e: Fix publication race for priv->channel_stats[]
    60fddda7207d8 net/mlx5e: Fix HV VHCA stats agent registration race
    420aabb32da43 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
    6a802de97a8bf net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
    4eef84b09a383 netfilter: xt_connmark: reject invalid shift parameters
    b29b67c729de0 netfilter: nft_set_rbtree: get command skips end element with open interval
    3d441be2b1c5e netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
    e702f6dd5d21e netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
    a597a722fb71a netfilter: xt_u32: reject invalid shift counts
    4a4a1d41c6e90 gue: validate REMCSUM private option length
    b153cfe84b134 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
    66f57dc92aeb6 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
    a6185c21d5510 selftests/hid: Cover hid_bpf_get_data() size overflow
    91ac1d7fd51e3 selftests/hid: Load only requested struct_ops maps
    61a959b82f1ae HID: bpf: Fix hid_bpf_get_data() range check
    4c65c3d9f660b arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
    dd395744e4ed8 HID: core: Fix OOB read in hid_get_report for numbered reports
    d354e523c6f74 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
    793b55c3f36f5 ata: libata-scsi: limit simulated SCSI command copy to response length
    232a2f2fce9b9 ata: sata_gemini: unwind clocks on IDE pinctrl errors
    86652704a7fd4 cifs: Fix missing credit release on failure in cifs_issue_read()
    c9170c83b0e0f uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
    2265b2b1c5aaa x86/uprobes: Keep shadow stack in sync for emulated CALLs
    adc7dda728ca3 drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
    a0a56b4480a0d drm/xe/hw_engine: Fix double-free of managed BO in error path
    f9a9abd7bbdab drm/xe/userptr: Hold notifier_lock for write on inject test path
    78b1074966d29 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
    a9b89752c2726 netfs: Fix folio state after ENOMEM whilst under writeback iteration
    1bb33d959aabc netfs: Fix writeback error handling
    7838131e296df netfs: Fix writethrough to use collection offload
    8ab75e445c161 netfs: Fix netfs_create_write_req() to handle async cache object creation
    1f38f65bf965f iomap: guard io_size EOF trim against concurrent truncate underflow
    08b2145470667 ovl: fix comment about locking order
    abe3536a4bedc minix: avoid overflow in bitmap block count calculation
    ce6aced2e8554 afs: Fix unchecked-length string display in debug statement
    158c5a0b1dfc0 afs: Fix the volume AFS_VOLUME_RM_TREE is set on
    657449e5581a4 afs: Fix premature cell exposure through /afs
    2ffb70a8a0198 afs: Fix lack of locking around modifications of net->cells_dyn_ino
    8afb1a787a280 afs: Fix vllist leak
    5492799ec5d27 afs: Fix missing NULL pointer check in afs_break_some_callbacks()
    0acbc09d2aca0 afs: Fix callback service message parsers to pass through -EAGAIN
    63d3f283858fa afs: Fix reinitialisation of the inode, in particular ->lock_work
    5ea289ca751c4 afs: Fix misplaced inc of net->cells_outstanding
    b5bc1e5d5ce57 afs: Fix bulk lookup malfunction due to change in dir_emit() API
    083a0ddc9cd49 afs: Remove erroneous seq |= 1 in volume lookup loop
    6eb0d929202a3 afs: use kvfree() to free memory allocated by kvcalloc()
    aa24cec5b3470 afs: Fix double netfs initialisation in afs_root_iget()
    8530206911fd6 afs: Fix error code in afs_extract_vl_addrs()
    a2038514e6937 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
    374fd8122421f net/sched: hhf: clear heavy-hitter state on reset
    fba8e250ce5f3 net/sched: dualpi2: clear stale classification on filter miss
    a203f2c3892b1 pinctrl: meson: restore non-sleeping GPIO access
    47120164c63d3 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
    5a5ac2852cd32 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
    d020e7f27bf65 ksmbd: reject undersized DACLs before parsing ACEs
    6b1304ce6cff0 net/sched: act_bpf: use rcu_dereference_bh() to read the filter
    a03387e1f6251 selftests: drv-net: tso: don't touch dangerous feature bits
    df9ffdceac053 cxgb4: Fix decode strings dump for T6 adapters
    124440df267dc virtio_net: disable cb when NAPI is busy-polled
    a8323fb2ab6cd sctp: fix addr_wq_timer race in sctp_free_addr_wq()
    4e8d498d32b6c irqchip/ts4800: Fix missing chained handler cleanup on remove
    c5d75800539bc irqchip/gic-v3-its: Fix OF node reference leak
    f0069a262bd41 tracing/probes: Make the $ prefix mandatory for comm access
    62988204162fc tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
    898cb5a7c4154 tracing: eprobe: read the complete FILTER_PTR_STRING pointer
    e0881f5cc4d71 tracing/events: Fix to check the simple_tsk_fn creation
    f148f86c65b8f tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
    3b51d6f07a199 tracing/eprobes: Allow use of BTF names to dereference pointers
    acbf1ecc22f3c drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
    a9d098b346db5 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
    1497a438ea34a drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
    dd0b2976b7c0f drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
    b4b3458ef88df bridge: stp: Fix a potential use-after-free when deleting a bridge
    9b7d05cbaa601 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
    ef940e042f329 net: gianfar: dispose irq mappings on probe failure and device removal
    58ba00999898b net: libwx: fix VMDQ mask for 1-queue mode
    86d379fcf1b79 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
    0a7d9c7c5f1f2 usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
    d8a01d27873e0 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
    83df3e2594cd7 eth: fbnic: don't cache shinfo across skb realloc
    898ca04b096b9 hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
    489291b6b5697 hwmon: (pmbus) Fix passing events to regulator core
    36554592e2f5c hwmon: adm1275: Prevent reading uninitialized stack
    1797eb92f0b39 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
    f14c3926fee38 ASoC: codecs: lpass-va-macro: add SM6115 compatible
    3d3638fe92137 MIPS: mm: Add check for highmem before removing memory block
    4e9f4ca9dc73c MIPS: DEC: Ensure RTC platform device deregistration upon failure
    bca3100f55028 sctp: add INIT verification after cookie unpacking
    ad6215d76b644 sctp: fix SCTP_RESET_STREAMS stream list length limit
    1681cc7974a61 net: enetc: check the number of BDs needed for xdp_frame
    b17751a2ebc4a qede: fix out-of-bounds check for cqe->len_list[]
    8dba7a94a269b seg6: validate SRH length before reading fixed fields
    8d501b1411548 net: pse-pd: scope pse_control regulator handle to kref lifetime
    e94d53a9ac22c gpio: htc-egpio: use managed gpiochip registration
    f4af803269ccd gpio: mvebu: fail probe if gpiochip registration fails
    46dee20d30b70 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
    8e0b7f94fb394 ACPI: RIMT: Only defer the IOMMU configuration in init stage
    776f70bafd45c spi: sh-msiof: abort transfers when reset times out
    d6cd34d17b951 tracing: probes: fix typo in a log message
    f28d7b5f1578a ALSA: FCP: Fix NULL pointer dereference in interface lookup
    d990a01b853e5 net: hns3: differentiate autoneg default values between copper and fiber
    2d149a20275ac net: hns3: fix permanent link down deadlock after reset
    92d05883ef337 net: hns3: refactor MAC autoneg and speed configuration
    43a6c6fb6ec50 net: hns3: unify copper port ksettings configuration path
    de051b146022c selftests: tls: size splice_short pipe by page size
    6727f580cf462 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
    9075efb9b2c1d net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
    c1e7286d05318 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
    7a7c7263bbbc4 LoongArch: BPF: Fix off-by-one error in tail call
    ed295077a2214 LoongArch: BPF: Fix outdated tail call comments
    0a8a729481c8e LoongArch: Move struct kimage forward declaration before use
    2f3c0895fb20a net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
    b15a3cc68e245 net: sungem: fix probe error cleanup
    b84dd48f9da1e net: mvneta: re-enable percpu interrupt on resume
    e0ac054416bf4 octeontx2-af: Validate NIX maximum LFs correctly
    9dc3cf8a35906 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
    0c11a1da41a64 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
    a69ccea6d7eb6 rtc: cmos: unregister HPET IRQ handler on probe failure
    5fd1f0512748d rtc: ds1307: Fix off-by-one issue with wday for rx8130
    d0bfd7004a87f smb/client: preserve errors from smb2_set_sparse()
    5b6165d7ec384 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
    ea43e7a231aa2 thermal: testing: zone: Flush work items during cleanup
    4e62be1490d23 eth: fbnic: fix ordering of heartbeat vs ownership
    123b559aa6bb6 ipv6: fix missing notification for ignore_routes_with_linkdown
    419017dd2dda2 ipv6: fix state corruption during proxy_ndp sysctl restart
    ae58dbf1d78d7 ipv6: fix error handling in disable_policy sysctl
    2bf70e0306f8d ipv6: fix error handling in forwarding sysctl
    b060606bc7e46 ipv6: fix error handling in ignore_routes_with_linkdown sysctl
    56c26538f0e58 ipv6: fix error handling in disable_ipv6 sysctl
    2140c2f3f2e7b net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
    ff127c0aa5279 net: usb: lan78xx: restore VLAN and hash filters after link up
    a9e6707322ef2 veth: fix NAPI leak in XDP enable error path
    4106295280670 net: dsa: sja1105: round up PTP perout pin duration
    7557df1b60f20 net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
    03b743586a246 net, bpf: check master for NULL in xdp_master_redirect()
    a0904f7d27035 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
    94defb18ac792 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
    04117aea9bc11 NTB: epf: Fix doorbell bitmask and IRQ vector handling
    56ec2a08d27b5 NTB: epf: Report 0-based doorbell vector via ntb_db_event()
    d2a41c85beb56 NTB: epf: Make db_valid_mask cover only real doorbell bits
    60a6689b9a5df gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
    33e1875d6b5b5 netfilter: nft_compat: ebtables emulation must reject non-bridge targets
    d3e9a7e2ce9dc netfilter: nft_synproxy: stop bypassing the priv->info snapshot
    329f2626ee5cb netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
    a73e7ac3f3b69 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
    49fa1be621dde bpf: Disable xfrm_decode_session hook attachment
    4d919c9b77099 md/raid5: avoid R5_Overlap races while breaking stripe batches
    3db13f82ba314 md/raid5: use stripe state snapshot in break_stripe_batch_list()
    828fad4fd418b ipv4: fib: Don't ignore error route in local/main tables.
    630ce3806b706 eth: bnxt: improve the timing of stats
    c0057e5f762b9 eth: bnxt: rename ring_err_stats -> ring_drv_stats
    33168db149d01 eth: bnxt: gather and report HW-GRO stats
    b0d0eb13a0441 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
    77bb0bbfcc4e7 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
    1f6a4aec0d366 rtc: msc313: fix NULL deref in shared IRQ handler at probe
    68115a7a336fc i40e: Fix i40e_debug() to use struct i40e_hw argument
    de80d04b13dec ice: dpll: fix memory leak in ice_dpll_init_info error paths
    eaffdd113f560 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
    854065a75e375 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
    4cc632fe63df8 ice: call netif_keep_dst() once when entering switchdev mode
    04c082b7dc5bf ice: fix AQ error code comparison in ice_set_pauseparam()
    dd6d8e4412f80 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
    9415a94cf6227 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
    e1e7c72a2301d PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
    9cc0f8e63e8c3 drm/edid: fix OOB read in drm_parse_tiled_block()
    5e4c4ab99abc9 gpiolib: initialize return value in gpiochip_set_multiple()
    7550becf33014 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
    9697db03e0103 bpf: Fix effective prog array index with BPF_F_PREORDER
    3bdfa0e435f31 bpf: zero-initialize the fib lookup flow struct
    b05337635be3c bpftool: Fix vmlinux BTF leak in cgroup commands
    68b41e68a6229 bpf: Fix stack slot index in nospec checks
    aa33b44f70bfe rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
    56e5f8a409f8c rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
    93f95538b611a dpaa2-switch: do not accept VLAN uppers while bridged
    ea24f911ead85 ipv6: ioam: fix type confusion of dst_entry
    a6450f7cfae57 ipv6: ndisc: fix NULL deref in accept_untracked_na()
    2066e692ec7a1 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
    1d51aff78f078 net/sched: act_ct: fix nf_connlabels leak on two error paths
    a103cdb0681e7 net: emac: Fix NULL pointer dereference in emac_probe
    2855ec137a224 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
    da603b606ceb3 octeontx2-pf: Clear stats of all resources when freeing resources
    5636f0f3bd99b octeontx2-af: mcs: Fix unsupported secy stats read
    ceef83f0eaf9c net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
    a0c5fdeb5fa25 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
    5dda4f164a633 net: marvell: prestera: initialize err in prestera_port_sfp_bind
    9200c8149910d selftests/mm: fix exclusive_cow test fork() handling
    55fc2f99d0979 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
    c8add1d06512b selftests/mm: clarify alternate unmapping in compaction_test
    0caa28e978941 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
    471b62966c782 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
    9dbfd514148dd selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
    a8673dbd3d4a0 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
    31b28910abe34 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
    fff7d3ea3a4c4 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
    8c65c58868ecc selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
    58cd8ff69e33c selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
    b805de2abfa34 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
    37e3e8a2c3bfd alloc_tag: fix use-after-free in /proc/allocinfo after module unload
    502b3ae43f798 irqchip/crossbar: Fix parent domain resource leak
    002ebbcc8414c mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
    7e23965d44f06 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
    d32e4301a0e5e netfilter: nf_reject: skip iphdr options when looking for icmp header
    8e935c51b65d9 netfilter: nft_flow_offload: zero device address for non-ether case
    4c61d28634fbf netfilter: flowtable: move path discovery infrastructure to its own file
    13c6ba6e0f216 netfilter: nft_meta_bridge: add validate callback for get operations
    5baa149abb41a netfilter: nft_payload: reject offsets exceeding 65535 bytes
    12088da6add5b netfilter: ipset: make sure gc is properly stopped
    8087bb360a936 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
    c4d257734e91b netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
    a0afd353c2f7e netfilter: ipset: annotate "pos" for concurrent readers/writers
    7228cc8ff6265 netfilter: ipset: Fix data race between add and dump in all hash types
    6d92dbd73d19a md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
    2c5384c40a4ce md/raid1: honor REQ_NOWAIT when waiting for behind writes
    119903c320830 md: merge mddev serialize_policy into mddev_flags
    2e414af05a7cf md: merge mddev faillast_dev into mddev_flags
    9408c233a5bbe md: merge mddev has_superblock into mddev_flags
    5464ee6442376 mac802154: Prevent overwrite return code in mac802154_perform_association()
    de3bd9809af75 ieee802154: fix kernel-infoleak in dgram_recvmsg()
    d22e278cd0679 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
    f4860dd988b10 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
    5d17ebdf6c236 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
    3b40ebc19ad02 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
    45465b0e01354 ACPI: resource: Amend kernel-doc style
    7ae67f0e1c16b thermal: intel: Fix dangling resources on thermal_throttle_online() failure
    679fd0bf4f8ab arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
    4c16176fc11a6 ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
    a762b9865f494 selftests: vlan_bridge_binding: Fix flaky operational state check
    c6d3bcb0f934d flow_dissector: check device type before reading ETH_ADDRS
    68af74ad696ce net: macb: add TX stall timeout callback to recover from lost TSTART write
    112b5eff24e04 net: airoha: fix foe_check_time allocation size
    5ffb2b4987cc9 devlink: Fix parent ref leak on tc-bw failure
    02c884d9aaca3 devlink: Fix parent ref leak in devl_rate_node_create()
    0dafdaaf8684b dpaa2-switch: fix VLAN upper check not rejecting bridge join
    c7fc9adf4e006 virtio-net: fix len check in receive_big()
    0d95587d662a5 spi: rpc-if: Use correct device for hardware reinitialization on resume
    f37f2f804796e PCI: iproc: Restore .map_irq() for the platform bus driver
    53c23d56b46b1 ALSA: usb-audio: qcom: clear opened when stream enable fails
    25a867aa5e67a ALSA: usb-audio: qcom: reject stream disable with no active interface
    207bb4ce8fe7d sctp: hold socket lock when dumping endpoints in sctp_diag
    a6cfb924ad74e net: psample: fix info leak in PSAMPLE_ATTR_DATA
    3d45d40b872ae octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
    290ad0a548915 drm/amdgpu: initialize irq.lock spinlock earlier
    96ac562a9ea30 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
    211bb9d8f17c4 drm/amd/display: Fix mem_type change detection for async flips
    0e27d92f69b8e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
    7bcd4ef375fa3 ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
    ca297485271c6 perf dso: Set standard errno on decompression failure
    05b11debdffe0 perf bpf: Validate array presence before casting BPF prog info pointers
    c8cb4a92eda6e perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
    b389a5b215e35 perf cs-etm: Require full global header in auxtrace_info size check
    c13532ff67fae perf cs-etm: Validate num_cpu before metadata allocation
    87d23f25b5e97 perf machine: Use snprintf() for guestmount path construction
    6d99379c58f7f xfrm: validate selector family and prefixlen during match
    7248ae02a9453 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
    a1a3360a0c44b xfrm: Fix xfrm state cache insertion race
    1467ca02ddac4 ALSA: usb-audio: qcom: Free sideband sg_table objects
    507a7b07f3fa3 i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
    34cd92141a024 i3c: master: Update dev_nack_retry_count under maintenance lock
    95028569589f4 spi: dw: fix wrong BAUDR setting after resume
    355e51eeffc6b drm/xe: Fix wa_oob codegen recipe for external module builds
    2024940522ef4 drm/i915: clear CRTC color blob pointers after dropping refs
    1348bf64c1978 gpio: mlxbf3: fail probe if gpiochip registration fails
    7d3532a0b11a2 perf cs-etm: Reject CPU IDs that would overflow signed comparison
    a56f29ad8aacf perf: Remove redundant kernel.h include
    f8898d2eb71ae perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
    cafd80d81f08b perf bpf: Reject oversized BPF metadata events that truncate header.size
    1935d213aeb23 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
    aea30b437ebd0 perf sched: Replace (void*)1 sentinel with proper runtime allocation
    bc27041e8971e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
    661f60a8a5cf8 perf tools: Use snprintf() for root_dir path construction
    5d080b7324f07 perf dso: Set error code when open() fails on uncompressed fallback path
    debfcd673a6d1 perf dso: Fix heap overflow in dso__get_filename() on decompressed path
    95bf4dbcd5022 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
    fa870f951793d perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
    3ae7947101b97 perf tools: Don't read build-ids from non-regular files
    2c19e40753ec1 perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
    137eabe3c18ff perf symbols: Validate p_filesz before use in filename__read_build_id()
    ca3393e258f63 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
    f231387f3d2bb sparc: led: avoid trimming a newline from empty writes
    17955f1995bf9 accel/ivpu: fix HWS command queue leak on registration failure
    85873b1bd3664 apparmor: fix label can not be immediately before a declaration
    38d3d33bf42c2 i3c: master: Prevent reuse of dynamic address on device add failure
    c4f2afcdc5470 i3c: master: Defer new-device registration out of DAA caller context
    3891c061341fb i3c: master: Ensure Hot-Join operations are stopped on shutdown
    57490b302b984 i3c: master: Consolidate Hot-Join DAA work in the core
    0bd450d40f874 i3c: master: Move rstdaa error suppression
    fd32e8d4a2933 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery
    b07a318afca16 i3c: master: Introduce optional Runtime PM support
    882ee831366a1 i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked()
    de2106d99b87a i3c: add sysfs entry and attribute for Device NACK Retry count
    0d66830f302fd i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
    eb9db96a5deb3 i3c: master: add WQ_PERCPU to alloc_workqueue users
    45bbc1e1fe626 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
    d22ab94261c7b i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc()
    973fda38b124c i3c: mipi-i3c-hci: Allow for Multi-Bus Instances
    5625b8767ce3e i3c: mipi-i3c-hci: Quieten initialization messages
    2791dd42d41e3 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
    fdf610a9a9e72 apparmor: don't audit files pointing to aa_null.dentry
    b58d240883dfe apparmor: put secmark label after secid lookup
    66a6c61369d41 apparmor: aa_getprocattr free procattr leak on format failure
    22dc9433d458c apparmor: fail policy unpack on accept2 allocation failure
    3b918f6f52390 apparmor: Fix return in ns_mkdir_op
    566d1ef98a711 apparmor: remove or add symlinks to rawdata according to export_binary
    fbfdb5a94a487 apparmor: fix NULL pointer dereference in unpack_pdb
    57b1bd4486d56 apparmor: fix potential UAF in aa_replace_profiles
    b427061ca4983 apparmor: grab ns lock and refresh when looking up changehat child profiles
    9111f76e8dc8c apparmor: fix rawdata_f_data implicit flex array
    ae02e603c0b39 apparmor: aa_label_alloc use aa_label_free on alloc failure
    d821601323456 apparmor: check label build before no_new_privs test
    ad965f36d2986 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
    045dbe89ac317 apparmor: fix refcount leak when updating the sk_ctx
    d8ea44f6090c0 apparmor: fix race in unix socket mediation when peer_path is used
    ef488d7429d23 apparmor: fix shadowing of plabel that prevents cache from being updated
    f79519f636059 Revert "PCI/MSI: Unmap MSI-X region on error"
    514b84b1bf30f PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
    11016555d7510 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
    872f9a63a108e PCI: mediatek: Use actual physical address instead of virt_to_phys()
    f77c490c45d46 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
    9ca0a78a5d561 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
    f1f5f8d334e91 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
    cc6cd3fe8b8b1 perf symbols: Add bounds checks to elf_read_build_id() note iteration
    a3e758e741228 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
    f593775fecf5a perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
    bafb6bfb346fe perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
    fe4d8ad2e96f4 tools lib api: Fix mount_overload() snprintf truncation and toupper range
    b0385203a09f0 tools lib api: Fix filename__write_int() writing uninitialized stack data
    41b3a92310450 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
    fbaf9bdfc0917 perf hwmon: Guard label read against empty or failed reads
    d34b42ee0c74d perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
    bc2fc12ce6e4d perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
    f830bb8d221f3 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
    76dfa13a0acb1 perf hwmon: Fix off-by-one null termination on sysfs reads
    56b17c84394f1 perf tools: Fix thread__set_comm_from_proc() on empty comm file
    f2e5262589d94 perf intel-pt: Fix snprintf size tracking bug in insn decoder
    45e7900e1555c perf symbols: Bounds-check .gnu_debuglink section data
    4f883ab5bc7b7 perf symbols: Fix signed overflow in sysfs__read_build_id() size check
    490473192ac2f tools lib api: Fix missing null termination in filename__read_int/ull()
    09962b811ef14 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
    a6eec54329b43 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
    e274dfa05904f perf cs-etm: Queue context packets for frontend
    fa9eb50ddfea3 perf s390: Fix TEXTREL in Python extension by compiling as PIC
    b5a0a4a564d21 xprtrdma: Return sendctx slot after Send preparation failure
    007b4da2f38dc xprtrdma: Repost Receive buffers for malformed replies
    469b22376ee73 xprtrdma: Sanitize the reply credit grant after parsing
    d7a2870dde3bb xprtrdma: Fix bcall rep leak and unbounded peek
    345652531400f xprtrdma: Resize reply buffers before reposting receives
    47b3dc59e09e9 xprtrdma: Document and assert reply-handler invariants
    7471e66373a44 xprtrdma: Check frwr_wp_create() during connect
    28743571c17b5 xprtrdma: Initialize re_id before removal registration
    d0479c2b12974 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
    6d52921f47020 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
    56ad33189ed5f perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
    c32fe40b0c745 perf sched: Fix idle-hist callchain display using wrong rb_first variant
    77051ef66e4ad perf sched: Bounds-check prio before test_bit() in timehist
    2e0dd50e5a4da PCI: rcar-host: Remove unused LIST_HEAD(res)
    b9e8406651dcc perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
    504028f561b19 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
    2a8244988316a perf tools: Fix get_max_num() size_t underflow on empty sysfs file
    3f4476a089a6d platform/x86/intel/vsec: Restore BAR fallback for header walk
    d6565e08166c8 platform/x86/intel/vsec: Return real error codes from registration path
    4df30a4dc0e97 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
    817ab332d37ce platform/x86/intel/vsec: Decouple add/link helpers from PCI
    e6523bcafeb61 platform/x86/intel/vsec: correct kernel-doc comments
    c0d97519c9dfb platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map
    b95e1facc5b7f platform/x86:intel/pmc: Rename PMC index variable to pmc_idx
    3e86797c0699d platform/x86:intel/pmc: Add support for multiple DMU GUIDs
    4f129fc6f756f fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
    d3491b23bc207 PCI: meson: Add missing remove callback
    a5c0ba31eef9e PCI: meson: Propagate devm_add_action_or_reset() failure
    f0aaa198e068b pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
    a57692ad365f3 PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
    f161ef7b0dd2f nfs: use nfsi->rwsem to protect traversal of the file lock list
    a6f147b23e361 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
    a70375f0b793e NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
    b694c7de94bc5 nfs: keep PG_UPTODATE clear after read errors in page groups
    f84949dd17847 NFSv4/pnfs: defer return_range callbacks until after inode unlock
    53442c7d0c888 xprtrdma: Decouple req recycling from RPC completion
    becc90a04780a xprtrdma: Use sendctx DMA state for Send signaling
    e7ae0883c8c89 xprtrdma: Post receive buffers after RPC completion
    f043dd58fbd79 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
    b7bc8e7f09ae4 xprtrdma: Avoid 250 ms delay on backlog wakeup
    44b73b4b7eff7 pNFS/filelayout: fix cheking if a layout is striped
    f3f21b94cf980 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
    e8dc126e80395 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
    c0e6bb2b0408f dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
    9f1ef67c041ef dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
    329ec20a86091 dmaengine: Fix possible use after free
    7d49f0ddaf5a4 dmaengine: qcom: gpi: set DMA_PRIVATE capability
    8e2c460a8f0e4 mshv: add bounds check on vp_index in mshv_intercept_isr()
    eaf937b501fd0 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
    032692e4525a0 dt-bindings: clock: qcom: Add X1P42100 camera clock controller
    c7c8bab87d0df perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
    e16012f8f63d3 perf timechart: Fix cpu2y() OOB read on untrusted CPU index
    330219fe8523f perf c2c: Fix use-after-free in he__get_c2c_hists() error path
    01564c1a260f6 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
    c05ba5b57505a perf mmap: Fix NULL deref in aio cleanup on alloc failure
    c4406dbe5d8f4 perf sched: Replace BUG_ON and add NULL checks in replay event helpers
    b1f7683632712 perf sched: Use thread__put() in free_idle_threads()
    1517402d0a81c perf sched: Clean up idle_threads entry on init failure
    d6b586bb8f489 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
    2f9f7224e7691 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
    278e30717c356 perf stat: Bounds-check CPU index in topology aggregation callbacks
    21a9b87ada08d perf mmap: Guard cpu__get_node() return in aio_bind()
    652cea73b7b7b perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
    068e9b6a07bc0 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
    1d25a8418c890 perf tools: Add bounds check to cpu__get_node()
    89489a31f4443 perf sched: Fix thread reference leak in latency_switch_event
    ea486d61b1663 perf tools: Guard test_bit from out-of-bounds sample CPU
    18961e0f8966e perf annotate: Fix crashes on empty annotate windows
    93f3e84fc74e6 perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
    d78b16d078149 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
    a498063f95bdd dmaengine: imx-sdma: Refine spba bus searching in probe
    da40583823153 thunderbolt: debugfs: Fix margining error counter buffer leak
    038a0f01dda59 drm/amd/display: Add missing kdoc for ALLM parameters
    c5388a957cf1d fs/ntfs3: fix mount failure on 64K page-size kernels
    a318932065883 fs/ntfs3: add bounds check to run_get_highest_vcn()
    097fcf945d93a HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
    26fa946925a09 clk: at91: keep securam node alive while mapping it
    0147c544cbc6e iio: tcs3472: power down chip on probe failure
    1cddef80a180a iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
    9ac3675bf8757 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
    3d57672119525 iio: magnetometer: ak8975: fix potential kernel stack memory leak
    6ec473b360342 iio: light: si1133: prevent race condition on timeout
    f835b69fbeaeb iio: light: si1133: reset counter to prevent race condition
    fd6b65ade1190 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
    be62602fe0797 PCI: qcom: Disable ASPM L0s for SA8775P
    de93ef83f99e8 powerpc tools perf: Initialize error code in auxtrace_record_init function
    96c8f732cadf7 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
    fdee9f207a48c gpib: fix double decrement of descriptor_busy in command_ioctl()
    3d5e4cc0d9dce char: tlclk: fix use-after-free in tlclk_cleanup()
    d72ece584c448 gpib: Fix inappropriate ioctl error return
    92f8b1d833834 perf test amd ibs: Fix incorrect kernel version check
    2b2b1613b734b usb: host: max3421: Reject hub port requests for non-existent ports
    02d03c61e8a7b usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
    43078449ad623 staging: most: video: avoid double free on video register failure
    45652323ce74b perf inject: Add --convert-callchain option
    28ebd287a7fad perf build-id: Fix off-by-one bug when printing kernel/module build-id
    fc5ce5606db57 PCI: dwc: Fix signedness bug in fault injection test code
    7d881615fb637 mailbox: mtk-adsp: fix UAF during device teardown
    91353d63bbf61 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
    e6bc4e127707d coresight: Fix source not disabled on idr_alloc_u32 failure
    67d0475e78b39 soundwire: intel_ace2x: release bpt_stream when close it
    5732869c70d42 clk: at91: sam9x7: Fix gmac_gclk clock definition
    f28906e7e32fd perf pmu: Skip test on Arm64 when #slots is zero
    210c202c0576b phy: phy-can-transceiver: Check driver match and driver data against NULL
    226feccaac818 clk: qcom: cmnpll: Account for reference clock divider
    6abdf27fbcfb3 coresight: fix missing error code when trace ID is invalid
    5bb87456dcd66 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
    601a9b2e3b2fb rust: alloc: fix assert in `Vec::reserve` doc test
    b773c7161cea7 PCI: loongson: Do not ignore downstream devices on external bridges
    e1b79f77336d1 perf sched: Add missing mmap2 handler in timehist
    c788955b4a145 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
    2ce4d93768d2c x86/platform/olpc: xo15: Drop wakeup source on driver removal
    1d495446ec7ac PCI: Check ROM header and data structure addr before accessing
    78f264c0cb2ac PCI: Introduce named defines for PCI ROM
    10021c2d33061 PCI/ASPM: Don't reconfigure ASPM entering low-power state
    48dde5c56426c coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
    65d87f28daec3 coresight: ete: Always save state on power down
    1ac8f4c112aa9 coresight: etm4x: Remove the state_needs_restore flag
    a454f61747c97 soundwire: fix bug in sdw_add_element_group_count found by syzkaller
    d3896c944338c soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
    c3ca7c6741af3 coresight: cti: Fix DT filter signals silently ignored
    fb940466fd4d3 perf debuginfo: Fix libdw API contract violations
    bb3d592c7d6c4 staging: nvec: fix use-after-free in nvec_rx_completed()
    466c7f87de52d i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
    db2d8b6525bdd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
    02e2dadd62eae eventpoll: Fix epoll_wait() report false negative
    f938bc8fde518 eventpoll: rename epi->next and txlist for clarity
    430dac191905b eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
    d8f88803152f0 eventpoll: extract ep_deliver_event() from ep_send_events()
    4fd51f413d7b5 eventpoll: split ep_insert() into alloc + register stages
    25e85dc040a6c eventpoll: rename attach_epitem() to ep_attach_file()
    baebd892f8a2c eventpoll: expand top-of-file overview / locking doc
    f04166c8677aa eventpoll: rename ep_remove_safe() back to ep_remove()
    13bf9879b778b net/9p: fix race condition on rdma->state in trans_rdma.c
    9c1c120471a67 9p: avoid returning ERR_PTR(0) from mkdir operations
    ae1f3460833d3 ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
    d35e4032f16d7 mfd: cs42l43: Sanity check firmware size
    706fe1ce4f3a5 mfd: rsmu: Fix page register setup
    35d3d6ff2bc1e ksmbd: fix use-after-free in same_client_has_lease()
    aa0c43c13c0bf RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
    0fe155aa844e4 RDMA/bnxt_re: Move the UAPI methods to a dedicated file
    95d46a8d3ba9f RDMA/bnxt_re: Avoid displaying the kernel pointer
    104a7ff382a58 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
    5a48dd5150d7c ionic: Fix check in ionic_get_link_ext_stats
    4c55003566c0b net: ethernet: oa_tc6: Remove FCS size in RX frame
    93e133b9193cb net: airoha: Fix always-true condition in PPE1 queue reservation loop
    d774cdbda6634 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
    0d8a12d714312 tipc: fix UAF in tipc_l2_send_msg()
    db1616263a2c5 KEYS: Use acquire when reading state in keyring search
    66919a6d72b9e powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
    527cd14a416f2 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
    73711688479df powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
    92f38fe85198a MIPS: mm: Fix out-of-bounds write in maar_res_walk()
    fe09dd288722f bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
    81567d2b3f4dc sockmap: Fix use-after-free in udp_bpf_recvmsg()
    073d957252696 net: remove addr_len argument of recvmsg() handlers
    4e40056bb5c82 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
    264d6a79c96ee udf: fix nls leak on udf_fill_super() failure
    5e8627b7a7b7c bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
    e803077769248 selftests/bpf: Initialize operation name before use
    9f32d4c2de85f selftests/bpf: Fix typo in verify_umulti_link_info
    74badb5e2b00a smb/client: always return a value for FS_IOC_GETFLAGS
    21303c4a2b727 cifs: remove all cifs files before kill super
    7a59146cb9ade ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
    87d1eaffeec41 netfilter: nf_conncount: callers must hold rcu read lock
    98a965cb1e767 ALSA: seq: avoid stale FIFO cells during resize
    287d506d4e086 ALSA: seq: oss: Serialize readq reset state with q->lock
    f01fb6138f8eb kcm: use WRITE_ONCE() when changing lower socket callbacks
    4d48c08a0bf6c net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
    dcac6e4221f39 net: airoha: Fix register index for Tx-fwd counter configuration
    36edab340a067 net: bcmgenet: Use weighted round-robin TX DMA arbitration
    b91b241a4eefe landlock: Fix unmarked concurrent access to socket family
    1bb02353e79f7 dpll: balance create/delete notifications in __dpll_pin_(un)register
    77a1ea975c877 dpll: guard sync-pair removal on full pin unregister
    8008ef973f012 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
    6564ce3a2f9c2 dpll: send delete notification before unregister in on-pin rollback
    f1e1c6eb82482 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
    20575400fc1ba dpll: Enhance and consolidate reference counting logic
    ebe4bd3560a7a dpll: Support dynamic pin index allocation
    f7aebaee2961b net: wwan: t7xx: check skb_clone in control TX
    34bd255dba321 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
    1d072cc3ba433 octeontx2-af: npc: Fix size of entry2cntr_map
    417bd36a085d7 bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
    3d90b15fb1918 net/mlx5: Check max_macs devlink param value against max capability
    8d5f4be134882 bpf: Run generic devmap egress prog on private skb
    450e48271827b net/sched: sch_dualpi2: Add missing module alias
    6d585d0dc6743 net: ethernet: mtk_wed: fix loading WO firmware for MT7986
    446fe8ce699ce net: watchdog: fix refcount tracking races
    697db22a9dcc4 net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
    62ce489acb428 net: mana: initialize gdma queue id to INVALID_QUEUE_ID
    bd851b10daee7 net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
    755108bb7a508 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
    0500af8630c32 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
    a05d638b60746 virtio_net: do not allow tunnel csum offload for non GSO packets
    ce311bd2e3659 tcp: clear sock_ops cb flags before force-closing a child socket
    67cec2f1eb9e5 handshake: Require admin permission for DONE command
    d0503357653ee power: supply: core: fix supplied_from allocations
    7f4aa81f5bb27 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
    0c22c00924359 iommu: Avoid copying the user array twice in the full-array copy helper
    1c9246a199e19 spi: xilinx: use FIFO occupancy register to determine buffer size
    dae23c545eb5a ALSA: seq: Fix kernel heap address leak in bounce_error_event()
    1749fef4bda0f ALSA: usb-audio: qcom: Guard sideband endpoint removal
    2ba2373151936 crypto: rng - Free default RNG on module exit
    fb4d57b83356d crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    5f99a396f706a crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    4941205f5fa39 cxl/test: Add check after kzalloc() memory in alloc_mock_res()
    a27481516d32f cxl/test: Unregister cxl_acpi in cxl_test_init() error path
    7e401233f9bb7 tipc: reject inverted service ranges from peer bindings
    3cfa3d8e0dc16 tipc: prevent snt_unacked underflow on CONN_ACK
    cebaefe1aceb6 tipc: require net admin for TIPCv2 netlink mutators
    66dbb13eeb2fc net/sched: sch_hfsc: Don't make class passive twice
    51a1d9836acc7 net: pfcp: allocate per-cpu tstats for PFCP netdevs
    ed8605c6f39b9 sctp: validate embedded address parameter length
    a090880c1f544 bridge: cfm: reject invalid CCM interval at configuration time
    bb4a5b3c91af3 net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
    0a8b5b74f0e6b net/sched: cls_flow: Dont expose folded kernel pointers
    10e05634ddc19 net: dsa: qca8k: fix led devicename when using external mdio bus
    e098c9c6477df ASoC: tegra: tegra210_ahub: Validate written enum value
    0f1510e84d7bf ASoC: fsl: fsl_audmix: Validate written enum values
    9131e4b023e0d ASoC: codecs: hdac_hdmi: Validate written enum value
    cb527e063a32e ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
    d3ff718c0c715 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
    4b87a2497276a RDMA/mlx5: Fix undefined shift of user RQ WQE size
    1bc1487f7a7f5 RDMA/mlx5: Remove raw RSS QP restrack tracking
    f704db4b0318a RDMA/mlx5: Remove DCT restrack tracking
    3a1687e0506be fs: efs: remove unneeded debug prints
    7e694ac97591c Bluetooth: vhci: validate devcoredump state before side effects
    ec4d352747a62 Bluetooth: hci: validate codec capability element length
    7f206a8d8d822 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
    a0fd1086a57b9 Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
    e8815ae9dcdc5 Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
    f1b4df9c260c5 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
    e284bb94ad451 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
    c86c861c64b58 s390/process: Fix kernel thread function pointer type
    0eab19ab9cb1b ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()
    c83255f3cf22d arm64: dts: allwinner: a523: Add missing GPIO interrupt
    ad6963c3bb458 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
    5985ddfd3e83f pinctrl: airoha: an7581: add missed gpio32 pin group
    db3cd694ded4c pinctrl: airoha: generalize pins/group/function/confs handling
    0234e8fc296e7 pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
    46fbafe3d2d56 bpf: Tighten cgroup storage cookie checks for prog arrays
    d416dcefdbac9 vfio/qat: fix f_pos race in qat_vf_resume_write()
    1201dbb260507 of: cpu: add check in __of_find_n_match_cpu_property()
    d2acea4f47475 cxl/test: Zero out LSA backing memory to avoid leaking to user
    42a9a76f314ef cxl/test: Fix integer overflow in mock LSA bounds checks
    91ad3088ee1b7 selftests/bpf: Fix bpf_iter/task_vma test
    f00f5c0dd5531 ext4: fix kernel BUG in ext4_write_inline_data_end
    c998a09c7144e bonding: 3ad: fix mux port state on oper down
    f0ada4846d11b bonding: 3ad: fix carrier when no usable slaves
    cb20a9b50efe0 bonding: 3ad: add lacp_strict configuration knob
    47636f0a70b36 netlink: specs: rt-link: missed broadcast-neigh
    6b2c271d2c394 tools: missed broadcast_neigh if_link uapi header
    484b3b9aa7986 ext4: fix ERR_PTR(0) in ext4_mkdir()
    88cb304c0be0c ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
    8b55e7ec116ca ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
    3ef0cfa77a3d5 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    54556d5394382 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
    86e0b37738dea tools/virtio: check mmap return value in vringh_test
    321c73baf54d9 vhost/net: complete zerocopy ubufs only once
    646614dcb1607 vduse: Requeue failed read to send_list head
    f9d9220234451 virtio_console: read size from config space during device init
    79366023aa891 virtio: rtc: tear down old virtqueues before restore
    1f5f94c6c6b2e vhost/vdpa: validate virtqueue index in mmap and fault paths
    a2d0a57538fd0 vduse: hold vduse_lock across IDR lookup in open path
    3d56f3fb201ff ASoC: codecs: aw88261: fix incorrect masks for boost regs
    ecb9be4fc8be0 spi: meson-spifc: fix runtime PM leak on remove
    da6f86ff4f2dd NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
    37e85be551c4d IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
    e6d83f877d5ab ASoC: sma1307: Fix uevent string leaks in fault worker
    701ea71c17c92 igc: skip RX timestamp header for frame preemption verification
    2aa37c8ef1092 btrfs: fix deadlock cloning inline extent when using flushoncommit
    f85410ebf20bb btrfs: annotate lockless read of defrag_bytes in should_nocow()
    18285888cb41a btrfs: zoned: always set max_active_zones for zoned devices
    943f5917c53ca Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"
    ba641829c11cb btrfs: zoned: don't account data relocation space-info in statfs free space
    bd5e90b0f5a09 hwmon: (it87) Clamp negative values to zero in set_fan()
    ebb579c5c0f0f vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
    de590cdf7efec fbdev: sm501fb: Fix buffer errors in OF binding code
    0678fed27def9 wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported
    47e5302722e09 gpio: mt7621: fix interrupt banks mapping on gpio chips
    90a9c909c5b75 ALSA: aloop: Drop superfluous break
    3b15d02be05e7 btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
    7ec839c7c0bc1 wifi: mt76: mt7996: fix potential tx_retries underflow
    ad12fdaaed16c wifi: mt76: mt7925: fix potential tx_retries underflow
    3b6e6fefa57f4 wifi: mt76: mt7921: fix potential tx_retries underflow
    6b8e35685c18c wifi: mt76: mt7915: fix potential tx_retries underflow
    6356a829a1edc wifi: mt76: fix argument to ieee80211_is_first_frag()
    42f34c478fcdf wifi: mt76: mt7996: limit work in set_bitrate_mask
    1a399103cacc9 wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()
    dfb27e5dd9e4d wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
    06e65d6cf8049 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
    c386e90a7ce8d wifi: mt76: mt7925: validate skb length in testmode query
    856fa6a21586f wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
    a10e4959a73be wifi: mt76: mt7925: keep TX BA state in the primary WCID
    b8bf7c221b364 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
    bd3b91ff13006 wifi: mt76: mt7996: add missing max_remain_on_channel_duration
    c7a83899203ed wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
    3f0ea6d14fa44 wifi: mt76: mt7925: clean up DMA on probe failure
    ce9d5a021cfca ARM: configs: Drop duplicated CONFIG_EXT4_FS
    c788617705c3a sched/fair: Fix cpu_util runnable_avg arithmetic
    a2e8b5264f92e hwspinlock: qcom: avoid uninitialized struct members
    bbd664b7c77f6 vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
    648a3960e3664 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39
    44cff0737127b pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39
    f775e7bda9a4f scsi: target: Remove tcm_loop target reset handling
    c2bd9fdb448d6 scsi: target: Fix hexadecimal CHAP_I handling
    0404baeb9e430 pinctrl: qcom: Fix resolving register base address from device node
    298821692d447 watchdog: unregister PM notifier on watchdog unregister
    637ef4961470e configfs: fix lockless traversals of ->s_children
    f25d6e4ec4c25 firmware_loader: Fix recursive lock in device_cache_fw_images()
    9e82497138abe ASoC: amd: acp-sdw-sof: Bound DAI link iteration
    1279bdab5fa1f ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
    e8d89baf92170 spi: ep93xx: fix double-free of zeropage on DMA setup failure
    e123f0ab02d05 IB/mlx5: Don't mangle the mr->pd inside the rereg callback
    fd284b12810e4 IB/mlx5: Pull the pdn out of the depths of the umr machinery
    8119fe468b01f IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
    d4f84bfa089fe IB/mlx5: Properly support implicit ODP rereg_mr
    f5657d399b7ef IB/mlx5: Don't take the rereg_mr fallback without a new translation
    c213b71a2d416 btrfs: don't force DIO writes to be serialized
    920dcf1cb8dae thermal: testing: reject missing command arguments
    dde04550fd6ff cpufreq: Documentation: fix conservative governor freq_step description
    6cb635ad1006d ACPI: IPMI: Fix message kref handling on dead device
    b7474f4432dd9 bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
    84932636d020b powerpc/8xx: implement get_direction() in cpm1
    8daa1a64711ed kunit:tool: Don't write to stdout when it should be disabled
    8b0510cc3a4a0 bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
    74ac1ce1f4afd ALSA: seq: Clear variable event pointer on read
    c04e0cde2fa38 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
    834d4cc067fa6 riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
    4b2b6bc7f5ebe ALSA: seq: Fix partial userptr event expansion
    af8f0ea1f0a3a wifi: wcn36xx: fix OOB read from short trigger BA firmware response
    f03782f7f41f2 wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
    1b5d8a248c3af wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
    495e7e832c670 bpf: Update transport_header when encapsulating UDP tunnel in lwt
    efe57b72196ae bpf: Check tail zero of bpf_prog_info
    58513d6d12410 bpf: Check tail zero of bpf_map_info
    2eb39de4962f8 bpf: Clear rb node linkage when freeing bpf_rb_root
    f6183983ce1ff RDMA/siw: Fix endpoint/socket association handling
    04255bda8d795 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
    e6ab22200e449 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well
    f3ef944c55991 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
    b5087fc4ef1f8 arm64: dts: imx95: Correct PCIe outbound address space configuration
    ab4b5a07e1c1a arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
    f9173e0fc026c RDMA/irdma: Initialize iwmr->access during MR registration
    54cab78df0375 RDMA/irdma: Fix OOB read during CQ MR registration
    844a1ae78e220 ALSA: hda: fix Kconfig dependency of HD Audio PCI
    47831b503ecb7 IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
    fe5414d6b3995 RDMA/hfi1: Open-code rvt_set_ibdev_name()
    77b4bfc1ce32a netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp
    d53eecbca16f0 netfilter: conntrack: revert ct extension genid infrastructure
    e6665d36b37b4 x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
    dd0d22fdae4cb ALSA: usb-audio: qcom: Initialize offload control return value
    8ebc31b86dccd netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
    5c9c67cf7a3d1 netfilter: synproxy: fix unaligned memory access in timestamp adjustment
    b171119082bab netfilter: synproxy: adjust duplicate timestamp options
    4dbb71c046f72 netfilter: synproxy: drop packets if timestamp adjustment fails
    dce1e3cf735d1 netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
    7b819a84f1d5f netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
    c3ebf67cf8a96 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()
    a087b2d3411e7 ocfs2/dlm: require a ref for locking_state debugfs open
    3fa7139b5f427 ocfs2: reject FITRIM ranges shorter than a cluster
    0e389fc290c35 ocfs2: fix buffer head management in ocfs2_read_blocks()
    3fe2d0d21c8ae lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
    bb44a7690a4d5 ocfs2: rebase copied fsdlm LVB pointers in locking_state
    9af58d10d0d8c of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
    9a030fcb4b192 drm/amdkfd: always resume_all after suspend_all
    b8d15e85596ad cxl/fwctl: Fix __fortify_panic
    b64120d54278e xfrm: fix NAT-related field inheritance in SA migration
    ac9e29b191a03 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
    58cbb1c2aadf8 perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
    4e18e9361aab0 perf/x86/amd/core: Always use the NMI latency mitigation
    f5102e0fc3c6d iommu/vt-d: Fix RB-tree corruption in probe error path
    7f229d27bf27c vhost: fix vhost_get_avail_idx for a non empty ring
    73f9f54d71749 bpftool: Use libbpf error code for flow dissector query
    4beed798daf4d drm/amdgpu: set sub_block_index for mca ras sub-blocks
    e82d515092a0c ext4: fix fast commit wait/wake bit mapping on 64-bit
    8cbd587e8cdb6 lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
    8d5ed4810e479 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
    c3b073a209a9b configfs_lookup(): don't leave ->s_dentry dangling on failure
    778bb4939d457 riscv: dts: sophgo: sg2042: use hex for CPU unit address
    efe71fbced524 riscv: dts: sophgo: sg2044: use hex for CPU unit address
    5a1168ba0a95b lib/test_meminit: use && for bools
    3777588848520 tick/sched: Fix TOCTOU in nohz idle time fetch
    5cf2c85b12312 bpf: Reject exclusive maps for bpf_map_elem iterators
    0830287cc6cb7 driver core: Use system_percpu_wq instead of system_wq
    5e406928404d6 nvme: fix FDP fdpcidx bounds check
    36bdda0c86d51 sched: restore timer_slack_ns when resetting RT policy on fork
    ffa974b2f50ad ext2: fix ignored return value of generic_write_sync()
    8d763babb2a2f mm/fake-numa: fix under-allocation detection in uniform split
    61f1972972824 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
    d81370c6c4f5f scsi: ufs: Fix wrong value printed in unexpected UPIU response case
    846052542cfa6 scsi: pm8001: Fix error code in non_fatal_log_show()
    0de14eae6de88 libbpf: Skip max_entries override on signed loaders
    abe383999640f libbpf: Skip initial_value override on signed loaders
    b6862b6a25c6a libbpf: Reject non-exclusive metadata maps in the signed loader
    3a0f73d27a8d3 bpf: Reject exclusive maps as inner maps in map-in-map
    91ca9eab008b9 scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"
    5c53406098b59 nvdimm/btt: Handle preemption in BTT lane acquisition
    d292b30e1b746 x86/cpu: Keep the PROCESSOR_SELECT menu together
    901802925ebed ARM: imx31: Fix IIM mapping leak in revision check
    617a5a67ce016 ata: libata: Fix ata_exec_internal()
    cfcea221db933 wifi: ath12k: fix NULL deref in change_sta_links for unready link
    eb9b89baf3087 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
    adf0eb748d21d HID: wiimote: Fix table layout and whitespace errors
    2d642797dd1c1 ARM: imx3: Fix CCM node reference leak
    f0742d09eb6ba NFSD: Fix delegation reference leak in nfsd4_revoke_states
    9e565962d999e ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
    8ec64276ecd24 spi: atmel: fix DMA channel and bounce buffer leaks
    ab4d04bf8b2f3 ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback
    803087a16a4ea libbpf: Skip endianness swap when loader generation failed
    f3389fbaff1a1 libbpf: Skip hash computation when loader generation failed
    a441c0794ac28 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
    a7131340d0f95 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
    5ac9e793ba258 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
    b7313f23ea5a7 md/raid10: reset read_slot when reusing r10bio for discard
    e04e384274f83 rpmsg: use generic driver_override infrastructure
    0e2f0833556c8 Drivers: hv: vmbus: use generic driver_override infrastructure
    d2cf52ba2803b cdx: use generic driver_override infrastructure
    b41923dbf6769 amba: use generic driver_override infrastructure
    ff4e38a37ba53 media: qcom: venus: relax encoder frame/blur step size on v6
    bc7c166cc1012 media: qcom: venus: relax encoder frame/blur dimension steps on v4
    ffe754288750a media: qcom: venus: drop extra padding in NV12 raw size calculation
    f8f48c851a0d2 Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
    5420eebf3b3c1 RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
    02558c86b6b76 RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
    4779f435627b2 RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM
    bae436a78a058 arm64: dts: st: Fix SAI addresses on stm32mp251
    5da012c605fd5 EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info
    9a84ced0243c7 EDAC/igen6: Fix call trace due to missing release()
    ed5c94cf4ee9e drm/msm/dp: Fix the ISR_* enum values
    bdaea74abcf0c drm/msm/dp: fix HPD state status bit shift value
    6d536a9107172 sched/deadline: Reject debugfs dl_server writes for offline CPUs
    4f3c17f14cf90 crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm
    5eac10c521396 crypto: tegra - Fix dma_free_coherent size error
    5231093c08295 crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq
    8572232ed74f5 crypto: hisilicon/qm - disable error report before flr
    ce7a2e26e144f ocfs2: kill osb->system_file_mutex lock
    3852478d34c7b ocfs2: don't BUG_ON an invalid journal dinode
    070f356ea4f41 rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
    598ed7393a639 dax/kmem: account for partial discontiguous resource upon removal
    afdb92d9c374d arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware
    e545fcba3660c ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware
    c87339cc08aa0 libbpf: Fix UAF in strset__add_str()
    39e8be33387e3 bpftool: Fix typo in struct_ops map FD generation for light skeleton
    ed7ba8d048a4c libbpf: Harden parse_vma_segs() path parsing
    340936ebf5aec drm/nouveau/bios: specify correct display fuse register for Ampere and Ada
    2ab7c96d8c3fb drm/tegra: Fix iommu_map_sgtable() return value check
    79240eee5a400 gpu: host1x: Fix iommu_map_sgtable() return value check
    142b34f7e329c drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
    8c0d3cf0d5108 gpu: host1x: Allow entries in BO caches to be freed
    6b617b6ccb6eb drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
    40a2a91da02c4 drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered
    05d85fd32e4fe rtla/actions: Restore continue flag in actions_perform()
    b7ac7ba19a0b8 rtla: Introduce for_each_action() helper
    dc266f6c4e262 iommu/amd: Fix premature break in init_iommu_one()
    10753da2d659d net/sched: cls_bpf: prevent unbounded recursion in offload rollback
    0db1949084e85 ipv6: guard against possible NULL deref in __in6_dev_stats_get()
    dc1470299d11d workqueue: drop spurious '*' from print_worker_info() fn declaration
    3e8aed5edaeeb nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
    140d6fff4ed26 nvme-multipath: fix flex array size in struct nvme_ns_head
    cba2ee57fd302 nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
    ba3209704b3cd nvmet-tcp: fix page fragment cache leak in error path
    24639c4dc466e init/initramfs_test: wait_for_initramfs() before running
    eb9280ea8dbd2 pinctrl: cs42l43: Fix polarity on debounce
    2739d234d8952 pinctrl: cs42l43: Fix leaked pm reference on error path
    95e0b4bc29ab9 pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table
    c418c956c21c9 selftests: Fix Makefile target for nsfs
    11165fe2c5ea0 ALSA: seq: midi: Serialize output teardown with event_input
    6dc781778b595 ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
    de236b813d8b4 ALSA: xen-front: Connect event channel after stream prepare
    56694f00fbe10 ALSA: xen-front: Reset event channel state on stream clear
    02f156309de0d mtd: spi-nor: Drop duplicate Kconfig dependency
    c4bb92b3ef54c mtd: spi-nor: debugfs: Fix the flags list
    3880ee7c88d78 driver core: Guard deferred probe timeout extension with delayed_work_pending()
    0a294feec21b6 driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout()
    2c12b0dfcedad mips: n64: add __iomem for writel call
    8db227dd895a8 mips: ralink: mt7621: add missing __iomem
    0c83d13f9b3f1 MIPS: DEC: Remove do_IRQ() call indirection
    c9a3ceeddc6ad MIPS: Fix big-endian stack argument fetching in o32 wrapper
    c9670fd84df12 PM: sleep: Use complete() in device_pm_sleep_init()
    80f8e2302e639 pinctrl: meson: amlogic-a4: fix gpio output glitch
    9420871183eab RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup
    66f44ec974ab3 RDMA/hns: Fix log flood after cmd_mbox failure
    16138ea9833d6 RDMA/hns: Fix warning in poll cq direct mode
    f67fbbfc3beb8 IB/mlx4: Fix refcount leak in add_port() error path
    e59a6aa89e0fc RDMA/rxe: Fix a use-after-free problem in rxe_mmap
    424d51d33c754 RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
    7a551951ebeb5 pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
    394ed8ad05889 bus: sunxi-rsb: Always check register address validity
    090f5fb1e3e23 RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed
    c11039512df49 pwm: imx27: Fix variable truncation in .apply()
    13db458099f28 cpufreq: conservative: Simplify frequency limit handling
    3fcbfc50dd52f cpufreq: Documentation: fix sampling_down_factor range
    376951c51cdd0 crypto: eip93 - fix reset ring register definition
    4a6f5cc42c7bf of: dynamic: Fix overlayed devices not probing because of fw_devlink
    ae62edb00c0eb Revert "treewide: Fix probing of devices in DT overlays"
    2df37ead6d84b driver core: Use mod_delayed_work to prevent lost deferred probe work
    62c8cc825f49e device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id()
    b0444205ba39e kernfs: fix suspicious RCU usage in kernfs_put()
    29de8448174cf writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount()
    2469039f0fd68 arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs
    baa333b2700a7 tracing: Bound synthetic-field strings with seq_buf
    09a2a7d041a78 arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node
    4ba44339fd3ac arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
    3c808cac676c5 arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node
    0d0ce8c7025ac arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
    a8be1bc8d124f arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node
    dc36463b283d9 arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node
    a2303478e7301 arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node
    b3e05859cb516 arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node
    11daac2817dca firmware: arm_scmi: Fix OOB in scmi_power_name_get()
    15e7368de5842 media: rockchip: rga: fix too small buffer size
    a88f6da618e8b net/sched: sch_drr: annotate data-races around cl->deficit
    276e731b1b577 nilfs2: Fix return in nilfs_mkdir
    16bf3154f8a80 tools/nolibc: getopt: Fix potential out of bounds access
    c67c672047667 regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
    75c0bc011abdd bitops: use common function parameter names
    407aeb8c1aee8 sysfs: clamp show() return value in sysfs_kf_read()
    bac3e70c2fb10 firmware: arm_scmi: Read sensor config as 32-bit value
    1f60c3cc302d2 firmware: smccc: Fix Arm SMCCC SOC_ID name call
    3024229e4a5af riscv: dts: spacemit: set console baud rate on Milk-V Jupiter
    63aa7dda9a1ed staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
    d57e67ea48e4d media: atomisp: gc2235: fix UAF and memory leak
    2e3e4cc0dd349 media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
    5d6f34dc4f056 arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply
    084d7d5668f30 arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply
    6a576739ce4c9 arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties
    0da72a88dbbab firmware: arm_ffa: Honor partition info descriptor size
    5e353d9497f95 selftests/mm: Fix resv_sz when parsing arm64 signal frame
    6a357ceb21100 iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table
    bcfc49f1bcf1b selftests/bpf: Fix test for refinement of single-value tnum
    e4d599a286b5a selftests/bpf: Reject unsupported -k option in vmtest.sh
    7471006cd854d drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
    be2c137f23d15 RDMA/hns: Initialize seqfile before creating file
    65572fbd86033 RDMA/srpt: fix integer overflow in immediate data length check
    5100febf8e9d6 RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
    ffa85a2c19793 RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
    2cd221fca036b RDMA/hns: Fix arithmetic overflow in calc_hem_config()
    65e344925fa30 IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
    b61af0268e3d1 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
    5c1196b5a3bf3 net/sched: sch_htb: annotate data-races (I)
    d8cae30582f06 net/sched: sch_htb: do not change sch->flags in htb_dump()
    68eae3592438d spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
    21650fe221ea9 crypto: ccp - Treat zero-length cert chain as query for blob lengths
    cb414aff28e18 scsi: hisi_sas: Add slave_destroy interface for v3 hw
    8b42290df1765 net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
    d29b9c38f6eb4 clk: scpi: Unregister child clock providers on remove
    69bc4a3998742 thermal: hwmon: Fix critical temperature attribute removal
    a0f64cf8bfcb3 evm: terminate and bound the evm_xattrs read buffer
    4c57df82af833 drm/hisilicon/hibmc: use clock to look up the PLL value
    28b91fd2adc4f drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
    94ab8a6e02bae drm/hisilicon/hibmc: fix no showing when no connectors connected
    689bb48c828ca drm/hisilicon/hibmc: add updating link cap in DP detect()
    27af16a44f590 arm64: dts: qcom: sm8450: Fix ICE reg size
    886fb63981a92 arm64: dts: qcom: kodiak: Fix ICE reg size
    2e2e5888764ba clk: scmi: Fix clock rate rounding
    8200ffd8259f0 rust: alloc: fix `Vec::extend_with` SAFETY comment
    9fe7605c1c143 arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host
    02367b12b303a uaccess: fix ignored_trailing logic in copy_struct_to_user()
    e003f3a4be738 bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
    8960088511ca1 soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge
    0dd1cf48a4217 iommu/amd: Fix a stale comment about which legacy mode is user visible
    feb10ab7abc24 media: venus: scale MMCX power domain on SM8250
    9e642727b97dd media: iris: scale MMCX power domain on SM8250
    e725aedd26e96 media: qcom: camss: vfe: fix PIX subdev naming on VFE lite
    f9f1a2cd912da nilfs2: fix backing_dev_info reference leak
    712714f818d83 dlm: fix add msg handle in send_queue ordered
    4695cfab48f90 ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
    6acd2fbd00f9c crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
    9b21d5bd33a7f crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
    aac63bbea8fd5 crypto: atmel-sha204a - fix blocking and non-blocking rng logic
    c5c79d92da0f9 crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
    25b0061adc1c1 crypto: ccp - Reverse the cleanup order in psp_dev_destroy()
    46696b0b21234 OPP: Fix race between OPP addition and lookup
    8fe4736532639 alarmtimer: Remove stale return description from alarm_handle_timer()
    224d7300b5691 drm: renesas: rz-du: mipi_dsi: Fix return path on error
    4a8cde6f7281e vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
    470984f1c2ed8 Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal"
    5f7777f0da030 Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal"
    b9c6ad49a942d arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
    a5e026d5b9487 arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
    6173c83d4d791 arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
    2b553fcec1cd8 ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
    d003d9bb44da1 drm/panel: Clean up S6E3HA2 config dependencies and fill help text
    76a4c3af3253d drm/gpuvm: take refcount on DRM device
    02b001d89157a dt-bindings: vendor-prefixes: Add Displaytech Ltd.
    a402b3d093815 pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
    c599af2eacd66 dts: spacemit: set console baud rate on bpif3
    796ff973077c7 lib/vsprintf: Fix to check field_width and precision
    53baa6b90f499 crypto: qat - fix heartbeat error injection
    928f758f8f214 memory: tegra: Wire up system sleep PM ops
    2b2a17af8d8c7 media: v4l2-common: Add YUV24 format info
    4534f70aa7042 media: cedrus: Fix failure to clean up hardware on probe failure
    facbb592e22dd watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure
    1917015aa0a1d watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
    d6e8d6b2f8f04 watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
    29fd4f4c73e2b Documentation/rv: Replace stale website link
    19eb0ab0bdffb ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
    5435fd3edcb11 wifi: ath9k: fix OOB access from firmware tx status queue ID
    7c79be7e63447 pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
    a83e77d1e52c0 soc: xilinx: Shutdown and free rx mailbox channel
    fbeea02c3564d kconfig: fix potential NULL pointer dereference in conf_askvalue
    ad445de67359f wifi: rtw89: add bounds check on firmware mac_id in link lookup
    01155ded5d4da wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer
    7a1ab5fdcae89 wifi: rtw89: Correct data type for scan index to avoid infinite loop
    1ef3d1338d94e wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
    aefc30e4a829c wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
    cc77f0d91e321 driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
    543ed0f61d565 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
    1638e178e4915 dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
    cc6ef5ee7d88a arm64: tegra: Fix Tegra234 MGBE PTP clock
    228db770fb086 wifi: cfg80211: fix grammar in MLO group key error message
    123e1cd95ba54 arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning
    d8367ee271aba arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning
    d72ae2c63b683 arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings
    8f8233d544aca arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
    58d0b4c55cdfd arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra
    6005cdd9f48fd Documentation: proc: fix section numbering in table of contents
    d10227f899c90 selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
    595710e6838c3 selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable
    2dfe817167af0 drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro
    afea00ffcf41c dt-bindings: timer: Remove sifive,fine-ctr-bits property
    bc4737e55ec41 selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest
    392c03362c278 libbpf: Report error when a negative kprobe offset is specified
    06dc892561f5a drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
    d9dfa176899d4 drm/radeon: fix integer overflow in radeon_align_pitch()
    daf5d03ddb8cc drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
    41a60487b5b04 drm/gpuvm: Do not prepare NULL objects
    353f26c74660b drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
    626fa93d194db drm/tidss: Drop extra drm_mode_config_reset() call
    ab487bb0402af drm/rockchip: Test for imported buffers with drm_gem_is_imported()
    b3ec263a719e0 drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
    0d60b835bca42 drm/rockchip: dw_dp: Switch to drmm_kzalloc()
    68dc52f308a17 accel/amdxdna: Fix leak when pinning ubuf pages
    8e644d9a8c8dc clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive()
    d50d320e88b4c openrisc: mm: Fix section mismatch between map_page and __set_fixmap
    24186d6f9b07e fbcon: Use correct type for vc_resize() return value
    6617df8c24631 fbcon: fix NULL pointer dereference for a console without vc_data
    231414253b648 afs: Fix uncancelled rxrpc OOB message handler
    8b4d1854295b0 afs: Fix further netns teardown to cancel the preallocation charger
    cc848a080f7a6 afs: handle CB.InitCallBackState3 requests without a server record
    23b3d457d8387 afs: fix NULL pointer dereference in afs_get_tree()
    b83ecf80e28af afs: Fix netns teardown to cancel the preallocation charger
    8cd8cf3052fff rxrpc: Fix double unlock in rxrpc_recvmsg()
    a89a13aea38ae rxrpc: Fix leak of connection from OOB challenge
    f9be514984471 rxrpc: Fix the reception of a reply packet before data transmission
    8db6a2c95e369 rxrpc: Fix ACKALL packet handling
    647e8e69c6ea3 rxrpc: Fix oob challenge leak in cleanup after notification failure
    7940e5c535489 rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate
    0fc5b37faec26 rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
    2b69b61057eb0 rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
    0d643a46fdea6 rxrpc: Fix socket notification race
    844b8525ce503 rxrpc: Fix UAF in rxgk_issue_challenge()
    9ada3931beb37 rxrpc: Don't move a peeked OOB message onto the pending queue
    d3b642cf95d48 rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
    35a967ff8b24d rxrpc: serialize kernel accept preallocation with socket teardown
    2ecd118fb6913 serial: 8250_omap: clear rx_running on zero-length DMA completes
    c37095c431c39 serial: max310x: implement gpio_chip::get_direction()
    d354716245192 serial: msm: Disable DMA for kernel console UART
    03fd857c33456 dt-bindings: power: imx93: Add MIPI PHY power domain
    d97a6b4a5a4fb dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
    79982331c1738 media: uvcvideo: Fix sequence number when no EOF
    19cb644d0ca59 media: uvcvideo: Relax the constrains for interpolating the hw clock
    bf58be93c51ba media: uvcvideo: Do not add clock samples with small sof delta
    aed8111f2392d media: uvcvideo: Fix dev_sof filtering in hw timestamp
    0f64f808fb4ee media: uvcvideo: Fix buffer sequence in frame gaps
    1a9baac645769 media: uvcvideo: Avoid partial metadata buffers
    caf800e0cab94 media: uvcvideo: Use hw timestaming if the clock buffer is full
    6b2c0cd5f9689 ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7
    2f33044aedd7a ALSA: hda: Fix cached processing coefficient verbs
    ae7f5b05d225c ALSA: hda: conexant: Remove mic bias threshold override
    12e43f99242b0 ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
    e0a71cbf0c190 af_unix: Drop all SCM attributes for SOCKMAP.
    9b6c12e1a6be0 iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19
    a4fb0954f3dc2 iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19
    62dde71ca2c8c exfat: preserve benign secondary entries during rename and move
    f3a0dd2d88e83 selftests/bpf: Add tests for stale delta leaking through id reassignment
    985b8a0e52c58 selftests/bpf: Add tests for delta tracking when src_reg == dst_reg
    d75376fbc8563 bpf: Clear delta when clearing reg id for non-{add,sub} ops
    19836e8145de9 selftests/bpf: Add a test cases for sync_linked_regs regarding zext propagation
    07259d661c9d4 selftests/bpf: Add tests for improved linked register tracking
    564e4ce9fb401 selftests: bpf: Add test for multiple syncs from linked register
    3659deaf7bf69 media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
    c401492e01c7b crypto: sun4i-ss - Remove insecure and unused rng_alg
    088ee46c18d99 nvmet-tcp: Fix potential UAF when ddgst mismatch
    2ed3c9d955e8c nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
    588718101e844 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
    c646431865f4b KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
    d7860b682da55 crypto: algif_skcipher - force synchronous processing
    de5a46f3b2c8d tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
    e0caf7c3d49c7 smb/server: do not require delete access for non-replacing links
    bbf04810b2a06 nvme-pci: DMA unmap the correct regions in nvme_free_sgls
    40e44eff5116d perf trace: Deal with compiler const checks
    30bbd7e8999d1 perf trace: Don't change const char strings
    bc29e0699b35d perf diff: Constify strchr() return variables
    292f32503eda3 perf list: Don't write to const memory
    d03adc7039c39 perf list: Signal changing const memory is ok
    4283a813d7089 perf tp_pmu: Address const-correctness errors in recent glibcs
    018533cfe83cf perf units: Constify variables storing the result of strchr() on const tables
    e7d3f92238a3d perf hwmon_pmu: Constify the variables returning bsearch() on const tables
    5bcff7ce5c3b1 perf tools: Use const for variables receiving str{str,r?chr}() returns
    ee8ab4e8e7029 perf metricgroup: Constify variables storing the result of strchr() on const tables
    8bac35a8fd98f perf trace-event: Constify variables storing the result of strchr() on const tables
    a816153dd8575 perf demangle-java: Constify variables storing the result of strchr() on const tables
    f8cb25b1d5ed2 perf session: Don't write to memory pointed to a const pointer
    5f6d997641de9 perf bpf-event: Constify variables storing the result of strchr() on const tables
    3b540ba9606bf perf tools: Switch printf("...%s", strerror(errno)) to printf("...%m")
    659a56ba86a96 perf list: Remove unused 'sep' variable
    33250aa5cfade perf jitdump: Constify variables storing the result of strchr() on const tables
    972c65697792c perf time-utils: Constify variables storing the result of strchr() on const tables
    9ae21594ee518 perf strlist: Remove dont_dupstr logic, used only once
    110ce8fed0f8e perf strlist: Don't write to const memory

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 197a98e6e4883e47335df4d8a742980ab0a2a6a4)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.18.bb              |  6 ++---
 .../linux/linux-yocto-tiny_6.18.bb            |  6 ++---
 meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
 3 files changed, 18 insertions(+), 18 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index 9d44c803eb9..37570538857 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "56572c42354027a50e261f16fe13b057604873e7"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 7ff47505aa0..5addcaae07e 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
 include recipes-kernel/linux/cve-exclusion.inc
 include recipes-kernel/linux/cve-exclusion_6.18.inc
 
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 6111ae89daa..3ceba003fa4 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.18/standard/base"
 KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
 
-SRCREV_machine:qemuarm ?= "78e0248ce3cecd33f63926cd1d54c64e163d076c"
-SRCREV_machine:qemuarm64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuloongarch64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
+SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8"
+SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
 SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuriscv64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuriscv32 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemux86 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemux86-64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
+SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
 SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "f89c296854b755a66657065c35b05406fc18264d"
+SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.18/base"
 
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
                   ` (35 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:

    7b923c78b50d2 Linux 6.18.43
    bfe7f9993467b x86/bugs: Make Safe-RET robust against interrupt injection
    856a9b51680cb Linux 6.18.42
    0f33b1c457c21 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
    846ed916cfa0c gpu: Fix uninitialized buddy for built-in drivers
    bcb29986bbba8 net: stmmac: fix dwmac4 transmit performance regression
    a0d1a11b90a51 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
    f282242906c12 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
    aeebcfa8237c3 rust: device: avoid trailing ; in printing macros
    e94e820df37d4 rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >= 1.98
    6ce0db97fb37a mm/damon/core: disallow overlapping input ranges for damon_set_regions()
    4b6f1d6d5d078 mm/damon/core: validate ranges in damon_set_regions()
    deead12d2e650 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization
    811b581fae651 i3c: mipi-i3c-hci: Fix Hot-Join NACK
    4fd5b33faf092 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
    c389893bb4037 pmdomain: imx93-blk-ctrl: convert to devm_* only
    dc8347f263b21 net: ipa: fix SMEM state handle leaks in SMP2P init
    4c1e8ccd8655e ata: libata-core: Reject an invalid concurrent positioning ranges count
    9466dc5e377f0 bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
    a88c2a70ea0ad bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
    c73b8795b45f4 octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
    4467fa514482b octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
    ae5ae3d5bfaa6 net: mana: Optimize irq affinity for low vcpu configs
    6d13eaa13341a net: mana: Validate the packet length reported by the NIC
    7b7bb07efe41b fs/resctrl: Fix use-after-free during unmount
    d48cf914c739e fs/resctrl: Move RMID initialization to first mount
    682d3c2cd20e0 fs/resctrl: Move allocation/free of closid_num_dirty_rmid[]
    8c5925f0fa128 x86,fs/resctrl: Rename some L3 specific functions
    696c34a1964f4 x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain
    ad4ea2a169a48 fs/resctrl: Split L3 dependent parts out of __mon_event_count()
    5b82af744e06c mmc: vub300: fix use-after-free on probe failure
    73d397ab54f2a mmc: vub300: rename probe error labels
    8ced1d242c34e dm: avoid leaking the caller's thread keyring via the table device file
    dd73cc92a55d7 cred: add kernel_cred() helper
    af7a4c2caa7a1 accel/amdxdna: reject command submission on devices without a submit op
    62dae36be7a62 ovl: use linked upper dentry in copy-up tmpfile
    043acb00e4edd dmaengine: dw-edma-pcie: Reject devices without driver data
    277a035cda47d dmaengine: dw-edma: Fix confusing cleanup.h syntax
    19360c25135fc mtd: maps: vmu-flash: fix fault in unaligned fixup
    b8271be34bce1 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
    3d561f46fa784 mm/sparse-vmemmap: fix vmemmap accounting underflow
    8af652cd99460 remoteproc: xlnx: Check remote core state
    6fc1919a6f2ed cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
    89b2ae039d188 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c
    eeab775069920 cxl/pci: Remove unnecessary CXL RCH handling helper functions
    a64661dccb2eb cxl/pci: Remove unnecessary CXL Endpoint handling helper functions
    5d964cb2b7bc8 SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
    b50b2cb87e7ac SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
    a112b91dd6349 sunrpc: allocate a separate bvec array for socket sends
    3120f21df3fb0 NFSD: pass nfsd_file to nfsd_iter_read()
    6876f767b0490 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
    7185c5262435b gpu/buddy: bail out of try_harder when alignment cannot be honoured
    9634fd144cdc1 drm: drop lib from header search path.
    65677f7a20c48 gpu: Move DRM buddy allocator one level up (part two)
    09755dc62b026 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
    a1a94a00b8844 netfilter: nf_conntrack_sip: remove net variable shadowing
    d01c913febead netfilter: nft_fib: reject fib expression on the netdev egress hook
    beeda5bf78577 netfilter: nf_tables: remove register tracking infrastructure
    1de827e24d0ad arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
    0d810ff7a6f65 arm64: dts: qcom: correct RBR opp entry
    690fb82c4122f VDUSE: avoid leaking information to userspace
    7764e9c727d58 vduse: take out allocations from vduse_dev_alloc_coherent
    db5c554b36d50 vduse: remove unused vaddr parameter of vduse_domain_free_coherent
    82e48ad2a1326 vduse: return internal vq group struct as map token
    b1f38c3ec620a xfs: don't replace the wrong part of the cow fork
    3bca70235a706 fuse-uring: fix race between registration and connection abortion
    40879c39d6740 audit: fix recursive locking deadlock in audit_dupe_exe()
    91b64f0be4163 audit: use 'unsigned int' instead of 'unsigned'
    eef6914f2b456 audit: widen ino fields to u64
    c5772ced573ea landlock: Account all audit data allocations to user space
    a95b62759f3b9 landlock: Fix formatting
    682a0066dde05 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
    81ea8e8221853 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
    337022d9dfac4 ksmbd: validate ACE size against SID sub-authorities
    f1eba60db813e ksmbd: bound DACL dedup walk to copied ACEs
    847ecd4eb3c11 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
    b6d3cc6a52441 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
    17e6b8c4319fa net: qrtr: ns: Raise node count limit to 512
    7dd26adf7e7d4 ublk: wait on ublk_dev_ready() instead of ub->completion
    5a15eaa50f92b drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
    5488d3a69d205 dm-verity: fix buffer overflow in FEC calculation
    3f31bde63f9ae dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
    d47281b9a4472 dm-verity-fec: fix reading parity bytes split across blocks (take 3)
    a556189c06756 dm-verity-fec: fix the size of dm_verity_fec_io::erasures
    22400725de070 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
    15a7cb71a5748 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
    ab7b40c638e0d drm/amd/pm: fix smu13 power limit range calculation
    6405c4e75b3bc drm/amdgpu: fix aperture mapping leak
    08fee493e0261 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
    68eab5a64ddbc drm/amdgpu: fix resource leak on ACP reset timeout
    ffb33d466a68c drm/amdgpu: fix division by zero with invalid uvd dimensions
    8c6d84a54823c drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
    bd868c077f675 drm/amdgpu/vcn4: avoid rereading IB param length
    7eebef042c12d drm/amdgpu/vce: fix integer overflow in image size
    f7e9eeaccca54 drm/amdgpu/soc24: reset dGPU if suspend got aborted
    dc3f5da1ba8e2 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
    76c977d396f12 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
    058373af59551 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
    042c047e8bc9c drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
    05aea3344c422 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
    f70bd5235d9ef drm/amdgpu/gfx8: drop unecessary BUG_ON()
    987bedd3ea89d drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
    dfd9bf09fd8fe drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
    7e22de67e545d drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
    e75f71143b68b drm/amd/pm: make pp_features read-only when scpm is enabled
    ada47af5c215e drm/amd/pm: fix amdgpu_pm_info power display units
    7b263cf1dd4c0 watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
    79370b573e92e vxlan: mdb: Fix source list corruption on a failed replace
    f60bac115d8dc vsock/virtio: collapse receive queue under memory pressure
    5f5a41a48dbf9 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
    234f9ffbd9b2c tcp: challenge ACK for non-exact RST in SYN-RECEIVED
    fadaff3f66e12 tcp: initialize standalone TCP-AO response padding
    4a4f3aa6af205 rtase: Workaround for TX hang caused by hardware packet parsing
    6866abf59976d pppoe: reload header pointer after dev_hard_header()
    460b9f0609d26 ovpn: hold peer before scheduling keepalive work
    b08526bf0bbf8 ovpn: fix peer refcount leak in TCP error paths
    100a23b1613e9 openvswitch: fix GSO userspace truncation underflow
    f80ba170d7b3a mctp: serial: handle zero-length frames to prevent rx buffer overflow
    f20dedce0429b mac802154: llsec: reject frames shorter than the authentication tag
    59c1d5463b7bc mac802154: hold an interface reference across the scan worker
    472aba2603ca7 ila: reload IPv6 header after pskb_may_pull in checksum adjust
    919d0accf2600 ice: use READ_ONCE() to access cached PHC time
    5e496f2b615ce ice: reject out-of-range ptype in ice_parser_profile_init
    91e0249f3ef62 gve: fix Rx queue stall on alloc failure
    18705cace0619 ksmbd: defer destroy_previous_session() until after NTLM authentication
    6098b55f6a0cf smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
    34f2a2f32af57 rbd: Reset positive result codes to zero in object map update path
    63d78b546eefc super: fix emergency thaw deadlock on frozen block devices
    e4406cbdd915f ice: fix PTP Call Trace during PTP release
    b3efb4744abf4 ptp: ptp_s390: Add missing facility check
    9a8a247f0f17b s390/ptff: Export ptff_function_mask[]
    4afc58ea75b96 proc: Fix broken error paths for namespace links
    4056cc19071a3 net: pcs: xpcs: fix SGMII state reading
    80d977f280b4e net: hip04: fix RX buffer leak on build_skb failure
    a4dfd46cc8f08 net: gro: fix double aggregation of flush-marked skbs
    ec6d91a1bf2eb net/x25: fix use-after-free in x25_kill_by_neigh()
    40f9a124ebbe0 net/mlx5e: Use sender devcom for MPV master-up
    900cd6d8119b7 net/iucv: fix use-after-free of a severed iucv_path
    33736ff5e7c97 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
    f8c498585d2a0 geneve: require CAP_NET_ADMIN in the device netns for changelink
    5d07b178bef51 net: slip: serialize receive against buffer reallocation
    730c7e5fea7f0 vxlan: require CAP_NET_ADMIN in the device netns for changelink
    a48a889b60f73 phonet: pep: fix use-after-free in pep_get_sb()
    03157872da5ed net: stmmac: intel: skip SerDes reconfig when rate is unchanged
    1b44a5f584bff iommu/vt-d: Disallow SVA if page walk is not coherent
    7037e7bdcd26f iomap: fix out-of-bounds bitmap_set() with zero-length range
    f139498c5ebdd io_uring/rw: fix missing ERESTARTSYS conversion in read paths
    65bf73bee1a4f ftrace: Add global mutex to serialize trace_parser access
    95376fe9c145b fscrypt: Add missing superblock check in find_or_insert_direct_key()
    a019b074903b3 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
    c78e38745ff1b fs/super: fix emergency thaw double-unlock of s_umount
    89b9121c3b016 binfmt_elf_fdpic: only honour the first PT_INTERP
    d309f8b52b34c ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
    c4d77740eca21 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
    1a644db2cf59f amt: fix use-after-free in AMT delayed works
    8f5a3abc54ba2 libceph: remove debugfs files before client teardown
    3b2f1937f5fce libceph: reject zero bucket types in crush_decode
    e67e8b694872c libceph: Reject monmaps advertising zero monitors
    0060ec912292a libceph: refresh auth->authorizer_buf{,_len} after authorizer update
    4716a64b7cc27 libceph: guard missing CRUSH type name lookup
    1732d89dfcd74 libceph: Fix multiplication overflow in decode_new_up_state_weight()
    4e7ebfaa0d14c libceph: bound get_version reply decode to front len
    7d03e08b763fd ceph: fix writeback_count leak in write_folio_nounlock()
    a7c2dfa610a12 ceph: fix refcount leak in ceph_readdir()
    a4228b93706fb ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
    3bf0e349cbb4f sctp: close UDP tunnel sockets during netns teardown
    be6aae9d1b91c sctp: avoid auth_enable sysctl UAF during netns teardown
    85aca407c560a sctp: don't free the ASCONF's own transport in DEL-IP processing
    3db217a4c2bdc mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
    ac7a6f61f56fe mm/kmemleak: fix checksum computation for per-cpu objects
    f2b2933599241 afs: Fix afs_edit_dir_remove() to get, not find, block 0
    d64f6c02495f3 mptcp: pm: userspace: fix use-after-free in get_local_id
    6cd3c3d631555 mptcp: only set DATA_FIN when a mapping is present
    6c936b5ad557e mptcp: decrement subflows counter on failed passive join
    35c4b274d4cc4 Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
    64ab0964c7db9 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
    9cd4b1a52eff3 arm64: make huge_ptep_get handled unaligned addresses
    9025946adec9a tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
    3b3be8653c594 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
    949ac1aeb37b8 tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
    6b5098d745811 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
    b6a4575f22925 tracing: Fix union collision of module and refcnt for dynamic events
    cf5a82bef623b tracing: Fix resource leak on mmiotrace trace_pipe close
    8464427e1c177 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
    1f2e7cd0ff976 tracing: Fix context switch counter truncation
    1da310b94504d misc: nsm: pin the module while the device is open
    8f068342096b0 misc: nsm: only unlock nsm_dev on post-lock error paths
    caba30eb8bd32 intel_th: fix MSC output device reference leak
    59dd34854202d mei: bus: access mei_device under device_lock on cleanup
    5118872357279 selftests: ntsync: correct CONFIG_NTSYNC name
    b2a3eeb57ba24 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
    4fae473b856b4 serial: sc16is7xx: implement gpio get_direction() callback
    635be8b097f0c uio_hv_generic: Bind to FCopy device by default
    cf26dd2d84158 comedi: comedi_parport: deal with premature interrupt
    9bb71b59e0aa3 x86/boot/compressed: Disable jump tables
    4f2db41a09eba firmware: stratix10-svc: fix memory leaks and list corruption bugs
    3ff7c1dbf722c rhashtable: clear stale iter->p on table restart
    d43c5c0c93552 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
    4427a33faabb4 LoongArch: Retrieve CPU package ID from PPTT when available
    38b025fcdc45b LoongArch: Move jump_label_init() before parse_early_param()
    6ab0abb5a2e0c LoongArch: Fix oops during single-step debugging
    a94d6726ec868 LoongArch: Fix address space mismatch in kexec command line lookup
    c404b1f30b252 objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
    8ccfb3b315a0e rust: allow `clippy::unwrap_or_default` globally
    6db0c42c87c46 rust: time: fix as_micros_ceil() to round correctly for negative Delta
    12be1d75e9b29 rust_binder: only print failure if error has source
    cc3bbff10b1a7 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
    1cd4e9b7967da binfmt_misc: set have_execfd only once the interpreter is opened
    2bc6bf70d4105 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
    780b04d09c941 Bluetooth: RFCOMM: Fix session UAF in set_termios
    a42f5536ea9c0 Bluetooth: hci_sync: Protect UUID list traversal
    91eff666c9078 staging: rtl8723bs: fix inverted HT40 secondary channel offset
    875479f18835a staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
    0dbaff14fd6a8 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
    efe9de178e4b9 wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
    044fca8f45ba9 wifi: brcmfmac: make release_scratchbuffers idempotent
    9cb72f67e1502 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
    263816e92e8d6 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
    ab4d213393e84 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
    e511e93abd6ee wifi: wilc1000: validate assoc response length before subtracting header
    9375a4ea41216 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
    18965470d41e6 wifi: ath6kl: fix use-after-free in aggr_reset_state()
    58c6c8dc2e022 wifi: ath6kl: fix OOB access from firmware ADDBA window size
    1395327a96614 ALSA: timer: don't re-enter an instance callback that is still running
    426c0ff1c433d ALSA: timer: drain a slave's callback before its master detaches it
    3bc4de57fc7d1 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
    6a10025c7fd09 ALSA: seq: close a re-opened queue timer in the destructor
    2ec8f95a08fed ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
    4091b216d11b3 media: vpif_capture: fix OF node reference imbalance
    1349af7f87df5 media: vivid: fix cleanup bugs in vivid_init()
    492c97cb50fea media: vivid: check for vb2_is_busy() when toggling caps
    26e7a8ac286f3 media: vivid: add vivid_update_reduced_fps()
    3780ad3810718 media: vimc: fix reference leak on failed device registration
    86ece01fba2d5 media: vidtv: fix reference leak on failed device registration
    16ae8c166e787 media: verisilicon: Export only needed pixels formats
    b88c929188e3c media: vb2: use ssize_t for vb2_read/vb2_write
    072a883061a46 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
    cf9732fd6c4f2 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
    3068ab802fc98 media: v4l2-ctrls: validate HEVC active reference counts
    836cfffb2ddbb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
    7e6521dd747ec media: ti: vpe: unwind v4l2 device registration on probe error
    127fc44e83256 media: tegra-video: vi: fix invalid u32 return value in format lookup
    118c2f5d1d363 media: synopsys: hdmirx: Fix HPD lane hold time
    b5184b3f0e9d4 media: sun4i-csi: Return queued buffers on start_streaming() failure
    931abe1deb65b media: stm32: dcmi: unregister notifier on probe failure
    ed342a86bb2f9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure
    b7936e8cbec1b media: saa7134: Fix a possible memory leak in saa7134_video_init1
    a7a141e4e93c8 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
    894e83509c669 media: rtl2832_sdr: Return queued buffers on start_streaming() failure
    2c71bda6edc63 media: rtl2832: fix use-after-free in rtl2832_remove()
    64cb15878b35e media: radio-si476x: Unregister v4l2_device on probe failure
    a58d01a0ed397 media: qcom: camss: Fix RDI streaming for CSID GEN3
    c39a1d9fde82b media: qcom: camss: Fix RDI streaming for CSID GEN2
    4e451100b35ee media: qcom: camss: Fix RDI streaming for CSID 680
    cb16b79a2be2c media: pwc: Return queued buffers on start_streaming() failure
    9afd605dcd96c media: pwc: Drain fill_buf on start_streaming() failure
    08ddfd628a2db media: pci: dm1105: Free allocated workqueue
    4e077bcb5e1f6 media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
    28ae75dba701d media: nxp: imx8-isi: Fix potential out-of-bounds issues
    659a7cea0be80 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
    4702afbd56f1d media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
    9e61258fbc3cf media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
    181a0aeefd56f media: nuvoton: npcm-video: fix memory leaks in probe and remove
    2147acb948a94 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
    264b5380c4f8a media: msi2500: Return queued buffers on start_streaming() failure
    1391b75bf0119 media: meson: vdec: Fix memory leak in error path of vdec_open
    18e3b838e09d7 media: marvell-cam: fix missing pci_disable_device() on remove
    cf48e9db85652 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
    d56044558a757 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
    00a98fb2a6fb2 media: imx219: Fix maximum frame length in lines
    7337c88205ed0 media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
    c68c4ce72feb6 media: cx23885: add ioremap return check and cleanup
    f468b7ee5d633 media: cx231xx: fix devres lifetime
    f24ca8b53fe15 media: chips-media: wave5: Move src_buf Removal to finish_encode
    9924cb548ee77 media: cedrus: skip invalid H.264 reference list entries
    000e51afb6068 media: cedrus: Fix missing cleanup in error path
    73504935e4365 media: cedrus: clean up media device on probe failure
    6efe665356ec8 media: cec: seco: unregister adapter on IR probe failure
    0459a4304cff8 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
    391fe3e36e59f media: amlogic-c3: Add validations for ae and awb config
    73bd277986537 media: airspy: Return queued buffers on start_streaming() failure
    a096a6aba6011 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
    a2212fef8e187 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
    6deaa31720185 drm/vc4: Prevent shader BO mappings from becoming writable
    b1379f0c42b88 drm/vmwgfx: Validate vmw_surface_metadata::array_size
    2b85e19792be4 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
    a38f2724eb93a drm/vc4: Shut down BO cache timer before teardown
    ee44ea4f7e309 drm/amd/display: Fix flip-done timeouts on mode1 reset
    ba7b6444097a7 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
    fd2de80f28a07 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
    490ceacd2162d drm/amd/display: Fix backlight max_brightness to match exported range
    9c0432044d34b drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
    51ea665c30c42 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
    0b9fa4272e24b drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
    679f23f0a3606 drm/amd/display: set new_stream to NULL after release
    123692ebc1ea7 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
    d8dc3a9e815d6 drm/amdgpu: Fix VFCT bus number matching with soft filter
    312278b309191 drm/amdgpu: Release VFCT ACPI table reference
    e64b2f1e826af drm/panthor: return error on truncated firmware
    22aa7fb4e7d0b drm/ttm: Account for NULL and handle pages in ttm_pool_backup
    b2d8b66c67393 drm/virtio: Don't detach GEM from a non-created context
    a4a1866d50c49 drm/gfx10: Program DB_RING_CONTROL
    e163c5a0946de drm/amd/pm: fix smu14 power limit range calculation
    e3bcd3bf7eeca drm/i915/mst: limit DP MST ESI service loop
    726f27bca93e6 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
    37951ce1567cc drm/i915/gem: Do not leak siblings[] on proto context error
    1173190412fb9 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
    5df5a59c32b46 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
    8b2da44446f9d drm/i915/bios: range check LFP Data Block panel_type2
    cbec6a57959ab drm/i915: Return NULL on error in active_instance
    d20b5c139b290 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
    09da54636bac1 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
    51fd520871651 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
    4c09483325360 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
    3d2ef8d389495 drm/i915/hdcp: check streams[] bounds before overflow
    1f876bd8adc79 drm/i915/hdcp: require monotonically increasing seq_num_v
    35be0e2c6862a drm/virtio: bound EDID block reads to the response buffer
    4ee77643e6194 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
    8a77ccf9cb992 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
    abce3276c57e3 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
    fd1691ec62701 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
    50319efb865f7 drm/amdkfd: Check bounds in allocate_event_notification_slot
    14a631dca9df0 drm/amdkfd: Use kvcalloc to allocate arrays
    6253bb56bb2eb drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
    c45fafa69fe3f drm/imagination: fix error checking of pvr_vm_context_lookup()
    b983a35dad370 drm/imagination: Fix user array stride in pvr_set_uobj_array()
    c88fdbf3da26e drm/imagination: Fix double call to drm_sched_entity_fini()
    c1954c66662de drm/xe: Hold a dma-buf reference for imported BOs
    038d0b80ab778 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
    90a8a938e0cae drm/xe: Return error on non-migratable faults requiring devmem
    3e1f909556aa6 drm/radeon: fix r100_copy_blit for large BOs
    fbb9effc81683 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
    45db277b2e1e3 drm/i915/gem: Add missing nospec on parallel submit slot
    748d425e53c31 drm/displayid: fix Tiled Display Topology ID size
    5452eb5c16630 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
    154795885e8f0 drm/sysfb: Avoid possible truncation with calculating visible size
    4e109faa9ea2b drm/nouveau: fix reversed error cleanup order in ucopy functions
    315d2e5741a81 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
    3fb10ec43c25a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
    9c2b01508831b drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
    f835eda74cf65 drm/sysfb: Avoid truncating maximum stride
    7daefc6d51952 drm/sysfb: Do not page-align visible size of the framebuffer
    ddba17b3dfa0e drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
    d068a2f53afc8 drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
    b3a01cda0ae16 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
    e28420e36542a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
    d5c70523cafa2 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
    e2c29d51c0f65 drm/imagination: Fit paired fragment job in the correct CCCB
    1e5827839ad0c drm/dp/mst: fix buffer overflows in sideband chunk accumulation
    533d9e2bede4a drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
    c0384d6872f4d drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
    943fa73ea0efa drm/imagination: Count paired job fence as dependency in prepare_job()
    6ab29a8683572 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
    50cd8a7e98dd2 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
    86ab4d93b3d47 drm/tidss: Fix missing drm_bridge_add() call
    300a2d970a535 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
    aa8ad3e0d1fe9 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
    786d690257ec7 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
    3a924139cf526 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
    391a23c503856 mctp: check register_netdevice_notifier() error in mctp_device_init()
    74ecebfbf1555 ptp: netc: explicitly clear TMR_OFF during initialization
    16df2d154ec82 rds: tcp: unregister sysctl before tearing down listen socket
    1db34097998cc ipv6: Change allocation flags to match rcu_read_lock section requirements
    684d4d0bda95a ice: prevent tstamp ring allocation for non-PF VSI types
    a32604e8d9e2c ice: fix LAG recipe to profile association
    3a81345467674 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
    5d54d603cf3e9 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
    e60e6009d3bae octeontx2-pf: tc: fix egress ratelimiting
    d612754a515cb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
    a7e430349fc5e net/mlx5e: Report zero bandwidth for non-ETS traffic classes
    cdddc8188db46 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
    87b39a8c875ca net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
    5f2ef3d53d374 net/mlx5: Refactor EEPROM query error handling to return status separately
    953d47cfe529a raw: annotate lockless match fields in raw_v4_match()
    8150c48fb978e net: qrtr: restrict socket creation to the initial network namespace
    0d57d43d7c4c6 hinic: remove unused ethtool RSS user configuration buffers
    8fc45a2a7cc24 ppp: annotate data races in ppp_generic
    19fe119dfa93f ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
    e037a41938c69 octeontx2-vf: set TC flower flag on MCAM entry allocation
    15a1c5f2ed2ee net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
    55515c1b1285a net: stmmac: enable the MAC on link up for all supported speeds
    1bcb737fb884d net: stmmac: reset residual action in L3L4 filters on delete
    370dde2b70e58 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
    55d2a8d184e24 net: stmmac: xgmac: fix l4 filter port overwrite on register update
    40413da850363 net: stmmac: cores: remove many xxx_SHIFT definitions
    4a3eea468a041 net: stmmac: socfpga: Add hardware supported cross-timestamp
    01d45e6b2c500 net: stmmac: socfpga: Enable TBS support for Agilex5
    dac8c2ab943a2 net: stmmac: socfpga: Agilex5 EMAC platform configuration
    d67136a931e5f net: stmmac: remove xstats.pcs_* members
    9f27c4f0ae35b bpf: tcp: fix double sock release on batch realloc
    b43bb9ab60035 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
    1b8fb5a20508b tipc: fix u16 MTU truncation in media and bearer MTU validation
    c8e4b2a567efb iomap: correct the range of a partial dirty clear
    279339aa8bdcf drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
    d18d9b2c29a12 drm/xe/i2c: Allow per domain unique id
    4fdb0f162ccdb vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
    18957373920ca sctp: auth: verify auth requirement when auth_chunk is NULL
    ae0ec759865e0 net: dpaa: fix mode setting
    b5ded444621b6 net: hsr: fix memory leak on slave unregistration by removing synced VLANs
    17bb59682b8e6 net: bridge: vlan: fix vlan range dumps starting with pvid
    0a347ca1d6a2e amt: make the head writable before rewriting the L2 header
    ca0e8b661957f amt: re-read skb header pointers after every pull
    9ec22c8113d8c ovl: check access to copy_file_range source with src mounter creds
    31f5f7c959c3e ovl: port ovl_copyfile() to cred guard
    cde234a493f6d ovl: add override_creds cleanup guard extension for overlayfs
    35f0b504394e0 cred: add scoped_with_kernel_creds()
    3139b806923b1 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
    790da254031cc ovl: fix trusted xattr escape prefix matching
    00ebbf030d8c4 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
    d5628f39fccc1 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
    95b0cf02731c7 wifi: mt76: mt7925: fix crash in reset link replay
    d14238523ca4c wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
    313343ab8cab7 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
    c058786b09cfa wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
    871549814eb4d wifi: mt76: mt7915: guard HE capability lookups
    f1ee53e08fdd2 wifi: mt76: mt7925: guard link STA in decap offload
    cc4d2f8b984c2 ppp: annotate concurrent dev->stats accesses
    b52ff80948d1c ppp: don't store tx skb in the fastpath
    cb9d3e0b55699 ppp: enable TX scatter-gather
    e740e90ca8e7f tipc: fix infinite loop in __tipc_nl_compat_dumpit
    d536bf205c71f nexthop: initialize extack in nh_res_bucket_migrate()
    961e9b1e33445 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
    023c5e0d0294a selftests: drv-net: increase timeout
    fa065685c8a91 selftests: ovpn: increase timeout
    e2b3d426c7ee5 selftests: ovpn: add IPV6 and VETH configs
    69eab5c4d9aa6 selftests: openvswitch: add config file
    340c389fd3d5d selftests: af_unix: add USER_NS config
    fbd91910c5025 tls: device: push pending open record on splice EOF
    a8bd8c109da5a net: mctp i3c: clean up notifier and buses if driver register fails
    1a10fe1aa9c01 sctp: validate stream count in sctp_process_strreset_inreq()
    c984a4184f810 pds_core: check for workqueue allocation failure
    cf0ed2ba202f5 pds_core: fix auxiliary device add/del races
    0e87fe52b560f pds_core: order completion reads after the ownership check
    3a831f40e88d3 pds_core: yield the CPU while waiting for the adminq to drain
    9e0f80fac50ab pds_core: fix use-after-free on workqueue during remove
    19ef775c91c6b pds_core: fix deadlock between reset thread and remove
    11092d79eb2b7 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
    2d34421bfa261 net: txgbe: fix FDIR filter leak on remove
    245bfe72a5ad4 net: Call net_enable_timestamp() before failure in sk_clone().
    4122792923312 soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
    f97d199287689 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
    e695cb9becbbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
    f5b8b8ccf9a4a pds_core: reject component parameter in legacy firmware update
    b5fcd1da05622 wifi: mac80211: recalculate TIM when a station enters power save
    d06fea9b85f03 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
    e5ebe8544df1a iommu/amd: Bound the early ACPI HID map
    d21464d93f8ba wifi: mwifiex: bound uAP association event IEs to the event buffer
    a0980682d84d2 vhost-net: fix TX stall when vhost owns virtio-net header
    59cbe6cfa0fa2 wan: wanxl: Only reset hardware after BAR mapping
    3b1d4fc3b73ea nfp: Check resource mutex allocation
    0f7eaeb950adb wifi: mac80211: tear down new links on vif update error path
    d053eb7e09e10 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
    76fc5604308a1 net: airoha: Fix DMA direction for NPU mailbox buffer
    f112df0744e2d dpaa2-eth: put MAC endpoint device on disconnect
    46e3bed4b0710 net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
    26ac2d3602347 dpaa2-switch: put MAC endpoint device on disconnect
    c9165e199f569 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
    b78547914bee5 gtp: parse extension headers before reading inner protocol
    9591042533140 rds: drop incoming messages that cross network namespace boundaries
    992dce02bdabb bonding: fix devconf_all NULL dereference when IPv6 is disabled
    1bc55c29cd858 net/packet: avoid fanout hook re-registration after unregister
    9f4f75df77c89 netlink: specs: rt-link: convert bridge port flag attributes to u8
    4264dbc84ca0a net: phy: marvell: fix return code
    8881daaafadbe Bluetooth: btusb: validate Realtek vendor event length
    9d208de7a8f64 regulator: mt6358: use regmap helper to read fixed LDO calibration
    538d862cc0dbd hwmon: occ: validate poll response sensor blocks
    2f0f661998941 ovpn: use monotonic clock for peer keepalive timeouts
    5b96227c0e8b2 ovpn: fix use after free in unlock_ovpn()
    47cd68e050a63 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
    c5bf6b39be235 ovpn: avoid putting unrelated P2P peer on socket release
    2fdd6d196c656 smb: client: validate DFS referral PathConsumed
    d6959dd79088a hwmon: (asus-ec-sensors) add missed handle for ENOMEM
    dd6f730be95b5 hwmon: (asus-ec-sensors) fix EC read intervals
    22e449c1dd543 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
    d5913f97b5b60 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
    d0a57f19fe286 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
    2d5dec517b539 wifi: iwlwifi: mvm: fix read in wake packet notification handler
    eae7fdf7d4469 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
    70a6de303c9b3 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
    a076b0c457c71 wifi: iwlwifi: mvm: validate SAR GEO response payload size
    cdf895bfd8035 ASoC: cs35l56: Use complete_all() to signal init_completion
    3c26e8bb14cc6 ASoC: cs35l56: Fix potential probe() deadlock
    1ddb3e0e502a1 ASoC: cs35l56: Don't use devres to unregister component
    9153fa1ee99bf ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
    08433c71f1598 ALSA: hda: cs35l41: validate and free ACPI mute object
    eca9fcf9f5d89 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
    41ae2b7d37c3d ASoC: tas2781: bound firmware description string parsing
    797dc567146c7 btrfs: free mapping node on duplicate reloc root insert
    9304713b70e7e btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
    39f196f64bd38 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
    f49ff44831d52 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
    4503829843353 wifi: carl9170: fix buffer overflow in rx_stream failover path
    fab6ff91d5b8c wifi: carl9170: fix OOB read from off-by-two in TX status handler
    9aee949c68dc6 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
    33b5342d20806 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
    eb636fbc44314 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
    0177e578d7a88 firewire: net: Fix fragmented datagram reassembly
    51516fda914cc wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
    9a9b0ea72d8b9 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
    a154ca3c441a6 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
    8681e5addf717 watchdog: airoha: Prevent division by zero when clock frequency is zero
    7d1658b066de3 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
    305c23993e43d hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
    205cff797a947 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
    f36e12cc8cfe9 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
    56d2deb644837 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
    ec477af3a7e8d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
    e5394605f9a98 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
    48a69cedde738 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
    593072aae7fc8 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
    938bcf99f53e8 selftests/bpf: Adjust verifier_map_ptr for the map's excl field
    fe7892d46921e usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
    958624d638603 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
    03eb7a8099474 RISC-V: KVM: Serialize virtual interrupt pending state updates
    731acda5ba777 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
    0905b3ce1deb7 usb: typec: ucsi: Add duplicate detection to nvidia registration path
    fe8cde072293c usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
    67d2626827e3c USB: serial: option: add TDTECH MT5710-CN
    601f75671b8fb USB: serial: keyspan_pda: fix data loss on receive throttling
    cbe00048b69d6 USB: serial: io_edgeport: cap received transmit credits
    c1611c6744e3a USB: serial: ftdi_sio: add support for E+H FXA291
    1f03658f3e9b2 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
    dcf3e2f164435 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
    40c706a0224bd usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
    12b3edca90d4d USB: gadget: fsl-udc: fix dev_printk() device
    66956a5a4258c USB: gadget: fsl-udc: fix device name leak on probe failure
    e5ecfb7767526 USB: gadget: snps-udc: fix device name leak on probe failure
    4cde0b38cc0cb usb: gadget: printer: fix infinite loop in printer_read()
    f45089eaad0a0 usb: gadget: f_midi: cancel pending IN work before freeing the midi object
    e239ea91b4818 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
    ace1a0adfc786 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
    8eca14198c202 USB: storage: add NO_ATA_1X quirk for Longmai USB Key
    0950ac52426b0 usb: musb: omap2430: Do not put borrowed of_node in probe
    7714fb896ed30 usb: core: port: Deattach Type-C connector on component unbind
    fb1b50ab69921 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
    217774e143d7b usb: core: sysfs: add lock to bos_descriptors_read()
    5f6e7b32bd1fb mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
    a8d20ba0ab518 sctp: fix auth_hmacs array size in struct sctp_cookie
    fed1b1ddab41a net/sched: act_tunnel_key: Defer dst_release to RCU callback
    51c2fcc4cd2e4 dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
    e666af5dcc905 tcp: fix TIME_WAIT socket reference leak on PSP policy failure
    6875ee2bef48f accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
    f6b522033bc83 drm/i915/selftests: Fix GT PM sort comparators
    c23abdb922c39 drm/i915/wm: clear the plane ddb_y entries on plane disable
    f0e337e7db67c ksmbd: validate compound request size before reading StructureSize2
    6ecb252efa0b4 ksmbd: pin conn during async oplock break notification
    5e5f298d0af64 drm/xe/wopcm: fix WOPCM size for LNL+
    35ba43b541117 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
    c1b19d8556265 drm/xe/vf: Shadow buffer management for CCS read/write operations
    bf293b5bcff41 drm/xe/sa: Shadow buffer support in the sub-allocator pool
    65129a03a8018 drm/xe: Allow the caller to pass guc_buf_cache size
    cfb66ad4aa8e5 can: j1939: fix lockless local-destination check
    3f398d45f3c75 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
    1d9a2f01b3c4e s390/checksum: Fix csum_partial() without vector facility
    5b06cf93341fe drm/panthor: Check debugfs GEM lock initialization
    250474c69bc3f bpf, sockmap: Reject unhashed UDP sockets on sockmap update
    c3e61df6fabca powerpc/vtime: Initialize starttime at boot for native accounting
    5c3a1cede86fd powerpc/time: Prepare to stop elapsing in dynticks-idle
    c1bbd0a6906b8 powerpc/85xx: Add fsl,ifc to common device ids
    00ba4bf879824 can: raw: add locking for raw flags bitfield
    479425744b219 drm/i915/gt: use correct selftest config symbol
    7e08ab7a061b1 smb/client: handle overlapping allocated ranges in fallocate
    cefb44c367b2b Bluetooth: hci_qca: Clear memdump state on invalid dump size
    d5b3b484b62bb Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
    ca58ad287bfc5 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
    83b7e67698d0b Bluetooth: hci_sync: extend conn_hash lookup critical sections
    57059ff14d81d Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
    a087ed960fce5 Bluetooth: qca: fix NVM tag length underflow in TLV parser
    f4e23e661a259 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
    b133f007ba02c accel/ivpu: Fix wrong register read in LNL failure diagnostics
    1842d45f461a7 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
    d28920db56960 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
    678d874e6ae11 ata: sata_dwc_460ex: use platform_get_irq()
    daa80b422ed92 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
    c7a1509123720 scsi: core: wake eh reliably when using scsi_schedule_eh
    2c77ed279c4bb udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
    c75a950e77356 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
    cb8be318b4432 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
    c9574b8a8edeb ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
    88f87cb4b52ed cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
    640a33e77f91b firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
    fb343716fad46 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
    7f2cb99eaf53c ASoC: cs42l43: Correct report for forced microphone jack
    9f393d8160435 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
    3b2d32f528152 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
    f33ad19e3e3d6 ASoC: amd: ps: disable MSI on resume in ACP PCI driver
    4801f6690f984 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
    b39b08e6bee81 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
    cf5708c9d78c9 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
    11ac7a5e75f51 wifi: cfg80211: bound element ID read when checking non-inheritance
    5c342437ea44b wifi: brcmfmac: initialize SDIO data work before cleanup
    a424985c3ef2a wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
    44eda4a8d1dcd wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
    fbaa8c31ef940 wifi: cfg80211: reject unsupported PMSR FTM location requests
    cfbda103aeae6 wifi: cfg80211: validate PMSR FTM preamble range
    0caf6416bfbb3 wifi: cfg80211: validate PMSR measurement type data
    0b6efde0ed970 wifi: nl80211: constrain MBSSID TX link ID range
    f8c547e543e12 wifi: nl80211: validate nested MBSSID IE blobs
    f649dc9c5e657 wifi: cfg80211: derive S1G beacon TSF from S1G fields
    fb052a6e2fa86 wifi: nl80211: free RNR data on MBSSID mismatch
    133684982dd0c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
    d38f5d868a0a4 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
    2aa1789880fa5 wifi: mac80211: defer link RX stats percpu free to RCU
    6cda91bbb8dc3 wifi: libertas: fix memory leak in helper_firmware_cb()
    5baaa1042f71d wifi: mac80211: fix fils_discovery double free on alloc failure
    d62b55b7c7dc6 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
    6dc76371a9a36 wifi: mac80211_hwsim: clamp virtio RX length before skb_put
    e67dc2b8d5ac4 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
    f442e581a8893 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
    9293574ac208d wifi: cfg80211: cancel sched scan results work on unregister
    7acc5ed2f3360 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
    ff636d7b7cba6 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
    d8aaf06b29f5a xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
    9845a35986a65 xfrm: clear mode callbacks after failed mode setup
    9e632a70f2044 RDMA/irdma: Prevent overflows in memory contiguity checks
    124382a2a9756 selftests/alsa: Fix memory leak in find_controls error path
    f98ae09c727dc mtd: fix double free and WARN_ON in add_mtd_device() error paths
    fcc9d50022bcd RDMA/siw: publish QP after initialization
    e221dde026af2 RDMA/hns: Fix potential integer overflow in mhop hem cleanup
    d842ef03d9145 RDMA/mana_ib: initialize err for empty send WR lists
    14e519f93a48c RDMA/erdma: initialize ret for empty receive WR lists
    ec675b4cdfd37 RDMA/irdma: Prevent user-triggered null deref on QP create
    1cd56258fe1a0 RDMA/irdma: Remove redundant legacy_mode checks
    ca1c29f05274b RDMA/irdma: Prevent rereg_mr for non-mem regions
    dbb945b80a3a4 RDMA/umem: Add pinned revocable dmabuf import interface
    c4ef25de94d73 RDMA/cma: Fix hardware address comparison length in netevent callback
    d7fc6f351c478 xfrm: reject optional IPTFS templates in outbound policies
    2907e9d0f05b5 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
    57acd51928333 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next
    996c5c19d5b5a firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
    8edc925251780 btrfs: fallback to transaction csum tree on a commit root csum miss
    a84ca16ce07e7 btrfs: use bool type for btrfs_path members used as booleans
    60a23d4ea169e btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
    5e1b2ca6b3493 btrfs: reject free space cache with more entries than pages
    0ac9c7d9ccfd7 mtd: nand: mtk-ecc: stop on ECC idle timeouts
    fdb53a9b26071 mtd: mtdswap: remove debugfs stats file on teardown
    98d2d468b4faa IB/mad: Drop unmatched RMPP responses before reassembly
    59114e0ff6e3a firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
    33e1b0d25ca0d xfrm: fix stale skb->prev after async crypto steals a GSO segment
    eae16fbc7ce20 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
    23bbb9eafec7a net: plumb drop reasons to __dev_queue_xmit()
    4cc4d6fb08e75 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT
    4c22b4e3ff502 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
    0b9858484d096 arm64: tegra: Remove fallback compatible for GPCDMA
    903f2edc04770 fuse: fix writeback array overflow when max_pages is one
    afe9cda0862aa Input: ims-pcu - fix logic error in packet reset
    d03a740e087de Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
    6cbed4be9a6ca xprtrdma: Clear receive-side ownership pointers on release
    0892b427c4b8b crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
    5f4de3c717d34 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
    ec9f66c91bffd dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
    eca8b44d51fc6 can: bcm: track a single source interface for ANYDEV timeout/throttle ops
    136de17f38630 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
    6be3e1fedf03e can: bcm: fix stale rx/tx ops after device removal
    b024c21c9066f can: bcm: add missing device refcount for CAN filter removal
    deb6a697cce3f can: bcm: validate frame length in bcm_rx_setup() for RTR replies
    bd46f55dec608 can: bcm: extend bcm_tx_lock usage for data and timer updates
    8104bcdb2612f can: bcm: fix CAN frame rx/tx statistics
    19b1994069dd2 can: bcm: add locking when updating filter and timer values
    ec9daa8fd1b6f KVM: x86/mmu: Fix use-after-free on vendor module reload
    8001d2ce9d9bd KVM: nVMX: Hide shadow VMCS right after VMCLEAR
    dd50ad7935d57 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
    f3477a6a4164f KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
    865dfe76c150b seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
    3958b1aeef43b seqlock: Allow KASAN to fail optimizing
    ec46baf830825 seqlock: Cure some more scoped_seqlock() optimization fails
    8e39ed92d7c5c fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
    89890a5fcefad drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
    f6410d18c1e2d netfilter: nf_tables: revert commit_mutex usage in reset path
    0c8a9022f4c56 netfilter: nft_quota: use atomic64_xchg for reset
    cd968dcdec6ae netfilter: nft_counter: serialize reset with spinlock
    55904f1a4689a selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
    ce01a4e5cfac7 bpf: Fix ld_{abs,ind} failure path analysis in subprogs
    bffc0b27e457c platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 24905528a09e7a6b2df9cba342b5f9ba6b8bcf3e)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.18.bb              |  6 ++---
 .../linux/linux-yocto-tiny_6.18.bb            |  6 ++---
 meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
 3 files changed, 18 insertions(+), 18 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index 37570538857..edb3696b25e 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 5addcaae07e..894267acdf1 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
 include recipes-kernel/linux/cve-exclusion.inc
 include recipes-kernel/linux/cve-exclusion_6.18.inc
 
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 3ceba003fa4..e510ff01aaf 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.18/standard/base"
 KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
 
-SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8"
-SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697"
+SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
 SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
 SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50"
+SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.18/base"
 
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
                   ` (34 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:

    1efe5d048a391 Linux 6.18.44
    358b5dcf1fd7f drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
    e7731507270c2 drm/fb-helper: Fix a locking bug in an error path
    7bc7af179916b usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
    10be509fa8fd9 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
    0902f06a6c0bb can: use skb hash instead of private variable in headroom
    157b1e3384d7d drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
    b1a71151317c4 drm/xe: Add page reclamation info to device info
    6107b64cfccef drm/xe: Stub out new pagefault layer
    184de3d31f728 drm/xe: Use SVM range helpers in PT layer
    df1582c0a101e drm/i915/vrr: require valid min/max vfreq for VRR
    894d4a7395662 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
    21976fe525849 drm/xe: Wait on external BO kernel fences in exec IOCTL
    b8ad916ba4e18 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
    d256dac008d1d drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
    8fa8b0a463729 drm/xe/vm: Prevent binding of purged buffer objects
    1ba553ee0b521 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
    0015b054b06d3 drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
    005b9b4431606 drm/xe/pat: Add helper to query compression enable status
    3cb42a973f889 drm/amd/display: Exit idle optimizations before programming
    dbbe08d73b8bc drm/amd/display: check GRPH_FLIP status before sending event
    b485bfb455551 drm/xe/guc: Fix buffer overflow in steered register list allocation
    30b2d0843a410 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
    e06c39cc1c48d drm/amdgpu: Fix context pstate override handling
    4d49ca777cf1a drm/tegra: fbdev: Remove offset into framebuffer memory
    3f58077457985 drm/fb-helper: Allocate and release fb_info in single place
    165613191ad9d userfaultfd: prevent registration of special VMAs
    02d378828af8b wifi: brcmfmac: drain bus_reset work on device removal
    d6f322d68abfd media: uapi: rkisp: Correct name version enum
    5c6d5d2484cab media: qcom: camss: Fix RDI streaming for CSID 340
    f730ee0ef8fac media: qcom: camss: csid-340: Fix unused variables
    276420a86e75f media: chips-media: wave5: Support CBP profile
    3f7b3728dd901 usb: typec: ucsi: Fix race condition and ordering in port unregistration
    58d9caa64f9c6 usb: typec: ucsi: split connector lock classes
    2bf24a7e190aa net/handshake: Drain pending requests at net namespace exit
    6e7b52bd13948 net/handshake: Close the submit-side sock_hold race
    68eba6519cbd6 net/handshake: hand off the pinned file reference to accept_doit
    b913801ad9b9a net/handshake: Take a long-lived file reference at submit
    5ddfc47e1228d net/handshake: Fix null-ptr-deref in handshake_complete()
    97e745b4ea055 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE()
    f00dd592abe77 file: ensure cleanup
    10827847c40c1 file: add FD_{ADD,PREPARE}()
    10065fb891651 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
    be11b4bf498a3 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
    2b9a07002c2f2 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
    fc0c76b0450f2 drm/xe/rtp: Ensure locking/ref counting for OA whitelists
    9783d8662b565 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
    f5966d9006623 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
    d43abc858f082 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
    c2cfee9bf8d46 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
    4bb92418e749f drm/xe/rtp: Generalize whitelist_apply_to_hwe
    cc716d3ac560f drm/xe/rtp: Keep track of non-OA nonpriv slots
    f73e97080debd drm/xe/rtp: Maintain OA whitelists separately
    7982678fa21ed drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
    542d3b9fa8ec6 drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting
    2b70bebc70948 HID: logitech-dj: Fix maxfield check in DJ short report validation
    6be3dbe45b287 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX
    042ca38779554 drm/vmwgfx: validate external BO copy bounds for both stride paths
    cfd163169af3b drm/vmwgfx: use check_add_overflow for shader size+offset bound
    1eb4f796695be drm/vmwgfx: enforce cursor size limits for MOB cursors
    96efee36453b6 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
    7e40e6120fb23 drm/vmwgfx: bound DMA command body size against suffix pointer
    dc0be7662b7b0 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
    a8434b145b1e4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
    b79e82ea18236 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
    10460699c312e drm/vmwgfx: clamp dirty-page range with min, not max
    e479240a1e076 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
    282f261cb035e drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
    6a52f48157fa7 drm/amdkfd: hold event_mutex while checkpointing CRIU events
    6189ceca5ce75 drm/amdkfd: Handle invalid event type in CRIU event restore
    6dc0b4b39ed4f drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
    5f0f2ddeac738 drm/amdkfd: fix QID bit leak in pqm_create_queue()
    9e52212aff8ed drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
    02647d9834073 drm/amd/display: use proper context for logging
    3c2ae9509717c drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
    1860818feb4db drm/amd/pm: fix torn gpu metrics reads
    45ba7f091abf4 drm/amdgpu: cap GTT size to physical RAM on APUs
    d330ac90d85f3 drm/amdgpu: restore UMD profile pstate after runtime resume
    18d21c9d04b00 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
    0f1ff05c58e17 drm/mediatek: ovl_adaptor: balance component registrations
    c835f2b0b7167 drm/panthor: validate firmware interface structure sizes
    2a761b9be5863 drm/panthor: reject firmware sections with oversized data
    da898bb6faf32 drm/bridge: display-connector: Fix I2C adapter resource leak
    57667eb7548fa drm/vc4: Zero the tile state data array before each BIN job
    6cd5acf6f87c0 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
    58d2bb394e884 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
    e8b797940536c can: ctucanfd: mark error-active controller status valid
    7d1619f56a75a can: ctucanfd: handle bus error interrupts
    46fc5aecde5cd can: ctucanfd: unmap BAR0 using base address
    cae2880f8ffae can: ctucanfd: use self-test mode for PRESUME_ACK
    aa5e790bf185e can: ctucanfd: add missing MODULE_DEVICE_TABLE()
    2427ef427bdd7 can: peak_usb: validate uCAN receive record lengths
    92d0de80ca222 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
    1acab790b7cec can: peak_usb: add bounds check for USB channel index
    2ee477e541a6d can: softing: fw_parse(): validate firmware record spans
    185cb1fa38142 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
    2e90b2b406077 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
    54258ea8d61fc can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
    8604a3b81b9d0 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
    996eb21acdc9c can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
    c311f17c261fd can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
    0b23144c59c12 can: ems_usb: validate CPC message lengths
    26cf99713a96f can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
    affd62f5719a7 i2c: imx: Cancel hrtimer before clearing slave pointer
    12a4f0950a158 i2c: imx: Fix slave registration race and error handling
    7a5db225ab5a6 i2c: imx: mark I2C adapter when hardware is powered down
    82233ff0e36df i2c: iproc: reset bus after timeout if START_BUSY is stuck
    19b783335d62e i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
    40dd717445998 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
    d9b5419df0654 i2c: spacemit: request IRQ after controller initialization
    6a5cc2b4e6faf ice: fix memory leak in ice_lbtest_prepare_rings()
    326c89ea2685a ice: fix VF interrupts cleanup
    7e8789f5b5d8a ice: wait for reset completion in ice_resume()
    e0ba8eaef2a0d net: openvswitch: fix skb leak on flow key update failure during ct
    9c7246cc509fd net: openvswitch: fix skb leak on flow key update failure during recirculation
    90623c9499627 net: openvswitch: fix potential UAF on meter attach failure
    74b30e7ef4618 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
    79a312664118f phy: zynqmp: use read-modify-write for SERDES scrambler bypass
    4211450f0fecb phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
    013a4484f061a s390/zcrypt: Validate length for CCA ECC private key requests
    ad93a1f1a4565 s390/zcrypt: Validate length for CCA AES cipher key requests
    fbb0410986e8a s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
    a57fd7fcdb63e s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
    672b12940e3f1 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
    e16e0fc54120c s390/dasd: Fix undersized format-check buffer
    86cdfd061509b s390/dasd: Fix potential NULL pointer dereference
    bd63c7879eaa8 s390/qeth: Check CAP_NET_ADMIN for private ioctls
    ef1aa7cfb8c63 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
    b039f13e095d2 power: supply: max17040: handle missing status supplier
    6d89f33a64675 power: supply: bq25890: fix the -10 C NTC lookup entry
    63d6c855b27df cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
    437b38a08c0a8 cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
    efbcecdecefc2 cifs: add fscache_resize_cookie() to cifs_setsize()
    466ab0c41d5f5 gpio: pch: use raw_spinlock_t for the register lock
    2e4bc8422cdee gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
    1883a09a37fed i2c: amd-mp2: Unregister callback on adapter add failure
    7a91d07939e07 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
    30ae663746378 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
    4ba5bf7ed50f2 sctp: prevent peer transport count overflow
    a0d1693923f41 sctp: reject stale cookies with mismatched verification tags
    2047ed09bf134 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
    5b4d4d5a29f92 selftests/clone3: fix wild pointer access of getline due to missing init
    a0bc578641d74 selftests/mm: fix potential wild pointer access of getline due to missing init
    2e047b4171de4 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
    581e5166f0780 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
    c26a6477e149c tracing/filters: Fix false positive match in regex_match_full()
    cbb5ed3be9cae tracing: Check return value of __register_event() in trace_module_add_events()
    205feb72e5beb ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
    ee799977d7941 vxlan: use pskb_network_may_pull() in route_shortcircuit()
    94dee751aad62 vxlan: use pskb_network_may_pull() for transmit path header pulls
    ff89415d34c3a vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    adeed09eeb3b6 vxlan: unclone skb head before modifying eth header in route_shortcircuit()
    1235e017aa11c vxlan: re-fetch eth header after route_shortcircuit()
    b24ba0bbffe3e veth: convert frag_list skbs before running XDP
    3bd35a5e272a1 uprobes: Fix NULL pointer dereference in hprobe_expire()
    180ff4c81faf0 um: vector: fix use-after-free in vector_mmsg_rx()
    e4b98f9778dfc powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
    4ef801b838d85 net: pktgen: fix proc entry use-after-free
    dc3ab04220667 net: ipv6: clear suppressed fib6 rule result
    0309ebbc57000 net: bridge: stop fast-leave after deleting a port group
    332a546b4ee56 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
    b11907c905fa0 mm/page_reporting: use system_freezable_wq to fix UAF during suspend
    63b361f228866 io_uring/net: initialize mshot_len for send
    4dad8ca637d44 binfmt_misc: don't let an 'F' entry pin its own instance
    840bb9c49c3e7 binfmt_misc: reject a flag character as the field delimiter
    255a758697da8 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
    fdc1d702bf300 binfmt_misc: restore write access when removing an entry
    c9dcfe6b8b713 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
    bed792737b5f1 tipc: avoid use-after-free in poll trace queue dumps
    88752b811f72a of/address: Fix NULL bus dereference in of_pci_range_parser_one()
    4ae701848e4ba netfilter: ipset: do not update comments from kernel-side hash adds
    f807a63d0d956 net/smc: fix socket use-after-free during link group termination
    2060764e0f46c mshv: fix hv_input_get_system_property struct
    a60b5da05e318 ksmbd: reject repeated SMB2 NEGOTIATE requests
    b5ee5b266f833 ipvs: do not propagate one-packet flag to synced conns
    3b5aee6fcbf6b igc: remove napi_synchronize() in igc_down()
    845a9cdd9b03b igbvf: Fix leak in TX DMA error cleanup
    b10bb77e91e97 e1000: fix memory leak in e1000_probe()
    b0bdca3a49cf3 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
    2db4535d6af79 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
    04595233e5606 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
    b5305a0d0bb8e ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
    7ba01e0d3539d ALSA: usb-audio: fix stack info leak in RME Digiface status
    cc014ebf80317 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
    79f8720029f26 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
    9562ddbc6ed8f ata: libata-eh: Increase STANDBY IMMEDIATE timeout
    0a02b0c878071 ASoC: tas2562: fix broken entries in the volume lookup table
    35d5f1852e390 ASoC: tas2562: fix DVC coefficient write order
    cac7d2066b2f0 ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
    6df5b32881602 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
    032746c2dd9a4 ALSA: ump: fix double free of out_cvts on rawmidi error
    a26a2e52736f9 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
    5260e195c53e8 ALSA: seq: Fix division by zero in initialize_timer()
    2940cc3cf43c7 ALSA: pcm: wake linked drain waiters on unlink
    4969533a1b950 ALSA: lx6464es: fix period byte count for 16-bit streams
    7484669d1fbab ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
    11e2953d9f4c7 ALSA: 6fire: Fix UAF at error handling during probe
    c0d3b81f703b2 afs: Fix UAF when sending a message
    d703f022a28a2 afs: Fix afs_fs_fetch_data() to subtract transferred from len
    b53face003b4d afs: Fix afs_fs_fetch_data() to set call->async
    5c7fdcbecbab2 bpf: lwt: Fix dst reference leak on reroute failure
    27cc0e603355c Bluetooth: HIDP: validate numbered report payloads
    2ebf63aa557a6 Bluetooth: HIDP: reject frames without a transaction header
    eb1d8318764de Bluetooth: hci_sync: Fix advertising data UAFs
    c569def320aa8 Bluetooth: mgmt: fix UAF in pair command cancellation
    a33bc07b4730b Bluetooth: SCO: give the socket its own sco_conn reference
    814f82f432dc6 Bluetooth: mgmt: fix pending command UAF in EIR updates
    6936b367ee6d4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
    f14d41dbc2fdf Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
    cae0dfed5d307 audit: fix potential use-after-free in audit_del_rule()
    185c784c98094 audit: fix potential integer overflow in audit_log_n_string()
    17b412468c7a4 sctp: validate Adaptation Indication parameter length
    c0837aeace961 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
    b878ba7e28144 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
    e137d082325bb KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
    1abf9ce39a862 KVM: s390: pci: Fix missing error codes and memory unaccounting
    70871b121f81d KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
    6837f0ae85fd5 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
    7668c58dcf465 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
    5acc92947baa2 KVM: VMX: add memory clobber to asm for VMX instructions
    e768ea3a422d1 tracing/fprobe: Roll back on enable_trace_fprobe() failure
    3b2e08e0ede72 tracing/probes: Reject $arg0 in meta argument expansion
    e0fa737783b5b mm/vmstat: fold stranded per-cpu node stats when a node comes online
    126a70bf1a08d mm/hugetlb: fix list corruption in allocate_file_region_entries()
    32134cf9211b8 mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
    7d3e1d3a0dce9 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
    c091462e46f75 selftest: fix headers in fclog.c
    9668ffe0e2a5e mm/util: don't read __page_2 for order-1 folios in snapshot_page()
    2be94d6b20789 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
    2205263b1e013 fortify: Disable -Wstringop-overread in tests
    96b0aa79b0e1e pinctrl: bm1880: add missing select GENERIC_PINCONF
    5aaa06dfc10f8 erofs: cap LZMA stream pool size
    ad0ad3c228b6f pinctrl: devicetree: don't free uninitialized dev_name on error path
    93d934668047f pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
    6da8f37419dd4 iommu/iommufd: Fix IOPF group ownership UAF
    564ac339c0f8b iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
    ee2212b482320 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
    294b464b2be7e iommufd/viommu: Release the igroup lock on the vdevice_size error path
    062aa5dcc49a9 mshv: Order pt_vp_array publish against irqfd assertion path
    f50f5d3972da0 mshv: Fix level-triggered check on uninitialized data
    fc362bfcb060e mshv: adjust interrupt control structure for ARM64
    72a90ce4918b5 mshv: Fix race in mshv_irqfd_deassign
    cfc686a1174aa iomap: add a separate bio_set for iomap_split_ioend
    9be4a66f019ea ksmbd: fix use-after-free in __close_file_table_ids()
    213b4568f6e5d ksmbd: return success for deferred final close
    cebba11df714b drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
    e51becb8f3377 qede: sync udp_tunnel ports outside qede_lock in the recovery path
    51c52e493346f spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
    caeaaf23f7c36 sched/deadline: Use revised wakeup rule only for running dl_server
    5a73e8c632c31 octeontx2-pf: Set correct sequence for carrier off and tx queue stop
    b90916156b472 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
    6bf322ab07418 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
    1e0dfb7e7a5d9 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
    fd9586881d478 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
    54e07a158f7ae riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
    b297559dc2f29 accel/qaic: use sizeof(*trans_hdr) for transaction length check
    01bd01b61ad9e riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
    a20a0010eb648 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
    9b604041f1009 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
    fc97dcb42fb46 fprobe: Fix module reference count leak on error in register_fprobe()
    84b5aa55de7c8 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
    50edffd0854fe can: isotp: check register_netdevice_notifier() error in module init
    b4f8c33593f25 net: sxgbe: check descriptor ring allocation failures
    42b87cfd9666e net: sxgbe: free TX rings on RX allocation failure
    69a258a5a322e scsi: target: Clear cmd_cnt when initial counter enrollment fails
    54c6fb24c6021 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
    ff333def31476 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
    c249cfe1d8df2 scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
    e504204489993 scsi: ufs: core: Cancel RTC work in active-active suspend
    bdd8a1297ef10 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
    613aaeeaf8cb1 net: phylink: put link_gpio if phylink_create fails
    5ea70ad040c1b x86/boot: Add volatile, clobbers and zero-length test in memcmp()
    5576afebf726c Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
    e8f9fef362bab Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
    de17305393ec8 Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
    c618a9a5b08ea Bluetooth: btintel: Validate length before parsing diagnostics TLV
    3b921533e8aa9 Bluetooth: ISO: fix refcounting of iso_conn
    e941799c31f68 Bluetooth: ISO: ensure no dangling hcon references in iso_conn
    82e982f54f962 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
    e76a0ae6542ae Bluetooth: ISO: fix leaking sk after socket release
    4e9b5e8669b36 Bluetooth: ISO: hold sk properly in iso_conn_ready
    09a69828ae594 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
    cde36776cfe64 Bluetooth: ISO: Fix not updating BIS sender source address
    dfce8d30fc5be Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
    1fc2132950c23 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
    e8e9cff6d80ee Bluetooth: ISO: lock sk in iso_connect_ind
    3120664aa3330 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths
    f1f167991a68f Bluetooth: HCI: Add initial support for PAST
    72d5bb1d77d7c Bluetooth: ISO: lock sk in iso_sock_getname
    58e3c5289ad23 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
    63c0f396a18b7 Bluetooth: ISO: clear iso_data always when detaching conn from hcon
    4e1f45de5b313 ice: suppress DPLL errors during reset recovery
    6ebbf198e76ca idpf: Fix mailbox IRQ name leak on request failure
    d44081c61dc92 idpf: adjust TxQ ring count minimum
    ae7120102e1bb hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
    276f1f180f55d net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
    2c148a31ca01f netfs: release readahead folios on iterator preparation failure
    291ebecdf315d netfs: handle single writeback rolling buffer allocation failure
    627826ef42080 netfs: clear PG_private_2 on copy-to-cache append failure
    b558e07708d88 wifi: mac80211: validate individual TWT params before driver setup
    f82a2ded3d7a9 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
    acbf711a20669 powerpc/boot: Fix treeboot-akebono CPU node lookup check
    b407b98cf665d powerpc/boot: Fix treeboot-currituck CPU node lookup check
    3d24f2e5641b2 powerpc/boot: Fix simpleboot CPU node lookup check
    db986098f3088 rtase: fix double free of multi-frag skb on DMA map failure
    5a6b0ccb8b018 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
    96ad57d317635 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
    ddd689bd72264 hwmon: (adt7470) Use cached PWM frequency value
    1d6b54dbe8850 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
    d5d4034bb6f6e hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
    82d65f7ef11ed hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
    3e06ff0c79ea3 hwmon: (adt7470) Fix cache updated before hardware write on I2C error
    28548ecc2b458 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
    ae20a8a4de06a forcedeth: fix UAF of txrx_stats in nv_remove
    2e0c6761c0553 net: bridge: mrp: fix Option TLV length in MRP_Test frames
    1b722740ac5c2 hwmon: (nct6775-core) Prevent access to unsupported weight registers
    5ec5f00fc606a net: do not send ICMP/NDISC Redirects when peer allocation fails
    2332d35aaf206 hwmon: (nzxt-smart2) DMA-align output buffer
    075fce376cf85 hwmon: (lm90) Only report alarms if driver is ready
    c498adfd4c3e8 hwmon: (sht3x) Fix unaligned accesses
    08aee6d45eefc hwmon: (ltc4282) Fix reading the minimum alarm voltage
    b60e8486c04de hwmon: (ina2xx) Fix various overflow issues
    e627f4ad9eea2 hwmon: (ina2xx) Shift INA234 shunt and current registers
    fdfde077e025c hwmon: (ina2xx) Add support for INA234
    8da94361f9ae1 hwmon: (ina2xx) Make it easier to add more devices
    a42d727dae570 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
    e28d478c003d7 spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
    d3337eefab626 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32
    fcc3d77fef02c ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
    b2851429afc5b smb: client: fix buffer leaks in SMB1 read and write
    9e24b47ef81d4 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
    72815741715bd scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
    3ef209ca0b4b6 scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
    8e0996418590b pinctrl-amd: Don't clear S4 wake bits at probe
    ceb00cb87a22c xsk: drain continuation descs after overflow in xsk_build_skb()
    411554cb868b8 xsk: use a smaller new lock for shared pool case
    05e283466b86e xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
    814c5b1590037 selftests/net/af_unix: test listen() rejects wrong socket states
    643ec3e24a490 selftest: af_unix: Create its own .gitignore.
    0372a52191127 selftests: af_unix: Add tests for ECONNRESET and EOF semantics
    5c170577049f9 af_unix: fix listen() succeeding on sockets in the wrong state
    b1d480fce05f8 rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
    f6787fdffcae5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
    4147866087fbe ASoC: SDCA: Ensure that Control Range is large enough for header
    16b553c46e347 netfilter: nft_payload: fix mask build for partial field offload
    e6f4b4b40db87 ipvs: do not mangle ICMP replies for non-first fragments
    ce96c40a049be ipvs: fix places with wrong packet offsets
    00eb23829fd08 ipvs: fix the checksum validations
    d186f77d18bdf netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
    63ba12b664a2c netfilter: nf_tables: make nft_object rhltable per table
    adf1a3ba27ad1 assoc_array: trim the final shortcut word using the current chunk end
    3d9f16c0b643c keys: make keyring key-chunk byte order agree with keyring_diff_objects()
    e9417d21a22ad keys: fix out-of-bounds read in keyring_get_key_chunk()
    6469ad3005087 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
    31d491f9da948 KVM: arm64: Reject guest_memfd memslots when the VM has MTE
    db1c4a8e9080f mshv: Fix sleeping under spinlock in mshv_portid_alloc
    a920ead0bc2f1 mshv: Fix duplicate GSI detection for GSI 0
    b215cb70e14c7 Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
    d397787dbc4bf Drivers: hv: Allocate the paravisor SynIC pages when required
    74d20e3cf88e4 Drivers: hv: Rename fields for SynIC message and event pages
    82cdbb6155a2c arch/x86: mshyperv: Discover Confidential VMBus availability
    6e70eba930a24 drm/mediatek: Check CRTC state before freeing
    f74554e67ccf0 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
    ec81ecd2ac093 phy: zynqmp: fix runtime PM leak on probe allocation failure
    86fb88ac8c915 phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
    dff474e723ede btrfs: raid56: fix an incorrect csum skip during scrub
    4d4ef6627304a btrfs: zoned: reset meta_write_pointer on zone reset
    deddd28fd83c2 btrfs: zoned: fix deadlock between metadata writeback and transaction commit
    762561c438599 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
    cfa7e27348773 of: reserved_mem: prevent OOB when too many dynamic regions are defined
    f5edba9bc69d0 ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
    3cbfb9b886dc1 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
    3fd94b9ffe997 phy: qcom: m31-eusb2: Fix return value of init call
    9355f526c821f ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
    a0f288ebe6d8a ata: sata_mv: accept 1 or 2 resources in platform probe
    8229a53888540 selftests/seccomp: Fix pointer type mismatch build error
    99dc2c143dfc0 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
    094145989b31f gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
    3808bab5d95ae iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
    0679c0c189d25 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
    9086b488f2737 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
    2ef9bb422dd6d pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
    3e55d28095476 pinctrl: qcom: Unconditionally mark gpio as wakeup enable
    54a62153c765c thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
    d01e88d421a6d mm/slab: prevent unbounded recursion in free path with new kmalloc type
    3e957c9b160cf lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
    98f57011e6cd1 HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
    bc3bba4656ad2 HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write
    df0f33293c0a3 HID: logitech-dj: Standardise hid_report_enum variable nomenclature
    302eb87651326 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
    e8362523fd1b6 drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
    a5cdd2407dd89 net: mpls: initialize rtm_tos in mpls_getroute()
    85b94a74a0b83 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge()
    9bb3714e09986 kunit: tool: Terminate kernel under test on SIGINT
    d36086cd1826e kunit: tool: skip stty when stdin is not a tty
    285641eb82f0e netfilter: nf_conntrack_expect: restore helper propagation via expectation

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 5ad5ad94f023ec2149585f0e0bae9847fc5bb06d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.18.bb              |  6 ++---
 .../linux/linux-yocto-tiny_6.18.bb            |  6 ++---
 meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
 3 files changed, 18 insertions(+), 18 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index edb3696b25e..a7051c6e47c 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 894267acdf1..6f3c9b63e5a 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
 include recipes-kernel/linux/cve-exclusion.inc
 include recipes-kernel/linux/cve-exclusion_6.18.inc
 
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index e510ff01aaf..2a515e6bfe9 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.18/standard/base"
 KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
 
-SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697"
-SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf"
+SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
 SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
 SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599"
+SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.18/base"
 
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (2 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
                   ` (33 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Bruce Ashfield <bruce.ashfield@gmail.com>

Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:

    5bbb9c9f8f808 Linux 6.18.48
    c49f04e8d2b94 inet: frags: strip GSO state from fragments before reassembly
    7519e95095c9b Linux 6.18.47
    3ce832e2bd431 net: gro: properly validate BIG TCP aggregation criteria
    5b4f2bec7bea6 ptp: vmclock: prevent read-only mappings from becoming writable
    dba60d26e9dda futex: Avoid private hash use-after-free on final put
    e1534d49a7b8b Bluetooth: hci_aml: validate firmware segment lengths
    b7d9edcf9fe6e Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
    1f6d1f2611af0 Bluetooth: ISO: zero the sockaddr before returning it in getname
    753af97d8d423 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
    fe93a697a7a92 Bluetooth: hci_sync: Fix accept list UAF during suspend
    e3f82e8f2a591 Bluetooth: hci_event: validate LE Set CIG Parameters response
    39a3afb91be3c Bluetooth: hci_event: fix LE list UAF on reset
    608f8fd8c0f7b HID: hyperv: validate initial device info bounds
    849e537160bbb HID: uclogic: fix use-after-free of inrange_timer on remove
    8406d4b69d48b HID: sensor: custom: Fix use-after-free in enable_sensor
    1fa1591efd417 HID: core: fix number/pointer type confusion on long items
    5efcd7bbfaaec HID: nintendo: stop device IO before hid_hw_stop on probe failure
    268679f501386 HID: nintendo: register input device after capabilities are set
    51cfd1adbe7a4 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
    942b89f7824f8 futex: Fix might_sleep() warning in futex_pivot_pending()
    86d12b34bafc9 futex: Fix race on the initial mm->futex.phash.ref allocation
    fdf538b2e6965 futex/pi: Plug private futex exec() race
    4da67def9efe6 futex: Sanitize and document task_struct::futex::state transitions
    2b92e5562653b futex/pi: Reject cross-mm private futex owners
    f303f6a4c9099 Input: atkbd - skip deactivate for HONOR ZQC-P
    936ea65543da0 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
    0ea8f06454012 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
    39fc615e355b6 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
    4529c03c3da8f HID: pidff: fix OOB write when hid->inputs is empty
    9a1d7c5f0d82e HID: core: fix OOB read of field->usage in hid_set_field()
    ace7fc4d38799 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
    15b60ade825c8 HID: magicmouse: do not keep a stale msc->input if no input is claimed
    62ec3c591ee81 HID: magicmouse: re-enable multitouch after reset-resume
    02a88f8308ae7 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
    b6baab796d11f ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
    9fe5eebb664ec mptcp: pm: fix memory leak from alloc-during-teardown race
    6fa2064761ec0 mptcp: pm: uniform announced addresses helpers
    714c6d11aceaa mptcp: pm: rename add_entry structure to add_addr
    defc59e74c1b4 mptcp: pm: use for_each_subflow helper
    f31650243c1ab nvmet: pci-epf: put CQ ref on create_cq mapping failure
    20be486d1c225 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
    9c95f7e66c62e nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
    6d27199ebe8cb nvmet-tcp: bound SGL data length before allocating command buffers
    8bce9cd08aae4 nvmet-fc: fix invalid free in LS IOD error path
    b26189d284421 nvmet-auth: zero the AUTH_RECEIVE response buffer
    23a475ff24d29 dmaengine: fsl-edma: Add error handling for devm_kasprintf
    364edaedf4125 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
    3dc98e5fe82d0 ipv6: fix use-after-free in ip6_finish_output2()
    d9d1a676b033a ipv4: reject undersized MTUs in ip_do_fragment()
    f034150305791 drm/xe: Fix DPT allocation paths.
    20892d2923e48 nfc: nci: free destination parameters when closing a connection
    0d4b5cfab6891 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
    2f08dbce3b376 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
    9620a91f8d643 nfc: nci: add data_len bound checks to activation parameter extractors
    bfcca5f42c9aa nfc: st21nfca: validate ATR_REQ length against the received frame
    2f5d093194ec2 nfc: pn533: purge fragmented skbs during cleanup
    e969e98410051 nfc: llcp: reject PDUs shorter than the LLCP header
    2d239590d1845 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
    e87527b506c40 nfc: llcp: bound the connect_sn TLV walk to the skb
    d0902a7c45432 nfc: microread: validate target discovery payload lengths
    db7e464b35096 nfc: fdp: bound the device-reported read length and fix an skb leak
    a56773e649ea9 nfc: digital: clamp SENSF_RES length to the destination buffer
    cb8246e5846db libceph: fix OOB read in decode_watchers() via missing bounds check
    184c1a80421a5 xfs: validate attr entry pointer before field access
    e0e7f464d6ce8 ext4: fix incorrect function call when initializing s_resgid
    458776af0061a ext4: don't enable DAX on new encrypted files
    f3d2fa3a99336 ext4: propagate errors from fast commit range replay
    5f46f084f74b5 ext4: avoid tail write_begin walk for uptodate folios
    fb5980fbe44fc ext4: clear error before retrying inode xattr space fallback
    e447f7edb99bd nilfs2: reject invalid block index in GC ioctl
    4902a5cba21ae ext4: stop retrying saturated xattr cache entries
    e11f5b48c8270 kcov: fix data corruption and race conditions on PREEMPT_RT
    164ca33cf5366 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
    6176313622e34 ocfs2: fix missing metadata reservation for large xattrs
    15ccf53709859 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
    45c945107e007 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
    4074ae2f1da9e io_uring/io-wq: fix worker accounting when canceling creation callbacks
    b6a768aa975b9 io_uring/cmd: fix iovec leak when the async cmd is not recycled
    f20c2c32ec1c5 ALSA: dummy: Check card index validity at probe
    3da64f2ed902b io_uring/futex: don't mark futex wake requests as inflight
    61dc1a37e04d4 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
    e971d956353d3 rndis_host: add overflow check in rndis_rx_fixup()
    4305e4b52acc0 ALSA: scarlett2: Use a private URB for the notification endpoint
    65aceb45ca91d ALSA: FCP: Use a private URB for the notification endpoint
    7596354148c5a iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
    d2ab08437e913 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
    d4b1a13b1eff2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
    0c55707bd5d0d PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
    159d162fe80bd xfs: don't livelock in scrub on a circular unlinked list
    a05a1b663464b xfs: hoist per-bucket unlinked list check to helper
    8d678be8e58e9 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
    00e2baf0b5ea9 xfs: add a xchk_ip_set_corrupt helper
    755d0b7ee3563 serial: sc16is7xx: enable THRI before filling TX FIFO
    c5a12344a043e serial: sc16is7xx: use guards for simple mutex locks
    450fe8f6f1f8c serial: sc16is7xx: rename EFR mutex with generic name
    1f99e9ab748fc Linux 6.18.46
    b7ce4b3bc1068 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
    192f44513a03b firewire: ohci: initialize page array to use alloc_pages_bulk() correctly
    e5e6ce7009a6c drm/vmwgfx: Set surface-framebuffer GEM objects
    7e351209dc2f4 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
    67ac7e01c26be spi: virtio: mark device ready before registering the controller
    a7d172b27aa3e drm/log: Fix infinite loop when scale is too large for display
    a6325e2807dc2 drm/client: Remove drm_client_framebuffer_delete()
    329731b3119f0 drm/client: Deprecate struct drm_client_buffer.gem
    0763282e689e2 drm/client: Inline drm_client_buffer_addfb() and _rmfb()
    60f1a2ecdf8b9 drm/client: Move dumb-buffer handling to drm_client_framebuffer_create()
    841bc853a2b11 drm/client: Remove pitch from struct drm_client_buffer
    16a2716910ecf drm/log: Fix out-of-bounds read on empty message length
    948f346fe36e1 drm/xe/oa: Fix sync entry leak on OA config emit failure
    ed5470771c7ed firewire: ohci: fix NULL pointer dereference in ar_context_release
    384d9f04b38f4 firewire: ohci: split page allocation from dma mapping
    adb3e7c26a51a net/sched: cls_bpf: reject dev-bound programs bound to a different device
    1f493c44a2f04 accel/amdxdna: Skip unmapped range in aie2_populate_range()
    72e4e3d7efc3b net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
    6cf600b276a55 regmap: sdw-mbq: don't call an unset readable_reg callback
    c27eed546ae20 m68k: Define NR_CPUS to 1
    31f26a95eeee9 net/sched: cls_u32: skip hash tables in u32_bind_class()
    abceabc4408fc net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
    98c5914d6b7bd af_packet: Don't send zero-byte data in tpacket_snd().
    37c5ccaaacd48 regmap: sdw-mbq: Fix swap of timeout and retry times
    f51a540b14eec ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
    82d9269f01ebf net/tls: Fail tls_sw_splice_read() after a failed async decrypt
    cef4c5b9aca24 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
    5ffaa5d7f56ab net: tap: fix wrong transport_header when sending VLAN-tagged frame
    f9297abbcaba7 net: packet: fix wrong transport_header when sending VLAN-tagged frame
    0af3afd054e7b net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
    17e3181d740d1 tcp: fix icsk_ack.ato bitfield overflow
    73f8dd22b1e53 veth: fix queue index used to wake the peer txq in veth_poll
    96fa90b74385b macvlan: inherit needed_headroom and needed_tailroom from lowerdev
    5f33188457bbc ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
    1072f0f442820 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
    394f1b16c5d1b eth: bnxt: cancel IRQ notifier before freeing affinity mask
    a26a1be1b6541 netfilter: ipset: let destroy callbacks adjust ext mem size
    29c011b3537d7 netfilter: ipset: fix list type element drift bug
    d9d3050a70efe netfilter: flowtable: publish GC-visible tuple last
    4a923fe60939a netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
    cb20da33839f2 netfilter: ipset: fix refcount race between list:set GC and swap
    9e75e7da43740 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
    24d0f33f5415f gpio: ml-ioh: share the register lock across channels
    7a03413f31c19 perf: Reject exited events as group leaders
    6c85d169eeecc riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
    a3a676495c641 ovpn: finish crypto callback cleanup before peer release
    a47a080d06ee9 ovpn: fix NULL dereference when killing missing key
    99a18e1d979e0 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
    3e4bf50c94511 crypto: ccm - Set rfc4309 maxauthsize from child
    d9ecc9787e118 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
    a4e340971fe8c NTB: ntb_netdev: Preserve RX queue depth on allocation failure
    08437c5156b0a net: ntb_netdev: Introduce per-queue context
    2a7d8fc0fd50e ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
    8c685df5c3b26 drm/amd/pm: fix pptable use-after-free
    2895aeb4327c9 drm/amd/pm: adjust the visibility of pp_table sysfs node
    7755be923e325 mm/page_table_check: skip special zero mappings
    4ae625d16eefb ring-buffer: Prevent resizing of persistent ring buffer
    54fc67500ad1b ring-buffer: Store bpage pointers into subbuf_ids
    27d7fcaf237df ring-buffer: Add helper functions for allocations
    2ca6b43edf83f sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
    f786e6652b931 sched_ext: Reorganize enable/disable path for multi-scheduler support
    0907f81536f7d sched_ext: Update p->scx.disallow warning in scx_init_task()
    4a7e941ca29a6 futex: Fix race in futex_pivot_pending() during private hash resize
    870f8392b284e can: rcar_canfd: change the initializing flow for clocks and resets
    45bf067681ad5 can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
    e7a4ca927857a can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
    f8c8c81707d17 can: rcar_canfd: Invert global vs. channel teardown
    562d4befa9357 can: rcar_canfd: Invert reset assert order
    867aed6a48487 binfmt_misc: don't leak the user namespace when the mount fails
    4c8d7595a10a6 ata: libata-scsi: terminate deferred commands on time out
    db488d653d896 ASoC: tas2562: Validate values for volume writes
    5f0a99ea72120 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
    ef60eca789ee6 userfaultfd: wait on source PMD during UFFDIO_MOVE
    ea563ed2b10ae mm: replace pmd_to_swp_entry() with softleaf_from_pmd()
    54a09573eb440 fs/proc/task_mmu: refactor pagemap_pmd_range()
    549148d5aa4e3 btrfs: zoned: fix missing chunk metadata reservation
    58ae8b7e8dc88 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg()
    d9e9753dfd43b ksmbd: validate minimum PDU size for transform requests
    15a2fedb5dff3 smb/server: fix minimum SMB2 PDU size
    23d34ce118857 smb/server: fix minimum SMB1 PDU size
    5649004f71613 ksmbd: rename smb2_get_msg to smb_get_msg
    29dbb4e29e1f1 ksmbd: Fix to handle removal of rfc1002 header from smb_hdr
    df3cf61adbe68 smb/server: rename include guard in smb_common.h
    9d154c3c0f5d9 smb: move get_rfc1002_len() to common/smbglob.h
    8ddc2eb0d2da9 net/sched: serialize qdisc_rtab_list against concurrent get/put
    89df5d71f83f8 libceph: fix two unsafe bare decodes in decode_lockers()
    590b07ceea138 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
    89a50fb32d69a libceph: Amend checking to fix `make W=1` build breakage
    a3bc6b3e9ef3f ceph: fix hanging __ceph_get_caps() with stale mds_wanted
    79d95b43ca090 ceph: avoid fs reclaim while using current->journal_info
    bb13785d54999 xfs: check v5 superblock features early
    04228b8ba196f xfs: check xfarray iteration errors when committing unlinked inode lists
    33b56c6c465aa xfs: don't ignore runtime errors in xrep_iunlink_reload_next
    38a4dbe588bd0 xfs: don't swallow dquot recovery verification errors
    0f27b22343b63 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
    cd1f876d1bc2e xfs: avoid UAF on sc->tempip in xrep_tempfile_create
    e75150d494dcd xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
    b6baf0db357fb xfs: fix another iunlink infinite loop bug in online fsck
    fc7d8a5c5fcc7 xfs: fix allocated inodes that show up in the unlinked list
    c36d7f68f1c2e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
    73ffd2620df3a xfs: don't zap the attr fork on repair when there are queued pptr updates
    514a5d42d4188 xfs: fix ilock leak on error in xfs_dq_get_next_id
    9680b1929d897 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
    8b52fa8fb3abb xfs: nlink scrub must take IOLOCK before determining ILOCK state
    7d1d82c463e22 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
    ab4e133370763 xfs: set the prev pointer when reinserting an inode on the unlinked list
    ce2a7006ec5ed xfs: don't double-lock when deleting a self-referential directory
    983588e756a30 xfs: only check mergeability of bnobt records
    62c0b1435dfe2 xfs: zero i_nlink before repair puts inode on unlinked list
    a9114c6d4ec2f xfs: fix transaction block reservation in xrep_rtbitmap
    90a49b8fcf821 xfs: check cowextsize in xrep_inode_cowextsize
    069c0eadc8df0 xfs: clear zapped attr fork state when bmap repair finds no attr fork
    aeadf3fd2dc3c xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
    f8288214459ea xfs: bounds-check buffer log item's dirty bitmap
    8a0ecae2ecda9 xfs: fix off-by-one in rtrefcount btree root level validation
    ec19cea4ef1ce xfs: propagate errors from xfs_rtginode_load
    71aa45f7bfe46 drm/amdgpu: disallow multiple FENCE chunks in one submit
    25ee120f3803a drm/amdgpu: Fix UVD decode image min size calculation
    38914cb2c6afb drm/amdgpu: Fix UVD dpb min size calculation for H264
    c76e5cca0675b drm/amdgpu: Fix UVD min buffer sizes
    86a5cb0203221 drm/amdgpu: Implement insert_end for VCE 3
    339deb76ee485 drm/amdgpu: Reject UVD message with dimensions above 4096
    220aa2589d732 drm/amdgpu: validate GEM_CREATE domain combinations
    a082bd76c5f25 drm/amdgpu: check ASPM on the dGPU host link
    916e8a1550be1 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
    e304c3e0d9ce2 drm/amdgpu: Reject UVD message with invalid number of h265 refs
    e3e6a631dcb1c drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
    cd99fa1cbaf5a drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
    5045fb4c70bfd drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
    95c1de6923b06 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
    7902be374cbfc s390/vfio_ccw: Implement a crw lock
    3b224d3c50a38 s390/vfio_ccw: Calculate idal length based on idaw type
    b6aecea4b2b24 s390/vfio_ccw: Selectively expand io_mutex
    af1759d8e6e6d s390/vfio_ccw: Move cp cleanup out of not operational
    4c2e1d359d7a2 s390/vfio_ccw: Fix out of bounds check on CCW array
    08ef2a8211569 s390/vfio_ccw: Ensure first IDAW remains constant
    649badf3a2fd8 s390/vfio_ccw: Ensure index for read/write regions are within range
    b7ae0f7993867 s390/vfio_ccw: Cancel existing workqueues
    06f4d6e5a8af6 s390/vfio_ccw: Limit the number of channel program segments
    32e3d364a7b82 s390/vfio_ccw: Free all memory if cp_init() fails
    45aa38567c798 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW
    0382ed41c6645 eth: bnxt: always set the queue mgmt ops
    31ef57083e785 drm/radeon: fix autosuspend cleanup during teardown
    361114857813d drm/xe: Fix xe_device_probe() failure
    7b90db6f024b8 drm/xe: Order ring writes before ring tail updates
    198b4a89b9033 pmdomain: mediatek: Fix mt8183 hang on boot
    8f7f7a6d5aed8 mmc: loongson2: Fix sg iteration in data reorder functions
    e5b527804a1ea drm/connector/hdmi: Fix out of bounds memory read
    b5060ff2f5460 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
    78e59ab343372 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
    7c0d1767ce464 mmc: sdhci: make tuning_err a signed int
    970b9c83a07c4 pmdomain: mediatek: fix remaining %pOF after of_node_put()
    36d1b69c5c698 mmc: sdhci: unmap the bounce buffer before device release
    0418b7ed2c1c6 mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
    b37e84280045b libceph: tolerate addrvecs with multiple entries of the same type
    4490fad7992a7 ceph: fix MDS random selection readiness predicate
    4f392fec07556 libceph: Avoid using invalid osd indices from primary_temp
    f3854719fba9f Input: sur40 - fix V4L error path cleanup
    5c1c5227c93f1 Input: sur40 - fix input device registration ordering
    a88d688be8d7f openrisc: signal: do not restore privileged SR bits on sigreturn
    f634598e8fb7b ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
    f8fe843a96344 ftrace: Protect direct_functions in ftrace_find_rec_direct
    d1bba38574d09 libceph: fix multiple unsafe decodes in decode_locker()
    ebdecef6fd842 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
    bc7934d0acd4f gpio: ml-ioh: use raw_spinlock_t for the register lock
    9e678cffc11c2 gve: fix zero-length skb frag with header-split
    bd4e5a97edf8c selftests/ftrace: Convert ELF entry point to file offset in uprobe test
    23e9f32c0c7d2 gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
    e9482feeed66d gve: fix NULL dereference due to missing ptp adjfine
    a134e4b8102c0 crypto: qce - fix error path in devm_qce_register_algs
    ef92c0ad0268e crypto: starfive - use scatterlist length before DMA mapping
    38e7d5c1ade04 Input: hynitron_cstxxx - validate touch count and finger IDs
    70f9aad394355 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
    ff0849705d292 Input: synaptics-rmi4 - block s_input when F54 queue is busy
    6b06aab79ff16 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
    b28593a05afdd Input: synaptics-rmi4 - zero report size on F54 work error
    828a8d1a9107a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
    2bdec532202b3 powerpc/pseries: lparcfg - fix kbuf[] underflow
    8dbfd8e32a13e Input: byd - synchronize timer deletion before freeing private data
    a64a8b6b31cd6 Input: iforce - validate input packet lengths
    e7b8a107ecad5 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
    8d622c58205ad Input: psxpad-spi - set driver data before use
    83c265bfc084d Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
    9b184c8337c6e Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
    652e952850d9a powerpc/pseries: pci - logic bug
    52a818c586ae2 Input: cs40l50-vibra - validate custom data from user space
    455dbb5bdd814 Input: xpad - add support for ZENAIM LEVERLESS
    6635d544bd6bc ASoC: SOF: topology: Use acpi mach from the machine driver
    bcc66461f574a drm/amdgpu: fix aperture iounmap skipped on device removal
    dffacbe8118fc drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
    e45356f6adae4 drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
    4550b90bd2e6c drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
    1474f3970d1af drm/amdgpu: reject oversized IBs with per-ring packet limits
    25556a46ae6ec drm/panthor: skip zero-sized firmware sections
    7ff87a01ae3a8 fbdev: core: Fix pointer desynchronization in fb_io_read()
    2fe7a89b2b5b7 ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
    cc61f0fa2c714 ASoC: cs35l41: sort the register default table
    3298f13d1f126 ASoC: cs35l45: sort the register default table
    d7bd683b0d90c ASoC: cs4265: sort the register default table
    f2435a46dfa1a ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
    8cba53b862e14 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
    a308364774794 s390/qeth: validate user buffer length in SNMP and ARP query ioctls
    75e564b2ced1c mptcp: fastopen: only mark MPTFO subflows with SYN data
    3f8e5eb0c4999 mptcp: pm: fix data race in add_addr timer callback
    1fade1b2ac5b1 mptcp: options: reset DSS fields in case of unexpected size
    a04dcc784959e mptcp: avoid combining some incoming suboptions
    0cb3846c26c11 selftests: mptcp: join: mark tests with data corruption as failed
    473f1a5ab2abc mptcp: reclaim forward-allocated memory on RX path errors
    9b46fba7528f5 selinux: reject a permission value exceeding the class permission count
    841aea4d5a25e selinux: reject an unclaimed class value in security_get_classes()
    1b4ff94ae7c58 selinux: do not cancel a policy conversion that never started
    acd5b09be98fd selinux: reject a class permission count below its inherited common
    42a7107f99d86 selinux: require every boolean value to be defined
    1a4c3ffe2a48b ipvs: separate destination availability state
    9ff46bf75bfad ubi: fastmap: fix ubi->fm memory leak
    075036cea14ae mtd: ubi: skip programming unused bits in ubi headers
    bb03b56d1d754 block: stop the timeout timer when releasing a never added disk
    e2c3337c2238e ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
    bf3be28f6721e Linux 6.18.45
    1eb0dc458b6e8 netfilter: flowtable: ensure sufficient headroom in xmit path
    99ec511f258e0 netfilter: always set route tuple out ifindex
    9977321835c7a thunderbolt: Fix bandwidth group reservation indexing
    40d2ffb74094c thunderbolt: Bound the DROM dual link port number before indexing sw->ports
    ca33df36aa014 sctp: clear new_transport when removing a peer
    07daf4f975010 sctp: fix use-after-free of cached ASCONF chunk
    2b3b5eec8b2c3 sctp: keep chunk->transport in step with the list it is queued on
    3bd46d33e3fd5 scsi: scsi_debug: Negate wrapped memcmp() result
    a14e4ef1d90c3 bpf, sockmap: Fix sk_redir use-after-free in send verdict
    3c6d4ffa0c6db fsverity: Fix silent truncation in bpf_get_fsverity_digest()
    2a5cfcad1d56e fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
    4917e3ebcab50 mm/filemap: __filemap_add_folio() restore index before retrying
    dd21c96a71e87 ima: Instantiate file_truncate and path_truncate hooks
    102fb2dacf450 sched/psi: Create the psimon kthread outside of cgroup_mutex
    8037c5b2b2a44 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
    653e888a24c87 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
    4eb15c465337b ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
    3b2231e358d26 ipv6: fix Route Information option length validation
    7f740664aec1f mm/ptdump: always stabilise against page table freeing using init_mm
    5b926fb04cb9e ring-buffer: Use current_context for safe per-CPU buffer swap
    2e37f2bf11142 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
    5fd91dd4a1434 ptp: ocp: Fix board ID over-read
    8d34019d14136 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
    5635211b44969 eventfs: Fix use-after-free in eventfs_remove_rec()
    66bc868a33cf1 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
    47976eaaf0a4e KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
    1ffacbadc1453 smb: client: Fix use-after-free in cifs_try_adding_channels()
    c3f2347a47754 tipc: read le->link under the node lock in tipc_node_link_down()
    3fc5044796dd8 tls: don't leave a full plaintext sk_msg ring unpushed
    68787940274ec tls: rx: restore msg_iter before TLS 1.3 optimistic retry
    f1e21108e3ddf vhost: reset the vring metadata cache on vring reconfiguration
    cdf745b7a777f veth: fix skb length accounting after XDP frag adjustment
    38c7763fdc533 vsock/virtio: avoid refilling the RX queue after teardown
    bd43a7ec668be vsock/virtio: read virtqueues under worker locks
    46bb297ad7768 vxlan: do not arm the ageing timer on a device that is down
    fab820f1691a9 xdp: reject clones that overrun skb_shared_info tailroom
    e708fc1566ebd x86/mce: Set up the polling timer before CMCI discovery
    846b92e26c8ab x86/CPU: Add a tlbi= cmdline switch
    69298af46f397 arm64: remove redundant concurrent ptdump UAF mitigation
    fe79571f40434 dibs: initialise dibs->lock in dibs_dev_alloc()
    a2e326c52c4bc Revert "drm/amdgpu: fix aperture mapping leak"
    24e95a24f151c binfmt_misc: don't warn when the mount is completed from another user namespace
    be161fa31e3e9 ovl: don't warn when the mount is completed from another user namespace
    92f00f1d4d204 net/sched: act_gact, act_police: range check the fallback control action
    b47bb899e04b5 net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
    782cc40b7ade4 net: atlantic: free RX pages of consumed but not refilled buffers
    b13202d401e1a net: atlantic: free stranded TX buffers on ring deinit
    0424186d570aa netfilter: nf_conntrack: defer invalid log until after unlock
    c58d34fe8b7e4 netfilter: bridge: release template ct on non-IP path
    e9bfe12b1d04c net: devmem: prevent net-iov / page mixing
    4bc522b33438f net/x25: fix use-after-free of the socket by its timers
    ece6426b61241 net/dibs: Correct freeing of dmb_clientid_arr
    680fbd7942185 ipv6: prevent in6_dev_get() from resurrecting inet6_dev
    0b7d54cedea5c net: smc: fix splice entry lifetime imbalance in smc_rx_splice
    b65c11bc62216 net: phy: mediatek: fix TX blink masks using the RX bits
    105d04edbec83 mm/huge_memory: fix huge_zero_pfn race
    152a00440dc6e tracing: Fix NULL pointer dereference in module event cache removal
    62978cf634797 ring-buffer: Prevent subbuf order change when resizing is disabled
    bc9db0d879c65 fbdev: bitblit: bound-check glyph index in bit_cursor()
    ed49684e69f84 tracing: Fix race between update_event_fields and, event_define_fields
    a979a642402d0 perf/core: Fix group leader use-after-free after sibling detach
    5884851a096d8 drm/v3d: Serialize the scheduler timeout handlers
    7779249561d14 ALSA: us144mkii: re-anchor capture URBs on resubmission
    a6b79dff1cc1c ALSA: hda/tas2781: fix ACPI reference handling
    bb30e35c36ed0 ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
    f75d6f61f0d9c ALSA: usx2y: bound the hwdep mmap fault offset
    d217d723c5e43 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
    976da5475472e mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
    e16b8d640ec99 samples/damon/mtier: error out for zero quota goal target values
    460181e4bb47a mm/damon/ops-common: putback folios on invalid migrate nid
    6dd7a06894d6d ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
    688c71bed6852 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
    af6345159abcb misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
    9bf22a7d950ce misc: fastrpc: Remove buffer from list prior to unmap operation
    c5a03c2cadd2f misc: fastrpc: fix channel ctx ref leak when session alloc fails
    cd02b93863159 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
    8b3e4ed9c35d3 staging: rtl8723bs: validate monitor transmit frame lengths
    a28a4b0592e4a staging: rtl8723bs: fix missing shared-key auth challenge length check
    e5b7610008f4e staging: rtl8723bs: fix OOB read in WMM_param_handler()
    e167a38a8a8f5 staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
    5974cb66681ea serial: amba-pl011: synchronize DMA teardown
    759ead98a39fb serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
    2a0ee25f75cdb serial: amba-pl011: fix indefinite RS485 post-send delay
    3ce24bc4d1153 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
    ae05d9e50b6b9 serial: 8250_dma: Clear stale RX state on shutdown
    1c31e2377f4c1 serial: qcom-geni: fix TX DMA buffer flush
    dd6946a70ddbd rust_binder: do not query current thread for all ioctls
    9dbe1d0111893 nvmem: layouts: Add fixed-layout driver
    da59844f561d1 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
    104c2e8b8e38b mei: pull kvfree out of spinlock
    63996ffc594d1 ipv4: fix use-after-free in fib_nhc_update_mtu()
    a59edda6eda12 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
    94166072975aa selftests/bpf: Adapt sockmap update error handling
    edee58a9c460a selftests/bpf: Ensure UDP sockets are bound
    dc0c462fa838c Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
    373d425f7638a Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
    8545f4ef9eae6 netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate
    7b8c53263f887 futex: Prevent robust futex exit race some more
    cf8a9672fc25c iommu/vt-d: Gather the unmapped range before freeing its page tables
    643b410bdfa48 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
    8d817ef1aa4e9 KVM: s390: pci: Fix aisb calculation
    cf895cd72e404 blk-mq: reinsert cached request to the list
    97e2d08de282e blk-mq: pop cached request if it is usable
    59b07ccca4c05 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
    5912cf1822fbe net: bridge: mrp: fix uninitialised bytes on the wire
    47a119ec8a7e2 netfilter: ebt_nflog: pin the NFLOG backend
    a0e76de6a2f28 igc: fix netdev not re-attached after resume if interface is down
    e6cd416a899ed mac802154: fix netdev use-after-free in beacon worker
    9f904dd3e4557 inet: frags: publish queues before arming timer
    dbb30dc943a93 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
    99ae2239069ed net: octeontx2-pf: Fix UB in shift operation
    a4b14a4df29d3 net/sched: reject overly deep qdisc hierarchies
    23716dd9d8d46 net: openvswitch: reallocate update replies for mismatched IDs
    5f30f9c302cea net: fix skb length accounting after generic XDP frag adjustment
    2c7b5eb87b2b2 packet: synchronize pressure clearing with ring reconfiguration
    971aa7d99242b net/packet: reset the MAC header on the packet-socket transmit path
    27e068d1b35db packet: use consistent hard_header_len in TX_RING send path
    5bb10753d428a packet: use consistent hard_header_len in non-ring send paths
    75eec935444db ipvs: clear IPv4 options after rebasing tunnel ICMP errors
    0f88fe0552bee ipvs: properly update the overload flag on dest edit
    59b90c17bec5b ipvs: add totalconns for dest
    e7f34f29b3302 ipvs: stop estimator after disabled calc phase
    27f3924061592 ima: fix out-of-bounds read in xattr_verify()
    c5bf8cd148cfe mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
    bd3c4108a56de Input: evdev - fix information leak in evdev_pass_values()
    b664592e9ba8c vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
    a1c31e026c93e vt: add permission check for KDSKBMETA ioctl
    2c7496124e94c net: usb: ipheth: fix carrier_work UAF on disconnect
    58733b1dd46bb net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
    d328fdc607fa1 usb: gadget: f_ncm: Use unsigned int for ndp_index
    2dfefdd498ab4 usb: cdnsp: fix incorrect endian conversions for APB timeout register
    6e4c09bea8e9c thunderbolt: icm: Preserve USB4 proxy data-valid bit
    2f73a065791d2 usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
    ebfd1e82ab0a6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
    04b71290fb419 usb: quirks: Add ShanWan gamepad to quirk list
    1740fd2aaa8fd usb: core: Add quirk for 255-bytes initial config read
    0a235379825e1 ALSA: usb-audio: fix OOB write on Type II inbound URBs
    4034ef247a9dd Input: evdev - sanitize event type index when fetching event masks
    8b444b126cd8e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
    fad7cecb5c2c0 net: fec: do not release NULL pages when RX buffer allocation fails
    c768fb2e43c8a hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
    de58b90a4d141 hwmon: (ltc4282) Clamp negative current limits
    124bd4b006199 hwmon: (ltc4282) Avoid overflow in maximum power calculation
    678a76c8fd33d hwmon: (ads7828) Fix external VREF regulator handling
    5ee1f603a64bd hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
    29fe74c9aa69d watchdog: at91sam9_wdt: prevent timer rearm during teardown
    6d1d3ca6c8f4a tls: don't abort the connection on signal-interrupted sends
    18d704bdd8093 sctp: clear control chunk transport if it is being removed
    9f77c1ab38218 net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
    fc3021284050e s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
    8fa684db8709b bnge: Fix resource leak in bnge_init_nic() error path
    a837deeaa37cc ata: pata_sl82c105: fix bridge revision use-after-free
    4dd71cb0d23d4 net: thunderbolt: Tear down DMA paths before stopping the rings
    78e5ebcd1c10e net/smc: fix TOCTOU race between smc_listen_out() and listener close
    c8f256dc84920 net: remove WARN_ON_ONCE() from sk_mc_loop()
    363e048a9d0a6 net: prestera: validate firmware header length
    02226af693627 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
    12afa450a6a6c netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
    25d40cf9dab15 netfilter: flowtable: consolidate xmit path
    a66e869cf0c90 tcp: fix TFO max_qlen accounting across reuseport migration
    6c24ec01fb768 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
    1e8f24b1e3fee bnxt_en: Fix PTP PPS setting bug
    aab3b5f4d8ec8 bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
    6a2e50924e57e bnxt_en: Refresh VNIC default ring on queue restart if needed
    f1a4e95e296b2 bnxt_en: Determine and store default RX ring in vnic structure
    965c45be24e15 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
    88664c48d7d1e net/mlx5e: fix BQL reset on SQ re-activation
    beb47092fe8fc bnge: use int for bnge_fix_rings_count() return value
    4901b23b5ca7b net: stmmac: resume PHY before hardware setup when opening the interface
    99b7bcee01589 selftests/ftrace: refactor eprobes test to fix argument checks
    a7a00ecf54243 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
    2e5ea8272ceae hwmon: (nzxt-smart2) Check return value of init_device() in probe
    9fccf43f05317 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
    d6222af7274f0 net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
    a8139285c8925 net/openvswitch: check Ethernet header length in key_extract()
    a06e4611d4551 vhost-scsi: reject feature changes after endpoint
    2417a498cf3fe vhost-scsi: Validate T10 PI scatterlist counts
    cd2f1d9fe8a50 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
    64d322c288577 udp: fix potential use-after-free in tunnel segmentation
    5fd121971912d xsk: validate metadata when processing requests
    1a1534cc3b419 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
    af511afa1d297 xsk: validate launch-time metadata size
    0ba2e1eb07a82 xsk: clear metadata pointer when no timestamp is requested
    5ec4f525373bc xsk: pass TX metadata pointer by reference
    642c6e73fce17 xsk: require at least 16 bytes of TX metadata
    b0b7202f751bb bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
    ad9ffc61fafeb eth: bnxt: support qcfg provided rx page size
    cd5485a702efd eth: bnxt: store rx buffer size per queue
    9c1406e2ecd2e net: pass queue rx page size from memory provider
    b3fecb888e94b net: add bare bone queue configs
    96197286b0ac8 net: reduce indent of struct netdev_queue_mgmt_ops members
    34debe05685d1 bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
    5ba1a458c5e26 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
    821f6416e6978 hwmon: (pmbus) Fix type confusion in notification logic
    11720d869be1a hwmon: (pmbus_core) Use guard() for mutex protection
    cde8931a25392 vdpa/mlx5: Fix buffer length in create_direct_keys()
    a1c236b385d85 vhost/vdpa: reject overflowing PA map page counts on 32-bit
    cefcbbe20846a bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
    846ce792b6dd2 counter: microchip-tcb-capture: Fix DT channel validation
    80094352bd40b net/mlx5: fw_tracer, return NULL on create error
    7b02c6d2a3cd2 devlink: fix net namespace reference leak in reload
    1efcc71140094 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
    0e7a8cf8895b0 net/sched: cls_route: fix fastmap use-after-free on filter
    10cb31b2b74cb net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
    d8a6f79935205 bpf: Propagate untrusted pointer state in commuted arithmetic
    c2da73a1f715f bpf: split check_reg_sane_offset() in two parts
    db6382ed3361b bpf: Preserve pointer state for commuted arithmetic
    24a8f2c29aebb btrfs: fix memory leak in btrfs_do_encoded_write()
    26e968526eb53 watchdog: bd96801_wdt: Fix timeout for enabled WDG
    b3ff48c4ea8b2 ipvs: return the csum validation for forward hook
    a69a4b3fff581 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
    1e8a5467a7a7b netfilter: ipset: switch ext_size to atomic64_t
    970e9494f44af pds_core: cancel pending PCI reset work on AER recovery
    ef8e37ac448d4 pds_core: keep the health thread stopped during reset
    ff9e7d5e3500b net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
    e506e704b7474 enic: fix tx_hang_reset use-after-free on device removal
    2faf75a8a0650 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
    35ddcc856b5b3 Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
    d512823059af8 net: hns3: fix speed configuration residue after driver reload
    8701a643db231 drm/bridge: ps8640: propagate AUX transfer register errors
    d47212d866906 ovpn: fix incorrect use of rcu_access_pointer()
    54dd83f24b913 ovpn: ensure TCP vars are initialized first
    f34949d63cbbe ovpn: disable IPv4 redirects on MP interfaces
    e774f7d8fc733 ovpn: hash floated peer by transport identity only
    9a776388ef8d5 ovpn: zero-initialize sockaddr before learning a floated endpoint
    61fb3cca40ff9 ovpn: ensure socket is owned by ovpn before deref sk_user_data
    157164812a0c5 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
    d20c181088984 ovpn: skip rehash for peers already removed from by_id
    9e5e88fbfc87d ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
    92b9d92a35a0f ovpn: add missing rtnl_link_ops->get_size callback
    d740dea9e2557 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
    23c94a468efe3 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
    913d2295b772e selftests/sched_ext: Handle sleeping task affinity changes in numa test
    ce0212d230bd6 ARM: npcm: Fix OF node refcount leaks in SMP setup
    ccf6738adcafa xfs: handle NULL b_addr in xfs_buf_free
    d90599a42f6c5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
    d71dfffa512e7 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
    bd45b89d7346f arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
    df9d22383d7c0 arm64: dts: qcom: purwa: Fix GPU IOMMU property
    7a6e90afb696c arm64: dts: qcom: rename x1p42100 to purwa
    1e2b408c1a769 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays
    387edbe4706b6 arm64: dts: qcom: rename x1e80100 to hamoa
    d089f32d34f82 drm/amd/display: Check for tg ops in dce110_set_avmute
    8aba384bfc8aa drm/amd/display: Add AV mute wait frames to dce110_set_avmute
    50359c42e0eba selftests/bpf: Fail unbound UDP on sockmap update
    62fefb817bb3b sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag")
    4043e196dc882 sched/fair: Separate se->vlag from se->vprot
    9a3eef676cd8b mount: honour SB_NOUSER in the new mount API
    79a45d44323b3 KVM: s390: pci: Fix resource leak on IRQ registration failure

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 714654a1625f4f39a5c44c5ded9602d75b6cb6c8)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../linux/linux-yocto-rt_6.18.bb              |  6 ++---
 .../linux/linux-yocto-tiny_6.18.bb            |  6 ++---
 meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
 3 files changed, 18 insertions(+), 18 deletions(-)

diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index a7051c6e47c..a0c2abf1c5f 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
         raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
 }
 
-SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "40cf3a2e9ae15c3d4b3a528d4de015263639cac3"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
 
 SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 6f3c9b63e5a..0d4c98f2840 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
 include recipes-kernel/linux/cve-exclusion.inc
 include recipes-kernel/linux/cve-exclusion_6.18.inc
 
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
 
 DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
 KMETA = "kernel-meta"
 KCONF_BSP_AUDIT_LEVEL = "2"
 
-SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
 
 PV = "${LINUX_VERSION}+git"
 
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 2a515e6bfe9..1a7a8659bf8 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
 KBRANCH:qemuloongarch64  ?= "v6.18/standard/base"
 KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
 
-SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf"
-SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuarm ?= "1cd95e881ac1b4f07906bd0e9482891e12f84a83"
+SRCREV_machine:qemuarm64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuloongarch64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
 SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuppc ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuriscv64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuriscv32 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemux86 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemux86-64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
 SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
 
 # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
 # get the <version>/base branch, which is pure upstream -stable, and the same
 # meta SRCREV as the linux-yocto-standard builds. Select your version using the
 # normal PREFERRED_VERSION settings.
 BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5"
+SRCREV_machine:class-devupstream ?= "5bbb9c9f8f808710e2123f2b30f0d61d7d698f52"
 PN:class-devupstream = "linux-yocto-upstream"
 KBRANCH:class-devupstream = "v6.18/base"
 
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
            git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
 
 LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
 
 PV = "${LINUX_VERSION}+git"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (3 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
                   ` (32 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Tatrai <peter.tatrai.ext@siemens.com>

The failure summary path assumed the unsuffixed bootlog file always
exists and unconditionally opened it.

This is not guaranteed when SERIAL_CONSOLES has fewer than two
entries (including empty), where qemurunner can produce only
bootlog suffix variants (for example .2 or .stdout).

On test failures, collect snippets from all existing files matching
bootlog and bootlog.* and prefix each snippet with its filename.
Also skip creating a symlink for a missing bootlog path.

This prevents FileNotFoundError from masking the original test
failure and improves diagnostics across qemu serial configurations.

(From OE-Core rev: 7a6596925cb0eb8dd48a0362a51875cdd60152bc)

Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/classes-recipe/testimage.bbclass | 27 +++++++++++++++++++++++----
 1 file changed, 23 insertions(+), 4 deletions(-)

diff --git a/meta/classes-recipe/testimage.bbclass b/meta/classes-recipe/testimage.bbclass
index 9902b8a5682..0f34d551e99 100644
--- a/meta/classes-recipe/testimage.bbclass
+++ b/meta/classes-recipe/testimage.bbclass
@@ -186,6 +186,7 @@ def get_testimage_boot_patterns(d):
 
 def testimage_main(d):
     import os
+    import glob
     import json
     import signal
     import logging
@@ -409,15 +410,33 @@ def testimage_main(d):
     # Copy additional logs to tmp/log/oeqa so it's easier to find them
     targetdir = os.path.join(get_json_result_dir(d), d.getVar("PN"))
     os.makedirs(targetdir, exist_ok=True)
-    os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog)))
+    if os.path.exists(bootlog):
+        os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog)))
+    else:
+        bb.note("testimage: boot log not found at %s" % bootlog)
+
     os.symlink(d.getVar("BB_LOGFILE"), os.path.join(targetdir, os.path.basename(d.getVar("BB_LOGFILE") + "." + d.getVar('DATETIME'))))
 
     if not results or not complete:
         bb.error('%s - FAILED - tests were interrupted during execution, check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True)
     if results and not results.wasSuccessful():
-        with open(bootlog, 'r') as bootlogfile:
-            bootlines = "".join(bootlogfile.readlines()[-20:])
-        bb.plain('%s - FAILED - Last lines of QEMU boot log:\n%s' % (pn, bootlines))
+        bootlog_files = []
+        for candidate in [bootlog] + sorted(glob.glob(bootlog + ".*")):
+            if os.path.exists(candidate) and candidate not in bootlog_files:
+                bootlog_files.append(candidate)
+
+        if bootlog_files:
+            snippets = []
+            for bootlog_file in bootlog_files:
+                try:
+                    with open(bootlog_file, 'r') as bootlogfile:
+                        bootlines = "".join(bootlogfile.readlines()[-20:])
+                except OSError as err:
+                    bootlines = "<failed to read %s: %s>\n" % (bootlog_file, err)
+                snippets.append("--- %s ---\n%s" % (os.path.basename(bootlog_file), bootlines))
+            bb.plain('%s - FAILED - Last lines of QEMU boot logs:\n%s' % (pn, "\n".join(snippets)))
+        else:
+            bb.plain('%s - FAILED - QEMU boot logs not available at %s or %s.*' % (pn, bootlog, bootlog))
         bb.error('%s - FAILED - also check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True)
 
 def get_runtime_paths(d):


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (4 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
                   ` (31 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Marko <peter.marko@siemens.com>

Release information [1]:

OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate.
This release incorporates the following bug fixes and mitigations:
* Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)
* Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
* Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)
* Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
* Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
* Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
* Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
* Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)
* Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
* Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)
* Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

[1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-357-and-openssl-358-25-aug-2026

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit db81c1a42a0f552d9a8ec124f004ae2063d58c33)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb}              | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%)

diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
similarity index 99%
rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb
rename to meta/recipes-connectivity/openssl/openssl_3.5.8.bb
index 212879dfa35..cc148f07c7d 100644
--- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb
+++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
@@ -19,7 +19,7 @@ SRC_URI:append:class-nativesdk = " \
            file://environment.d-openssl.sh \
            "
 
-SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8"
+SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2"
 
 inherit lib_package multilib_header multilib_script ptest perlnative manpages
 MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (5 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
                   ` (30 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Marko <peter.marko@siemens.com>

Removed included patches and refresh remaining one.

Release Notes: [1]

Changes with APR-util 1.6.5

  *) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.

Changes with APR-util 1.6.4

  *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
     client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility memcached client
     This issue affects Apache Portable Runtime Utility: from 1.3.0
     through 1.6.3.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
     buffer overflow in APR redis client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility redis client.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
     Injection in apr_dbd_oracle (cve.mitre.org)
     Improper Neutralization of Special Elements used in an SQL
     Command ('SQL Injection') vulnerability in Apache Portable
     Runtime Utility via apr_dbd_oracle provider.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
     apr-util XML stack recursion crash (cve.mitre.org)
     A bug in APR-util version 1.6.3 (and earlier) allows a stack
     recursion attack against any library consumer which parses XML
     from untrusted sources and uses the apr_xml_quote_elem()
     function.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Younghyo Cho @ CISLab, SeoulTech

  *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
     timing attack (cve.mitre.org)
     APR-util versions 1.6.3 (and earlier) function
     apr_password_validate() was not constant-time with regards to
     hashes or passwords comparisons, potentially leaking their
     content via a side channel timing attack particularly on
     platforms without crypt() such as  Windows, BeOS, NetWare, or
     Android.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Michael Rowley <michael csirt.global>

  *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
     avoid producing an empty bucket.  PR 64273
     [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]

  *) apr_brigade: Metadata buckets are now ignored in
     apr_brigade_split_line, apr_brigade_flatten and
     apr_brigade_to_iovec, fixing possible undefined behaviour.  PR 68278
     [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]

  *) apr_crypto_openssl: Compatibility with OpenSSL 3.  [Yann Ylavic]

  *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
     on versions 1.1+. [Graham Leggett]

  *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
     [Lubos Uhliarik <luhliari redhat.com>]

  *) configure: Fix Berkeley DB detection with compilers enforcing
     strict C99 compliance.  PR 66396.
     [Florian Weimer <fweimer redhat.com>]

[1] https://github.com/apache/apr-util/blob/1.6.5/CHANGES

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit bb8e0e12c54c452ffb17ce600972edfa9455f459)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 ...le-function-prototype-warning-with-c.patch | 130 ------------------
 ...ion-Check-if-transform-is-supported-.patch |  37 -----
 .../apr/apr-util/configfix.patch              |   4 +-
 .../{apr-util_1.6.3.bb => apr-util_1.6.5.bb}  |   4 +-
 4 files changed, 3 insertions(+), 172 deletions(-)
 delete mode 100644 meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
 delete mode 100644 meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
 rename meta/recipes-support/apr/{apr-util_1.6.3.bb => apr-util_1.6.5.bb} (93%)

diff --git a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch b/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
deleted file mode 100644
index e523859927a..00000000000
--- a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
+++ /dev/null
@@ -1,130 +0,0 @@
-From 05afaf207eaff4c175198abd129ed1acde220df3 Mon Sep 17 00:00:00 2001
-From: Yann Ylavic <ylavic@apache.org>
-Date: Thu, 14 Mar 2024 15:52:25 +0000
-Subject: [PATCH] sdbm: Fix old style function prototype warning with clang
-
-This fixes the following warning with clang
-
-../dbm/sdbm/sdbm_pair.c:63:1: warning: a function definition without a prototype is
-deprecated in all versions of C and is not supported in C2x [-Wdeprecated-non-prototype]
-   63 | fitpair(pag, need)
-      | ^
-
-Upstream-Status: Backport [https://github.com/apache/apr-util/commit/073368a46fbe92995927258ae2fc97d3920872f2]
-Signed-off-by: Biswapriyo Nath <nathbappai@gmail.com>
-Submitted by: Biswapriyo Nath <nathbappai@gmail.com>
-Github: closes #47
-
-Merges r1912679 from ^/apr/apr/trunk
-
-git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.7.x@1916307 13f79535-47bb-0310-9956-ffa450edef68
-Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
----
- dbm/sdbm/sdbm_pair.c | 39 +++++++++------------------------------
- 1 file changed, 9 insertions(+), 30 deletions(-)
-
-diff --git a/dbm/sdbm/sdbm_pair.c b/dbm/sdbm/sdbm_pair.c
-index 50d7965..6ecaff6 100644
---- a/dbm/sdbm/sdbm_pair.c
-+++ b/dbm/sdbm/sdbm_pair.c
-@@ -60,9 +60,7 @@ static int seepair(char *, int, char *, int);
-  */
- 
- int
--fitpair(pag, need)
--char *pag;
--int need;
-+fitpair(char *pag, int need)
- {
- 	register int n;
- 	register int off;
-@@ -79,10 +77,7 @@ int need;
- }
- 
- void
--putpair(pag, key, val)
--char *pag;
--apr_sdbm_datum_t key;
--apr_sdbm_datum_t val;
-+putpair(char *pag, apr_sdbm_datum_t key, apr_sdbm_datum_t val)
- {
- 	register int n;
- 	register int off;
-@@ -108,9 +103,7 @@ apr_sdbm_datum_t val;
- }
- 
- apr_sdbm_datum_t
--getpair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+getpair(char *pag, apr_sdbm_datum_t key)
- {
- 	register int i;
- 	register int n;
-@@ -129,18 +122,14 @@ apr_sdbm_datum_t key;
- }
- 
- int
--duppair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+duppair(char *pag, apr_sdbm_datum_t key)
- {
- 	register short *ino = (short *) pag;
- 	return ino[0] > 0 && seepair(pag, ino[0], key.dptr, key.dsize) > 0;
- }
- 
- apr_sdbm_datum_t
--getnkey(pag, num)
--char *pag;
--int num;
-+getnkey(char *pag, int num)
- {
- 	apr_sdbm_datum_t key;
- 	register int off;
-@@ -159,9 +148,7 @@ int num;
- }
- 
- int
--delpair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+delpair(char *pag, apr_sdbm_datum_t key)
- {
- 	register int n;
- 	register int i;
-@@ -231,11 +218,7 @@ apr_sdbm_datum_t key;
-  * return 0 if not found.
-  */
- static int
--seepair(pag, n, key, siz)
--char *pag;
--register int n;
--register char *key;
--register int siz;
-+seepair(char *pag, register int n, register char *key, register int siz)
- {
- 	register int i;
- 	register int off = PBLKSIZ;
-@@ -251,10 +234,7 @@ register int siz;
- }
- 
- void
--splpage(pag, new, sbit)
--char *pag;
--char *new;
--long sbit;
-+splpage(char *pag, char *new, long sbit)
- {
- 	apr_sdbm_datum_t key;
- 	apr_sdbm_datum_t val;
-@@ -295,8 +275,7 @@ long sbit;
-  * this could be made more rigorous.
-  */
- int
--chkpage(pag)
--char *pag;
-+chkpage(char *pag)
- {
- 	register int n;
- 	register int off;
diff --git a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch b/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
deleted file mode 100644
index 261b78736f6..00000000000
--- a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
+++ /dev/null
@@ -1,37 +0,0 @@
-From 3a97f58cfb40fc1911bbfd067e8457a472613d75 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 18 Apr 2023 22:58:00 -0700
-Subject: [PATCH] test_transformation: Check if transform is supported before
- using it
-
-This helps in excluding these tests on systems where these are not
-available e.g. musl
-
-Upstream-Status: Submitted [https://bz.apache.org/bugzilla/show_bug.cgi?id=66570]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- test/testxlate.c | 8 ++++++--
- 1 file changed, 6 insertions(+), 2 deletions(-)
-
-diff --git a/test/testxlate.c b/test/testxlate.c
-index 6981eff..de00fa4 100644
---- a/test/testxlate.c
-+++ b/test/testxlate.c
-@@ -116,8 +116,12 @@ static void test_transformation(abts_case *tc, void *data)
-     }
- 
-     /* 4. Transformation using charset aliases */
--    one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p);
--    one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p);
-+    if (is_transform_supported(tc, "UTF-8", "UTF-7", p)) {
-+        one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p);
-+    }
-+    if (is_transform_supported(tc, "UTF-7", "UTF-8", p)) {
-+        one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p);
-+    }
- }
- 
- #endif /* APR_HAS_XLATE */
--- 
-2.40.0
-
diff --git a/meta/recipes-support/apr/apr-util/configfix.patch b/meta/recipes-support/apr/apr-util/configfix.patch
index dbb1148809b..4cc0ad79ae0 100644
--- a/meta/recipes-support/apr/apr-util/configfix.patch
+++ b/meta/recipes-support/apr/apr-util/configfix.patch
@@ -4,7 +4,7 @@ Index: apr-util-1.3.4/apu-config.in
 ===================================================================
 --- apr-util-1.3.4.orig/apu-config.in	2009-01-12 17:08:06.000000000 +0000
 +++ apr-util-1.3.4/apu-config.in	2009-01-12 17:09:00.000000000 +0000
-@@ -134,14 +134,7 @@
+@@ -139,14 +139,7 @@ while test $# -gt 0; do
      exit 0
      ;;
      --includes)
@@ -19,7 +19,7 @@ Index: apr-util-1.3.4/apu-config.in
      ;;
      --ldflags)
      flags="$flags $LDFLAGS"
-@@ -155,28 +148,10 @@
+@@ -160,28 +153,10 @@ while test $# -gt 0; do
      exit 0
      ;;
      --link-ld)
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.5.bb
similarity index 93%
rename from meta/recipes-support/apr/apr-util_1.6.3.bb
rename to meta/recipes-support/apr/apr-util_1.6.5.bb
index cb5465f8729..ba1e3359ff5 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.5.bb
@@ -11,12 +11,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=158aa0b1efe0c12f23d4b007ddb9a5db \
 
 SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \
            file://configfix.patch \
-	   file://0001-test_transformation-Check-if-transform-is-supported-.patch \
-	       file://0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch \
            file://run-ptest \
            "
 
-SRC_URI[sha256sum] = "2b74d8932703826862ca305b094eef2983c27b39d5c9414442e9976a9acf1983"
+SRC_URI[sha256sum] = "f43a1c8c79eef497a022ec6c99dddbdf57e42001da6ccbfae259631ed5aa2805"
 
 EXTRA_OECONF = "--with-apr=${STAGING_BINDIR_CROSS}/apr-1-config \
 		--without-odbc \


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (6 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
                   ` (29 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-13346

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed patch format]
---
 .../python/python3-pip/CVE-2026-13346.patch   | 206 ++++++++++++++++++
 .../python/python3-pip_26.0.1.bb              |   4 +-
 2 files changed, 209 insertions(+), 1 deletion(-)
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch

diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
new file mode 100644
index 00000000000..e800f29e304
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
@@ -0,0 +1,206 @@
+From 10dfb6b9005484578b386f64b9f36982e3dc6679 Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Tue, 30 Jun 2026 21:52:39 -0400
+Subject: [PATCH] Fix Link.filename decoding URL path twice (#14110)
+
+Link already percent-decodes the URL path into `self._path`, but
+`Link.filename` decoded the basename again, so a doubly-encoded
+separator was decoded twice: `%252F` became `%2F` in `__init__`, then
+`/` in `filename`, turning the single component `a%2Fb.whl` into
+`a/b.whl`.
+
+Drop the second decode, and add a `join_within_directory` helper so the
+download-path joins treat the name as a single path component.
+
+CVE: CVE-2026-13346
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679]
+
+Backport Changes:
+- Omit news/14110.bugfix.rst and tests/unit/test_link.py because these
+  paths are absent from the pip 26.0.1 PyPI sdist used by this recipe.
+  All runtime-source changes are unchanged from upstream.
+
+(cherry picked from commit 10dfb6b9005484578b386f64b9f36982e3dc6679)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/models/link.py        | 63 ++++++++++++++++++++-----
+ src/pip/_internal/network/download.py   | 20 ++++++--
+ src/pip/_internal/operations/prepare.py |  6 +--
+ 3 files changed, 69 insertions(+), 20 deletions(-)
+
+diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py
+index 200ec34c5..1a6439873 100644
+--- a/src/pip/_internal/models/link.py
++++ b/src/pip/_internal/models/link.py
+@@ -14,6 +14,7 @@ from dataclasses import dataclass
+ from typing import (
+     Any,
+     NamedTuple,
++    NewType,
+ )
+ 
+ from pip._internal.exceptions import InvalidEggFragment
+@@ -31,6 +32,49 @@ from pip._internal.utils.urls import path_to_url, url_to_path
+ logger = logging.getLogger(__name__)
+ 
+ 
++# A single path component: percent-decoded once and reduced to a basename, so it
++# contains no path separator and is not a ``.`` or ``..`` reference. The empty
++# string means "no component".
++PathComponent = NewType("PathComponent", str)
++
++
++def _to_path_component(name: str) -> PathComponent:
++    """Reduce ``name`` to a single path component, or ``""`` if it has none.
++
++    ``os.path.basename`` drops any directory part, drive letter, or separator;
++    a ``.``, ``..``, or empty result is not a component and becomes ``""``.
++    """
++    name = os.path.basename(name)
++    if name in ("", os.curdir, os.pardir):
++        return PathComponent("")
++
++    return PathComponent(name)
++
++
++def as_path_component(name: str) -> PathComponent:
++    """Like ``_to_path_component`` but reject the empty result.
++
++    Use where a file is about to be written, so a missing name is an error
++    rather than a silent fallback to the directory itself.
++    """
++    component = _to_path_component(name)
++    if not component:
++        raise ValueError(f"Unexpected file name derived from URL: {name!r}")
++
++    return component
++
++
++def join_within_directory(directory: str, component: PathComponent) -> str:
++    """Join a single path ``component`` onto ``directory``.
++
++    ``component`` is a :data:`PathComponent`, so by type it has no separator and
++    is not a ``.`` or ``..`` reference; the result can never escape ``directory``.
++    Requiring ``PathComponent`` rather than ``str`` lets the type checker enforce
++    at the call site that the name was reduced to a safe component beforehand.
++    """
++    return os.path.join(directory, component)
++
++
+ # Order matters, earlier hashes have a precedence over later hashes for what
+ # we will pick to use.
+ _SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5")
+@@ -423,18 +467,13 @@ class Link:
+         return redact_auth_from_url(self.url)
+ 
+     @property
+-    def filename(self) -> str:
+-        path = self.path.rstrip("/")
+-        name = posixpath.basename(path)
+-        if not name:
+-            # Make sure we don't leak auth information if the netloc
+-            # includes a username and password.
+-            netloc, user_pass = split_auth_from_netloc(self.netloc)
+-            return netloc
+-
+-        name = urllib.parse.unquote(name)
+-        assert name, f"URL {self._url!r} produced no filename"
+-        return name
++    def filename(self) -> PathComponent:
++        name = _to_path_component(posixpath.basename(self.path.rstrip("/")))
++        if name:
++            return name
++
++        # No component in the path; fall back to the netloc, dropping any auth.
++        return _to_path_component(split_auth_from_netloc(self.netloc)[0])
+ 
+     @property
+     def file_path(self) -> str:
+diff --git a/src/pip/_internal/network/download.py b/src/pip/_internal/network/download.py
+index 26966423f..fa71c75a3 100644
+--- a/src/pip/_internal/network/download.py
++++ b/src/pip/_internal/network/download.py
+@@ -20,7 +20,12 @@ from pip._vendor.urllib3.exceptions import ReadTimeoutError
+ from pip._internal.cli.progress_bars import BarType, get_download_progress_renderer
+ from pip._internal.exceptions import IncompleteDownloadError, NetworkConnectionError
+ from pip._internal.models.index import PyPI
+-from pip._internal.models.link import Link
++from pip._internal.models.link import (
++    Link,
++    PathComponent,
++    as_path_component,
++    join_within_directory,
++)
+ from pip._internal.network.cache import SafeFileCache, is_from_cache
+ from pip._internal.network.session import CacheControlAdapter, PipSession
+ from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks
+@@ -117,11 +122,14 @@ def parse_content_disposition(content_disposition: str, default_filename: str) -
+     return filename or default_filename
+ 
+ 
+-def _get_http_response_filename(resp: Response, link: Link) -> str:
++def _get_http_response_filename(resp: Response, link: Link) -> PathComponent:
+     """Get an ideal filename from the given HTTP response, falling back to
+     the link filename if not provided.
++
++    The result is validated as a single path component, so it can be joined onto
++    a download directory without escaping it.
+     """
+-    filename = link.filename  # fallback
++    filename: str = link.filename  # fallback
+     # Have a look at the Content-Disposition header for a better guess
+     content_disposition = resp.headers.get("content-disposition")
+     if content_disposition:
+@@ -135,7 +143,7 @@ def _get_http_response_filename(resp: Response, link: Link) -> str:
+         ext = os.path.splitext(resp.url)[1]
+         if ext:
+             filename += ext
+-    return filename
++    return as_path_component(filename)
+ 
+ 
+ @dataclass
+@@ -188,7 +196,9 @@ class Downloader:
+         resp = self._http_get(link)
+         download_size = _get_http_response_size(resp)
+ 
+-        filepath = os.path.join(location, _get_http_response_filename(resp, link))
++        filepath = join_within_directory(
++            location, _get_http_response_filename(resp, link)
++        )
+         with open(filepath, "wb") as content_file:
+             download = _FileDownload(link, content_file, download_size)
+             self._process_response(download, resp)
+diff --git a/src/pip/_internal/operations/prepare.py b/src/pip/_internal/operations/prepare.py
+index 67f9ee950..d260d15a2 100644
+--- a/src/pip/_internal/operations/prepare.py
++++ b/src/pip/_internal/operations/prepare.py
+@@ -29,7 +29,7 @@ from pip._internal.exceptions import (
+ from pip._internal.index.package_finder import PackageFinder
+ from pip._internal.metadata import BaseDistribution, get_metadata_distribution
+ from pip._internal.models.direct_url import ArchiveInfo
+-from pip._internal.models.link import Link
++from pip._internal.models.link import Link, join_within_directory
+ from pip._internal.models.wheel import Wheel
+ from pip._internal.network.download import Downloader
+ from pip._internal.network.lazy_wheel import (
+@@ -201,7 +201,7 @@ def _check_download_dir(
+     """Check download_dir for previously downloaded file with correct hash
+     If a correct file is found return its path else None
+     """
+-    download_path = os.path.join(download_dir, link.filename)
++    download_path = join_within_directory(download_dir, link.filename)
+ 
+     if not os.path.exists(download_path):
+         return None
+@@ -683,7 +683,7 @@ class RequirementPreparer:
+             # No distribution was downloaded for this requirement.
+             return
+ 
+-        download_location = os.path.join(self.download_dir, link.filename)
++        download_location = join_within_directory(self.download_dir, link.filename)
+         if not os.path.exists(download_location):
+             shutil.copy(req.local_file_path, download_location)
+             download_path = display_path(download_location)
+-- 
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
index 9640bc926aa..3ff6cd39cd2 100644
--- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
+++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
@@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=63ec52baf95163b597008bb46db68030 \
 
 inherit pypi python_setuptools_build_meta
 
-SRC_URI += "file://no_shebang_mangling.patch"
+SRC_URI += "file://no_shebang_mangling.patch \
+            file://CVE-2026-13346.patch \
+           "
 
 SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (7 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
                   ` (28 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Tatrai <peter.tatrai.ext@siemens.com>

When SDKMACHINE is set to i686 or i586, nativesdk binaries are compiled
as 32-bit. Without -D_TIME_BITS=64 and -D_FILE_OFFSET_BITS=64, stat()
and time-related syscalls use 32-bit types, causing EOVERFLOW on
filesystems with large inode numbers (e.g. container overlay filesystems)
and Y2038 issues.

Add SDK_CC_ARCH appends for class-nativesdk:i686 and class-nativesdk:i586
using GLIBC_64BIT_TIME_FLAGS, mirroring how target architectures are
handled.

Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>"
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit d9f62a45555673842021d5746437e66c40d3f3cc)
Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/conf/distro/include/time64.inc | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/meta/conf/distro/include/time64.inc b/meta/conf/distro/include/time64.inc
index 19177b1f3cc..a2fe03354d5 100644
--- a/meta/conf/distro/include/time64.inc
+++ b/meta/conf/distro/include/time64.inc
@@ -38,6 +38,16 @@ TARGET_CC_ARCH:append:x86 = "${@bb.utils.contains('TUNE_FEATURES', 'm32', '${GLI
 GLIBC_64BIT_TIME_FLAGS:pn-glibc = ""
 GLIBC_64BIT_TIME_FLAGS:pn-glibc-testsuite = ""
 
+# Apply the same flags to nativesdk packages when building for a 32-bit SDK
+# host (i686, i586).
+SDK_CC_ARCH:append:class-nativesdk:i686 = "${GLIBC_64BIT_TIME_FLAGS}"
+SDK_CC_ARCH:append:class-nativesdk:i586 = "${GLIBC_64BIT_TIME_FLAGS}"
+
+# nativesdk-pseudo wraps both 32-bit and 64-bit libc calls; enabling LFS flags
+# causes duplicate symbol errors (e.g. creat64, fopen64) on i686 because glibc
+# aliases the non-LFS names to their 64-bit counterparts via macros.
+GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-pseudo = ""
+
 # Caused by the flags exceptions above
 INSANE_SKIP:append:pn-glibc = " 32bit-time"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 10/38] grub: disable grub-protect for native builds
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (8 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
                   ` (27 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Himanshu Jadon <hjadon@cisco.com>

grub-native fails on hosts where libtasn1 headers are not available
when configure tries to build grub-protect:

  util/grub-protect.c:25:10: fatal error:
  libtasn1.h: No such file or directory

grub-protect is an optional utility for sealing disk-encryption keys
using the TPM2 key protector. It is not used by the GRUB native tools
staged for Yocto recipe execution.

Disable grub-protect for class-native so grub-native does not depend on
libtasn1. This keeps the native build focused on the tools needed by
Yocto and avoids adding another native library dependency only for an
unused utility.

Target and nativesdk builds keep the upstream default, so image and SDK
behaviour is unchanged.

Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 9290ca0517e5a8888ee8a695a87c0d7e7b5ea377)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-bsp/grub/grub2.inc | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-bsp/grub/grub2.inc b/meta/recipes-bsp/grub/grub2.inc
index 0656489ead3..466c772e5bf 100644
--- a/meta/recipes-bsp/grub/grub2.inc
+++ b/meta/recipes-bsp/grub/grub2.inc
@@ -73,6 +73,8 @@ EXTRA_OECONF = "--with-platform=${GRUBPLATFORM} \
                 --disable-werror \
 "
 
+EXTRA_OECONF:append:class-native = " --disable-grub-protect"
+
 PACKAGECONFIG ??= ""
 PACKAGECONFIG[grub-mount] = "--enable-grub-mount,--disable-grub-mount,fuse"
 PACKAGECONFIG[device-mapper] = "--enable-device-mapper,--disable-device-mapper,libdevmapper"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (9 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
                   ` (26 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Pratik Farkase <pratik.farkase@est.tech>

The 'pgrep match against full process name' test uses pgrep -f with a
regex pattern close to ARG_MAX in size (~100KB). This intermittently
fails on qemuriscv64 where the process cmdline may not be fully visible
in /proc/<pid>/cmdline at the time pgrep reads it, or the large regex
match times out under TCG emulation.

Skip this single test case while keeping all other 30+ pgrep tests
which are reliable.

[YOCTO #16290]

Signed-off-by: Pratik Farkase <pratik.farkase@est.tech>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit b9166b8fda40bece8c2007ac1f06d51693ac617a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 ...p-pgrep-full-process-name-match-test.patch | 39 +++++++++++++++++++
 meta/recipes-extended/procps/procps_4.0.6.bb  |  1 +
 2 files changed, 40 insertions(+)
 create mode 100644 meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch

diff --git a/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
new file mode 100644
index 00000000000..43c930ce086
--- /dev/null
+++ b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
@@ -0,0 +1,39 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Pratik Farkase <pratik.farkase@est.tech>
+Date: Mon, 17 Aug 2026 10:00:00 +0000
+Subject: [PATCH] testsuite: skip pgrep full process name match test
+
+The "pgrep match against full process name" test uses pgrep -f with a
+regex pattern close to ARG_MAX in size (~100KB). This intermittently
+fails on qemuriscv64 where the process cmdline may not be fully visible
+in /proc/<pid>/cmdline at the time pgrep reads it, or the large regex
+match times out under TCG emulation.
+
+Skip this single test case while keeping all other pgrep tests which
+are reliable.
+
+https://bugzilla.yoctoproject.org/show_bug.cgi?id=16290
+
+Upstream-Status: Inappropriate [OE-ptest specific: fails only under QEMU TCG emulation]
+Signed-off-by: Pratik Farkase <pratik.farkase@est.tech>
+---
+ testsuite/pgrep.test/pgrep.exp | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/testsuite/pgrep.test/pgrep.exp b/testsuite/pgrep.test/pgrep.exp
+index 54e75df..66edbaa 100644
+--- a/testsuite/pgrep.test/pgrep.exp
++++ b/testsuite/pgrep.test/pgrep.exp
+@@ -35,9 +35,9 @@ set test "pgrep with : delimiter"
+ spawn $pgrep -d : $testproc_comm
+ expect_pass "$test" "^${testproc1_pid}:${testproc2_pid}\\s*$"
+ 
+-set test "pgrep match against full process name"
+-spawn $pgrep -f "$testproc_path\\s+$testproc_arg_str"
+-expect_pass "$test" "^$testproc1_pid\\s*$"
++# Skip: intermittent failure on riscv64 - pgrep -f with large ARG_MAX
++# patterns can fail under QEMU emulation (timing/cmdline visibility race)
++untested "pgrep match against full process name"
+ 
+ set test "pgrep with matching gid"
+ spawn $pgrep -G $gid $testproc_comm
diff --git a/meta/recipes-extended/procps/procps_4.0.6.bb b/meta/recipes-extended/procps/procps_4.0.6.bb
index a9ec3f39d6c..541a8cd99cd 100644
--- a/meta/recipes-extended/procps/procps_4.0.6.bb
+++ b/meta/recipes-extended/procps/procps_4.0.6.bb
@@ -15,6 +15,7 @@ inherit autotools gettext pkgconfig update-alternatives ptest
 SRC_URI = "git://gitlab.com/procps-ng/procps.git;protocol=https;branch=master;tag=v${PV} \
            file://sysctl.conf \
            file://0001-tests-Disable-twice-total-pmap-X-tests.patch \
+           file://0001-testsuite-skip-pgrep-full-process-name-match-test.patch \
            file://run-ptest \
            "
 SRCREV = "4dafddf4c3f4646caa517f039a2307e92657ec93"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (10 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
                   ` (25 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73072

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73072.patch            | 64 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 65 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73072.patch b/meta/recipes-support/vim/files/CVE-2026-73072.patch
new file mode 100644
index 00000000000..0ae3b2b49e6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73072.patch
@@ -0,0 +1,64 @@
+From 05c41c922309c7a11b6ec2f124be66551c90d66a Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Fri, 24 Jul 2026 00:58:37 +0900
+Subject: [PATCH] patch 9.2.0846: [security]: heap buffer overflow in
+ set_sofo()
+
+Problem:  [security]: heap buffer overflow in set_sofo()
+          (Yazan Balawneh)
+Solution: Reset sl_sal_first (Yasuhiro Matsumoto).
+
+A crafted spell file with an empty SN_SAL section before an SN_SOFO
+section reaches set_sofo() with sl_sal_first[] already set to -1 by
+set_sal_first(). The counting loop then under-counts colliding
+multi-byte "from" characters, allocates an undersized list and writes
+past its end.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73072
+Upstream-Status: Backport [https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/spellfile.c                | 4 +++-
+ src/testdir/test_spellfile.vim | 5 +++++
+ 2 files changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/src/spellfile.c b/src/spellfile.c
+index b3ee9c0d63..a9f7e83752 100644
+--- a/src/spellfile.c
++++ b/src/spellfile.c
+@@ -1433,7 +1433,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to)
+ 	gap->ga_len = 256;
+ 
+ 	// First count the number of items for each list.  Temporarily use
+-	// sl_sal_first[] for this.
++	// sl_sal_first[] for this.  Reset it first: a preceding SN_SAL section
++	// may have set the entries to -1 via set_sal_first().
++	vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256);
+ 	for (p = from, s = to; *p != NUL && *s != NUL; )
+ 	{
+ 	    c = mb_cptr2char_adv(&p);
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 3a93883b4d..0b0cf42066 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -319,6 +319,11 @@ func Test_spellfile_format_error()
+   " SN_SOFO: multi-byte characters in sofofrom and sofoto
+   call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '')
+ 
++  " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters
++  " sharing the same low byte.  A preceding SN_SAL poisons sl_sal_first[], so
++  " without a reset set_sofo() under-counts and writes out of bounds.
++  call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '')
++
+   " SN_COMPOUND: compmax is less than 2
+   call Spellfile_Test(0z08000000000101, 'E759:')
+ 
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 1da47d92430..34d45079061 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-59856.patch \
            file://CVE-2026-59857.patch \
            file://CVE-2026-59858.patch \
+           file://CVE-2026-73072.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (11 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
                   ` (24 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73073

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73073.patch            | 105 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 106 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73073.patch b/meta/recipes-support/vim/files/CVE-2026-73073.patch
new file mode 100644
index 00000000000..5defa7339e6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73073.patch
@@ -0,0 +1,105 @@
+From 2f628d8104958fa7421664f792ca6d4f7a39a10f Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Fri, 17 Jul 2026 09:11:42 +0900
+Subject: [PATCH] patch 9.2.0845: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem:  [security]: arbitrary Ex command execution during C
+          omni-completion (Threonine)
+Solution: Match tags typeref literally to block Ex command injection
+          (Yasuhiro Matsumoto).
+
+Escaping only "/" and "\" left the typeref able to break out of the
+:vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern
+skipping fail, and the parser then treats a following "|" as a command
+separator, so the tag value runs as Ex commands during C omni-completion.
+Match the field literally with \V so no regex metacharacter can affect
+pattern parsing.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73073
+Upstream-Status: Backport [https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/autoload/ccomplete.vim        |  5 ++++-
+ src/testdir/test_plugin_ccomplete.vim | 26 ++++++++++++++++++++++++++
+ src/version.c                         |  4 ++++
+ 3 files changed, 34 insertions(+), 1 deletion(-)
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index dc3388b524..593789a84f 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -599,8 +599,11 @@ def StructMembers( # {{{1
+       if complete_check()
+         return []
+       endif
++      # Match "typename" literally (\V): escaping alone is not enough, as e.g.
++      # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of
++      # the tag value is then parsed as Ex commands.
+       execute 'silent! keepjumps noautocmd '
+-        .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
++        .. n .. 'vimgrep ' .. '/\t\V' .. escape(typename, '/\') .. '\m\(\t\|$\)/j '
+         .. fnames
+ 
+       qflist = getqflist()
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+index a635bd50bd..c1754d17c1 100644
+--- a/src/testdir/test_plugin_ccomplete.vim
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref()
+   unlet! g:ccomplete_injected
+ endfunc
+ 
++" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed
++" "[" makes vimgrep's pattern skipping fail, and the command parser then treats
++" the first "|" as a command separator.  The typeref must be matched literally.
++func Test_ccomplete_no_exec_via_typeref_bracket()
++  CheckUnix
++  let sentinel = tempname()
++  call delete(sentinel)
++  let tagsfile = s:WriteTags([
++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:[|call system('touch " .. sentinel .. "')|####",
++        \ ])
++
++  let save_tags = &tags
++  let &tags = tagsfile
++
++  new
++  call ccomplete#Complete(1, '')
++  call ccomplete#Complete(0, 'myvar.x')
++
++  call assert_false(filereadable(sentinel),
++        \ 'typeref field was executed as an Ex command during omni-completion')
++
++  bwipe!
++  let &tags = save_tags
++  call delete(sentinel)
++endfunc
++
+ " A legitimate typeref must still drive struct-member completion: escaping the
+ " field value must not break the normal path.
+ func Test_ccomplete_typeref_completion_still_works()
+diff --git a/src/version.c b/src/version.c
+index 92cd53129e..26e4e026c3 100644
+--- a/src/version.c
++++ b/src/version.c
+@@ -734,6 +734,10 @@ static char *(features[]) =
+ 
+ static int included_patches[] =
+ {   /* Add new patch number below this line */
++/**/
++    845,
++/**/
++    846,
+ /**/
+     736,
+ /**/
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 34d45079061..7ab7a405ffc 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -40,6 +40,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-59857.patch \
            file://CVE-2026-59858.patch \
            file://CVE-2026-73072.patch \
+           file://CVE-2026-73073.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (12 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
                   ` (23 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73074

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73074.patch            | 115 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 116 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73074.patch b/meta/recipes-support/vim/files/CVE-2026-73074.patch
new file mode 100644
index 00000000000..896298b7032
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73074.patch
@@ -0,0 +1,115 @@
+From a9336b476fd1a182e3f79b5f83c0ffb04f8a922b Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Thu, 23 Jul 2026 20:14:13 +0000
+Subject: [PATCH] patch 9.2.0841: [security]: heap overflow when adding > 65535
+ text properties
+
+Problem:  [security]: heap overflow when adding > 65535 text properties
+          (Wang1rrr).
+Solution: Verify that the number of text properties falls within the
+          limit (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-hm4g-pjfx-m27j
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73074
+Upstream-Status: Backport [https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/errors.h                  |  4 ++++
+ src/po/vim.pot                |  3 +++
+ src/testdir/test_textprop.vim | 18 ++++++++++++++++++
+ src/textprop.c                |  7 +++++++
+ src/version.c                 |  2 ++
+ 5 files changed, 34 insertions(+)
+
+diff --git a/src/errors.h b/src/errors.h
+index 53e5b1dda6..1682c8587c 100644
+--- a/src/errors.h
++++ b/src/errors.h
+@@ -3812,3 +3812,7 @@ EXTERN char e_gethostbyname_in_channel_listen[]
+ EXTERN char e_cannot_create_pipes[]
+ 	INIT(= N_("E1575: Cannot create pipes"));
+ #endif
++#ifdef FEAT_PROP_POPUP
++EXTERN char e_too_many_text_properties_on_a_single_line[]
++	INIT(= N_("E1580: Too many text properties on a single line"));
++#endif
+diff --git a/src/po/vim.pot b/src/po/vim.pot
+index b2e3b0f647..aed7d833cf 100644
+--- a/src/po/vim.pot
++++ b/src/po/vim.pot
+@@ -8859,6 +8859,9 @@ msgstr ""
+ msgid "E1575: Cannot create pipes"
+ msgstr ""
+ 
++msgid "E1580: Too many text properties on a single line"
++msgstr ""
++
+ #. type of cmdline window or 0
+ #. result of cmdline window or 0
+ #. buffer of cmdline window or NULL
+diff --git a/src/testdir/test_textprop.vim b/src/testdir/test_textprop.vim
+index f94acfc97c..a293363a8a 100644
+--- a/src/testdir/test_textprop.vim
++++ b/src/testdir/test_textprop.vim
+@@ -4907,4 +4907,22 @@ func Test_textprop_materialize_list()
+ 	call assert_equal([], prop_list(1, #{ids: 3->range()}))
+ endfunc
+ 
++" Adding more than 65535 text properties to one line must be rejected instead
++" of wrapping the uint16_t property count and overflowing the allocation.
++func Test_prop_add_over_uint16_max()
++  CheckNotAsan
++  CheckNotValgrind
++  new
++  call setline(1, 'x')
++  call prop_type_add('overflow', {})
++  for _ in range(0xffff)
++    call prop_add(1, 1, {'type': 'overflow', 'length': 0})
++  endfor
++  call assert_equal(0xffff, prop_list(1)->len())
++  call assert_fails("call prop_add(1, 1, {'type': 'overflow', 'length': 0})", 'E1580:')
++  call assert_equal(0xffff, prop_list(1)->len())
++  call prop_type_delete('overflow')
++  bwipe!
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 5959ecc45f..fe453244c1 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -758,6 +758,13 @@ prop_add_one(
+ 	proplen = get_text_props(buf, lnum, &props, TRUE);
+ 	textlen = ml_get_buf_len(buf, lnum) + 1;
+ 
++	// prop_count is a uint16_t; stop before proplen + 1 wraps to zero.
++	if (proplen >= 0xffff)
++	{
++	    emsg(_(e_too_many_text_properties_on_a_single_line));
++	    goto theend;
++	}
++
+ 	if (lnum == start_lnum)
+ 	    col = start_col;
+ 	else
+diff --git a/src/version.c b/src/version.c
+index 26e4e026c3..2a056f9da5 100644
+--- a/src/version.c
++++ b/src/version.c
+@@ -734,6 +734,8 @@ static char *(features[]) =
+ 
+ static int included_patches[] =
+ {   /* Add new patch number below this line */
++/**/
++    841,
+ /**/
+     845,
+ /**/
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 7ab7a405ffc..9dda2c0be55 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-59858.patch \
            file://CVE-2026-73072.patch \
            file://CVE-2026-73073.patch \
+           file://CVE-2026-73074.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (13 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
                   ` (22 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73076

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73076.patch            | 167 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 168 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73076.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73076.patch b/meta/recipes-support/vim/files/CVE-2026-73076.patch
new file mode 100644
index 00000000000..5f5c92b1681
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73076.patch
@@ -0,0 +1,167 @@
+From 581a2f3ac9c6f96a26324f6b2c8c11415fd0d452 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Fri, 24 Jul 2026 17:43:51 +0200
+Subject: [PATCH] patch 9.2.0847: [security]: vimball: code execution via
+ .VimballRecord file
+
+Problem:  [security]: vimball: code execution via .VimballRecord file
+          (tdjackey)
+Solution: Forbid arbitrary commands, fix broken directory deletion code,
+          refactor code
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-r22p-fhw4-84p2
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73076
+Upstream-Status: Backport [https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/autoload/vimball.vim        | 50 ++++++++++++++++++++---------
+ src/testdir/test_plugin_vimball.vim | 16 ++++++++-
+ 2 files changed, 50 insertions(+), 16 deletions(-)
+
+diff --git a/runtime/autoload/vimball.vim b/runtime/autoload/vimball.vim
+index d661ded631..20ce55cd69 100644
+--- a/runtime/autoload/vimball.vim
++++ b/runtime/autoload/vimball.vim
+@@ -20,9 +20,9 @@ if &cp || exists("g:loaded_vimball")
+  finish
+ endif
+ let g:loaded_vimball = "v37"
+-if v:version < 704
++if v:version < 900
+  echohl WarningMsg
+- echo "***warning*** this version of vimball needs vim 7.4"
++ echo "***warning*** this version of vimball needs vim 9.0"
+  echohl Normal
+  finish
+ endif
+@@ -237,6 +237,12 @@ fun! vimball#Vimball(really,...)
+      bw! Vimball
+      call s:ChgDir(curdir)
+      return
++   elseif fname =~? '\%(^\|/\)\.VimballRecord$'
++     echomsg "(Vimball) Forbidding .VimballRecord filename, aborting..."
++     exe "tabn ".curtabnr
++     bw! Vimball
++     call s:ChgDir(curdir)
++     return
+    endif
+ 
+    if a:really
+@@ -264,7 +270,7 @@ fun! vimball#Vimball(really,...)
+      let fnamebuf = substitute(fnamebuf,'^.\{-}/\(.*\)$','\1','')
+      if !isdirectory(dirname)
+       call mkdir(dirname)
+-      call s:RecordInVar(home,"rmdir('".dirname."')")
++      call s:RecordDirInVar(dirname)
+      endif
+     endwhile
+    endif
+@@ -295,7 +301,7 @@ fun! vimball#Vimball(really,...)
+       exe "silent w! ".fnameescape(fnamepath)
+     endif
+     echo "wrote ".fnameescape(fnamepath)
+-    call s:RecordInVar(home,"call delete('".fnamepath."')")
++    call s:RecordInVar(fnamepath)
+     endif
+ 
+     " return to tab with vimball
+@@ -394,10 +400,17 @@ fun! vimball#RmVimball(...)
+     endif
+     let s:VBRstring= substitute(exestring,'call delete(','','g')
+     let s:VBRstring= substitute(s:VBRstring,"[')]",'','g')
+-    sil! keepalt keepjumps exe exestring
++    let nr_files= 0
++    for line in split(exestring, '|')
++      if line !~ '^call delete(''[^'']\{-}''\(,"d"\)\?)$'
++        echomsg "ignoring .VimballRecord entry: " line
++      else
++        sil! keepalt keepjumps exe line
++        let nr_files+= 1
++      endif
++    endfor
+     sil! keepalt keepjumps d
+-    let exestring= strlen(substitute(exestring,'call delete(.\{-})|\=',"D","g"))
+-    echomsg "removed ".exestring." files"
++    echomsg "removed ".nr_files." files"
+    else
+     let s:VBRstring= ''
+     let curfile    = substitute(curfile,'\.vmb','','')
+@@ -539,13 +552,20 @@ fun! s:ChgDir(newdir)
+ endfun
+ 
+ " ---------------------------------------------------------------------
+-" s:RecordInVar: record a un-vimball command in the .VimballRecord file {{{2
+-fun! s:RecordInVar(home,cmd)
++" s:RecordInVar: record a un-vimball file deletion in the .VimballRecord file {{{2
++fun! s:RecordInVar(file)
+   if !exists("s:recordfile")
+-   let s:recordfile= a:cmd
+-  else
+-   let s:recordfile= s:recordfile."|".a:cmd
++    let s:recordfile=[]
++  endif
++  call add(s:recordfile, $'call delete({string(a:file)})')
++endfun
++
++" s:RecordDirInVar: record a un-vimball dir deletion in the .VimballRecord file {{{2
++fun! s:RecordDirInVar(dir)
++  if !exists("s:recorddir")
++    let s:recorddir = []
+   endif
++  call add(s:recorddir, $'call delete({string(a:dir)},"d")')
+ endfun
+ 
+ " ---------------------------------------------------------------------
+@@ -566,11 +586,11 @@ fun! s:RecordInFile(home)
+    setlocal ma
+    $
+    if exists("s:recordfile") && exists("s:recorddir")
+-    let cmd= cmd.s:recordfile."|".s:recorddir
++    let cmd= cmd.join(s:recordfile, '|')."|".join(s:recorddir, '|')
+    elseif exists("s:recorddir")
+-    let cmd= cmd.s:recorddir
++    let cmd= cmd.join(s:recorddir, '|')
+    elseif exists("s:recordfile")
+-    let cmd= cmd.s:recordfile
++    let cmd= cmd.join(s:recordfile, '|')
+    else
+     return
+    endif
+diff --git a/src/testdir/test_plugin_vimball.vim b/src/testdir/test_plugin_vimball.vim
+index 2d5b4ba768..8025846694 100644
+--- a/src/testdir/test_plugin_vimball.vim
++++ b/src/testdir/test_plugin_vimball.vim
+@@ -65,7 +65,7 @@ func Test_vimball_basic()
+   call assert_true(filereadable('.VimballRecord'))
+   let record = readfile('.VimballRecord')
+   call assert_equal(1, record->len())
+-  call assert_match('^Xtest.vmb: rmdir.*call delete(', record[0])
++  call assert_match('^Xtest.vmb: call delete(''.\{-}'')|call delete(''.\{-}'',"d")$', record[0])
+   call s:teardown()
+ endfunc
+ 
+@@ -83,3 +83,17 @@ func Test_vimball_path_traversal()
+   call assert_false(filereadable('../XVimball/Xtest.txt'))
+   call s:teardown()
+ endfunc
++
++func Test_vimball_VimballRecord_filenames()
++  call s:Mkvimball()
++  call delete('XVimball', 'rf')
++  sp Xtest.vmb
++  4s#.*\ze\t#.VimballRecord#
++  so %
++  call feedkeys("\<cr>", "it")
++
++  let mess = execute(':mess')->split('\n')[-1]
++  call assert_match('(Vimball) Forbidding .VimballRecord filename.* aborting\.\.\.', mess)
++  call assert_false(filereadable('.VimballRecord'))
++  call s:teardown()
++endfunc
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 9dda2c0be55..f0524ba7300 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-73072.patch \
            file://CVE-2026-73073.patch \
            file://CVE-2026-73074.patch \
+           file://CVE-2026-73076.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (14 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
                   ` (21 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73077

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73077.patch            | 105 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 106 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73077.patch b/meta/recipes-support/vim/files/CVE-2026-73077.patch
new file mode 100644
index 00000000000..41a9fdb1586
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73077.patch
@@ -0,0 +1,105 @@
+From c5a82fe013e73c98004ad7cd4f906b1ad1ed610e Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Thu, 23 Jul 2026 19:13:15 +0000
+Subject: [PATCH] patch 9.2.0839: [security]: arbitrary code execution via
+ keyword lookup
+
+Problem:  [security]: arbitrary code execution via keyword lookup in
+          sh.vim, zsh.vim and ps1.vim filetype plugin
+          (manus-use)
+Solution: For powershell, quote the commands using single quotes, for
+          sh/zsh pass the argument as a separate list item to term_start()/system()
+          (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73077
+Upstream-Status: Backport [https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/ftplugin/ps1.vim | 5 +++--
+ runtime/ftplugin/sh.vim  | 5 +++--
+ runtime/ftplugin/zsh.vim | 8 ++++----
+ 3 files changed, 10 insertions(+), 8 deletions(-)
+
+diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim
+index f1fe78df4c..9ff764a282 100644
+--- a/runtime/ftplugin/ps1.vim
++++ b/runtime/ftplugin/ps1.vim
+@@ -6,6 +6,7 @@
+ "              2024 May 23 by Riley Bruins <ribru17@gmail.com> ('commentstring')
+ "              2024 Sep 19 by Konfekt (simplify keywordprg #15696)
+ "              2025 Jul 22 by phanium (use :hor term #17822)
++"              2026 Jul 10 by Vim Project (quote K argument, prevent command injection)
+ 
+ " Only do this when not done yet for this buffer
+ if exists("b:did_ftplugin") | finish | endif
+@@ -52,9 +53,9 @@ endif
+ 
+ if exists('s:pwsh_cmd')
+   if exists(':terminal') == 2
+-    command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full "<args>"' . (executable('less') ? ' | less' : '')
++    command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')])
+   else
+-    command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full <args>')
++    command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'"])
+   endif
+   setlocal keywordprg=:GetHelp
+   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp"
+diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim
+index 18cd219cdc..45e6f44fcf 100644
+--- a/runtime/ftplugin/sh.vim
++++ b/runtime/ftplugin/sh.vim
+@@ -8,6 +8,7 @@
+ "			2024 Dec 29 by Vim Project (improve setting shellcheck compiler)
+ "			2025 Mar 09 by Vim Project (set b:match_skip)
+ "			2025 Jul 22 by phanium (use :hor term #17822)
++"			2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection)
+ 
+ if exists("b:did_ftplugin")
+   finish
+@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0))
+ 
+ if s:is_bash
+   if exists(':terminal') == 2
+-    command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "<args>" 2>/dev/null || man "<args>""'
++    command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', <q-args>])
+   else
+-    command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help <args>" 2>/dev/null || MANPAGER= man "<args>"')
++    command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', <q-args>])
+   endif
+   setlocal keywordprg=:ShKeywordPrg
+   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg"
+diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim
+index 850bef055c..8163585939 100644
+--- a/runtime/ftplugin/zsh.vim
++++ b/runtime/ftplugin/zsh.vim
+@@ -2,7 +2,7 @@
+ " Language:             Zsh shell script
+ " Maintainer:           Christian Brabandt <cb@256bit.org>
+ " Previous Maintainer:  Nikolai Weibull <now@bitwi.se>
+-" Latest Revision:      2025 Jul 23
++" Latest Revision:      2026 Jul 23
+ " License:              Vim (see :h license)
+ " Repository:           https://github.com/chrisbra/vim-zsh
+ 
+@@ -25,9 +25,9 @@ endif
+ 
+ if executable('zsh') && &shell !~# '/\%(nologin\|false\)$'
+   if exists(':terminal') == 2
+-    command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help <args>"'
+-  else
+-    command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help <args> 2>/dev/null"')
++    command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', <q-args>])
++  elseif has("patch-9.2.0250")
++    command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', <q-args>])
+   endif
+   setlocal keywordprg=:ZshKeywordPrg
+   let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg'
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index f0524ba7300..c132444040a 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-73073.patch \
            file://CVE-2026-73074.patch \
            file://CVE-2026-73076.patch \
+           file://CVE-2026-73077.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (15 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
                   ` (20 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hitendra Prajapati <hprajapati@mvista.com>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73078

Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../vim/files/CVE-2026-73078.patch            | 94 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 95 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-73078.patch b/meta/recipes-support/vim/files/CVE-2026-73078.patch
new file mode 100644
index 00000000000..62d156f5680
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73078.patch
@@ -0,0 +1,94 @@
+From 29c6fd090d4520592f8be7d9ec81190edf25ef69 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Mon, 6 Jul 2026 13:54:03 +0900
+Subject: [PATCH] patch 9.2.0840: [security]: code injection in netrw via
+ bookmarks
+
+Problem:  [security]: code injection in netrw via bookmarks and history
+          (David Carliez)
+Solution: Escape the '|' explicitly (Yasuhiro Matsumoto)
+
+The bookmark and history menu builders interpolate paths into :execute'd
+:menu commands using g:netrw_menu_escape, which did not escape the Ex
+command separator '|'. A crafted path could break out of the :menu command
+and run arbitrary Ex/shell commands when the menu was built or triggered.
+
+Add '|' to g:netrw_menu_escape for the menu names, escape the :e right-hand
+side with fnameescape(), and quote the netrw#MakeTgt() argument with
+string() instead of raw single-quote interpolation.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-rcr7-f3wr-22r2
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73078
+Upstream-Status: Backport [https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++-------
+ 1 file changed, 9 insertions(+), 7 deletions(-)
+
+diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+index d7eca30e45..c240bbd13f 100644
+--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+@@ -398,7 +398,7 @@ if has("win32")
+ else
+   call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\')
+ endif
+-call s:NetrwInit("g:netrw_menu_escape",'.&? \')
++call s:NetrwInit("g:netrw_menu_escape",'.&? \|')
+ call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\<C-V>\"")
+ if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4')
+   let s:treedepthstring= "│ "
+@@ -3752,13 +3752,14 @@ function s:NetrwBookmarkMenu()
+         if exists("g:netrw_bookmarklist") && g:netrw_bookmarklist != [] && g:netrw_dirhistmax > 0
+             let cnt= 1
+             for bmd in g:netrw_bookmarklist
+-                let bmd= escape(bmd,g:netrw_menu_escape)
++                let ebmd= escape(bmd,g:netrw_menu_escape)
++                let fbmd= escape(fnameescape(bmd),'|')
+ 
+                 " show bookmarks for goto menu
+-                exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.bmd.'    :e '.bmd."\<cr>"
++                exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.ebmd.'    :e '.fbmd."\<cr>"
+ 
+                 " show bookmarks for deletion menu
+-                exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.bmd.'   '.cnt."mB"
++                exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.ebmd.'   '.cnt."mB"
+                 let cnt= cnt + 1
+             endfor
+ 
+@@ -3774,7 +3775,8 @@ function s:NetrwBookmarkMenu()
+                 let priority = g:netrw_dirhistcnt + histcnt
+                 if exists("g:netrw_dirhist_{cnt}")
+                     let histdir= escape(g:netrw_dirhist_{cnt},g:netrw_menu_escape)
+-                    exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.'    :e '.histdir."\<cr>"
++                    let ehistdir= escape(fnameescape(g:netrw_dirhist_{cnt}),'|')
++                    exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.'    :e '.ehistdir."\<cr>"
+                 endif
+                 let first = 0
+                 let cnt   = ( cnt - 1 ) % g:netrw_dirhistmax
+@@ -7119,7 +7121,7 @@ function s:NetrwTgtMenu()
+                 let tgtdict[bmd]= cnt
+                 let ebmd= escape(bmd,g:netrw_menu_escape)
+                 " show bookmarks for goto menu
+-                exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt('".bmd."')\<cr>"
++                exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt(".escape(string(bmd),'|').")\<cr>"
+                 let cnt= cnt + 1
+             endfor
+         endif
+@@ -7137,7 +7139,7 @@ function s:NetrwTgtMenu()
+                     endif
+                     let tgtdict[histentry] = histcnt
+                     let ehistentry         = escape(histentry,g:netrw_menu_escape)
+-                    exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry."     :call netrw#MakeTgt('".histentry."')\<cr>"
++                    exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry."     :call netrw#MakeTgt(".escape(string(histentry),'|').")\<cr>"
+                 endif
+                 let histcnt = histcnt + 1
+             endwhile
+-- 
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index c132444040a..77f681410a9 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-73074.patch \
            file://CVE-2026-73076.patch \
            file://CVE-2026-73077.patch \
+           file://CVE-2026-73078.patch \
            "
 
 PV .= ".0340"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (16 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
                   ` (19 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hiago De Franco <hfranco@baylibre.com>

The guard added in 80ff4903ea tests "detail" in cve_data, but cve_data is
keyed by CVE id, so it asks whether a CVE literally named "detail" was
scanned. That is never true, the condition short-circuits, and the guard
never runs: a CVE_STATUS[CVE-...] = "backported-patch" set for a vendor
cherry-picked patch is silently overwritten to Unpatched by the CNA.

Use .get() on the entry instead. Guard the fallthrough warning the same
way, it makes the same assumption.

Tested against a qemuarm64 linux-yocto report (6.6.142+git, 16221 entries,
4313 of them with no detail). Current master and this version produce
identical output, 18773 entries with no difference. Adding
CVE_STATUS[CVE-2024-42067] = "backported-patch" to that report then makes
the only difference between them: master overwrites it to Unpatched, this
version keeps it Patched. The pre-80ff4903ea code aborts on the same
report with "KeyError: 'detail'".

(cherry picked from commit f5da16b0d3c8f889dab061ba1d8808aba95d4c67)

AI-Generated: Uses Claude (claude-opus-5)
Fixes: 80ff4903ea1b ("improve_kernel_cve_report: validate that cve details field exists")
Signed-off-by: Hiago De Franco <hfranco@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 scripts/contrib/improve_kernel_cve_report.py | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py
index b386c9383a7..f0e471be459 100755
--- a/scripts/contrib/improve_kernel_cve_report.py
+++ b/scripts/contrib/improve_kernel_cve_report.py
@@ -363,7 +363,7 @@ def cve_update(cve_data, cve, entry):
     if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched":
         # Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch)
         # has priority over unpatch from CNA
-        if "detail" in cve_data and cve_data[cve]['detail'] == "backported-patch":
+        if cve_data[cve].get('detail') == "backported-patch":
             return
         logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve)
         cve_data[cve] = copy_data(cve_data[cve], entry)
@@ -382,7 +382,7 @@ def cve_update(cve_data, cve, entry):
         logging.debug("CVE entry %s updated from Unpatched to Ignored", cve)
         return
     logging.warning("Unhandled CVE entry update for %s %s from %s %s to %s",
-        cve, cve_data[cve]['status'], cve_data[cve]['detail'],  entry['status'], entry['detail'])
+        cve, cve_data[cve]['status'], cve_data[cve].get('detail'),  entry['status'], entry['detail'])
 
 def main():
     parser = argparse.ArgumentParser(


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (17 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
                   ` (18 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>

ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5

0.26.5 (stable)
* rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) [PR#777]

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb}            | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (97%)

diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
similarity index 97%
rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
index fde122d3ca5..423c751307b 100644
--- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
+++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
@@ -12,7 +12,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else ''
 
 SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV} \
            "
-SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
+SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
 
 PACKAGECONFIG ??= ""
 PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (18 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
                   ` (17 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Darsh Kelaiya <dkelaiya@cisco.com>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358
[2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../python/python3-lxml/CVE-2026-41066.patch  | 349 ++++++++++++++++++
 .../python/python3-lxml_6.0.2.bb              |   4 +-
 2 files changed, 352 insertions(+), 1 deletion(-)
 create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch

diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
new file mode 100644
index 00000000000..b1a6f6629d3
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
@@ -0,0 +1,349 @@
+From 3a79355229f58e0fe51371385102dd7577bbfb26 Mon Sep 17 00:00:00 2001
+From: Stefan Behnel <stefan_ml@behnel.de>
+Date: Fri, 10 Apr 2026 10:13:03 +0200
+Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for
+ all parser subclasses.
+
+CVE: CVE-2026-41066
+Upstream-Status: Backport [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358]
+
+Backport Changes:
+- Reformat the iterparse signature and resolve_entities documentation
+  without semantic changes, preserving line numbers to avoid generated
+  source-location churn.
+- Regenerate src/lxml/etree.c with Cython 3.1.4, matching the version
+  recorded in the shipped file, using
+  "python setup.py build_ext -i --with-cython".
+- Restore the shipped Cython metadata field order and omit
+  the environment-only "-w" compiler flag to avoid unrelated
+  generated changes.
+
+(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ src/lxml/etree.c       | 60 +++++++++++++++++++++---------------------
+ src/lxml/iterparse.pxi | 10 +++----
+ src/lxml/parser.pxi    |  6 ++---
+ 3 files changed, 38 insertions(+), 38 deletions(-)
+
+diff --git a/src/lxml/etree.c b/src/lxml/etree.c
+index 29553531..f2208e43 100644
+--- a/src/lxml/etree.c
++++ b/src/lxml/etree.c
+@@ -147986,7 +147986,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,             # <<<<<<<<<<<<<<
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ */
+       if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -147997,7 +147997,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+  *                  ns_clean=False, recover=False, schema=None,             # <<<<<<<<<<<<<<
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+ */
+       if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148007,17 +148007,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+       /* "src/lxml/parser.pxi":1734
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,             # <<<<<<<<<<<<<<
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',             # <<<<<<<<<<<<<<
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):
+ */
+       if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+-      if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True));
++      if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+ 
+       /* "src/lxml/parser.pxi":1735
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,             # <<<<<<<<<<<<<<
+  *                  target=None, compact=True):
+  *         XMLParser.__init__(self,
+@@ -148027,7 +148027,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+       if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True));
+ 
+       /* "src/lxml/parser.pxi":1736
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):             # <<<<<<<<<<<<<<
+  *         XMLParser.__init__(self,
+@@ -148054,7 +148054,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,             # <<<<<<<<<<<<<<
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ */
+       if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148065,7 +148065,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+  *     def __init__(self, *, encoding=None, attribute_defaults=False,
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+  *                  ns_clean=False, recover=False, schema=None,             # <<<<<<<<<<<<<<
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+ */
+       if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148075,17 +148075,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+       /* "src/lxml/parser.pxi":1734
+  *                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,             # <<<<<<<<<<<<<<
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',             # <<<<<<<<<<<<<<
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):
+ */
+       if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+-      if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True));
++      if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+ 
+       /* "src/lxml/parser.pxi":1735
+  *                  ns_clean=False, recover=False, schema=None,
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,             # <<<<<<<<<<<<<<
+  *                  target=None, compact=True):
+  *         XMLParser.__init__(self,
+@@ -148095,7 +148095,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+       if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True));
+ 
+       /* "src/lxml/parser.pxi":1736
+- *                  huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ *                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+  *                  remove_comments=True, remove_pis=True, strip_cdata=True,
+  *                  target=None, compact=True):             # <<<<<<<<<<<<<<
+  *         XMLParser.__init__(self,
+@@ -195499,7 +195499,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=("end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,             # <<<<<<<<<<<<<<
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+ */
+       if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195508,7 +195508,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=("end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,             # <<<<<<<<<<<<<<
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+ */
+       if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195518,17 +195518,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+       /* "src/lxml/iterparse.pxi":71
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,             # <<<<<<<<<<<<<<
++ *                  compact=True, resolve_entities='internal', remove_comments=False,             # <<<<<<<<<<<<<<
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,
+ */
+       if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True));
+-      if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True));
++      if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+       if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+ 
+       /* "src/lxml/iterparse.pxi":72
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,             # <<<<<<<<<<<<<<
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,
+  *                  XMLSchema schema=None):
+@@ -195538,7 +195538,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+       if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None));
+ 
+       /* "src/lxml/iterparse.pxi":73
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,             # <<<<<<<<<<<<<<
+  *                  XMLSchema schema=None):
+@@ -195588,7 +195588,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=("end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,             # <<<<<<<<<<<<<<
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+ */
+       if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+       if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195597,7 +195597,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+  *     def __init__(self, source, events=("end",), *, tag=None,
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,             # <<<<<<<<<<<<<<
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+ */
+       if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195607,17 +195607,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+       /* "src/lxml/iterparse.pxi":71
+  *                  attribute_defaults=False, dtd_validation=False,
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,             # <<<<<<<<<<<<<<
++ *                  compact=True, resolve_entities='internal', remove_comments=False,             # <<<<<<<<<<<<<<
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,
+ */
+       if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True));
+-      if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True));
++      if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+       if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+ 
+       /* "src/lxml/iterparse.pxi":72
+  *                  load_dtd=False, no_network=True, remove_blank_text=False,
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,             # <<<<<<<<<<<<<<
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,
+  *                  XMLSchema schema=None):
+@@ -195627,7 +195627,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+       if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None));
+ 
+       /* "src/lxml/iterparse.pxi":73
+- *                  compact=True, resolve_entities=True, remove_comments=False,
++ *                  compact=True, resolve_entities='internal', remove_comments=False,
+  *                  remove_pis=False, strip_cdata=True, encoding=None,
+  *                  html=False, recover=None, huge_tree=False, collect_ids=True,             # <<<<<<<<<<<<<<
+  *                  XMLSchema schema=None):
+@@ -263283,7 +263283,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_XMLParser[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = {
+   {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser},
+-  {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False,                  load_dtd=False, no_network=True, decompress=False, ns_clean=False,                  recover=False, schema: XMLSchema =None, huge_tree=False,                  remove_blank_text=False, resolve_entities=True,                  remove_comments=False, remove_pis=False, strip_cdata=True,                  collect_ids=True, target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as additional argument to various parse\n    functions of the lxml API.  A default parser is always available\n    and can be replaced by a call to the global function\n    'set_default_parser'.  New parsers can be created at any time\n    without a major run-time overhead.\n\n    The keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if DTD\n    validation or attribute default values are requested (unless you\n    additionally provide an XMLSchema from which the default\n    attributes can be read).\n\n    Available boolean keyword arguments:\n\n    - attribute_defaults - inject default attributes from DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the document\n    - load_dtd           - use DTD for parsing\n    - no_network         - prevent network access for related files (default: True)\n    - decompress         - automatically decompress gzip input\n                           (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n    - ns_clean           - clean up redundant namespace declarations\n    - recover            - try hard to parse through broken XML\n    - remove_blank_text  - discard blank text nodes that appear ignorable\n    - remove_comments    - discard comments\n    - remove_pis         - discard processing instructions\n    - strip_cdata        - replace CDATA sections by normal text content (default: True)\n    - compact        ""    - save memory for short text content (default: True)\n    - collect_ids        - use a hash table of XML IDs for fast access\n                           (default: True, always True with DTD validation)\n    - huge_tree          - disable security restrictions and support very deep trees\n                           and very long text content\n\n    Other keyword arguments:\n\n    - resolve_entities - replace entities by their text value: False for keeping the\n          entity references, True for resolving them, and 'internal' for resolving\n          internal definitions only (no external file/URL access).\n          The default used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: libiconv encoding name)\n    - target   - a parser target object that will receive the parse events\n    - schema   - an XMLSchema to validate against\n\n    Note that you should avoid sharing parsers between threads.  While this is\n    not harmful, it is more efficient to use separate parsers.  This does not\n    apply to the default parser.\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False,                  load_dtd=False, no_network=True, decompress=False, ns_clean=False,                  recover=False, schema: XMLSchema =None, huge_tree=False,                  remove_blank_text=False, resolve_entities='internal',                  remove_comments=False, remove_pis=False, strip_cdata=True,                  collect_ids=True, target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as additional argument to various parse\n    functions of the lxml API.  A default parser is always available\n    and can be replaced by a call to the global function\n    'set_default_parser'.  New parsers can be created at any time\n    without a major run-time overhead.\n\n    The keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if DTD\n    validation or attribute default values are requested (unless you\n    additionally provide an XMLSchema from which the default\n    attributes can be read).\n\n    Available boolean keyword arguments:\n\n    - attribute_defaults - inject default attributes from DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the document\n    - load_dtd           - use DTD for parsing\n    - no_network         - prevent network access for related files (default: True)\n    - decompress         - automatically decompress gzip input\n                           (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n    - ns_clean           - clean up redundant namespace declarations\n    - recover            - try hard to parse through broken XML\n    - remove_blank_text  - discard blank text nodes that appear ignorable\n    - remove_comments    - discard comments\n    - remove_pis         - discard processing instructions\n    - strip_cdata        - replace CDATA sections by normal text content (default: True)\n    - compact  ""          - save memory for short text content (default: True)\n    - collect_ids        - use a hash table of XML IDs for fast access\n                           (default: True, always True with DTD validation)\n    - huge_tree          - disable security restrictions and support very deep trees\n                           and very long text content\n\n    Other keyword arguments:\n\n    - resolve_entities - replace entities by their text value: False for keeping the\n          entity references, True for resolving them, and 'internal' for resolving\n          internal definitions only (no external file/URL access).\n          The default used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: libiconv encoding name)\n    - target   - a parser target object that will receive the parse events\n    - schema   - an XMLSchema to validate against\n\n    Note that you should avoid sharing parsers between threads.  While this is\n    not harmful, it is more efficient to use separate parsers.  This does not\n    apply to the default parser.\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+   {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser},
+@@ -263326,7 +263326,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_XMLParser = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+-  PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False,                  load_dtd=False, no_network=True, decompress=False, ns_clean=False,                  recover=False, schema: XMLSchema =None, huge_tree=False,                  remove_blank_text=False, resolve_entities=True,                  remove_comments=False, remove_pis=False, strip_cdata=True,                  collect_ids=True, target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as additional argument to various parse\n    functions of the lxml API.  A default parser is always available\n    and can be replaced by a call to the global function\n    'set_default_parser'.  New parsers can be created at any time\n    without a major run-time overhead.\n\n    The keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if DTD\n    validation or attribute default values are requested (unless you\n    additionally provide an XMLSchema from which the default\n    attributes can be read).\n\n    Available boolean keyword arguments:\n\n    - attribute_defaults - inject default attributes from DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the document\n    - load_dtd           - use DTD for parsing\n    - no_network         - prevent network access for related files (default: True)\n    - decompress         - automatically decompress gzip input\n                           (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n    - ns_clean           - clean up redundant namespace declarations\n    - recover            - try hard to parse through broken XML\n    - remove_blank_text  - discard blank text nodes that appear ignorable\n    - remove_comments    - discard comments\n    - remove_pis         - discard processing instructions\n    - strip_cdata        - replace CDATA sections by normal text content (default: True)\n    - compact        ""    - save memory for short text content (default: True)\n    - collect_ids        - use a hash table of XML IDs for fast access\n                           (default: True, always True with DTD validation)\n    - huge_tree          - disable security restrictions and support very deep trees\n                           and very long text content\n\n    Other keyword arguments:\n\n    - resolve_entities - replace entities by their text value: False for keeping the\n          entity references, True for resolving them, and 'internal' for resolving\n          internal definitions only (no external file/URL access).\n          The default used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: libiconv encoding name)\n    - target   - a parser target object that will receive the parse events\n    - schema   - an XMLSchema to validate against\n\n    Note that you should avoid sharing parsers between threads.  While this is\n    not harmful, it is more efficient to use separate parsers.  This does not\n    apply to the default parser.\n    "), /*tp_doc*/
++  PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False,                  load_dtd=False, no_network=True, decompress=False, ns_clean=False,                  recover=False, schema: XMLSchema =None, huge_tree=False,                  remove_blank_text=False, resolve_entities='internal',                  remove_comments=False, remove_pis=False, strip_cdata=True,                  collect_ids=True, target=None, compact=True)\n\n    The XML parser.\n\n    Parsers can be supplied as additional argument to various parse\n    functions of the lxml API.  A default parser is always available\n    and can be replaced by a call to the global function\n    'set_default_parser'.  New parsers can be created at any time\n    without a major run-time overhead.\n\n    The keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if DTD\n    validation or attribute default values are requested (unless you\n    additionally provide an XMLSchema from which the default\n    attributes can be read).\n\n    Available boolean keyword arguments:\n\n    - attribute_defaults - inject default attributes from DTD or XMLSchema\n    - dtd_validation     - validate against a DTD referenced by the document\n    - load_dtd           - use DTD for parsing\n    - no_network         - prevent network access for related files (default: True)\n    - decompress         - automatically decompress gzip input\n                           (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n    - ns_clean           - clean up redundant namespace declarations\n    - recover            - try hard to parse through broken XML\n    - remove_blank_text  - discard blank text nodes that appear ignorable\n    - remove_comments    - discard comments\n    - remove_pis         - discard processing instructions\n    - strip_cdata        - replace CDATA sections by normal text content (default: True)\n    - compact  ""          - save memory for short text content (default: True)\n    - collect_ids        - use a hash table of XML IDs for fast access\n                           (default: True, always True with DTD validation)\n    - huge_tree          - disable security restrictions and support very deep trees\n                           and very long text content\n\n    Other keyword arguments:\n\n    - resolve_entities - replace entities by their text value: False for keeping the\n          entity references, True for resolving them, and 'internal' for resolving\n          internal definitions only (no external file/URL access).\n          The default used to be True and was changed to 'internal' in lxml 5.0.\n    - encoding - override the document encoding (note: libiconv encoding name)\n    - target   - a parser target object that will receive the parse events\n    - schema   - an XMLSchema to validate against\n\n    Note that you should avoid sharing parsers between threads.  While this is\n    not harmful, it is more efficient to use separate parsers.  This does not\n    apply to the default parser.\n    "), /*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+   0, /*tp_richcompare*/
+@@ -263506,7 +263506,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_ETCompatXMLParser[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = {
+   {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser},
+-  {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False,                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,                  ns_clean=False, recover=False, schema=None,                  huge_tree=False, remove_blank_text=False, resolve_entities=True,                  remove_comments=True, remove_pis=True, strip_cdata=True,                  target=None, compact=True)\n\n    An XML parser with an ElementTree compatible default setup.\n\n    See the XMLParser class for details.\n\n    This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus ignores comments and processing instructions.\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False,                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,                  ns_clean=False, recover=False, schema=None,                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',                  remove_comments=True, remove_pis=True, strip_cdata=True,                  target=None, compact=True)\n\n    An XML parser with an ElementTree compatible default setup.\n\n    See the XMLParser class for details.\n\n    This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus ignores comments and processing instructions.\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+   {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser},
+@@ -263549,7 +263549,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_ETCompatXMLParser = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+-  PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False,                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,                  ns_clean=False, recover=False, schema=None,                  huge_tree=False, remove_blank_text=False, resolve_entities=True,                  remove_comments=True, remove_pis=True, strip_cdata=True,                  target=None, compact=True)\n\n    An XML parser with an ElementTree compatible default setup.\n\n    See the XMLParser class for details.\n\n    This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus ignores comments and processing instructions.\n    "), /*tp_doc*/
++  PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False,                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,                  ns_clean=False, recover=False, schema=None,                  huge_tree=False, remove_blank_text=False, resolve_entities='internal',                  remove_comments=True, remove_pis=True, strip_cdata=True,                  target=None, compact=True)\n\n    An XML parser with an ElementTree compatible default setup.\n\n    See the XMLParser class for details.\n\n    This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n    and thus ignores comments and processing instructions.\n    "), /*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+   0, /*tp_richcompare*/
+@@ -266739,7 +266739,7 @@ static struct PyGetSetDef __pyx_getsets_4lxml_5etree_iterparse[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = {
+   {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse},
+-  {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,                   attribute_defaults=False, dtd_validation=False,                   load_dtd=False, no_network=True, remove_blank_text=False,                   remove_comments=False, remove_pis=False, encoding=None,                   html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental parser.\n\n    Parses XML into a tree and generates tuples (event, element) in a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the parser just\n    found opening or closing.  For 'start-ns', it is a tuple (prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply None.  Note that\n    all start and end events are guaranteed to be properly nested.\n\n    The keyword argument ``events`` specifies a sequence of event type names\n    that should be generated.  By default, only 'end' events will be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' and 'end' events to\n    those elements that match the given tag.  The ``tag`` argument can also be\n    a sequence of tags to allow matching more than one tag.  By default,\n    events are generated for all elements.  Note that the 'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n    The other keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if validation or\n    attribute default values are requested.\n\n    Available boolean keyword arguments:\n     - attribute_defaults: read default attributes from DTD\n     - dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for parsing\n     - no_network: prevent network access for related files\n     - remove_blank_text: discard blank text nodes\n     - remove_comments: discard comments\n     - remove_pis: discard processing instructions\n     - strip_cdata: repla""ce CDATA sections by normal text content (default: \n       True for XML, ignored otherwise)\n     - compact: safe memory for short text content (default: True)\n     - resolve_entities: replace entities by their text value (default: True)\n     - huge_tree: disable security restrictions and support very deep trees\n                  and very long text content (only affects libxml2 2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try hard to parse through broken input (default: True for HTML,\n                False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the document encoding\n     - schema: an XMLSchema to validate against\n    ")},
++  {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,                   attribute_defaults=False, dtd_validation=False,                   load_dtd=False, no_network=True, remove_blank_text=False,                   compact=True, resolve_entities='internal', remove_comments=False,                   remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental parser.\n\n    Parses XML into a tree and generates tuples (event, element) in a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the parser just\n    found opening or closing.  For 'start-ns', it is a tuple (prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply None.  Note that\n    all start and end events are guaranteed to be properly nested.\n\n    The keyword argument ``events`` specifies a sequence of event type names\n    that should be generated.  By default, only 'end' events will be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' and 'end' events to\n    those elements that match the given tag.  The ``tag`` argument can also be\n    a sequence of tags to allow matching more than one tag.  By default,\n    events are generated for all elements.  Note that the 'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n    The other keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if validation or\n    attribute default values are requested.\n\n    Available boolean keyword arguments:\n     - attribute_defaults: read default attributes from DTD\n     - dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for parsing\n     - no_network: prevent network access for related files\n     - remove_blank_text: discard blank text nodes\n     - remove_comments: discard comments\n     - remove_pi""s: discard processing instructions\n     - strip_cdata: replace CDATA sections by normal text content (default:\n       True for XML, ignored otherwise)\n     - compact: safe memory for short text content (default: True)\n     - resolve_entities: replace entities by their text value (default: 'internal' only)\n     - huge_tree: disable security restrictions and support very deep trees\n                  and very long text content (only affects libxml2 2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try hard to parse through broken input (default: True for HTML,\n                False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the document encoding\n     - schema: an XMLSchema to validate against\n    ")},
+   {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse},
+   {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse},
+   {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__},
+@@ -266785,7 +266785,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_iterparse = {
+   0, /*tp_setattro*/
+   0, /*tp_as_buffer*/
+   Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+-  PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,                   attribute_defaults=False, dtd_validation=False,                   load_dtd=False, no_network=True, remove_blank_text=False,                   remove_comments=False, remove_pis=False, encoding=None,                   html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental parser.\n\n    Parses XML into a tree and generates tuples (event, element) in a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the parser just\n    found opening or closing.  For 'start-ns', it is a tuple (prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply None.  Note that\n    all start and end events are guaranteed to be properly nested.\n\n    The keyword argument ``events`` specifies a sequence of event type names\n    that should be generated.  By default, only 'end' events will be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' and 'end' events to\n    those elements that match the given tag.  The ``tag`` argument can also be\n    a sequence of tags to allow matching more than one tag.  By default,\n    events are generated for all elements.  Note that the 'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n    The other keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if validation or\n    attribute default values are requested.\n\n    Available boolean keyword arguments:\n     - attribute_defaults: read default attributes from DTD\n     - dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for parsing\n     - no_network: prevent network access for related files\n     - remove_blank_text: discard blank text nodes\n     - remove_comments: discard comments\n     - remove_pis: discard processing instructions\n     - strip_cdata: repla""ce CDATA sections by normal text content (default: \n       True for XML, ignored otherwise)\n     - compact: safe memory for short text content (default: True)\n     - resolve_entities: replace entities by their text value (default: True)\n     - huge_tree: disable security restrictions and support very deep trees\n                  and very long text content (only affects libxml2 2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try hard to parse through broken input (default: True for HTML,\n                False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the document encoding\n     - schema: an XMLSchema to validate against\n    "), /*tp_doc*/
++  PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None,                   attribute_defaults=False, dtd_validation=False,                   load_dtd=False, no_network=True, remove_blank_text=False,                   compact=True, resolve_entities='internal', remove_comments=False,                   remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n    Incremental parser.\n\n    Parses XML into a tree and generates tuples (event, element) in a\n    SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n    'end-ns'.\n\n    For 'start' and 'end', ``element`` is the Element that the parser just\n    found opening or closing.  For 'start-ns', it is a tuple (prefix, URI) of\n    a new namespace declaration.  For 'end-ns', it is simply None.  Note that\n    all start and end events are guaranteed to be properly nested.\n\n    The keyword argument ``events`` specifies a sequence of event type names\n    that should be generated.  By default, only 'end' events will be\n    generated.\n\n    The additional ``tag`` argument restricts the 'start' and 'end' events to\n    those elements that match the given tag.  The ``tag`` argument can also be\n    a sequence of tags to allow matching more than one tag.  By default,\n    events are generated for all elements.  Note that the 'start-ns' and\n    'end-ns' events are not impacted by this restriction.\n\n    The other keyword arguments in the constructor are mainly based on the\n    libxml2 parser configuration.  A DTD will also be loaded if validation or\n    attribute default values are requested.\n\n    Available boolean keyword arguments:\n     - attribute_defaults: read default attributes from DTD\n     - dtd_validation: validate (if DTD is available)\n     - load_dtd: use DTD for parsing\n     - no_network: prevent network access for related files\n     - remove_blank_text: discard blank text nodes\n     - remove_comments: discard comments\n     - remove_pi""s: discard processing instructions\n     - strip_cdata: replace CDATA sections by normal text content (default:\n       True for XML, ignored otherwise)\n     - compact: safe memory for short text content (default: True)\n     - resolve_entities: replace entities by their text value (default: 'internal' only)\n     - huge_tree: disable security restrictions and support very deep trees\n                  and very long text content (only affects libxml2 2.7+)\n     - html: parse input as HTML (default: XML)\n     - recover: try hard to parse through broken input (default: True for HTML,\n                False otherwise)\n\n    Other keyword arguments:\n     - encoding: override the document encoding\n     - schema: an XMLSchema to validate against\n    "), /*tp_doc*/
+   __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/
+   __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/
+   0, /*tp_richcompare*/
+diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi
+index 42b75249..9319f646 100644
+--- a/src/lxml/iterparse.pxi
++++ b/src/lxml/iterparse.pxi
+@@ -6,8 +6,8 @@ cdef class iterparse:
+     """iterparse(self, source, events=("end",), tag=None, \
+                   attribute_defaults=False, dtd_validation=False, \
+                   load_dtd=False, no_network=True, remove_blank_text=False, \
+-                  remove_comments=False, remove_pis=False, encoding=None, \
+-                  html=False, recover=None, huge_tree=False, schema=None)
++                  compact=True, resolve_entities='internal', remove_comments=False, \
++                  remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)
+ 
+     Incremental parser.
+ 
+@@ -42,10 +42,10 @@ cdef class iterparse:
+      - remove_blank_text: discard blank text nodes
+      - remove_comments: discard comments
+      - remove_pis: discard processing instructions
+-     - strip_cdata: replace CDATA sections by normal text content (default: 
++     - strip_cdata: replace CDATA sections by normal text content (default:
+        True for XML, ignored otherwise)
+      - compact: safe memory for short text content (default: True)
+-     - resolve_entities: replace entities by their text value (default: True)
++     - resolve_entities: replace entities by their text value (default: 'internal' only)
+      - huge_tree: disable security restrictions and support very deep trees
+                   and very long text content (only affects libxml2 2.7+)
+      - html: parse input as HTML (default: XML)
+@@ -68,7 +68,7 @@ cdef class iterparse:
+     def __init__(self, source, events=("end",), *, tag=None,
+                  attribute_defaults=False, dtd_validation=False,
+                  load_dtd=False, no_network=True, remove_blank_text=False,
+-                 compact=True, resolve_entities=True, remove_comments=False,
++                 compact=True, resolve_entities='internal', remove_comments=False,
+                  remove_pis=False, strip_cdata=True, encoding=None,
+                  html=False, recover=None, huge_tree=False, collect_ids=True,
+                  XMLSchema schema=None):
+diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi
+index 3106e610..ba9875c0 100644
+--- a/src/lxml/parser.pxi
++++ b/src/lxml/parser.pxi
+@@ -1584,7 +1584,7 @@ cdef class XMLParser(_FeedParser):
+     """XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, \
+                  load_dtd=False, no_network=True, decompress=False, ns_clean=False, \
+                  recover=False, schema: XMLSchema =None, huge_tree=False, \
+-                 remove_blank_text=False, resolve_entities=True, \
++                 remove_blank_text=False, resolve_entities='internal', \
+                  remove_comments=False, remove_pis=False, strip_cdata=True, \
+                  collect_ids=True, target=None, compact=True)
+ 
+@@ -1717,7 +1717,7 @@ cdef class ETCompatXMLParser(XMLParser):
+     """ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \
+                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False, \
+                  ns_clean=False, recover=False, schema=None, \
+-                 huge_tree=False, remove_blank_text=False, resolve_entities=True, \
++                 huge_tree=False, remove_blank_text=False, resolve_entities='internal', \
+                  remove_comments=True, remove_pis=True, strip_cdata=True, \
+                  target=None, compact=True)
+ 
+@@ -1731,7 +1731,7 @@ cdef class ETCompatXMLParser(XMLParser):
+     def __init__(self, *, encoding=None, attribute_defaults=False,
+                  dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+                  ns_clean=False, recover=False, schema=None,
+-                 huge_tree=False, remove_blank_text=False, resolve_entities=True,
++                 huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+                  remove_comments=True, remove_pis=True, strip_cdata=True,
+                  target=None, compact=True):
+         XMLParser.__init__(self,
+-- 
+2.35.6
+
diff --git a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
index 876fda93b63..75894460ec5 100644
--- a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
+++ b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
@@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt"
 
 SRC_URI[sha256sum] = "cd79f3367bd74b317dda655dc8fcfa304d9eb6e4fb06b7168c5cf27f96e0cd62"
 
-SRC_URI += "${PYPI_SRC_URI}"
+SRC_URI += "${PYPI_SRC_URI} \
+            file://CVE-2026-41066.patch"
+
 inherit pkgconfig pypi setuptools3
 
 # {standard input}: Assembler messages:


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (19 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-10  4:42   ` Hemanth Kumar M D
  2026-09-09  7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
                   ` (16 subsequent siblings)
  37 siblings, 1 reply; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Harish Sadineni <Harish.Sadineni@windriver.com>

Allocate the maximum array sizes directly, instead of resizing
the arrays as needed.  This eliminates alloca usage from the
function, and fixes the out-of-bounds accesses.  The asserts
guard against the bug coming back if the balancing of the tree
turns out not to work correctly.

Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
CVE: CVE-2026-19542

Reference:
[1]https://security-tracker.debian.org/tracker/CVE-2026-19542
[2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
[3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3

Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed CVE: tag in patch]
---
 .../glibc/glibc/0023-CVE-2026-19542.patch     | 98 +++++++++++++++++++
 meta/recipes-core/glibc/glibc_2.43.bb         |  1 +
 2 files changed, 99 insertions(+)
 create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch

diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
new file mode 100644
index 00000000000..094a50919dc
--- /dev/null
+++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
@@ -0,0 +1,98 @@
+From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
+From: Florian Weimer <fweimer@redhat.com>
+Date: Fri, 14 Aug 2026 13:41:16 +0200
+Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
+
+Allocate the maximum array sizes directly, instead of resizing
+the arrays as needed.  This eliminates alloca usage from the
+function, and fixes the out-of-bounds accesses.  The asserts
+guard against the bug coming back if the balancing of the tree
+turns out not to work correctly.
+
+CVE: CVE-2026-19542
+Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
+
+Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
+Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
+---
+ misc/tsearch.c | 31 +++++++++++--------------------
+ 1 file changed, 11 insertions(+), 20 deletions(-)
+
+diff --git a/misc/tsearch.c b/misc/tsearch.c
+index 9b2eb34b25..e517dfa712 100644
+--- a/misc/tsearch.c
++++ b/misc/tsearch.c
+@@ -85,6 +85,7 @@
+ #include <assert.h>
+ #include <stdalign.h>
+ #include <stddef.h>
++#include <stdint.h>
+ #include <stdlib.h>
+ #include <string.h>
+ #include <search.h>
+@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+   int cmp;
+   node *rootp = (node *) vrootp;
+   node root, unchained;
+-  /* Stack of nodes so we remember the parents without recursion.  It's
+-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
+-     would need to have around 250.000 nodes.  */
+-  int stacksize = 40;
++  /* Stack of nodes so we remember the parents without recursion.  The
++     stack size is a conservative approximation of the maximum height
++     of a red-black tree, based on size of the address space.
++     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
++  enum { stacksize = 2 * UINTPTR_WIDTH };
+   int sp = 0;
+-  node **nodestack = alloca (sizeof (node *) * stacksize);
++  node *nodestack[stacksize];
+ 
+   if (rootp == NULL)
+     return NULL;
+@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+   root = DEREFNODEPTR(rootp);
+   while ((cmp = (*compar) (key, root->key)) != 0)
+     {
+-      if (sp == stacksize)
+-	{
+-	  node **newstack;
+-	  stacksize += 20;
+-	  newstack = alloca (sizeof (node *) * stacksize);
+-	  nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
+-	}
+-
++      assert (sp < stacksize);
+       nodestack[sp++] = rootp;
+       p = DEREFNODEPTR(rootp);
+       if (cmp < 0)
+@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+       node upn;
+       for (;;)
+ 	{
+-	  if (sp == stacksize)
+-	    {
+-	      node **newstack;
+-	      stacksize += 20;
+-	      newstack = alloca (sizeof (node *) * stacksize);
+-	      nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
+-	    }
++	  assert (sp < stacksize);
+ 	  nodestack[sp++] = parentp;
+ 	  parentp = up;
+ 	  upn = DEREFNODEPTR(up);
+@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ 		  SETNODEPTR(pp,q);
+ 		  /* Make sure pp is right if the case below tries to use
+ 		     it.  */
++		  assert (sp < stacksize);
+ 		  nodestack[sp++] = pp = LEFTPTR(q);
+ 		  q = RIGHT(p);
+ 		}
+@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ 		  SETLEFT(p,RIGHT(q));
+ 		  SETRIGHT(q,p);
+ 		  SETNODEPTR(pp,q);
++		  assert (sp < stacksize);
+ 		  nodestack[sp++] = pp = RIGHTPTR(q);
+ 		  q = LEFT(p);
+ 		}
diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
index 9f3a3814d0a..3ef2301191d 100644
--- a/meta/recipes-core/glibc/glibc_2.43.bb
+++ b/meta/recipes-core/glibc/glibc_2.43.bb
@@ -55,6 +55,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
            file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
            file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
            file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
+           file://0023-CVE-2026-19542.patch \
 "
 B = "${WORKDIR}/build-${TARGET_SYS}"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (20 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
                   ` (15 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Vijay Anusuri <vanusuri@mvista.com>

Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001
[2] https://security-tracker.debian.org/tracker/CVE-2026-56001

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../xorg-lib/libxfont/CVE-2026-56001.patch    | 87 +++++++++++++++++++
 .../xorg-lib/libxfont_1.5.4.bb                |  3 +
 2 files changed, 90 insertions(+)
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch

diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
new file mode 100644
index 00000000000..1de7f3e0372
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
@@ -0,0 +1,87 @@
+From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:46:10 +1000
+Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps
+ bytestoalloc
+
+bytestoalloc is declared as unsigned int (32-bit). When the sum of
+per-glyph byte counts exceeds 2^32, the value wraps around and calloc()
+allocates a buffer that is too small. The subsequent ScaleBitmap loop
+then writes past the end of the allocated buffer.
+
+Change bytestoalloc from unsigned int to size_t to match the actual
+allocation size type, and add an explicit overflow check in the
+accumulation loop to bail out if the total would exceed SIZE_MAX.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56001/ZDI-CAN-30558
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Note: 'SIZE_MAX' is defined in header '<stdint.h>'. Add '#include
+<stdint.h>' to fix build failure.
+
+Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
+Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778]
+CVE: CVE-2026-56001
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 24 +++++++++++++++++++++---
+ 1 file changed, 21 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 13ed924..32144d6 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -38,6 +38,7 @@ from The Open Group.
+ #include <X11/fonts/bitmap.h>
+ #include <X11/fonts/fontutil.h>
+ #include <math.h>
++#include <stdint.h>
+ 
+ #ifndef MAX
+ #define   MAX(a,b)    (((a)>(b)) ? a : b)
+@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf,          /* scaled font */
+ 		opci;
+     FontInfoPtr pfi;
+     int         glyph;
+-    unsigned    bytestoalloc = 0;
++    size_t      bytestoalloc = 0;
+     int		firstCol, lastCol, firstRow, lastRow;
+ 
+     double	xform[4], inv_xform[4];
+@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf,          /* scaled font */
+     glyph = pf->glyph;
+     for (i = 0; i < nchars; i++)
+     {
+-	if ((pci = ACCESSENCODING(bitmapFont->encoding, i)))
+-	    bytestoalloc += BYTES_FOR_GLYPH(pci, glyph);
++	if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) {
++	    size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph);
++	    if (bytestoalloc > SIZE_MAX - glyphsize) {
++		fprintf(stderr,
++			"Error: bitmap allocation overflow for scaled font\n");
++		goto bail;
++	    }
++	    bytestoalloc += glyphsize;
++	}
++    }
++
++    /* Reject unreasonably large bitmap allocations that could result
++     * from malicious fonts with extreme scale factors.  256 MiB is
++     * far beyond any legitimate scaled bitmap font. */
++#define BITMAP_SCALE_MAX_ALLOC	(256 * 1024 * 1024)
++    if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) {
++	fprintf(stderr,
++		"Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc);
++	goto bail;
+     }
+ 
+     /* Do we add the font malloc stuff for VALUE ADDED ? */
+-- 
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 9ec7cc30f58..59c489b785d 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -19,6 +19,9 @@ XORG_EXT = "tar.bz2"
 
 BBCLASSEXTEND = "native"
 
+SRC_URI += "file://CVE-2026-56001.patch \
+           "
+
 SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"
 
 PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (21 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
                   ` (14 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Vijay Anusuri <vanusuri@mvista.com>

Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002
[2] https://security-tracker.debian.org/tracker/CVE-2026-56002

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../xorg-lib/libxfont/CVE-2026-56002.patch    | 150 ++++++++++++++++++
 .../xorg-lib/libxfont_1.5.4.bb                |   1 +
 2 files changed, 151 insertions(+)
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch

diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
new file mode 100644
index 00000000000..cef8a06a686
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
@@ -0,0 +1,150 @@
+From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:48:40 +1000
+Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph
+ metrics
+
+pcfReadFont() uses bitmapSizes[] read directly from the PCF file to
+allocate the repadded bitmap buffer. However, per-glyph metrics (also
+from the file) control how much data RepadBitmap() writes. A malicious
+PCF font can declare a small bitmapSizes[] value while having per-glyph
+metrics that require more space, causing a heap buffer overflow.
+
+A similar issue happens with the encoding offsets: pcfReadFont reads
+encoding offsets from the PCF file and uses them to index into the
+metrics array without bounds checking.  A crafted font can set an
+encoding offset larger than nmetrics, causing an out-of-bounds pointer
+that is later dereferenced when glyphs are accessed through the encoding
+table.
+
+And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested
+glyph pad) only validated that each glyph's offset was within the bitmap
+buffer, but did not check that the full glyph extent (offset +
+BYTES_PER_ROW * height) fits within the buffer.  A crafted font with a
+glyph offset near the end of a small bitmap buffer but large glyph
+metrics causes a heap buffer over-read when the glyph is later rendered.
+
+This vulnerability was discovered by:
+  Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56002/ZDI-CAN-30559
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Note: 'INT_MAX' is defined in header '<limits.h>'. Add '#include
+<limits.h>' to fix build failure.
+
+Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
+Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674]
+CVE: CVE-2026-56002
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/pcfread.c | 60 +++++++++++++++++++++++++++++++++++++++++---
+ 1 file changed, 57 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c
+index 4a372c5..0cc9777 100644
+--- a/src/bitmap/pcfread.c
++++ b/src/bitmap/pcfread.c
+@@ -45,6 +45,7 @@ from The Open Group.
+ #include <stdarg.h>
+ #include <stdint.h>
+ #include <string.h>
++#include <limits.h>
+ 
+ void
+ pcfError(const char* message, ...)
+@@ -529,25 +530,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ 	int         old,
+ 	            new;
+ 	xCharInfo  *metric;
++	int         srcPad = PCF_GLYPH_PAD(format);
+ 
+-	sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)];
+-	padbitmaps = malloc(sizepadbitmaps);
++	/* Compute the actual required size from per-glyph metrics instead
++	 * of trusting the file's bitmapSizes[] value, which may be smaller
++	 * than the actual data written by RepadBitmap. */
++	sizepadbitmaps = 0;
++	for (i = 0; i < nbitmaps; i++) {
++	    int w, h, glyphBytes;
++	    metric = &metrics[i].metrics;
++	    w = metric->rightSideBearing - metric->leftSideBearing;
++	    h = metric->ascent + metric->descent;
++	    glyphBytes = BYTES_PER_ROW(w, glyph) * h;
++	    if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) {
++		pcfError("pcfReadFont(): bitmap size overflow\n");
++		goto Bail;
++	    }
++	    sizepadbitmaps += glyphBytes;
++	}
++	padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1);
+ 	if (!padbitmaps) {
+           pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps);
+ 	    goto Bail;
+ 	}
+ 	new = 0;
+ 	for (i = 0; i < nbitmaps; i++) {
++	    int srcGlyphBytes;
++
+ 	    old = offsets[i];
+ 	    metric = &metrics[i].metrics;
++
++	    /* Validate source offset and source glyph size against the
++	     * source bitmap buffer to prevent out-of-bounds reads. */
++	    srcGlyphBytes = BYTES_PER_ROW(
++		metric->rightSideBearing - metric->leftSideBearing,
++		srcPad) * (metric->ascent + metric->descent);
++	    if (old < 0 || old > sizebitmaps ||
++		srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) {
++		pcfError("pcfReadFont(): bitmap offset/size out of bounds\n");
++		free(padbitmaps);
++		goto Bail;
++	    }
++
+ 	    offsets[i] = new;
+ 	    new += RepadBitmap(bitmaps + old, padbitmaps + new,
+-			       PCF_GLYPH_PAD(format), glyph,
++			       srcPad, glyph,
+ 			  metric->rightSideBearing - metric->leftSideBearing,
+ 			       metric->ascent + metric->descent);
+ 	}
+ 	free(bitmaps);
+ 	bitmaps = padbitmaps;
++    } else {
++	/* Validate offsets and full glyph extents against bitmap buffer */
++	for (i = 0; i < nbitmaps; i++) {
++	    int glyphBytes;
++	    xCharInfo *metric = &metrics[i].metrics;
++
++	    glyphBytes = BYTES_PER_ROW(
++		metric->rightSideBearing - metric->leftSideBearing,
++		glyph) * (metric->ascent + metric->descent);
++	    if (offsets[i] >= (CARD32)sizebitmaps ||
++		glyphBytes < 0 ||
++		glyphBytes > sizebitmaps - (int)offsets[i]) {
++		pcfError("pcfReadFont(): bitmap offset/size out of bounds "
++			 "(offset %u, size %d, total %d)\n",
++			 offsets[i], glyphBytes, sizebitmaps);
++		goto Bail;
++	    }
++	}
+     }
+     for (i = 0; i < nbitmaps; i++)
+ 	metrics[i].bits = bitmaps + offsets[i];
+@@ -622,6 +672,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ 	if (IS_EOF(file)) goto Bail;
+ 	if (encodingOffset == 0xFFFF) {
+ 	    pFont->info.allExist = FALSE;
++	} else if (encodingOffset >= nmetrics) {
++	    pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n",
++		     encodingOffset, nmetrics);
++	    goto Bail;
+ 	} else {
+             if(!encoding[SEGMENT_MAJOR(i)]) {
+                 encoding[SEGMENT_MAJOR(i)]=
+-- 
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 59c489b785d..08c96fdac87 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -20,6 +20,7 @@ XORG_EXT = "tar.bz2"
 BBCLASSEXTEND = "native"
 
 SRC_URI += "file://CVE-2026-56001.patch \
+            file://CVE-2026-56002.patch \
            "
 
 SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (22 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
                   ` (13 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Vijay Anusuri <vanusuri@mvista.com>

Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003
[2] https://security-tracker.debian.org/tracker/CVE-2026-56003

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../xorg-lib/libxfont/CVE-2026-56003.patch    | 114 ++++++++++++++++++
 .../xorg-lib/libxfont_1.5.4.bb                |   1 +
 2 files changed, 115 insertions(+)
 create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch

diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
new file mode 100644
index 00000000000..0092c712d44
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
@@ -0,0 +1,114 @@
+From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:49:55 +1000
+Subject: [PATCH] bitscale: add bounds check to computeProps for property
+ buffer
+
+ComputeScaledProperties allocates a fixed-size property buffer of 70
+slots. computeProps iterates the source font's properties and writes 1
+slot for unscaled properties or 2 slots for scaledX/scaledY properties,
+with no bounds check. A malicious font with many duplicate properties
+matching fontPropTable entries can overflow the allocated buffer.
+
+Fix this by passing the remaining buffer capacity to computeProps and
+checking it before each write. Properties that would exceed the buffer
+are silently skipped.
+
+The function is also restructured to handle the buffer writes for
+scaledX/scaledY inside the switch cases directly, rather than in a
+separate block after the switch. This makes the control flow clearer and
+ensures the bounds check covers all writes.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56003/ZDI-CAN-30560
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939]
+CVE: CVE-2026-56003
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 39 ++++++++++++++++++++-------------------
+ 1 file changed, 20 insertions(+), 19 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 32144d6..2affc11 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -513,7 +513,8 @@ static int
+ computeProps(FontPropPtr pf, char *wasStringProp,
+ 	     FontPropPtr npf, char *isStringProp,
+ 	     unsigned int nprops, double xfactor, double yfactor,
+-	     double sXfactor, double sYfactor)
++	     double sXfactor, double sYfactor,
++	     int maxprops)
+ {
+     int         n;
+     int         count;
+@@ -528,14 +529,26 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+ 
+ 	switch (t->type) {
+ 	case scaledX:
+-	    npf->value = doround(xfactor * (double)pf->value);
+-	    rawfactor = sXfactor;
+-	    break;
+ 	case scaledY:
+-	    npf->value = doround(yfactor * (double)pf->value);
+-	    rawfactor = sYfactor;
++	    if (count + 2 > maxprops)
++		continue;
++	    npf->value = (t->type == scaledX)
++		? doround(xfactor * (double)pf->value)
++		: doround(yfactor * (double)pf->value);
++	    rawfactor = (t->type == scaledX) ? sXfactor : sYfactor;
++	    npf->name = pf->name;
++	    npf++;
++	    count++;
++	    npf->value = doround(rawfactor * (double)pf->value);
++	    npf->name = rawFontPropTable[t - fontPropTable].atom;
++	    npf++;
++	    count++;
++	    *isStringProp++ = *wasStringProp;
++	    *isStringProp++ = *wasStringProp;
+ 	    break;
+ 	case unscaled:
++	    if (count + 1 > maxprops)
++		continue;
+ 	    npf->value = pf->value;
+ 	    npf->name = pf->name;
+ 	    npf++;
+@@ -545,18 +558,6 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+ 	default:
+ 	    break;
+ 	}
+-	if (t->type != unscaled)
+-	{
+-	    npf->name = pf->name;
+-	    npf++;
+-	    count++;
+-	    npf->value = doround(rawfactor * (double)pf->value);
+-	    npf->name = rawFontPropTable[t - fontPropTable].atom;
+-	    npf++;
+-	    count++;
+-	    *isStringProp++ = *wasStringProp;
+-	    *isStringProp++ = *wasStringProp;
+-	}
+     }
+     return count;
+ }
+@@ -671,7 +672,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */
+     n = NPROPS;
+     n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp,
+ 		      fp, isStringProp, sourceFontInfo->nprops, dx, dy,
+-		      sdx, sdy);
++		      sdx, sdy, nProps - NPROPS);
+     return n;
+ }
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 08c96fdac87..e254516fcf9 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -21,6 +21,7 @@ BBCLASSEXTEND = "native"
 
 SRC_URI += "file://CVE-2026-56001.patch \
             file://CVE-2026-56002.patch \
+            file://CVE-2026-56003.patch \
            "
 
 SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 25/38] wget: fix CVE-2026-16599
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (23 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
                   ` (12 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY
authentication functionality.
The server-supplied sequence number from the FTP challenge line is used
as an iteration count for an MD5 key-derivation loop without any upper
bound validation. A malicious FTP server or a network attacker
positioned to intercept FTP traffic can send a crafted OPIE challenge
with a sequence number near INT_MAX, causing wget to perform up to
approximately 2.1 billion MD5 computations and suspend for some time.
The --timeout option does not mitigate this because it applies only to
network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

Reference:
https://nvd.nist.gov/vuln/detail/cve-2026-16599

Backport the patch to fix CVE-2026-16599.
https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

Signed-off-by: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: rewrapped commit message]
---
 .../wget/wget/CVE-2026-16599.patch            | 68 +++++++++++++++++++
 meta/recipes-extended/wget/wget_1.25.0.bb     |  1 +
 2 files changed, 69 insertions(+)
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-16599.patch

diff --git a/meta/recipes-extended/wget/wget/CVE-2026-16599.patch b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch
new file mode 100644
index 00000000000..fbe8c0566cd
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch
@@ -0,0 +1,68 @@
+From e9697d98e7249b0f68a6be040a4f3dcc5bc101fa Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Sat, 20 Jun 2026 14:39:54 +0200
+Subject: [PATCH] Fix server-controlled unbounded MD5 loop in FTP OPIE
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+* src/ftp-basic.c (ftp_login): Limit the skey sequence to 9999.
+
+Report:
+wget accepts an unbounded server-controlled integer as the iteration
+count for its OPIE/S-KEY MD5 key-derivation loop. No upper bound is
+enforced on the sequence number supplied by the server in the FTP
+challenge line. The value is passed directly to skey_response() as a
+loop counter, causing wget to perform up to ~2.1 billion full MD5
+computations before responding to the authentication challenge.
+
+Reported-by: Michał Majchrowicz and Marcin Wyczechowski
+
+CVE: CVE-2026-16599
+
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa]
+
+Signed-off-by: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>
+---
+ src/ftp-basic.c | 15 +++++++++++----
+ 1 file changed, 11 insertions(+), 4 deletions(-)
+
+diff --git a/src/ftp-basic.c b/src/ftp-basic.c
+index 0f4bb821..af38a69a 100644
+--- a/src/ftp-basic.c
++++ b/src/ftp-basic.c
+@@ -204,12 +204,11 @@ ftp_login (int csock, const char *acc, const char *pass)
+       "331 s/key ",
+       "331 opiekey "
+     };
+-    size_t i;
+     const char *seed = NULL;
+ 
+-    for (i = 0; i < countof (skey_head); i++)
++    for (size_t i = 0; i < countof (skey_head); i++)
+       {
+-        int l = strlen (skey_head[i]);
++        size_t l = strlen (skey_head[i]);
+         if (0 == c_strncasecmp (skey_head[i], respline, l))
+           {
+             seed = respline + l;
+@@ -222,7 +221,15 @@ ftp_login (int csock, const char *acc, const char *pass)
+ 
+         /* Extract the sequence from SEED.  */
+         for (; c_isdigit (*seed); seed++)
+-          skey_sequence = 10 * skey_sequence + *seed - '0';
++          {
++            skey_sequence = 10 * skey_sequence + *seed - '0';
++            if (skey_sequence > 9999)
++              {
++                xfree (respline);
++                return FTPLOGREFUSED;
++              }
++          }
++
+         if (*seed == ' ')
+           ++seed;
+         else
+-- 
+GitLab
+
diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb
index dc4903429be..95845d695a9 100644
--- a/meta/recipes-extended/wget/wget_1.25.0.bb
+++ b/meta/recipes-extended/wget/wget_1.25.0.bb
@@ -21,6 +21,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
            file://CVE-2026-58471.patch \
            file://CVE-2026-58472.patch \
            file://CVE-2026-58472-regression.patch \
+           file://CVE-2026-16599.patch \
            "
 
 SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (24 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
                   ` (11 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Daniel Turull <daniel.turull@ericsson.com>

- The RAR5 double-free in init_unpack() is a regression introduced
  upstream by commit 620bdafa on 2026-05-16 and existed only
  on the git master branch until it was fixed by PR #3071 (commit
  1c914cdf) on 2026-05-24. It was never part of an upstream release.
- The upstream release tarballs (3.6.x/3.7.x/3.8.6) use the older
  init_unpack() with unchecked calloc and no early-return path, so the
  freed window_buf/filtered_buf pointers are never left dangling and the
  double-free cannot occur.

References:
 https://nvd.nist.gov/vuln/detail/cve-2026-14164
 https://lore.kernel.org/openembedded-core/0447ebc9d29b0736de8ba0c75f155ed4f880d072.camel@pbarker.dev/

Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/libarchive/libarchive_3.8.7.bb | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
index e8c3a3bfe3d..afc06f85d4c 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
@@ -92,3 +92,7 @@ RDEPENDS:${PN}-ptest += "bsdtar bsdcpio"
 CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7"
 CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7"
 CVE_STATUS[CVE-2026-5745] = "fixed-version: fixed since 3.8.6"
+CVE_STATUS[CVE-2026-14164] = "fixed-version: Double-free regression in the RAR5\
+ reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\
+ only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\
+ never part of an upstream release tarball."


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (25 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09 17:00   ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
                   ` (10 subsequent siblings)
  37 siblings, 1 reply; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

Analysis:
- NVD identifies the vulnerable code as net/tcp.c when
  CONFIG_PROT_TCP is enabled [1].
- tools-only_defconfig disables networking, so this code is not built
  into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 7eaf721ca83..0e57bb88849 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -1,2 +1,4 @@
 require u-boot-common.inc
 require u-boot-tools.inc
+
+CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (26 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
                   ` (9 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

Analysis:
- NVD identifies the vulnerable code as net/tcp.c when
  CONFIG_PROT_TCP is enabled [1].
- tools-only_defconfig disables networking, so this code is not built
  into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29008
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 0e57bb88849..6b28718c54a 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -2,3 +2,4 @@ require u-boot-common.inc
 require u-boot-tools.inc
 
 CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
+CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (27 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
                   ` (8 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

Analysis:
- NVD identifies the vulnerable code as the NFS client implementation
  enabled by CONFIG_CMD_NFS [1].
- tools-only_defconfig disables networking, so net/nfs.c is not built
  into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29009
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 6b28718c54a..5e2ed063868 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -3,3 +3,4 @@ require u-boot-tools.inc
 
 CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
 CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
+CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools."


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (28 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
                   ` (7 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

CVE-2026-33243 is assigned to barebox, but NVD currently also maps it
to denx:u-boot. That U-Boot mapping is incorrect because the U-Boot-side
FIT hashed-nodes verification issue is tracked separately as
CVE-2026-46728. A correction request has been sent to NVD to remove the
incorrect denx:u-boot mapping. The existing patch backports U-Boot commit
2092322b31cc8b1f8c9e2e238d1043ae0637b241 [3], which is the U-Boot fix
referenced by CVE-2026-46728 [2].

Rename the patch and update its CVE tag so the filename and metadata
identify the affected U-Boot vendor correctly.

Apply the same patch to u-boot-tools because that recipe builds
fit_check_sign, which uses the affected FIT signature-verification path.
The bootloader recipe already carried the backport, but u-boot-tools did
not.

[1] https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728
[3] https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../{CVE-2026-33243.patch => CVE-2026-46728.patch}    | 11 ++++++++---
 meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb       |  4 ++++
 meta/recipes-bsp/u-boot/u-boot_2026.01.bb             |  4 +++-
 3 files changed, 15 insertions(+), 4 deletions(-)
 rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%)

diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
similarity index 98%
rename from meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch
rename to meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
index c7086e183fb..4e582d529ea 100644
--- a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch
+++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
@@ -28,11 +28,16 @@ Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.c
 Reported-by: Apple Security Engineering and Architecture (SEAR)
 Tested-by: Tom Rini <trini@konsulko.com>
 
-[YB: Removed a skippable condition in fit_config_get_hash_list.
-	This flag is not available in this version]
-CVE: CVE-2026-33243
+CVE: CVE-2026-46728
 Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241]
+
+Backport Changes:
+Dropped the FIT_COMPAT_PROP condition because this macro is not
+available in U-Boot v2026.01.
+
+(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241)
 Signed-off-by: Yanis Binard <yanis.binard@smile.fr>
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
 ---
  boot/image-fit-sig.c        | 226 +++++++++++++++++++++++++++++-------
  doc/usage/fit/signature.rst |  19 ++-
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 5e2ed063868..77e086815c1 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -1,6 +1,10 @@
 require u-boot-common.inc
 require u-boot-tools.inc
 
+SRC_URI += "file://CVE-2026-46728.patch"
+
+CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport."
+
 CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
 CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
 CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools."
diff --git a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
index 6d9bc126a16..9610d9e8fe0 100644
--- a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
@@ -3,7 +3,9 @@ require u-boot.inc
 
 DEPENDS += "bc-native dtc-native gnutls-native python3-pyelftools-native"
 
-SRC_URI += "file://CVE-2026-33243.patch"
+SRC_URI += "file://CVE-2026-46728.patch"
+
+CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport."
 
 # workarounds for aarch64 kvm qemu boot regressions
 SRC_URI:append:qemuarm64 = " file://disable-CONFIG_BLOBLIST.cfg"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (29 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
                   ` (6 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Apply patches recommended by upstream[1] as mentioned in the NVD[2]

[1] https://w1.fi/security/2026-1/
[2] https://nvd.nist.gov/vuln/detail/cve-2026-58374

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../wpa-supplicant/CVE-2026-58374-1.patch     | 52 ++++++++++++++++++
 .../wpa-supplicant/CVE-2026-58374-2.patch     | 47 ++++++++++++++++
 .../wpa-supplicant/CVE-2026-58374-3.patch     | 55 +++++++++++++++++++
 .../wpa-supplicant/CVE-2026-58374-4.patch     | 46 ++++++++++++++++
 .../wpa-supplicant/CVE-2026-58374-5.patch     | 47 ++++++++++++++++
 .../wpa-supplicant/wpa-supplicant_2.11.bb     |  5 ++
 6 files changed, 252 insertions(+)
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
 create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch

diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
new file mode 100644
index 00000000000..625371c2b55
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
@@ -0,0 +1,52 @@
+From 708a4247581c98c0cc46504e4abb874b4c835ffe Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 23:24:04 +0300
+Subject: [PATCH 1/5] AP MLD: Fix link ID validation in Basic MLE parsing
+
+Link ID 15 can be indicated in the field, but that is not a valid value
+and must be rejected to avoid issues pointing beyond the array of links
+for a non-AP MLD. Without this, an invalid MLE could result in writing
+beyond the end of the buffer and causing process termination or
+unexpected behavior.
+
+Fixes: 5f5db9366cde ("AP: MLO: Process Multi-Link element from (Re)Association Request frame")
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/ieee802_11_eht.c | 10 ++++++++--
+ 1 file changed, 8 insertions(+), 2 deletions(-)
+
+diff --git a/src/ap/ieee802_11_eht.c b/src/ap/ieee802_11_eht.c
+index b935ee889a89..804808c0dbfd 100644
+--- a/src/ap/ieee802_11_eht.c
++++ b/src/ap/ieee802_11_eht.c
+@@ -1262,6 +1262,7 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ 		size_t sub_elem_len = *(pos + 1);
+ 		size_t sta_info_len;
+ 		u16 control;
++		u8 link_id;
+ 
+ 		wpa_printf(MSG_DEBUG, "MLD: sub element len=%zu",
+ 			   sub_elem_len);
+@@ -1302,8 +1303,13 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ 			goto out;
+ 		}
+ 		control = WPA_GET_LE16(pos);
+-		link_info = &info->links[control &
+-					 EHT_PER_STA_CTRL_LINK_ID_MSK];
++		link_id = control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++		if (link_id >= MAX_NUM_MLD_LINKS) {
++			wpa_printf(MSG_DEBUG,
++				   "MLD: Invalid Link ID in Per-STA Profile subelement");
++			goto out;
++		}
++		link_info = &info->links[link_id];
+ 		pos += 2;
+ 		ml_len -= 2;
+ 		sub_elem_len -= 2;
+-- 
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
new file mode 100644
index 00000000000..07dd9d3a65f
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
@@ -0,0 +1,47 @@
+From 00e74b2f6e21e4d01aa58433a441ca4c81fb10ab Mon Sep 17 00:00:00 2001
+From: Amarnath Hullur Subramanyam <amarnathhs@google.com>
+Date: Thu, 30 Apr 2026 18:24:35 -0700
+Subject: [PATCH 2/5] BSS: Add bounds check for link_id in Basic MLE parsing
+
+In wpa_bss_parse_basic_ml_element() in bss.c, an extracted link_id is
+used without validation against the maximum allowed links
+(MAX_NUM_MLD_LINKS). Processing a malformed Basic Multi-Link element
+(MLE) with an out-of-bounds link_id could lead to memory corruption.
+However, the modified location is within the body of the received frame
+and as such, this does not result in additional issues since that area
+is controlled by the transmitter of the frame. In any case, it is better
+to be explicit with validating the Link ID value.
+
+This commit introduces a strict bounds check immediately after link_id
+extraction. If link_id exceeds or equals MAX_NUM_MLD_LINKS, parsing is
+gracefully aborted with a debug log entry.
+
+Fixes: de5e01010cb2 ("wpa_supplicant: Support ML probe request")
+Signed-off-by: Amarnath Hullur Subramanyam <amarnathhs@google.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=aa9d345887389a251c63a3781d2ad2940d079193]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/bss.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/wpa_supplicant/bss.c b/wpa_supplicant/bss.c
+index e8aaf6fe1848..11950064a1b6 100644
+--- a/wpa_supplicant/bss.c
++++ b/wpa_supplicant/bss.c
+@@ -1710,6 +1710,11 @@ int wpa_bss_parse_basic_ml_element(struct wpa_supplicant *wpa_s,
+ 			  ETH_ALEN);
+ 
+ 	link_id = ml_basic_common_info->variable[0] & EHT_ML_LINK_ID_MSK;
++	if (link_id >= MAX_NUM_MLD_LINKS) {
++		wpa_printf(MSG_DEBUG, "MLD: Invalid link ID %u in Basic MLE",
++			   link_id);
++		goto out;
++	}
+ 
+ 	bss->mld_link_id = link_id;
+ 	seen = bss->valid_links = BIT(link_id);
+-- 
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
new file mode 100644
index 00000000000..9e28d0a95a3
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
@@ -0,0 +1,55 @@
+From ae24a10634f6e19d75888f5d786f380bb7af5b86 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 23:16:08 +0300
+Subject: [PATCH 3/5] MLD: Validate MLE Link ID fields in association rejection
+ case
+
+The Link ID Info field in the Common Info field needs to ignore the
+reserved bits to be more extensible for future. Both that link ID for
+the association link and the link IDs for other links need to be
+verified to be within the valid range (0-14), so check that here. The
+parsed link ID was not used for anything yet, but it is better to make
+sure this in theory common parser is not exposing invalid data to the
+caller should it be used for additional purposes in the future.
+
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=a8531e3d871e6fa72f2f85d91e9f787326b2af8b]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/events.c | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c
+index 49917f7aaf72..600718d8efc4 100644
+--- a/wpa_supplicant/events.c
++++ b/wpa_supplicant/events.c
+@@ -3864,7 +3864,12 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ 	pos = common_info->variable;
+ 
+ 	/* Store the information for the association link */
+-	ml_info[i].link_id = *pos;
++	ml_info[i].link_id = *pos & EHT_ML_LINK_ID_MSK;
++	if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) {
++		wpa_printf(MSG_DEBUG,
++			   "MLD: Invalid Link ID value for assoc link");
++		goto out;
++	}
+ 	pos++;
+ 
+ 	/* Skip the BSS Parameters Change Count */
+@@ -3999,6 +4004,10 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ 			   MAC2STR(pos + 1), nstr_bitmap_len);
+ 
+ 		ml_info[i].link_id = ctrl & EHT_PER_STA_CTRL_LINK_ID_MSK;
++		if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) {
++			wpa_printf(MSG_DEBUG, "MLD: Invalid Link ID value");
++			goto out;
++		}
+ 		os_memcpy(ml_info[i].bssid, pos + 1, ETH_ALEN);
+ 
+ 		pos += sta_info_len;
+-- 
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
new file mode 100644
index 00000000000..1f42a4017f1
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
@@ -0,0 +1,46 @@
+From c4fc1bf2fd7fe6bebf72d32385bc2bd20d144093 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Mon, 18 May 2026 15:45:15 +0300
+Subject: [PATCH 4/5] AP MLD: Verify AP MLD link ID validity before updating
+ bitmap of links
+
+Link ID is 0..14, so ignore value 15 if an invalid frame is processed.
+It does not look like the invalid value was actually used to reference
+any local array, but in any case, it is better to not mark an invalid
+link as being specified.
+
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=ce1a8612e309fe86133ecf05ffb452b0bdf3b035]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/beacon.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/src/ap/beacon.c b/src/ap/beacon.c
+index cec0c9829fd9..cc295c18f61b 100644
+--- a/src/ap/beacon.c
++++ b/src/ap/beacon.c
+@@ -1305,6 +1305,7 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ 	for_each_element_id(sub, 0, pos, len) {
+ 		const struct ieee80211_eht_per_sta_profile *sta;
+ 		u16 sta_control;
++		u8 link_id;
+ 
+ 		if (*links == 0xffff)
+ 			*links = 0;
+@@ -1324,7 +1325,9 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ 		 * partial profile was requested.
+ 		 */
+ 		sta_control = le_to_host16(sta->sta_control);
+-		*links |= BIT(sta_control & EHT_PER_STA_CTRL_LINK_ID_MSK);
++		link_id = sta_control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++		if (link_id < MAX_NUM_MLD_LINKS)
++			*links |= BIT(link_id);
+ 	}
+ 
+ 	if (!for_each_element_completed(sub, pos, len)) {
+-- 
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
new file mode 100644
index 00000000000..34a0c0af3ba
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
@@ -0,0 +1,47 @@
+From dad0d98570e3615b441d1c1e72e2945483a6fe77 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 17:47:03 +0300
+Subject: [PATCH 5/5] MLD: Fix length check in common info for association
+ failure cases
+
+It is not sufficient to check that the indicated common info length is
+sufficiently large to contain the information; there needs to be a check
+for the indicated value to not be too large to go beyond the end of the
+MLE as well. Without this, invalid MLE might result in ml_len wrapping
+around to a huge value and reading beyond the end of the buffer for the
+received frame. This could result in process termination.
+
+Add the missed check for the Common Info field not being truncated in
+the MLE in association failure cases.
+
+Fixes: a58a0c592e20 ("MLD: Fix Multi-Link element parsing for association failures")
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=41c86a2ebed50567c73de23c102c2bf83eb883f2]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/events.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c
+index 600718d8efc4..d81578438588 100644
+--- a/wpa_supplicant/events.c
++++ b/wpa_supplicant/events.c
+@@ -3852,6 +3852,13 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ 		goto out;
+ 	}
+ 
++	if (sizeof(*ml) + common_info->len > ml_len) {
++		wpa_printf(MSG_DEBUG,
++			   "MLD: Truncated common info (common_info->len=%u ml_len=%zu)",
++			   common_info->len, ml_len);
++		goto out;
++	}
++
+ 	wpa_printf(MSG_DEBUG, "MLD: address: " MACSTR,
+ 		   MAC2STR(common_info->mld_addr));
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
index 7c7a8bd9c13..7d1f9ffc6d6 100644
--- a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
@@ -21,6 +21,11 @@ SRC_URI = "http://w1.fi/releases/wpa_supplicant-${PV}.tar.gz \
            file://0004-defconfig-Uncomment-CONFIG_IEEE80211BE-y.patch \
            file://CVE-2025-24912-01.patch \
            file://CVE-2025-24912-02.patch \
+           file://CVE-2026-58374-1.patch \
+           file://CVE-2026-58374-2.patch \
+           file://CVE-2026-58374-3.patch \
+           file://CVE-2026-58374-4.patch \
+           file://CVE-2026-58374-5.patch \
            "
 SRC_URI[sha256sum] = "912ea06f74e30a8e36fbb68064d6cdff218d8d591db0fc5d75dee6c81ac7fc0a"
 


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 32/38] curl: patch CVE-2026-11352
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (30 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
                   ` (5 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Marko <peter.marko@siemens.com>

Pick patch per [1].

[1] https://curl.se/docs/CVE-2026-11352.html

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../curl/curl/CVE-2026-11352.patch            | 48 +++++++++++++++++++
 meta/recipes-support/curl/curl_8.19.0.bb      |  1 +
 2 files changed, 49 insertions(+)
 create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11352.patch

diff --git a/meta/recipes-support/curl/curl/CVE-2026-11352.patch b/meta/recipes-support/curl/curl/CVE-2026-11352.patch
new file mode 100644
index 00000000000..df414b9112b
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-11352.patch
@@ -0,0 +1,48 @@
+From 56eca2afb4806f1032872fa97d1834b3c1385276 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Fri, 5 Jun 2026 08:34:46 +0200
+Subject: [PATCH] quic: count zero length packets against max
+
+With a flood of zero lenght UDP packets to curl, the receive loop might
+run longer than intended to. Count such packets against the max to
+terminate the loop as intended.
+
+URL: https://hackerone.com/reports/3783438
+Reported-by: vectorqueue on hackerone
+Closes #21869
+
+CVE: CVE-2026-11352
+Upstream-Status: Backport [https://github.com/curl/curl/commit/56eca2afb4806f1032872fa97d1834b3c1385276]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/vquic/vquic.c | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/lib/vquic/vquic.c b/lib/vquic/vquic.c
+index 2f0e072951..475f18e04a 100644
+--- a/lib/vquic/vquic.c
++++ b/lib/vquic/vquic.c
+@@ -454,8 +454,10 @@ static CURLcode recvmmsg_packets(struct Curl_cfilter *cf,
+     VERBOSE(++calls);
+     for(i = 0; i < mcount; ++i) {
+       /* A zero-length UDP packet is no QUIC packet. Ignore. */
+-      if(!mmsg[i].msg_len)
++      if(!mmsg[i].msg_len) {
++        ++pkts;
+         continue;
++      }
+       total_nread += mmsg[i].msg_len;
+ 
+       gso_size = vquic_msghdr_get_udp_gro(&mmsg[i].msg_hdr);
+@@ -538,8 +540,10 @@ static CURLcode recvmsg_packets(struct Curl_cfilter *cf,
+     ++calls;
+ 
+     /* A 0-length UDP packet is no QUIC packet */
+-    if(!nread)
++    if(!nread) {
++      ++pkts;
+       continue;
++    }
+ 
+     gso_size = vquic_msghdr_get_udp_gro(&msg);
+     if(gso_size == 0)
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 7497337cb95..6c9801f8792 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -27,6 +27,7 @@ SRC_URI = " \
     file://CVE-2026-8927.patch \
     file://CVE-2026-8932-dependent.patch \
     file://CVE-2026-8932.patch \
+    file://CVE-2026-11352.patch \
 "
 
 SRC_URI:append:class-nativesdk = " \


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 33/38] curl: patch CVE-2026-11586
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (31 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
                   ` (4 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Peter Marko <peter.marko@siemens.com>

Pick patch per [1].
Resolve fuzz caused by having additional tests in new version.

[1] https://curl.se/docs/CVE-2026-11586.html

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../curl/curl/CVE-2026-11586.patch            | 203 ++++++++++++++++++
 meta/recipes-support/curl/curl_8.19.0.bb      |   1 +
 2 files changed, 204 insertions(+)
 create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11586.patch

diff --git a/meta/recipes-support/curl/curl/CVE-2026-11586.patch b/meta/recipes-support/curl/curl/CVE-2026-11586.patch
new file mode 100644
index 00000000000..3444166b326
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-11586.patch
@@ -0,0 +1,203 @@
+From 849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Mon, 8 Jun 2026 16:57:01 +0200
+Subject: [PATCH] ws: make pong sending lazy
+
+Do not send PONG frames unless there is sufficient space left in the
+websocket send buffer. A server might be lazy in reading our data and
+intermediary PONG frames can be skipped by a client (RFC 6455, ch.
+5.5.3).
+
+Add test case measuring no real RSS increase on a server blasting with
+PING frames.
+
+Closes #21911
+
+CVE: CVE-2026-11586
+Upstream-Status: Backport [https://github.com/curl/curl/commit/849317ff5c5a5e13f50ec3d001e46ddffa77d8a4]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/ws.c                         | 33 +++++++++-----
+ tests/http/test_20_websockets.py | 78 ++++++++++++++++++++++++++++++++
+ 2 files changed, 99 insertions(+), 12 deletions(-)
+
+diff --git a/lib/ws.c b/lib/ws.c
+index d7840f1ffb..d00891b83f 100644
+--- a/lib/ws.c
++++ b/lib/ws.c
+@@ -632,6 +632,7 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data,
+                                  size_t plen,
+                                  unsigned int frame_type)
+ {
++  (void)data;
+   DEBUGASSERT(plen <= WS_MAX_CNTRL_LEN);
+   if(plen > WS_MAX_CNTRL_LEN)
+     return CURLE_BAD_FUNCTION_ARGUMENT;
+@@ -641,13 +642,6 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data,
+   ws->pending.type = frame_type;
+   ws->pending.payload_len = plen;
+   memcpy(ws->pending.payload, payload, plen);
+-
+-  if(!ws->enc.payload_remain) { /* not in the middle of another frame */
+-    CURLcode result = ws_enc_add_pending(data, ws);
+-    if(!result)
+-      (void)ws_flush(data, ws, Curl_is_in_callback(data));
+-    return result;
+-  }
+   return CURLE_OK;
+ }
+ 
+@@ -716,7 +710,7 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+ {
+   struct ws_cw_ctx *ctx = writer->ctx;
+   struct websocket *ws;
+-  CURLcode result;
++  CURLcode result = CURLE_OK;
+ 
+   CURL_TRC_WRITE(data, "ws_cw_write(len=%zu, type=%d)", nbytes, type);
+   if(!(type & CLIENTWRITE_BODY) || data->set.ws_raw_mode)
+@@ -749,7 +743,8 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+     if(result == CURLE_AGAIN) {
+       /* insufficient amount of data, keep it for later.
+        * we pretend to have written all since we have a copy */
+-      return CURLE_OK;
++      result = CURLE_OK;
++      goto out;
+     }
+     else if(result) {
+       failf(data, "[WS] decode payload error %d", (int)result);
+@@ -760,10 +755,16 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+   if((type & CLIENTWRITE_EOS) && !Curl_bufq_is_empty(&ctx->buf)) {
+     failf(data, "[WS] decode ending with %zd frame bytes remaining",
+           Curl_bufq_len(&ctx->buf));
+-    return CURLE_RECV_ERROR;
++    result = CURLE_RECV_ERROR;
+   }
+ 
+-  return CURLE_OK;
++out:
++  if(!result) {
++    result = ws_flush(data, ws, Curl_is_in_callback(data));
++    if(result == CURLE_AGAIN)
++      result = CURLE_OK;
++  }
++  return result;
+ }
+ 
+ /* WebSocket payload decoding client writer. */
+@@ -1627,8 +1628,16 @@ CURLcode curl_ws_recv(CURL *d, void *buffer,
+ static CURLcode ws_flush(struct Curl_easy *data, struct websocket *ws,
+                          bool blocking)
+ {
++  CURLcode result;
++
++  /* If there is space, add any pending control frame */
++  if(Curl_bufq_len(&ws->sendbuf) < ws->sendbuf.chunk_size) {
++    result = ws_enc_add_pending(data, ws);
++    if(result && (result != CURLE_AGAIN))
++      return result;
++  }
++
+   if(!Curl_bufq_is_empty(&ws->sendbuf)) {
+-    CURLcode result;
+     const uint8_t *out;
+     size_t outlen, n;
+ #ifdef DEBUGBUILD
+diff --git a/tests/http/test_20_websockets.py b/tests/http/test_20_websockets.py
+index 3a55d41b2b..00fc394a3b 100644
+--- a/tests/http/test_20_websockets.py
++++ b/tests/http/test_20_websockets.py
+@@ -24,11 +24,15 @@
+ #
+ ###########################################################################
+ #
++import base64
++import hashlib
+ import logging
+ import os
++import re
+ import shutil
+ import socket
+ import subprocess
++import threading
+ import time
+ from datetime import datetime, timedelta
+ from typing import Dict
+@@ -207,3 +211,77 @@ class TestWebsockets:
+         large = 0
+         r = client.run(args=[f'-{model}', '-c', str(count), '-m', str(large), url])
+         r.check_exit_code(0)
++
++    def test_20_11_crazy_pings(self, env: Env):
++        st = {}
++        send_rounds = 1
++
++        def srv():
++            try:
++                with socket.socket() as s:
++                    s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
++                    s.bind(("127.0.0.1", 0))
++                    s.listen(1)
++                    st["p"] = s.getsockname()[1]
++
++                    c, _ = s.accept()
++                    c.setsockopt(socket.SOL_SOCKET, socket.SO_RCVBUF, 4096)
++                    c.settimeout(Env.SERVER_TIMEOUT)
++                    req = b""
++                    while b"\r\n\r\n" not in req:
++                        req += c.recv(4096)
++
++                    k = re.search(rb"(?im)^Sec-WebSocket-Key:\s*(\S+)", req).group(1)
++                    a = base64.b64encode(
++                        hashlib.sha1(k + b"258EAFA5-E914-47DA-95CA-C5AB0DC85B11").digest()
++                    ).decode()
++                    c.sendall(
++                        (
++                            "HTTP/1.1 101 Switching Protocols\r\n"
++                            "Upgrade: websocket\r\n"
++                            "Connection: Upgrade\r\n"
++                            f"Sec-WebSocket-Accept: {a}\r\n\r\n"
++                        ).encode()
++                    )
++
++                    f = b"\x89\x00" * 65536  # PING frames, many
++                    try:
++                        for _ in range(send_rounds):
++                            c.sendall(f)
++                        f = b"\x88\x00"  # CLOSE frame
++                        c.sendall(f)
++                    except OSError:
++                        pass
++                    time.sleep(1)
++                    c.close()
++            except OSError as e:
++                st["err"] = e
++
++        curl = CurlClient(env=env)
++        send_rounds = 2
++        threading.Thread(target=srv, daemon=True).start()
++        while "p" not in st and "err" not in st:
++            time.sleep(0.01)
++        assert "err" not in st, f'ws-ping server failed to start: {st["err"]}'
++
++        url = f'ws://127.0.0.1:{st["p"]}/'
++        r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True,
++                               with_profile=True)
++        assert r.exit_code in [55, 56], f'{r.dump_logs()}'  # SEND/RECV_ERROR
++        assert r.profile, f'{r}'
++        rss1 = r.profile.stats['rss'] / (1024 * 1024)
++
++        st.clear()
++        send_rounds = 10
++        threading.Thread(target=srv, daemon=True).start()
++        while "p" not in st and "err" not in st:
++            time.sleep(0.01)
++        assert "err" not in st, f'ws-ping server failed to start: {st["err"]}'
++
++        url = f'ws://127.0.0.1:{st["p"]}/'
++        r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True,
++                               with_profile=True)
++        assert r.exit_code in [55, 56], f'{r.dump_logs()}'  # SEND/RECV_ERROR
++        assert r.profile, f'{r}'
++        rss2 = r.profile.stats['rss'] / (1024 * 1024)
++        assert (rss1 * 1.1) >= rss2, 'bad memory increase'
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 6c9801f8792..a964868d872 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -28,6 +28,7 @@ SRC_URI = " \
     file://CVE-2026-8932-dependent.patch \
     file://CVE-2026-8932.patch \
     file://CVE-2026-11352.patch \
+    file://CVE-2026-11586.patch \
 "
 
 SRC_URI:append:class-nativesdk = " \


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (32 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
                   ` (3 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>

Backport patch to fix CVE-2026-33845.

References:
  https://nvd.nist.gov/vuln/detail/CVE-2026-33845

Upstream fix:
  https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413

Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../gnutls/gnutls/CVE-2026-33845.patch        | 166 ++++++++++++++++++
 meta/recipes-support/gnutls/gnutls_3.8.12.bb  |   1 +
 2 files changed, 167 insertions(+)
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch

diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
new file mode 100644
index 00000000000..004d3082c5a
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
@@ -0,0 +1,166 @@
+From 490bfb28002fc0253010243ac387c756014c06e5 Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Mon, 23 Mar 2026 15:09:43 +0100
+Subject: [PATCH] buffers: switch from end_offset over to frag_length
+
+Instead of maintaining an inclusive [start_offset, end_offset] range
+when reassembling DTLS handshake,
+track start_offset and a relative frag_length instead.
+
+You'd think it'd be a no-op, but it fixes:
+
+* 0-length fragments triggering completion if message was 1 byte long
+* a remotely triggerable underflow and an ensuing heap overrun
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1811
+Fixes: CVE-2026-33845
+Fixes: GNUTLS-SA-2026-04-29-3
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+
+CVE: CVE-2026-33845
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413]
+Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
+---
+ lib/buffers.c    | 50 +++++++++++++++++++++++++-----------------------
+ lib/gnutls_int.h |  4 ++--
+ 2 files changed, 28 insertions(+), 26 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index 09779a8f3..02cc222c4 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -919,10 +919,7 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel,
+ 	}
+ 	data_size = _mbuffer_get_udata_size(bufel) - handshake_header_size;
+ 
+-	if (frag_size > 0)
+-		hsk->end_offset = hsk->start_offset + frag_size - 1;
+-	else
+-		hsk->end_offset = 0;
++	hsk->frag_length = frag_size;
+ 
+ 	_gnutls_handshake_log(
+ 		"HSK[%p]: %s (%u) was received. Length %d[%d], frag offset %d, frag length: %d, sequence: %d\n",
+@@ -936,9 +933,10 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel,
+ 
+ 	if (hsk->length > 0 &&
+ 	    (frag_size > data_size ||
+-	     (frag_size > 0 && hsk->end_offset >= hsk->length))) {
++	     (frag_size > 0 && hsk->start_offset + frag_size > hsk->length))) {
+ 		return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH);
+-	} else if (hsk->length == 0 && hsk->end_offset != 0 &&
++	} else if (hsk->length == 0 &&
++		   hsk->start_offset + frag_size != hsk->start_offset &&
+ 		   hsk->start_offset != 0)
+ 		return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH);
+ 
+@@ -1002,11 +1000,10 @@ static int merge_handshake_packet(gnutls_session_t session,
+ 			hsk->data.length = hsk->length;
+ 		}
+ 
+-		if (hsk->length > 0 && hsk->end_offset > 0 &&
+-		    hsk->end_offset - hsk->start_offset + 1 != hsk->length) {
++		if (hsk->length > 0 && hsk->frag_length > 0 &&
++		    hsk->frag_length != hsk->length) {
+ 			memmove(&hsk->data.data[hsk->start_offset],
+-				hsk->data.data,
+-				hsk->end_offset - hsk->start_offset + 1);
++				hsk->data.data, hsk->frag_length);
+ 		}
+ 
+ 		session->internals.handshake_recv_buffer_size++;
+@@ -1040,20 +1037,27 @@ static int merge_handshake_packet(gnutls_session_t session,
+ 		}
+ 
+ 		if (hsk->start_offset < recv_buf[pos].start_offset &&
+-		    hsk->end_offset + 1 >= recv_buf[pos].start_offset) {
++		    hsk->start_offset + hsk->frag_length >=
++			    recv_buf[pos].start_offset) {
+ 			memcpy(&recv_buf[pos].data.data[hsk->start_offset],
+ 			       hsk->data.data, hsk->data.length);
+ 			recv_buf[pos].start_offset = hsk->start_offset;
+-			recv_buf[pos].end_offset =
+-				MIN(hsk->end_offset, recv_buf[pos].end_offset);
+-		} else if (hsk->end_offset > recv_buf[pos].end_offset &&
+-			   hsk->start_offset <= recv_buf[pos].end_offset + 1) {
++			recv_buf[pos].frag_length = MIN(
++				hsk->frag_length, recv_buf[pos].frag_length);
++		} else if (hsk->start_offset + hsk->frag_length >
++				   recv_buf[pos].start_offset +
++					   recv_buf[pos].frag_length &&
++			   hsk->start_offset <=
++				   recv_buf[pos].start_offset +
++					   recv_buf[pos].frag_length) {
+ 			memcpy(&recv_buf[pos].data.data[hsk->start_offset],
+ 			       hsk->data.data, hsk->data.length);
+ 
+-			recv_buf[pos].end_offset = hsk->end_offset;
+ 			recv_buf[pos].start_offset = MIN(
+ 				hsk->start_offset, recv_buf[pos].start_offset);
++			recv_buf[pos].frag_length = hsk->start_offset +
++						    hsk->frag_length -
++						    recv_buf[pos].start_offset;
+ 		}
+ 		_gnutls_handshake_buffer_clear(hsk);
+ 	}
+@@ -1113,8 +1117,8 @@ static int get_last_packet(gnutls_session_t session,
+ 		}
+ 
+ 		else if ((recv_buf[LAST_ELEMENT].start_offset == 0 &&
+-			  recv_buf[LAST_ELEMENT].end_offset ==
+-				  recv_buf[LAST_ELEMENT].length - 1) ||
++			  recv_buf[LAST_ELEMENT].frag_length ==
++				  recv_buf[LAST_ELEMENT].length) ||
+ 			 recv_buf[LAST_ELEMENT].length == 0) {
+ 			session->internals.dtls.hsk_read_seq++;
+ 			_gnutls_handshake_buffer_move(hsk,
+@@ -1125,8 +1129,9 @@ static int get_last_packet(gnutls_session_t session,
+ 			/* if we don't have a complete handshake message, but we
+ 			 * have queued data waiting, try again to reconstruct the
+ 			 * handshake packet, using the queued */
+-			if (recv_buf[LAST_ELEMENT].end_offset !=
+-				    recv_buf[LAST_ELEMENT].length - 1 &&
++			if ((recv_buf[LAST_ELEMENT].start_offset +
++			     recv_buf[LAST_ELEMENT].frag_length) !=
++				    recv_buf[LAST_ELEMENT].length &&
+ 			    record_check_unprocessed(session) > 0)
+ 				return gnutls_assert_val(
+ 					GNUTLS_E_INT_CHECK_AGAIN);
+@@ -1313,9 +1318,7 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session)
+ 					&session->internals.record_buffer,
+ 					bufel, ret);
+ 
+-				data_size = MIN(tmp.length,
+-						tmp.end_offset -
+-							tmp.start_offset + 1);
++				data_size = MIN(tmp.length, tmp.frag_length);
+ 
+ 				ret = _gnutls_buffer_append_data(
+ 					&tmp.data,
+@@ -1331,7 +1334,6 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session)
+ 				ret = merge_handshake_packet(session, &tmp);
+ 				if (ret < 0)
+ 					return gnutls_assert_val(ret);
+-
+ 			} while (_mbuffer_get_udata_size(bufel) > 0);
+ 
+ 			prev = bufel;
+diff --git a/lib/gnutls_int.h b/lib/gnutls_int.h
+index 54d3c9f67..283f25c07 100644
+--- a/lib/gnutls_int.h
++++ b/lib/gnutls_int.h
+@@ -479,10 +479,10 @@ typedef struct {
+ 	uint16_t sequence;
+ 
+ 	/* indicate whether that message is complete.
+-	 * complete means start_offset == 0 and end_offset == length
++	 * complete means start_offset == 0 and frag_length == length
+ 	 */
+ 	uint32_t start_offset;
+-	uint32_t end_offset;
++	uint32_t frag_length; /* used exclusively in DTLS reassembly */
+ 
+ 	uint8_t header[MAX_HANDSHAKE_HEADER_SIZE];
+ 	int header_size;
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
index 51ef394dfcf..d513752072c 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
@@ -40,6 +40,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
            file://CVE-2026-42011_p1.patch \
            file://CVE-2026-42011_p2.patch \
            file://CVE-2026-42010.patch \
+           file://CVE-2026-33845.patch \
            "
 
 SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (33 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
                   ` (2 subsequent siblings)
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Vijay Anusuri <vanusuri@mvista.com>

Pick patch according to [2]

[1] https://nvd.nist.gov/vuln/detail/cve-2026-57433
[2] https://security-tracker.debian.org/tracker/CVE-2026-57433

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../perl/files/CVE-2026-57433.patch           | 32 +++++++++++++++++++
 meta/recipes-devtools/perl/perl_5.42.0.bb     |  1 +
 2 files changed, 33 insertions(+)
 create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch

diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57433.patch b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch
new file mode 100644
index 00000000000..f0ea08b1fe0
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch
@@ -0,0 +1,32 @@
+From e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Sat, 9 May 2026 16:47:14 +0100
+Subject: [PATCH] Storable.xs: Avoid signed int overflow when unpacking a list
+ of hook data items
+
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7]
+CVE: CVE-2026-57433
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ dist/Storable/Storable.xs | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/dist/Storable/Storable.xs b/dist/Storable/Storable.xs
+index 3930db6..62a1a6d 100644
+--- a/dist/Storable/Storable.xs
++++ b/dist/Storable/Storable.xs
+@@ -5035,7 +5035,10 @@ static SV *retrieve_hook_common(pTHX_ stcxt_t *cxt, const char *cname, int large
+         }
+         else
+             GETMARK(len3);
+-        if (len3) {
++        if (len3 == I32_MAX)
++            /* If len3 is exactly I32_MAX it will upset av_extend below */
++            CROAK(("Invalid count of hook data items"));
++        else if (len3) {
+             av = newAV();
+             av_extend(av, len3 + 1);    /* Leave room for [0] */
+             AvFILLp(av) = len3;         /* About to be filled anyway */
+-- 
+2.43.0
+
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 3469258f727..6f0092c1cc7 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -22,6 +22,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
            file://CVE-2026-57432-01.patch \
            file://CVE-2026-57432-02.patch \
            file://CVE-2026-42496.patch \
+           file://CVE-2026-57433.patch \
            "
 SRC_URI:append:class-native = " \
            file://perl-configpm-switch.patch \


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (34 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
It also includes the upstream follow-up in [3],
which preserves 64-bit wgint parsing on 32-bit targets.

[1] https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58470
[3] https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

(cherry picked from commit 9b2b418a1546ae4bd6d044474765fa817e9a95f8)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../wget/wget/CVE-2026-58470-regression.patch | 48 +++++++++++
 .../wget/wget/CVE-2026-58470.patch            | 79 +++++++++++++++++++
 meta/recipes-extended/wget/wget_1.25.0.bb     |  2 +
 3 files changed, 129 insertions(+)
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch

diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
new file mode 100644
index 00000000000..c452261a9ac
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
@@ -0,0 +1,48 @@
+From 01ff771caac1958662ca8665eed2021ec386a7af Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Wed, 12 Aug 2026 19:45:21 +0200
+Subject: [PATCH] * src/http.c (parse_content_range): Use strtoll instead of
+ strtol.
+
+CVE: CVE-2026-58470
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af]
+
+(cherry picked from commit 01ff771caac1958662ca8665eed2021ec386a7af)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/http.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/src/http.c b/src/http.c
+index e5e75ee695..8170a43c27 100644
+--- a/src/http.c
++++ b/src/http.c
+@@ -949,7 +949,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+     return false;
+ 
+   errno = 0;
+-  num = strtol(hdr, &end, 10);
++  num = strtoll(hdr, &end, 10);
+   if (errno == ERANGE)
+     return false;
+   hdr = end;
+@@ -959,7 +959,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+   *first_byte_ptr = num;
+ 
+   errno = 0;
+-  num = strtol(hdr, &end, 10);
++  num = strtoll(hdr, &end, 10);
+   if (errno == ERANGE)
+     return false;
+   hdr = end;
+@@ -976,7 +976,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+   else
+     {
+       errno = 0;
+-      num = strtol(hdr, NULL, 10);
++      num = strtoll(hdr, NULL, 10);
+       if (errno == ERANGE)
+         return false;
+     }
+-- 
+2.35.6
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
new file mode 100644
index 00000000000..5d864c5fda6
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
@@ -0,0 +1,79 @@
+From 8740efcdd0d9e7eb04122f63bdb151f1f4d94af8 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Mon, 29 Jun 2026 18:57:54 +0200
+Subject: [PATCH] * src/http.c (parse_content_range): Fix integer overflow
+
+Reported-by: TristanInSec@gmail.com
+
+CVE: CVE-2026-58470
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf]
+
+(cherry picked from commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/http.c | 35 ++++++++++++++++++++++++-----------
+ 1 file changed, 24 insertions(+), 11 deletions(-)
+
+diff --git a/src/http.c b/src/http.c
+index 07af1867..ea2e591b 100644
+--- a/src/http.c
++++ b/src/http.c
+@@ -914,6 +914,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+                      wgint *last_byte_ptr, wgint *entity_length_ptr)
+ {
+   wgint num;
++  char *end;
+ 
+   /* Ancient versions of Netscape proxy server, presumably predating
+      rfc2068, sent out `Content-Range' without the "bytes"
+@@ -932,27 +933,39 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+     }
+   if (!c_isdigit (*hdr))
+     return false;
+-  for (num = 0; c_isdigit (*hdr); hdr++)
+-    num = 10 * num + (*hdr - '0');
+-  if (*hdr != '-' || !c_isdigit (*(hdr + 1)))
++
++  errno = 0;
++  num = strtol(hdr, &end, 10);
++  if (errno == ERANGE)
++    return false;
++  hdr = end;
++
++  if (*hdr++ != '-' || !c_isdigit (*hdr))
+     return false;
+   *first_byte_ptr = num;
+-  ++hdr;
+-  for (num = 0; c_isdigit (*hdr); hdr++)
+-    num = 10 * num + (*hdr - '0');
+-  if (*hdr != '/')
++
++  errno = 0;
++  num = strtol(hdr, &end, 10);
++  if (errno == ERANGE)
++    return false;
++  hdr = end;
++
++  if (*hdr++ != '/')
+     return false;
+   *last_byte_ptr = num;
+-  if (!(c_isdigit (*(hdr + 1)) || *(hdr + 1) == '*'))
++  if (!(c_isdigit (*hdr) || *hdr == '*'))
+     return false;
+   if (*last_byte_ptr < *first_byte_ptr)
+     return false;
+-  ++hdr;
+   if (*hdr == '*')
+     num = -1;
+   else
+-    for (num = 0; c_isdigit (*hdr); hdr++)
+-      num = 10 * num + (*hdr - '0');
++    {
++      errno = 0;
++      num = strtol(hdr, NULL, 10);
++      if (errno == ERANGE)
++        return false;
++    }
+   *entity_length_ptr = num;
+   if ((*entity_length_ptr <= *last_byte_ptr) && *entity_length_ptr != -1)
+     return false;
diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb
index 95845d695a9..26f5c84e5a7 100644
--- a/meta/recipes-extended/wget/wget_1.25.0.bb
+++ b/meta/recipes-extended/wget/wget_1.25.0.bb
@@ -22,6 +22,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
            file://CVE-2026-58472.patch \
            file://CVE-2026-58472-regression.patch \
            file://CVE-2026-16599.patch \
+           file://CVE-2026-58470.patch \
+           file://CVE-2026-58470-regression.patch \
            "
 
 SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (35 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  2026-09-09  7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Hetvi Thakar <hthakar@cisco.com>

This patch backports the upstream fix for CVE-2026-8643 and the two
follow-up regression fixes. The primary commit is included in pip
26.1.2 and referenced in [1]. The public CVE advisory is referenced
in [2].

The first follow-up fixes doubled-slash directory handling and the
second reuses pip's shared directory-containment helper. The upstream
regression commits are referenced in [3] and [4].

[1] https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
[2] https://github.com/advisories/GHSA-wf93-45jw-7689
[3] https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5
[4] https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 .../CVE-2026-8643-regression_p1.patch         | 35 ++++++++
 .../CVE-2026-8643-regression_p2.patch         | 69 ++++++++++++++++
 .../python/python3-pip/CVE-2026-8643.patch    | 80 +++++++++++++++++++
 .../python/python3-pip_26.0.1.bb              |  3 +
 4 files changed, 187 insertions(+)
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
 create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch

diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
new file mode 100644
index 00000000000..e269dca667b
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
@@ -0,0 +1,35 @@
+From 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5 Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Mon, 18 May 2026 23:22:51 -0400
+Subject: [PATCH] Fix is_within_directory for doubled-slash roots
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5]
+
+Backport Changes:
+- Omitted tests/unit/test_utils_unpacking.py because the pip 26.0.1
+  PyPI sdist used by this recipe does not ship the upstream tests
+  directory.
+
+(cherry picked from commit 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/utils/unpacking.py | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py
+index 879b40c37e..ba7cb52579 100644
+--- a/src/pip/_internal/utils/unpacking.py
++++ b/src/pip/_internal/utils/unpacking.py
+@@ -83,8 +83,7 @@ def is_within_directory(directory: str, target: str) -> bool:
+     abs_directory = os.path.abspath(directory)
+     abs_target = os.path.abspath(target)
+ 
+-    prefix = os.path.commonpath([abs_directory, abs_target])
+-    return prefix == abs_directory
++    return abs_target == abs_directory or abs_target.startswith(abs_directory + os.sep)
+ 
+ 
+ def _get_default_mode_plus_executable() -> int:
+-- 
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
new file mode 100644
index 00000000000..bd40e3b9e8f
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
@@ -0,0 +1,69 @@
+From fa7854f6b37113a2c4698cdde902e1fcc9bebdd5 Mon Sep 17 00:00:00 2001
+From: Damian <damian.peter.shaw@gmail.com>
+Date: Sun, 24 May 2026 14:54:47 -0400
+Subject: [PATCH] Use is_within_directory for entry point check
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5]
+
+Backport Changes:
+- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist
+  used by this recipe does not ship the upstream tests directory.
+
+(cherry picked from commit fa7854f6b37113a2c4698cdde902e1fcc9bebdd5)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/operations/install/wheel.py | 18 ++++++------------
+ src/pip/_internal/utils/unpacking.py          |  1 +
+ 2 files changed, 7 insertions(+), 12 deletions(-)
+
+diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py
+index 231e400658..6f9a983364 100644
+--- a/src/pip/_internal/operations/install/wheel.py
++++ b/src/pip/_internal/operations/install/wheel.py
+@@ -397,17 +397,6 @@ class MissingCallableSuffix(InstallationError):
+         )
+ 
+ 
+-def _script_within_dir(name: str, scripts_dir: str) -> bool:
+-    """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
+-
+-    distlib joins the entry point name onto the scripts directory, so a name
+-    with path separators or ``..`` components can resolve elsewhere.
+-    """
+-    root = os.path.normpath(scripts_dir)
+-    dest = os.path.normpath(os.path.join(scripts_dir, name))
+-    return dest.startswith(root + os.sep)
+-
+-
+ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+     entry = get_export_entry(specification)
+     if entry is None:
+@@ -416,7 +405,12 @@ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+     if entry.suffix is None:
+         raise MissingCallableSuffix(str(entry))
+ 
+-    if not _script_within_dir(entry.name, scripts_dir):
++    # distlib joins the entry point name onto the scripts directory, so a name
++    # with path separators or ``..`` components can resolve elsewhere. The script
++    # must resolve to a path strictly inside the scripts directory.
++    dest = os.path.join(scripts_dir, entry.name)
++    resolves_to_scripts_dir = os.path.abspath(dest) == os.path.abspath(scripts_dir)
++    if resolves_to_scripts_dir or not is_within_directory(scripts_dir, dest):
+         raise InstallationError(
+             f"Invalid script entry point name {entry.name!r}: the script "
+             f"would be installed outside the scripts directory ({scripts_dir})."
+diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py
+index ba7cb52579..8a9b2059ca 100644
+--- a/src/pip/_internal/utils/unpacking.py
++++ b/src/pip/_internal/utils/unpacking.py
+@@ -79,6 +79,7 @@ def has_leading_dir(paths: Iterable[str]) -> bool:
+ def is_within_directory(directory: str, target: str) -> bool:
+     """
+     Return true if the absolute path of target is within the directory
++    (including when target is equal to the directory).
+     """
+     abs_directory = os.path.abspath(directory)
+     abs_target = os.path.abspath(target)
+-- 
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
new file mode 100644
index 00000000000..2f38ad0207c
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
@@ -0,0 +1,80 @@
+From 483d83c13c9d69c1916c06cab29991f6c2725cee Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Wed, 20 May 2026 15:20:25 -0400
+Subject: [PATCH] Reject entry point names that escape scripts dir (#14000)
+
+* Reject entry point names that escape scripts dir
+
+* NEWS ENTRY
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb]
+
+Backport Changes:
+- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist
+  does not ship the upstream test suite and the OE recipe does not
+  enable ptest.
+
+(cherry picked from commit 8eb178480bd1a2b223f509fc430796b265158dfb)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ news/14000.bugfix.rst                         |  2 ++
+ src/pip/_internal/operations/install/wheel.py | 26 ++++++++++++++++---
+ 2 files changed, 25 insertions(+), 3 deletions(-)
+ create mode 100644 news/14000.bugfix.rst
+
+diff --git a/news/14000.bugfix.rst b/news/14000.bugfix.rst
+new file mode 100644
+index 000000000..3b86f1b3b
+--- /dev/null
++++ b/news/14000.bugfix.rst
+@@ -0,0 +1,2 @@
++Reject ``console_scripts`` and ``gui_scripts`` entry points whose name would
++install a script outside the scripts directory.
+diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py
+index 40097d6a7..231e40065 100644
+--- a/src/pip/_internal/operations/install/wheel.py
++++ b/src/pip/_internal/operations/install/wheel.py
+@@ -397,11 +397,31 @@ class MissingCallableSuffix(InstallationError):
+         )
+ 
+ 
+-def _raise_for_invalid_entrypoint(specification: str) -> None:
++def _script_within_dir(name: str, scripts_dir: str) -> bool:
++    """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
++
++    distlib joins the entry point name onto the scripts directory, so a name
++    with path separators or ``..`` components can resolve elsewhere.
++    """
++    root = os.path.normpath(scripts_dir)
++    dest = os.path.normpath(os.path.join(scripts_dir, name))
++    return dest.startswith(root + os.sep)
++
++
++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+     entry = get_export_entry(specification)
+-    if entry is not None and entry.suffix is None:
++    if entry is None:
++        return
++
++    if entry.suffix is None:
+         raise MissingCallableSuffix(str(entry))
+ 
++    if not _script_within_dir(entry.name, scripts_dir):
++        raise InstallationError(
++            f"Invalid script entry point name {entry.name!r}: the script "
++            f"would be installed outside the scripts directory ({scripts_dir})."
++        )
++
+ 
+ class PipScriptMaker(ScriptMaker):
+     # Override distlib's default script template with one that
+@@ -419,7 +439,7 @@ class PipScriptMaker(ScriptMaker):
+     def make(
+         self, specification: str, options: dict[str, Any] | None = None
+     ) -> list[str]:
+-        _raise_for_invalid_entrypoint(specification)
++        _raise_for_invalid_entrypoint(specification, self.target_dir)
+         return super().make(specification, options)
+ 
+ 
diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
index 3ff6cd39cd2..b6581575580 100644
--- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
+++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
@@ -26,6 +26,9 @@ inherit pypi python_setuptools_build_meta
 
 SRC_URI += "file://no_shebang_mangling.patch \
             file://CVE-2026-13346.patch \
+            file://CVE-2026-8643.patch \
+            file://CVE-2026-8643-regression_p1.patch \
+            file://CVE-2026-8643-regression_p2.patch \
            "
 
 SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8"


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite
  2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
                   ` (36 preceding siblings ...)
  2026-09-09  7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
@ 2026-09-09  7:29 ` Yoann Congal
  37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09  7:29 UTC (permalink / raw)
  To: openembedded-core

From: Himani Ramesh Barde <HimaniRamesh.Barde@windriver.com>

randtest performs autocorrelation analysis on random number sequences
and fails intermittently on overloaded CI/autobuilder systems where
CPU scheduling and floating point conditions vary between runs.

An upstream fix was previously merged (ccabae3036a7) to improve sigma
threshold handling, but the test failed again on qemux86-64-musl-ptest
on 2026-07-21 with 'Tau= 162, Autocorr= 5.15181 sigma'.

The test is inherently unsuitable for shared overloaded build
infrastructure. Skip it, consistent with how 'time' and 'timeout'
are already handled.

[YOCTO #16254]

Signed-off-by: Himani Barde <HimaniRamesh.Barde@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 5266eed8f8c2096462da720093aa1556df726098)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
 meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/meta/recipes-extended/gawk/gawk_5.4.0.bb b/meta/recipes-extended/gawk/gawk_5.4.0.bb
index f44d82b37c5..5be7efad452 100644
--- a/meta/recipes-extended/gawk/gawk_5.4.0.bb
+++ b/meta/recipes-extended/gawk/gawk_5.4.0.bb
@@ -85,7 +85,10 @@ do_install_ptest() {
 	# https://bugzilla.yoctoproject.org/show_bug.cgi?id=14371
 	rm -f ${D}${PTEST_PATH}/test/time.*
 	rm -f ${D}${PTEST_PATH}/test/timeout.*
-	for t in time timeout; do
+	# randtest is a statistical test that intermittently fails on overloaded systems
+	# https://bugzilla.yoctoproject.org/show_bug.cgi?id=16254
+	rm -f ${D}${PTEST_PATH}/test/randtest.*
+	for t in time timeout randtest; do
 		echo $t >> ${D}${PTEST_PATH}/test/skipped.txt
 	done
 }


^ permalink raw reply related	[flat|nested] 42+ messages in thread

* Re: [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007
  2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
@ 2026-09-09 17:00   ` Yoann Congal
  0 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 17:00 UTC (permalink / raw)
  To: Yoann Congal, openembedded-core

On Wed Sep 9, 2026 at 9:29 AM CEST, Yoann Congal wrote:
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Analysis:
> - NVD identifies the vulnerable code as net/tcp.c when
>   CONFIG_PROT_TCP is enabled [1].
> - tools-only_defconfig disables networking, so this code is not built
>   into u-boot-tools [2].
> - Hence ignoring the CVE for this recipe.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
> [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
>
> Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
> ---
>  meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> index 7eaf721ca83..0e57bb88849 100644
> --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> @@ -1,2 +1,4 @@
>  require u-boot-common.inc
>  require u-boot-tools.inc
> +
> +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."

Hello,

I just noticed that these CVEs are not visible from our tracking because
the CPE is "u-boot" vs the PN "u-boot-tools".

To fix this, I plan to add to this series the recent patch:
[wrynose][PATCH] u-boot: share CVE_PRODUCT with u-boot-tools - Hiago De Franco
https://lore.kernel.org/all/20260909-uboot-cve-product-wrynose-v1-1-072b994b426f@baylibre.com/

Regards,
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 42+ messages in thread

* Re: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
  2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
@ 2026-09-10  4:42   ` Hemanth Kumar M D
  2026-09-10 12:53     ` Yoann Congal
  0 siblings, 1 reply; 42+ messages in thread
From: Hemanth Kumar M D @ 2026-09-10  4:42 UTC (permalink / raw)
  To: openembedded-core, Yoann Congal

[-- Attachment #1: Type: text/plain, Size: 7063 bytes --]

Hi Yoann,

This CVE patch will come with the glibc 2.43 stable branch updates:
https://lists.openembedded.org/g/openembedded-core/message/245453 
<https://lists.openembedded.org/g/openembedded-core/message/245453>

Please drop this patch.

On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
> CAUTION: This email comes from a non Wind River email account!
> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>
> From: Harish Sadineni<Harish.Sadineni@windriver.com>
>
> Allocate the maximum array sizes directly, instead of resizing
> the arrays as needed.  This eliminates alloca usage from the
> function, and fixes the out-of-bounds accesses.  The asserts
> guard against the bug coming back if the balancing of the tree
> turns out not to work correctly.
>
> Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> CVE: CVE-2026-19542
>
> Reference:
> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>
> Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> Signed-off-by: Yoann Congal<yoann.congal@smile.fr>
> [YC: fixed CVE: tag in patch]
> ---
>   .../glibc/glibc/0023-CVE-2026-19542.patch     | 98 +++++++++++++++++++
>   meta/recipes-core/glibc/glibc_2.43.bb         |  1 +
>   2 files changed, 99 insertions(+)
>   create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>
> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> new file mode 100644
> index 00000000000..094a50919dc
> --- /dev/null
> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> @@ -0,0 +1,98 @@
> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
> +From: Florian Weimer<fweimer@redhat.com>
> +Date: Fri, 14 Aug 2026 13:41:16 +0200
> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
> +
> +Allocate the maximum array sizes directly, instead of resizing
> +the arrays as needed.  This eliminates alloca usage from the
> +function, and fixes the out-of-bounds accesses.  The asserts
> +guard against the bug coming back if the balancing of the tree
> +turns out not to work correctly.
> +
> +CVE: CVE-2026-19542
> +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> +
> +Reviewed-by: Adhemerval Zanella<adhemerval.zanella@linaro.org>
> +Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> +---
> + misc/tsearch.c | 31 +++++++++++--------------------
> + 1 file changed, 11 insertions(+), 20 deletions(-)
> +
> +diff --git a/misc/tsearch.c b/misc/tsearch.c
> +index 9b2eb34b25..e517dfa712 100644
> +--- a/misc/tsearch.c
> ++++ b/misc/tsearch.c
> +@@ -85,6 +85,7 @@
> + #include <assert.h>
> + #include <stdalign.h>
> + #include <stddef.h>
> ++#include <stdint.h>
> + #include <stdlib.h>
> + #include <string.h>
> + #include <search.h>
> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +   int cmp;
> +   node *rootp = (node *) vrootp;
> +   node root, unchained;
> +-  /* Stack of nodes so we remember the parents without recursion.  It's
> +-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
> +-     would need to have around 250.000 nodes.  */
> +-  int stacksize = 40;
> ++  /* Stack of nodes so we remember the parents without recursion.  The
> ++     stack size is a conservative approximation of the maximum height
> ++     of a red-black tree, based on size of the address space.
> ++     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
> ++  enum { stacksize = 2 * UINTPTR_WIDTH };
> +   int sp = 0;
> +-  node **nodestack = alloca (sizeof (node *) * stacksize);
> ++  node *nodestack[stacksize];
> +
> +   if (rootp == NULL)
> +     return NULL;
> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +   root = DEREFNODEPTR(rootp);
> +   while ((cmp = (*compar) (key, root->key)) != 0)
> +     {
> +-      if (sp == stacksize)
> +-      {
> +-        node **newstack;
> +-        stacksize += 20;
> +-        newstack = alloca (sizeof (node *) * stacksize);
> +-        nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +-      }
> +-
> ++      assert (sp < stacksize);
> +       nodestack[sp++] = rootp;
> +       p = DEREFNODEPTR(rootp);
> +       if (cmp < 0)
> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +       node upn;
> +       for (;;)
> +       {
> +-        if (sp == stacksize)
> +-          {
> +-            node **newstack;
> +-            stacksize += 20;
> +-            newstack = alloca (sizeof (node *) * stacksize);
> +-            nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +-          }
> ++        assert (sp < stacksize);
> +         nodestack[sp++] = parentp;
> +         parentp = up;
> +         upn = DEREFNODEPTR(up);
> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +                 SETNODEPTR(pp,q);
> +                 /* Make sure pp is right if the case below tries to use
> +                    it.  */
> ++                assert (sp < stacksize);
> +                 nodestack[sp++] = pp = LEFTPTR(q);
> +                 q = RIGHT(p);
> +               }
> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> +                 SETLEFT(p,RIGHT(q));
> +                 SETRIGHT(q,p);
> +                 SETNODEPTR(pp,q);
> ++                assert (sp < stacksize);
> +                 nodestack[sp++] = pp = RIGHTPTR(q);
> +                 q = LEFT(p);
> +               }
> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
> index 9f3a3814d0a..3ef2301191d 100644
> --- a/meta/recipes-core/glibc/glibc_2.43.bb
> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
> @@ -55,6 +55,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
>              file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
>              file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
>              file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
> +file://0023-CVE-2026-19542.patch \
>   "
>   B = "${WORKDIR}/build-${TARGET_SYS}"
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#245430):https://lists.openembedded.org/g/openembedded-core/message/245430
> Mute This Topic:https://lists.openembedded.org/mt/121158859/10244482
> Group Owner:openembedded-core+owner@lists.openembedded.org
> Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [Hemanth.KumarMD@windriver.com]
> -=-=-=-=-=-=-=-=-=-=-=-

-- 
Regards,
Hemanth Kumar M D

[-- Attachment #2: Type: text/html, Size: 9581 bytes --]

^ permalink raw reply	[flat|nested] 42+ messages in thread

* Re: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
  2026-09-10  4:42   ` Hemanth Kumar M D
@ 2026-09-10 12:53     ` Yoann Congal
  0 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-10 12:53 UTC (permalink / raw)
  To: Hemanth Kumar M D, openembedded-core

On Thu Sep 10, 2026 at 6:42 AM CEST, Hemanth Kumar M D wrote:
> Hi Yoann,
>
> This CVE patch will come with the glibc 2.43 stable branch updates:
> https://lists.openembedded.org/g/openembedded-core/message/245453 
> <https://lists.openembedded.org/g/openembedded-core/message/245453>
>
> Please drop this patch.

Right,

For the record, the patch fixing this CVE in this branch is:
0afa34adb0 misc: Fix out-of-bounds array write in tdelete (bug 34506)

I will drop this one before requesting a merge.

Thanks!
>
> On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
>> CAUTION: This email comes from a non Wind River email account!
>> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>>
>> From: Harish Sadineni<Harish.Sadineni@windriver.com>
>>
>> Allocate the maximum array sizes directly, instead of resizing
>> the arrays as needed.  This eliminates alloca usage from the
>> function, and fixes the out-of-bounds accesses.  The asserts
>> guard against the bug coming back if the balancing of the tree
>> turns out not to work correctly.
>>
>> Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> CVE: CVE-2026-19542
>>
>> Reference:
>> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
>> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
>> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>>
>> Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
>> Signed-off-by: Yoann Congal<yoann.congal@smile.fr>
>> [YC: fixed CVE: tag in patch]
>> ---
>>   .../glibc/glibc/0023-CVE-2026-19542.patch     | 98 +++++++++++++++++++
>>   meta/recipes-core/glibc/glibc_2.43.bb         |  1 +
>>   2 files changed, 99 insertions(+)
>>   create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>>
>> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> new file mode 100644
>> index 00000000000..094a50919dc
>> --- /dev/null
>> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> @@ -0,0 +1,98 @@
>> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
>> +From: Florian Weimer<fweimer@redhat.com>
>> +Date: Fri, 14 Aug 2026 13:41:16 +0200
>> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
>> +
>> +Allocate the maximum array sizes directly, instead of resizing
>> +the arrays as needed.  This eliminates alloca usage from the
>> +function, and fixes the out-of-bounds accesses.  The asserts
>> +guard against the bug coming back if the balancing of the tree
>> +turns out not to work correctly.
>> +
>> +CVE: CVE-2026-19542
>> +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> +
>> +Reviewed-by: Adhemerval Zanella<adhemerval.zanella@linaro.org>
>> +Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
>> +---
>> + misc/tsearch.c | 31 +++++++++++--------------------
>> + 1 file changed, 11 insertions(+), 20 deletions(-)
>> +
>> +diff --git a/misc/tsearch.c b/misc/tsearch.c
>> +index 9b2eb34b25..e517dfa712 100644
>> +--- a/misc/tsearch.c
>> ++++ b/misc/tsearch.c
>> +@@ -85,6 +85,7 @@
>> + #include <assert.h>
>> + #include <stdalign.h>
>> + #include <stddef.h>
>> ++#include <stdint.h>
>> + #include <stdlib.h>
>> + #include <string.h>
>> + #include <search.h>
>> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> +   int cmp;
>> +   node *rootp = (node *) vrootp;
>> +   node root, unchained;
>> +-  /* Stack of nodes so we remember the parents without recursion.  It's
>> +-     _very_ unlikely that there are paths longer than 40 nodes.  The tree
>> +-     would need to have around 250.000 nodes.  */
>> +-  int stacksize = 40;
>> ++  /* Stack of nodes so we remember the parents without recursion.  The
>> ++     stack size is a conservative approximation of the maximum height
>> ++     of a red-black tree, based on size of the address space.
>> ++     Actual numbers are closer to 57 (32 bit) and 117 (63 bit).  */
>> ++  enum { stacksize = 2 * UINTPTR_WIDTH };
>> +   int sp = 0;
>> +-  node **nodestack = alloca (sizeof (node *) * stacksize);
>> ++  node *nodestack[stacksize];
>> +
>> +   if (rootp == NULL)
>> +     return NULL;
>> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> +   root = DEREFNODEPTR(rootp);
>> +   while ((cmp = (*compar) (key, root->key)) != 0)
>> +     {
>> +-      if (sp == stacksize)
>> +-      {
>> +-        node **newstack;
>> +-        stacksize += 20;
>> +-        newstack = alloca (sizeof (node *) * stacksize);
>> +-        nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +-      }
>> +-
>> ++      assert (sp < stacksize);
>> +       nodestack[sp++] = rootp;
>> +       p = DEREFNODEPTR(rootp);
>> +       if (cmp < 0)
>> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> +       node upn;
>> +       for (;;)
>> +       {
>> +-        if (sp == stacksize)
>> +-          {
>> +-            node **newstack;
>> +-            stacksize += 20;
>> +-            newstack = alloca (sizeof (node *) * stacksize);
>> +-            nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +-          }
>> ++        assert (sp < stacksize);
>> +         nodestack[sp++] = parentp;
>> +         parentp = up;
>> +         upn = DEREFNODEPTR(up);
>> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> +                 SETNODEPTR(pp,q);
>> +                 /* Make sure pp is right if the case below tries to use
>> +                    it.  */
>> ++                assert (sp < stacksize);
>> +                 nodestack[sp++] = pp = LEFTPTR(q);
>> +                 q = RIGHT(p);
>> +               }
>> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> +                 SETLEFT(p,RIGHT(q));
>> +                 SETRIGHT(q,p);
>> +                 SETNODEPTR(pp,q);
>> ++                assert (sp < stacksize);
>> +                 nodestack[sp++] = pp = RIGHTPTR(q);
>> +                 q = LEFT(p);
>> +               }
>> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
>> index 9f3a3814d0a..3ef2301191d 100644
>> --- a/meta/recipes-core/glibc/glibc_2.43.bb
>> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
>> @@ -55,6 +55,7 @@ SRC_URI =  "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
>>              file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
>>              file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
>>              file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
>> +file://0023-CVE-2026-19542.patch \
>>   "
>>   B = "${WORKDIR}/build-${TARGET_SYS}"
>>
>> -=-=-=-=-=-=-=-=-=-=-=-
>> Links: You receive all messages sent to this group.
>> View/Reply Online (#245430):https://lists.openembedded.org/g/openembedded-core/message/245430
>> Mute This Topic:https://lists.openembedded.org/mt/121158859/10244482
>> Group Owner:openembedded-core+owner@lists.openembedded.org
>> Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [Hemanth.KumarMD@windriver.com]
>> -=-=-=-=-=-=-=-=-=-=-=-


-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 42+ messages in thread

end of thread, other threads:[~2026-09-10 12:53 UTC | newest]

Thread overview: 42+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
2026-09-10  4:42   ` Hemanth Kumar M D
2026-09-10 12:53     ` Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
2026-09-09 17:00   ` Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.